The operational reality

What Makes Education Different

Your student information system is a single point of institutional failure. PowerSchool, Infinite Campus, Blackbaud, FACTS/RenWeb in private and parochial schools; Ellucian Banner or Colleague and Workday Student in higher education. A compromise there is not an IT incident - it is every family you serve.

Federal financial aid makes an institution a financial institution. Federal Student Aid has communicated that Title IV participating institutions are subject to the GLBA Safeguards Rule, including a designated Qualified Individual, a written risk assessment, and an incident response plan (Federal Student Aid Knowledge Center). Colleges reliably discover this during a program review.

The endpoint fleet outnumbers the IT department by three orders of magnitude. One-to-one Chromebook programs with one or two IT staff is the norm, not the exception.

Compliance is owned by a business manager or a bursar. Not a technologist. They need the requirement translated into a decision, not a control matrix.

Security competes with instruction at the board table. Every dollar is visibly a dollar not spent on a classroom. That is a real constraint and it should shape how work is sequenced, not be treated as an objection.

Failure patterns

What Usually Goes Wrong

  • Ed-tech is adopted without a data agreement. A teacher signs up, student names and emails go in, and no one reviewed what the vendor does with them.
  • A vendor breach becomes your breach. When the SIS is compromised, the notification burden and the parent phone calls are yours, whatever the contract says.
  • Higher education misses GLBA entirely because "that is a banking rule," and the Qualified Individual requirement goes unassigned until a program review.
  • Private and parochial schools assume zero obligation because they take no federal funds, overlooking state student data statutes and their own contractual commitments.
  • Staff email has no multi-factor authentication, and a phished teacher account becomes a path into the SIS.
  • The one-to-one device fleet has no lifecycle, so devices leave with graduating students still enrolled in management.
  • Backups are never restore-tested until the semester a restore is needed.
  • Security lives in the technology budget rather than in risk governance, so it gets cut against instructional priorities without a documented decision.

Questions people ask

Frequently Asked Questions

Is my private school required to comply with FERPA?
FERPA applies to educational agencies and institutions that receive funds under applicable US Department of Education programs. A private school receiving no such funds is generally outside FERPA - but that is not the same as having no obligations, because state student data laws and your own enrollment contracts may still apply. Start with the Student Privacy Policy Office material at studentprivacy.ed.gov.
Does FERPA apply to charter schools?
Charter schools are public schools and generally receive federal funding, which brings them within FERPA. Independence in governance does not change the funding analysis.
What is the difference between FERPA and COPPA?
FERPA governs education records held by funded institutions and gives rights to parents and eligible students. COPPA governs online collection of personal information from children under thirteen and applies to the operator of the online service. A single ed-tech app in a fourth grade classroom can implicate both.
Do we need parental consent for ed-tech apps under COPPA?
COPPA requires verifiable parental consent before collecting personal information from children under thirteen, and the FTC has published guidance on the limited circumstances in which a school may provide consent in the parent's place for educational purposes. The safe operational answer is a reviewed vendor list and a written consent process, not case-by-case teacher judgment.
Is Title IV financial aid data subject to GLBA?
Yes. Federal Student Aid has communicated that institutions participating in Title IV programs are subject to the GLBA Safeguards Rule, and program reviews have requested evidence of the required program elements. Materials are published at fsapartners.ed.gov.
What does the FTC Safeguards Rule mean for a college?
In practice: a designated Qualified Individual, a written risk assessment, access controls and multi-factor authentication, encryption, service provider oversight, an incident response plan, staff training, and periodic reporting to your governing body. The rule text is at 16 CFR Part 314.
Do I need a written information security plan for my school?
If you handle Title IV aid, yes, and the elements are specified. If you do not, a written plan is still what your cyber insurer, your board, and any state student data statute expect you to be able to produce.
Are Chromebooks a security risk in schools?
The device is not the risk. Unmanaged enrollment, absent update policy, shared accounts, and no offboarding process are. A properly managed fleet is one of the easier endpoint environments to secure; an unmanaged one is thousands of untracked doors.
Is our student information system vendor required to notify us of a breach?
That obligation comes from your contract and from applicable state breach law, not from FERPA itself. This is why the notification clause in the data agreement is worth reading before signature rather than after an incident.
Do we need multi-factor authentication for staff email at a small school?
A compromised staff mailbox is the most common route into the systems that hold student and family data, and it is also what your insurer will ask about. There is no small-school exemption from that reality.