Regulatory anatomy · FERPA · 20 U.S.C. 1232g · 34 CFR Part 99 · PTAC

The FERPA Field Guide: Education Records, the Destruction Duties, and the Devices They Live On

The Family Educational Rights and Privacy Act is a disclosure law. It tells schools who may see a student’s education records and under what conditions; it does not contain a security rule, a breach-notification clock, or a destruction standard. And yet it reaches every retired laptop cart, faculty workstation, registrar server, and copier on a campus, because the records those devices hold remain education records until they are gone — and because in two places the regulations require that personally identifiable information be destroyed when it is no longer needed. This guide explains what FERPA actually says, where the destruction duties live, what the Department of Education’s own privacy office recommends for carrying them out, and how an institution turns a 1974 disclosure law into a 2026 disposition program. Not legal advice. For the sector video, see Higher Education ITAD; for student health records, the HIPAA guide.

Reading time: ~14 min Published: September 1, 2026 Author: Brian Boynton Applies to: 20 U.S.C. 1232g; 34 CFR Part 99

STRAIGHT ANSWER

What does FERPA require when schools retire IT equipment?

FERPA protects education records from unauthorized disclosure and, in two provisions, requires that personally identifiable information be destroyed when no longer needed: by organizations conducting studies and by authorities conducting audits or evaluations. It prescribes no destruction method. The Department of Education’s Privacy Technical Assistance Center recommends NIST SP 800-88 Clear, Purge, or Destroy, signed certification forms, and contracts requiring third parties to destroy student data.

TL;DR

FERPA is a disclosure law with destruction consequences. Education records — records directly related to a student and maintained by the institution or a party acting for it — may not be disclosed without consent except under listed exceptions; a retired device that leaks them is an unauthorized disclosure, whatever the mechanism. Two provisions require destruction outright: 34 CFR 99.31(a)(6)(iii)(C) (organizations conducting studies must destroy PII when no longer needed, within a specified period) and 34 CFR 99.35(b)(2) (state and local educational authorities and authorized representatives must destroy PII collected for audits or evaluations when no longer needed). Neither names a method. The Department’s Privacy Technical Assistance Center fills the gap: destruction as a data-lifecycle stage, NIST SP 800-88 Clear / Purge / Destroy chosen by sensitivity, signed certification forms, and contract terms requiring third parties to destroy PII including backups. Enforcement runs through the Department’s Student Privacy Policy Office and the condition of federal funding, not private lawsuits — and state student-privacy laws layer their own requirements on top.

Section 01

What FERPA is — and what it isn’t

Most compliance frameworks reach disposition through a security rule. FERPA reaches it through the definition of a disclosure.

The Family Educational Rights and Privacy Act, 20 U.S.C. 1232g, with regulations at 34 CFR Part 99, applies to educational agencies and institutions that receive funds under programs administered by the U.S. Department of Education — effectively all public K-12 schools and districts and nearly all postsecondary institutions. It gives parents, and students once they turn 18 or enroll in postsecondary education (“eligible students”), the right to inspect and review education records, to seek amendment, and to consent to disclosures of personally identifiable information from those records, subject to exceptions.

Education records (34 CFR 99.3) are records that are “directly related to a student” and “maintained by an educational agency or institution or by a party acting for the agency or institution.” The definition is medium-neutral — paper, electronic, or otherwise — and it does not care where the record sits. A grade export on a departed teacher’s laptop, a financial-aid file cached on a registrar’s workstation, a scanned transcript in a copier’s memory: all education records, all subject to the disclosure rules until they cease to exist.

What FERPA does not contain is as important. There is no general security rule comparable to HIPAA’s, no breach-notification requirement, no prescribed destruction method, and no private right of action — enforcement runs through the Department’s Student Privacy Policy Office, with the ultimate sanction being loss of federal funding. That structure shapes how the law reaches disposition: not through a “you must sanitize” provision, but through the fact that a retired device disclosing education records to an unauthorized person is a FERPA violation, and through two provisions that require destruction directly.

Bottom line

FERPA governs who may see education records. A retired device that lets the wrong person see them is a disclosure violation regardless of how it happened — which is why disposition is a FERPA matter even though the statute never mentions hardware.

