FERPA-Compliant User Research: Interviewing Students, Parents, and Educators
How FERPA, PPRA, and state student-privacy laws apply to edtech user research — when the school official exception covers you, when PPRA consent kicks in, and how to run compliant student interviews.
The short answer
FERPA governs education records held by a school. It does not automatically govern feedback a student gives you directly. That single distinction decides most edtech research questions — and most teams get it backwards, assuming FERPA blocks everything or that it does not apply to them at all.
If you are an edtech company interviewing students, three laws matter and they trigger differently:
- FERPA (20 U.S.C. 1232g; 34 CFR Part 99) applies when you touch education records — grades, enrolment, disciplinary files — held by a school receiving US Department of Education funds. Access usually flows through the school official exception, not through consent.
- PPRA (20 U.S.C. 1232h) applies when you survey students on any of eight protected topics. This is the one that actually catches research, and almost nobody plans for it.
- COPPA applies to any child under 13 online, school or no school. It runs in parallel and does not care whether FERPA applies.
Get the trigger analysis right and student research becomes routine. Get it wrong and you either block valuable research unnecessarily or run a study your district partner has to shut down.
What FERPA actually covers
FERPA requires schools and educational agencies receiving ED funds to obtain written consent from the parent — or from the "eligible student," meaning one who is 18 or attending a postsecondary institution — before disclosing personally identifiable information from education records.
Two limits matter enormously for researchers:
- FERPA binds the school, not you. It is a funding condition on educational institutions. As a vendor you inherit obligations contractually, through the school official exception and your data agreement — not directly by statute.
- It covers education records specifically. An education record is information directly related to a student and maintained by the institution. A student's answers in a product-feedback interview you conducted are not an education record simply because the student attends a school.
So a study where you interview students about your app's onboarding — no grades, no enrolment data, no roster pulled from the school's SIS — often sits outside FERPA entirely while still sitting squarely inside PPRA and COPPA.
The school official exception
When you do need roster or record data — to sample properly, to segment by grade level, to reach a specific cohort — the practical route is 34 CFR 99.31(a)(1). A vendor can be treated as a "school official with a legitimate educational interest" when the district has determined that you:
- perform an institutional service or function the district would otherwise do itself;
- are under the direct control of the district with respect to use and maintenance of the data;
- use the information only for the purpose for which the disclosure was made; and
- do not redisclose the information without authorisation.
The clause that ends most research ambitions is the third. "Only for the purpose for which the disclosure was made" means roster data handed over to run a district-commissioned evaluation cannot be quietly reused to recruit for your own product research. If you want both, get both in the agreement up front.
The district must also have specified the criteria for legitimate educational interest in its annual FERPA notification. Ask to see it. If your use case is not describable within that notice, the exception is not available to you.
Directory information
Some data — name, grade level, dates of attendance, email address, participation in activities — can be designated directory information and disclosed without consent, provided the school gives public notice of what it designates and a reasonable period to opt out. Directory information is a legitimate recruiting channel for research, but it is narrower than people assume and every district designates a different subset. Never assume; ask for the district's current designation in writing.
PPRA: the law that actually catches research
This is the section to read twice. PPRA governs the administration of any survey, analysis, or evaluation to students that concerns one or more of eight protected areas:
| # | Protected area |
|---|---|
| 1 | Political affiliations or beliefs of the student or parent |
| 2 | Mental or psychological problems of the student or family |
| 3 | Sex behaviour or attitudes |
| 4 | Illegal, anti-social, self-incriminating, or demeaning behaviour |
| 5 | Critical appraisals of others with whom the student has a close family relationship |
| 6 | Legally recognised privileged relationships (lawyers, physicians, ministers) |
| 7 | Religious practices, affiliations, or beliefs of the student or parent |
| 8 | Income, other than as required to determine programme eligibility |
If the survey is funded by the US Department of Education and touches any of the eight, prior written parental consent is required — active consent, meaning a signed form returned before the student participates. For surveys not funded by ED, districts must generally provide notice and an opt-out opportunity instead.
Researchers walk into area 2 and area 4 constantly without noticing. "How do you feel when you fall behind your classmates?" is a wellbeing question. "Have you ever shared your login with another student?" invites a self-incriminating answer about policy violation. Neither reads like a protected-area survey when you draft it; both are.
Practical rule: run your question list against the eight areas before fielding, not after. It takes ten minutes and it is the single highest-value compliance step in student research.
State law sits on top
Roughly forty states have enacted student-privacy statutes since 2014, California's SOPIPA being the model many followed. These commonly prohibit targeted advertising to students, selling student data, and building non-educational profiles — and they bind the vendor directly, unlike FERPA. Check the states your districts operate in; a FERPA-clean study can still violate a state statute.
A compliant workflow for edtech research
1. Classify the study. Answer three questions in writing: Am I touching education records? Am I asking about any of the eight PPRA areas? Is any participant under 13? Those three answers determine everything downstream.
2. Pick your access route. Direct recruitment with parental consent, district-mediated recruitment under the school official exception, or directory-information outreach. Do not mix routes in one study without documenting each.
