FERPA Violation Examples in EdTech Integration Contexts
Schools hold the liability when EdTech vendors misuse student data they legally can access.

FERPA doesn't regulate EdTech vendors. It regulates schools that take federal money. That single fact explains almost every weird, backwards-looking compliance failure in the K-12 tech stack, because the company holding the data is often the one with zero direct legal obligation to protect it.
Vendors get into student records through something called the "school official exception," a rule that lets a district treat a company like an employee for data purposes, as long as three boxes get checked: the vendor performs a service the school would otherwise do itself, the school keeps "direct control" over how the data gets used, and the vendor sticks to the purpose it was hired for. Miss any one of those three, and the disclosure is unlawful, no matter if the vendor signed a stack of paperwork an inch thick. The exception either holds or it doesn't.
Here's the part that should bother you more than it probably does: the vendor has no statutory FERPA obligation of its own. If something goes wrong, the institution eats the liability, even though the institution rarely has the technical ability to check what the vendor is actually doing with the data behind the login screen. Schools sign the contract, and vendors run the server, but guess who the regulator calls first.
This exact same legal mechanism, the school official exception, is what lets a teacher pull up a gradebook and what lets an EdTech company ingest 40,000 student profiles. Same rule, wildly different risk profile, and that conflation is where a lot of well-meaning IT directors get tripped up.
How a missing or vague Data Processing Agreement turns the school official exception into a loophole
A Data Processing Agreement is the thing that turns "we handed a vendor our students' data" from a violation into something legal. It's the hinge the whole exception swings on. To do that job, a DPA needs three things: a clearly stated permitted purpose, a flat prohibition on redisclosure, and audit rights for the district. Skip one of those, and the school has no lawful basis for the sharing, no matter how many signatures are on the document.
Now consider the number that should make you sit up: per TechPolicy.Press (2025), fewer than 25% of school-vendor agreements actually specify the purpose of data disclosures. Three out of every four contracts leave the legal basis for handing over student data completely undefined. Undefined purpose means no enforceable limit on what happens next, like signing a lease that never says what the apartment can be used for, then acting surprised when your tenant opens a nightclub downstairs.
The gaps tend to rhyme across procurement cycles:
- Purpose clauses that say "educational purposes" and stop there, defining nothing
- No language ruling out product improvement, ad targeting, or building profiles for non-educational use
- No deletion schedule, no requirement to return or destroy data when the contract ends
- No audit or inspection rights, meaning the district takes the vendor's word for it
Even a well-drafted DPA has a soft underbelly, though, since it depends on the vendor to self-report when something's gone wrong. Districts almost never have the technical means to verify compliance on their own; they're reading a report card the student wrote.
When vendors use student data for purposes the school never authorized
Some uses fall outside the school official exception no matter what the contract says: advertising, product improvement, building a profile of a kid that has nothing to do with their education. A DPA can't bless these, because they were never available to bless in the first place.
The Edmodo case, brought by the FTC in May 2023, is the example every compliance officer should have taped to their monitor. The FTC alleged Edmodo collected personal data from kids under 13 without verified parental consent and used it for advertising. Edmodo's defense, essentially, was that its terms of service told teachers they were solely responsible for COPPA compliance. The FTC called that argument "nonsensical" and threw it out without much ceremony. A $6 million civil penalty followed (suspended, because Edmodo couldn't pay it), but the fine wasn't the headline.
The real teeth were in the remedy: the FTC ordered Edmodo to delete "Affected Work Product," meaning any AI model or algorithm trained on the unlawfully collected data. Not audit it, not disclose it, but delete it entirely. That's the regulator saying, in plain terms, that a model trained on tainted data is itself tainted, and you don't get to keep the model just because you're sorry about the input.
The lesson under the lesson: you cannot outsource your compliance obligation to a teacher's checkbox or a parent's consent form. The platform owns its own data practices. There's also a structural wrinkle worth naming out loud: free and freemium EdTech tools carry a built-in incentive to monetize student data, because the school isn't paying enough (or anything) to make the business model work otherwise. Nobody builds a free app out of pure civic duty.
The emerging FERPA question around AI model training on student records
Here's where things get genuinely unresolved, not just messy. The school official exception lets a vendor use education records for the "authorized purpose" of the service it's contracted to deliver. But if a company is hired to build an adaptive tutoring tool, does training an AI model on student performance data count as "delivering the service," or is that a second, separate use that needed its own permission slip?
