Skip to content

Evidence request lists

Family Educational Rights and Privacy Act (FERPA)

Evidence request list. 15 controls, 15 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

FERPA: Annual Notification, Right to Inspect and Review (Subpart B)

FERPA-Part99.10_11_12
Right to Inspect and Review (34 CFR 99.10, 99.11, 99.12)

34 CFR 99.10 right to inspect + review; 99.11 fees; 99.12 limitations. RIGHT: parents + eligible students must be permitted to inspect + review the student's education records within 45 days of receipt of a request (or sooner if individual state law shortens the period). The institution must respond to reasonable requests for explanations + interpretations of records + provide copies if circumstances effectively prevent inspection at the institution. FEES: institutions may charge a reasonable fee for copies UNLESS the fee would effectively prevent the exercise of the right of inspection (e.g. low-income family). LIMITATIONS: 99.12 carves out certain records from inspection (e.g. financial records of parents; confidential letters of recommendation submitted before 1 January 1975 + post-1975 if the student has waived the right of inspection of those letters in writing; records of college s

Artefacts an auditor will ask for
  • Inspection request procedure published
  • Inspection request log + 45-day SLA tracking
  • Fee schedule + reasonable-fee policy
  • Redaction procedure for joint records
Where this commonly fails
  • 45-day SLA missed
  • Fees too high effectively preventing exercise
  • Joint records released without redacting other-student information
  • Letters-of-recommendation handling without proper waiver evidence
FERPA-Part99.7
Annual Notification of Rights (34 CFR 99.7)

34 CFR 99.7 + PTAC training guidance. ANNUAL NOTIFICATION REQUIREMENT: educational agencies + institutions must annually notify parents + eligible students of their FERPA rights including (a) the right to inspect and review education records; (b) the right to request amendment; (c) the right to consent to disclosures with the exceptions; (d) the right to file a complaint with the SPPO. CONTENT: the notice must include the procedure for inspecting + reviewing records + the procedure for requesting amendment + the criteria for designating school officials with legitimate educational interest + the FERPA office contact information + the SPPO contact information. METHOD: any means reasonably likely to inform (e.g. student handbook + website + email + paper notice + parent-teacher conference). DIRECTORY INFORMATION: the annual notice must also specify the types of information designated as di

Artefacts an auditor will ask for
  • Annual FERPA notice + distribution evidence
  • Directory information designation list + opt-out procedure
  • Workforce FERPA training records + acknowledgments
  • FERPA office + SPPO contact information published
Where this commonly fails
  • Annual notice missing or incomplete
  • Directory information opt-out deadline + procedure unclear
  • Workforce training not delivered or undocumented
  • FERPA office contact stale or missing

FERPA: Data Security Safeguards (PTAC Best Practices and SPPO Guidance)

FERPA-Safeguards-PTAC
Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

34 CFR 99.31(a)(6)(iii)(D) safeguards requirement + the PTAC Best Practices Guidance + SPPO Guidance. The 2011 final rule explicitly requires APPROPRIATE METHODS to PROTECT PII when disclosed under the studies + audit + evaluation exceptions. While FERPA itself does not prescribe specific security controls, the SPPO + PTAC + state-law (e.g. SOPIPA + CCPA-derived state student privacy laws + the 2018 Connecticut Act Concerning Student Data Privacy) impose the following safeguards on educational institutions + vendors processing student PII: (a) ACCESS CONTROL - need-to-know basis + role-based access + login authentication + just-in-time access + multi-factor authentication for sensitive PII; (b) ENCRYPTION - in-transit (TLS 1.2+) + at-rest (AES-256) + key management; (c) NETWORK + INFRASTRUCTURE SECURITY - firewall + IDS/IPS + segmentation + vulnerability management; (d) DATA RETENTION +

Artefacts an auditor will ask for
  • Access control policy + RBAC
  • Encryption-at-rest + in-transit evidence
  • Retention + destruction schedule
  • IR plan + tabletop test
  • Vendor FERPA agreement template + DPAs
  • Workforce FERPA + security training records
  • Privacy-by-design + edtech vendor evaluation
Where this commonly fails
  • Access control too permissive
  • Encryption inconsistent or absent
  • Retention indefinite + destruction undocumented
  • IR plan untested + breach notification unclear
  • Vendor agreements lacking FERPA-required terms
  • Training records missing
  • Edtech vendor evaluation skipped

