# The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA

> K-12 · AI Course · K12-1
> Source: https://ibl.ai/solutions/k-12/course/k12-ai-compliance-stack
> Last updated: 2026-08-25

**The three federal rules governing AI in a district, what each requires of a vendor, and the deployment architecture that satisfies all three at once.**

## The Short Answer

**FERPA, COPPA, and CIPA each constrain district AI differently, and no vendor certificate satisfies all three. ibl.ai deploys inside district-controlled infrastructure where you own all the code and the data, so student records never reach a third party — which resolves the disclosure question under all three regimes rather than arguing each one separately.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore K-12](https://ibl.ai/solutions/k-12)

## Course facts

- **Level:** Foundational
- **Duration:** 5.5 hours across 8 modules
- **Format:** Cohort workshop with contract review labs
- **Modules:** 8
- **Catalog code:** K12-1
- **Frameworks covered:** FERPA, COPPA, CIPA, State student privacy law

## What is this course about?

Districts face three overlapping federal regimes plus a growing stack of state student-privacy laws, and most AI vendor conversations address none of them precisely. This course works through what each rule actually requires, why consent under COPPA becomes the district's problem rather than the vendor's, and which architecture resolves all three without a separate compliance argument for each.

## Who is this course for?

- District privacy officers and data protection officers
- CTOs and directors of technology
- Superintendents and cabinet-level administrators
- District counsel and board members

### What do I need before starting?

- Access to at least one current district AI or edtech vendor agreement
- No technical or legal background required

## What will I be able to do afterwards?

- State what FERPA, COPPA, and CIPA each require of an AI deployment
- Determine who bears the consent obligation for under-13 users and why
- Assess a vendor agreement against all three regimes plus applicable state law
- Explain the district's risk posture to a school board in ten slides
- Choose a deployment architecture that removes rather than manages disclosure risk

## What does each module cover?

### Module 1 — What does FERPA require of a district using AI?

Education records in a district context and the school official exception applied to an AI vendor. _(45 min)_

**Objectives**

- Classify district data as education records, directory information, or out of scope
- Apply the school official exception to an AI vendor arrangement
- Identify the direct control requirement's architectural consequence

**Topics:** Education records in K-12 · School official exception · Directory information · Direct control

**Activity:** Classify data elements from five district systems and flag the ambiguous ones.

### Module 2 — Why is COPPA consent the district's problem?

The under-13 consent regime and why schools end up bearing an obligation vendors present as handled. _(45 min)_

**Objectives**

- Explain COPPA's application when a school authorizes a service
- Determine when school consent can substitute for parental consent
- Identify the conditions that make school consent invalid

**Topics:** Under-13 scope · School consent doctrine · Educational purpose limits · Commercial use prohibition

**Activity:** Assess whether school consent could validly cover three real vendor tools.

### Module 3 — What does an AI chat interface do to your CIPA posture?

Filtering obligations, E-Rate exposure, and how a generative interface differs from a website. _(40 min)_

**Objectives**

- State CIPA's filtering and monitoring requirements
- Assess how a generative interface interacts with filtering
- Protect E-Rate eligibility while deploying AI

**Topics:** CIPA requirements · Filtering and generative content · E-Rate eligibility · Monitoring obligations

**Activity:** Draft the CIPA compliance narrative for an AI tutoring deployment.

### Module 4 — Which state laws are stricter than the federal floor?

The state student-privacy statutes that impose obligations federal law does not. _(45 min)_

**Objectives**

- Identify the state student-privacy law applicable to your district
- Compare state requirements against the federal floor
- Build a combined requirements checklist

**Topics:** State student privacy statutes · Data deletion mandates · Vendor registries · Combined checklists

**Activity:** Build the combined federal-plus-state requirements checklist for your state.

### Module 5 — How do you read an AI vendor contract as a district?

The clauses that decide exposure — training rights, retention, subprocessors, deletion, and termination. _(50 min)_

**Objectives**

- Locate model-training and data-use clauses
- Evaluate retention and deletion against your records schedule
- Assess subprocessor chains and redisclosure

**Topics:** Training rights · Retention and deletion · Subprocessors · Termination and return

**Activity:** Redline a real vendor agreement against the combined checklist.

### Module 6 — Which architecture satisfies all three regimes at once?

Why district-controlled deployment collapses three separate compliance arguments into one. _(45 min)_

**Objectives**

- Trace student data through hosted and district-controlled deployments
- Explain why self-hosting removes the disclosure question
- Assess the operational cost of each architecture honestly

**Topics:** Hosted data flow · District-controlled deployment · Disclosure elimination · Operational trade-offs

**Activity:** Draw the data-flow diagram for your intended deployment and mark every boundary crossing.

### Module 7 — How do you explain the risk posture to a school board?

Board communication that is accurate without being alarming or falsely reassuring. _(45 min)_

**Objectives**

- Structure a board presentation around decisions rather than technology
- Present residual risk honestly
- Prepare for the questions boards reliably ask

**Topics:** Board communication · Residual risk presentation · Decision framing · Anticipated questions

**Activity:** Build the ten-slide board deck and present it to the cohort.

### Module 8 — Scoring two real vendor agreements

The workshop module: applying the full checklist to two live agreements and producing a recommendation. _(55 min)_

**Objectives**

- Score two agreements against the combined checklist
- Document the gaps that require negotiation
- Produce a defensible procurement recommendation

**Topics:** Comparative scoring · Gap documentation · Negotiation priorities · Recommendation writing

**Activity:** Score both agreements and write the recommendation memo.

## What is the capstone project?

**District AI compliance package.** Produce the district's complete AI compliance package: combined federal and state checklist, vendor scoring rubric, data-flow diagram for the chosen architecture, and the board-facing risk narrative.

