# FERPA-Compliant AI: Deploying Agents on Student Data

> Higher Education · AI Course · HE-1
> Source: https://ibl.ai/solutions/higher-education/course/ferpa-compliant-ai
> Last updated: 2026-08-25

**Run AI agents against your SIS and LMS without a vendor ever seeing a student record — the school official exception, vendor DPAs, and the architecture FERPA implies.**

## The Short Answer

**FERPA does not ban AI on student records — it governs who may see them. ibl.ai runs advising and enrollment agents against your SIS and LMS under the school official exception, self-hosted inside your own perimeter, where you own all the code and the data. No third-party vendor ever receives an education record, so the disclosure question never arises.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore Higher Education](https://ibl.ai/solutions/higher-education)

## Course facts

- **Level:** Foundational
- **Duration:** 6 hours across 8 modules
- **Format:** Cohort workshop or self-paced, with a hands-on lab
- **Modules:** 8
- **Catalog code:** HE-1
- **Frameworks covered:** FERPA, 34 CFR Part 99, NIST AI RMF

## What is this course about?

FERPA is the first question every campus AI project runs into and the one most vendors answer badly. This course works through what the statute actually regulates, why 'the vendor is SOC 2 certified' answers a different question entirely, and how the deployment architecture you choose either creates a disclosure problem or removes it. It ends with a working advising agent that answers from the SIS without exporting a single record.

## Who is this course for?

- Registrars and student records staff
- CIOs, CTOs, and IT directors evaluating AI vendors
- General counsel and privacy officers
- Provosts and deans sponsoring an AI initiative

### What do I need before starting?

- Working familiarity with your institution's SIS and LMS
- No legal or technical background required

## What will I be able to do afterwards?

- Classify any campus data set as an education record, directory information, or out of scope
- Apply the school official exception to a specific vendor arrangement and defend the reasoning
- Read an AI vendor DPA and identify the four clauses that decide FERPA exposure
- Trace where student data physically travels in a hosted, VPC, and on-premise deployment
- Assemble the audit evidence a regional accreditor or OCR complaint would require

## What does each module cover?

### Module 1 — What actually counts as an education record?

The definitional work that every later decision rests on — and the categories that routinely get misfiled in both directions. _(45 min)_

**Objectives**

- Distinguish education records from directory information and sole-possession notes
- Identify which campus systems hold records subject to FERPA
- Explain why over-classifying is as costly as under-classifying

**Topics:** Education record definition · Directory information and opt-outs · Sole-possession and law enforcement exceptions · System-by-system data inventory

**Activity:** Inventory five campus systems and classify each data element, flagging the ambiguous ones for counsel.

### Module 2 — How does the school official exception decide your architecture?

The single clause that determines whether an AI vendor arrangement is lawful, and the four conditions it imposes. _(45 min)_

**Objectives**

- State the four conditions of the school official exception
- Apply the 'direct control' test to a real vendor relationship
- Explain why the exception constrains architecture, not just paperwork

**Topics:** Legitimate educational interest · Direct control requirement · Redisclosure limits · Annual notification obligations

**Activity:** Score a live vendor arrangement against all four conditions and write the one-paragraph justification.

### Module 3 — Why doesn't a SOC 2 certificate answer the FERPA question?

Security attestations and privacy obligations are different axes; conflating them is the most common vendor-evaluation error on campus. _(40 min)_

**Objectives**

- Separate security posture from privacy authority
- Identify what SOC 2, ISO 27001, and HECVAT each do and do not establish
- Ask the four questions a security certificate cannot answer

**Topics:** SOC 2 scope and limits · HECVAT in practice · Certification versus authority · Vendor questionnaire design

**Activity:** Rewrite your institution's vendor questionnaire to separate security from privacy authority.

### Module 4 — How do you read an AI vendor's data processing agreement?

The clauses that decide exposure — model training rights, retention, subprocessors, and what happens at termination. _(50 min)_

**Objectives**

- Locate and interpret the model-training clause in a vendor agreement
- Evaluate retention and deletion terms against your records schedule
- Assess subprocessor disclosure and redisclosure risk

**Topics:** Training-rights clauses · Retention and destruction · Subprocessor chains · Termination and data return

**Activity:** Redline a real AI vendor DPA, marking every clause that would fail a FERPA review.

### Module 5 — Where does student data physically go in each deployment model?

Tracing an advising question request-by-request through hosted SaaS, private VPC, and on-premise deployments. _(50 min)_

**Objectives**

- Diagram the data path for a single student query in three architectures
- Identify every point at which a record crosses an organizational boundary
- Explain why self-hosting removes the disclosure question rather than mitigating it

**Topics:** Hosted SaaS data flow · Private VPC boundaries · On-premise and air-gapped deployment · Inference-time data exposure

**Activity:** Draw the data-flow diagram for your own intended deployment and mark each boundary crossing.

### Module 6 — What audit evidence proves compliance to an accreditor?

Building the logging, notification, and access-review artifacts before anyone asks for them. _(40 min)_

**Objectives**

- Specify the audit log fields a FERPA review requires
- Draft the AI disclosure language for the annual notification
- Design an access review cadence tied to role changes

**Topics:** Audit log design · Annual notification content · Access review cadence · Accreditation and OCR evidence

**Activity:** Write the AI paragraph for your institution's annual FERPA notification.

### Module 7 — What do you do when an agent surfaces the wrong student's record?

Incident response for AI-specific failure modes, which behave differently from a conventional data breach. _(45 min)_

**Objectives**

- Recognize AI-specific disclosure failure modes
- Run the containment sequence for a retrieval permissions failure
- Determine notification obligations and document the determination