FERPA: Directory Information, Recordkeeping and Redisclosure (Subpart D)

FERPA-Part99.32-Recordkeeping-99.33-Redisclosure
Recordkeeping of Disclosures + Limitations on Redisclosure (34 CFR 99.32, 99.33)

34 CFR 99.32 record of disclosures + 99.33 limitations on redisclosure. RECORDKEEPING (99.32): for each request for access to + each disclosure of PII (with EXCEPTIONS for: disclosures to + access by the student; school officials under 99.31(a)(1); disclosures with consent; disclosures of directory information; disclosures to a party seeking access pursuant to a judicial order or subpoena issued at a request of the institution), the institution must record: (a) the parties who have requested or received PII + the legitimate interest; (b) the date; (c) for disclosures to (a)(11) directory information, (a)(13) sex offense final results, (a)(15) parents of dependent students, the record must include the names of state + local officials who received the information. The record must be maintained as long as the underlying education record + made available for inspection by the parent + eligib

Artefacts an auditor will ask for
  • Disclosure log template + records
  • Redisclosure agreement clauses
  • Inspection procedure for log
  • Log retention aligned with record retention
Where this commonly fails
  • Disclosure log missing or incomplete
  • Redisclosure without compliant agreement
  • Log not made available for inspection
  • Log retention shorter than record retention
FERPA-Part99.37-Directory
Directory Information (34 CFR 99.31(a)(11), 99.37)

34 CFR 99.31(a)(11) directory information + 99.37 conditions for disclosure. DIRECTORY INFORMATION: information not generally considered harmful or an invasion of privacy if disclosed. Typically includes name + address + phone + email + photograph + date + place of birth + dates of attendance + major + degree + honors + sport participation + height/weight of athletes + most-recent-previous-school. NB: a SOCIAL SECURITY NUMBER + student ID may NEVER be designated as directory information; a non-electronic identifier used for ID may be designated only if it cannot be used to gain access to electronic education records. REQUIREMENTS for disclosure WITHOUT consent: (a) the institution must give annual PUBLIC NOTICE specifying the types of information designated; (b) the institution must give parents + eligible students a REASONABLE OPPORTUNITY TO REFUSE the designation (opt-out); (c) the ins

Artefacts an auditor will ask for
  • Directory information designation list + annual notice
  • Opt-out procedure + record
  • Partial opt-out support
  • Military recruiter + higher-ed disclosure procedure with opt-out check
Where this commonly fails
  • SSN + student ID designated as directory information (PROHIBITED)
  • Opt-out window too short or unclear
  • Partial opt-out not supported
  • Military recruiter request fulfilled without opt-out check

FERPA: Disclosure Restrictions, Consent and Exceptions (Subpart D)

FERPA-99.31a1-School-Officials
School Officials with Legitimate Educational Interest (34 CFR 99.31(a)(1))

34 CFR 99.31(a)(1) school officials with legitimate educational interest. The most-used FERPA exception + the source of most institutional disclosure decisions. DEFINITION + REQUIREMENTS: a school official includes institutional employees + contractors + consultants + volunteers + or other parties (e.g. attorneys + auditors + collection agents + cloud + edtech vendors) performing institutional services or functions for which the institution would otherwise use its employees + provided that: (i) the party is under the DIRECT CONTROL of the institution with respect to the use + maintenance of PII (e.g. contract clauses + control of data + return + deletion at end of engagement); AND (ii) the party is subject to the same FERPA + confidentiality requirements as institutional employees + AND (iii) the party uses the PII only to perform the institutional function for which they are designated.

