FERPA & FOIA K-12 Schools: Email, SMS, and Social Media Compliance
In 2024, PowerSchool disclosed a cybersecurity breach that would become the largest student data breach in U.S. history, containing records of 62 million students and 9.5 million educators, including names, addresses, birthdates, Social Security numbers, and health information.
Every data point FERPA exists to protect.
Less than two years later, a Canvas ransomware attack hit nearly 9,000 educational institutions worldwide during final exams, proving the threat hadn’t peaked. It had spread.
What both incidents make clear is that FERPA compliance is no longer just a records management obligation. It is a district’s first line of defense against the legal, financial, and reputational consequences of a breach.
This guide covers what K-12 districts need to know about FERPA and FOIA compliance in 2026:
- How these laws apply to email, SMS, and social media
- Real-world violation consequences
- A practical framework for building a defensible communications program.
What Is FERPA and Who Does It Apply To
The Family Educational Rights and Privacy Act (FERPA), codified at 20 U.S.C. § 1232g, is the federal law protecting the privacy of student education records. It applies to every educational institution that receives U.S. Department of Education funding, which means every public K-12 school in the country.
FERPA gives parents of minor students the right to inspect, amend, and control their child’s personally identifiable information (PII). Once a student turns the age of 18, they have full control of their education records.
Compliance obligations follow student data everywhere it travels: email, text messages, social media, and third-party platforms included.
What Counts as an “Education Record” Under FERPA?
An education record under FERPA is any record, file, document, or material that: (1) directly relates to a student, and (2) is maintained by an educational agency or institution.
This is a broad definition that encompasses far more than transcripts and report cards. This includes:
- Student grades, test scores, and academic performance data
- Attendance and enrollment records
- Disciplinary records
- IEP (Individualized Education Program) and special education records
- Health records maintained by the school
- Financial aid and loan records
- Any email, text message, or digital communication in which a student is identified and their records are discussed
- Third-party vendor records that contain student PII
Third party vendors are where many districts face the greatest risk. A teacher emails a parent about a student’s grades, discusses a disciplinary situation over text message, or posts information about a student on a school social media account. All of these can constitute education records subject to FERPA.
FERPA and Email Archiving
Email is the primary communication channel in most K-12 school districts. Teachers email parents about student performance. Counselors discuss student mental health concerns. Administrators coordinate IEP meetings.
All of this communication flows through email systems. Without proper archiving and controls, this can create significant FERPA exposure.
Why School Email Is a FERPA Risk Area
The compliance risk in school email includes:
Cc/Bcc errors: A teacher writing a message about a student’s academic performance who accidentally includes other parents in the recipient field has disclosed an education record to unauthorized parties without consent.
Personal email accounts: When staff use personal Gmail or Yahoo accounts for school business, those messages are outside the district’s control, cannot be archived, and cannot be produced in response to a FOIA request or legal hold. The district has no legal chain of custody over that data.
Unencrypted transmission: Standard email is not end-to-end encrypted. If any server in the transmission chain does not enforce TLS, then messages containing student PII can travel that hop in plaintext, which produces multiple unencrypted copies of a student record.
Vendor access: Third-party providers with access to school email systems are considered School Officials with Legitimate Educational Interest under FERPA only if a proper data governance agreement is in place. Many districts lack these agreements with every vendor that touches student data.
Retention gaps: If email systems automatically purge messages after 90 days, the district may be deleting records it was legally required to retain, which is itself a FERPA violation.
FERPA Email Compliance Requirements
To keep email compliant with FERPA, districts must:
- Deploy an email archiving solution that captures 100% of inbound and outbound communications in a tamper-proof format
- Encrypt email both in transit and at rest
- Implement role-based access controls so only authorized personnel can access archived student-related communications
- Establish and enforce written data governance agreements with all third-party vendors that access student email data
- Set retention policies aligned with state retention schedules and FERPA’s requirement to maintain records indefinitely for currently enrolled students
FERPA and SMS/Text Messages: The Compliance Gap Most Districts Miss
Text messaging is common in K-12 communications. Teachers text parents, coaches message students, counselors send wellness check-ins, and administrators coordinate via group SMS. In most districts, none of it is being archived.
FERPA applies to text messages the same way it applies to email. If a message directly relates to a student and is maintained by the school or its officials, it is an education record. The problem is that most districts have no technical mechanism to capture, store, or produce those records.
