FERPA Exceptions and Permissible Disclosure Scenarios
Schools must document threats and recipients to legally withhold student records in emergencies.

FERPA runs on a simple default: a school can't hand out personally identifiable information from a student's education record without written consent from the parent, or from the student once they turn 18 or enroll in college. But if that rule had zero exceptions, schools would grind to a halt. You couldn't email a transcript to another school, couldn't tell a coach a kid's GPA, couldn't even print a yearbook, so Congress built in exceptions. This piece walks through each one, what it actually permits, and where schools keep tripping over the fine print.
How the Exceptions Are Actually Structured
The legal skeleton here is pretty simple, even if the muscle on top of it gets complicated. The statute is 20 U.S.C. § 1232g, and the regulations that flesh it out live in 34 CFR Part 99. The Department of Education's Family Policy Compliance Office (FPCO) is the referee.
FERPA dates back to 1974, and it's been amended a bunch of times since, mostly to spell out new disclosures schools can make without asking permission first. So the exception list you see today isn't some tidy original blueprint. It's more like a house that's had six additions built onto it over fifty years, each one solving a specific problem that came up.
The full list of permissible nonconsensual disclosures sits in 34 CFR § 99.31, and some exceptions get their own extra detail elsewhere (health and safety emergencies get their own section, § 99.36, because apparently one paragraph wasn't enough). Here's the thing worth tattooing on the inside of every administrator's eyelids: meeting the label of an exception isn't the same as meeting its conditions. Saying "this is an emergency" doesn't make it one under the law. Each exception has its own checklist, and skipping steps on that checklist is still a violation, even when the intent was good.
Think of the exceptions less like loopholes and more like marked lanes on a highway. You're allowed to drive in them, but you're not allowed to swerve outside the lines just because you're in a hurry.
School Officials: What "Legitimate Interest" Really Means
This is the one schools use constantly, probably without even thinking about it. Under 34 CFR § 99.31(a)(1), a school can share records internally with school officials who have a "legitimate educational interest" in them.
What does that actually mean? It means the person needs the record to do their job, not because they're curious. A counselor reviewing grades to plan a schedule has a legitimate interest. A teacher looking up a student's disciplinary file because they heard a rumor in the break room does not, no matter how juicy the rumor. The need has to connect to an actual professional responsibility, whether that's an administrative task, a supervisory role, instruction, or a defined service like healthcare or financial aid.
And this exception isn't limited to employees. Outside vendors can count as "school officials" too, but only if three things are true: they're doing work the school would otherwise assign to its own staff, the school keeps direct control over how they use and store the data, and they follow FERPA's rules on use and redisclosure. This matters a lot right now, with schools handing student data to ed-tech platforms, cloud storage providers, and outsourced services left and right. A school can't just ship records off to a vendor and then shrug when something goes wrong. The responsibility doesn't transfer, it just gets shared.
Schools also need reasonable methods to make sure officials only see what their role requires, whether that's a technical access control or just a policy that's actually enforced. The most common way schools mess this up is sharing a student's entire file with everyone loosely connected to a case, instead of giving each person only the slice relevant to their job. It's the records equivalent of forwarding an email to "everyone" instead of just the two people who needed it.
Directory Info Needs Its Own Policy Infrastructure
Directory information covers stuff schools have historically treated as low-stakes: name, address, phone number, birth date and place, major, dates of attendance, activities, an athlete's height and weight, degrees and honors. Sounds harmless, and it can be, but only if the school does its homework first.
Before releasing any of it, the school has to give parents (or eligible students) real public notice about what counts as directory information at that institution, plus the right to opt out. FERPA doesn't require a school to have a directory information policy at all, but if it does have one, that notice-and-opt-out process isn't optional, it's the price of admission.
Here's the part that catches people off guard: once information goes out the door as directory information, it's no longer protected by FERPA at all. It leaves the building and doesn't come back, with no use restrictions and no redisclosure limits. So if a school releases something it later regrets, there's no putting the toothpaste back in the tube.
The most frequent misapplication is treating directory information like a free-for-all release valve, skipping the notice step, or forgetting to check the opt-out list before hitting send. And that opt-out check matters even for information that clearly fits the directory definition. If a student filed an opt-out, that information is off-limits, full stop, policy or no policy.
Safety Emergencies Demand an "Articulable Threat"
Schools can disclose records without consent when it's necessary to protect health or safety, under 34 CFR §§ 99.31(a)(10) and 99.36. The key phrase is "articulable and significant threat," not a vague worry or a gut feeling, but a threat the school can actually describe out loud, with a clear explanation of why disclosure is needed to deal with it.
FPCO gives school officials real room to make this call, and that deference is meaningful; it just isn't a blank check. Officials still need to be able to explain, after the fact, what the threat was and why sharing information addressed it.
The scope is tight in a few specific ways:
- It only lasts as long as the emergency does, not indefinitely.
- It doesn't authorize dumping a student's whole file, only what's needed for that specific threat.
- It has to connect to something real and immediate, like a shooting, a natural disaster, an act of terrorism, or a disease outbreak.
Who's allowed to receive this information? Law enforcement, public health officials, trained medical staff, and parents.
If a school uses this exception, it has to document two things in the student's record: what the threat was, and who got the information. Without that documentation, there's no defense later if someone questions the call.
This exception got a lot more flexible after the 2007 Virginia Tech shootings, when 2008 regulatory amendments gave schools more breathing room to act on perceived risks. But more flexibility cuts both ways, since it also raises the bar for schools that fail to act when they probably should have.
