FERPA and COPPA: what AI use leaves in the audit record a school district reads.

For a district's technology lead, its student privacy officer, school counsel, the board and any edtech vendor holding student records, this page sets each FERPA and COPPA rule beside what a Verillian record shows when staff use AI on enrolled devices.

What the rules ask, section by section

What the rule asksA Verillian record showsIt does not show
'Education records' are 'those records that are: (1) Directly related to a student; and (2) Maintained by an educational agency or institution or by a party acting for the agency or institution.' 34 CFR 99.3One entry per captured request sent from an enrolled staff device, giving the provider's name, the ruling, and the clock time, and attributed to the user and device the checkpoint reports.Whether a prompt, or what came back, is an education record. That turns on a link to a particular student and on who maintains it, which your counsel decides.
'Personally identifiable information' 'includes, but is not limited to' '(a) The student's name; (b) The name of the student's parent or other family members; (c) The address of the student or student's family; (d) A personal identifier, such as the student's social security number, student number, or biometric record', and '(f) Other information that, alone or in combination, is linked or linkable to a specific student that would allow a reasonable person in the school community, who does not have personal knowledge of the relevant circumstances, to identify the student with reasonable certainty'. 34 CFR 99.3The values your policy flags in a prompt, replaced with a stand-in token on the device before the prompt leaves, and the entry that says so. Redaction is best effort.That a flagged value was a student's information, a value outside the fixed set the detectors catch, or an indirect identifier that needs context to link to a student.
'Disclosure means to permit access to or the release, transfer, or other communication of personally identifiable information contained in education records by any means, including oral, written, or electronic means, to any party except the party identified as the party that provided or created the record.' 34 CFR 99.3The provider each captured request was sent to, and when.Whether a given request was a disclosure under this definition. The record shows where a request went; what that makes it is for counsel to decide.
'The parent or eligible student shall provide a signed and dated written consent before an educational agency or institution discloses personally identifiable information from the student's education records, except as provided in § 99.31.' The consent 'must' 'Specify the records that may be disclosed', 'State the purpose of the disclosure', and 'Identify the party or class of parties to whom the disclosure may be made'. 34 CFR 99.30(a), (b)The provider and the clock time of each captured request.Any consent. Verillian does not collect it, store it or check for it, and a record cannot say whether consent exists or an exception applies.
'A contractor, consultant, volunteer, or other party to whom an agency or institution has outsourced institutional services or functions may be considered a school official under this paragraph provided that the outside party' '(1) Performs an institutional service or function for which the agency or institution would otherwise use employees; (2) Is under the direct control of the agency or institution with respect to the use and maintenance of education records; and (3) Is subject to the requirements of § 99.33(a) governing the use and redisclosure of personally identifiable information from education records.' 34 CFR 99.31(a)(1)(i)(B)The provider named on each captured request, so a reviewer can see which outside party a contract has to cover.Whether that party meets any of the three conditions. They turn on your contract and on the party's own practices, which sit outside a record of staff devices.
'An educational agency or institution must maintain a record of each request for access to and each disclosure of personally identifiable information from the education records of each student', kept 'with the education records of the student', and the record 'must include: (i) The parties who have requested or received personally identifiable information from the education records; and (ii) The legitimate interests the parties had in requesting or obtaining the information.' Paragraph (a) of that section 'does not apply if the request was from, or the disclosure was to' 'A school official under § 99.31(a)(1)'. 34 CFR 99.32(a)(1) to (3), (d)(2)The provider and the clock time on each captured request, attributed to the user and device the checkpoint reports.The record this section describes. A Verillian entry is not kept with a student's education records and holds no party's legitimate interest. The text speaks of requests for access and disclosures from a student's education records and mentions no software or AI tool.
'An educational agency or institution may disclose personally identifiable information from an education record only on the condition that the party to whom the information is disclosed will not disclose the information to any other party without the prior consent of the parent or eligible student.' The party's staff 'may use the information, but only for the purposes for which the disclosure was made.' 34 CFR 99.33(a)(1), (a)(2)The provider that received each captured request, by name.What that service did with the content afterward, or whom it passed it to. Those steps happen in the provider's systems.
'Child means an individual under the age of 13.' An 'Operator' is 'any person who operates a website located on the internet or an online service and who collects or maintains personal information from or about the users of or visitors to such website or online service', where it is operated for commercial purposes in the ways the definition lists. 16 CFR 312.2Nothing about age. Entries come from enrolled staff devices, so they reflect what staff sent to a governed provider.Whether anyone in a prompt is under 13, or whether your district, a vendor or neither is the operator of a tool. Counsel and the vendor settle that.
'It shall be unlawful for any operator of a website or online service directed to children, or any operator that has actual knowledge that it is collecting or maintaining personal information from a child, to collect personal information from a child in a manner that violates the regulations prescribed under this part.' An operator must 'Provide notice on the website or online service of what information it collects from children', and 'Obtain verifiable parental consent prior to any collection, use, and/or disclosure of personal information from children'. 16 CFR 312.3(a), (b); 312.5(a)(1)Nothing on notice or consent. Verillian is not a notice or consent tool, and it does not collect personal information from children.A notice, a parent's consent, or the method used to verify a parent. Those belong to the operator, and a record of staff devices holds none of them.
'The operator must establish, implement, and maintain a written information security program that contains safeguards that are appropriate to the sensitivity of the personal information collected from children', and before 'releasing children's personal information' to a third party 'must obtain written assurances that such entities will employ reasonable measures to maintain the confidentiality, security, and integrity of the information.' 16 CFR 312.8(b), (c)Content is encrypted under a key you control; even Verillian cannot read content. Each entry names the provider that received the request.An operator's security program, its assessments, or its written assurances. A vendor's own safeguards are the vendor's to document.
'An operator of a website or online service shall retain personal information collected online from a child for only as long as is reasonably necessary to fulfill the specific purpose(s) for which the information was collected.' The operator 'must establish, implement, and maintain a written data retention policy'. 16 CFR 312.10The time on each entry, and the records themselves, held on your own infrastructure.How long a vendor keeps what it received, or whether it deleted it. Your contract with the vendor is the lever.
LimitsCaptured requests only, from enrolled staff devices to a provider your signed policy names. Redaction is best effort, and screening has been verified for the Claude API format only. A provider the signed policy leaves out is not governed.Completeness, student-facing tools, or anything inside an edtech vendor's own cloud. Verillian is not a FERPA or COPPA compliance product. It does not decide what is an education record or who is a school official, does not collect parental consent, and gives no legal advice. No certification is claimed.