Artefacts an auditor will ask for
  • School official designation policy
  • Vendor + contractor FERPA contract clauses
  • Legitimate-educational-interest determination process
  • Annual notification criteria language
Where this commonly fails
  • Vendors without direct control or confidentiality clauses still classified as school officials
  • Cloud + edtech vendor contracts missing FERPA-required terms
  • Legitimate-educational-interest threshold too low (over-disclosure)
  • Annual notification criteria vague
FERPA-99.31a3-Audit-99.31a6-Studies
Audit and Evaluation Exception + Studies Exception (34 CFR 99.31(a)(3), 99.31(a)(6), 99.35)

34 CFR 99.31(a)(3) audit + evaluation + 99.35 authorised representatives; 99.31(a)(6) studies for or on behalf of the institution. AUDIT + EVALUATION (99.31(a)(3) + 99.35): authorised representatives of the Secretary of Education + State + local educational authorities + Attorney General + Comptroller General of the United States may receive PII without consent for audit + evaluation of federal- or state-supported education programs + or for enforcement of federal or state legal requirements relating to such programs. The 2011 final rule clarified WHO qualifies as an authorised representative + required: (a) a written agreement with the authorised representative; (b) the authorised representative is under the direct control of the educational authority; (c) the authorised representative uses PII only for the audit/evaluation purpose; (d) appropriate safeguards in place; (e) destruction o

Artefacts an auditor will ask for
  • Written audit/evaluation agreement + safeguards
  • Written studies-exception agreement template
  • Vendor + researcher direct-control evidence
  • PII destruction certification at end of engagement
Where this commonly fails
  • Audit/evaluation disclosure without written agreement
  • Studies exception used for vendor analytics without compliant agreement
  • Lack of destruction requirement + evidence
  • Direct control absent for vendor research
FERPA-99.31a9-Judicial-99.31a10-Emergency-99.31a13-14
Judicial Disclosure + Health and Safety Emergency + Sex Offense Disclosures (34 CFR 99.31(a)(9), (10), (13), (14), 99.36)

34 CFR 99.31(a)(9) compliance with judicial order or subpoena; 99.31(a)(10) + 99.36 health or safety emergency; 99.31(a)(13)/(14) sex offense + crimes of violence disclosures. JUDICIAL DISCLOSURE (99.31(a)(9)): the institution may disclose PII in compliance with a judicial order or lawfully issued subpoena. NOTIFICATION: the institution must make a reasonable effort to NOTIFY the parent + eligible student in advance of compliance unless the order or subpoena is from a federal grand jury or other law enforcement subpoena that prohibits disclosure or the institution receives a separate court order to that effect. HEALTH OR SAFETY EMERGENCY (99.36): the institution may disclose PII to appropriate parties (e.g. parents + police + medical professionals) when knowledge of the information is necessary to protect the health or safety of the student or other individuals + based on the institution

Artefacts an auditor will ask for
  • Subpoena response procedure + notification evidence
  • Health/safety emergency threat determination policy
  • Sex offense disclosure procedure + Clery + Title IX coordination
  • Documented disclosure decision for each exception use
Where this commonly fails
  • Subpoena response without advance notification when permitted
  • Health/safety emergency over-used without articulable threat determination
  • Sex offense disclosure not coordinated with Title IX
  • Documentation lacking for emergency or sex-offense disclosure decision
FERPA-Part99.30_31
Prior Consent Required for Disclosure + Exceptions (34 CFR 99.30, 99.31)

34 CFR 99.30 prior consent requirement + 99.31 exceptions. PRIOR CONSENT (§99.30): the institution must obtain SIGNED + DATED WRITTEN CONSENT (electronic signature acceptable) BEFORE disclosing PII from education records (with the §99.31 exceptions). The consent must specify the records to be disclosed + the purpose + the party to whom disclosure is made. EXCEPTIONS to consent (§99.31) - disclosures permitted without consent: (a)(1) school officials with legitimate educational interest; (a)(2) other educational institutions where the student seeks or intends to enroll; (a)(3) authorised representatives for audit + evaluation; (a)(4) financial aid; (a)(5) state + local officials under State statute (1974 + 1979 statutory exceptions); (a)(6) studies for or on behalf of the institution; (a)(7) accrediting organizations; (a)(8) parents of dependent students per IRS Section 152; (a)(9) compli

Artefacts an auditor will ask for
  • Consent form template + signed-dated evidence
  • Disclosure log per 99.32
  • Exception-based disclosure log + basis
  • School official designation + legitimate-educational-interest determination
Where this commonly fails
  • Consent form generic or undated
  • Disclosure log missing or incomplete
  • Exception applied without documented basis
  • School official designation overly broad (e.g. vendors lacking direct institutional control + confidentiality requirements)