_Deliverable:_ A package the district privacy officer can apply to every future AI procurement.

## How are learners assessed?

- Classification exercise scored against a reference determination
- Vendor redline assessed against the combined checklist
- Board deck reviewed for accuracy and appropriate risk framing

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Administration Agent](https://ibl.ai/solutions/k-12/agent/administration-agent)
- [Student Safety Agent](https://ibl.ai/solutions/k-12/agent/student-safety-agent)
- [Family Communication Agent](https://ibl.ai/solutions/k-12/agent/family-communication-agent)
- [Curriculum Alignment Agent](https://ibl.ai/solutions/k-12/agent/curriculum-alignment-agent)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [Children's Online Privacy Protection Rule](https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa) — Federal Trade Commission. The COPPA rule itself, underpinning the consent analysis in Module 2.
- [Student Privacy Policy Office](https://studentprivacy.ed.gov/) — U.S. Department of Education. FERPA guidance for districts and vendor arrangements.
- [Children's Internet Protection Act](https://www.fcc.gov/consumer-governmental-affairs/childrens-internet-protection-act) — Federal Communications Commission. CIPA obligations and E-Rate conditions covered in Module 3.
- [Student Privacy Compass](https://studentprivacycompass.org/) — Future of Privacy Forum. Practical district guidance and state law tracking for Module 4.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- State law varies enormously and Module 4 must be localized per cohort. Do not ship a generic state module — verify the applicable statute for each district and update it, since several states amend annually.
- Module 2 is the one most districts get wrong. Emphasize that a vendor saying 'we're COPPA compliant' describes their product, not the district's consent obligation.
- Use composite, anonymized vendor agreements throughout. Naming and attacking a specific edtech vendor turns a compliance course into a competitive one and undermines its credibility.
- The board deck in Module 7 needs a real board member to critique it. Technologists systematically overestimate how much technical detail a board wants.
- Include a plain-language glossary. District cohorts mix lawyers, technologists, and educators, and unexplained jargon loses a third of the room in the first hour.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA course cover?

Districts face three overlapping federal regimes plus a growing stack of state student-privacy laws, and most AI vendor conversations address none of them precisely. This course works through what each rule actually requires, why consent under COPPA becomes the district's problem rather than the vendor's, and which architecture resolves all three without a separate compliance argument for each. It runs 5.5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: District AI compliance package.

### Who should take The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA?

It is written for District privacy officers and data protection officers, CTOs and directors of technology, Superintendents and cabinet-level administrators, District counsel and board members. Prerequisites: Access to at least one current district AI or edtech vendor agreement; No technical or legal background required.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for k-12 teams that cannot send work to a public AI tool.

### How do we get access to The K-12 AI Compliance Stack: FERPA, COPPA, and CIPA?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for k-12 cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More K-12 courses

- [Safe AI Tutoring for Minors: Guardrails and Escalation](https://ibl.ai/solutions/k-12/course/safe-ai-tutoring-for-minors): Building a tutoring agent for children — content moderation, self-harm escalation, grooming-pattern detection, and the mandatory-reporter workflow behind it.
- [AI Lesson Planning Aligned to State Standards](https://ibl.ai/solutions/k-12/course/ai-lesson-planning-standards-aligned): Generate standards-aligned lessons that survive a curriculum audit — grounded on your state's standards, your adopted materials, and your scope and sequence.
- [AI in the IEP Process: Drafting, Compliance, and the Human Signature](https://ibl.ai/solutions/k-12/course/ai-in-the-iep-process): Cut IEP paperwork without ceding a legally binding decision — drafting present levels, goal writing, and the IDEA requirements no agent can satisfy for you.
- [Academic Integrity and Assessment in K-12](https://ibl.ai/solutions/k-12/course/academic-integrity-and-assessment-k12): What to do when every student has a writing machine — grade-band policy, assessment redesign, and why detection tools create more problems than they solve.
- [Teaching AI Literacy: A K-12 Scope and Sequence](https://ibl.ai/solutions/k-12/course/k12-ai-literacy-scope-and-sequence): A vertically-aligned AI literacy progression from elementary through high school — what to teach at each band, and the activities that make it concrete.
- [District AI Procurement: Evaluating Vendors and Contracts](https://ibl.ai/solutions/k-12/course/district-ai-procurement): A procurement process a school board will approve and a privacy officer will sign — evaluation rubric, contract clauses, and the questions vendors dodge.
