FERPA Compliance

De-identification of student PII and determination of re-identification risk

Some of the most important provisions of the Family Educational Rights and Privacy Act (FERPA) of 1974 concerning stored data include: * **Student's Right to Access:** Parents and eligible students (those 18 or older or attending a post-secondary institution) have the right to inspect and review the student's education records. This includes records maintained by the school, district, or any entity acting on their behalf. * **Consent for Disclosure:** Generally, schools must have written consent from the parent or eligible student before disclosing personally identifiable information from education records to outside parties. There are specific exceptions to this consent requirement, such as disclosures to school officials with legitimate educational interests, to comply with a judicial order or subpoena, or in cases of health and safety emergencies. * **Accuracy of Records:** Schools must take reasonable steps to ensure that education records are accurate, up-to-date, and that the personally identifiable information contained within them is not misused. Parents and eligible students have the right to request amendments to records they believe are inaccurate, misleading, or otherwise in violation of their privacy. * **Definition of Education Records:** FERPA defines "education records" broadly to include a wide range of information maintained by an educational agency or institution or by a person acting for such agency or institution which relates to a student. This can include grades, transcripts, disciplinary records, and personally identifiable information like names, addresses, and social security numbers. However, certain records are excluded, such as law enforcement unit records, sole possession notes sent only to the maker, employment records, and medical records of students over 18 which are maintained by a physician or other recognized professional and made on the occasion of a visit. * **Directory Information:** Schools may release certain "directory information" without consent, such as a student's name, address, telephone number, date and place of birth, honor roll status, and participation in officially recognized activities and sports. However, parents and eligible students must be notified of these categories of directory information annually and have the right to refuse disclosure of this information. * **Record of Disclosure:** Schools must maintain a record of all disclosures of personally identifiable information from education records, except for disclosures made to school officials with legitimate educational interests or those made with written consent. This record must include the parties who received the information and their legitimate interest in receiving it. * **Protection of Personally Identifiable Information (PII):** FERPA aims to protect sensitive PII within education records, preventing its unauthorized access, use, or disclosure. This includes ensuring systems and procedures are in place to safeguard this data.

A program must establish procedures to protect the confidentiality of any personally identifiable information (PII) in child records.“

„(a) A program must maintain child records in a manner that ensures only parents, and officials within the program or acting on behalf of the program have access, and such records must be destroyed within a reasonable timeframe after such records are no longer needed or required to be maintained.“

This creates the need for software capable of classifying and finding student records, de-identifying or deleting them, and auditing changes to student records managed by educational institutions and the agencies that serve them. All of these functions are included in the affordable IRI FieldShield-, CellShield– and DarkShield- data masking tools included – or in the comprehensive IRI Voracity-data management platform that includes these tools – while enabling integration, cleansing, migration/replication, and reporting on disparate data.

 

PII can also include indirect information in a dataset or „quasi-identifiers“ that, when used with or without directly identifying information, can still identify a student. Consider e.g. in the following list:

As enforced under 20 U.S. Code § 1232g and defined under 34 CFR § 99.3, PII includes, but is not limited to,

Evaluation Assistant Re-ID Risk, who in static Data masking tool IRI FieldShield, which is included, uses expert-vetted algorithms to determine and measure the risk of re-identification based on the distinguishing and separating attributes of one or more quasi-identifiers (demographic data) in a student dataset. As long as the dataset is in a flat file (e.g., CSV) or a JDBC-connected data source (e.g., an SQL Server table), it will work.

These features can also help data recipients and other authorized third parties comply with the provisions of the Protection of Pupil Rights Amendment (PPRA) and Section 1061 (Student Privacy) of the No Child Left Behind Act. These data users can leverage the results of the risk determination report to further refine the riskier quasi-identifiers. generalize (to be anonymized) so that the utility of this data is preserved.

In short: Complying with FERPA is about protecting student data. The security features for educational data in the Data masking tools von IRI can help you find and protect PII and other sensitive information in structured, semi-structured, and unstructured data sources – on-premises or in the cloud!