Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

What is FERPA? FERPA Violation Examples, What They Look Like, and How Schools Prevent Them

August 11, 2026
hero-ferpa-violation-examples-schools-1.png

A FERPA violation happens when a school discloses personally identifiable student information without consent. No exception covers the disclosure. The Family Educational Rights and Privacy Act is a federal law. It protects student education records (20 U.S.C. Most violations start as IT or process gaps, not deliberate misconduct.

This guide is written for school IT staff and administrators responsible for preventing violations. It is not written for parents seeking to file a complaint against a school. You might manage student data systems, set access permissions, or vet EdTech vendors. This breakdown is built for you.

Why FERPA Violations Keep Happening

Most FERPA violations are not the result of bad actors. They come from misconfigured systems, sloppy access controls, and gaps in recordkeeping. A staff member forwards the wrong file. A shared drive gets set up with permissions too broad for the job. A substitute teacher gets system access nobody ever scoped down.

None of these look like scandals from the outside. Each one still counts as a violation under FERPA’s disclosure rules. The patterns below show up across districts every year. They are not isolated incidents. They are the predictable result of how school IT systems get built and maintained.

Treat them as a checklist for your own environment, not a list of things that only happen to other districts.

Pattern 1: Unauthorized Disclosure Through IT Misconfiguration

The most common FERPA violation is not a hack. It is a permissions mistake. A U.S. Government Accountability Office review of K-12 breaches found something clear. School staff caused most accidental disclosures, not outside attackers or students (GAO-20-644).

This pattern shows up in a few recurring forms:

  • Overly broad shared drives or cloud folders. A folder meant for one grade level or one department gets shared district-wide, exposing records to staff who have no reason to see them.
  • Misaddressed emails. A record meant for one parent or one staff member goes out to a distribution list, a wrong address, or a reply-all chain.
  • Screen-share exposure. A staff member pulls up one student’s record during a video call or in-person meeting, and another student’s data stays visible on the same screen or open tab.

Every one of these is preventable with basic access hygiene. None of them require malicious intent to become a real violation. A misconfigured folder permission is enough on its own.

Pattern 2: Access Without Legitimate Educational Interest

FERPA allows schools to share student records without consent under one major exception. The record can go to a school official with a legitimate educational interest in it. That means they need the record to do their job under federal rule 34 CFR 99.31(a)(1). That exception is also where schools most often overreach.

The rule assumes access is scoped to the role. In practice, many districts hand out access first and worry about scope later. That gap between assumption and practice is where Pattern 2 lives. It matters for vendors too. A “school official” can include a contracted service provider, not just staff on payroll, which is exactly why IT vendor access needs the same scrutiny as a staff login.

Common examples of this pattern include:

  • Substitutes or aides with full gradebook or record access, not scoped to their assigned classroom
  • Parent or community volunteers with system logins broader than the single task they were brought in for
  • Former staff or contractors whose access was never revoked after their role ended
  • IT or support vendors with standing access to student data outside a specific, documented need

None of these require a malicious actor. They require an access review that never happened. That is the gap this guide returns to again and again. FERPA compliance is less about one bad decision. It is about whether access controls match the job someone actually does.

Pattern 3: Directory Information Mishandled

FERPA lets schools share “directory information” without consent. Directory information includes things like a student’s name or enrollment status. Two conditions have to be met first. The school must give public notice of what counts as directory information. It must also let parents opt out in writing (34 CFR 99.37(a)).

Requirements vs Common Violations

Two things go wrong most often.

  • A parent files an opt-out, and the school discloses the information anyway. A yearbook photo, a sports roster, a printed program. The opt-out gets missed because nobody flagged the record.
  • A school discloses information it never designated as directory information in its annual notice. If it wasn’t named in that notice, it isn’t directory information. Disclosing it needs consent, like any other record.

Neither mistake looks dramatic. Both are still violations.

Pattern 4: Missing or Incomplete Disclosure Recordkeeping

FERPA requires schools to log most disclosures of student records. For each one, the school must record who requested it and why. That log has to stay with the student’s record. It stays as long as the record itself exists (34 CFR 99.32).

Most districts don’t build this habit. There’s no required software. There’s no standard template. The obligation is just as real without one.

This becomes an audit gap fast. If a parent asks who has seen their child’s file, the school needs an answer. Without a log, there isn’t one. If SPPO opens a complaint, that same gap becomes the first friction point in the investigation.

A quick self-check: can your system show, right now, who accessed a specific student’s file and why? If nobody can answer that within a minute, this gap is probably in your environment too.

Pattern 5: Third-Party and Vendor Exposure

Modern schools don’t just manage FERPA in-house. They hand student data to student information systems, gradebook platforms, and other EdTech vendors. When a vendor’s access controls fail, the exposure can dwarf anything a single school could cause on its own.

In January 2025, PowerSchool disclosed a major breach. PowerSchool is a student information system used by thousands of K-12 districts. Court filings later put the number affected at roughly 62 million, students and teachers combined (PowerSchool breach reporting, May 2025).

The cause traced back to one compromised credential on a customer support portal. There was no multi-factor authentication in place to stop it.

A single compromised credential, with no MFA in place, led to the largest disclosed exposure of student data on record.

