📅 Book a 30-min Demo📞 Call/text (571) 293-0242
Higher Education · AI Course · HE-1

FERPA-Compliant AI: Deploying Agents on Student Data

Run AI agents against your SIS and LMS without a vendor ever seeing a student record — the school official exception, vendor DPAs, and the architecture FERPA implies.

Last updated:

The Short Answer

FERPA does not ban AI on student records — it governs who may see them. ibl.ai runs advising and enrollment agents against your SIS and LMS under the school official exception, self-hosted inside your own perimeter, where you own all the code and the data. No third-party vendor ever receives an education record, so the disclosure question never arises.

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

The full course design is published below — every module, its objectives and hands-on activity, the capstone, and every source it cites.

What is this course about?

FERPA is the first question every campus AI project runs into and the one most vendors answer badly. This course works through what the statute actually regulates, why 'the vendor is SOC 2 certified' answers a different question entirely, and how the deployment architecture you choose either creates a disclosure problem or removes it. It ends with a working advising agent that answers from the SIS without exporting a single record.

Who is this course for?

  • Registrars and student records staff
  • CIOs, CTOs, and IT directors evaluating AI vendors
  • General counsel and privacy officers
  • Provosts and deans sponsoring an AI initiative

What do I need before starting?

  • Working familiarity with your institution's SIS and LMS
  • No legal or technical background required

What will I be able to do afterwards?

  • Classify any campus data set as an education record, directory information, or out of scope
  • Apply the school official exception to a specific vendor arrangement and defend the reasoning
  • Read an AI vendor DPA and identify the four clauses that decide FERPA exposure
  • Trace where student data physically travels in a hosted, VPC, and on-premise deployment
  • Assemble the audit evidence a regional accreditor or OCR complaint would require

What does each module cover?

1

What actually counts as an education record?

45 min

The definitional work that every later decision rests on — and the categories that routinely get misfiled in both directions.

Objectives

  • Distinguish education records from directory information and sole-possession notes
  • Identify which campus systems hold records subject to FERPA
  • Explain why over-classifying is as costly as under-classifying

Topics

Education record definitionDirectory information and opt-outsSole-possession and law enforcement exceptionsSystem-by-system data inventory

Activity. Inventory five campus systems and classify each data element, flagging the ambiguous ones for counsel.

2

How does the school official exception decide your architecture?

45 min

The single clause that determines whether an AI vendor arrangement is lawful, and the four conditions it imposes.

Objectives

  • State the four conditions of the school official exception
  • Apply the 'direct control' test to a real vendor relationship
  • Explain why the exception constrains architecture, not just paperwork

Topics

Legitimate educational interestDirect control requirementRedisclosure limitsAnnual notification obligations

Activity. Score a live vendor arrangement against all four conditions and write the one-paragraph justification.

3

Why doesn't a SOC 2 certificate answer the FERPA question?

40 min

Security attestations and privacy obligations are different axes; conflating them is the most common vendor-evaluation error on campus.

Objectives

  • Separate security posture from privacy authority
  • Identify what SOC 2, ISO 27001, and HECVAT each do and do not establish
  • Ask the four questions a security certificate cannot answer

Topics

SOC 2 scope and limitsHECVAT in practiceCertification versus authorityVendor questionnaire design

Activity. Rewrite your institution's vendor questionnaire to separate security from privacy authority.

4

How do you read an AI vendor's data processing agreement?

50 min

The clauses that decide exposure — model training rights, retention, subprocessors, and what happens at termination.

Objectives

  • Locate and interpret the model-training clause in a vendor agreement
  • Evaluate retention and deletion terms against your records schedule
  • Assess subprocessor disclosure and redisclosure risk

Topics

Training-rights clausesRetention and destructionSubprocessor chainsTermination and data return

Activity. Redline a real AI vendor DPA, marking every clause that would fail a FERPA review.

5

Where does student data physically go in each deployment model?

50 min

Tracing an advising question request-by-request through hosted SaaS, private VPC, and on-premise deployments.

Objectives

  • Diagram the data path for a single student query in three architectures
  • Identify every point at which a record crosses an organizational boundary
  • Explain why self-hosting removes the disclosure question rather than mitigating it

Topics

Hosted SaaS data flowPrivate VPC boundariesOn-premise and air-gapped deploymentInference-time data exposure

Activity. Draw the data-flow diagram for your own intended deployment and mark each boundary crossing.

6

What audit evidence proves compliance to an accreditor?

40 min

Building the logging, notification, and access-review artifacts before anyone asks for them.

