FERPA vs COPPA Compliance: A Practical Guide to Student Data Privacy in 2026
Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.
Why FERPA and COPPA Compliance Both Matter Now
If your organization handles student data — whether you are a school, a school district, an EdTech company, or a third-party vendor — you face a growing compliance challenge. Two federal laws govern student and children’s data privacy: the Family Educational Rights and Privacy Act (FERPA) and the Children’s Online Privacy Protection Act (COPPA). They overlap but are not interchangeable, and violating one is not excused by complying with the other.
The urgency is real. In March 2026, CalPrivacy (the California Privacy Protection Agency) issued a $1.1 million fine against PlayOn Sports — a digital ticketing platform used by about 1,400 California schools — for requiring students to consent to tracking before accessing event tickets, then using that data for targeted advertising. This was the first CPPA enforcement action specifically addressing student privacy, and it signals a new era of enforcement at the intersection of children’s privacy, education, and state consumer privacy laws.
On top of that, the FTC’s amended COPPA Rule became effective June 23, 2025, and its main compliance date passed April 22, 2026, bringing stricter consent requirements, new data retention limits, and expanded definitions of personal information. See our COPPA Compliance Guide for a full breakdown, or work straight through the COPPA Rule amendments compliance checklist if you need the amendment-by-amendment task list. (Source: Federal Register, 90 FR 16918; retrieved 2026-07-21.)
This guide compares FERPA and COPPA, explains where they overlap and diverge, and addresses the third compliance layer: state privacy laws that increasingly apply to educational contexts.
FERPA: Protecting Education Records
FERPA is a federal law that protects the privacy of student education records. It applies to all schools and educational agencies that receive federal funding — which includes virtually every public K–12 school and most colleges and universities in the United States.
Key FERPA Requirements
- Parental rights — Parents have the right to inspect and review their child’s education records, request corrections, and consent to disclosures of personally identifiable information (PII). These rights transfer to the student at age 18 or upon enrollment in postsecondary education.
- Consent before disclosure — Schools generally must obtain written parental consent before disclosing PII from education records to third parties.
- School official exception — Schools may share records with “school officials” who have a “legitimate educational interest.” This exception is how EdTech vendors typically access student data — the school designates them as school officials through a contract or policy.
- Directory information — Schools can designate certain data as “directory information” (name, grade level, participation in activities) and share it without consent, provided parents are given the opportunity to opt out.
FERPA Enforcement
FERPA is enforced by the U.S. Department of Education’s Student Privacy Policy Office (SPPO). The penalty for violations is loss of federal funding — a severe but rarely imposed sanction. FERPA does not provide a private right of action, meaning individuals cannot sue for FERPA violations in court.
COPPA: Protecting Children Under 13 Online
COPPA is a federal law enforced by the FTC that regulates how operators of websites and online services collect personal information from children under 13. Unlike FERPA, COPPA is not limited to educational contexts — it applies to any online service directed at children or that knowingly collects data from children under 13.
Key COPPA Requirements
- Verifiable parental consent — Operators must obtain verifiable parental consent before collecting, using, or disclosing a child’s personal information. The 2026 COPPA Rule amendments now require separate consent for third-party sharing and advertising.
- Privacy notice — Operators must post a clear, comprehensive privacy notice on their site describing their data practices for children’s data.
- Data minimization — Operators cannot condition a child’s participation in an activity on the child providing more personal information than is reasonably necessary.
- Data retention limits (new in 2026) — Operators must establish a written data retention policy, retain children’s data only as long as necessary, and then delete it.
- Data security — Operators must maintain reasonable procedures to protect the confidentiality, security, and integrity of children’s personal information.
COPPA Enforcement
The FTC enforces COPPA with civil penalties of up to $53,088 per violation (2026 amount, adjusted annually for inflation). State attorneys general can also bring COPPA enforcement actions. Recent FTC settlements have ranged from tens of thousands to hundreds of millions of dollars — the 2019 YouTube/Google settlement was $170 million.
