FERPA
Family Educational Rights and Privacy Act
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Access
| Code | Title |
|---|---|
| 34 CFR 99.10 | Right to inspect and review education records |
| 34 CFR 99.11 | Fees for copies of records |
| 34 CFR 99.12 | Limitations on right to inspect and review |
Amendment
| Code | Title |
|---|---|
| 34 CFR 99.20 | Procedure to request amendment of records |
| 34 CFR 99.21 | Right to a hearing |
| 34 CFR 99.22 | Minimum requirements for a hearing |
Annual Notice
| Code | Title |
|---|---|
| 34 CFR 99.7 | Annual notification of rights |
Audit and Evaluation Exception
| Code | Title |
|---|---|
| 34 CFR 99.31(a)(3) and 99.35 | Authorized representatives for audit and evaluation |
Definitions
| Code | Title |
|---|---|
| 34 CFR 99.3 | Definitions (education records, PII, directory information, eligible student) |
| 34 CFR 99.39 | Disciplinary proceedings as education records |
Directory Information
| Code | Title |
|---|---|
| 34 CFR 99.31(a)(11) and 99.37 | Directory information |
Disclosure Restrictions
| Code | Title |
|---|---|
| 34 CFR 99.30 | Prior consent required for disclosure |
| 34 CFR 99.31(a)(13) and (14) | Disclosures related to sex offenses and crimes of violence |
| 34 CFR 99.31(a)(15) | Disclosure to parents regarding alcohol and drug violations |
| 34 CFR 99.31(a)(2) | Disclosure to other educational institutions |
| 34 CFR 99.31(a)(4) | Financial aid disclosures |
| 34 CFR 99.31(a)(7) | Accrediting organizations |
| 34 CFR 99.31(a)(8) | Disclosure to parents of dependent students |
| 34 CFR 99.31(b) | De identified data disclosure |
| 34 CFR 99.34 | Conditions for disclosure to other educational agencies |
| 34 CFR 99.38 | Disclosure to State and local officials under State statute |
Enforcement
| Code | Title |
|---|---|
| 34 CFR 99.60 - 99.63 | Enforcement and complaint procedures |
| 34 CFR 99.64 - 99.66 | Investigation, voluntary compliance, and enforcement actions |
FERPA: Accountability & Compliance
Demonstration of compliance and accountability (FERPA)
| Code | Title |
|---|---|
| FERPA-25 | Compliance monitoring and auditing |
| FERPA-26 | Training and awareness programs |
| FERPA-27 | Regulatory reporting and cooperation |
| FERPA-28 | Complaints handling and resolution |
| FERPA-29 | Enforcement and penalties awareness |
FERPA: Data Collection & Consent
Requirements for lawful collection and consent management (FERPA)
| Code | Title |
|---|---|
| FERPA-01 | Notice and transparency requirements |
| FERPA-02 | Consent management and withdrawal |
| FERPA-03 | Lawful basis for processing |
| FERPA-04 | Purpose limitation and specification |
| FERPA-05 | Data minimization requirements |
FERPA: Data Governance
Organizational governance of personal data processing (FERPA)
| Code | Title |
|---|---|
| FERPA-19 | Data protection officer designation |
| FERPA-20 | Records of processing activities |
| FERPA-21 | Data protection impact assessments |
| FERPA-22 | Privacy by design and default |
| FERPA-23 | Data processing agreements |
| FERPA-24 | Cross-border transfer safeguards |
FERPA: Data Security
Technical and organizational security measures (FERPA)
| Code | Title |
|---|---|
| FERPA-13 | Encryption of personal data |
| FERPA-14 | Pseudonymization techniques |
| FERPA-15 | Access control for personal data |
| FERPA-16 | Data breach notification requirements |
| FERPA-17 | Security incident response procedures |
| FERPA-18 | Regular security testing and assessment |
FERPA: Data Subject Rights
Individual rights regarding their personal data (FERPA)
| Code | Title |
|---|---|
| FERPA-06 | Right of access to personal data |
| FERPA-07 | Right to rectification of inaccurate data |
| FERPA-08 | Right to erasure and deletion |
| FERPA-09 | Right to data portability |
| FERPA-10 | Right to restrict processing |
| FERPA-11 | Right to object to processing |
| FERPA-12 | Automated decision-making protections |
Health and Safety Emergency
| Code | Title |
|---|---|
| 34 CFR 99.31(a)(10) and 99.36 | Health or safety emergency |
Judicial Disclosure
| Code | Title |
|---|---|
| 34 CFR 99.31(a)(9) and 99.31(a)(9)(ii) | Compliance with judicial order or subpoena |
Recordkeeping
| Code | Title |
|---|---|
| 34 CFR 99.32 | Record of disclosures |
Redisclosure
| Code | Title |
|---|---|
| 34 CFR 99.33 | Limitations on redisclosure |
Rights Transfer
| Code | Title |
|---|---|
| 34 CFR 99.4 | Rights of parents and eligible students |
| 34 CFR 99.5 | Rights of postsecondary students |
Safeguards
| Code | Title |
|---|---|
| 34 CFR 99.31(a)(6)(iii)(D) and PTAC Best Practices | Data security safeguards for PII in education records |
School Officials Exception
| Code | Title |
|---|---|
| 34 CFR 99.31(a)(1) School Officials | School officials with legitimate educational interest |
Scope Exclusions
| Code | Title |
|---|---|
| 34 CFR 99.8 | Law enforcement unit records |
Scope and Applicability
| Code | Title |
|---|---|
| 34 CFR 99.1 | Applicability of FERPA |
Studies Exception
| Code | Title |
|---|---|
| 34 CFR 99.31(a)(6) | Studies conducted for or on behalf of the institution |
Training
| Code | Title |
|---|---|
| 34 CFR 99.7 and PTAC Training Guidance | Workforce training and awareness |
Your Compliance Coverage
If you comply with FERPA, you already cover:
COPPA
22%
14 controls mapped
Compare →CCPA/CPRA
22%
14 controls mapped
Compare →Privacy Act 1988 (Australia)
22%
14 controls mapped
Compare →+ 606 more: CTDPA (Connecticut Data Privacy Act) (22%), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (22%)
See all 609 mapped frameworks ↓Maps to 609 other frameworks
Frequently Asked Questions
What is FERPA?
FERPA is a compliance framework from United States with 24 domains and 64 controls. Family Educational Rights and Privacy Act It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does FERPA have?
FERPA has 64 controls organised across 24 domains. The largest domains are Disclosure Restrictions (10 controls), FERPA: Data Subject Rights (7 controls), FERPA: Data Governance (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does FERPA map to?
FERPA maps to 609 other compliance frameworks. The top mapping partners are COPPA (22% coverage), CCPA/CPRA (22% coverage), Privacy Act 1988 (Australia) (22% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with FERPA compliance?
Start your FERPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FERPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 64 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required