Nobody has issued clear FERPA guidance on this yet. The closest signal is that Edmodo deletion order, which strongly implies regulators see model training as its own distinct act, not a natural extension of "using the product." That's a meaningful hint, even if it's not a rule.
Consider also that the stakes here are worse than a typical data leak, because once student information lands inside an AI training set, getting it back out is extraordinarily hard and expensive. "Unlearning" is not a mature technology, and the harm doesn't reverse just because someone catches the mistake. There's a quieter risk sitting underneath all of this, too: large language models trained on general internet data can inadvertently absorb student information if an EdTech platform never bothered to sanitize its inputs before feeding them into a training pipeline.
For districts negotiating contracts, "educational purposes" is no longer a phrase specific enough to mean anything. DPAs need explicit language on whether student data can be used to train, fine-tune, or improve an AI model at all. Most templates currently in circulation were written before generative AI got baked into every EdTech product on the market, which means most of them simply don't address the question. They're using a map from before the road existed.
How insecure vendor infrastructure converts a compliance gap into a mass data exposure
A paperwork problem is bad, but a paperwork problem sitting on top of an unencrypted database is a disaster. The Illuminate Education breach shows exactly how that combination plays out.
Unauthorized access ran from December 28, 2021 to January 8, 2022, hitting student data across New York City and Los Angeles, two of the largest public school systems in the country. In New York City alone, personal data belonging to 820,000 current and former students got exposed, which Education Week has described as possibly the single largest cyberattack on a school district in U.S. history. The data wasn't just names and birthdates, either; it included racial and ethnic profiles, test scores, and in some cases disability status, behavioral incident records, and migrant status.
The FTC's investigation, resolved in December 2025, laid out exactly how the failure happened, and it's not subtle:
- Student data sat in plaintext in AWS S3 buckets, unencrypted, until at least January 2022
- No comprehensive incident response plan existed until November 2022
- No policy for inventorying or deleting unnecessary data existed until March 2022
- A third-party vendor had flagged security vulnerabilities as early as January 2020; Illuminate failed to take adequate steps to correct them
Two years of warning went unaddressed. The FTC's order required Illuminate to build an actual data security program and delete data it didn't need — the FTC's action had alleged hackers accessed data belonging to more than 10 million students. Separately, California, Connecticut, and New York reached a $5.1 million settlement with the company. And in a move with real symbolic weight, the Future of Privacy Forum pulled Illuminate off the Student Privacy Pledge, the first company ever removed from that list.
That last detail matters for procurement teams everywhere: a voluntary privacy pledge is a nice logo on a sales deck. It is not a security audit, and it never was.
What the PowerSchool breach reveals about vendor concentration risk
Disclosed December 28, 2024, the PowerSchool breach compromised data tied to 62 million students and 9.5 million educators worldwide. That number alone puts it in a different category than Illuminate, but the real story is what PowerSchool represents structurally.
PowerSchool serves roughly 75% of the K-12 education market, operating across more than 90 countries and over 18,000 schools in North America. When a vendor at that level of market penetration gets breached, a district's own security posture becomes almost irrelevant, because there's no fallback system to fall back on. Everyone's downstream of the same pipe.
The cause was almost insultingly small: a single compromised credential on a customer support portal, with no multi-factor authentication protecting it. That one password was the whole story of how names, birthdates, Social Security numbers, contact details, and limited medical information for millions of students and educators walked out the door, with some districts reporting exposed records going back more than 20 years.
Then came the sequel nobody wanted. PowerSchool paid a ransom to secure deletion of the stolen data. Months later, the Toronto District School Board, serving over 240,000 students, reported being extorted by a threat actor holding data samples that matched the December breach. The data was supposedly deleted, but it clearly wasn't. That's double extortion in its textbook form: pay once, get shaken down again, because there was never any real guarantee the first payment did what it promised.
Worth sitting with, too: PowerSchool's CEO had spoken at a White House cybersecurity summit in 2023, and the company had spent real marketing effort positioning itself as a leader in K-12 data security. Reputation and reality diverged badly here, and that gap is exactly why districts need contractual audit rights baked into agreements. Trust the paperwork, not the keynote speech.
Operational failures that cause FERPA violations without any breach at all
Most FERPA violations have nothing to do with hackers. They come from ordinary workflow failures, the kind that happen in every office everywhere, except here the stakes involve a kid's disability records instead of a missed meeting invite.