FERPA vs COPPA: Key Differences
| Dimension | FERPA | COPPA |
|---|---|---|
| Scope | Education records at federally funded schools | Online services directed at or knowingly collecting data from children under 13 |
| Who it applies to | Schools and educational agencies | Website/app operators (including EdTech vendors) |
| Age threshold | All students (rights transfer at 18) | Children under 13 only |
| Consent requirement | Written parental consent for disclosure (with exceptions) | Verifiable parental consent for collection (limited exceptions) |
| Enforcer | U.S. Department of Education | FTC and state attorneys general |
| Penalties | Loss of federal funding (rarely imposed) | Civil fines up to $53,088 per violation |
| Private right of action | No | No |
| Data retention rules | Schools must maintain records but no deletion mandate | Must delete data when no longer necessary (2026 rule) |
Where FERPA and COPPA Overlap
The critical overlap occurs when an online service used in a school setting collects personal information from students under 13. In this scenario, both laws may apply simultaneously:
- The school is bound by FERPA and must ensure its vendors protect student records
- The vendor (EdTech company, digital ticketing platform, learning management system) may be bound by COPPA if it collects data from children under 13
The FTC has clarified that schools can consent to the collection of student data on behalf of parents under COPPA — but only when the data is used for a school-authorized educational purpose. If the vendor uses student data for commercial purposes (such as advertising, profiling, or selling data to third parties), the school’s consent is not valid under COPPA, and the vendor must obtain direct parental consent.
This is exactly the scenario in the PlayOn Sports case: the platform was used by schools for event ticketing (a school-authorized purpose), but PlayOn deployed tracking technologies to serve targeted ads to ticketholders. Because the advertising use went beyond the school-authorized purpose, the COPPA consent exception did not apply — and CalPrivacy imposed a $1.1 million fine under the CCPA.
Is a Tool “FERPA and COPPA Compliant”? How to Evaluate an EdTech Vendor
No EdTech product is “FERPA compliant” or “COPPA compliant” on its own, and as of August 17, 2026 that is not a technicality — it is where the law puts the conditions. Of the 12 conditions that decide whether a school’s use of a tool is lawful under the two statutes, only 4 can be settled by examining the vendor; the other 8 are terms of the written agreement or steps the school itself must take. FERPA’s school-official route, the route essentially every EdTech vendor relies on, requires that the vendor be “under the direct control of the agency or institution with respect to the use and maintenance of education records” (34 CFR § 99.31(a)(1)(i)(B)(2)) — a condition no feature, certification or trust badge can create, because only your contract can. So the useful question is never “is this tool compliant?” but “which of these 12 conditions does our paperwork actually cover?”
| What has to be true | Under | Settled where | What to ask for or inspect | Source |
|---|---|---|---|---|
| The vendor performs an institutional service or function the school would otherwise use its own employees for. | FERPA | Written agreement | A recital in the agreement naming the institutional function being outsourced. A tool a teacher signed up for on their own has no such recital. | 34 CFR § 99.31(a)(1)(i)(B)(1) (Regulation; retrieved 2026-08-17) |
| The vendor is under the direct control of the school with respect to the use and maintenance of education records. | FERPA | Written agreement | A direct-control clause: the school directs use, the vendor may not change purposes unilaterally, and records are returned or deleted on termination. No product feature can create this. | 34 CFR § 99.31(a)(1)(i)(B)(2) (Regulation; retrieved 2026-08-17) |
| The vendor is contractually subject to § 99.33(a) on the use and redisclosure of education records. | FERPA | Written agreement | An express reference to § 99.33(a) in the agreement, not a generic confidentiality clause. | 34 CFR § 99.31(a)(1)(i)(B)(3) (Regulation; retrieved 2026-08-17) |
| The vendor will not disclose the information to any other party without prior parental (or eligible-student) consent. | FERPA | Written agreement | A no-onward-disclosure term, plus a named subprocessor list so you can tell whether it is already being breached. | 34 CFR § 99.33(a)(1) (Regulation; retrieved 2026-08-17) |
| The vendor’s officers, employees and agents use the information only for the purposes for which the disclosure was made. | FERPA | Written agreement | A purpose-limitation term that names the permitted purpose and excludes product improvement, model training and advertising unless you have agreed to them. | 34 CFR § 99.33(a)(2) (Regulation; retrieved 2026-08-17) |
