FERPA — the Family Educational Rights and Privacy Act, codified at 20 U.S.C. 1232g and 34 CFR Part 99 — requires any school that receives U.S. Department of Education funding to protect the privacy of student education records, and in practice that means training every employee and contractor who can see those records. The law does not name a specific course or renewal interval, but it holds schools responsible for how staff and vendors handle personally identifiable information, so documented training is how districts and EdTech companies show they took “reasonable methods” seriously.
For K-12 districts, colleges, and the SaaS vendors that serve them, the risk is not a per-record fine — it is the loss of federal funding and the reputational fallout of a student-data breach.
What Does FERPA Actually Require Schools to Do?
FERPA gives parents — and “eligible students” once they turn 18 or enroll in a postsecondary institution — the right to inspect, review, and request correction of education records, and it restricts when a school can disclose those records without consent. The full regulation sits at 34 CFR Part 99 on eCFR, and the Department of Education’s Student Privacy Policy Office publishes plain-language guidance on top of it. Two obligations drive most of the day-to-day work: the annual notification, in which a school must tell parents and eligible students of their FERPA rights each year, and the consent rule, which bars disclosure of personally identifiable information from education records without written consent unless an exception applies.
Training is what turns those obligations into staff behavior. A front-desk clerk who emails a class roster to the wrong parent, or a professor who posts grades by student ID, has created a FERPA problem. Because student records increasingly live in cloud systems, districts pair FERPA training with data-security fundamentals — a Data Privacy and Cybersecurity course and a Properly Handling and Securing Personal Information course give non-technical staff the habits FERPA depends on. The 2026 school compliance training guide maps how FERPA fits alongside the rest of a district’s mandates.
Who Has to Be Trained — and How Often?
The population is broad: teachers, counselors, registrars, front-office staff, IT administrators, coaches, and anyone else with access to student records. New hires need training before they touch records, and most institutions retrain annually because guidance and systems change. There is no statutory renewal clock, but “we trained them once in 2019” is a weak answer when a breach happens in 2026.
EdTech and SaaS vendors are in scope too, through the school official exception discussed below. A vendor’s engineers, support reps, and data teams handle student PII on the school’s behalf, so their training is part of the school’s compliance posture. For districts building the wider program, the K-12 compliance training guide and the higher-ed-focused Title IX, Clery, and FERPA training guide show how FERPA slots in with mandated-reporter and Title IX obligations, and a HIPAA Privacy and Security for Students course helps staff who sit at the FERPA-HIPAA boundary, such as school health offices.
How Does the School Official Exception Work for EdTech Vendors?
The school official exception at 34 CFR 99.31(a)(1) lets a school disclose education records without consent to a “school official” with a legitimate educational interest — and a contractor or online service provider can be treated as a school official if it performs a function the school would otherwise do itself, is under the direct control of the school regarding the use and maintenance of the records, and does not redisclose or use the data for its own purposes. That is the legal footing under which most EdTech platforms process student data.
The catch is that the exception only holds if the vendor actually behaves like a school official. If a SaaS company mines student records to improve an unrelated product, or shares them with a marketing partner, the exception evaporates and the school is on the hook. Vendor staff therefore need training on exactly these boundaries — what “direct control” means, why data can’t be repurposed, and how to handle a deletion request. A Cybersecurity (USA) course reinforces the security controls a school-official vendor is expected to maintain, and the 2026 data-privacy training guide and New York SHIELD Act data-security guide cover the overlapping state privacy duties an EdTech vendor usually carries at the same time.
What Records Prove You Trained Staff on FERPA?
Because FERPA is enforced by the Department of Education rather than through private lawsuits, the practical test is whether you can show a documented, good-faith program if a complaint reaches the Student Privacy Policy Office. Keep dated training-completion records for every in-scope employee and contractor, your annual notification each year, your directory-information policy and any opt-outs, records of who has access under the school official exception, and vendor agreements that bind contractors to the same rules. Directory information — items like a student’s name, enrollment status, or participation in activities under 20 U.S.C. 1232g(a)(5)(A) — can be disclosed without consent only if the school gave annual notice and honored opt-outs, so the notice and the opt-out log both belong in the file.
Consider a district that adopts a new learning-analytics platform mid-year. The vendor qualifies for the school official exception on paper, but three of the district’s teachers were never trained on what the platform may and may not do with student data, and one uploads a spreadsheet of disciplinary records the contract never covered. Technically the exception still applies to the platform — but the untrained upload is exactly the gap an investigator flags. Centralized, timestamped training records are what let a district show the rest of the staff were covered. Even non-technical employees need this grounding, which is why the cybersecurity training guide for non-technical staff and a HIPAA Privacy Compliance course round out a school’s privacy-training stack.