It’s also a direct answer to a question FERPA leaves open. FERPA’s “reasonable methods” standard doesn’t specify vendor security requirements (34 CFR 99.31(c)). In practice, it has to extend to vendor access hygiene, not just the school’s own network.

Illinois schools carry an extra layer here. Under SOPPA, any vendor that receives student data must first sign a written data privacy agreement (105 ILCS 85/15). FERPA has no equivalent mandatory-agreement rule.

What FERPA and SOPPA Enforcement Actually Look Like

FERPA enforcement is complaint-driven, not proactive. A parent or eligible student files a complaint with the Student Privacy Policy Office (SPPO). SPPO investigates within 180 days of receiving it (34 CFR 99.64).

If SPPO finds a violation, it has four possible remedies (34 CFR 99.67(a)):

  • Require voluntary corrective action
  • Issue a cease-and-desist order
  • Withhold federal payments
  • Terminate the agency’s federal funding eligibility

Here’s the honest nuance: the Department of Education has never terminated funding over a FERPA violation. That holds true as of 2025 (Public Interest Privacy Center, 2025). It has worked toward corrective action in every case to date.

That doesn’t mean a finding is low-stakes. SPPO has opened new investigations and issued findings against districts in 2025 and 2026. A finding still creates legal exposure, reputational damage, and sometimes parental lawsuits, even with no federal fine attached.

Illinois schools face a second enforcement path SOPPA created. Violations are treated as unlawful practices under the Illinois Consumer Fraud and Deceptive Business Practices Act. The Illinois Attorney General is authorized to bring enforcement action (105 ILCS 85/35). That path runs independently of, and in addition to, FERPA’s federal process.

FrameworkWho EnforcesInvestigation WindowTypical Remedies
FERPA (federal)U.S. Dept of Education, Student Privacy Policy Office180 days from complaint (34 CFR 99.64)Corrective action, cease-and-desist, funding withheld or terminated (34 CFR 99.67(a)); termination never used to date
SOPPA (Illinois)Illinois Attorney GeneralNot fixed by statuteAction under the Illinois Consumer Fraud and Deceptive Business Practices Act (105 ILCS 85/35)

Closing the Gaps: Where to Start

Every pattern above traces back to the same root cause. Access doesn’t match legitimate educational interest, and nobody’s reviewed the controls in a while. A short list closes most of it:

  • Review shared drive and cloud folder permissions by role, not by convenience
  • Scope substitute, volunteer, and vendor access to the specific task, then revoke it when the task ends
  • Publish your directory information notice and track opt-outs in one place
  • Log disclosures as they happen, not after a complaint forces you to reconstruct them
  • Require a signed data privacy agreement, and multi-factor authentication, from every vendor touching student data

For the full technical build-out, see LeadingIT’s FERPA IT compliance checklist for Illinois schools. It walks through each control in more depth.

See Where You Stand

Most of these patterns come down to one question: does your access match what FERPA and SOPPA already require? A short, plain-English check can tell you fast, no sign-up needed to see your result.

Take the free 2-minute FERPA & SOPPA Risk-Check

Frequently Asked Questions

A parent or eligible student files a complaint with the Student Privacy Policy Office, the federal office that enforces FERPA. Once received, SPPO has 180 days to investigate. Most investigations start this way rather than from a routine audit or inspection.

No. FERPA requires schools to use reasonable methods so only staff with legitimate educational interest can access records, but it does not name encryption or any specific technical control. Illinois schools have a sharper standard under SOPPA, which requires security practices that meet or exceed industry standards. In practice, most districts treat encryption as part of meeting that bar even though neither law spells it out by name.

At the federal level, the Student Privacy Policy Office within the U.S. Department of Education enforces FERPA. Illinois schools also face a state-level path: SOPPA violations are treated as unlawful practices under the Illinois Consumer Fraud and Deceptive Business Practices Act, and the Illinois Attorney General is authorized to take action. The two enforcement paths run independently of each other.

FERPA has no civil monetary penalty structure. Its remedies are corrective action, a cease-and-desist order, or withholding or terminating federal funding, and funding has never actually been terminated over a FERPA violation to date. That said, a finding still carries legal and reputational risk. Illinois’s SOPPA runs through the state Consumer Fraud Act instead, which is a separate legal exposure.

FERPA is a federal law that applies to any school receiving federal education funding, and it does not require a written agreement with IT vendors. SOPPA is Illinois’s state law layered on top of FERPA.<details> <summary>Do school IT vendors need a written agreement to access student data?</summary> <p>Under FERPA alone, no. Vendors can qualify as a school official with a legitimate educational interest without a mandatory written contract. Illinois schools have a stricter rule under SOPPA: any vendor receiving student data must first sign a written data privacy agreement specifying what data it gets and when it must be deleted or returned.

Get Your Compliance Program Reviewed

FERPA and SOPPA don’t hand your IT team a technical checklist. Both assume you already have one built. LeadingIT designs and manages the access controls, MFA, and audit logging that close these gaps. We work with Illinois school districts across Chicagoland.

See LeadingIT’s school IT compliance services, book a call, or contact us to talk through your environment.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.