| The school uses reasonable methods to ensure school officials reach only the records in which they have legitimate educational interests. | FERPA | Your own process | Role-based access configured on your side, or — if you use administrative policy instead of technical controls — a policy the regulation requires you to show is effective. | 34 CFR § 99.31(a)(1)(ii) (Regulation; retrieved 2026-08-17) |
| To rely on the school’s consent, the operator gives the school the same direct notice of its collection, use and disclosure practices it would otherwise give a parent. | COPPA | Ask the vendor | The direct notice itself. Ask for the document; a link to the general privacy policy is not it. | FTC, Complying with COPPA: Frequently Asked Questions, FAQ N.1–N.2 (FTC guidance; retrieved 2026-08-17) |
| On the school’s request the operator provides a description of the types of personal information collected, an opportunity to review it and have it deleted, and a way to stop further use or collection. | COPPA | Ask the vendor | A named route for each of the three — review, delete, stop — reachable by a school administrator rather than by each parent. | FTC, Complying with COPPA: Frequently Asked Questions, FAQ N.1 (FTC guidance; retrieved 2026-08-17) |
| The operator’s method of taking school consent is reasonably calculated to ensure a school is actually giving it — not a child posing as a teacher. | COPPA | Ask the vendor | Domain-verified or administrator-provisioned accounts. A self-serve "I am a teacher" checkbox is the failure this condition names. | FTC, Complying with COPPA: Frequently Asked Questions, FAQ N.2 (FTC guidance; retrieved 2026-08-17) |
| The operator does not state in its Terms of Service or anywhere else that the school is responsible for COPPA compliance — under the Rule that responsibility is the operator’s. | COPPA | Ask the vendor | Search the vendor’s ToS for "COPPA". A clause making you responsible for it is the one red flag you can find in minutes, before any contract exists. | FTC, Complying with COPPA: Frequently Asked Questions, FAQ N.1 (FTC guidance; retrieved 2026-08-17) |
| Data is collected for the use and benefit of the school and for no other commercial purpose; any commercial use beyond that needs consent from parents, not the school. | COPPA | Written agreement | A no-secondary-use term. This is the condition the PlayOn Sports facts turned on: a school-authorized purpose does not stretch to advertising. | FTC, Complying with COPPA: Frequently Asked Questions, FAQ N.2 (FTC guidance; retrieved 2026-08-17) |
| The school or district — not an individual teacher — decides whether a service’s information practices are acceptable. | COPPA | Your own process | A district approval list. The FTC frames this as a recommended best practice rather than a Rule requirement, so it is leverage you give yourself, not a demand you can make of a vendor. | FTC, Complying with COPPA: Frequently Asked Questions, FAQ N.3 (FTC recommended practice; retrieved 2026-08-17) |
Notice which column the COPPA rows cite. 16 CFR § 312.5 — the Rule’s parental-consent section, including its list of exceptions to prior parental consent — does not mention schools at all: the school-consent framework is FTC staff guidance interpreting the Rule, not a codified exception inside it (checked 2026-08-17). That matters in procurement, because a vendor cannot point to a Rule exception it is operating under; it can only show you that it follows the guidance. The FTC also notes that the school’s agreement with an operator “must also be reviewed under the school official exception or other applicable exception under FERPA” — the two instruments are cumulative, and satisfying one says nothing about the other. (Source: 16 CFR § 312.5, eCFR; date_retrieved: 2026-08-17.)
The fastest check on this list needs nothing from the vendor: search its Terms of Service for “COPPA”. The FTC’s guidance is explicit that operators “should not state in Terms of Service or anywhere else that the school is responsible for complying with COPPA, as it is the responsibility of the operator to comply with the Rule.” A vendor that pushes COPPA responsibility onto you in its own contract is telling you, in writing, that it has read the framework and decided you should carry it. (Source: FTC, Complying with COPPA: Frequently Asked Questions, FAQ N.1; date_retrieved: 2026-08-17.)
Read the “Settled where” column before you read anything a vendor has published about itself. A tool can hold every certification on the market and still fail 8 of these 12 conditions, because those 8 are not about the tool. Conversely, a plain product with a properly drafted agreement and district-level approval can satisfy all 12. This is also why a teacher signing up for a free classroom app is the single highest-risk pattern in K–12: it produces no agreement at all, so 6 conditions fail simultaneously and the school — not the teacher — is the FERPA-covered party.