FERPA: Enforcement, Complaints and Coordination (Subpart E)

FERPA-99.60-99.67-Enforcement
Enforcement and Complaint Procedures (34 CFR 99.60 to 99.67)

34 CFR 99.60 to 99.67 enforcement + complaint procedures. ENFORCEMENT AUTHORITY: the SPPO within the Department of Education is responsible for investigating FERPA complaints + taking enforcement action. COMPLAINT FILING: any parent + eligible student + or third party may file a written complaint with the SPPO within 180 days of the alleged violation. INVESTIGATION (99.62-65): the SPPO investigates complaints + may request information from the institution + the complainant; the SPPO determines whether a violation occurred + provides the institution with findings + an opportunity to respond + a period of voluntary compliance. ENFORCEMENT ACTIONS (99.66-67): if voluntary compliance is not achieved, the Secretary of Education may take action including: (a) withholding of further payments under any applicable program; (b) issuing complaints to compel compliance through cease + desist orders;

Artefacts an auditor will ask for
  • Complaint procedure published
  • SPPO investigation response readiness
  • Voluntary compliance corrective action plan
  • Coordination with state Attorney General + private cause of action under state law
Where this commonly fails
  • Complaint procedure missing or unclear
  • SPPO investigation response slow
  • Corrective action plan not implemented
  • Misunderstanding that FERPA provides private right of action
FERPA-Coord-COPPA-PPRA-State
Coordination with COPPA, PPRA, State Student Privacy Laws and Sectoral Laws

FERPA coordinates with adjacent + overlapping privacy regimes. (1) COPPA (Children Online Privacy Protection Act, 15 USC 6501-6506 + 16 CFR Part 312) - FTC-administered; applies to online services collecting PII from children under 13; school + ed-tech vendor coordination via the 2014 FTC COPPA + FERPA Joint Statement allowing schools to consent on behalf of parents for educational-use ed-tech (parental notice still required + sole-purpose-of-education-only); (2) PPRA (Protection of Pupil Rights Amendment, 20 USC 1232h + 34 CFR Part 98) - applies to K-12 institutions receiving Department of Education funds + governs surveys + analyses + evaluations of students containing certain protected categories (political affiliations + mental health + sexual behaviour + illegal behaviour + critical appraisals of family relationships + religious practices + family income); (3) STATE STUDENT PRIVACY

Artefacts an auditor will ask for
  • COPPA + FERPA coordination policy for ed-tech vendors
  • PPRA survey opt-in/opt-out procedure
  • State student privacy law inventory + compliance
  • FERPA-HIPAA dual coverage policy
Where this commonly fails
  • COPPA-FERPA confused (e.g. school consent overstepped)
  • PPRA survey conducted without proper notice
  • State student privacy law more stringent than FERPA missed
  • FERPA-HIPAA dual coverage misapplied (incorrect health records classification)
FERPA-Status
FERPA Implementation Status, 2024-2025 Guidance and AI/Cloud Trends

FERPA implementation status as of 2026. STATUTORY + REGULATORY BASE: 20 USC 1232g (Family Educational Rights and Privacy Act of 1974 - the Buckley Amendment) implemented by 34 CFR Part 99 with FINAL RULE revisions in 1988 + 1995 + 2008 + 2011 (major revisions on directory information + studies/audit/evaluation exceptions + redisclosure) + 2020 SPPO study + ongoing administrative guidance. CURRENT GUIDANCE: SPPO Technical Assistance Letters + PTAC Best Practices Guidance + Joint Statements on COPPA + HIPAA. 2024-2025 PRIORITIES + TRENDS: (a) AI + machine learning systems processing student PII - PTAC guidance evolving on AI vendor agreements + algorithmic transparency + child-safety; (b) Cloud + edtech vendor evaluation - documented criteria + due diligence + contract clauses; (c) Data breach notification - while FERPA itself has no breach notification deadline, all 50 states + DC have da

