The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law, enacted in 1974, that protects the privacy of student education records. It gives parents — and students themselves once they turn 18 or enroll in postsecondary education — the right to inspect their education records, request corrections, and control most disclosures of personally identifiable information from those records. It is important to be clear up front: FERPA is a privacy law, not an accessibility law. It says nothing directly about screen readers, color contrast, or WCAG. But if your website, student portal, or edtech product touches education records, FERPA shapes how you must handle that data online, and accessibility becomes part of delivering FERPA rights in practice.
FERPA applies to educational agencies and institutions that receive funding from the U.S. Department of Education — which covers virtually all public K-12 schools and districts and the vast majority of colleges and universities, public and private. Vendors and edtech companies are not directly regulated by FERPA, but they inherit obligations by contract: when a school shares student data with a learning platform, grading tool, or portal provider under the "school official" exception, that provider must use the data only for the authorized purpose, keep it under the school's control, and protect it from unauthorized disclosure.
For website operators, the practical questions are: does my site or product collect, store, or display information from student education records? If so, who can see it, how is it secured, and can every parent and student — including those using assistive technology — actually exercise the rights FERPA gives them? This guide walks through the essentials in plain English.
Privacy law, not an accessibility statute
FERPA governs the confidentiality of student education records. It does not set accessibility standards, but accessible portals and notices are how its rights get delivered online.
Who is covered
Schools, districts, colleges, and universities that receive U.S. Department of Education funding — plus edtech vendors indirectly, through the contracts that give them access to student data.
Consent before disclosure
Personally identifiable information from education records generally cannot be shared without written consent, subject to specific exceptions such as directory information and school officials.
Enforcement by the Department of Education
FERPA is enforced administratively by the Student Privacy Policy Office. The ultimate sanction is loss of federal funding; there is no private right for individuals to sue under FERPA.
What FERPA is and why it exists
FERPA was passed in 1974 to give families control over school records at a time when those records were often shared freely with third parties. It establishes two core rights: the right to access and seek amendment of education records, and the right to consent before those records are disclosed to outsiders. "Education records" is defined broadly — grades, transcripts, class schedules, disciplinary records, health records held by the school, and any other records maintained by an institution that directly relate to a student.
These rights belong to parents for students under 18 in K-12, and transfer to the student (becoming an "eligible student") at age 18 or upon enrolling in a postsecondary institution. That transfer matters for website design: a university portal must be built around the student controlling their own data, while a K-12 portal typically needs parent-facing access as well.
Who must comply
FERPA directly binds educational agencies and institutions that receive funds under programs administered by the U.S. Department of Education. In practice that means nearly every public school district and almost all higher-education institutions, since federal student aid counts. Private K-12 schools that receive no federal education funding are generally not covered.
Edtech companies, hosting providers, and website vendors are not regulated by FERPA directly, but they are very much inside its orbit. Schools may share education records with a vendor without parental consent only if the vendor qualifies as a "school official" with a legitimate educational interest — which requires the school to keep direct control over the records and the vendor to use them only for the contracted purpose. If you sell software to schools, expect FERPA obligations to flow into your contracts, and expect districts to ask detailed questions about data handling, retention, and deletion.
Core requirements for websites and digital products
Translated to the web, FERPA's requirements cluster around a few themes. First, disclosure control: anything on a public-facing page is a disclosure to the world, so student names paired with grades, ID numbers, or disciplinary information must never appear on public sites without consent. Even "directory information" — things like names, photos, and honors that schools may publish — requires an annual notice and a chance for families to opt out.
Second, access control and security: student portals, learning management systems, and parent dashboards must reliably show each user only the records they are entitled to see. Authentication mistakes, predictable URLs that expose other students' records, or misconfigured permissions are classic FERPA failure modes online.
Third, transparency: institutions must annually notify parents and eligible students of their FERPA rights, and those notices increasingly live on the web — which means they need to be findable and readable by everyone.
