What is this course about?
Districts face three overlapping federal regimes plus a growing stack of state student-privacy laws, and most AI vendor conversations address none of them precisely. This course works through what each rule actually requires, why consent under COPPA becomes the district's problem rather than the vendor's, and which architecture resolves all three without a separate compliance argument for each.
Who is this course for?
- District privacy officers and data protection officers
- CTOs and directors of technology
- Superintendents and cabinet-level administrators
- District counsel and board members
What do I need before starting?
- Access to at least one current district AI or edtech vendor agreement
- No technical or legal background required
What will I be able to do afterwards?
- State what FERPA, COPPA, and CIPA each require of an AI deployment
- Determine who bears the consent obligation for under-13 users and why
- Assess a vendor agreement against all three regimes plus applicable state law
- Explain the district's risk posture to a school board in ten slides
- Choose a deployment architecture that removes rather than manages disclosure risk
What does each module cover?
What does FERPA require of a district using AI?
45 minEducation records in a district context and the school official exception applied to an AI vendor.
Objectives
- Classify district data as education records, directory information, or out of scope
- Apply the school official exception to an AI vendor arrangement
- Identify the direct control requirement's architectural consequence
Topics
Activity. Classify data elements from five district systems and flag the ambiguous ones.
Why is COPPA consent the district's problem?
45 minThe under-13 consent regime and why schools end up bearing an obligation vendors present as handled.
Objectives
- Explain COPPA's application when a school authorizes a service
- Determine when school consent can substitute for parental consent
- Identify the conditions that make school consent invalid
Topics
Activity. Assess whether school consent could validly cover three real vendor tools.
What does an AI chat interface do to your CIPA posture?
40 minFiltering obligations, E-Rate exposure, and how a generative interface differs from a website.
Objectives
- State CIPA's filtering and monitoring requirements
- Assess how a generative interface interacts with filtering
- Protect E-Rate eligibility while deploying AI
Topics
Activity. Draft the CIPA compliance narrative for an AI tutoring deployment.
Which state laws are stricter than the federal floor?
45 minThe state student-privacy statutes that impose obligations federal law does not.
Objectives
- Identify the state student-privacy law applicable to your district
- Compare state requirements against the federal floor
- Build a combined requirements checklist
Topics
Activity. Build the combined federal-plus-state requirements checklist for your state.
How do you read an AI vendor contract as a district?
50 minThe clauses that decide exposure β training rights, retention, subprocessors, deletion, and termination.
Objectives
- Locate model-training and data-use clauses
- Evaluate retention and deletion against your records schedule
- Assess subprocessor chains and redisclosure
Topics
Activity. Redline a real vendor agreement against the combined checklist.
Which architecture satisfies all three regimes at once?
45 minWhy district-controlled deployment collapses three separate compliance arguments into one.
Objectives
- Trace student data through hosted and district-controlled deployments
- Explain why self-hosting removes the disclosure question
- Assess the operational cost of each architecture honestly
Topics
Activity. Draw the data-flow diagram for your intended deployment and mark every boundary crossing.
How do you explain the risk posture to a school board?
45 minBoard communication that is accurate without being alarming or falsely reassuring.
Objectives
- Structure a board presentation around decisions rather than technology
- Present residual risk honestly
- Prepare for the questions boards reliably ask
Topics
Activity. Build the ten-slide board deck and present it to the cohort.
Scoring two real vendor agreements
55 minThe workshop module: applying the full checklist to two live agreements and producing a recommendation.
Objectives
- Score two agreements against the combined checklist
- Document the gaps that require negotiation
- Produce a defensible procurement recommendation
Topics
Activity. Score both agreements and write the recommendation memo.
What is the capstone project?
District AI compliance package
Produce the district's complete AI compliance package: combined federal and state checklist, vendor scoring rubric, data-flow diagram for the chosen architecture, and the board-facing risk narrative.
Deliverable: A package the district privacy officer can apply to every future AI procurement.
How are learners assessed?
- Classification exercise scored against a reference determination
- Vendor redline assessed against the combined checklist
- Board deck reviewed for accuracy and appropriate risk framing
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for k-12.
Where does the course material come from?
Every module is grounded in primary sources β the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- Children's Online Privacy Protection Rule
Federal Trade Commission
The COPPA rule itself, underpinning the consent analysis in Module 2.
- Student Privacy Policy Office
U.S. Department of Education
FERPA guidance for districts and vendor arrangements.
- Children's Internet Protection Act
Federal Communications Commission
CIPA obligations and E-Rate conditions covered in Module 3.
- Student Privacy Compass
Future of Privacy Forum
Practical district guidance and state law tracking for Module 4.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- State law varies enormously and Module 4 must be localized per cohort. Do not ship a generic state module β verify the applicable statute for each district and update it, since several states amend annually.
- Module 2 is the one most districts get wrong. Emphasize that a vendor saying 'we're COPPA compliant' describes their product, not the district's consent obligation.
- Use composite, anonymized vendor agreements throughout. Naming and attacking a specific edtech vendor turns a compliance course into a competitive one and undermines its credibility.
- The board deck in Module 7 needs a real board member to critique it. Technologists systematically overestimate how much technical detail a board wants.
- Include a plain-language glossary. District cohorts mix lawyers, technologists, and educators, and unexplained jargon loses a third of the room in the first hour.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter β you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM β Claude, GPT, Llama, Gemini, Command β and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped β including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA course cover?
Districts face three overlapping federal regimes plus a growing stack of state student-privacy laws, and most AI vendor conversations address none of them precisely. This course works through what each rule actually requires, why consent under COPPA becomes the district's problem rather than the vendor's, and which architecture resolves all three without a separate compliance argument for each. It runs 5.5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: District AI compliance package.
Who should take The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA?
It is written for District privacy officers and data protection officers, CTOs and directors of technology, Superintendents and cabinet-level administrators, District counsel and board members. Prerequisites: Access to at least one current district AI or edtech vendor agreement; No technical or legal background required.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere β cloud, private VPC, on-premise, or fully air-gapped β and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for k-12 teams that cannot send work to a public AI tool.
How do we get access to The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA?
Request access and we will set it up for your cohort β hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for k-12 cost on ibl.ai?
There is no per-seat pricing β you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.