What Makes SMS Archiving Uniquely Challenging
Personal device use: When a teacher texts a parent from a personal phone, that message lives outside the district’s IT infrastructure and outside its legal control. There may be no way to retrieve it for a FOIA request, litigation, or FERPA investigation.
No native retention: Unlike email, SMS messages are not automatically retained. Once a device is replaced or a conversation deleted, those records may be permanently gone.
Third-party platforms: Many districts use Remind, ClassDojo, and ParentSquare for parent-teacher communication. These platforms generate records that may qualify as education records but are stored on vendor infrastructure, often without a FERPA-compliant data agreement in place.
SMS Compliance Requirements for K-12 Districts:
- An SMS archiving solution that captures all outbound communications from district-authorized messaging platforms
- A policy of staff from using personal phones to text students or parents about student-specific matters or, if personal devices are permitted, a clear process for capturing those communications
- Written data processing agreements with all third-party communication platforms that handle student information
- A retention policy for text message records aligned with state retention schedules
- Staff training on what types of information may and may not be communicated via text, with clear examples
Understanding FOIA and State Sunshine Laws for K-12 Schools
The federal Freedom of Information Act applies to federal agencies, not to local school districts. Each state has its own open records law, and these sunshine laws are often stricter than federal FOIA in their deadlines and scope.
How State Open Records Laws Apply to K-12 Schools
Public school districts are government entities subject to public accountability. State open records laws require districts to make records available upon request, including email, text messages, meeting minutes, contracts, and social media.
The tension with FERPA is real: the same email that must be produced in response to a public records request may also contain student PII that must be redacted before production. That redaction obligation requires districts to manually review large volumes of records. This process is error-prone without proper technology.
Missing state response deadlines, which range from three business days in Missouri to ten in California, can expose a district to legal action even if the underlying records are eventually produced.
What Records Are Schools Required to Produce
Under state open records laws, public K-12 districts are required to produce any record related to the conduct of public business including:
- Email and text messages sent through district platforms
- Official social media posts and direct messages
- Meeting minutes
- Vendor contracts are all subject to production.
Records that may be withheld include student education records (FERPA-protected PII), certain personnel records, attorney-client privileged communications, and records related to ongoing investigations.
The Relationship Between FERPA-FOIA
FOIA says make records public. FERPA says keep student data private. Districts have to satisfy both laws at the same time, and that is where most run into trouble.
When a public records request touches student-related communications, the district must identify all responsive records, redact any student PII protected by FERPA, document every redaction decision in case it is challenged, and produce the redacted records within the state deadline. This is done all at the same time. Without a centralized, searchable archive of all electronic communications, districts cannot reliably complete this process accurately or on time.
FERPA Violation and Penalty Reference Table
The following table summarizes violation categories, typical enforcement actions, and documented financial consequences:
| Violation Type | Enforcement Mechanism | Financial Consequence | Real-World Example |
| Unauthorized disclosure of student records | SPPO corrective action order, state AG investigation | $15,000–$75,000 per incident | Middleton Cross Plains Area School District — 2025 SPPO finding for denying parent access to student records |
| Third-party vendor data breach exposing student PII | Multi-state AG joint enforcement
FTC consent orders |
$5.1M settlement and mandatory remediation | Illuminate Education — $5.1M settlement (Nov 2025) after 2022 breach exposed 3M student records |
| Failure to archive / produce records for FOIA | State open records enforcement; court sanctions, litigation | Legal fees, court judgement, staff time | Delaware AG — 2025 FOIA opinion against Brandywine School District for inadequate records production |
| Cybersecurity breach exposing student data | Federal criminal prosecution
FERPA investigation of district |
$14M restitution order, district remediation costs in millions | PowerSchool breach (Dec 2024) — 62M students; perpetrator sentenced to 4 years federal prison, $14M restitution |
| Directory information disclosure without opt-out process | SPPO corrective action
Required policy revision |
Most common violation type (1/3 are repeat offenders) | Most K-12 districts that receive SPPO findings; mandatory retraining ordered |
💡 The Key Difference between state-level enforcement and federal FERPA enforcement
State laws create private rights of action and impose direct financial penalties. While FERPA’s primary enforcement mechanism is federal funding withdrawal (which has never been used in isolation). For practical risk management purposes, state law exposure is where most of the immediate financial consequences arise.
The K-12 FERPA + FOIA Compliance Framework: A Practical Step-by-Step Plan
Step 1: Conduct a Comprehensive Digital Communications Audit
Start by mapping every channel through which student information flows: Email, SMS, social media, and third-party applications. For each one, document who uses it, what student information moves through it, how records are retained, and whether a FERPA-compliant data agreement exists with the vendor. You cannot build a compliant program around channels you have not fully inventoried.