- Never publish personally identifiable education-record data on public pages without consent
- Honor directory-information opt-outs across the website, newsletters, and social media
- Enforce strict per-user access controls in portals and learning platforms
- Provide a working online route for parents and students to request access to records
- Keep vendor contracts aligned with the school-official exception, including data-use limits and deletion
Enforcement and penalties
FERPA is enforced by the U.S. Department of Education's Student Privacy Policy Office, which investigates complaints and works with institutions to correct violations. The statute's ultimate penalty is withdrawal of federal funding, though in practice enforcement is overwhelmingly corrective rather than punitive — the Department seeks voluntary compliance first.
Notably, the Supreme Court held in 2002 that FERPA does not give individuals a private right to sue. That does not make violations low-stakes: schools face reputational damage, state-law privacy claims, and contractual fallout, and vendors that misuse student data can be barred from receiving education records from an institution — an existential problem for an edtech business.
Where accessibility fits in
FERPA never mentions accessibility, but the two obligations converge on the same institutions. Schools and universities covered by FERPA are almost always also covered by accessibility law: Section 504 of the Rehabilitation Act, the ADA, and — for federally funded programs — Section 508-style expectations. Under the Department of Justice's 2024 rule on ADA Title II, state and local government entities, including public schools and universities, must bring their web content and mobile apps into conformance with WCAG 2.1 AA, with compliance deadlines of April 2026 or April 2027 depending on population size.
That convergence has a practical meaning: the very interfaces FERPA cares about — student portals, grade views, records-request forms, annual privacy notices, directory-information opt-outs — must work for parents and students who use screen readers, keyboard navigation, captions, or magnification. A records-access right that only works for mouse users is a right some families cannot exercise. Building consent flows, login pages, and privacy notices to WCAG standards is therefore not just an ADA concern; it is how FERPA rights become real for everyone. Tools like AccessWiser can help identify and remediate accessibility barriers on these pages, though no automated tool alone guarantees legal compliance — accessible design and periodic expert review still matter.
Practical steps toward compliance
Whether you run a school website or build products for schools, a sensible FERPA program for your digital presence looks like this:
- Map where education-record data lives in your website, portal, and third-party tools
- Audit public pages for student information that should not be there, and honor opt-outs
- Publish the annual FERPA rights notice online in an accessible, easy-to-find format
- Lock down portal access controls and test that users cannot reach other students' records
- Review vendor agreements for school-official language, data-use limits, and deletion terms
- Test key flows — login, records requests, consent forms, opt-outs — with keyboard and screen reader
- Train staff who publish web content on what counts as an education record
Frequently asked questions
Does FERPA require my website to meet WCAG?
No — FERPA itself sets no accessibility standard. But the schools and universities FERPA covers are separately required to be accessible under Section 504 and the ADA, and public institutions face WCAG 2.1 AA deadlines under the 2024 ADA Title II rule. In practice, FERPA-related pages like portals and privacy notices need to be accessible to satisfy those laws and to make FERPA rights usable by everyone.
Is my edtech company directly covered by FERPA?
Not directly — FERPA binds funded educational institutions. But when schools share student data with you under the school-official exception, your contract will require you to use the data only for the authorized purpose, keep it under the school's control, and protect it. Violating those terms can get your company cut off from receiving education records.
Can we post student names, photos, or honor rolls on our public website?
Often yes, if the school has designated that information as directory information, given the required annual notice, and honored every opt-out. Never publish grades, ID numbers, or other non-directory record information publicly without written consent.
Can parents or students sue us for a FERPA violation?
There is no private lawsuit under FERPA itself — enforcement runs through the U.S. Department of Education, whose ultimate sanction is loss of federal funding. Violations can still trigger state privacy claims, contract disputes, and serious reputational harm, so the absence of private suits is not a reason to relax.
How does FERPA relate to COPPA?
They cover different things: FERPA protects education records held by funded schools, while COPPA regulates online services that collect personal information from children under 13. An edtech product used in elementary schools can easily be subject to both — COPPA directly, and FERPA through its school contracts.
This article is provided for general information about accessibility regulations and standards. It is not legal advice — consult a qualified professional about your specific compliance obligations.