“HIPAA doesn’t apply to public schools.” That line has misled EdTech teams, confused school leaders, and put student data at risk for over two decades. It’s true that FERPA usually governs student records in K–12. But here’s what most people miss: HIPAA still matters, especially when schools use third-party platforms to handle health-related data. From school-based telehealth to IEP services to student mental health screening tools, the line between educational records and medical records is blurrier than ever. And when the wrong line gets crossed? It’s not just a compliance issue. It’s a breach. Here’s what I tell EdTech companies and school leaders: - Understand which privacy law governs each data set (there are many permutations of who owns and governs the data) - Avoid assuming FERPA coverage is a catch-all (again think of all the permutations in this hyper-connected, thirty-party platform driven world) - Build governance into your products and partnerships - Train teams on real-world data-sharing risks, not just legal theory Because when student privacy is mishandled, it’s not just trust that erodes. It’s the entire foundation of the EdTech ecosystem. #EdTech #FERPA #HIPPA #AIGovernance #StudentPrivacy
Student Privacy Laws
Explore top LinkedIn content from expert professionals.
Summary
Student privacy laws are regulations that protect the personal information and records of students from improper collection, use, or sharing by schools, education technology providers, and app developers. These laws define who can access student data, how it must be handled, and what consent is required, with rules varying by state and type of data, including health and online activity.
- Clarify consent requirements: Make sure your organization understands which law governs each type of student data and avoids assuming a single rule applies across all situations.
- Update privacy policies: Regularly review and revise privacy notices and practices to reflect changes in state laws, especially regarding minors' data and parental consent.
- Train your teams: Educate staff on real-world risks of sharing student information and ensure they know how to properly handle consent, data minimization, and age verification processes.
-
-
Children's information and sharing it is top of mind for regulators, as we have been telling our clients for a while, and as we saw yesterday in a new CA AG $500,000 settlement with Tilting Point Media LLC (Tilting Point) for #CCPA and #COPPA compliance issues in mobile app game “SpongeBob: Krusty Cook-Off.” Practice points: Directed at children: 🔹 If you are aware that children under 13 are using your services - they are is directed to children. Saying in your terms of service and privacy policy that consumers under 13 are not authorized to use it - doesn't change this. Regulator 1, 2, 3: 🔹 CA AG will use every enforcement tool to ensure compliance with the law and that companies exercise diligence with privacy law requirements 🔹 If one regulator tells you that you are not compliant (here BBB National Programs CARU): assess your compliance with other laws you could be enforced against by another regulator Data minimization: 🔹 Don't collect more personal information than reasonably necessary for a child to participate. Mind your SDKs: 🔹An SDK facilitates data sharing that can be a sale (CCPA) and/or unfair/deceptive (FTC) and/or subject to COPPA just like any data sharing. 🔹 You need to know: what information each SDK collects; evaluate contracts re: sharing of data through them - making sure you have the right consent. 🔹 You may need a formal SDK governance framework. 🔹 Every year: assess data minimization and SDK usage. (ensuring data flows appropriately change based on the consumer's age). 🔹 Every year: conduct adequate training for personnel re sharing and SDKs Sale/share: 🔹 Disclose your sale and share correctly in your privacy notice 🔹 Don't sell/share personal information of under 13's without parental consent 🔹When you do sell/share: provide a just-in-time notice explaining what information is collected, the purpose, sale/share, link to privacy policy, & parental or opt-in consent required. [FTC also says this in BetterHelp] Mixed audience 🔹When using an age screen it has to be neutral. 🔹Neutral means: (1) ask age information in a neutral manner that does not default to a set age of 16 or above or encourage users to falsify age information; (2) not suggest that certain features will not be available; and (3) provide CLEAR AND CONSPICUOUS notice that the age entered should be accurate to the user and is collected to ensure data use and advertising is appropriate. 🔹If the person is under 13 or 16 - direct them to a portion of the service that doesn't use data other than as permitted by COPPA/CCPA or get parental / opt in consent For ads in your apps, make sure they are: 🔹Identified as being an ad; 🔹Include a prominent one-click “X” or “Close” button; 🔹Do not manipulate or deceive consumers into engaging 🔹Do not advertise activities/products in which children cannot legally engage/possess. #dataprivacy #dataprotection #privacyFOMO Complaint: https://rb.gy/enu19e Agreement: https://rb.gy/jq6lke
-
