FERPA is a U.S. federal law that safeguards the privacy of student education records, granting parents and eligible students rights to access, amend, and control the disclosure of personally identifiable information from these records.
SA-10
SC-1
SI-1
SR-1
Procedures and contract terms to ensure third-party vendors comply with FERPA regulations when accessing student data.
Contracts with vendors who handle student data must specify FERPA compliance requirements to ensure the protection of student privacy.
Designated individual responsible for overseeing the institution’s FERPA compliance program.
Designated role responsible for overseeing FERPA compliance and ensuring all organizational processes meet FERPA requirements.
Technology and procedures for logging and reviewing access to student records to monitor compliance with FERPA.
Technology and procedures for maintaining and reviewing logs of access to student records.
Organizational plan for responding to data breaches involving FERPA-protected student data, including notifications.
Plan for responding to data breaches affecting FERPA-protected information, including containment, notification, and resolution procedures.
Regular audits to assess compliance with FERPA policies and procedures, identifying gaps and ensuring corrective actions.
Audits to assess FERPA compliance across organizational processes and policies.
Documentation and tracking of all FERPA training activities and employee participation to ensure compliance.
Documentation of all FERPA training sessions and employee participation records.
Procedures to ensure proper tracking and documentation of consent forms for FERPA disclosures.
Procedures for tracking signed consent forms authorizing disclosure of FERPA-protected information.
Procedures for managing legal requests for student records, including subpoenas and court orders, under FERPA.
Procedures for managing legal requests for student records.
Procedures for handling complaints or investigations of FERPA violations.
Procedures for managing complaints or investigations related to FERPA violations.
Procedures and technologies to manage and limit access to student data based on roles and responsibilities.
Procedures to ensure only authorized users access student records.
Policy and procedures for retaining and disposing of student records as required by FERPA and other regulations.
Policy defining the retention period for student records and the secure disposal of records after the retention period.
Measures to protect FERPA-protected data from unauthorized access or breaches through encryption, authentication, and monitoring.
Security measures to protect FERPA-protected data from unauthorized access or breaches.
Standardized forms to obtain consent from students or guardians for sharing personal information.
Standardized form to obtain consent from students or guardians for information sharing.
Policy governing the disclosure of student directory information and the process for opting out of such disclosures.
Policy defining what constitutes directory information and how it is shared, with an opt-out process.
A policy to identify, assess, and mitigate risks to FERPA-protected data and ensure data protection across the institution.
A policy to systematically identify, assess, and mitigate risks to FERPA-regulated student information.
Training program to educate staff on FERPA compliance and best practices for protecting student records.
Regular training program to educate staff on FERPA requirements and best practices.
Procedures for securely handling, storing, and managing student records to comply with FERPA.
Procedures for securely handling, storing, and managing student records.