Education

Your Biggest Data Risk Is a Vendor Your Teachers Signed Up For

School security is not a firewall problem. It is a vendor problem - dozens of ed-tech applications collecting student information, approved individually by teachers and departments, layered on infrastructure that was never designed for them.

And the compliance obligations do not stop at FERPA. If you handle federal financial aid, a rule most people associate with banks applies to you.

The operational reality

What Makes Education Different

Your student information system is a single point of institutional failure. PowerSchool, Infinite Campus, Blackbaud, FACTS/RenWeb in private and parochial schools; Ellucian Banner or Colleague and Workday Student in higher education. A compromise there is not an IT incident - it is every family you serve.

Federal financial aid makes an institution a financial institution. Federal Student Aid has communicated that Title IV participating institutions are subject to the GLBA Safeguards Rule, including a designated Qualified Individual, a written risk assessment, and an incident response plan (Federal Student Aid Knowledge Center). Colleges reliably discover this during a program review.

The endpoint fleet outnumbers the IT department by three orders of magnitude. One-to-one Chromebook programs with one or two IT staff is the norm, not the exception.

Compliance is owned by a business manager or a bursar. Not a technologist. They need the requirement translated into a decision, not a control matrix.

Security competes with instruction at the board table. Every dollar is visibly a dollar not spent on a classroom. That is a real constraint and it should shape how work is sequenced, not be treated as an objection.

Frameworks

Your Compliance Landscape

Applicability turns on federal funding, the ages of the students, and how you take money. Your counsel makes the determination.

Almost always applies

  • Applies to educational agencies and institutions receiving funds under applicable Department of Education programs, governing access to and disclosure of education records (FERPA at studentprivacy.ed.gov). Private schools that receive no such federal funds are generally outside it - which is exactly where the confusion lives, because state law may still reach them.
  • Governs online collection of personal information from children under thirteen, and it lands on the operator of the service (16 CFR Part 312). Schools regularly sit in the middle of consent for ed-tech tools - the FTC has published guidance for education technology at ftc.gov.
  • For Title IV institutions handling student financial aid information. The control set is the same one banks work from (16 CFR Part 314), including the named Qualified Individual.
  • The framework federal education guidance points institutions toward (NIST CSF).
  • Tuition, cafeteria accounts, athletics, and event payments (PCI SSC).

Applies in some cases

  • School-based clinics and college student health centers. Note that records qualifying as education records under FERPA are treated differently - HHS and ED have published joint guidance on the boundary.
  • School resource officer programs and safety data shared with law enforcement systems (CJIS Security Policy).
  • Request it from your SIS, LMS, and ed-tech vendors during procurement. You almost certainly do not need to hold one.
  • Larger systems and institutions with international recruiting or research partnerships.

The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.

Failure patterns

What Usually Goes Wrong

  • Ed-tech is adopted without a data agreement. A teacher signs up, student names and emails go in, and no one reviewed what the vendor does with them.
  • A vendor breach becomes your breach. When the SIS is compromised, the notification burden and the parent phone calls are yours, whatever the contract says.
  • Higher education misses GLBA entirely because "that is a banking rule," and the Qualified Individual requirement goes unassigned until a program review.
  • Private and parochial schools assume zero obligation because they take no federal funds, overlooking state student data statutes and their own contractual commitments.
  • Staff email has no multi-factor authentication, and a phished teacher account becomes a path into the SIS.
  • The one-to-one device fleet has no lifecycle, so devices leave with graduating students still enrolled in management.
  • Backups are never restore-tested until the semester a restore is needed.
  • Security lives in the technology budget rather than in risk governance, so it gets cut against instructional priorities without a documented decision.

Our services

How We Work With Education

  • Third-Party Assessments

    The ed-tech and SIS vendor review - data agreements, subprocessors, breach notification terms, and what happens to student data at contract end. This is where the actual risk lives.

  • Governance, Risk & Compliance (GRC)

    The written information security program, the risk assessment, and the incident response plan - including the Qualified Individual documentation Title IV institutions are asked for.

  • Cyber Risk Management

    Multi-factor for staff, endpoint and identity protection across a large managed fleet, and monitoring that a one-person IT department can actually operate.

  • Helpdesk Support

    Support at school-year scale, including the first two weeks of term when everything breaks at once.

  • Fractional CIO, CTO & CISO

    Security leadership your board and head of school can talk to, so the business manager is not making technical risk calls alone.

  • Digital Forensics & Incident Response

    Response when a student information system or a staff mailbox is compromised, including the notification analysis.

Questions people ask

Frequently Asked Questions

Is my private school required to comply with FERPA?
FERPA applies to educational agencies and institutions that receive funds under applicable US Department of Education programs. A private school receiving no such funds is generally outside FERPA - but that is not the same as having no obligations, because state student data laws and your own enrollment contracts may still apply. Start with the Student Privacy Policy Office material at studentprivacy.ed.gov.
Does FERPA apply to charter schools?
Charter schools are public schools and generally receive federal funding, which brings them within FERPA. Independence in governance does not change the funding analysis.
What is the difference between FERPA and COPPA?
FERPA governs education records held by funded institutions and gives rights to parents and eligible students. COPPA governs online collection of personal information from children under thirteen and applies to the operator of the online service. A single ed-tech app in a fourth grade classroom can implicate both.
Do we need parental consent for ed-tech apps under COPPA?
COPPA requires verifiable parental consent before collecting personal information from children under thirteen, and the FTC has published guidance on the limited circumstances in which a school may provide consent in the parent's place for educational purposes. The safe operational answer is a reviewed vendor list and a written consent process, not case-by-case teacher judgment.
Is Title IV financial aid data subject to GLBA?
Yes. Federal Student Aid has communicated that institutions participating in Title IV programs are subject to the GLBA Safeguards Rule, and program reviews have requested evidence of the required program elements. Materials are published at fsapartners.ed.gov.
What does the FTC Safeguards Rule mean for a college?
In practice: a designated Qualified Individual, a written risk assessment, access controls and multi-factor authentication, encryption, service provider oversight, an incident response plan, staff training, and periodic reporting to your governing body. The rule text is at 16 CFR Part 314.
Do I need a written information security plan for my school?
If you handle Title IV aid, yes, and the elements are specified. If you do not, a written plan is still what your cyber insurer, your board, and any state student data statute expect you to be able to produce.
Are Chromebooks a security risk in schools?
The device is not the risk. Unmanaged enrollment, absent update policy, shared accounts, and no offboarding process are. A properly managed fleet is one of the easier endpoint environments to secure; an unmanaged one is thousands of untracked doors.
Is our student information system vendor required to notify us of a breach?
That obligation comes from your contract and from applicable state breach law, not from FERPA itself. This is why the notification clause in the data agreement is worth reading before signature rather than after an incident.
Do we need multi-factor authentication for staff email at a small school?
A compromised staff mailbox is the most common route into the systems that hold student and family data, and it is also what your insurer will ask about. There is no small-school exemption from that reality.

Florida & the Treasure Coast

Education on the Treasure Coast

Florida maintains its own student records and privacy provisions in the K-20 education code, including Fla. Stat. §1002.22 on student records and rights and §1002.221 on the confidentiality of K-12 education records. Private schools that assume the absence of federal funding means the absence of obligation should have counsel read these against their own operations. Breach notification to Florida residents runs under §501.171 on a 30-day clock.

Locally, the mix across Martin, St. Lucie, and Palm Beach counties includes district schools, charter schools, independent and parochial K-12, and state colleges - four different regulatory postures within a twenty mile radius, frequently sharing the same ed-tech vendors and the same regional service providers.

[NEEDS: client proof for this vertical]