FERPA and student data privacy for school leaders

For principals, district administrators, privacy officers, board members and edtech leaders: run a compliant student privacy program, from notices and disclosures to vendors, breaches and Title IX records.

For: Principals and assistant principals, district administrators, student data privacy officers, school board members and edtech or technology leaders

  • 3 contact hours
  • 9 modules
  • 10 interactives
  • 5 job aids
  • Updated October 11, 2026

What you will be able to do

  • Explain FERPA's structure, enforcement and leaders' written duties, and manage access, amendment, annual notice and directory information decisions.
  • Apply FERPA's consent exceptions, including school officials, contractors, emergencies, subpoenas, law enforcement units, transfers, studies and discipline records, with correct recordkeeping.
  • Distinguish FERPA, HIPAA, PPRA and COPPA, and apply them to school health records, student surveys and edtech for children under 13.
  • Govern vendors, AI and monitoring tools through direct control, data privacy agreements, state student privacy laws, data minimization and an annual program cycle.
  • Lead student data incident and breach response, and manage Title IX, discipline and multi-student records under current rules.

Go beyond the basics to the decisions leaders own: annual notices and directory information policy, access and amendment requests, every major consent exception from school officials and emergencies to subpoenas and studies, how FERPA fits with HIPAA, PPRA and COPPA, vendor and AI governance, breach response, and Title IX records under the rules restored in September 2026.

Written for principals, district administrators, privacy officers, board members and edtech leaders. Scenarios set in real US districts walk through a parent's request for counseling files, a detective at the front desk, a wellness survey, 400 unvetted apps, a vendor breach and a board member's request about a Title IX case.

Current to the March 2025 and August 2026 federal letters, the 2025 COPPA amendments and the September 2026 Title IX recodification, the course separates legal requirements from good practice and gives you a leader checklist, a policy review template, an incident log, a vendor review worksheet and a quick-reference card.

What you’ll be able to do Monday morning

  1. Compare your annual notices across schools and fix inconsistencies or missing school official criteria.
  2. Set up a central log for records requests and track response times.
  3. Give principals a one-page protocol for police requests, subpoenas and emergencies.
  4. Start an inventory of every tool receiving student data and its agreement status.
  5. Require PPRA and state law review for every student survey or screener.
  6. Confirm your Title IX policy and posted training materials reflect the September 2026 recodification.

Curriculum

9 modules · 36 lessons · about 3 contact hours

01What does FERPA require of school and district leaders?Free preview20 min
  1. What is FERPA's structure, and who does it bind?
  2. How is FERPA enforced, and what changed in 2025 and 2026?
  3. Who should own what in a district?
  4. What does a leader's compliance baseline look like?
  • Matching activity: Which law governs what?

Diagram · In practice checklist · 2-question knowledge check

02How should leaders manage access, amendment and hearings?19 min
  1. What must a district do when a parent asks to see records?
  2. Are counselor notes and separate files education records?
  3. How do amendment requests and hearings work?
  4. Divorced parents, eligible students and other tricky access questions
  • Decision tree: Records request decision tool

Diagram · In practice checklist · 2-question knowledge check

03How should annual notices and directory information policy work?18 min
  1. What must the annual notice contain?
  2. How should a district design its directory information policy?
  3. How do opt-outs, former students and military recruiters fit in?
  4. What did Bertram change?
  • Spot the issue: Spot the problems in an annual notice draft

Diagram · In practice checklist · 2-question knowledge check

04When can a district disclose without consent?22 min
  1. School officials and contractors: the most-used exception
  2. Health or safety emergencies
  3. Police, subpoenas, court orders and law enforcement units
  4. Transfers, studies, audits and the recordkeeping rules
  • Sort activity: Consent needed or exception available?

Diagram · In practice checklist · 3-question knowledge check

05How do FERPA, HIPAA, PPRA and COPPA fit together?22 min
  1. FERPA or HIPAA: who holds the record?
  2. What does PPRA require for surveys?
  3. How does COPPA apply when schools choose edtech?
  4. Putting the four laws together
  • Ethics dilemma: The wellness survey

Diagram · In practice checklist · 2-question knowledge check

06How do you govern edtech vendors, AI and surveillance tools?24 min
  1. What does 'direct control' require in practice?
  2. How do state student privacy laws raise the bar?
  3. What extra questions do AI tools raise?
  4. What about student monitoring and surveillance tools?
  • Spot the issue: Spot the weak terms in a vendor agreement

Diagram · In practice checklist · 2-question knowledge check

07How do you prepare for and respond to a student data breach?22 min
  1. What do FERPA and other laws require after a breach?
  2. What should an incident response plan include?
  3. How should leaders handle a vendor breach?
  4. How do you lower breach risk before it happens?
  • Branching scenario: Monday, 6:40 a.m.: vendor breach
  • State rules selector: State student privacy laws for leaders