The classic examples are almost boring: a teacher hits reply-all on a grade report, an administrator emails a transcript to the wrong address, a school publishes an honor roll without checking who opted out. Low drama, but high consequence.
EdTech adds its own flavor of these mistakes:
- Former students or staff who still have login access to systems holding active student records
- Roster syncs that lag behind actual enrollment, exposing data for kids who already left the district
- Missing export controls, so anyone with admin access can download and share student records with zero logging
- Long chains of intermediary systems, where an LMS feeds a reporting tool, which feeds an AI system, which feeds a support platform, and nobody documented the agreements covering every handoff
Per Magic EdTech, modern school technology stacks rarely live in one tidy ecosystem; student data moves through learning management systems, analytics tools, AI tutoring platforms, assessment software, and third-party integrations, often simultaneously. A DPA with the primary vendor covers exactly that vendor, but it does not automatically cover whatever three other tools that vendor happens to plug into. Each node in that chain needs its own authorization, which almost nobody actually tracks in practice.
Surveillance tools like GoGuardian and Gaggle add another wrinkle entirely: real-time screen monitoring, message scanning, behavioral flagging. These generate a constant stream of student data, and the retention rules, access limits, and secondary-use policies governing that stream are rarely spelled out anywhere in the procurement agreement, because nobody asked and nobody wrote it down.
How delayed and misleading breach disclosure compounds the original violation
FERPA itself sets no clock on breach notification, but state laws increasingly do, and the FTC has shown it will act on delayed disclosure regardless. The Illuminate case is instructive here too: the FTC alleged the company failed to notify districts in the timeframe it had promised, in some cases waiting nearly two years after the breach to say anything.
A 2024–2025 investigation by The 74, looking across more than 300 K-12 cyberattacks, found a recurring pattern: districts routinely gave families "incomplete, misleading or downright inaccurate information" about breaches, according to the Public Interest Privacy Center (July 2025). Two examples stand out.
In Los Angeles, officials initially denied that student psychological evaluations were exposed in a 2022 ransomware attack, calling the reports "absolutely incorrect." Later, they acknowledged that roughly 2,000 of those evaluations had actually been published online. In Minneapolis, officials first told families there was "no evidence" personal information had been compromised, then waited nearly two weeks to walk that back, then took months more to send direct notification letters to affected families.
Delayed or wrong disclosure doesn't erase the original breach. It creates a second violation stacked on top of the first, and in states with mandatory notification laws, that second failure carries its own separate liability. What most districts underestimate: whatever gets said publicly in the first 48 hours after discovering a breach isn't a communications call. It's a compliance decision, and it gets treated as one by regulators later, whether the district meant it that way or not.
What enforcement actually looks like — and where the real consequences come from
Here's the part that surprises almost everyone new to this space: the Department of Education has never once terminated funding over a FERPA violation, and every single case has ended in corrective action instead. Thanks to Gonzaga University v. Doe, individual students can't sue a school to enforce FERPA directly, which strips out the kind of litigation pressure that keeps other privacy regimes honest.
So where does the actual pain land? Not where you'd expect.
The FTC has become the sharper instrument, using its own jurisdiction over the same conduct FERPA nominally governs: the $6 million Edmodo penalty and model-deletion order in 2023, the data security program and mandatory deletion imposed on Illuminate in 2025. State attorneys general are doing real work too; the $5.1 million Illuminate settlement came from California, Connecticut, and New York, not from Washington. State privacy statutes carry their own independent teeth; California's SOPIPA operates on its own terms, and CalPrivacy fined PlayOn Sports $1.1 million in March 2026 over conduct touching roughly 1,400 California schools. Then there's the market itself: getting removed from the Student Privacy Pledge, as Illuminate was, functions as its own kind of enforcement, quietly closing doors with privacy-conscious buyers who'll never sign a contract in the first place.
Add it up, and the picture looks like this: federal FERPA enforcement is gentle almost to the point of toothlessness, but the exact same conduct exposes a vendor, and often the institution alongside it, to the FTC, to state attorneys general, and to civil penalties under state law. That gap between federal softness and everything sitting behind it is precisely why DPAs, security audits, and real contractual audit rights aren't paperwork theater. They're the only thing standing between a school district and a liability that doesn't go away just because nobody in Washington is in a hurry to enforce it.


