Back to Frameworks

Family Educational Rights and Privacy Act (FERPA)

United States
v2023
7 domains
15 controls

FERPA is the Family Educational Rights and Privacy Act of 1974 (20 USC 1232g) implemented by 34 CFR Part 99 + administered by the US Department of Education Student Privacy Policy Office (SPPO) + Privacy Technical Assistance Center (PTAC). FERPA protects the privacy of student education records held by educational agencies + institutions receiving funds from any program administered by the Secretary of Education + applies to virtually all US K-12 + postsecondary educational institutions. FERPA confers four core rights on parents (transferred to eligible students at age 18 or upon postsecondary enrollment): (a) the right to INSPECT AND REVIEW education records; (b) the right to REQUEST AMENDMENT of records believed to be inaccurate or misleading; (c) the right to CONSENT to disclosures of personally identifiable information (PII) from education records subject to specified exceptions; (d) the right to FILE A COMPLAINT with the Department of Education for FERPA violations. Educational institutions must provide ANNUAL NOTIFICATION of these rights + the criteria for designating school officials with legitimate educational interest. Disclosures without consent are limited to specific exceptions: school officials + other educational institutions for enrolment + financial aid + accrediting organizations + parents of dependent students + court orders + health/safety emergencies + studies for or on behalf of the institution + audit + evaluation by authorised representatives + directory information after public notice. DIRECTORY INFORMATION (typically name + address + phone + email + photograph + dates of attendance + grade level + sport participation + degrees + honors) may be disclosed without consent if the institution provides annual public notice + a reasonable opportunity to opt-out. DATA SECURITY SAFEGUARDS for PII in education records are required under the studies + audit + evaluation exceptions + the SPPO/PTAC Best Practices Guidance. ENFORCEMENT is by the SPPO (within DoE) + may result in loss of federal funding (the sole statutory remedy). FERPA is coordinated with the Children Online Privacy Protection Act (COPPA) + the Protection of Pupil Rights Amendment (PPRA) + state student privacy laws (SOPIPA + Connecticut + New York + California + ~20 other states). FERPA Final Rule revisions: 1988 + 1995 + 2008 + 2011 (audit + evaluation + studies exceptions clarified) + 2011 directory information + 2020 study by SPPO + ongoing 2024-2025 PTAC guidance updates on AI + cloud + edtech vendor agreements + data breach notification standards.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

FERPA: Annual Notification, Right to Inspect and Review (Subpart B)

2 controls
Controls in the FERPA: Annual Notification, Right to Inspect and Review (Subpart B) domain of Family Educational Rights and Privacy Act (FERPA)2 controls
CodeTitle
FERPA-Part99.10_11_12Right to Inspect and Review (34 CFR 99.10, 99.11, 99.12)
FERPA-Part99.7Annual Notification of Rights (34 CFR 99.7)

FERPA: Data Security Safeguards (PTAC Best Practices and SPPO Guidance)

1 controls
Controls in the FERPA: Data Security Safeguards (PTAC Best Practices and SPPO Guidance) domain of Family Educational Rights and Privacy Act (FERPA)1 controls
CodeTitle
FERPA-Safeguards-PTACData Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FERPA: Directory Information, Recordkeeping and Redisclosure (Subpart D)

2 controls
Controls in the FERPA: Directory Information, Recordkeeping and Redisclosure (Subpart D) domain of Family Educational Rights and Privacy Act (FERPA)2 controls
CodeTitle
FERPA-Part99.32-Recordkeeping-99.33-RedisclosureRecordkeeping of Disclosures + Limitations on Redisclosure (34 CFR 99.32, 99.33)
FERPA-Part99.37-DirectoryDirectory Information (34 CFR 99.31(a)(11), 99.37)

FERPA: Disclosure Restrictions, Consent and Exceptions (Subpart D)

4 controls
Controls in the FERPA: Disclosure Restrictions, Consent and Exceptions (Subpart D) domain of Family Educational Rights and Privacy Act (FERPA)4 controls
CodeTitle
FERPA-99.31a1-School-OfficialsSchool Officials with Legitimate Educational Interest (34 CFR 99.31(a)(1))
FERPA-99.31a3-Audit-99.31a6-StudiesAudit and Evaluation Exception + Studies Exception (34 CFR 99.31(a)(3), 99.31(a)(6), 99.35)
FERPA-99.31a9-Judicial-99.31a10-Emergency-99.31a13-14Judicial Disclosure + Health and Safety Emergency + Sex Offense Disclosures (34 CFR 99.31(a)(9), (10), (13), (14), 99.36)
FERPA-Part99.30_31Prior Consent Required for Disclosure + Exceptions (34 CFR 99.30, 99.31)

FERPA: Enforcement, Complaints and Coordination (Subpart E)

3 controls
Controls in the FERPA: Enforcement, Complaints and Coordination (Subpart E) domain of Family Educational Rights and Privacy Act (FERPA)3 controls
CodeTitle
FERPA-99.60-99.67-EnforcementEnforcement and Complaint Procedures (34 CFR 99.60 to 99.67)
FERPA-Coord-COPPA-PPRA-StateCoordination with COPPA, PPRA, State Student Privacy Laws and Sectoral Laws
FERPA-StatusFERPA Implementation Status, 2024-2025 Guidance and AI/Cloud Trends

