Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Free FERPA & SOPPA Self-Assessment:
Would Your District Pass a Review?

FERPA + Illinois SOPPA Risk Check

  • 9 quick questions
  • Takes about 2 minutes
  • No sign-up to see your result

Your top next moves

    Nothing critical flagged. Keep everything current and re-check yearly.

    Book a call

    Use the interactive FERPA and Illinois SOPPA risk check below to see where your school or district actually stands.

    Answer 8 quick questions, weighted toward device security and edtech vendor coverage since that’s where student data actually leaks, and get your readiness score in about 2 minutes: your risk level, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.

    No sign-up to see your result.

    What FERPA and Illinois SOPPA Actually Require (the short version)

    FERPA, the Family Educational Rights and Privacy Act, is the federal law that controls who can see a student’s education records. It requires a parent’s (or an adult student’s) consent before those records, or the personally identifiable information in them, are disclosed to a third party, with narrow exceptions like a school official with a legitimate educational interest. Illinois’ Student Online Personal Protection Act (SOPPA) layers a technology-specific overlay on top of FERPA for K-12 districts:

    It requires a written Data Privacy Agreement (DPA) with every operator, meaning every edtech vendor, that receives student data, restricts what a vendor can do with that data (no targeted advertising to students, no profiles built beyond the educational purpose), and sets its own parent-notification clock after a breach.

    In practice, the compliance work splits into two halves:

    • A Paperwork Half

      (Consent, disclosure rules, a directory-information policy)

    • A Technical Half

      (Who can access student data, whether it’s encrypted, whether every vendor has a signed DPA, and whether a lost device is actually protected)

    No single, official technical checklist exists for either law, which is exactly why most IT departments genuinely don’t know where they stand until something forces the question.

    The checklist below is organized around both halves.

    The Full FERPA & SOPPA Checklist

    Work through each area. Anything you can’t confirm is a gap. If you can’t prove it, a state investigator can’t either.

    • 1. Edtech Vendor Coverage (SOPPA Data Privacy Agreements):

      ✓ A current, complete inventory of every edtech app or platform your staff and students actually use. The average school district runs roughly 1,449 of them, and each one is a separate risk point.

      ✓ A signed, SOPPA-compliant Data Privacy Agreement (DPA) in place with each vendor before any student data is shared.

      ✓ A review process for new apps before a teacher or department starts using one, so the list doesn’t grow faster than your DPA coverage.

    • 2. Access Control:

      ✓ A unique login for every user, no shared accounts, for systems holding student records.

      ✓ Access granted on a least-privilege basis: only the staff who need it, only the records they need.

      ✓ Multi-factor authentication (MFA) required on your student information system and any remote access to it.

    • 3. Encryption:

      ✓ Student data encrypted at rest (student information system, servers, backups).

      ✓ Student data encrypted in transit (email, parent portals, file transfers).

    • 4. Device Security and Mobile Device Management (MDM):

      ✓ Every laptop, Chromebook, and phone that can access student data is encrypted.

      ✓ Devices enrolled in MDM so they can be locked or wiped remotely the moment one is lost or stolen. Device loss and theft is the most common real-world cause of a student-data violation, more common than any hack.

      ✓ A documented process for what happens the minute a device is reported missing, not after someone gets around to it.

    • 5. Breach Response and State Notification Readiness:

      ✓ A written incident-response plan that names Illinois SOPPA’s parent-notification deadline alongside FERPA’s own obligations.

      ✓ A clear owner for executing that plan the moment a breach is suspected, not after it’s confirmed.

    • 6. Staff Training and Accountability:

      ✓ Annual privacy and security training for all staff who touch student data, with signed or logged attestations.

      ✓ A named person or role, a Director of Technology or Data Privacy Officer, accountable for student-data-privacy compliance.

      ✓ Written policies staff can actually reference, not tribal knowledge held by one person.

    • 7. Directory Information and Parental Rights

      ✓ A published directory-information policy reviewed this school year.

      ✓ A working, easy-to-find opt-out process for parents.

      ✓ A process for handling a parent’s request to inspect or correct their child’s education records.

    How to read your gaps?

    • 0 – 2 Gaps (0 Vendor DPA or Device Security Gaps)

      Strong Shape

    • 3 – 6 Gaps Or 1+ Critical Gaps

      Real, findable gaps that would draw findings in a state review or a parent complaint.

    • 7+ Gaps or 2+ Critical Gaps

      You’d likely have real findings today and may be carrying live breach exposure right now.

    FERPA’s ultimate penalty is loss of federal funding. In practice, the Department of Education’s Family Policy Compliance Office works with districts to fix problems first, and funding termination is the escalation path, not the opening move, but it’s a real, on-the-books consequence, not a scare tactic.

    Most of the items above (vendor DPAs, MFA, encryption, MDM) live in your IT setup, not a policy binder, which is the half of FERPA and SOPPA a managed IT partner operates for you.

    FERPA & SOPPA FAQ

    What’s the difference between FERPA and Illinois SOPPA?

    FERPA is the federal law governing access to and disclosure of student education records. SOPPA is Illinois’ state-level overlay for K-12 districts, and it’s narrower and more technical: it specifically regulates the edtech vendors that touch student data, requiring a signed Data Privacy Agreement with each one and setting its own breach-notification timeline. A district needs to satisfy both, not one or the other.

    What happens if a school violates FERPA?

    The legal penalty is loss of federal funding, enforced by the Department of Education’s Family Policy Compliance Office. In practice, the office prioritizes voluntary compliance and works with a district to fix the problem before pursuing that penalty. That doesn’t make it hollow. It’s the real enforcement mechanism behind the law, and it’s why “we think we’re fine” isn’t good enough for something federal money depends on.

    How many edtech apps does a typical school district actually use?

    Roughly 1,449, on average, across a school year. Each one is a separate vendor relationship, a separate place student data lives, and under SOPPA, a separate Data Privacy Agreement that needs to exist. That volume is exactly why most IT departments lose track without a maintained inventory.

    What triggers a FERPA or SOPPA review?

    Usually a parent complaint, a reported breach, or a vendor incident that surfaces during a routine audit of your edtech agreements. Because you can’t predict the timing, the practical answer is to stay ready year-round rather than reconstructing your vendor list and device inventory after the fact.

    How often should we review our edtech vendor list and DPAs?

    At least once a school year, and any time a new app is adopted mid-year. A list that’s accurate in August and untouched by May isn’t accurate anymore.

    Does a small district really need all of this?

    Yes. Neither FERPA nor SOPPA scales down for district size. A smaller district simply has fewer systems, vendors, and devices to track, which makes a maintained inventory easier, not optional.

    Ready to close your gaps?

    If your result flagged gaps in vendor DPA coverage, device encryption, or MDM, most of that is technical work an IT partner handles day to day.

    LeadingIT helps Chicagoland school districts build the access controls, encryption, device management, and vendor-agreement tracking that FERPA and Illinois SOPPA expect. We deliver this FOR districts, not as a certifying body, no FERPA or SOPPA “certification” exists for an IT company to hold.

    For more on the cybersecurity side of protecting student data, see our guide to protecting student data. Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us to see how we deliver FERPA/SOPPA-aligned IT as a managed service.