Edtechnolog

Student Data Privacy Frameworks Across US State Regulations

States built separate privacy frameworks because federal law hasn't updated since the 1970s.

Senior Writer · · 10 min read
Cover illustration for “Student Data Privacy Frameworks Across US State Regulations”
EdTech Compliance · August 27, 2026 · 10 min read · 2,256 words

Student data privacy in the US runs on a patchwork. Federal law set a floor in the 1970s and never really got updated, so states filled the gap themselves, each one writing its own version of "don't sell kids' data" with its own teeth behind it. It looks messy from far away, but get closer and you start seeing the pattern.

What the federal layer actually covers, and what it leaves open

Federal student privacy law is really three separate tools, and they don't fit together cleanly. FERPA covers education records at any school that takes federal funding, and the Department of Education's Student Privacy Policy Office is supposed to enforce it. The penalty on paper is losing federal funding, which sounds like a nuclear option, yet it almost never gets used. Families can't sue over a FERPA violation either. No private right of action exists, so the whole thing rests on a federal office that rarely pulls the trigger.

COPPA is a different animal. The FTC runs it, and it covers online collection of personal info from kids under 13, no matter where that collection happens. PPRA is the narrowest of the three: parental sign-off for certain surveys tied to Department of Education funding, and not much beyond that.

These three don't overlap the way you'd want them to. A vendor might answer to COPPA and sit completely outside FERPA's reach. A fourteen-year-old messing around with an AI writing tool at home might fall outside both laws at once. Here's the gap state lawmakers keep circling back to: FERPA puts the compliance job on schools, not on the companies schools hire to run their software. Vendors get treated like an extension of the school, almost like a school employee, rather than as a regulated entity in their own right. That one design choice, made decades before cloud software existed, is basically the reason so much state law exists today.

Diagram: Three Federal Laws, Three Gaps. Visualizes: Show the three federal student privacy laws as a layered or segmented diagram, each with its enforcer, its scope, and its key weakness.

California's SOPIPA and why it became the national template

California didn't wait for Washington. SOPIPA, signed in 2014 and in effect by 2016, was the first state law to put privacy obligations directly on edtech companies instead of routing everything through school districts. It bans selling student data, period, and it bans using school-derived data for targeted ads aimed at kids or their families. It also bans building student profiles for anything outside education.

FERPA cares about records: name, birthdate, student ID number. SOPIPA reaches further, covering behavior, including search activity inside a school platform. Vendors have to secure the data and delete it when a district asks them to. California backed this up with Education Code section 49073.1, also known as AB 1584, which spells out exactly what the contract between a district and a vendor has to say.

Why did this spread everywhere? Because it solved the real problem: districts are underfunded and understaffed, and asking them to police every single vendor was never going to work. Putting the obligation on the vendor itself closed the hole FERPA left wide open, and other states took notice fast. One thing SOPIPA still doesn't touch: general-purpose AI tools that teachers and students pick up on their own, outside any school-approved platform. That gap is about to matter a lot more, and we'll get there.

How other states built on, diverged from, or specialized the California model

Table: How Key States Answered the Same Three Design Questions. Compares Compliance Burden Falls On, Named Security Standard, Family Right to Sue, Enforcement Mechanism, and 1 more by California, New York, Colorado, Utah, and 1 more.

New York went a completely different direction. Education Law § 2-d builds the compliance machine inside the school system itself. Districts have to name a Data Protection Officer, and they need a written Data Security and Privacy Policy that lines up with NIST standards. Every vendor has to sign a Data Privacy Agreement before touching student data, and New York's model version of that agreement, called Exhibit E, has been widely referenced across the field. Repeat violations carry real fines, which gives the law a concrete enforcement mechanism, and parents also get a specific right to review and correct their kid's data. New York's system covers so many students that the compliance infrastructure had to be built at that scale from day one; there wasn't really another option.

Colorado took a third path: transparency at the state level. A public inventory of what student data state systems hold, plus limits on sending that data outside Colorado. Utah went governance-first, handing its State Board of Education the authority and funding to set data privacy policy statewide rather than legislating every rule by hand. Smaller states like Montana, North Dakota, and South Dakota mostly stuck close to the SOPIPA playbook: restrict targeted ads, restrict profiling, require deletion, skip the heavier institutional buildout New York went with.

Line these up and the same three questions keep surfacing. Who carries the compliance burden, the vendor, the district, or a state agency? Does the law name a specific security standard, or leave districts to figure that out on their own? Can a family sue directly, or does enforcement sit entirely with a regulator? Every state answers these questions differently, but they're all answering the same three questions, and that tells you where the actual design decisions are hiding.

Where state frameworks converge: the provisions that appear nearly everywhere

Pull back far enough and the variation shrinks. Nearly every state law bans the sale of student data outright, which goes further than COPPA's narrower ad-only restriction. Most ban targeted ads aimed at students or their households, and most require the privacy terms to actually be written into the vendor contract, not just assumed or implied somewhere. Most require breach notification that goes beyond whatever thin requirement FERPA sets, and most require data to be deleted or handed back once the vendor relationship ends.

None of this happened by accident. States copied SOPIPA, then copied each other, and ended up building something close to a shared legislative dialect, even where the fine print still differs. The vendor contract, specifically the Data Privacy Agreement, is where all of this gets enforced day to day. It's the paperwork that actually turns state law into something a vendor is bound by.

Shared vocabulary isn't the same as shared meaning, though. What counts as a "sale" of data, what counts as "targeted advertising," what counts as personally identifiable information in the first place: these definitions shift from state to state in ways that matter enormously once you're the one drafting the compliance checklist.