FERPA: Right to Request Amendment + Hearing (Subpart C)

1 controls
Controls in the FERPA: Right to Request Amendment + Hearing (Subpart C) domain of Family Educational Rights and Privacy Act (FERPA)1 controls
CodeTitle
FERPA-Part99.20_21_22Right to Request Amendment + Hearing (34 CFR 99.20, 99.21, 99.22)

FERPA: Scope, Applicability, Definitions and Rights Transfer (Subpart A)

2 controls
Controls in the FERPA: Scope, Applicability, Definitions and Rights Transfer (Subpart A) domain of Family Educational Rights and Privacy Act (FERPA)2 controls
CodeTitle
FERPA-Part99.1_3Applicability and Definitions (34 CFR 99.1, 99.3)
FERPA-Part99.4_5Rights Transfer (34 CFR 99.4, 99.5)

Maps to 96 other frameworks

15 total controls
Ley Orgánica de Protección de Datos Personales (LOPDP)
8 source controls mapped|5 target controls covered
53%
Privacy Act 1988 (Australia)
8 source controls mapped|7 target controls covered
53%
Law No. 172-13 on the Protection of Personal Data
8 source controls mapped|5 target controls covered
53%
India DPDP Act
8 source controls mapped|5 target controls covered
53%
Bahrain PDPL
8 source controls mapped|13 target controls covered
53%
53%
Pakistan Personal Data Protection Bill 2023
6 source controls mapped|5 target controls covered
40%
Global Cross-Border Privacy Rules (Global CBPR) Forum
6 source controls mapped|2 target controls covered
40%
APPI
6 source controls mapped|11 target controls covered
40%
Barbados Data Protection Act 2019
6 source controls mapped|7 target controls covered
40%
Azure Security Benchmark
6 source controls mapped|7 target controls covered
40%
40%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
5 source controls mapped|3 target controls covered
33%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
5 source controls mapped|3 target controls covered
33%
Russia Federal Law on Personal Data (152-FZ)
5 source controls mapped|2 target controls covered
33%
Azerbaijan Law on Personal Data (2010)
5 source controls mapped|4 target controls covered
33%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
4 source controls mapped|2 target controls covered
27%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
4 source controls mapped|1 target controls covered
27%
India Account Aggregator Framework (RBI)
4 source controls mapped|2 target controls covered
27%
Florida Digital Bill of Rights (FDBR)
4 source controls mapped|2 target controls covered
27%
Armenia Law on Protection of Personal Data (2015)
4 source controls mapped|3 target controls covered
27%
Australian Privacy Principles (APPs)
4 source controls mapped|4 target controls covered
27%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
4 source controls mapped|6 target controls covered
27%
ISO/IEC 27400:2022
4 source controls mapped|7 target controls covered
27%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
4 source controls mapped|5 target controls covered
27%
Tennessee Information Protection Act (TIPA)
3 source controls mapped|3 target controls covered
20%
TEFCA - Trusted Exchange Framework and Common Agreement
3 source controls mapped|1 target controls covered
20%
South Korea PIPA
3 source controls mapped|2 target controls covered
20%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
3 source controls mapped|1 target controls covered
20%
ISO/IEC 29100:2024
3 source controls mapped|3 target controls covered
20%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
3 source controls mapped|4 target controls covered
20%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
3 source controls mapped|4 target controls covered
20%
ISO/IEC 38500:2024 - Governance of IT
3 source controls mapped|1 target controls covered
20%
ISO/IEC 29134:2023
3 source controls mapped|3 target controls covered
20%
ISO/IEC 27014:2020
3 source controls mapped|2 target controls covered
20%
COSO Internal Control - Integrated Framework (2013)
3 source controls mapped|2 target controls covered
20%
Illinois Biometric Information Privacy Act (BIPA)
3 source controls mapped|1 target controls covered
20%
ICH E6(R3) - Good Clinical Practice
3 source controls mapped|2 target controls covered
20%
AWS Well-Architected Security Pillar
3 source controls mapped|6 target controls covered
20%
Regulation on the European Health Data Space (EHDS)
2 source controls mapped|3 target controls covered
13%
OWASP DevSecOps Maturity Model (DSOMM)
2 source controls mapped|5 target controls covered
13%
Law on Personal Data Protection (Official Gazette No. 42/2020)
2 source controls mapped|1 target controls covered
13%
Georgia Law on Personal Data Protection (2012)
2 source controls mapped|1 target controls covered
13%
ASD Strategies to Mitigate Cyber Security Incidents
2 source controls mapped|4 target controls covered
13%
ISO/IEC 27011:2024
2 source controls mapped|6 target controls covered
13%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|5 target controls covered
13%
FedRAMP High
1 source controls mapped|1 target controls covered
7%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
7%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
7%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
7%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
7%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|3 target controls covered
7%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
7%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|1 target controls covered
7%
Singapore Cybersecurity Act 2018
1 source controls mapped|1 target controls covered
7%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|3 target controls covered
7%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|2 target controls covered
7%
OWASP Top 10:2025
1 source controls mapped|4 target controls covered
7%
OWASP ASVS
1 source controls mapped|4 target controls covered
7%
OWASP API Security Top 10 - 2023
1 source controls mapped|2 target controls covered
7%
MITRE D3FEND
1 source controls mapped|1 target controls covered
7%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
7%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
7%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|3 target controls covered
7%
API 1164
1 source controls mapped|7 target controls covered
7%
BSI IT-Grundschutz
1 source controls mapped|10 target controls covered
7%
APRA CPS 230 Operational Risk Management
1 source controls mapped|2 target controls covered
7%
APRA CPS 234
1 source controls mapped|5 target controls covered
7%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|2 target controls covered
7%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
7%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|2 target controls covered
7%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|3 target controls covered
7%
FBI CJIS Security Policy
1 source controls mapped|3 target controls covered
7%
ISO 19011
1 source controls mapped|2 target controls covered
7%
7%
ISO 31000:2018
1 source controls mapped|2 target controls covered
7%
ISO/IEC 27010:2015
1 source controls mapped|4 target controls covered
7%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|7 target controls covered
7%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
7%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
7%
ISO/IEC 30111:2019
1 source controls mapped|2 target controls covered
7%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
7%
ISO 27005
1 source controls mapped|1 target controls covered
7%
ISO 20000-1
1 source controls mapped|1 target controls covered
7%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|3 target controls covered
7%
ISO/IEC 27031:2011
1 source controls mapped|1 target controls covered
7%
NIST SP 800-171
1 source controls mapped|1 target controls covered
7%
ISO/IEC 29147:2018
1 source controls mapped|2 target controls covered
7%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|3 target controls covered
7%

