FERPA and the "legitimate educational interest" standard

FERPA generally restricts disclosure of a student's education records to school officials with a legitimate educational interest in the information. In a 1:1 device or classroom-app context, this standard matters because many educational apps and platforms are, functionally, receiving and storing student information on the district's behalf, which means the district (and often, individual staff who set up the tool) needs to have confirmed the platform's data practices align with FERPA before students start using it broadly.

This is why many districts require a formal vetting or approval process before a teacher rolls out a new app or website to a class, rather than allowing any staff member to sign students up for any tool independently. If your district has such a process and you skip it because a tool seems obviously fine, you may be creating a compliance gap even with good intentions.

COPPA and the under-13 age threshold

COPPA requires operators of commercial websites and online services directed at children under 13 to obtain verifiable parental consent before collecting personal information from those children, with a specific exception that allows a school to provide consent on parents' behalf for tools used strictly for an educational purpose within the school context — but that school-consent exception has real limits and does not cover every possible use of a platform.

In practice, this means a tool that is genuinely appropriate and properly vetted for classroom use under the school-consent exception may not be appropriate for the same students to use for non-educational or open-ended purposes, and staff should not assume that because a platform is approved for one specific instructional use, it is broadly approved for any use a student or teacher might come up with.

Advertisement

What day-to-day responsibility looks like for a classroom teacher or staff member

In practice, staff-level responsibility usually includes only using apps and platforms that have gone through your district's approval process, not entering more student information into a tool than the specific lesson or activity actually requires, and being cautious about what you post or upload publicly (to a class website, a social media account, or a shared platform) that includes identifiable student information or images.

If a parent or guardian asks what data a specific tool collects about their child or requests that their child's data be limited or removed, direct that request to your district's designated privacy or data officer rather than trying to resolve it yourself at the classroom level, since the correct response often depends on specifics of the platform's agreement with the district that an individual teacher would not have visibility into.

Before rolling out a new app or tool to a class

  1. Confirm it has gone through your district's app or platform approval process.
  2. Enter only the student information the specific lesson or activity actually requires.
  3. Check whether the tool is approved for the specific use you're planning, not just approved in general.
  4. Route any parent question about student data to your district's privacy or data officer.
  5. Keep your own running list of apps and platforms used with students during the year.

Building an inventory habit, even informally

Keep your own running list of which apps, websites, and platforms you actually use with students during the year, even if your district does not formally require it, since this makes it much easier to answer a parent's question, respond to a data-privacy audit, or simply remember what needs a district data-privacy agreement renewed before the following year.

If you are ever unsure whether a specific tool has been through your district's approval process, ask before using it with an entire class rather than assuming it is fine because you have seen a colleague use something similar — different tools, even ones that look alike, can have very different data practices behind them.

What happens when a device is lost, stolen, or a student leaves the district

A lost or stolen 1:1 device is both a hardware problem and a potential data-security concern if the device had cached student information, saved passwords, or ongoing access to accounts. Report a lost or stolen device to your district's IT department immediately, since many districts can remotely lock, wipe, or track a device, and delaying the report reduces the chance any of those measures still work.

When a student leaves the district, transfers schools, or graduates, ask what your district's policy is for that student's data across the platforms and apps used during the year — some information has a specific required retention or deletion timeline under FERPA or a district's own data-governance policy, and this is generally handled at the district level rather than something an individual teacher needs to manage manually, but knowing the general policy helps you answer a parent's question accurately if asked.

None of this is meant to make staff afraid to use technology in the classroom. The point of following your district's approval process is that someone with visibility into a platform's actual data practices and contract terms has already done the evaluation, so you do not have to personally assess a vendor's privacy policy every time you want to use a new tool.

Sources used for this guide

Rules can change. Use these sources as a starting point and confirm any state, district, student-plan, employment, licensing, or retirement requirement with the agency or team that governs your situation.

Questions school staff ask about this situation

Is protecting student data only IT's job, not the classroom teacher's?

No. FERPA's "legitimate educational interest" standard and COPPA's parental-consent framework place real responsibilities on the staff member choosing and using a tool with students, not only on the district's IT department.

Does a school need parental consent for every app that collects student data?

COPPA includes an exception allowing a school to consent on parents' behalf for tools used strictly for an educational purpose, but that exception has real limits and does not cover every possible use of a platform.

What should I do if a parent asks what data an app collects about their child?

Direct the request to your district's designated privacy or data officer rather than trying to answer it yourself, since the correct response often depends on the platform's specific agreement with the district.

Can I use any classroom app I find as long as it seems appropriate?

Most districts require a formal vetting or approval process before a new app or platform is used broadly with students — using an unapproved tool, even with good intentions, can create a compliance gap.

Does approval for one use of a tool mean it's approved for every use?

No. A tool approved for one specific instructional purpose under the school-consent exception may not be appropriate for open-ended or non-educational use by the same students.