Section 02

The two express destruction duties

FERPA’s regulations require destruction of personally identifiable information in exactly two places, both attached to disclosure exceptions.

The studies exception — 34 CFR 99.31(a)(6). An institution may disclose PII without consent to organizations conducting studies for or on its behalf (to develop or validate tests, administer student aid, or improve instruction), but only under a written agreement that, among other requirements, must “require the organization to destroy all personally identifiable information when the information is no longer needed for the purposes for which the study was conducted and specifies the time period in which the information must be destroyed.” The destruction duty and the deadline are mandatory contract terms.

The audit and evaluation exception — 34 CFR 99.35. Authorized representatives of state and local educational authorities and certain federal officials may access PII to audit or evaluate federal- or state-supported education programs or to enforce legal requirements. Under 99.35(b)(2), information collected for those purposes must, except where the parent or eligible student has consented or the collection is specifically authorized by law, “be destroyed when no longer needed for the purposes listed in paragraph (a)” of the section. The written agreement with an authorized representative must also address destruction and the time period for it.

Neither provision says how. The regulations require that destruction occur and, in the agreements, when; they leave the method to the party performing it. That silence is not permission to be casual — a destruction that leaves PII recoverable has not destroyed it — but it means the technical standard has to come from somewhere else, which is where the Department’s own guidance enters.

ProvisionWho must destroyWhenMethod specified?
34 CFR 99.31(a)(6)(iii)(C)Organization conducting a study for or on behalf of the institutionWhen PII is no longer needed for the study, within the period the written agreement specifiesNo
34 CFR 99.35(b)(2)State/local educational authorities and authorized representatives (audits, evaluations, enforcement)When no longer needed for the audit, evaluation, or enforcement purposeNo
Institution’s own retired devicesNot an express duty — governed by the disclosure prohibition and the institution’s record policiesPer the institution’s retention schedule; disposal must not discloseNo
Section 03

PTAC’s Best Practices for Data Destruction

The Department of Education’s Privacy Technical Assistance Center wrote the guidance FERPA itself omits, and it points squarely at the same standard the rest of the disposition world uses.

PTAC’s Best Practices for Data Destruction (first issued May 2014, revised 2019) frames destruction as the final stage of the data lifecycle: when data are no longer needed, “destruction of the data becomes a critical, and often required, component of an effective data governance program.” It is explicit that “simple deletion of the data is not effective” because deletion removes references while the data remain recoverable, and it adopts NIST SP 800-88’s Clear, Purge, and Destroy categories as the method framework, to be selected based on data sensitivity.

Two practices in the guidance map directly onto ITAD documentation. First, certification: PTAC recommends “certification forms which are signed by the individual responsible for performing the destruction” recording what was destroyed, how, when, and by whom — which is, in substance, NIST 800-88 Rev. 2’s Certificate of Sanitization. Second, contract terms: written agreements with third parties should require them to “destroy all PII that was provided to the third party when no longer needed,” including copies in backups and temporary files, with a specified timeline — mirroring the 99.31 and 99.35 requirements and extending the same discipline to vendors generally, including the ones that take custody of retired hardware.

Because PTAC’s guidance predates NIST’s September 2025 revision, it cites Rev. 1. The framework it adopts is unchanged in Rev. 2 — the three methods survive intact — but an institution writing policy today should cite Rev. 2 for the program and IEEE 2883 for technique, and treat PTAC as the Department’s endorsement of that approach for education records.

Bottom line

PTAC turns FERPA’s silence into a recommendation: NIST 800-88 methods by sensitivity, signed certification of each destruction, and contracts that require third parties to destroy PII on a timeline. That is the Department’s own description of a compliant disposition program.

Section 04

Where education records hide on campus

Institutions tend to picture education records in the student information system. FERPA’s definition follows the record to every device it touches.