Artefacts an auditor will ask for
  • FERPA + PTAC guidance subscription + tracking
  • AI + edtech vendor evaluation matrix
  • State student privacy law inventory
  • CISA + SPPO advisory tracking + IR coordination
Where this commonly fails
  • FERPA compliance program not updated for AI + cloud + edtech
  • Cybersecurity + ransomware risk not addressed
  • State law coordination skipped
  • COPPA 2.0 + Title IX + Clery coordination missing

FERPA: Right to Request Amendment + Hearing (Subpart C)

FERPA-Part99.20_21_22
Right to Request Amendment + Hearing (34 CFR 99.20, 99.21, 99.22)

34 CFR 99.20 procedure to request amendment; 99.21 right to a hearing; 99.22 minimum requirements for a hearing. AMENDMENT REQUEST: parents + eligible students may request amendment of an education record believed to be INACCURATE + MISLEADING + or in VIOLATION of the student's right of privacy. The institution must decide within a REASONABLE TIME whether to amend + inform the requestor of the decision + the right to a hearing if denied. HEARING REQUIREMENTS (99.22): (a) within a reasonable time after receipt of the request; (b) advance written notice of date + place + reasonable time; (c) opportunity to present evidence + be assisted by representatives (incl. attorney at requestor expense); (d) conducted by an institutional official with no direct interest in the outcome; (e) written decision including findings of fact + conclusions; (f) right to place an explanatory statement in the re

Artefacts an auditor will ask for
  • Amendment request procedure published
  • Amendment request log + decision
  • Hearing officer designation + impartiality evidence
  • Explanatory statement maintenance + disclosure procedure
Where this commonly fails
  • Amendment confused with substantive academic challenge
  • Hearing not scheduled or scheduled with biased hearing officer
  • Written decision lacking findings + conclusions
  • Explanatory statement not maintained or not disclosed alongside record

FERPA: Scope, Applicability, Definitions and Rights Transfer (Subpart A)

FERPA-Part99.1_3
Applicability and Definitions (34 CFR 99.1, 99.3)

34 CFR 99.1 applicability + 99.3 definitions. APPLICABILITY: FERPA applies to any educational agency or institution receiving funds from any program administered by the Secretary of Education (including all US K-12 + nearly all postsecondary institutions accepting federal funding incl. Pell grants). KEY DEFINITIONS: EDUCATION RECORDS = records directly related to a student + maintained by the institution + excluding sole-possession notes + law enforcement unit records under §99.8 + alumni-only records + employment-not-as-student records + medical-treatment records of postsecondary adult students (Buckley Amendment); PERSONALLY IDENTIFIABLE INFORMATION (PII) = direct identifiers (student name + parent name + address + SSN + ID number + biometric) + indirect identifiers (date of birth + place of birth + mother maiden name) + other information linked or linkable to a specific student + info

Artefacts an auditor will ask for
  • FERPA applicability assessment
  • Education records inventory + classification
  • PII definition aligned with FERPA
  • Directory information designation list
  • School official designation criteria
Where this commonly fails
  • Confusing education records with other records (e.g. sole-possession notes + medical-treatment records improperly classified)
  • PII definition too narrow or too broad
  • Directory information disclosed without proper designation + annual notice
  • School official designation lacking institutional direct control + confidentiality requirements
FERPA-Part99.4_5
Rights Transfer (34 CFR 99.4, 99.5)

34 CFR 99.4 rights of parents + eligible students; 99.5 rights of postsecondary students. Parents hold FERPA rights for students attending K-12 + students younger than 18 at postsecondary level. Rights TRANSFER to the student when: (a) the student attains age 18; OR (b) the student attends a postsecondary institution at any age. Once rights transfer, the student becomes the ELIGIBLE STUDENT + parents lose direct FERPA rights (but may still access records under §99.31(a)(8) if the student is a dependent for IRS tax purposes + the institution chooses to disclose). The transfer is automatic + does not require institutional or parental action; institutions must update records-access procedures upon transfer.

Artefacts an auditor will ask for
  • Rights transfer procedures
  • Postsecondary enrollment registration trigger
  • Dependent-student exception process
  • Updated annual notification reflecting transfer
Where this commonly fails
  • Continuing parental access after rights transfer without §99.31(a)(8) IRS-dependent basis
  • Postsecondary enrollment not triggering transfer
  • Procedural updates not made (e.g. continuing to send transcripts to parents after transfer)
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.