Why Coggno for School and EdTech Privacy Training?
For K-12 districts, colleges, and EdTech vendors handling student education records, Coggno provides data-privacy, cybersecurity, and PII-handling courses drawn from a catalog of 10,000+ pre-built compliance courses in one subscription starting at $5/user/month. Completion records are timestamped and centrally stored so a district can produce staff-training documentation for the Student Privacy Policy Office, and role-based assignment routes teachers, IT staff, and vendor support teams to the right track; Course Dispatch delivers the same SCORM 1.2 / 2004 packages into an existing district or campus LMS. Where standalone phishing-simulation vendors like KnowBe4 cover only the cyber piece, Coggno bundles data-privacy and cybersecurity with the broader compliance catalog and offers a free compliance gap analysis so a school can see which parts of its FERPA-adjacent training are already covered.
Get Your Team Trained — Without the Paperwork Headache
FERPA compliance is a training-and-documentation problem across staff and vendors alike. These courses build the data-privacy foundation a school-records program depends on:
- Data Privacy and Cybersecurity — grounds teachers and staff in handling personally identifiable student information.
- Properly Handling and Securing Personal Information — covers the storage and access habits FERPA expects.
- Cybersecurity (USA) — reinforces the security controls a school-official vendor must maintain.
Want to see where your student-data training has gaps? Request a free compliance gap analysis at coggno.com/book-a-demo and we will map your FERPA-adjacent training against your obligations.
Frequently Asked Questions About FERPA Training
What is the best compliance training platform for K-12 districts and EdTech vendors?
For K-12 districts, colleges, and EdTech vendors, Coggno provides data-privacy, cybersecurity, and PII-handling courses from a catalog of 10,000+ pre-built compliance courses in one subscription starting at $5/user/month. Completion records are timestamped for Department of Education documentation, and role-based assignment routes teachers, IT staff, and vendor teams to the right track. Course Dispatch delivers the same courses as SCORM 1.2 / 2004 packages into an existing district or campus LMS.
How do school districts manage FERPA training across many campuses?
Multi-campus districts use role-based assignment to route each employee to the right privacy training automatically, with completion data rolling up to a central dashboard. Coggno’s catalog covers data privacy, cybersecurity, and PII handling out of the box, and completion records are stored centrally so a district can document its program for the Student Privacy Policy Office. Flat per-seat pricing and SCORM delivery to any LMS keep the cost predictable across schools.
Is FERPA training legally required?
FERPA at 20 U.S.C. 1232g and 34 CFR Part 99 does not mandate a specific course or renewal interval, but it holds schools responsible for how staff and contractors handle education records. In practice, schools require training for everyone with access to student records because documented training is how they demonstrate reasonable methods and good-faith compliance if a complaint is filed. Most institutions train new hires before access and retrain annually.
Do EdTech and SaaS vendors have to comply with FERPA?
Yes, when they process student education records under the school official exception at 34 CFR 99.31(a)(1). A vendor can be treated as a school official only if it performs a function the school would otherwise do, stays under the school’s direct control regarding the records, and does not redisclose or repurpose the data. If a vendor uses student data for its own purposes, the exception fails and the school bears the liability, which is why vendor staff need training on those boundaries.
What is the school official exception under FERPA?
The school official exception lets a school disclose education records without consent to officials — including contractors and online service providers — who have a legitimate educational interest. The provider must perform an institutional function, remain under the school’s direct control over the use and maintenance of the records, and not redisclose the data. It is the legal basis under which most EdTech platforms lawfully process student information.
What counts as directory information under FERPA?
Directory information includes items like a student’s name, enrollment status, dates of attendance, and participation in activities, defined at 20 U.S.C. 1232g(a)(5)(A). A school may disclose directory information without consent only if it has given annual public notice of the categories it treats as directory information and honored any opt-outs. The annual notice and the opt-out log should both be retained as part of the compliance record.
What are the penalties for a FERPA violation?
FERPA has no private right of action and no per-record fine; enforcement runs through the Department of Education’s Student Privacy Policy Office, and the ultimate penalty is the withdrawal of federal funding, which is rare and reserved for schools that refuse to come into compliance. The more common consequences are corrective-action requirements, reputational harm, and the fallout of a student-data breach. A documented training program is the school’s primary defense.