Education and EdTech compliance
Education compliance — FERPA, COPPA, IDEA, Section 504, ADA, Title VI/IX, state student-data laws, ED guidance, accessibility.
Education AI compliance braids federal student-record law (FERPA) + child-data law (COPPA) + civil rights statutes + state student-data laws + accessibility law. Stakes are high because student trajectories are at issue and regulators (OCR, FTC, state AGs) are active.
Regulatory frame
FERPA (20 USC § 1232g)
Schools/agencies receiving DOE funds
School official exception evidence; consent/notice; records access
PPRA
Surveys / behavioral data of minors
Notice, parental consent for protected categories
COPPA (15 USC § 6501)
Online services likely used by under-13
Parental consent, data minimization, retention limits
IDEA / Section 504 / ADA
Students with disabilities
Accommodation accuracy, accessible delivery
Title VI
Federally-funded programs
Disparate impact monitoring
Title IX
Sex discrimination in federally-funded programs
Bias audit on grading and admissions
State student-data privacy laws
Varies by state — most states now have one
Specific notice/consent/data-localization rules
State AI laws
E.g., NY Education Law § 2-d, CA AB 2273
Per-state requirements
Department of Education guidance
Federal funded programs
Reasonable use of AI evidence
OCR enforcement
Federally-funded programs
Investigation cooperation; corrective action plans
GDPR / UK GDPR
EU/UK students
Lawful basis; DPA; transfer mechanism
FERPA
20 USC § 1232g, 34 CFR Part 99. Core requirements:
Schools may disclose education records only with parent/eligible-student consent or under exceptions
School official exception — most common AI-vendor pathway; vendor must perform institutional service, be under direct control, and use records only for authorized purpose
Records access rights for parents/eligible students
Limited directory information disclosure with notice/opt-out
Stratix evaluation evidence:
DPA executable as a school-official-exception agreement
Audit trail of who accessed which records
Tenant isolation — one school's records never touch another's
COPPA
For services likely used by children under 13:
Verifiable parental consent before collecting
Limited data; no behavioral targeting against under-13
Strict retention and deletion
FTC has specifically called out AI services that train on under-13 data
Stratix evaluation evidence:
Hard age-band gate
Audit log of consent state at the time of trace
No training on tenant data without consent (enterprise contractual term)
IDEA / Section 504 / ADA
For students with disabilities:
IDEA — IEP-based services; AI tools must support, not replace, IEP-required services
Section 504 — accommodations for substantially limiting impairments
ADA Title II (public schools) and Title III (private schools / EdTech vendors) — accessible delivery
Stratix evaluation evidence:
Accessibility scoring on AI outputs (reading level, alt-text, captioning WER)
Accommodation-database matching as code assertion
Audit trail of accommodation delivery
Title VI / Title IX
Federal civil rights statutes:
Disparate impact on protected class triggers OCR investigation
AI grading, AI integrity-detection, AI admissions all currently in OCR scrutiny
Settlement consent decrees include monitoring and retraining obligations
Stratix evaluation evidence:
Group-fairness scorers per scenario
Audit-trail per evaluation showing the decision basis
Retention to support OCR investigation timelines
State student-data privacy laws
Most US states have at least one. Notable examples:
NY Education Law § 2-d — strict vendor data agreement requirements; "Bill of Rights"
CA Student Online Personal Information Protection Act (SOPIPA)
CT, IL, CO, FL, KY, NC, TX, UT — varying flavors
Many require:
Specific data-handling notices to parents
No targeted advertising to students
No selling student data
Specific deletion / retention rules
Per-vendor public agreement registry
Stratix evaluation evidence:
Per-state DPA addenda available under Enterprise tier
Tenant isolation with state-specific configuration
Audit retention matching state requirements
State AI in education laws
Emerging:
NY — guidance on AI in K-12 (2024-2025)
CA — multiple bills around AI literacy and disclosure
TX, FL, OH, others — proposed and adopted bills around AI assessment, integrity
Track state-by-state; defaults below cover most current frameworks.
US Department of Education guidance
ED has issued non-binding guidance on AI in education (2023-2024) including:
"Designing for Education with AI" report
Guidance on AI accessibility
Cybersecurity advisories for AI-enabled services
Treat as non-binding-but-influential — many state and district policies cite ED.
OCR enforcement
US Education Department Office for Civil Rights investigates Title VI / Title IX / Section 504 / ADA / IDEA complaints. Recent focus areas:
AI-detection bias against non-native English writers
Accessibility of AI-generated content
Disparate-impact investigations on AI grading
Stratix evaluation evidence supports OCR cooperation:
Pull-on-demand fairness reports
Audit trail of AI-influenced student outcomes
GDPR / UK GDPR
For EU/UK students:
Lawful basis (consent or legitimate interest, with care)
DPIA for high-risk AI use
Cross-border transfer mechanism
DPA with the institution
Recommended setup
Pro tier minimum; Enterprise for large districts and university systems
SSO + RBAC scoped to district / school / class / role
DPA executable as FERPA school-official-exception
State-specific DPA addenda for NY § 2-d and similar
Hard rules: instructor-final-decision on grading, age-band gating, accommodation match
Group fairness scorers on all student-affecting AI
Accessibility scoring on every student-facing output
Audit retention matching the longest applicable state requirement (default 5 years post-graduation)
No training on tenant data without explicit consent
BYOK custom models for the most sensitive student data
See also
Last updated
Was this helpful?