FERPA and ChatGPT for Teachers: What's Protected
FERPA in plain terms: what OpenAI's stated support for it means in practice — and what FERPA does NOT guarantee just because a vendor claims to support it.
When OpenAI launched ChatGPT for Teachers, the reassuring phrase in the announcement was that the workspace is built with education-grade privacy, security, and compliance meant to support FERPA. That's a real and welcome signal. It's also one of the most misunderstood sentences in ed-tech, because "supports FERPA" does not mean "you no longer have to think about student privacy."
FERPA compliance is not a badge a vendor earns and hands to you. It's a legal obligation that sits on your school and district — and a tool can only ever make that obligation easier or harder to meet. This is the plain-terms version of what FERPA actually protects, what OpenAI's stated support does for you, and, most importantly, the gap between those two things.
Key Takeaways
- FERPA binds schools and districts, not vendors. The Family Educational Rights and Privacy Act governs institutions that receive U.S. Department of Education funding. A vendor can support your compliance, but the legal duty is always yours.
- "FERPA support" means a tool can be configured to meet the law — not that using it is automatically compliant. The same product can be used compliantly or not, depending on what data you put in and how the district has set it up.
- The "school official" exception is the mechanism that lets vendors touch student data at all. It requires the vendor act under the district's direct control and not repurpose the data — which is exactly why the "not used for training by default" posture matters.
- FERPA protects education records, not everything. De-identified materials and your own original lesson content aren't the risk; personally identifiable student information is.
- The safest teacher habit is data minimization. Keep identifiable student records out of any general AI workspace unless your district has explicitly cleared it — the strongest privacy control is the data you never paste in.
What FERPA actually is, in plain terms
FERPA — the Family Educational Rights and Privacy Act — is a 1974 federal law that protects the privacy of student education records. In practice it does two big things. First, it gives parents (and students once they turn 18, the "eligible student") the right to access and request corrections to their education records. Second, it restricts how schools disclose personally identifiable information from those records: generally, a school needs written consent before handing that information to a third party, with a set of specific exceptions.
The crucial detail most vendor marketing glosses over: FERPA regulates institutions that receive Department of Education funding — your school and district. It does not directly regulate software companies. The U.S. Department of Education's Student Privacy Policy Office is the authoritative reference for how this works, and its guidance is consistent on one point: the obligation runs to the school, and the school is responsible for the vendors it uses.
What "FERPA support" from a vendor really means
So how does a tool like ChatGPT for Teachers touch student data at all without violating FERPA? Through an exception. FERPA lets schools share education records, without separate parental consent, with a "school official" who has a legitimate educational interest — and a contracted vendor can qualify as a school official if it operates under the district's direct control over the use and maintenance of the records, and doesn't use the data for its own unrelated purposes.
Read that condition again, because it's where OpenAI's design choices become legally load-bearing. The launch coverage — from CNBC and GovTech — emphasizes that data shared in the workspace is not used to train OpenAI's models by default. "Not repurposing the data" is precisely the kind of commitment the school-official exception hinges on. That's what "supports FERPA" is really pointing at: the product is architected so a district can use it within the exception. It doesn't do the district's compliance work; it makes that work possible.
What FERPA does NOT automatically guarantee
Here's the contrast that matters, laid out plainly. Confusing the left column for the right is how districts get burned.
| What people assume "FERPA-compliant" means | What it actually means |
|---|---|
| The vendor is legally liable for privacy | Your district is legally liable; the vendor is a processor under your control |
| Any use of the tool is automatically compliant | Only compliant if configured and used within FERPA's exceptions |
| Student data is safe to enter freely | Nothing about a compliance claim invites you to paste in identifiable records |
| A signed agreement covers all data types | Agreements cover specified uses; unusual data flows may fall outside them |
| "Supports FERPA" is a certification | There is no single official FERPA "certification" a product passes |
None of this means ChatGPT for Teachers is unsafe. It means the compliance claim is a starting point for your district's own review, not a substitute for it. The IT director's checklist exists precisely to turn a vendor's privacy posture into a documented district decision.
The teacher's practical line: what to keep out of the box
FERPA protects personally identifiable information from education records — a student's name attached to their grades, disciplinary records, IEP details, or other protected data. It does not protect a de-identified worksheet or the original unit plan you wrote from scratch. That distinction gives teachers a clean operating rule.
Safe to use freely: lesson plans, activities, rubrics, generic examples, and any material with no identifiable student information in it. Building next week's plans in a structured tool like Lesson Plan Studio touches none of FERPA's protected categories, because there's no student record involved.
Keep out unless your district has explicitly cleared it: anything that ties a real, identifiable student to protected record data — "write feedback for Marcus Chen, who scored 42% and has a reading IEP." Strip the identifier, and you've moved the same task out of FERPA's scope. This is the single most powerful privacy control a teacher has, and it costs nothing: the data you never enter can't be exposed. It's also why the question of whether OpenAI trains on your lesson plans deserves a careful read — the "by default" wording carries more weight than it first appears.
Who's actually on the hook
If there's one thing to internalize, it's the direction the liability points. When a K-12 privacy incident happens, FERPA's accountability lands on the institution, not the software vendor's homepage. That's not a reason to distrust the tool — it's a reason to treat "supports FERPA" as an invitation to do your own diligence rather than an excuse to skip it.
Districts that get this right do three things: they review the vendor's actual data terms rather than the marketing summary, they document why the tool fits within FERPA's exceptions, and they train teachers on the keep-it-out line above. Districts that get burned assume a compliance claim did all three for them. And because a free AI workspace holds classroom materials and, potentially, student information, the stakes of getting it wrong are real — which is exactly the risk explored in what a K-12 AI data breach would actually mean.
Frequently Asked Questions
Is ChatGPT for Teachers FERPA-compliant?
The product is built to support FERPA compliance, and OpenAI states that shared data isn't used to train its models by default. But compliance is ultimately a property of how your district configures and uses the tool, not a fixed attribute of the software. Do your own review.
Can I put student names and grades into ChatGPT for Teachers?
Not unless your district has explicitly reviewed and approved that use. The safest default is to strip identifiable student information and work with de-identified materials, which moves the task outside FERPA's protected scope entirely.
Does OpenAI sign a data agreement with schools?
OpenAI describes education-grade privacy and a managed-account path for districts, but the exact contractual terms should be confirmed directly with OpenAI and reviewed by your district before you rely on them. Never assume terms you haven't read.
Who is legally responsible if student data is exposed?
Under FERPA, the school or district — the institution receiving Department of Education funding — carries the legal obligation. A vendor operating as a "school official" acts under the district's control, which is why your own diligence and data-minimization habits matter so much.
Does FERPA protect my lesson plans?
No. FERPA protects personally identifiable information from student education records, not the original materials you create. Your own lesson plans, rubrics, and de-identified activities aren't FERPA-protected data.
FERPA is a duty that lives with your district, and no vendor claim transfers it. OpenAI's stated support for FERPA is a genuine and useful signal — it means ChatGPT for Teachers can be used within the law — but the compliant outcome comes from your configuration, your review, and the identifiable data your teachers simply never enter. Treat "supports FERPA" as the first line of your diligence, not the last.
Part 10 of 100 in the ChatGPT for Teachers series. Previously: District Rollout 101: Provisioning ChatGPT for Teachers. Next: Does OpenAI Train on Your Lesson Plans?. Browse more builder insights or explore AI skills for education at aiskill.market.