The Third Layer: State Privacy Laws
Beyond FERPA and COPPA, EdTech companies and school vendors now face a growing patchwork of state comprehensive privacy laws. COPPA stops at the child’s 13th birthday; 17 of the 20 state comprehensive privacy laws in force reach past it, so a high-school deployment that is outside COPPA entirely can still be squarely inside a state law. Every in-force law is listed below — not just the large states — and each row is generated from the same statutory dataset behind our state law pages, so it cannot drift out of step with them.
| State (law) | Ages protected above 13 | Mechanism | Note |
|---|---|---|---|
| Connecticut (CTDPA) | under 18 | Prohibited outright — consent does not cure | SB 1295 (Public Act 25-113), in force since July 1, 2026, bars processing any minor's data for targeted advertising or sale outright - consent does not cure it. |
| Florida (FDBR) | under 18 | Prohibited outright — consent does not cure | The FDBR bars covered social-media platforms from processing under-13 data and requires age-appropriate defaults and processing limits for teens under 18. |
| Maryland (MODPA) | under 18 | Prohibited outright — consent does not cure | MODPA bars the sale of any consumer's data under 18 and bars targeted advertising to minors outright - there is no consent that cures it. |
| Oregon (OCPA) | under 16 | Prohibited outright — consent does not cure | HB 2008 bars the sale of personal data outright once the controller actually knows the consumer is under 16; consent still governs targeted advertising for 13-to-15-year-olds. |
| California (CCPA/CPRA) | under 16 | Teen’s own opt-in consent | Opt-in consent required before selling or sharing the data of a consumer under 16; the CPRA triples the penalty cap for violations involving minors. |
| Colorado (CPA) | 13-17 | Teen’s own opt-in consent | SB 24-041 added an age-appropriate design code and opt-in consent for targeted advertising and sale of 13-to-17-year-olds' data. |
| Delaware (DPDPA) | 13-17 | Teen’s own opt-in consent | Consent required before processing a 13-to-17-year-old's data for targeted advertising or sale. |
| Indiana (INCDPA) | 13-17 | Teen’s own opt-in consent | Opt-in consent required before processing a 13-to-17-year-old's data for targeted advertising or sale; protections attach to known children, with no age-verification mandate. |
| Kentucky (KCDPA) | 13-17 | Teen’s own opt-in consent | Consent required before processing a 13-to-17-year-old's data for targeted advertising or sale. |
| Minnesota (MCDPA) | 13-16 | Teen’s own opt-in consent | Targeted advertising and sale are barred without consent once the controller knows the consumer is between 13 and 16. |
| Montana (MCDPA) | 13-15 | Teen’s own opt-in consent | SB 297 requires the consumer's consent before selling or targeting advertising to someone the controller knows is at least 13 and under 16, plus a duty of care toward minors. |
| Nebraska (NDPA) | 13-17 | Teen’s own opt-in consent | Consent required for targeted advertising and sale involving teens; LB 504's age-appropriate design code separately covers users under 18. |
| New Hampshire (NHPA) | 13-17 | Teen’s own opt-in consent | Affirmative consent required for targeted advertising or sale involving 13-to-17-year-olds; willfully disregarding age counts as actual knowledge. |
| New Jersey (NJDPA) | under 17 | Teen’s own opt-in consent | Affirmative consent required before selling the data of, or targeting advertising to, a consumer under 17. |
| Rhode Island (RIDTPPA) | 13-17 | Teen’s own opt-in consent | Opt-in consent required for targeted advertising or sale involving 13-to-17-year-olds, with no cure period before the AG can act. |
| Tennessee (TIPA) | 13-17 | Teen’s own opt-in consent | Affirmative opt-in required before processing a 13-to-17-year-old's data for targeted advertising or sale. |
| Virginia (VCDPA) | 13-17 | Teen’s own opt-in consent | Consent required before processing a 13-to-17-year-old's data for targeted advertising or sale. |
| Iowa (ICDPA) | None — COPPA only | Nothing above 13 | The ICDPA defers to COPPA for known children and adds no teen tier. |
| Texas (TDPSA) | None — COPPA only | Nothing above 13 | The TDPSA's consent requirement runs on known children under 13; Texas's under-18 rules sit in the separate SCOPE Act, not in the privacy statute. |
| Utah (UCPA) | None — COPPA only | Nothing above 13 | The UCPA adds no teen tier above COPPA's under-13 line. |
The 4 states in the “prohibited outright” tier are the ones that change EdTech product decisions rather than just consent copy: where the practice is banned for a minor, obtaining the teen’s consent — or the school’s — does not cure it. The CalPrivacy enforcement against PlayOn shows state agencies will pursue EdTech vendors on these grounds even where the FTC does not act.
