πŸ“… Book a 30-min DemoπŸ“ž Call/text (571) 293-0242
K-12 Β· AI Course Β· K12-1

The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA

The three federal rules governing AI in a district, what each requires of a vendor, and the deployment architecture that satisfies all three at once.

Last updated:

The Short Answer

FERPA, COPPA, and CIPA each constrain district AI differently, and no vendor certificate satisfies all three. ibl.ai deploys inside district-controlled infrastructure where you own all the code and the data, so student records never reach a third party β€” which resolves the disclosure question under all three regimes rather than arguing each one separately.

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing β€” so you can deploy anywhere, from your own cloud to a fully air-gapped network.

The full course design is published below β€” every module, its objectives and hands-on activity, the capstone, and every source it cites.

What is this course about?

Districts face three overlapping federal regimes plus a growing stack of state student-privacy laws, and most AI vendor conversations address none of them precisely. This course works through what each rule actually requires, why consent under COPPA becomes the district's problem rather than the vendor's, and which architecture resolves all three without a separate compliance argument for each.

Who is this course for?

  • District privacy officers and data protection officers
  • CTOs and directors of technology
  • Superintendents and cabinet-level administrators
  • District counsel and board members

What do I need before starting?

  • Access to at least one current district AI or edtech vendor agreement
  • No technical or legal background required

What will I be able to do afterwards?

  • State what FERPA, COPPA, and CIPA each require of an AI deployment
  • Determine who bears the consent obligation for under-13 users and why
  • Assess a vendor agreement against all three regimes plus applicable state law
  • Explain the district's risk posture to a school board in ten slides
  • Choose a deployment architecture that removes rather than manages disclosure risk

What does each module cover?

1

What does FERPA require of a district using AI?

45 min

Education records in a district context and the school official exception applied to an AI vendor.

Objectives

  • Classify district data as education records, directory information, or out of scope
  • Apply the school official exception to an AI vendor arrangement
  • Identify the direct control requirement's architectural consequence

Topics

Education records in K-12School official exceptionDirectory informationDirect control

Activity. Classify data elements from five district systems and flag the ambiguous ones.

2

Why is COPPA consent the district's problem?

45 min

The under-13 consent regime and why schools end up bearing an obligation vendors present as handled.

Objectives

  • Explain COPPA's application when a school authorizes a service
  • Determine when school consent can substitute for parental consent
  • Identify the conditions that make school consent invalid

Topics

Under-13 scopeSchool consent doctrineEducational purpose limitsCommercial use prohibition

Activity. Assess whether school consent could validly cover three real vendor tools.

3

What does an AI chat interface do to your CIPA posture?

40 min

Filtering obligations, E-Rate exposure, and how a generative interface differs from a website.

Objectives

  • State CIPA's filtering and monitoring requirements
  • Assess how a generative interface interacts with filtering
  • Protect E-Rate eligibility while deploying AI

Topics

CIPA requirementsFiltering and generative contentE-Rate eligibilityMonitoring obligations

Activity. Draft the CIPA compliance narrative for an AI tutoring deployment.

4

Which state laws are stricter than the federal floor?

45 min

The state student-privacy statutes that impose obligations federal law does not.

Objectives

  • Identify the state student-privacy law applicable to your district
  • Compare state requirements against the federal floor
  • Build a combined requirements checklist

Topics

State student privacy statutesData deletion mandatesVendor registriesCombined checklists

Activity. Build the combined federal-plus-state requirements checklist for your state.

5

How do you read an AI vendor contract as a district?

50 min

The clauses that decide exposure β€” training rights, retention, subprocessors, deletion, and termination.

Objectives

  • Locate model-training and data-use clauses
  • Evaluate retention and deletion against your records schedule
  • Assess subprocessor chains and redisclosure

Topics

Training rightsRetention and deletionSubprocessorsTermination and return

Activity. Redline a real vendor agreement against the combined checklist.

6

Which architecture satisfies all three regimes at once?

45 min

Why district-controlled deployment collapses three separate compliance arguments into one.

Objectives

  • Trace student data through hosted and district-controlled deployments
  • Explain why self-hosting removes the disclosure question
  • Assess the operational cost of each architecture honestly

Topics

Hosted data flowDistrict-controlled deploymentDisclosure eliminationOperational trade-offs

Activity. Draw the data-flow diagram for your intended deployment and mark every boundary crossing.

