The Family Educational Rights and Privacy Act is often summarized as a consent rule for schools. That description is incomplete. A 2026 letter from the U.S. Department of Education shows how quickly FERPA questions can become questions about access controls, patching, incident response, vendor oversight, and evidence.
On May 12, 2026, the Department’s Student Privacy Policy Office sent a four-page letter to Instructure, the company behind the Canvas learning-management platform. The letter followed cybersecurity incidents affecting customers and others. It stated that the incidents resulted in unauthorized access to student education records and that FERPA violations “likely occurred.” It requested a written response by May 25 describing the incidents, the number of affected U.S. K-12 and higher-education students, the types of information exposed, corrective actions, and communications with schools, parents, and students.
That language matters, but so does the procedural status. The letter was a request for information under the Department’s FERPA enforcement authority. It was not a final adjudication, civil penalty, enacted amendment, or scheduled congressional vote. Its significance comes from the evidence the Department requested and the compliance expectations that evidence reveals.
FERPA follows education records into outsourced systems
FERPA is an existing federal law implemented through 34 C.F.R. Part 99. It applies to educational agencies and institutions receiving funds under programs administered by the Department of Education. It gives parents rights involving their children’s education records; those rights generally transfer to the student when the student turns 18 or attends a postsecondary institution.
The law generally requires signed and dated consent before personally identifiable information from education records is disclosed, unless an exception applies. Consent must identify the records, the purpose, and the party or class of parties receiving them. FERPA also gives parents and eligible students rights to inspect records and seek amendment of information they believe is inaccurate, misleading, or in violation of privacy rights.
Schools regularly rely on outside platforms for functions they once performed internally. FERPA’s “school official” exception can permit disclosure to a contractor, consultant, volunteer, or other outside party without prior consent, but it is not a blank check. The Department’s school-official guidance says the outside party must perform a function for which the school would otherwise use employees, remain under the school’s direct control regarding the use and maintenance of the records, follow limits on use and redisclosure, and meet the criteria in the school’s annual FERPA notice.
For a product team, “direct control” cannot exist only in a contract. Roles, permissions, retention, exports, support access, model-training pipelines, and subprocessors must align with the educational purpose for which the data was disclosed.
The letter asked for evidence, not promises
The most instructive part of the Instructure letter is Exhibit A. The Department requested governance documents such as an information-security policy, risk assessments, a risk register, data-classification and handling rules, access-control policies, and vendor-risk procedures. It also requested operational evidence: incident-response plans and testing logs, periodic user-access reviews, patch records, change-management logs, and security-training records.
The technical list continued with network diagrams, asset inventories, configuration standards, penetration-test results, and independent assurance materials such as SOC 2 Type II reports or ISO 27001 certification. The Department also identified AI-use policies and remote-work security as key focus areas for 2026.
This is a useful distinction for every privacy program. A written policy describes intended behavior. Logs, inventories, reviews, test results, and remediation records show whether the organization followed that policy. When sensitive records are exposed, a regulator will not be satisfied by a general statement that security is taken seriously.
Developers should translate those categories into product requirements. Every service should have an owner and a place in the asset inventory. Administrative access should be narrow and reviewable. Security-relevant configuration changes should leave an audit trail. Patches should have severity-based deadlines and documented exceptions. Incident exercises should test who can identify affected students, schools, data categories, and downstream recipients during a crisis.
Classroom convenience does not erase approval and purpose limits
The Department separately advises teachers to check whether an online tool is approved by their school or district before using it. Its guidance on classroom applications says a service receiving education-record information under the school-official exception must remain under the school’s direct control, use data consistently with the annual FERPA notice, and avoid unauthorized use or redisclosure.
That should shape onboarding design. A teacher’s ability to create an account or connect a class roster does not prove that the district approved the product. An OAuth consent screen does not answer whether the school has a permitted FERPA basis for the disclosure. A privacy policy does not create direct control. Ed-tech services need deployment paths that support district review, scoped permissions, documented purposes, contractual restrictions, and reliable deletion or return of records when the service ends.
AI features create another risk of purpose drift. Student submissions collected to provide feedback should not silently become training data for a separate general-purpose model. If an AI feature uses education records, the organization needs to identify the authorized educational purpose, minimize the inputs, control who can retrieve prompts and outputs, and prevent secondary use that exceeds the disclosure basis.
What parents, students, and schools can do
Parents and eligible students can request the school’s annual FERPA notice, ask to inspect education records, and seek correction through the school’s established process. They should also read the school’s directory-information notice, which must identify the designated categories, explain the right to refuse disclosure, and provide a deadline for opting out. Directory information is not a universal license to disclose every student detail.
When a breach occurs, affected people should ask which records were involved, which organization maintained them, who gained access, what the information was used for, and what corrective measures are underway. FERPA is only one part of the analysis; state student-privacy statutes, breach-notification laws, contracts, and other federal rules may also apply.
For schools and vendors, the Instructure letter offers a clear operational lesson: privacy compliance is not complete when a policy is published or a contract is signed. The organization must be able to show what data it holds, why it holds it, who can reach it, what changed, what failed, and what was done in response.
About Joseph Sides
Joseph Sides is a South Florida-based data privacy advocate, consultant, and entrepreneur whose work focuses on consumer rights, digital transparency, website tracking, meaningful privacy choices, and responsible technology. His public DEV introduction describes a bachelor's degree in criminology, a minor in business, and training in data analytics. These interests connect questions about how technology operates with questions about what people understand and how organizations remain accountable for their decisions.
The educational purpose of these articles is to make privacy developments easier to follow and their practical implications easier to examine. That means connecting the language of laws and regulatory actions with familiar experiences: visiting a website, choosing an app, responding to a consent request, or trying to delete information. For developers, the discussion also considers how interface choices and data practices shape the choices available to consumers. The aim is informed understanding and thoughtful questions, with attention to both individual rights and responsible product decisions.
Educational Information — Not Legal Advice
This article provides general education and commentary, not legal advice. Joseph writes as a privacy advocate and consultant, not as an attorney. Reading this article does not create an attorney-client relationship, and the discussion is not a substitute for advice from a qualified attorney about your particular circumstances.
Laws, interpretations, applicability, exemptions, and deadlines vary by jurisdiction and can change. A requirement that applies to one organization or activity may apply differently to another. Readers should consult current primary sources and a qualified attorney when evaluating obligations, available rights, or a specific course of action. This article does not promise complete coverage, guaranteed outcomes, or personal legal guidance.
AI Disclosure
Prepared with AI assistance.
Top comments (0)