FERPA and EdTech vendors: which student records are excluded from a data license?
EdTech vendors generally cannot license student education records they hold under a school's authority, because use is limited to the purpose the school authorized. Their own engineering, finance, sales and support records may still be licensable after rights review and redaction. Counsel should confirm the position under FERPA, state law and district contracts.
Can an EdTech vendor license student records? The short answer
Generally not the student records themselves. An EdTech vendor typically holds education records only because a school or district let it, and that permission usually limits the vendor to providing the service. The operational records that sit around the product, such as the vendor's own support tickets, engineering history, sales and finance files, are a different category and are where a licensing conversation can start.
For a referral partner the useful skill is sorting. You are not interpreting student privacy law, but you can tell which half of an EdTech company's archive is probably off the table and which half might be in play.
What does FERPA do for vendors, in plain terms?
The Family Educational Rights and Privacy Act protects student education records held by schools that receive federal education funding. Schools may share records with a vendor under a "school official" arrangement when the vendor performs a function the school would otherwise do itself, works under the school's direct control for use of the records, and uses them only for the authorized purpose. The federal regulations also contain a provision on releasing de-identified education data, which schools and vendors treat as having its own conditions.
Read the current regulation text, or have counsel read it, before relying on any summary, including this one. The point for licensing is the purpose limit: a vendor that received records to run a gradebook or learning platform does not gain a right to sell or license them for a different purpose.
Contract promises matter as well. FTC staff have written that a company's promises about how it will use customer data are enforceable, whether they appear in privacy policies, terms of service or promotional materials. A district agreement or student-privacy pledge that bars secondary use counts the same way in practice.
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
Which EdTech records are excluded, and which may remain?
| Record category | Typical status | Why |
|---|---|---|
| Student education records (grades, attendance, assignments, IDs) | Excluded unless a lawful basis and school authorization exist | Held for the school's purpose under its control |
| Student-generated content and activity logs | Excluded by default | Often tied to identifiable students and covered by district agreements |
| Teacher and administrator account data | Needs review | May be covered by district contracts and state student-privacy laws |
| Vendor support tickets with school staff | Possible after redaction | Content may mention students, so de-identification is required |
| Engineering history, code review, incident records | Often usable | The vendor created them, subject to secrets scanning |
| Sales, finance, HR and operations records | Often usable | Business records created by the vendor |
| Product analytics and aggregated usage | Needs review | Depends on contract terms and whether it is truly aggregated |
A sorting screen: the three questions
- Who gave us this? If a school or district supplied it, the district contract governs it.
- Why did we receive it? If the answer is "to deliver the service", assume secondary use is blocked until counsel says otherwise.
- Can a person be picked out? If students or staff can be identified directly or by combination, de-identification and the rules above come first.
If the honest answer to the first question is "nobody, we created it", as with the vendor's own engineering and finance records, that is the green zone. If a school supplied it, it was received to deliver the service and people can be picked out, that is the red zone.
State laws and district contracts
Many states have student-privacy statutes that go beyond FERPA, and many districts require vendors to sign standard data privacy agreements. These often restrict targeted advertising, sale of student data and secondary use, and some require deletion on contract end. The details vary, so the answer for a given vendor depends on the states and districts it serves. Do not assume a clean answer from the federal rule alone.
Pre-introduction checklist for EdTech vendors
- The company can separate its own business records from data received from schools.
- Its district agreements and privacy pledges have been read for secondary-use and sale limits.
- Engineering, finance, sales and support systems each have a named owner who can export history.
- Support tickets and email can be filtered or redacted to remove student information.
- Records for users under 13 or other protected groups are scoped out unless counsel decides otherwise.
- An authorized sponsor, such as the owner, CEO or CFO, is willing to consider an exclusive license for an agreed term.
What to say to an EdTech owner
Follow with two practical asks. First, request a short call with the owner, CEO or CFO and whoever manages the district contracts. Second, suggest that the company list its systems with the data inventory builder rather than sending files, so no records leave the building during the introduction.
Illustrative scenario
A fictional 120-person tutoring-software company serves 40 districts. Its student activity logs are off the table because district agreements restrict use to service delivery. Its product engineering history, internal design reviews, finance close files and sales pipeline records are authored by the company and fall in the possible group. After counsel confirms rights, the data inventory covers only that second group.
What does this mean for a referral partner?
Keep the conversation at the level of fit. Ask the owner whether the company has operational history beyond the product data it receives from schools, and whether anyone has read its district agreements for secondary-use limits. Never ask for records. If the real value is in student data, the company is probably not a fit.
Related questions often arise in the same chat: how field-of-use restrictions narrow what a buyer may do, what a residuals clause does not cover, how to carve EU and UK records out of a US data license, and why the objection that data is too sensitive is often answered by scoping rather than refusing. The data license agreement overview shows where these limits land in the contract.
The partner earns 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, up to $100,000 per referred company, paid only after the buyer pays and SourceX receives its fee.
Next step
Use the company fit checker for a preliminary screen, check how it works, and register as a partner if an EdTech company with 50+ full-time employees at peak (contractors excluded) and strong business-side records comes to mind.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can an EdTech company sell de-identified student data?
FERPA's regulations address releasing de-identified education data with conditions, and many state laws and district contracts add limits or ban secondary use outright. A vendor should have counsel check the current text and every district agreement before treating any student-derived dataset as licensable.
What does the school official exception mean for a vendor?
It lets a school share education records with a vendor performing a function the school would otherwise do, under the school's direct control and for the authorized purpose only. The vendor therefore receives the records to deliver a service, not to commercialize them.
Which EdTech records are usually safest to scope?
Records the vendor created itself, such as engineering history, internal design reviews, finance, sales and operations files. Support tickets need redaction because they can mention students. Each category still needs rights confirmation and secrets or personal-data scanning before inventory.
Do state student-privacy laws matter if FERPA allows something?
Yes. Many states add restrictions on sale, targeted advertising and secondary use, and districts often require signed data privacy agreements. The strictest applicable rule or contract term controls what the vendor can do, so the answer depends on where its customers are.
Should a partner ask an EdTech owner for sample records?
No. Partners never export, upload or describe confidential records. Ask only high-level fit questions, such as company size, years of operation and whether business-side records exist apart from school-supplied data, then introduce the owner or CFO.
Related pages
Free resources
- Days sales outstanding calculator — How many days customers take to pay.
- Business succession planning assessment — Ten questions on successor, transition and documentation.
- NPV calculator — Net present value with a discounted cash flow table.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment