Educational Resources

Research-based resources to help district and state education agency teams evaluate online tutoring and SaaS tools, including, but not limited to, Pearl Education. These are general explainers, not legal advice; confirm specifics with your own counsel and policies.

FERPA in Online Tutoring

The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records. When a school uses an online tutoring provider:

  • The school controls the education records; a vendor typically accesses them only to provide the service.
  • Many vendors operate under FERPA’s “school official” exception (34 C.F.R. §99.31(a)(1)), which generally requires that the vendor perform a function the school would otherwise perform, be under the school’s direct control regarding the use of records, and follow FERPA’s limits on re-disclosure.
  • Questions to ask a vendor: How are you designated as a school official? What student data do you access, and why? How is re-disclosure limited? How and when is data returned or deleted?

COPPA in School-Based SaaS

The Children’s Online Privacy Protection Act (COPPA) governs online collection of personal information from children under 13.

  • In a school context, FTC guidance allows a school to provide consent on behalf of parents for the educational use of a service, when collection is limited to educational purposes.
  • This does not eliminate the parent’s interest: schools should disclose which tools they use and for what purpose.
  • Questions to ask: Is data collection limited to what the educational service needs? Is the data used for advertising or sold? Can the school direct deletion?

AI in K-12: Questions Districts Should Ask

As AI features appear in education tools, districts should evaluate them deliberately:

  • Purpose and scope: What does the AI feature do, and what data does it use as input?
  • Data use: Is student data used only to provide the service, or also to train models? Is identifiable student data used for model training? (A clear answer should be available in writing.)
  • Human oversight: Are AI outputs decision-support for educators rather than automated decisions about students?
  • Transparency: Does the vendor publish documentation describing its AI practices?
  • Accuracy and bias: How does the vendor address errors, limitations, and fairness?

Data-Sharing Best Practices for Districts

Practical steps when sharing student data with any provider:

  • Sign the right agreement. Use a Data Privacy Agreement (DPA) — or a state/national NDPA where available — that addresses ownership, permitted uses, security, breach notification, and deletion.
  • Minimize data. Share only the fields the service actually needs; avoid sensitive identifiers (e.g., SSNs, government IDs, financial or biometric data) unless explicitly required and agreed.
  • Confirm security. Ask for encryption in transit and at rest, access controls, and an independent security assessment or report.
  • Plan the exit. Confirm export, deletion timelines, and deletion certification before the contract starts.
  • Inform families. Maintain clear notices about the tools in use and the purposes for which data is shared.