**Topics:** Retrieval permission failures · Prompt-injection disclosure · Containment sequence · Notification determination

**Activity:** Tabletop a permissions-failure incident end to end, producing the written determination.

### Module 8 — Building an advising agent that never exports a record

The hands-on module: a working agent that answers SIS-grounded questions with role-inherited permissions. _(65 min)_

**Objectives**

- Configure role-based retrieval so an agent inherits the user's permissions
- Ground responses in the SIS without bulk extraction
- Verify with a test suite that the agent cannot answer across student boundaries

**Topics:** Role-inherited retrieval · Query-time grounding · Permission test suites · Deployment verification

**Activity:** Deploy the agent in a lab environment and run the cross-boundary test suite until it passes clean.

## What is the capstone project?

**FERPA readiness review for one live AI use case.** Take a real AI initiative at your institution and produce the complete compliance package: data classification, school official exception justification, vendor DPA assessment, data-flow diagram, audit plan, and incident response annex.

_Deliverable:_ A review document a general counsel could sign and an accreditor could inspect.

## How are learners assessed?

- Scenario questions requiring classification of ambiguous data elements
- Redline exercise scored against a rubric of the four decisive DPA clauses
- Capstone reviewed against the stated learning outcomes

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Academic Advisor Agent](https://ibl.ai/solutions/higher-education/agent/academic-advisor-agent)
- [Student Services Agent](https://ibl.ai/solutions/higher-education/agent/student-services-agent)
- [Enrollment Agent](https://ibl.ai/solutions/higher-education/agent/enrollment-agent)
- [IT Help Desk Agent](https://ibl.ai/solutions/higher-education/agent/it-help-desk-agent)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [Student Privacy Policy Office](https://studentprivacy.ed.gov/) — U.S. Department of Education. Primary guidance on FERPA application, the school official exception, and vendor arrangements.
- [FERPA regulations, 34 CFR Part 99](https://www.ecfr.gov/current/title-34/subtitle-A/part-99) — Electronic Code of Federal Regulations. The regulatory text itself — used for the definitional work in Modules 1 and 2.
- [Office of Educational Technology](https://tech.ed.gov/) — U.S. Department of Education. Federal guidance on AI in education, used to frame the policy context.
- [AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) — NIST. Structures the audit and incident-response work in Modules 6 and 7.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- Module 2 is the load-bearing one. If a learner leaves without being able to state the four conditions of the school official exception from memory, the course has failed regardless of what else they retained.
- Do not let this become a legal-advice course. Every module frames the analysis and names where institutional counsel must decide. Include an explicit disclaimer slide.
- The Module 8 lab needs a synthetic SIS with at least 200 fictional student records and a deliberately mis-scoped role, so the cross-boundary test suite actually fails on first run.
- Keep the vendor DPA in Module 4 anonymized and composite. Do not use a named competitor's real agreement.
- Regulatory currency matters here — re-verify the eCFR citation and any ED guidance at each revision, and bump lastUpdated when they change.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the FERPA-Compliant AI: Deploying Agents on Student Data course cover?

FERPA is the first question every campus AI project runs into and the one most vendors answer badly. This course works through what the statute actually regulates, why 'the vendor is SOC 2 certified' answers a different question entirely, and how the deployment architecture you choose either creates a disclosure problem or removes it. It ends with a working advising agent that answers from the SIS without exporting a single record. It runs 6 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: FERPA readiness review for one live AI use case.

### Who should take FERPA-Compliant AI: Deploying Agents on Student Data?

It is written for Registrars and student records staff, CIOs, CTOs, and IT directors evaluating AI vendors, General counsel and privacy officers, Provosts and deans sponsoring an AI initiative. Prerequisites: Working familiarity with your institution's SIS and LMS; No legal or technical background required.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for higher education teams that cannot send work to a public AI tool.

### How do we get access to FERPA-Compliant AI: Deploying Agents on Student Data?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for higher education cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More Higher Education courses

- [AI Academic Advising at Scale: Design and Guardrails](https://ibl.ai/solutions/higher-education/course/ai-academic-advising-at-scale): Build an advising agent that handles degree audits and registration at 20,000-student scale without ever giving a student wrong graduation advice.
- [Enrollment and Yield AI: Agents Across the Funnel](https://ibl.ai/solutions/higher-education/course/enrollment-and-yield-ai): Deploy AI across inquiry, application, admit, and melt — where agents lift yield, where they damage trust, and how to keep the funnel on infrastructure you own.
- [AI Tutoring That Improves Outcomes, Not Just Engagement](https://ibl.ai/solutions/higher-education/course/ai-tutoring-that-improves-outcomes): Design a tutoring agent that produces measurable learning gains — Socratic scaffolding, answer-withholding, misconception detection, and honest outcome measurement.
- [Assessment Redesign for the AI Era](https://ibl.ai/solutions/higher-education/course/assessment-redesign-for-the-ai-era): Detection does not work. Rebuild assessment around what AI cannot fake — process, oral defense, local context, and in-class artifacts — with department-ready rubrics.
- [Writing a Campus AI Policy That Survives Accreditation](https://ibl.ai/solutions/higher-education/course/campus-ai-policy-that-survives-accreditation): Draft institutional AI policy a regional accreditor, a general counsel, and a faculty senate will each accept — with the governance to keep it current.
- [RAG on Institutional Knowledge: Catalogs, Policies, Handbooks](https://ibl.ai/solutions/higher-education/course/rag-on-institutional-knowledge): Retrieval-augmented generation over the documents a campus runs on — chunking a catalog, versioning policy, and stopping the agent citing a 2019 handbook.