October comes next week, and so do new privacy requirements in three states. Here's a recap and what to check ⤵️ 1️⃣ Colorado Privacy Act amendments related to minors' personal data will: 🔸impose obligations where a controller knows or willfully disregards that a user is a minor; 🔸require opt-in consent to sell or use a minor's personal data for targeted advertising, or to use system design features to increase engagement; 🔸limit how precise geolocation data of minors can be processed; and 🔸mandate data protection assessments in additional contexts. Rulemaking is underway to provide further clarity on these new requirements, including to specify when a data controller "willfully disregards" that a user is a minor and what system design features increase engagement. See the draft regulations here: https://lnkd.in/gcBtzyTi 2️⃣ Montana privacy law amendments that: 🔸lower the law's threshold for applicability; 🔸remove the general non-profit exemption; 🔸add privacy policy content requirements; 🔸require sale and targeted advertising opt-out links outside the privacy policy; and 🔸remove the right to cure violations. 3️⃣Maryland's Online Data Privacy Act takes effect. It has a low bar for applicability, and unique or less common requirements like: 🔸prohibiting processing of sensitive personal data unless it is strictly necessary to provide or maintain a consumer-requested product or service; 🔸forbidding collection of personal data unless it is reasonably necessary and proportionate to provide or maintain a consumer-requested product or service; 🔸banning sales of personal data of minors, and processing of their personal data for #TargetedAdvertising; 🔸broad data deletion right unless retention is required by law (though other provisions may give some flexibility); 🔸privacy policy requirements including to disclose the type of, business model of, or processing conducted by each third party to which personal data is disclosed; and 🔸consumer health data requirements. If you haven't already, identify which of these laws apply to your organization, and see if your current privacy practices address what's required. Consider especially: ✔️ How your organization identifies accounts, profiles, and personal data of minors, and treats them in line with Colorado's, Maryland's, and other states' increasingly complex requirements 💡 Validate that there are processes to address parental reports, app store provided age information, and other reports and signals that a data subject is a minor; ✔️ Data collection and use limits to address Maryland's strict data minimization requirements, particularly for sensitive personal data 💡 Updates may be appropriate in #privacy impact assessment processes, organizational policies, and organizational privacy training; ✔️ Confirming your organization's privacy policy has the third party details required under the Maryland law.
-
For decades, edtech vendors have relied on a simple legal framework: schools consent on behalf of parents when digital tools collect student data. The FTC just told a federal court that's wrong. In an amicus brief supporting a lawsuit against IXL Learning, a platform used by more than 18 million students, the Federal Trade Commission wrote that COPPA does not create "an agency relationship between schools and the parents of school children." Andrew Liddell, co-founder of the EdTech Law Center, put it more bluntly: "These theories of consent that companies rely on in order to bypass actual consent from parents are all bogus. They have no basis in the law whatsoever." The lawsuits are piling up. Three Kansas families sued IXL over "deceptive design techniques" that keep children engaged and share their data with third-party companies. Two California mothers sued Curriculum Associates, maker of i-Ready, arguing the company gained "virtually unfettered access" to children's personal information, including birth date, gender, race, and disability status. Districts are already responding. Los Angeles and Washoe County, Nevada, are rethinking their use of i-Ready or scaling back screen time. A Utah state board investigation of 100 apps commonly used in schools found that over a third shared student information with advertisers. A New York comptroller's audit documented 141 data breaches or unauthorized data releases between 2023 and 2025. But Mark Williams, a California attorney specializing in edtech contracts, warned that requiring vendors to get direct parent consent for every product would be an "administrative nightmare." For education innovators, this is the most urgent compliance signal of the year. Every company collecting student data needs to understand that the legal foundation they've relied on is being challenged in court with FTC support. Parent consent management platforms, vendor data-flow mapping tools, and privacy audit services move from "nice to have" to "required before your next contract renewal."
-
I've heard from many folks that it's hard to track what youth privacy and safety laws actually passed this year and which are recently subject to litigation and in the news. I would be lying if I said I also hadn't had trouble tracking all of this - so I decided to make a tracker! This list is all of the youth privacy/safety and age verification laws that actually passed, effective dates, a quick summary (including scope!), and any relevant litigation information. While I traditionally would not categorize the "age verification for adult content" laws as "youth" laws, they are helpful for me to understand the outcomes of age verification and what the courts are saying. Let me know if I missed anything or if you have a more recent litigation update than I do!
