Back to Resources
COMPLIANCE

FERPA Compliance Guide for K-12 Schools

How to protect student privacy when using web filtering and safety monitoring tools.

10 min read

What is FERPA?

The Family Educational Rights and Privacy Act (FERPA) is a federal law enacted in 1974 that protects the privacy of student education records. It gives parents certain rights with respect to their children's education records, and these rights transfer to the student when they reach age 18.

FERPA applies to all educational agencies and institutions that receive funding under any applicable program of the U.S. Department of Education — which includes virtually every public school district in the country.

Why It Matters for Web Filtering

When web filtering tools collect per-student browsing data, safety alerts, or behavioral analytics, this data can constitute "education records" under FERPA. Schools must ensure their filtering vendor handles this data with proper privacy safeguards.

What FERPA Protects

FERPA protects "education records" — any records that are directly related to a student and maintained by an educational agency or institution. This includes:

Student names and contact information

Student ID numbers and device identifiers

Grades, transcripts, and academic records

Disciplinary records and behavioral data

Browsing activity logs linked to students

Safety monitoring alerts (self-harm, bullying)

Special education records (IEPs)

Biometric data and photographs

Parent Rights Under FERPA

Right to Inspect

Parents can inspect and review their child's education records within 45 days of a request.

Right to Amend

Parents can request correction of records they believe are inaccurate or misleading.

Right to Consent

Schools must obtain written consent before disclosing PII from education records (with exceptions).

Right to File Complaints

Parents can file complaints with the U.S. Department of Education if they believe FERPA was violated.

FERPA Exceptions for Web Filtering Vendors

Schools can share student data with web filtering vendors without parental consent under the "school official" exception (34 CFR § 99.31(a)(1)). This requires:

1

The vendor performs a service that would otherwise be done by school employees

2

The vendor is under the school's direct control regarding use of education records

3

The vendor uses the data only for the purpose for which the disclosure was made

4

The vendor meets the criteria for a 'school official' in the school's annual FERPA notification

5

The vendor does not re-disclose PII without authorization

Best Practice

Include web filtering vendors in your district's annual FERPA notification as "school officials with legitimate educational interests." This ensures transparency and compliance.

How KyberGate Ensures FERPA Compliance

Encryption at Rest & Transit

All student data encrypted with AES-256 at rest and TLS 1.3 in transit. No plaintext student data anywhere.

Organization-Scoped Data

Each school's data is completely isolated. No cross-organization data access is possible.

Role-Based Access Control

Admins, teachers, and counselors see only what they need. Principals see more than teachers. Parents see only their child.

No Data Sales or Advertising

We never sell, share, or use student data for advertising, marketing, or any purpose beyond the school's authorized use.

Data Retention Controls

Schools control their data retention period. All data is permanently deleted within 30 days of contract termination.

Audit Trail

Every access to student data is logged. Schools can audit who viewed what, when, for compliance documentation.

Parent Portal

Built-in parent access to their child's safety data, fulfilling the 'right to inspect' requirement transparently.

DPA Ready

We sign Data Processing Agreements (DPAs) and are listed on the Student Data Privacy Consortium registry.

FERPA Compliance Checklist

Frequently Asked Questions

What is FERPA?

The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of student education records. It applies to all schools that receive funding from the U.S. Department of Education, which includes virtually every public K-12 school in the United States.

Does FERPA apply to web filtering and monitoring?

Yes. Browsing activity logs, safety alerts, and behavioral data collected by web filtering tools can constitute education records under FERPA if they are maintained by the school and directly related to a student. Schools must ensure their web filtering vendor handles this data appropriately.

What is considered PII under FERPA?

Personally Identifiable Information (PII) under FERPA includes student names, addresses, Social Security numbers, student ID numbers, biometric records, and any information that could be used to identify a student — including device identifiers linked to specific students.

Can schools share student data with web filtering vendors?

Yes, under the 'school official' exception. FERPA allows schools to share student data with contractors and vendors who perform services that would otherwise be performed by school employees, as long as the vendor is under the school's direct control and uses the data only for authorized purposes.

Do parents have the right to see their child's web filtering data?

Yes. Under FERPA, parents have the right to inspect and review their child's education records. If your web filtering tool maintains per-student browsing logs, parents can request to see them. KyberGate's Parent Portal provides controlled access to this data.

Is KyberGate FERPA compliant?

Yes. KyberGate is fully FERPA compliant. All student data is encrypted at rest (AES-256) and in transit (TLS 1.3). Data is scoped to individual organizations, access is role-based, and we never sell, share, or use student data for advertising. We act as a 'school official' under your district's direct control.

What happens to student data when a school cancels KyberGate?

Upon cancellation, all student data is permanently deleted within 30 days. Schools can request an export of their data before cancellation. We do not retain student data beyond the contractual period.

FERPA-compliant web filtering, out of the box

KyberGate handles student data the right way. Encrypted, scoped, and never sold.

Chat with KyberGate

We typically respond within a few hours

👋 Hi! Have questions about KyberGate for your school? Drop us a message and we'll get back to you.