FERPA & COPPA

Privacy & Compliance / Law guide

FERPA and COPPA for Website Tracking

Summary

FERPA and COPPA both limit what tracking tags on education and children’s websites can collect and share. FERPA protects students’ education records. COPPA protects personal information collected online from children under 13, including cookies and device identifiers. Since April 22, 2026, it also requires separate parental consent before most third-party disclosures, which the FTC says covers targeted advertising.

FERPA is the Family Educational Rights and Privacy Act. COPPA is the Children’s Online Privacy Protection Act, enforced by the Federal Trade Commission (FTC) through its COPPA Rule. The two laws overlap on edtech platforms, school portals, and any site students use, and a single analytics or ad tag can raise questions under both.

The sections below take each law in turn, then cover the amended COPPA Rule, teenagers and enforcement. They finish with how to check what your tags collect from students and children, and what schools and edtech companies should do.

What is FERPA, and does it apply to website tracking?

FERPA is a federal law that protects the privacy of students’ education records at schools and colleges that receive US Department of Education funding. It generally requires consent from a parent, or from the student once they turn 18 or enter college, before a school discloses personally identifiable information from those records.

FERPA applies to tracking when a tag can see information from education records. That usually means logged-in pages: a student portal, a learning management system, a grades or enrollment page, or a financial aid form. If a third-party tag on those pages captures page content, URLs, or form fields that reveal a student’s records, the school may be disclosing that information without consent.

Schools can share records with vendors under FERPA’s “school official” exception only when all three conditions are met: the vendor performs an institutional service for the school, is under the school’s direct control for the use and maintenance of the records, and is subject to FERPA’s limits on use and redisclosure (34 CFR 99.33(a)). An advertising pixel that sends data to an ad platform for the platform’s own use is hard to fit into that exception.

The Supreme Court held in Gonzaga University v. Doe (2002) that FERPA’s nondisclosure provisions create no personal rights enforceable under 42 U.S.C. 1983. Enforcement rests with the Department of Education. Its remedies include withholding payments and cease-and-desist orders, and it can end a school’s funding eligibility only when compliance cannot be secured by voluntary means.

What is COPPA, and how does it apply to tracking?

COPPA applies to operators of websites, apps, and online services directed to children under 13, and to general-audience services that have actual knowledge they are collecting personal information from a child under 13. It requires verifiable parental consent before collecting, using, or disclosing that information.

Under the COPPA Rule, persistent identifiers count as personal information. A persistent identifier is something that recognizes a user over time and across sites, such as a cookie ID, an IP address, or a mobile device ID. That is why ordinary analytics and advertising tags fall under COPPA. There is a narrow exception for identifiers used only to support the site’s internal operations, such as keeping it running or measuring its own performance. Using them for behavioral advertising or to build profiles falls outside that exception.

What changed in the amended COPPA Rule?

The FTC published amendments to the COPPA Rule on April 22, 2025. They took effect June 23, 2025, and most requirements have applied since the compliance date of April 22, 2026.

The change that matters most for tracking is separate consent for third-party disclosure. Operators must now get separate verifiable parental consent to disclose a child’s personal information to third parties, unless the disclosure is integral to the website or online service. The FTC says this covers targeted advertising. For a site running ad pixels on child-directed pages, that means the pixel’s data sharing needs its own consent.

The amendments also add biometric identifiers to the definition of personal information, widen the Social Security number item to cover government-issued identifiers, and require a written information security program and a written data retention policy.

What about teenagers?

COPPA stops at 13. State privacy laws pick up some of the gap. Under the California Consumer Privacy Act (CCPA), a business cannot sell or share the personal information of a consumer it knows is at least 13 and under 16 without that teen’s affirmative opt-in consent (for under 13, a parent’s or guardian’s). A business that willfully disregards a consumer’s age is treated as knowing it. “Sharing” under the CCPA includes passing data to third parties for cross-context behavioral advertising, which is what many ad pixels do.

For how the CCPA treats tags in general, see CCPA and CPRA for tags.

What does enforcement look like?

Two actions show the pattern regulators focus on.

In May 2023, the FTC acted against the edtech platform Edmodo, in a complaint filed by the Department of Justice on the FTC’s behalf. The FTC said Edmodo used children’s personal information, including persistent identifiers, for advertising, and pushed its COPPA compliance duties onto schools and teachers. The order carried a $6 million civil penalty, suspended because of the company’s inability to pay. Samuel Levine, then Director of the FTC’s Bureau of Consumer Protection, said the order “makes clear that ed tech providers cannot outsource compliance responsibilities to schools, or force students to choose between their privacy and education.”

