Back to Blog
🔐

FERPA and COPPA for AI Tools: A K-8 Vetting Checklist

No AI tool is "FERPA compliant" on its own, because FERPA is a duty on schools, not vendors. What a school can do is use a tool under FERPA's school official exception, with a written agreement that keeps the school in direct control of student data. For students under 13, COPPA adds a second test: the vendor may rely on the school's consent only if the data is used solely for the school's educational purpose. This checklist turns both laws into questions you can put to any AI vendor.

This is practical guidance, not legal advice. Your district's counsel and privacy officer have the final word.

Why AI tools need a closer look than other edtech

Most edtech collects what students click. AI tools collect what students say: free-text questions, stories, worries, sometimes their name or school typed in without anyone noticing. That makes three questions sharper than usual:

The US Department of Education's July 2025 guidance on using federal funds for AI lists "data-protective" among its principles for responsible use, and expects AI systems to comply with federal privacy law, including FERPA (U.S. Department of Education, July 2025).

What makes an AI tool FERPA compliant

FERPA protects education records held by schools that receive US Department of Education funds. Normally, sharing personally identifiable information from those records needs parental consent. The common route for edtech is the school official exception (34 CFR 99.31): a vendor can be treated as a school official if it:

  1. Performs a service the school would otherwise use its own staff for.
  2. Is under the school's direct control regarding the use and maintenance of the records.
  3. Uses the data only for the authorized purpose and does not redisclose it.
  4. Meets the criteria in the school's annual FERPA notification for having a legitimate educational interest.

"Direct control" is where AI tools most often fail. If the vendor's terms let it change how it uses data, keep it indefinitely, or train general-purpose models on it, the school is not in control. The Department's Student Privacy Policy Office publishes guidance on protecting student privacy in online educational services and a model terms of service checklist worth keeping open while you review contracts.

COPPA in two minutes

COPPA applies to operators of online services that collect personal information from children under 13. Schools are not the operator, but they matter. The FTC's COPPA FAQ (section N) says:

The amended COPPA Rule, published in April 2025, took effect on 23 June 2025, with most obligations requiring compliance by 22 April 2026 (Federal Register). Notably, the FTC chose not to finalize its proposed ed tech and school-authorization provisions, and said it would keep enforcing COPPA in schools under its existing guidance. Changes that do apply to vendors include separate parental consent before disclosing children's data to third parties for purposes such as targeted advertising, and limits on keeping children's data longer than reasonably necessary.

The vetting checklist

Send these questions to the vendor and keep their written answers with the contract.

Data collected

Use of data

School control

Classroom safety

Security

Parent communication

A vendor that cannot answer these in writing is not ready for your students, however good the demo. Many states add their own student privacy laws on top of FERPA and COPPA, so check your state's requirements and any statewide data privacy agreement your district already uses.

Common pitfalls

Click-through terms signed by a teacher. An individual teacher accepting a free tool's terms is the most common gap. The FTC's best practice is a school or district decision, so route new AI tools through whoever owns data privacy agreements.

Teacher tools with student data pasted in. A general AI assistant approved for lesson planning is not automatically approved for student records. Pasting identifiable student work into it is a different use. Our AI prompts for teachers are written to avoid this.

"FERPA certified" badges. There is no official FERPA certification. Treat badges as marketing and read the contract.

Consumer chatbots in the classroom. General-purpose chatbots set minimum ages in their terms and are not designed for young children. For a full discussion, see ChatGPT in schools.

How Askie for Schools answers the checklist

Askie for Schools is designed to support FERPA and COPPA school-authorized consent, as well as UK GDPR and GDPR. In practice:

Send us the rest of the checklist at askie@kidsai.app. You can start free with up to 20 students on Askie for Schools.

Frequently asked questions

Is ChatGPT FERPA compliant?

No consumer tool is FERPA compliant by itself, because FERPA obligations sit with the school. A school can only use a tool under FERPA if it has an agreement that keeps student data under its direct control. Check whether your district has such an agreement before any student data goes in.

Not always. Under the FTC's guidance, a school can consent for parents when the tool is used only for an educational purpose and the vendor uses the data for no other commercial purpose. Many districts still notify parents, and some require opt-in. A letter to parents about AI helps either way.

Did the 2025 COPPA amendments change the rules for schools?

The FTC did not finalize its proposed school-specific changes, so school consent still works under existing FTC guidance. Vendors do face new obligations, including on third-party disclosure and data retention.

Who should vet AI tools in a district?

The person or team that owns data privacy agreements, usually with the technology director and a curriculum lead. For a pilot, see how schools can pilot AI.

An AI Tool Built Around School Consent

Askie for Schools is designed to support FERPA and COPPA school-authorized consent. Your school stays in control of student data. Free for 20 students.

Review Askie for Schools