-
#Kidprivacy enforcement is not limited to #coppa. This settlement out of the Office of the New York State Attorney General focusing on #teen #privacy is a good reminder that many #StateAG offices have emphasized teen privacy is a priority area, which means we’re likely to see more settlements and litigation on such topics in 2025. Among other things, this enforcement highlights the importance of having rigorous authentication measures for any teen focused platform; privacy forward default settings; and a reminder that all of your public statements will be scrutinized for accuracy. Pro tip: review any injunctive terms in new privacy settlements for insights on what regulators view as requirements under their laws or required measures following a violation. Here, the settlement requires the company to: 1. Notify current users regarding app verification changes 2. Provide users with options to modify their privacy settings. 3. Provide all current and future users under the age of 18 with enhanced privacy options, such as hiding social media accounts from non-friends and prompt all users under 18 to review their privacy settings every six months. 4. Hide the personal information of current users under 18 until company obtains informed consent to the new app terms. 5. Requires company to limit the visibility of information about non-app-using students that other app users may enter into the app, such as the non-app user’s class enrollment or event attendance. 6. Prohibits company from making any future claims about user safety or user verification unless the company has a reasonable basis for making the claim based on competent and reliable scientific evidence. 7. Requires company to allow teachers to block their name, initials, or other personal identifier from appearing in the app’s class schedule feature. 8. Delete retained copies of the phone contact books of certain users. Also a $650K monetary provision. #privacylaws not just #ccpa #udaplaws #udap #stateattorneysgeneral Kelley Drye & Warren LLP https://lnkd.in/eByWuNDW
-
🇮🇪 The Data Protection Commission (DPC, Ireland) has published a “Data Protection Toolkit for Schools” (”toolkit”), a new resource dedicated to further assisting schools in meeting their data protection obligations when processing the personal data of children. The toolkit covers the following: 1. A detailed guidance piece on different aspects of data protection law in the specific context of schools 2. An FAQ section containing answers to questions commonly received by the DPC from the education sector 3. An appendix containing three helpful resources for schools, namely: - A sample template for Data Protection Impact Assessments (DPIAs) - An infographic on what information to include in a Privacy Policy - A “checklist” for schools on how to respond to a Subject Access Request (SAR) #privacy #europe #ireland #gdpr #children #dataprotection #dpia
-
You've heard of #COPPA and you're pretty sure kids' privacy laws don't apply to you? Well, think again! With renewed efforts at passing federal youth safety and privacy laws, including the Kids Online Safety Act #KOSA and COPPA 2.0, it's time for a rethink about how you interact with the personal data of anyone under 17. (I really mean it.) In my column this week, I explain the overlapping circles of scope within the updated draft of KOSA as well as the importance of an expanded knowledge standard for COPPA. https://lnkd.in/e7hwrh9n But wait, there's more! Even without Congressional action, COPPA will soon be updated by the Federal Trade Commission. IAPP's Westin Fellow Andrew Folks just published an excellent analysis of the top takeaways from the proposed COPPA Rule update here: https://lnkd.in/e3PwC72M
-
ICYMI: Despite an updated COPPA rule, states aren't waiting for Congress to act on protecting kids online. Here are a few of the proposed laws making their way through state legislatures and one that was signed into law last week: 🌴In South Carolina, a proposed State Senate bill (S268) mandates that online services enhance minors' safety by restricting data collection, preventing potential harm, offering tools for managing screen time and data, facilitating parental controls, and enabling harm reporting. Additionally, these services must publicly disclose their safety practices concerning minors' data and safety. 🌞In North Carolina, the proposed Children's Online Safety Act would enact safeguards to protect children online, establish the online safety division at the Department of Justice and the cyberbullying unit at the state Bureau of Investigation, create the online child safety commission, and appropriate funds for those purposes. 🏙️ The New York Children's Online Safety Bill (SB S4609) would require operators of covered platforms to conduct age verification to determine whether a user is a covered minor, utilize default privacy settings for covered minors, and require parental approval of activity related to a covered minor's covered platform account. 👉🏼 Arkansas Governor Huckabee Sanders signed the three children’s privacy-related bills passed by the legislature last week into law: HB 611, HB 612, and HB 1717. Under HB 1717, operators who know they are collecting personal information from teens must provide notice of what information the operator collects, the purpose for processing personal data, and disclosure practices.
-
As Students Return, So Do Our Responsibilities: A Reminder for Higher Ed Administrators The start of a new academic year brings energy, excitement and essential compliance obligations. As college administrators, it’s our duty to ensure students are not only welcomed, but also informed, protected, and empowered. Here are key areas that require attention and communication: Annual Consumer Information Disclosures Under the Higher Education Act, institutions must distribute a wide range of disclosures to all enrolled students, including but not limited to: • Financial aid eligibility and procedures • Tuition and refund policies • Accreditation and licensure information • Campus crime statistics (Clery Act) • Drug and alcohol prevention programs • Retention and graduation rates • Voter registration resources Make sure your disclosures are posted online and actively distributed (e.g., via email, handbook or portal) documentation matters. FERPA (Family Educational Rights and Privacy Act) Remind your teams of their FERPA obligations: • Student educational records must remain confidential. • Training is not only essential, it’s required • Students have the right to inspect and request amendments to their records. If your institution hasn’t completed annual FERPA training or updated directory information policies, now is the time. Constitution & Citizenship Day - September 17 Institutions must provide an educational program on the U.S. Constitution for students, plan now and document the delivery. These aren’t just checkboxes. They’re cornerstones of trust, transparency, and student protection. Let’s lead the way with clear communication, accessible resources, and a culture of compliance that supports student success from day one. Here’s to the start of another amazing year!