COVID gave a clean, real-world example of the scope limit in action. A school can tell the community "a student in this building tested positive" without naming names. Identifying a specific student is only justified if it's genuinely necessary to protect others, and that call gets made case by case, not as a blanket policy.
Research Access Is Narrower Than You Think
Under 34 CFR § 99.31(a)(6), schools can share PII with organizations doing studies on their behalf, but only for three specific purposes: developing or validating predictive tests, running student aid programs, or improving instruction. That's the full list.
People love to read this as a general research exception. It isn't. A university professor doing interesting academic work on student outcomes doesn't automatically get access just because the research has value. The study has to be done for or on behalf of the school, not simply about education as a broad subject.
Three conditions have to hold all at once. The study has to be conducted for the school's benefit, not identify individual students except to a rep of the organization who has a legitimate reason to see that data, and destroy the PII once it's no longer needed. On top of that, published results can't allow anyone to identify a specific student or parent. Researchers get to use identifiable data to do the work; they don't get to publish it in identifiable form.
So the practical upshot: a university can't wave a researcher through the door just because the project sounds academically compelling. It has to fit the narrow purpose and clear all three conditions, every time.
Audits Are Strictly for Education Oversight Only
This one covers disclosure to authorized reps of the Comptroller General, the Attorney General, the Secretary of Education, and state or local educational authorities, for the purpose of auditing, evaluating, or enforcing education programs.
The boundary that trips people up: this only applies to educational authorities. A state health department, a social services agency, whatever other government office has a stake in student outcomes, none of them qualify just because they're a government agency doing important work. This exception has a narrow lane, and it's specifically for education oversight.
This is also the legal backbone behind most state longitudinal data systems, the ones that track student records across districts and years for evaluation purposes. Useful infrastructure, built on a fairly narrow exception that a lot of people assume is broader than it actually is.
Aid, Transfers, and Subpoenas: Transaction-Driven Exceptions
These three exceptions all share a theme: they exist because of a specific transaction happening, not a general policy interest.
Financial aid. Schools, mostly postsecondary ones, can share information needed to figure out eligibility, award amounts, and conditions attached to aid, plus enforce those conditions. If the financial aid office passes that data to another office internally, the receiving office has to agree not to redisclose it. The restriction travels with the data like a tracking chip.
Transfers. A school can send records to another school where a student is enrolling or planning to enroll. The No Child Left Behind Act added a specific twist here: states must have a procedure for transferring disciplinary records, including suspensions and expulsions, when a student moves to a new public or private K-12 school. That's a state-level mandate, not a school's personal choice, even though plenty of schools treat it like a suggestion.
Judicial orders and subpoenas. Schools can comply with a court order or subpoena, but they have to make a reasonable effort to notify the parent or eligible student first. There are two exceptions to that notification step: law enforcement subpoenas and ex parte orders under the USA PATRIOT Act, where the issuing authority can order the school to keep quiet about the subpoena's existence entirely. Outside of that, without a subpoena and without a health or safety emergency, schools can't hand non-directory information to law enforcement. A lot of administrators don't realize how firm that line actually is.
Parents Don't Always Lose College-Age Access
Once a student turns 18 or enrolls in college, FERPA rights move to the student, full stop, and parents lose their automatic access. Except when they don't.
The dependent student exception. If either parent claims the student as a tax dependent, that parent can get nonconsensual disclosure of records, regardless of the student's age and regardless of custody arrangements. A court order specifically blocking access overrides this. The student's consent isn't required here; tax dependency status alone does the job.
Alcohol and drug violations (postsecondary only). A college can notify the parents of a student under 21 if that student violated laws or campus policy around alcohol or drugs. This doesn't exist for K-12 schools at all, and notice the word "may," not "must." The school has discretion; it's permitted, not mandatory.
Disciplinary proceedings involving violent crimes or nonforcible sex offenses. The final result of a disciplinary proceeding can be shared with the alleged victim no matter how it turned out. But names of other students tied to the case, including witnesses, stay protected unless they consent in writing. And this only covers the final result: the investigative file and interim findings are not fair game.
Where Disclosure Practice Actually Breaks Down
Across every exception here, the failure pattern looks the same: someone invokes the label without meeting the conditions. "This is a safety emergency" without an articulable, significant threat behind it. "This is a school official" without any defined legitimate interest tied to their role. The label feels like enough in the moment, but it isn't.
Documentation is the seatbelt here. The health and safety exception makes recordkeeping mandatory, but the same logic applies everywhere. If a disclosure was legitimate, the school should be able to explain why, on paper, after the fact, not from memory, and not with a shrug of "I'm pretty sure that was fine."
Redisclosure is the quiet problem nobody thinks about until it bites them. The financial aid exception and the studies exception both come with strict limits on what a recipient can do with the data once they have it. If a school hands off information without telling the recipient about those limits, the school hasn't actually satisfied the exception it thinks it used.
Directory information has its own gap: schools often have a policy on paper but an opt-out list that's out of date or barely checked. And the vendor blindspot might be the biggest one of all right now. Plenty of schools treat their ed-tech platforms and cloud vendors as outside FERPA's reach, when legally, those vendors are functioning as school officials under § 99.31(a)(1) the moment they're handling student records on the school's behalf. Handing off the data doesn't hand off the responsibility. It never did.


