Every edtech vendor selling AI tools to higher education says they are "FERPA compliant." Most of them cannot explain what that actually means. If you are evaluating AI platforms for transcript evaluation, GPA standardization, or admissions processing, here are the specific FERPA questions you need to ask — and what acceptable answers look like.
Why FERPA Matters for AI Admissions Tools
FERPA grants students rights over their educational records and restricts how institutions and their vendors can use that data. When you give a vendor access to student transcript data, you are extending your institution's FERPA obligations to that vendor. If the vendor mishandles that data, your institution bears the regulatory exposure.
The Seven Questions to Ask Every AI Vendor
1. Are you a "school official" under FERPA? A vendor can only access student records if they qualify as a school official with a legitimate educational interest. Ask them to document this explicitly in the contract.
2. Is student data used to train your AI model? This is the most important question. Student personally identifiable information cannot be used to train a commercial AI model without student consent. The answer must be an unambiguous, contractually enforceable no.
3. Do you have a Data Processing Agreement? A signed DPA should be standard. If the vendor hesitates, that is a red flag.
4. What is your audit trail for every decision? Every action taken on student data must be logged, timestamped, and immutable. You must be able to produce these logs for compliance review.
5. Who else has access to this data? Subprocessors and third-party services the vendor uses may also have access to student data. Get the full list and review each one.
6. What is your data retention and deletion policy? How long is student data retained? Can you request deletion? What happens to data after your contract ends?
7. What is your breach notification process? Under FERPA, institutions must be notified of breaches. Get the timeline and process in writing.
Frequently Asked Questions
FERPA Questions? Talk to Our Team.
We document every FERPA compliance requirement and provide a complete Data Processing Agreement with every LioraAI contract. No hedging.
Book a Free Demo →