Student data is not used to train general-purpose AI models. The platform supports COPPA consent workflows for under-13 users, PPRA survey controls, and state student privacy statutes and data privacy agreements, with documentation supplied during procurement.
The legal framework
| Law | What it governs |
|---|---|
| FERPA | Privacy of student education records; parent and eligible student rights of access, amendment and consent over disclosure |
| COPPA | Collection of personal information from children under 13 by online services |
| PPRA | Surveys and collection of protected information; parental notice and consent rights |
| IDEA | Additional confidentiality obligations around special education records |
| State statutes | State-level student privacy laws, which in many states are more restrictive than federal law |
| State DPAs | Standard data privacy agreements many states and consortia require vendors to sign |
A vendor that talks only about FERPA has told you about the least restrictive layer.
School official status
FERPA permits a district to disclose education records without consent to a contractor performing a service the district would otherwise perform itself, provided that contractor is under the direct control of the district with respect to the use and maintenance of the records, and uses the data only for the authorized purpose.
Edves operates under that provision. In practice this means the district determines what data is held, who may access it, how long it is retained, and what happens to it at termination — and the contract says so.
How access actually works
- Field-level role scoping. A coach sees athletic eligibility and not health records. A paraprofessional sees assigned students. A counselor sees pastoral notes a classroom teacher does not. Special education records carry separate access controls.
- Audit logging. Every access to a student record is logged with user, timestamp and record. This is what makes FERPA’s legitimate educational interest standard enforceable rather than aspirational.
- Configurable retention. Retention schedules are set to district policy and state records law, not to a vendor default.
- Directory information handling. Configurable per district policy with opt-out flags respected across every output, including family communication and any published material.
AI and student data — the specific commitments
This is where district privacy officers should press hardest with any AI vendor, so the position is stated plainly:
- Student data is not used to train general-purpose AI models.
- Student data is not sold, and not used for advertising or profiling.
- Data used to personalize instruction stays within the district’s tenant.
- Subprocessors are disclosed, with processing locations identified.
- Contractual terms confirming all of the above are provided during procurement, not referenced in a marketing page.
When evaluating any AI education vendor, including this one, ask for the contract language rather than the claim. A vendor unwilling to put a training-data restriction in writing has answered the question.
COPPA
For students under 13, Edves supports the school-obtained consent pathway, where the school consents on behalf of parents for educational-purpose collection, with age-appropriate data minimization and no behavioral advertising. Districts should still confirm their own notice practices, since the consent is the school’s to give and the notice obligation is the school’s to meet.
Data ownership and exit
| Question | Position |
|---|---|
| Who owns the data? | The district or school, stated in contract |
| Can we export everything? | Yes, including historical academic records, in a usable format, at any time |
| What does export cost? | Nothing, including at termination |
| What happens at termination? | Export delivered, then deletion on the district’s instruction and schedule, with certification |
| Is there a hostage clause? | No. Data access is not contingent on renewal |
The exit terms are worth more attention than they usually get during procurement. They are the only leverage a district retains after signature.
Breach and incident response
Incident notification timelines, the district’s own notification obligations under state breach law, and the coordination between them are specified in the agreement. Districts should confirm the notification window in the contract matches what their state statute requires of them — a vendor window longer than the district’s own obligation is a real problem and a common one.
Questions to ask every vendor
- Will you sign our state’s standard data privacy agreement without amendment?
- Show me the contract clause on model training.
- List your subprocessors and their processing locations.
- What is your incident notification window, and does it fit inside our state obligation?
- What does data export cost at termination, and in what format?
- Who at your company can access our student data, and how is that logged?
Related
ESSA reporting for the accountability data this governs. AI in education for the wider policy sequence. Student information system for how access control is implemented.