Frequently Asked Questions

What is Family Educational Rights and Privacy Act (FERPA)?

Family Educational Rights and Privacy Act (FERPA) is a compliance framework from United States with 7 domains and 15 controls. FERPA is the Family Educational Rights and Privacy Act of 1974 (20 USC 1232g) implemented by 34 CFR Part 99 + administered by the US Department of Education Student Privacy Policy Office (SPPO) + Privacy Technical Assistance Center (PTAC). FERPA protects the privacy of student education records held by educational agencies + institutions receiving funds from any program administered by the Secretary of Education + applies to virtually all US K-12 + postsecondary educational institutions. FERPA confers four core rights on parents (transferred to eligible students at age 18 or upon postsecondary enrollment): (a) the right to INSPECT AND REVIEW education records; (b) the right to REQUEST AMENDMENT of records believed to be inaccurate or misleading; (c) the right to CONSENT to disclosures of personally identifiable information (PII) from education records subject to specified exceptions; (d) the right to FILE A COMPLAINT with the Department of Education for FERPA violations. Educational institutions must provide ANNUAL NOTIFICATION of these rights + the criteria for designating school officials with legitimate educational interest. Disclosures without consent are limited to specific exceptions: school officials + other educational institutions for enrolment + financial aid + accrediting organizations + parents of dependent students + court orders + health/safety emergencies + studies for or on behalf of the institution + audit + evaluation by authorised representatives + directory information after public notice. DIRECTORY INFORMATION (typically name + address + phone + email + photograph + dates of attendance + grade level + sport participation + degrees + honors) may be disclosed without consent if the institution provides annual public notice + a reasonable opportunity to opt-out. DATA SECURITY SAFEGUARDS for PII in education records are required under the studies + audit + evaluation exceptions + the SPPO/PTAC Best Practices Guidance. ENFORCEMENT is by the SPPO (within DoE) + may result in loss of federal funding (the sole statutory remedy). FERPA is coordinated with the Children Online Privacy Protection Act (COPPA) + the Protection of Pupil Rights Amendment (PPRA) + state student privacy laws (SOPIPA + Connecticut + New York + California + ~20 other states). FERPA Final Rule revisions: 1988 + 1995 + 2008 + 2011 (audit + evaluation + studies exceptions clarified) + 2011 directory information + 2020 study by SPPO + ongoing 2024-2025 PTAC guidance updates on AI + cloud + edtech vendor agreements + data breach notification standards. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Family Educational Rights and Privacy Act (FERPA) have?

Family Educational Rights and Privacy Act (FERPA) has 15 controls organised across 7 domains. The largest domains are FERPA: Disclosure Restrictions, Consent and Exceptions (Subpart D) (4 controls), FERPA: Enforcement, Complaints and Coordination (Subpart E) (3 controls), FERPA: Annual Notification, Right to Inspect and Review (Subpart B) (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Family Educational Rights and Privacy Act (FERPA) map to?

Family Educational Rights and Privacy Act (FERPA) maps to 96 other compliance frameworks. The top mapping partners are Ley Orgánica de Protección de Datos Personales (LOPDP) (53% coverage), Privacy Act 1988 (Australia) (53% coverage), Law No. 172-13 on the Protection of Personal Data (53% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Family Educational Rights and Privacy Act (FERPA) compliance?

Start your Family Educational Rights and Privacy Act (FERPA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Family Educational Rights and Privacy Act (FERPA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 15 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required