FERPA and K-5 SEL curriculum compliance

FERPA and K-5 SEL Curriculum

What Districts Should Ask Vendors

Math Platform Data

  • • Scores
  • • Time on task
  • • Problem completion rates

Academic performance data

SEL Platform Data

  • • How a 7-year-old responded about feeling sad
  • • What a 9-year-old wrote about conflict at home
  • • Emotional regulation assessment scores
  • • Behavioral intervention flags

Emotional and psychological data about children

The question every district should ask before purchasing an SEL curriculum is not just whether the vendor is FERPA-compliant. It is whether the curriculum needs to collect student data at all.

Three Federal Laws, One Problem

FERPA

Education Records

Protects students' education records and gives parents rights to access, review, and request corrections. Applies to every public school receiving federal funding.[1]

SEL implication: If your vendor stores student-level data, you need a FERPA-compliant data sharing agreement specifying what is collected, how it is used, retention periods, and what happens when the contract ends.

COPPA

Children Under 13

Regulates collection of personal information from children under 13. Requires verifiable parental consent. Schools can consent on behalf of parents only for educational purposes.[2]

SEL implication: Elementary students are almost entirely under 13. If the vendor uses data for product development, marketing, or any purpose beyond education, school consent is insufficient.

PPRA

Sensitive Surveys

Governs surveys collecting sensitive information. Two categories directly relevant to SEL: “mental or psychological problems” and “illegal, anti-social, incriminating, or demeaning behavior.”[3]

SEL implication: Any check-in, assessment, or prompt asking about emotions or family life may trigger PPRA. A question like “How are you feeling today?” can elicit responses about sensitive topics.

Why SEL Data Is Different

A reading level assessment tells you how well a student reads. An SEL assessment tells you how a student feels, how they cope, what stresses them, and what is happening in their emotional world. This data reveals a child's interior life — stored digitally, subject to breaches, vendor acquisitions, and gradual scope expansion.

4,388

cyberattacks per organization per week in education (Q2 2025) — 31% year-over-year increase[4]

$17.25M

PowerSchool breach settlement with Chicago Public Schools (Dec 2024)[5]

Over the past decade, nearly 150 new state student privacy laws have passed across 40+ states. Twenty states have comprehensive privacy laws in effect as of 2026. Every SEL vendor that collects student data adds a compliance obligation.[7][8]

What Districts Should Ask Vendors

1

Does this product create student accounts?

If yes → triggers FERPA data sharing + COPPA obligations. If no → zero compliance burden at the student data level.

2

What student data does it collect, and where is it stored?

Ask for a complete inventory: names, emails, credentials, behavioral data, mood check-ins, written reflections, usage patterns, metadata. If the vendor can't produce this clearly, they don't control the data.

3

Does it include assessments or check-ins about emotions, family life, or behavior?

If yes → may trigger PPRA. Review every question for potential to elicit information about mental/psychological problems, even unintentionally.

4

How long is student data retained? What happens when the contract ends?

Some vendors retain data indefinitely. Get retention policy and deletion/return procedures in writing — in the agreement, not a sales conversation.

5

Has the vendor experienced a data breach?

A breach isn't automatically disqualifying. The response (speed of notification, remediation, transparency) reveals how the vendor treats data security when it matters most.

6

Is data used for any purpose beyond the specified educational use?

COPPA requires data from children under 13 be used only for the specified educational purpose. Product development, algorithm training, aggregated analytics sold to third parties — if the vendor hedges, the answer is yes.

7

What happens if the vendor is acquired?

Vendor acquisitions are common in edtech. The acquiring company inherits the data. If the agreement is silent on this, students' emotional data could end up with a company you never vetted.

8

Does the product require student devices?

Device-dependent products create additional data collection points and introduce the adoption barriers documented in edtech research.

The Simplest Compliance Strategy

The most effective way to protect student privacy in SEL instruction is to eliminate the data collection that creates the compliance burden.

A curriculum with no student accounts:

FERPA

No data sharing agreement needed

COPPA

No obligations triggered

PPRA

No digital surveys or check-ins

Breaches

Zero exposure — no data on vendor servers

A teacher-led, device-free curriculum where the teacher projects content and the class participates together produces the same instructional outcomes — without generating any of the data that creates compliance obligations.

Curriculum teaches. Screeners measure. They don't need to be the same product.

For districts that want individual student-level SEL data, universal screeners like DESSA or Panorama provide that function through validated instruments with privacy protections built around their data sensitivity. Separating curriculum from measurement allows each to be evaluated on its own merits and compliance profile.

A Note on Trust

Student data privacy is not solely a compliance question. It is a trust question.

With student accounts:

“What are you doing with my child's data?”

Without student accounts:

“What skills is my child learning?”

The second conversation is the one every school wants to have.

References

  1. U.S. Department of Education, Student Privacy Policy Office. Protecting Student Privacy (FERPA). studentprivacy.ed.gov
  2. Future of Privacy Forum. Student Privacy Primer: COPPA. fpf.org
  3. Public Interest Privacy Center. Mitigating Risks in Student Surveys: An Overview of PPRA. publicinterestprivacy.org
  4. Secure Privacy. Privacy Software for Schools: Protecting Student Data and Staying Compliant. secureprivacy.ai
  5. Parent Coalition for Student Privacy. PowerSchool Settlement. studentprivacymatters.org
  6. University of Washington. A Privacy by Design Framework for LLM-Based Applications for Children. arxiv.org
  7. Career Clutch. Vendor Compliance Criteria for School Partnerships (2026). careerclutch.ai
  8. Student Privacy Compass. PPRA FAQs. studentprivacycompass.org

Zero Student Data. Zero Compliance Risk.

Be The Buffalo collects no student data. No accounts. No logins. No digital surveys. No emotional data on vendor servers. The teacher projects the lesson. The class participates together. Full SEL instruction with zero privacy compliance burden.

Sign Up Free

Related Resources