Objectives

  • Specify the audit log fields a FERPA review requires
  • Draft the AI disclosure language for the annual notification
  • Design an access review cadence tied to role changes

Topics

Audit log designAnnual notification contentAccess review cadenceAccreditation and OCR evidence

Activity. Write the AI paragraph for your institution's annual FERPA notification.

7

What do you do when an agent surfaces the wrong student's record?

45 min

Incident response for AI-specific failure modes, which behave differently from a conventional data breach.

Objectives

  • Recognize AI-specific disclosure failure modes
  • Run the containment sequence for a retrieval permissions failure
  • Determine notification obligations and document the determination

Topics

Retrieval permission failuresPrompt-injection disclosureContainment sequenceNotification determination

Activity. Tabletop a permissions-failure incident end to end, producing the written determination.

8

Building an advising agent that never exports a record

65 min

The hands-on module: a working agent that answers SIS-grounded questions with role-inherited permissions.

Objectives

  • Configure role-based retrieval so an agent inherits the user's permissions
  • Ground responses in the SIS without bulk extraction
  • Verify with a test suite that the agent cannot answer across student boundaries

Topics

Role-inherited retrievalQuery-time groundingPermission test suitesDeployment verification

Activity. Deploy the agent in a lab environment and run the cross-boundary test suite until it passes clean.

What is the capstone project?

FERPA readiness review for one live AI use case

Take a real AI initiative at your institution and produce the complete compliance package: data classification, school official exception justification, vendor DPA assessment, data-flow diagram, audit plan, and incident response annex.

Deliverable: A review document a general counsel could sign and an accreditor could inspect.

How are learners assessed?

  • Scenario questions requiring classification of ambiguous data elements
  • Redline exercise scored against a rubric of the four decisive DPA clauses
  • Capstone reviewed against the stated learning outcomes

What ships with the course?

Facilitator guide

Session-by-session running order, discussion prompts, and the questions that reliably derail a room.

Learner workbook

Exercises, checklists, and the templates each module's activity produces.

Hands-on lab environment

A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.

Assessment bank

Scenario questions and rubric criteria mapped to each stated learning outcome.

Source bibliography

Every primary regulation and standard cited on this page, linked and dated.

Which AI agents does this course use?

The hands-on modules run against agents already deployable on the ibl.ai platform for higher education.

Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

Delivery notes

Binding guidance for anyone preparing and delivering this course.

  • Module 2 is the load-bearing one. If a learner leaves without being able to state the four conditions of the school official exception from memory, the course has failed regardless of what else they retained.
  • Do not let this become a legal-advice course. Every module frames the analysis and names where institutional counsel must decide. Include an explicit disclaimer slide.
  • The Module 8 lab needs a synthetic SIS with at least 200 fictional student records and a deliberately mis-scoped role, so the cross-boundary test suite actually fails on first run.
  • Keep the vendor DPA in Module 4 anonymized and composite. Do not use a named competitor's real agreement.
  • Regulatory currency matters here — re-verify the eCFR citation and any ED guidance at each revision, and bump lastUpdated when they change.

Why run AI training on a platform you own?

You own the course, not a licence to it

Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.

Model-agnostic delivery

Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.

No per-seat training licences

Usage-based or self-hosted, so cost tracks actual use rather than headcount.

Deploy anywhere

Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

Frequently asked questions

What does the FERPA-Compliant AI: Deploying Agents on Student Data course cover?

FERPA is the first question every campus AI project runs into and the one most vendors answer badly. This course works through what the statute actually regulates, why 'the vendor is SOC 2 certified' answers a different question entirely, and how the deployment architecture you choose either creates a disclosure problem or removes it. It ends with a working advising agent that answers from the SIS without exporting a single record. It runs 6 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: FERPA readiness review for one live AI use case.

Who should take FERPA-Compliant AI: Deploying Agents on Student Data?

It is written for Registrars and student records staff, CIOs, CTOs, and IT directors evaluating AI vendors, General counsel and privacy officers, Provosts and deans sponsoring an AI initiative. Prerequisites: Working familiarity with your institution's SIS and LMS; No legal or technical background required.

Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for higher education teams that cannot send work to a public AI tool.

How do we get access to FERPA-Compliant AI: Deploying Agents on Student Data?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

How much does AI training for higher education cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

Request access to FERPA-Compliant AI: Deploying Agents on Student Data

Tell us about your cohort and we will set it up — hosted by ibl.ai, or running against your own deployment, where you own all the code and the data.