In March 2026, the California Privacy Protection Agency (CalPrivacy) fined PlayOn Sports, which runs the GoFan ticketing platform used by high schools, $1.1 million under the CCPA. The order says ticket holders had to click “Agree” to tracking before they could use their tickets, were pointed to industry opt-out tools instead of PlayOn’s own, and had their opt-out preference signals ignored. PlayOn neither admitted nor denied most of the allegations. CalPrivacy described it as the first Board decision on student privacy, as of March 2026. Michael Macko, CalPrivacy’s head of enforcement, said: “Students trying to go to prom or a high school football game shouldn’t have to leave their privacy rights at the door.”

The full case detail is on Enforcement Watch: PlayOn Sports’ $1.1M CPPA fine.

How to check what your tags collect from students and children

Compliance under both laws turns on facts about your tags: which ones run on which pages, what each sends, and whether consent and opt-out signals are honored before anything fires. Those facts come from testing.

DataTrue sensitive data results for a PII leak check: the persona's credit card number, email and SSN were each found once.

DataTrue tests your live site in a real browser and records what every tag sends. A Coverage test crawls the whole site and reports what is tagged on every page, including tags added outside your tag manager. A Simulation test walks a defined journey, such as logging into a student portal or opening a digital ticket, in each consent state, and checks what fires at each step. Sensitive Data Detection inspects the payloads for personal data. Because the tests use fictitious personas, invented students with fake details, no real child’s data is involved. Tests also check whether tags respect Global Privacy Control, the browser signal that tells a site not to sell or share the visitor’s data.

Tests run on a schedule, with alerts when something changes, such as an ad tag appearing on a logged-in page after a release. The result is a timestamped record of what each tag sent and where.

What should schools and edtech companies do?

  • Keep advertising tags off logged-in student pages and any page that shows education records, and confirm with testing that they stay off.
  • Treat persistent identifiers as personal information on child-directed pages. Limit tags there to what supports internal operations, or get verifiable parental consent.
  • Get separate parental consent before a child’s data goes to third parties for advertising.
  • Honor opt-out preference signals such as Global Privacy Control, and get opt-in consent before selling or sharing data from users you know are at least 13 and under 16 in California.
  • Monitor continuously, because tags change with every release and campaign.

Questions

Does FERPA apply to website analytics?

It can. FERPA applies when a school discloses personally identifiable information from education records without consent. A third-party tag on a student portal or grades page that captures that information can be a disclosure. Public school web pages with no student records are generally outside FERPA.

Does COPPA apply to cookies and tracking pixels?

Yes. The COPPA Rule treats persistent identifiers such as cookie IDs, IP addresses, and device IDs as personal information. Using them on a child-directed site for anything beyond supporting the site’s internal operations, such as behavioral advertising, requires verifiable parental consent.

What changed in COPPA in 2026?

The amended COPPA Rule, published April 22, 2025, reached its compliance date on April 22, 2026. It requires separate verifiable parental consent before disclosing a child’s personal information to third parties, unless the disclosure is integral to the website or online service. The FTC says this covers targeted advertising. It also adds written security and data retention requirements.

Can a school consent to tracking on behalf of parents?

Only in limited cases, and only under FTC guidance: the 2025 amendments did not write school consent into the COPPA Rule. The guidance lets a school consent only where the operator collects students’ personal information for the use and benefit of the school and for no other commercial purpose. It does not cover commercial uses such as advertising. In its 2023 Edmodo action, the FTC made clear that an edtech provider cannot shift its COPPA compliance duties onto schools.

Can students sue under FERPA?

Not under 42 U.S.C. 1983. The Supreme Court held in Gonzaga University v. Doe (2002) that FERPA’s nondisclosure provisions create no personal rights enforceable under that statute. Whether other claims, such as state-law claims, are available is a separate question. The Department of Education enforces FERPA and can withhold payments, issue cease-and-desist orders, or, where voluntary compliance fails, end a school’s funding eligibility.

30-day free trial

Find personal data in your tags before an ad platform does

DataTrue fills your forms with test personas and reads each tag request for emails, names and card numbers. A leak shows up in a test, with the tag and the page that sent it.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue flagging sensitive data found in a tag request: a credit card number, an email address and an SSN from a test persona
Sensitive data found in a tag request