FERPAConsumer & EducationUnited StatesEducation

Family Educational Rights and Privacy Act

US federal law protecting the privacy of student education records. Applies to all schools receiving federal funding and requires comprehensive access logging.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

FERPA34 CFR 99.32A record of access

Record of Disclosures

Educational agencies MUST maintain records of each disclosure of personally identifiable information.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

FERPA34 CFR 99.31A record of access

Consent Requirements

REQUIRES prior written consent for disclosure with exceptions requiring disclosure logging.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

FERPA34 CFR 99.10Answering for an individual

Right to Inspect

Parents and eligible students MUST be able to inspect and review education records.

Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.

FERPA34 CFR 99.35Retention and availability

Record Maintenance

Disclosure records MUST be maintained for the life of the education record.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

What FERPA covers

34 CFR 99.3 — education records

Records directly related to a student and maintained by an educational agency or institution, or by a party acting for it.

In scope

  • Grades, transcripts and class lists
  • Student schedules and course records
  • Disciplinary records
  • Financial aid and billing records

What falls outside

Sole-possession notes kept by one person and not shared, law enforcement unit records, employment records where employment is not contingent on being a student, and treatment records for students over 18.

Directory information is the operative half. An institution may designate name, address, dates of attendance and similar as directory information and disclose it without consent — provided it has given public notice and honoured opt-outs. That designation, not the record type, is what decides disclosure.

34 CFR 99.3 · as at 2026-08

How FERPA is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Student Privacy Policy Office at the US Department of Education.

FERPA is enforced by one instrument only, and it is a blunt one: an institution that fails to comply can lose federal education funding entirely. Because that sanction is all or nothing, the Department has never imposed it on anyone, and pursues corrective action instead. The Supreme Court confirmed in 2002 that students cannot sue under Section 1983 for a FERPA violation.

The absence of a fine does not mean the absence of consequence — investigations, corrective action plans, and the reputational effect on an institution are the real mechanism.

Uncapped exposure that sits outside this instrument

These come from company law rather than from FERPA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for FERPA,
not configured for it afterwards

Policy Template

Student Record Monitoring

Track all access to student education databases

Report

FERPA Disclosure Log

Lifetime disclosure records for education records

Classification

Student Data Patterns

Identify student IDs, grades, disciplinary records, and PII

Alert

Unauthorized Student Data Access

Alert on access outside FERPA authorized purposes

Walk into the FERPA audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment