What FERPA is — and what it isn’t
Most compliance frameworks reach disposition through a security rule. FERPA reaches it through the definition of a disclosure.
The Family Educational Rights and Privacy Act, 20 U.S.C. 1232g, with regulations at 34 CFR Part 99, applies to educational agencies and institutions that receive funds under programs administered by the U.S. Department of Education — effectively all public K-12 schools and districts and nearly all postsecondary institutions. It gives parents, and students once they turn 18 or enroll in postsecondary education (“eligible students”), the right to inspect and review education records, to seek amendment, and to consent to disclosures of personally identifiable information from those records, subject to exceptions.
Education records (34 CFR 99.3) are records that are “directly related to a student” and “maintained by an educational agency or institution or by a party acting for the agency or institution.” The definition is medium-neutral — paper, electronic, or otherwise — and it does not care where the record sits. A grade export on a departed teacher’s laptop, a financial-aid file cached on a registrar’s workstation, a scanned transcript in a copier’s memory: all education records, all subject to the disclosure rules until they cease to exist.
What FERPA does not contain is as important. There is no general security rule comparable to HIPAA’s, no breach-notification requirement, no prescribed destruction method, and no private right of action — enforcement runs through the Department’s Student Privacy Policy Office, with the ultimate sanction being loss of federal funding. That structure shapes how the law reaches disposition: not through a “you must sanitize” provision, but through the fact that a retired device disclosing education records to an unauthorized person is a FERPA violation, and through two provisions that require destruction directly.
FERPA governs who may see education records. A retired device that lets the wrong person see them is a disclosure violation regardless of how it happened — which is why disposition is a FERPA matter even though the statute never mentions hardware.
The two express destruction duties
FERPA’s regulations require destruction of personally identifiable information in exactly two places, both attached to disclosure exceptions.
The studies exception — 34 CFR 99.31(a)(6). An institution may disclose PII without consent to organizations conducting studies for or on its behalf (to develop or validate tests, administer student aid, or improve instruction), but only under a written agreement that, among other requirements, must “require the organization to destroy all personally identifiable information when the information is no longer needed for the purposes for which the study was conducted and specifies the time period in which the information must be destroyed.” The destruction duty and the deadline are mandatory contract terms.
The audit and evaluation exception — 34 CFR 99.35. Authorized representatives of state and local educational authorities and certain federal officials may access PII to audit or evaluate federal- or state-supported education programs or to enforce legal requirements. Under 99.35(b)(2), information collected for those purposes must, except where the parent or eligible student has consented or the collection is specifically authorized by law, “be destroyed when no longer needed for the purposes listed in paragraph (a)” of the section. The written agreement with an authorized representative must also address destruction and the time period for it.
Neither provision says how. The regulations require that destruction occur and, in the agreements, when; they leave the method to the party performing it. That silence is not permission to be casual — a destruction that leaves PII recoverable has not destroyed it — but it means the technical standard has to come from somewhere else, which is where the Department’s own guidance enters.
| Provision | Who must destroy | When | Method specified? |
|---|---|---|---|
| 34 CFR 99.31(a)(6)(iii)(C) | Organization conducting a study for or on behalf of the institution | When PII is no longer needed for the study, within the period the written agreement specifies | No |
| 34 CFR 99.35(b)(2) | State/local educational authorities and authorized representatives (audits, evaluations, enforcement) | When no longer needed for the audit, evaluation, or enforcement purpose | No |
| Institution’s own retired devices | Not an express duty — governed by the disclosure prohibition and the institution’s record policies | Per the institution’s retention schedule; disposal must not disclose | No |
PTAC’s Best Practices for Data Destruction
The Department of Education’s Privacy Technical Assistance Center wrote the guidance FERPA itself omits, and it points squarely at the same standard the rest of the disposition world uses.
PTAC’s Best Practices for Data Destruction (first issued May 2014, revised 2019) frames destruction as the final stage of the data lifecycle: when data are no longer needed, “destruction of the data becomes a critical, and often required, component of an effective data governance program.” It is explicit that “simple deletion of the data is not effective” because deletion removes references while the data remain recoverable, and it adopts NIST SP 800-88’s Clear, Purge, and Destroy categories as the method framework, to be selected based on data sensitivity.
Two practices in the guidance map directly onto ITAD documentation. First, certification: PTAC recommends “certification forms which are signed by the individual responsible for performing the destruction” recording what was destroyed, how, when, and by whom — which is, in substance, NIST 800-88 Rev. 2’s Certificate of Sanitization. Second, contract terms: written agreements with third parties should require them to “destroy all PII that was provided to the third party when no longer needed,” including copies in backups and temporary files, with a specified timeline — mirroring the 99.31 and 99.35 requirements and extending the same discipline to vendors generally, including the ones that take custody of retired hardware.
Because PTAC’s guidance predates NIST’s September 2025 revision, it cites Rev. 1. The framework it adopts is unchanged in Rev. 2 — the three methods survive intact — but an institution writing policy today should cite Rev. 2 for the program and IEEE 2883 for technique, and treat PTAC as the Department’s endorsement of that approach for education records.
PTAC turns FERPA’s silence into a recommendation: NIST 800-88 methods by sensitivity, signed certification of each destruction, and contracts that require third parties to destroy PII on a timeline. That is the Department’s own description of a compliant disposition program.
Where education records hide on campus
Institutions tend to picture education records in the student information system. FERPA’s definition follows the record to every device it touches.
| Device population | Typical education records present | Disposition consideration |
|---|---|---|
| Faculty and staff laptops and workstations | Grade exports, advising notes, accommodation records, financial-aid correspondence, class rosters | Highest-volume population; departed-employee devices are the classic gap |
| Registrar, bursar, and financial-aid servers | The systems of record and their backups | Certificated Purge or Destroy per drive; retention cleared with the records officer first |
| Copiers and multifunction printers | Scanned transcripts, forms, and correspondence cached on internal storage | Drive removal or vendor-verified overwrite before lease return |
| Student and classroom devices (1:1 programs, carts, labs) | Student work, accounts, cached credentials | Sanitize before redeployment, resale, or donation; volume favors device-internal sanitize commands |
| Research computing | Study data disclosed under the studies exception | The 99.31 destruction deadline in the study agreement governs; document destruction to the agreement |
| Health and counseling centers | Treatment records (may be HIPAA or FERPA depending on setting) and student health records | Confirm which regime applies; the HIPAA guide covers the medical side |
The pattern across the table is that education records are distributed across the campus in proportion to who touches students — which is nearly everyone — and that the devices most likely to leave campus with records intact are the ones furthest from central IT: the departed instructor’s laptop, the department’s copier at lease end, the donated lab cart. A FERPA-aware disposition program is an inventory program first.
The overlay: state student-privacy laws and HIPAA
FERPA sets the federal floor for education records. Two other bodies of law routinely sit on top of it at the disposition stage.
State student-privacy laws. Since 2014 a majority of states have enacted student data privacy statutes — many modeled on California’s Student Online Personal Information Protection Act — that impose security and, in many cases, deletion or destruction obligations on schools and on the operators and vendors that hold student data for them. These frequently require data to be deleted upon request or when no longer needed for the contracted purpose and require contracts with vendors to address it. State data-breach and data-disposal statutes of general application also reach institutions as holders of personal information. The Compliance Map and the multi-state guide cover the state layer; the operative point is that FERPA’s silence on method does not mean the institution’s state is silent.
HIPAA. Student health records held by a school’s health or counseling service are generally education records under FERPA (or “treatment records” for eligible students) rather than HIPAA protected health information, but records held by a hospital-affiliated clinic or a covered entity operating on campus may be PHI. The Departments of Education and Health and Human Services have published joint guidance on the boundary. For disposition, the practical rule is to identify which regime governs a health-record device before it is retired — HIPAA brings a security rule and breach-notification duties that FERPA lacks. The HIPAA field guide covers that side.
State student-privacy statutes vary significantly in scope, definitions, and vendor obligations, and the FERPA/HIPAA boundary is fact-specific. This section identifies the overlay; it does not describe any state’s law or resolve any institution’s classification question. Consult counsel.
The ITAD program, FERPA edition
For an institution, FERPA-aligned disposition is mostly the Department’s own PTAC recommendations applied to hardware.
- Treat every device as a potential education record. Inventory by role and location, not just by asset class; the departed instructor’s laptop and the department copier are the highest-risk populations.
- Adopt NIST SP 800-88 Rev. 2 by name. PTAC endorses the Clear/Purge/Destroy framework; cite the current revision for the program and IEEE 2883 for technique, and choose the method by the sensitivity of the records present.
- Clear retention before destruction. Institutional records schedules and state archives rules govern when; FERPA and PTAC govern that it be done properly. Records management signs off first.
- Certify every destruction. PTAC’s signed certification form is NIST 800-88 Rev. 2’s Certificate of Sanitization in substance: per device, method, date, and the responsible person.
- Put destruction in every third-party agreement. Study agreements (99.31) and authorized-representative agreements (99.35) must specify destruction and a time period; PTAC recommends the same term, including backups, for every vendor holding PII — including the ITAD vendor taking custody of hardware.
- Sequence copier and lease returns. Internal storage removed or vendor-verified overwritten before any device leaves under a lease; put the term in the lease.
