For the complete documentation index, see llms.txt. This page is also available as Markdown.

Education and EdTech compliance

Education compliance — FERPA, COPPA, IDEA, Section 504, ADA, Title VI/IX, state student-data laws, ED guidance, accessibility.

Education AI compliance braids federal student-record law (FERPA) + child-data law (COPPA) + civil rights statutes + state student-data laws + accessibility law. Stakes are high because student trajectories are at issue and regulators (OCR, FTC, state AGs) are active.

Regulatory frame

Regime
Applies when
Evaluation-evidence shape

FERPA (20 USC § 1232g)

Schools/agencies receiving DOE funds

School official exception evidence; consent/notice; records access

PPRA

Surveys / behavioral data of minors

Notice, parental consent for protected categories

COPPA (15 USC § 6501)

Online services likely used by under-13

Parental consent, data minimization, retention limits

IDEA / Section 504 / ADA

Students with disabilities

Accommodation accuracy, accessible delivery

Title VI

Federally-funded programs

Disparate impact monitoring

Title IX

Sex discrimination in federally-funded programs

Bias audit on grading and admissions

State student-data privacy laws

Varies by state — most states now have one

Specific notice/consent/data-localization rules

State AI laws

E.g., NY Education Law § 2-d, CA AB 2273

Per-state requirements

Department of Education guidance

Federal funded programs

Reasonable use of AI evidence

OCR enforcement

Federally-funded programs

Investigation cooperation; corrective action plans

GDPR / UK GDPR

EU/UK students

Lawful basis; DPA; transfer mechanism

FERPA

20 USC § 1232g, 34 CFR Part 99. Core requirements:

  • Schools may disclose education records only with parent/eligible-student consent or under exceptions

  • School official exception — most common AI-vendor pathway; vendor must perform institutional service, be under direct control, and use records only for authorized purpose

  • Records access rights for parents/eligible students

  • Limited directory information disclosure with notice/opt-out

Stratix evaluation evidence:

  • DPA executable as a school-official-exception agreement

  • Audit trail of who accessed which records

  • Tenant isolation — one school's records never touch another's

COPPA

For services likely used by children under 13:

  • Verifiable parental consent before collecting

  • Limited data; no behavioral targeting against under-13

  • Strict retention and deletion

  • FTC has specifically called out AI services that train on under-13 data

Stratix evaluation evidence:

  • Hard age-band gate

  • Audit log of consent state at the time of trace

  • No training on tenant data without consent (enterprise contractual term)

IDEA / Section 504 / ADA

For students with disabilities:

  • IDEA — IEP-based services; AI tools must support, not replace, IEP-required services

  • Section 504 — accommodations for substantially limiting impairments

  • ADA Title II (public schools) and Title III (private schools / EdTech vendors) — accessible delivery

Stratix evaluation evidence:

  • Accessibility scoring on AI outputs (reading level, alt-text, captioning WER)

  • Accommodation-database matching as code assertion

  • Audit trail of accommodation delivery

Title VI / Title IX

Federal civil rights statutes:

  • Disparate impact on protected class triggers OCR investigation

  • AI grading, AI integrity-detection, AI admissions all currently in OCR scrutiny

  • Settlement consent decrees include monitoring and retraining obligations

Stratix evaluation evidence:

  • Group-fairness scorers per scenario

  • Audit-trail per evaluation showing the decision basis

  • Retention to support OCR investigation timelines

State student-data privacy laws

Most US states have at least one. Notable examples:

  • NY Education Law § 2-d — strict vendor data agreement requirements; "Bill of Rights"

  • CA Student Online Personal Information Protection Act (SOPIPA)

  • CT, IL, CO, FL, KY, NC, TX, UT — varying flavors

Many require:

  • Specific data-handling notices to parents

  • No targeted advertising to students

  • No selling student data

  • Specific deletion / retention rules

  • Per-vendor public agreement registry

Stratix evaluation evidence:

  • Per-state DPA addenda available under Enterprise tier

  • Tenant isolation with state-specific configuration

  • Audit retention matching state requirements

State AI in education laws

Emerging:

  • NY — guidance on AI in K-12 (2024-2025)

  • CA — multiple bills around AI literacy and disclosure

  • TX, FL, OH, others — proposed and adopted bills around AI assessment, integrity

Track state-by-state; defaults below cover most current frameworks.

US Department of Education guidance

ED has issued non-binding guidance on AI in education (2023-2024) including:

  • "Designing for Education with AI" report

  • Guidance on AI accessibility

  • Cybersecurity advisories for AI-enabled services

Treat as non-binding-but-influential — many state and district policies cite ED.

OCR enforcement

US Education Department Office for Civil Rights investigates Title VI / Title IX / Section 504 / ADA / IDEA complaints. Recent focus areas:

  • AI-detection bias against non-native English writers

  • Accessibility of AI-generated content

  • Disparate-impact investigations on AI grading

Stratix evaluation evidence supports OCR cooperation:

  • Pull-on-demand fairness reports

  • Audit trail of AI-influenced student outcomes

GDPR / UK GDPR

For EU/UK students:

  • Lawful basis (consent or legitimate interest, with care)

  • DPIA for high-risk AI use

  • Cross-border transfer mechanism

  • DPA with the institution

  1. Pro tier minimum; Enterprise for large districts and university systems

  2. SSO + RBAC scoped to district / school / class / role

  3. DPA executable as FERPA school-official-exception

  4. State-specific DPA addenda for NY § 2-d and similar

  5. Hard rules: instructor-final-decision on grading, age-band gating, accommodation match

  6. Group fairness scorers on all student-affecting AI

  7. Accessibility scoring on every student-facing output

  8. Audit retention matching the longest applicable state requirement (default 5 years post-graduation)

  9. No training on tenant data without explicit consent

  10. BYOK custom models for the most sensitive student data

See also

Last updated

Was this helpful?