Additionally, many states have enacted student-specific privacy laws (separate from their comprehensive privacy laws) that restrict how student data can be used by EdTech vendors. California’s Student Online Personal Information Protection Act (SOPIPA), for example, prohibits EdTech vendors from using student data for non-educational advertising purposes.
Use our Privacy Law Calculator to check which state privacy laws apply to your organization based on your user counts and revenue.
Compliance Checklist: Navigating FERPA, COPPA, and State Laws Together
If your organization handles student data or data from children under 13 in an educational context, use this checklist to assess your compliance posture across all three layers:
1. Determine Which Laws Apply
- Does your organization receive federal education funding? → FERPA applies
- Does your online service collect data from children under 13? → COPPA applies
- Do you have users in states with comprehensive privacy laws? → Check each state. Use the Privacy Law Calculator
- Are you an EdTech vendor contracting with schools? → Likely subject to FERPA (as a school official), COPPA, and applicable state laws simultaneously
2. Map Your Data Flows
- What personal information do you collect from students and children?
- How is it used? Distinguish educational purposes from commercial purposes (advertising, analytics, profiling)
- Who receives the data? Identify all third-party recipients — ad networks, analytics providers, data brokers
- Under the 2026 COPPA Rule, you must identify every third party by name in your direct notice to parents
3. Implement Proper Consent Mechanisms
- For FERPA: obtain written consent from parents before disclosing student records, or ensure the school official exception applies with a proper contract
- For COPPA: obtain verifiable parental consent before collecting children’s data. Schools can consent on behalf of parents only for school-authorized educational purposes
- For COPPA (2026 rule): obtain separate consent for third-party sharing and advertising — bundled consent no longer works
- For state laws: check whether each applicable state requires opt-in consent for processing children’s data for advertising. Most do.
4. Establish Data Retention and Deletion Policies
- Under the 2026 COPPA Rule, you must have a written data retention policy specifying how long you keep children’s data and when it is deleted
- State privacy laws grant consumers (including parents on behalf of children) the right to deletion
- See our Data Retention Policy Guide for building a compliant retention schedule
5. Review Vendor Contracts
- If you are a school: ensure your EdTech vendor contracts include FERPA-compliant provisions designating the vendor as a school official, limiting data use to educational purposes, and requiring data deletion after the contract ends
- If you are a vendor: ensure your contracts with schools clearly define permitted data uses and comply with the data processing agreement requirements of applicable state laws
- The Tractor Supply and PlayOn enforcement cases both involved inadequate vendor contracts — regulators are checking this
6. Prohibit Advertising Use of Student Data
- Do NOT use student data collected under a school contract for targeted advertising, profiling, or any commercial purpose beyond the educational service
- Do NOT deploy tracking technologies (cookies, pixels, fingerprinting) on educational platforms without proper consent
- If your platform serves both educational and commercial users, implement technical controls to separate these data streams
- This was the core violation in the PlayOn case — using school-authorized data for advertising without proper opt-out mechanisms
Lessons From the PlayOn Sports Enforcement
The March 2026 CalPrivacy enforcement against PlayOn Sports is a blueprint for future cases at the intersection of education and consumer privacy. Key takeaways:
- School authorization does not cover advertising — A school’s agreement to use your platform does not constitute consent for you to use student data for advertising. The COPPA school consent exception is narrowly limited to educational purposes.
- Opt-out friction is enforcement bait — PlayOn directed users to third-party ad industry opt-out tools instead of providing its own opt-out mechanism. CalPrivacy and dark pattern enforcement trends make clear that businesses must operate their own, easy-to-use opt-out.
- State AGs will enforce even where the FTC does not — The PlayOn case was brought under the CCPA, not COPPA. State privacy laws give additional enforcers the power to pursue student privacy violations that might otherwise fall through federal enforcement gaps.
- Student privacy is a multiplier — Violations involving children and students attract higher scrutiny, larger fines, and more public attention. The $1.1 million fine was significant for a company of PlayOn’s size.
For a detailed analysis of the PlayOn case, see our PlayOn Sports CCPA Fine guide.