- Redeploy and donate only after sanitization. 1:1 and lab devices have long second lives; a Purge with verification before redeployment or donation keeps a good practice from becoming a disclosure.
- Map the overlay. Identify which state student-privacy and disposal statutes apply, and which health-record devices fall under HIPAA instead of FERPA.
CyberCrunch is NAID AAA certified continuously since 2012 and R2v3, RIOS, and PA DEP certified; sanitizes to NIST SP 800-88 Rev. 2 with IEEE 2883 technique selection; and documents every device with a serialized certificate that carries the fields PTAC’s certification form and NIST’s Certificate of Sanitization describe. The Higher Education ITAD video and the FERPA Doesn’t Graduate short cover the campus story in minutes.
Inventory by role, adopt 800-88 Rev. 2 and IEEE 2883, clear retention first, certify per device, write destruction into every agreement, handle copiers and leases, sanitize before redeployment, map the state and HIPAA overlay. That is FERPA-aligned disposition as the Department itself describes it.
Frequently asked questions
Does FERPA require schools to destroy student data on retired computers?
Indirectly for the institution's own devices and directly in two situations. FERPA prohibits disclosure of personally identifiable information from education records without consent except under listed exceptions, so a retired device that exposes records is a disclosure violation. Separately, 34 CFR 99.31(a)(6)(iii)(C) requires organizations conducting studies to destroy PII when no longer needed within a specified period, and 34 CFR 99.35(b)(2) requires authorities conducting audits or evaluations to destroy PII when no longer needed. The regulations do not specify a destruction method; the Department of Education's Privacy Technical Assistance Center recommends NIST SP 800-88 methods.
What are 'education records' under FERPA?
Under 34 CFR 99.3, records that are directly related to a student and maintained by an educational agency or institution or by a party acting for it, in any medium. The definition follows the record rather than the system, so grade exports on a faculty laptop, financial-aid files on a workstation, scanned transcripts cached in a copier, and study data on research computing are education records as long as they exist, and their disposition is subject to FERPA's disclosure rules.
Does FERPA specify a data destruction method?
No. The statute and regulations require that personally identifiable information be destroyed in the studies and audit/evaluation contexts and prohibit unauthorized disclosure generally, but they do not prescribe how destruction is performed. The Department of Education's Privacy Technical Assistance Center fills the gap in its Best Practices for Data Destruction, adopting NIST SP 800-88's Clear, Purge, and Destroy framework selected by data sensitivity, recommending signed certification forms for each destruction, and recommending contract terms requiring third parties to destroy PII, including backups, on a timeline.
What does PTAC recommend for destroying student data?
PTAC frames destruction as a required stage of the data lifecycle, states that simple deletion is not effective because data remain recoverable, adopts NIST SP 800-88's Clear, Purge, and Destroy categories chosen by sensitivity, recommends certification forms signed by the person performing the destruction that record what was destroyed, how, and when, and recommends that written agreements with third parties require destruction of all PII provided, including copies in backups and temporary files, within a specified period. Its guidance cites NIST Rev. 1; the framework is unchanged in the September 2025 Rev. 2.
Are student health records at a school covered by FERPA or HIPAA?
Usually FERPA. Health records maintained by a school's own health or counseling service on students are generally education records (or treatment records for eligible students) and are excluded from HIPAA's definition of protected health information; records held by a hospital-affiliated clinic or other HIPAA covered entity operating on campus may be PHI. The Departments of Education and Health and Human Services have issued joint guidance on the boundary. For disposition, identify which regime governs each health-record device before retirement, because HIPAA brings security and breach-notification duties that FERPA does not.
Campus disposition with a signed record for every device
CyberCrunch retires faculty, staff, classroom, and administrative devices with sanitization to NIST SP 800-88 Rev. 2, IEEE 2883 technique selection, and a serialized certificate per device — the certification form the Department’s own guidance recommends. NAID AAA certified since 2012; R2v3, RIOS, and PA DEP certified.
This guide is informational only and reflects, as of September 2026, the Family Educational Rights and Privacy Act (20 U.S.C. 1232g), its regulations at 34 CFR Part 99 as published in the Electronic Code of Federal Regulations, and the U.S. Department of Education Privacy Technical Assistance Center’s Best Practices for Data Destruction. Quotations are from those sources. It describes federal requirements at the pattern level; state student-privacy, data-disposal, and breach-notification laws, institutional records schedules, and the FERPA/HIPAA boundary add requirements that vary by state and institution. It is not legal advice, creates no attorney-client relationship, and should not be relied on to determine any institution’s obligations; consult qualified counsel. CyberCrunch credential and practice statements reflect certificates and procedures at the time of publication.