Plain Answers · Education
Is ChatGPT FERPA compliant?
The tool isn't the unit. The arrangement is.
No AI tool is "FERPA compliant" as a product. Student-privacy rules generally attach to schools and their arrangements with vendors, not to a piece of software, so what matters is the arrangement: the contract, the control the school keeps over student records, and what the vendor may do with them. A teacher clicking "I agree" on a personal account isn't that arrangement.
Rules that may apply to you
Depending on what you do and who you serve, you may be subject to rules such as the ones below. We link the official sources and leave the interpretation to your district's counsel or privacy officer. This is a starting point, not a complete list, and nothing on this page says what these rules require of you.
- U.S. Department of Education — FERPA (34 CFR Part 99)(opens in new tab)
- U.S. Department of Education — Who is a "school official" under FERPA?(opens in new tab)
- U.S. Department of Education — Protecting Student Privacy While Using Online Educational Services(opens in new tab)
- California Education Code section 49073.1(opens in new tab)
- California K–12 Pupil Online Personal Information Protection Act — Business and Professions Code section 22584(opens in new tab)
Why the answer depends on the contract
Schools that receive federal education funding may be subject to FERPA, and the U.S. Department of Education publishes plain-language guidance on when outside vendors can handle student records. Both are linked above. Read the Department's discussion of "school officials" with your counsel; it's short.
Our non-lawyer reading of the practical upshot: a district needs an actual agreement with the vendor, and real control over what the vendor does with student records. Whether a particular agreement delivers that is for your counsel to judge. It's hard to see how a district would show it with no agreement at all.
The click-through problem
The Department has also published guidance on online educational services, linked above. It predates generative AI, and it's still worth reading for how it treats click-through terms of service. The situation it was written for is the one teachers are in today: a capable free tool, one click away, under terms nobody at the district has read.
California's two extra checkpoints
California districts may also be subject to Education Code section 49073.1, which concerns contracts for digital pupil-record services, and to the state's K–12 pupil online privacy statute, often still called SOPIPA. Both are linked above.
Two practical suggestions, neither of them legal advice. First, bring that Education Code section to every AI vendor conversation and go through it with counsel as a checklist. Second, don't assume a general-purpose chatbot carries the same protections as a product built for schools. Ask the vendor which one they consider themselves to be, and ask your counsel whether they agree.
What to ask an AI vendor
- Will you sign our district's data privacy agreement — or only offer your own terms?
- Do you consider yourselves an operator under California's pupil privacy statute? Get the answer in writing.
- Is student data used to train or improve your models?
- What is retained, for how long, and how do we get it deleted when a student leaves or the contract ends?
- Can your staff or subcontractors view student content?
- Does the product treat staff accounts and student accounts differently? Age matters to many vendors' own terms.
- Can the terms change without our signature?
A rule staff can remember
Most of the risk isn't a district-wide rollout. It's one overworked teacher pasting an IEP summary into a personal account to get help with wording. Give staff three bins: lesson planning and public material — any approved tool; anything describing an identifiable student — only the tool the district has contracted for; when unsure — ask first. Removing a name isn't always enough. A detailed description of one student in a class of twenty-four identifies them.
What we check when we deploy for a school
- Student records stay on district hardware. The model runs on a server the district owns, behind the district's firewall, with no outbound path. We test it unplugged.
- Sign-in through the district's own directory, so access follows the roles you already maintain and ends when employment does.
- Staff-facing first. We'd start with staff use — policy lookup, drafting, document processing — before anything a student touches.
- Logs the district controls, with retention set by your records policy.
- Our own agreement. We don't knowingly process student education records without an explicit agreement and appropriate controls in place.
An in-house server isn't free — $1,500 to $7,500 for a single-GPU system, more for district-wide concurrency — but it's a capital purchase rather than a per-student subscription. It doesn't replace board policy, staff training, or parent communication. For the general version of this question, see Is ChatGPT safe for business documents?