Diagram · In practice checklist · 2-question knowledge check

08How do Title IX records, discipline and safety information fit in?22 min
  1. Which Title IX rules are in force?
  2. How does FERPA interact with Title IX records?
  3. How should discipline and threat assessment records be handled?
  4. What about board members, media and public records requests?
  • Ethics dilemma: The board member's email

Diagram · In practice checklist · 2-question knowledge check

09How do you build a privacy program that lasts?20 min
  1. What does good data governance look like?
  2. How should training be structured?
  3. How do you monitor and improve the program?
  4. What does an annual privacy calendar look like?
  • Self-assessment: District privacy program self-assessment

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 29 questions, 80% to pass, then your certificate

Try it now, no account needed

Monday, 6:40 a.m.: vendor breach

A branching scenario from this course. Your choices are not saved.

Free sample activity

Monday, 6:40 a.m.: vendor breach

You are the district privacy officer. Your student information system vendor emails that an unauthorized party accessed a database. It does not yet know which districts or data are affected.

Inside the course

Practice activities

  • Matching activity1
  • Decision tree1
  • Spot the issue2
  • Sort activity1
  • Ethics dilemma2
  • Branching scenario1
  • State rules selector1
  • Self-assessment1

Job aids you keep

  • Leader FERPA and Student Privacy Compliance ChecklistChecklist
  • Student Records Policy Review TemplateTemplate
  • Student Data Incident LogLog
  • Edtech and AI Vendor Review WorksheetWorksheet
  • FERPA Quick Reference for School LeadersPocket card

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 3 contact hours of instruction. It is not approved or accredited by any state education agency, licensing board or continuing education accreditor, and it is not a state-specific training. Check with your state licensing office or district whether it is accepted for administrator license renewal or professional development hours.

Pathways we may pursue include review by state administrator license renewal approvers and IACET-aligned processes. None of these approvals exists today; the course page will show an approval only after it is granted.

Our full approvals list

State notes

FERPA sets a federal floor. States add student privacy statutes and regulations that change leaders' duties, especially for vendors. Examples covered in this course: California's SOPIPA (Business and Professions Code 22584) and Education Code 49073.1; New York Education Law 2-d and 8 NYCRR Part 121 (Parents' Bill of Rights, data protection officer, cybersecurity framework, contractor terms, annual staff training); Illinois's Student Online Personal Protection Act (105 ILCS 85); Colorado's Student Data Transparency and Security Act (C.R.S. 22-16-101 and following); Texas Education Code Chapter 32, Subchapter D; and Connecticut General Statutes 10-234aa to 10-234dd.

States also differ on general data breach notification (coverage of public entities, data elements, deadlines), records retention schedules, public records laws, consent rules for surveys and mental health screening, and Title IX-related state requirements. Maintain a state compliance matrix with counsel and confirm details before relying on any summary.

Questions about this course

Who should take this leader course instead of the staff course?

Principals, assistant principals, district administrators, privacy officers, registrars' supervisors, edtech and technology leaders, and school board members. It covers district-level duties such as annual notices, disclosure decisions, vendor agreements, PPRA review, breach response and Title IX records. All school staff should also take the separate staff course on daily privacy practice.

Is the course current with recent federal changes?

It reflects the Department of Education's March 2025 letter on FERPA and PPRA priorities, SPPO's August 2026 PPRA letter, the FTC's 2025 COPPA amendments and the September 29, 2026 Title IX recodification. Federal priorities and rules change, so the course shows you where to check, and we review it at least every 12 months and after major changes.

Does this course replace legal advice?

No. It explains the law and good practice so leaders can recognize issues and ask the right questions. Subpoenas, custody orders, breaches, Title IX matters and state law questions should go to your district's counsel.

How long does it take, and what do I receive?

Plan on about three hours, including nine modules, interactive exercises, knowledge checks and a final assessment. You need 80 percent to pass. You receive a certificate of completion for 3 contact hours plus a leader checklist, a policy review template, an incident log, a vendor review worksheet and a quick-reference card.

Does it cover my state's student privacy law?

It summarizes examples from several states and explains common features, and it includes a state lookup. It is not a state edition. Use your state education agency's guidance and counsel to confirm your exact duties.

Is it approved for administrator license renewal?

Not at this time. It awards a certificate of completion for 3 contact hours and is not approved by any state education agency or accreditor. Check with your state licensing office whether it accepts the course for renewal hours.

This course is general education and training awareness from CE Courses Hub on FERPA and student data privacy for school leaders. It is not legal, medical or professional advice and does not replace your district's policies, your licensing board's rules, or advice from a qualified professional or your district's legal counsel. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.