Repeat this audit annually to confirm retention policies, vendor agreements, and training are current.
Step 2: Establish a Written Digital Communications Policy
Every district needs a written policy defining which channels may be used for student-related communications, what information may be shared through each, and the consequences for violations. It should explicitly prohibit personal email and devices for student matters, require district-authorized platforms only, and outline the process for reporting potential FERPA violations.
Step 3: Deploy a Unified Archiving Solution Covering Email, SMS, and Social Media
Technology is not optional, it is the foundation. A compliant archiving solution must capture 100% of communications across email, SMS, and social media in tamper-proof WORM format, preserve complete metadata, enforce retention policies aligned with FERPA and state law, support legal hold, and generate a full audit trail of every access and export.
Step 4: Implement a FOIA Response Workflow
Designate a FOIA compliance officer and document a workflow for receiving, tracking, and responding to public records requests, including a redaction step for student PII. A searchable archive makes this process fast enough to meet state deadlines.
Step 5: Train All Staff and Audit Vendor Agreements
Every employee who has access to student information needs to understand what constitutes an education record, the rules around email, text, and social media disclosures, and how to handle parent records requests. Districts with proactive training programs see fewer violations. But when violations occur, they are treated more favorably in penalty assessments.
Every vendor that handles student data on the district’s behalf must have a signed data processing agreement specifying permitted uses, prohibiting resale or repurposing, and requiring breach notification. Districts without these agreements are already non-compliant before any breach occurs.
💡 See How K-12 Districts Stay Compliant
Intradyn’s email archiving solution, SMS/text message archiver, and social media archiving solution platform provide this unified coverage for K-12 districts. Ensuring that every communication channel is captured, retained, and searchable from a single interface.
Key Takeaways:
- FERPA follows student data everywhere: Email, text, social media, third-party apps. The channel doesn’t matter. If it contains identifiable student information and the school maintains it, it’s an education record.
- The PowerSchool breach (62 million records) and the Canvas ransomware attack prove the threat is no longer theoretical. Compliance is now also your breach defense strategy.
- Email is your biggest exposure channel. CC errors, personal accounts, and missing vendor agreements are the three most common ways districts create FERPA liability without knowing it.
- SMS archiving is the gap most districts have never closed. Teacher texts, coach messages, and third-party platforms like Remind all generate records. Most of it isn’t being captured.
- Social media posts require specific, platform-level consent — general photo release forms don’t cover public Instagram or Facebook posts.
- FERPA and FOIA conflict constantly. Every public records request that touches student data requires redaction before production. Without a searchable archive, you can’t do it accurately or on time.
- State open records laws response windows are short (as few as three business days), and missing them exposes districts to legal action independent of FERPA.
- Vendor agreements aren’t optional. Every third-party platform touching student data needs a signed data processing agreement. Without one, you’re already non-compliant before anything goes wrong.
FAQ
Can a district be penalized under FERPA even if no data was actually misused?
Yes. FERPA violations are based on unauthorized disclosure, not harm. A teacher who accidentally copies the wrong parent on an email about a student’s IEP has committed a violation the moment it’s sent. Intent and outcome are not defenses.
What happens if a staff member leaves and their devices or accounts are wiped before a records request is fulfilled?
That’s a spoliation problem. If a FOIA request or litigation hold was already in place, destroying those records can trigger court sanctions and state open records violations. Proper archiving captures records at the server level — they survive regardless of what happens to individual devices.
Do FERPA obligations apply to teachers’ personal social media accounts?
Yes, in specific circumstances. A “private” post shared with even one person who isn’t a school official with legitimate educational interest can constitute a FERPA violation. Personal account use should be addressed explicitly in staff training
If a parent requests their child’s records, are the district’s internal communications about that student also producible?
Potentially yes. Internal emails discussing a student’s performance, discipline, or IEP are education records if they directly relate to a student and are maintained by the institution. The main exception is personal notes kept solely by one staff member and never shared. Once emailed to a colleague or filed anywhere, that exception typically disappears.
Is Your District’s Email, SMS, and Social Media Actually Compliant?
Don’t wait for a breach, FOIA request, or FERPA violation to find out your communications aren’t being captured. Our Intradyn team can help you build a defensible archiving program across email, SMS, and social media.