3. Get consent and assent right. Parental consent is the legal permission; assent is the child's own willing agreement, and you need both. Assent language must be age-appropriate — a 9-year-old cannot meaningfully agree to a paragraph written for adults.
4. Screen your questions against PPRA. Rewrite anything landing in a protected area, or escalate to active consent.
5. Minimise at the point of collection. Do not collect the student's full name if a pseudonymous ID answers your research question. Do not collect school name if grade band suffices.
6. Interview educators and parents too. They sit outside FERPA and PPRA entirely and often hold the answers you need. Teacher and administrator interviews are the fastest legitimate path to insight in K-12 — and the buying committee lives there anyway.
7. Set retention before you start. Short, artefact-specific retention is both a compliance mitigation and an operational simplification.
Where Koji fits
Student research is bottlenecked by consent logistics and scheduling, not by willingness to participate. Koji removes most of that friction while keeping the compliance surface small.
Asynchronous, link-based interviews. Participants join an AI-moderated interview by text or voice through a shared link, at a time a parent can supervise. No scheduling, no moderator calendar, no classroom time surrendered. For parent-mediated research with minors, the supervised-at-home pattern is far easier to run than a live session.
Structured questions keep you inside the lines. Koji supports six question types — open_ended, scale, single_choice, multiple_choice, ranking, and yes_no. In student research this matters more than in any other vertical: a scale or single_choice question collects a bounded value, so a nine-year-old cannot volunteer a family disclosure into a free-text box you then have to handle. Reserve open_ended for topics where you genuinely need narrative, and let the AI probe within scope. See the structured questions guide.
No human moderator, fewer people exposed to raw disclosures. Traditional student research puts a moderator, a notetaker, and often observers in the room with a child. Koji's AI runs the session and produces aggregate analysis, which shrinks both the privacy surface and the safeguarding burden.
Speed that matches the academic calendar. Edtech research has brutal timing — you get a window before term starts, or the weeks around renewal, and nothing in between. A traditional study with district approval, scheduling, and manual analysis does not fit those windows. Studies that run asynchronously and report automatically do, which is often the difference between evidence-based roadmap decisions and guessing until next semester.
Reach the adults at scale. Teacher, administrator, and parent research carries none of the FERPA or PPRA burden, and Koji's model — hundreds of conversational interviews in parallel rather than a dozen scheduled calls — fits that population particularly well. See AI research for edtech for the wider vertical playbook.
Common mistakes
- Assuming FERPA applies to everything. Direct product feedback from a student is usually not an education record. Do the classification.
- Assuming FERPA applies to nothing because you are a vendor. The moment roster or record data reaches you, the school official exception and its purpose limitation bind you contractually.
- Missing PPRA entirely. It is the likeliest trigger in real research and the least known.
- Reusing district-provided data for a second purpose. Explicitly prohibited by the exception.
- Collecting consent but not assent. Both are required when working with minors.
- Ignoring state student-privacy statutes, which bind vendors directly where FERPA does not.
Related Resources
- User Research With Children and Teens — COPPA, parental consent, and assent in depth
- AI Research for EdTech — the vertical playbook for education products
- Student Satisfaction Survey Guide — question sets for the education sector
- Structured Questions Guide — the six question types and why they minimise collection
- Research Consent Form Templates — consent and assent language you can adapt
- HIPAA-Compliant AI User Research — the parallel playbook for healthcare
- DPIA for User Research — risk assessment when EU participants are involved
- Research Data Retention and Deletion — setting the retention schedule your agreement promises
Related Articles
AI-Powered User Research for EdTech: Learners, Educators, and Administrators
How EdTech companies can run parallel research streams with learners, educators, and administrators using AI-moderated interviews — without scheduling headaches or research team scale limitations.
DPIA for User Research: When You Need One and How to Write It (2026)
A practical guide to Data Protection Impact Assessments for customer and user research: the Article 35 triggers, the WP29 nine criteria, what belongs in each section, and a worked example for AI-moderated interviews.
HIPAA-Compliant AI User Research: A Practical Playbook for Healthcare and HealthTech
Run AI-moderated customer research in healthcare contexts without putting PHI at risk. Patterns for HIPAA alignment, anonymous-mode interviews, BYOK, sub-processor handling, and what Enterprise teams need from a vendor.
Research Consent Form Templates: GDPR-Compliant Forms for Every Study
Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.
Research Data Retention and Deletion: How Long Should You Keep Interview Data?
There is no universal legal number - which is exactly why having no retention schedule is itself the compliance failure. A tiered, per-artifact schedule for recordings, transcripts, quotes, and reports, plus how to handle deletion requests without losing your insights.
Structured Questions in AI Interviews
Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.
How to Measure Student Satisfaction and Improve Institutional Outcomes
A comprehensive guide to designing student satisfaction surveys that capture meaningful feedback across academic, social, and administrative dimensions to drive institutional improvement.
User Research With Children and Teens: COPPA, Parental Consent, and Assent
Researching under-13s triggers COPPA verifiable parental consent - including a separate consent before any child data trains AI. Here is the compliance path, the parent-mediated pattern most teams should use instead, and how to design sessions that actually work with young participants.