Device populationTypical education records presentDisposition consideration
Faculty and staff laptops and workstationsGrade exports, advising notes, accommodation records, financial-aid correspondence, class rostersHighest-volume population; departed-employee devices are the classic gap
Registrar, bursar, and financial-aid serversThe systems of record and their backupsCertificated Purge or Destroy per drive; retention cleared with the records officer first
Copiers and multifunction printersScanned transcripts, forms, and correspondence cached on internal storageDrive removal or vendor-verified overwrite before lease return
Student and classroom devices (1:1 programs, carts, labs)Student work, accounts, cached credentialsSanitize before redeployment, resale, or donation; volume favors device-internal sanitize commands
Research computingStudy data disclosed under the studies exceptionThe 99.31 destruction deadline in the study agreement governs; document destruction to the agreement
Health and counseling centersTreatment records (may be HIPAA or FERPA depending on setting) and student health recordsConfirm which regime applies; the HIPAA guide covers the medical side

The pattern across the table is that education records are distributed across the campus in proportion to who touches students — which is nearly everyone — and that the devices most likely to leave campus with records intact are the ones furthest from central IT: the departed instructor’s laptop, the department’s copier at lease end, the donated lab cart. A FERPA-aware disposition program is an inventory program first.

Section 05

The overlay: state student-privacy laws and HIPAA

FERPA sets the federal floor for education records. Two other bodies of law routinely sit on top of it at the disposition stage.

State student-privacy laws. Since 2014 a majority of states have enacted student data privacy statutes — many modeled on California’s Student Online Personal Information Protection Act — that impose security and, in many cases, deletion or destruction obligations on schools and on the operators and vendors that hold student data for them. These frequently require data to be deleted upon request or when no longer needed for the contracted purpose and require contracts with vendors to address it. State data-breach and data-disposal statutes of general application also reach institutions as holders of personal information. The Compliance Map and the multi-state guide cover the state layer; the operative point is that FERPA’s silence on method does not mean the institution’s state is silent.

HIPAA. Student health records held by a school’s health or counseling service are generally education records under FERPA (or “treatment records” for eligible students) rather than HIPAA protected health information, but records held by a hospital-affiliated clinic or a covered entity operating on campus may be PHI. The Departments of Education and Health and Human Services have published joint guidance on the boundary. For disposition, the practical rule is to identify which regime governs a health-record device before it is retired — HIPAA brings a security rule and breach-notification duties that FERPA lacks. The HIPAA field guide covers that side.

Scope caution

State student-privacy statutes vary significantly in scope, definitions, and vendor obligations, and the FERPA/HIPAA boundary is fact-specific. This section identifies the overlay; it does not describe any state’s law or resolve any institution’s classification question. Consult counsel.

Section 06

The ITAD program, FERPA edition

For an institution, FERPA-aligned disposition is mostly the Department’s own PTAC recommendations applied to hardware.

  • Treat every device as a potential education record. Inventory by role and location, not just by asset class; the departed instructor’s laptop and the department copier are the highest-risk populations.
  • Adopt NIST SP 800-88 Rev. 2 by name. PTAC endorses the Clear/Purge/Destroy framework; cite the current revision for the program and IEEE 2883 for technique, and choose the method by the sensitivity of the records present.
  • Clear retention before destruction. Institutional records schedules and state archives rules govern when; FERPA and PTAC govern that it be done properly. Records management signs off first.
  • Certify every destruction. PTAC’s signed certification form is NIST 800-88 Rev. 2’s Certificate of Sanitization in substance: per device, method, date, and the responsible person.
  • Put destruction in every third-party agreement. Study agreements (99.31) and authorized-representative agreements (99.35) must specify destruction and a time period; PTAC recommends the same term, including backups, for every vendor holding PII — including the ITAD vendor taking custody of hardware.
  • Sequence copier and lease returns. Internal storage removed or vendor-verified overwritten before any device leaves under a lease; put the term in the lease.
  • Redeploy and donate only after sanitization. 1:1 and lab devices have long second lives; a Purge with verification before redeployment or donation keeps a good practice from becoming a disclosure.
  • Map the overlay. Identify which state student-privacy and disposal statutes apply, and which health-record devices fall under HIPAA instead of FERPA.

CyberCrunch is NAID AAA certified continuously since 2012 and R2v3, RIOS, and PA DEP certified; sanitizes to NIST SP 800-88 Rev. 2 with IEEE 2883 technique selection; and documents every device with a serialized certificate that carries the fields PTAC’s certification form and NIST’s Certificate of Sanitization describe. The Higher Education ITAD video and the FERPA Doesn’t Graduate short cover the campus story in minutes.