The National Data Privacy Agreement as an attempt to standardize across state lines

The Student Data Privacy Consortium built the National Data Privacy Agreement to fix an obvious waste of everyone's time: every school and every vendor negotiating a data agreement from scratch, over and over, with no shared starting point. The NDPA is a model contract built across a large coalition of state alliances, meant to set a common baseline and cut down on redundant back-and-forth. Version 2 came out in April 2024, with another update following in late 2025, since state law keeps moving and the agreement has to keep up with it.

The SDPC also runs a Resource Registry, basically a clearinghouse of signed agreements between thousands of schools and thousands of app makers. It's genuinely useful if you want to check a vendor's track record before signing anything yourself.

There's real friction here. Big vendors love having one standard agreement they can reuse across fifty states, while smaller edtech companies have pushed back, arguing the model agreement locks in obligations they have no room to negotiate around, which raises the cost of even trying to enter the market in the first place. The NDPA is also voluntary, not a mandate. A state with its own required form, like New York's Exhibit E, is going to want that form regardless of what a vendor signed elsewhere. The NDPA imposes some order on the patchwork, but the patchwork's still there underneath it.

What the PowerSchool breach revealed about gaps between law and practice

Late December 2024: PowerSchool, whose student information systems run a dominant share of K-12 districts across the country, disclosed a breach affecting tens of millions of students and educators worldwide. One compromised login was all it took: access into the customer support portal, then a path from there into the core system schools use for grades, attendance, and enrollment records.

An audit brought in after the fact found that basic security steps had apparently gone missing somewhere along the way, which lands directly on the security promises every one of those vendor contracts and DPAs is supposed to guarantee. PowerSchool confirmed it paid a ransom to stop the stolen data from being leaked or sold. Months later, individual districts started getting their own separate ransom demands, using samples of the same data as proof it was real.

Multiple state attorneys general opened investigations. If you want to see how one vendor's bad week becomes a dozen states' regulatory event overnight, this is the clearest example on record. A class action settlement followed, landing on a multimillion-dollar payment split between PowerSchool and a major district, unusually large money for a field where accountability is usually a lot quieter than this.

What the breach actually exposed: state laws require security language in a contract, but they don't always require anyone independent to check whether that security is real. A vendor can look compliant on paper while running weak practice underneath the paper, and breach notification rules also differ state to state, so a vendor serving schools nationally ends up juggling a pile of different clocks and different reporting formats at once. FERPA's big penalty, yanking federal funding, never came up once. Accountability arrived through state attorneys general and a lawsuit, mostly bypassing the federal law that was supposed to be the backbone of student privacy in the first place.

How AI in classrooms is straining frameworks built for a pre-AI world

Most districts now have some kind of generative AI effort underway, and a good chunk of them are running it with zero formal policy attached. That gap by itself is live compliance exposure under laws already on the books.

Then there's what people in the field call shadow AI: teachers and students grabbing free tools on their own, browser extensions, writing helpers, feedback generators, that IT never approved and no DPA ever covered. These tools might hold onto student input, and they might use it to train their own models, or they might hand it off to a third party down the line. Any of that could violate a state's ban on selling or commercially using student data, but the violation stays invisible unless the vendor actually discloses what it's doing, and most don't bother.

FERPA and COPPA were both built around a defined record and a specific moment of data collection, but a large language model just doesn't work that way. It gets fed a prompt, picks up behavioral signals, infers things about a student that were never entered as a data field anywhere, and none of that maps cleanly onto how existing law defines personal information.

States aren't sitting still on this, to their credit. The 2025 legislative session brought a real wave of AI-in-education bills: AI literacy requirements, use guidelines, impact studies, outright bans in specific areas. The same themes keep showing up, like keeping AI out of student mental health support and behavioral evaluation, stopping AI from replacing a teacher's judgment on grading, and requiring vendors to disclose more about how their AI tools handle student data. The NDPA and similar contract templates are starting to add AI-specific clauses, but coverage is spotty, and the technology is moving faster than anyone can write contract language for it.

What the federal reform debate has and has not resolved

Congress has floated FERPA updates more than once, but none of them have passed. The federal floor hasn't moved in any real way since 1974, small amendments aside. The reform idea that comes up most is shifting compliance directly onto vendors instead of funneling everything through the schools that hire them, which is exactly the fix California already made at the state level a decade ago.

Preemption is the sticking point that keeps sinking these bills. A federal student privacy law could set a true floor and let states keep their stronger rules on top of it, or it could wipe those state rules out and replace them with one national standard. Industry tends to want the second version, while privacy advocates tend to want the first, and that disagreement alone has stalled things for years, with no sign of breaking anytime soon.

Nothing here suggests the patchwork is temporary. State legislatures aren't slowing down; if anything the pace has picked up over the last two years. Waiting on a federal fix stopped being a real strategy a while ago, if it was ever one to begin with. Districts and vendors need to build compliance for the actual fifty-state map sitting in front of them right now, since a cleaner federal version may never show up.

One thing's easy to miss in all this: even without a federal law passing, a shared vocabulary has quietly taken hold anyway. Terms like "sale of student data," "commercial use prohibition," and "vendor DPA requirement" now show up across federal proposals and state statutes alike, almost interchangeably. That shapes how new state bills get drafted, how model agreements get written, how a judge reads an ambiguous clause on a random Tuesday. Congress may never pass a bill, yet the norm keeps forming anyway, one state law at a time, whether Washington shows up for it or not.

Sources

  1. studentprivacy.ed.gov
  2. nysed.gov
  3. slocoe.org
  4. eff.org

More in EdTech Compliance