Student data can be safe with AI grading tools, but FERPA places that responsibility on your school or district, not the tool itself. FERPA lets approved vendors handle education records only under a data privacy agreement, so use district-vetted tools and never upload identifiable student work to a personal AI account.
What does FERPA actually protect, and who has to comply?
FERPA, the Family Educational Rights and Privacy Act, protects the privacy of student education records and applies to any school or district that receives funding from the U.S. Department of Education, which covers virtually all public K-12 schools. Education records include personally identifiable information such as names, grades, and the graded work a school keeps on file. That means a student’s graded essay or assessment stored by the school is protected.
FERPA gives parents the right to access and control disclosure of these records, and those rights transfer to the student at age 18 or when they enroll in a postsecondary institution. Schools generally need written consent before disclosing personally identifiable information from education records, with a handful of specific exceptions the law spells out. Uploading a class set of essays to an outside AI service is a disclosure, which is exactly why it needs a lawful basis rather than a leap of faith in a vendor’s marketing.
Does FERPA apply to the AI grading tool or to your school?
FERPA applies to your school or district, not to the AI vendor directly, so no tool is inherently “FERPA-compliant” on its own. Compliance is something a school achieves by controlling how a vendor handles student data. When a marketing page claims a product is FERPA-compliant, read it as a starting point for questions, not a guarantee that your specific use is lawful.
The usual legal pathway is FERPA’s “school official” exception. A school can share education records with an outside vendor if that vendor performs a service the school would otherwise do itself, stays under the school’s direct control over how records are used, and does not reuse or redisclose the data for its own purposes. In practice, districts establish this through a written data privacy agreement that spells out permitted uses, security expectations, retention limits, and deletion. Without that agreement in place, an AI tool has no clear standing to hold your students’ work.
Can you upload student work to an AI tool on your own?
Usually not without district approval. Because FERPA responsibility sits with the school, an individual teacher signing up for a consumer AI account and pasting in identifiable student essays can put the district out of compliance, even with good intentions. Most districts maintain an approved-tools list and a vetting process precisely so no single classroom decision creates a data-sharing relationship the district never agreed to.
The bigger risk with personal or free accounts is what happens to the data after you submit it. Some consumer AI services reserve the right to retain inputs or use them to improve their models unless you are on an enterprise or education plan with different terms. Check whether your submission becomes training data before you upload anything a parent would recognize as their child’s.
What should you ask a vendor before uploading student work?
Ask whether the vendor will sign your district’s data privacy agreement and act as a school official under FERPA. That single question surfaces most of what matters: data ownership, permitted uses, retention, and deletion. If a vendor will not contract on those terms, that is a meaningful signal on its own.
Route these questions through whoever owns edtech vetting in your district, often a technology director or privacy officer, rather than resolving them alone. Your job as a classroom teacher is to flag the tool and the intended use, not to sign off on the legal terms yourself.
- Will you sign our data privacy agreement (DPA) and act as a school official under FERPA?
- Is student work ever used to train your AI models, and can that be turned off?
- Where is data stored, who can access it, and are sub-processors disclosed?
- How long is student data retained, and can we request deletion?
- What security measures such as encryption, access controls, and breach notification are in place?
How can you lower the risk when a tool isn't fully approved?
De-identify the work first. FERPA protections attach to personally identifiable information, so removing names, student IDs, and other identifying details before uploading meaningfully reduces exposure. Be aware that essays can still identify a student through their content, since a personal narrative about a specific event may be recognizable even without a name attached.
Other practical steps help too: use a single anonymized sample to test a tool rather than a whole class set, avoid pasting anything from special-education or health records, and confirm your state’s rules. Several states impose stricter requirements than FERPA, and those obligations still apply even when a tool clears the federal bar. Treat de-identification as a stopgap for exploration, not a substitute for the district vetting that any ongoing classroom use should have.
What privacy rules apply beyond FERPA?
Beyond FERPA, two layers matter most. COPPA, the Children’s Online Privacy Protection Act enforced by the FTC, governs how online services collect personal information from children under 13 and often shifts consent duties onto schools acting on parents’ behalf. State student-privacy laws add another layer, frequently with tighter rules on data use and vendor contracts.
Examples include New York’s Education Law 2-d, California’s Student Online Personal Information Protection Act (SOPIPA), and Colorado’s student data transparency requirements. The practical takeaway is that clearing FERPA is necessary but not always sufficient. When federal and state rules overlap, the stricter standard is the one you have to meet.
How does a tool like JeddAI fit a FERPA-conscious workflow?
A tool built for classrooms should make FERPA-conscious choices easier, not harder. JeddAI drafts feedback and grading against your own rubric, success criteria, and comment banks, and keeps the teacher reviewing and editing every result, so professional judgment stays with you rather than being outsourced to a model. The privacy questions above still apply, and your district’s vetting still governs any classroom rollout.
The point is not that any single product removes your obligations, but that the right setup lets you apply criteria consistently and save grading time while keeping student data handling deliberate. If you want to explore that approach, you can Get started with JeddAI and bring the same vetting checklist to the conversation.
| Area | Reassuring sign | Warning sign |
|---|---|---|
| Contract | Will sign your district's DPA as a school official | Consumer terms of service only, no DPA |
| Data use | Student work is never used to train models | Inputs may be used to improve the product by default |
| Retention | Clear retention limits and deletion on request | Vague or indefinite retention |
| Access | Documented access controls and encryption | Unclear who can view uploaded work |
| Sub-processors | Third parties disclosed and contractually bound | Undisclosed sub-processors or data sharing |
Frequently asked questions
Who enforces FERPA and what happens if a district violates it?
The U.S. Department of Education's Student Privacy Policy Office enforces FERPA. There is no private right to sue; the ultimate penalty is withdrawal of federal funding, which is why districts treat compliance seriously.
Can parents opt out of a third-party AI tool being used with their child's work?
Often yes, depending on district policy and state law. Because FERPA and many state laws give parents rights over education records, districts frequently provide notice and, in some cases, consent or opt-out processes for outside tools.
How is FERPA different from COPPA for classroom AI tools?
FERPA protects education records at federally funded schools, while COPPA governs online collection of personal information from children under 13 and is enforced by the FTC. An AI tool used with young students may implicate both.
What is a data privacy agreement (DPA), and why does it matter?
A DPA is a contract that binds a vendor to specified uses, security, retention, and deletion of student data. It is the mechanism that lets a district lawfully share education records with an AI vendor under FERPA's school official exception.
Get started with Jeddle
Jeddle gives teachers and students instant, syllabus-aligned feedback powered by JeddAI.
Looking for study material? Browse Jeddle's Australian-English subject resources, or explore more articles on AI in Education.