What EdTech Operators Should Do Now
Because the amended COPPA Rule’s main compliance date has passed, EdTech companies and school vendors should close any remaining gaps now:
- Audit third-party data sharing — Identify every third party receiving children’s data and prepare to obtain separate consent for each
- Update your privacy notice — Ensure it identifies third-party recipients by name and category, describes data retention periods, and explains the new separate consent requirements
- Implement a data retention policy — Create a written policy specifying retention periods and deletion procedures for children’s data
- Review consent flows — Ensure your consent mechanism collects separate consent for third-party sharing vs. data collection. Use our Cookie Consent Checker to verify your current approach
- Disable advertising tracking on educational services — If you cannot obtain proper consent, disable all advertising-related tracking on platforms used by students
Frequently Asked Questions
Does FERPA apply to EdTech companies?
Not directly. FERPA applies to schools and educational agencies that receive federal funding. However, EdTech companies become subject to FERPA requirements when a school designates them as “school officials” under a contract. In that role, the vendor must use student data only for the school-authorized educational purpose and comply with the school’s FERPA obligations. If the vendor uses data for commercial purposes, it violates the terms of the school official designation.
Can schools consent to COPPA on behalf of parents?
Yes, but only for school-authorized educational purposes. The FTC has clarified that schools can act as agents for parents under COPPA when an online service is used for a legitimate educational purpose. This consent does NOT extend to commercial uses such as advertising, profiling, or selling data. If a vendor uses student data for any non-educational commercial purpose, it must obtain direct verifiable parental consent.
What is the penalty for violating both FERPA and COPPA?
The penalties differ. FERPA violations can result in loss of federal funding for the school. COPPA violations can result in FTC civil penalties of up to $53,088 per violation. In practice, COPPA fines have reached into millions of dollars for large-scale violations. Additionally, state privacy law violations add another layer — CalPrivacy’s $1.1 million PlayOn fine demonstrates that state-level fines for student privacy violations are significant and growing.
Do state privacy laws apply to student data?
Yes. Most state comprehensive privacy laws apply to student data unless it falls within the FERPA exemption. The FERPA data exemption in state laws (similar to HIPAA and GLBA exemptions) typically applies only to education records maintained by a FERPA-covered school or its designated school officials. Data collected by an EdTech company outside the FERPA framework is subject to state privacy laws. Check our state comparison tool to see how each state handles educational data exemptions.
Is the CCPA FERPA exemption the same as the COPPA exemption?
No. The CCPA exempts FERPA-protected education records at the data level — meaning those specific records are excluded from CCPA requirements. Separately, COPPA compliance does not exempt a company from the CCPA. The PlayOn case illustrates this: even though FERPA may have governed some of the student data in the school context, the advertising-related data collection fell outside both the FERPA framework and any CCPA exemption, making it subject to CalPrivacy enforcement.
Is [my EdTech tool] FERPA and COPPA compliant?
Not a question the product can answer. Of the 12 conditions that decide whether a school’s use of a tool is lawful under FERPA and COPPA, only 4 can be settled by examining the vendor — the rest are terms of your written agreement or steps your district takes. FERPA’s school-official route requires the vendor to be “under the direct control” of the school over the use and maintenance of education records (34 CFR § 99.31(a)(1)(i)(B)(2)), which only a contract can establish. Work the due-diligence table against your paperwork rather than against a vendor’s compliance page.
What should a school ask an EdTech vendor before approving it?
The 4 things the vendor alone can answer: the direct notice it would give a parent, and that it will give that notice to you instead; named routes for a school administrator to review, delete, and stop further collection of student data; how it verifies that a real school is granting consent rather than a student posing as a teacher; and whether its Terms of Service try to make you responsible for COPPA compliance, which the FTC says operators should not do. Everything else belongs in the agreement.
Does a teacher signing up for a free classroom app create a FERPA problem?
Usually, yes — and the exposure sits with the school, not the teacher. FERPA’s school-official exception is available only where the outsourced party is under the school’s direct control and is contractually subject to 34 CFR § 99.33(a) on use and redisclosure. A self-serve signup produces no agreement, so 6 of the 12 conditions fail at once. The FTC separately recommends that the school or district, rather than an individual teacher, decide whether a service’s information practices are acceptable.
Is the COPPA school-consent rule actually in the COPPA Rule?
No. 16 CFR § 312.5 — the Rule’s parental-consent section and its list of exceptions — does not mention schools at all (checked 2026-08-17). Schools acting as the parent’s agent is FTC staff guidance interpreting the Rule, not a codified exception. Practically, that means a vendor cannot cite a Rule exception it operates under; it can only show it follows the guidance — and the FTC states that responsibility for COPPA compliance remains the operator’s regardless of what its contract with you says.
Last updated: August 17, 2026.Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.