Family Educational Rights and Privacy Act (FERPA)
FERPA: Disclosure Restrictions, Consent and Exceptions (Subpart D)

Family Educational Rights and Privacy Act (FERPA) FERPA-99.31a1-School-Officials: School Officials with Legitimate Educational Interest (34 CFR 99.31(a)(1))

34 CFR 99.31(a)(1) school officials with legitimate educational interest. The most-used FERPA exception + the source of most institutional disclosure decisions. DEFINITION + REQUIREMENTS: a school official includes institutional employees + contractors + consultants + volunteers + or other parties (e.g. attorneys + auditors + collection agents + cloud + edtech vendors) performing institutional services or functions for which the institution would otherwise use its employees + provided that: (i) the party is under the DIRECT CONTROL of the institution with respect to the use + maintenance of PII (e.g. contract clauses + control of data + return + deletion at end of engagement); AND (ii) the party is subject to the same FERPA + confidentiality requirements as institutional employees + AND (iii) the party uses the PII only to perform the institutional function for which they are designated. LEGITIMATE EDUCATIONAL INTEREST means a need to access education records to fulfil a professional responsibility for the institution. ANNUAL NOTIFICATION must specify the criteria for designating school officials + the legitimate-educational-interest standard. The 2008 + 2011 amendments expanded contractor/vendor coverage + the SPPO/PTAC Best Practices Guidance details documentation + control requirements for cloud + edtech vendors.

What else in your programme already covers this

This control maps to 23 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Bahrain PDPL · 3 controls

  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

India DPDP Act · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in FERPA: Disclosure Restrictions, Consent and Exceptions (Subpart D)

Query this from an agent

The graph holds this control, the 23 it maps to, and the evidence behind each claim, over MCP and REST.