Sources: eCFR, current as of October 7, 2026, for 34 CFR Part 99 and 16 CFR Part 312, read on October 9, 2026. Every quotation comes from these sections: 34 CFR 99.3, 34 CFR 99.30, 34 CFR 99.31, 34 CFR 99.32, 34 CFR 99.33, 16 CFR 312.2, 16 CFR 312.3, 16 CFR 312.5, 16 CFR 312.8, 16 CFR 312.10.

Aligned, not certified: FERPA and COPPA have no certification, and Verillian holds none for them. This is not legal advice. Your counsel decides what satisfies the rules.

To read an entry beside a section, bring a sample request to a demo. We read every request and reply.

Questions about FERPA, COPPA and AI

Does FERPA mention AI?

No. A text search of 34 CFR Part 99 as shown on eCFR (current as of October 7, 2026) finds none of the terms artificial intelligence, machine learning, generative, algorithm or chatbot, and 16 CFR Part 312 has none either. The rules work through definitions: education records, personally identifiable information and disclosure, all in section 99.3. Whether a staff member's prompt is a disclosure of information from an education record is for your counsel to decide.

Does an AI vendor become a school official?

Only if it meets every condition in section 99.31(a)(1)(i)(B). The text says an outside party 'may be considered a school official' provided it performs a service the institution would otherwise use employees for, is under the institution's direct control over the use and maintenance of education records, and is subject to the use and redisclosure limits of section 99.33(a). Whether a given vendor meets those conditions comes down to your contract and your counsel. Using Verillian does not make a vendor a school official.

Does COPPA apply when staff use an AI tool?

COPPA's duties fall on an operator, and sections 312.2 and 312.3 tie them to personal information gathered from children younger than 13 by a website or online service. A checkpoint on staff devices is not that operator: Verillian does not run an online service that collects from children and never receives your data. Whether a vendor's tool makes the vendor an operator, or puts any duty on the district, is for your counsel.

Does using Verillian satisfy FERPA or COPPA?

No. Your policy runs on the staff devices you enroll, and each captured request lands in a signed record held on infrastructure you run. Consent, who counts as a school official, an operator's notices and a vendor's own safeguards all stay with your district, your vendors and your counsel. Aligned, not certified, and neither law has a certification.

Read an entry beside these sections.

Thirty minutes. Bring a sample request, watch it ruled live, and open the signed record together.