Educational Resources
Research-based resources to help district and state education agency teams evaluate online tutoring and SaaS tools, including, but not limited to, Pearl Education. These are general explainers, not legal advice; confirm specifics with your own counsel and policies.
FERPA in Online Tutoring
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records. When a school uses an online tutoring provider:
- The school controls the education records; a vendor typically accesses them only to provide the service.
- Many vendors operate under FERPA’s “school official” exception (34 C.F.R. §99.31(a)(1)), which generally requires that the vendor perform a function the school would otherwise perform, be under the school’s direct control regarding the use of records, and follow FERPA’s limits on re-disclosure.
- Questions to ask a vendor: How are you designated as a school official? What student data do you access, and why? How is re-disclosure limited? How and when is data returned or deleted?
COPPA in School-Based SaaS
The Children’s Online Privacy Protection Act (COPPA) governs online collection of personal information from children under 13.
- In a school context, FTC guidance allows a school to provide consent on behalf of parents for the educational use of a service, when collection is limited to educational purposes.
- This does not eliminate the parent’s interest: schools should disclose which tools they use and for what purpose.
- Questions to ask: Is data collection limited to what the educational service needs? Is the data used for advertising or sold? Can the school direct deletion?
AI in K-12: Questions Districts Should Ask
As AI features appear in education tools, districts should evaluate them deliberately:
- Purpose and scope: What does the AI feature do, and what data does it use as input?
- Data use: Is student data used only to provide the service, or also to train models? Is identifiable student data used for model training? (A clear answer should be available in writing.)
- Human oversight: Are AI outputs decision-support for educators rather than automated decisions about students?
- Transparency: Does the vendor publish documentation describing its AI practices?
- Accuracy and bias: How does the vendor address errors, limitations, and fairness?
Data-Sharing Best Practices for Districts
Practical steps when sharing student data with any provider:
- Sign the right agreement. Use a Data Privacy Agreement (DPA) — or a state/national NDPA where available — that addresses ownership, permitted uses, security, breach notification, and deletion.
- Minimize data. Share only the fields the service actually needs; avoid sensitive identifiers (e.g., SSNs, government IDs, financial or biometric data) unless explicitly required and agreed.
- Confirm security. Ask for encryption in transit and at rest, access controls, and an independent security assessment or report.
- Plan the exit. Confirm export, deletion timelines, and deletion certification before the contract starts.
- Inform families. Maintain clear notices about the tools in use and the purposes for which data is shared.