7

How do you explain the risk posture to a school board?

45 min

Board communication that is accurate without being alarming or falsely reassuring.

Objectives

  • Structure a board presentation around decisions rather than technology
  • Present residual risk honestly
  • Prepare for the questions boards reliably ask

Topics

Board communicationResidual risk presentationDecision framingAnticipated questions

Activity. Build the ten-slide board deck and present it to the cohort.

8

Scoring two real vendor agreements

55 min

The workshop module: applying the full checklist to two live agreements and producing a recommendation.

Objectives

  • Score two agreements against the combined checklist
  • Document the gaps that require negotiation
  • Produce a defensible procurement recommendation

Topics

Comparative scoringGap documentationNegotiation prioritiesRecommendation writing

Activity. Score both agreements and write the recommendation memo.

What is the capstone project?

District AI compliance package

Produce the district's complete AI compliance package: combined federal and state checklist, vendor scoring rubric, data-flow diagram for the chosen architecture, and the board-facing risk narrative.

Deliverable: A package the district privacy officer can apply to every future AI procurement.

How are learners assessed?

  • Classification exercise scored against a reference determination
  • Vendor redline assessed against the combined checklist
  • Board deck reviewed for accuracy and appropriate risk framing

What ships with the course?

Facilitator guide

Session-by-session running order, discussion prompts, and the questions that reliably derail a room.

Learner workbook

Exercises, checklists, and the templates each module's activity produces.

Hands-on lab environment

A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.

Assessment bank

Scenario questions and rubric criteria mapped to each stated learning outcome.

Source bibliography

Every primary regulation and standard cited on this page, linked and dated.

Which AI agents does this course use?

The hands-on modules run against agents already deployable on the ibl.ai platform for k-12.

Where does the course material come from?

Every module is grounded in primary sources β€” the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

Delivery notes

Binding guidance for anyone preparing and delivering this course.

  • State law varies enormously and Module 4 must be localized per cohort. Do not ship a generic state module β€” verify the applicable statute for each district and update it, since several states amend annually.
  • Module 2 is the one most districts get wrong. Emphasize that a vendor saying 'we're COPPA compliant' describes their product, not the district's consent obligation.
  • Use composite, anonymized vendor agreements throughout. Naming and attacking a specific edtech vendor turns a compliance course into a competitive one and undermines its credibility.
  • The board deck in Module 7 needs a real board member to critique it. Technologists systematically overestimate how much technical detail a board wants.
  • Include a plain-language glossary. District cohorts mix lawyers, technologists, and educators, and unexplained jargon loses a third of the room in the first hour.

Why run AI training on a platform you own?

You own the course, not a licence to it

Course content, learner data, and the platform run inside your perimeter β€” you own all the code and the data.

Model-agnostic delivery

Run the course's AI components on any LLM β€” Claude, GPT, Llama, Gemini, Command β€” and switch anytime.

No per-seat training licences

Usage-based or self-hosted, so cost tracks actual use rather than headcount.

Deploy anywhere

Cloud, private VPC, on-premise, or fully air-gapped β€” including for cohorts that cannot use public AI tools.

Frequently asked questions

What does the The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA course cover?

Districts face three overlapping federal regimes plus a growing stack of state student-privacy laws, and most AI vendor conversations address none of them precisely. This course works through what each rule actually requires, why consent under COPPA becomes the district's problem rather than the vendor's, and which architecture resolves all three without a separate compliance argument for each. It runs 5.5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: District AI compliance package.

Who should take The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA?

It is written for District privacy officers and data protection officers, CTOs and directors of technology, Superintendents and cabinet-level administrators, District counsel and board members. Prerequisites: Access to at least one current district AI or edtech vendor agreement; No technical or legal background required.

Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere β€” cloud, private VPC, on-premise, or fully air-gapped β€” and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for k-12 teams that cannot send work to a public AI tool.

How do we get access to The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA?

Request access and we will set it up for your cohort β€” hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

How much does AI training for k-12 cost on ibl.ai?

There is no per-seat pricing β€” you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

Request access to The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA

Tell us about your cohort and we will set it up β€” hosted by ibl.ai, or running against your own deployment, where you own all the code and the data.