Bottom line

Inventory by role, adopt 800-88 Rev. 2 and IEEE 2883, clear retention first, certify per device, write destruction into every agreement, handle copiers and leases, sanitize before redeployment, map the state and HIPAA overlay. That is FERPA-aligned disposition as the Department itself describes it.

Section 07

Frequently asked questions

Does FERPA require schools to destroy student data on retired computers?

Indirectly for the institution's own devices and directly in two situations. FERPA prohibits disclosure of personally identifiable information from education records without consent except under listed exceptions, so a retired device that exposes records is a disclosure violation. Separately, 34 CFR 99.31(a)(6)(iii)(C) requires organizations conducting studies to destroy PII when no longer needed within a specified period, and 34 CFR 99.35(b)(2) requires authorities conducting audits or evaluations to destroy PII when no longer needed. The regulations do not specify a destruction method; the Department of Education's Privacy Technical Assistance Center recommends NIST SP 800-88 methods.

What are 'education records' under FERPA?

Under 34 CFR 99.3, records that are directly related to a student and maintained by an educational agency or institution or by a party acting for it, in any medium. The definition follows the record rather than the system, so grade exports on a faculty laptop, financial-aid files on a workstation, scanned transcripts cached in a copier, and study data on research computing are education records as long as they exist, and their disposition is subject to FERPA's disclosure rules.

Does FERPA specify a data destruction method?

No. The statute and regulations require that personally identifiable information be destroyed in the studies and audit/evaluation contexts and prohibit unauthorized disclosure generally, but they do not prescribe how destruction is performed. The Department of Education's Privacy Technical Assistance Center fills the gap in its Best Practices for Data Destruction, adopting NIST SP 800-88's Clear, Purge, and Destroy framework selected by data sensitivity, recommending signed certification forms for each destruction, and recommending contract terms requiring third parties to destroy PII, including backups, on a timeline.

What does PTAC recommend for destroying student data?

PTAC frames destruction as a required stage of the data lifecycle, states that simple deletion is not effective because data remain recoverable, adopts NIST SP 800-88's Clear, Purge, and Destroy categories chosen by sensitivity, recommends certification forms signed by the person performing the destruction that record what was destroyed, how, and when, and recommends that written agreements with third parties require destruction of all PII provided, including copies in backups and temporary files, within a specified period. Its guidance cites NIST Rev. 1; the framework is unchanged in the September 2025 Rev. 2.

Are student health records at a school covered by FERPA or HIPAA?

Usually FERPA. Health records maintained by a school's own health or counseling service on students are generally education records (or treatment records for eligible students) and are excluded from HIPAA's definition of protected health information; records held by a hospital-affiliated clinic or other HIPAA covered entity operating on campus may be PHI. The Departments of Education and Health and Human Services have issued joint guidance on the boundary. For disposition, identify which regime governs each health-record device before retirement, because HIPAA brings security and breach-notification duties that FERPA does not.

THE CERTIFICATION PTAC DESCRIBES

Campus disposition with a signed record for every device

CyberCrunch retires faculty, staff, classroom, and administrative devices with sanitization to NIST SP 800-88 Rev. 2, IEEE 2883 technique selection, and a serialized certificate per device — the certification form the Department’s own guidance recommends. NAID AAA certified since 2012; R2v3, RIOS, and PA DEP certified.

NAID AAA · SINCE 2012 R2v3 · APPENDICES A/B/C RIOS PA DEP · WMGR081

This guide is informational only and reflects, as of September 2026, the Family Educational Rights and Privacy Act (20 U.S.C. 1232g), its regulations at 34 CFR Part 99 as published in the Electronic Code of Federal Regulations, and the U.S. Department of Education Privacy Technical Assistance Center’s Best Practices for Data Destruction. Quotations are from those sources. It describes federal requirements at the pattern level; state student-privacy, data-disposal, and breach-notification laws, institutional records schedules, and the FERPA/HIPAA boundary add requirements that vary by state and institution. It is not legal advice, creates no attorney-client relationship, and should not be relied on to determine any institution’s obligations; consult qualified counsel. CyberCrunch credential and practice statements reflect certificates and procedures at the time of publication.