Scope: how DevAcademia satisfies the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99) when providing services to US K-12 schools, districts, and higher-education institutions.
Audience: school district legal counsel, security auditors, and enterprise-procurement teams performing vendor due diligence.
About this document. This is a transparent description of
how DevAcademia is built to meet its FERPA obligations, and how
students, parents, and institutions exercise their rights — what
we collect, what we preserve, and what we do with data. It is
reviewed periodically and updated as our services and applicable
law evolve. The specific terms governing DevAcademia's role as a
school official are set out in the agreement — including a Data
Processing Agreement — entered into with each institution.
#Executive summary
FERPA is a US federal law protecting the privacy of student education records. When an institution shares records with an outside party such as DevAcademia, that party becomes bound by FERPA through the "school official" exception at 34 CFR § 99.31(a)(1)(i)(B).
When an institution engages DevAcademia, DevAcademia is designed to operate as a school official on its behalf. The exception requires that DevAcademia:
- Performs a service the institution would otherwise use its own
employees for.
- Is under the direct control of the institution regarding the
use and maintenance of education records.
- Adheres to any institutional policy restricting the use and
re-disclosure of education records.
- Uses education records only for the purpose the institution
authorizes.
This document describes how DevAcademia meets each requirement and how students, parents, and institutions exercise their FERPA rights on the platform.
#What FERPA protects
Education records: any record maintained by (or on behalf of) an institution that is directly related to a student and contains personally identifiable information. Under 34 CFR § 99.3 this includes:
- Grades, transcripts, class rosters, disciplinary records
- Test scores, attendance data, coursework submissions
- Behavioral and enrollment data
- Anything derived from those records (aggregations, analytics)
DevAcademia treats all of the above as education records and never uses them for any purpose other than delivering the service the institution authorizes. DevAcademia does not sell student data, does not serve advertising, and does not use student data to train external AI models.
#How DevAcademia meets its FERPA obligations
| Requirement | How DevAcademia satisfies it |
|---|---|
| Data minimization — collect only what's needed | Each institution's data is isolated from every other institution's by design. One institution's records are never visible to another. |
| Direct institutional control | Institution administrators control access, roles, and content within their own environment. DevAcademia acts only on the institution's instructions. |
| Purpose limitation | Education records are used only to provide the learning service — never for advertising, resale, or unrelated profiling. |
| Audit trail — who accessed what and when | Every administrative and governance action is recorded in an append-only, tamper-evident audit log attributed to the actor, available to institution administrators. |
| Encryption | Data is encrypted in transit (TLS) and at rest (provider-managed, block-level encryption on our hosted database and backups). Sensitive integration secrets are additionally encrypted at the application layer, with keys rotated at least annually. |
| Access control | Every data access is gated by role and institution membership. Elevated cross-institution access (used only by DevAcademia platform staff for support) is itself logged. |
| Retention limits | Operational data is auto-removed on a published schedule; education records are retained only as long as the institution wants them. See the data retention schedule. |
| Right to inspect (§ 99.10) | Students have a self-service data export (below). |
| Right to amend (§ 99.20) | Students can file amendment requests reviewed by their institution (below). |
| Disclosure logging (§ 99.32) | Access and disclosure of records is recorded in the compliance audit trail. |
#Student and parent rights on the platform
#Right to inspect and review records — § 99.10
Signed-in students (or parents of minor students, through the institution) can download a machine-readable copy of their own records directly from their dashboard. Each export carries a SHA-256 checksum so the recipient can verify it has not been altered, and it is scoped strictly to the requesting student — it never contains another student's data. The export focuses on the records the student is the subject of; it does not include other students' data or internal grading notes.
- Statutory deadline: 45 days from request (§ 99.10(b)).
DevAcademia's self-service export returns in seconds.
- Every export is recorded in the institution's audit trail as
proof the request was fulfilled.
- If records are needed that fall outside the self-service export,
the institution can request them through DevAcademia support and DevAcademia will assemble them within the same 45-day window.
#Right to request amendment of records — § 99.20
Students can file a formal amendment request from their dashboard when they believe a record is inaccurate or misleading.
- The request goes to the student's institution, which reviews and
accepts or rejects it.
- Statutory deadline: 45 days from request (§ 99.20(a)). The
platform surfaces a countdown to the reviewing administrator.
- If the institution rejects the amendment, the student receives
the § 99.20(c) notice of their right to a hearing.
- Every step of the request is recorded in the institution's
compliance audit trail.
#Breach notification
If DevAcademia discovers a confirmed disclosure of personally identifiable information, it notifies each affected institution's designated FERPA point of contact within 72 hours of confirmation. The institution decides whether to notify affected parents or students, which is the institution's statutory duty. Full details are in the incident & breach notification policy.
#Sub-processors
DevAcademia uses a small number of vetted third-party services to deliver the platform. Each is covered by a written data-protection agreement and is named in the public sub-processor list. Institutions receive at least 30 days' notice before any new sub-processor that will process education records is enabled.
#Data Processing Agreement
DevAcademia provides a Data Processing Agreement (DPA) to each institution it works with that includes the FERPA "school official" designation, purpose and re-disclosure limits, sub-processor terms, breach- notification commitments, and data-return-and-deletion obligations on termination. Institutions can request the current DPA template from compliance@devacademia.com.
#Contact
FERPA questions, vendor due-diligence requests, and rights requests that need DevAcademia's help go to compliance@devacademia.com.
#Change history
| Date | Change |
|---|---|
| 2026-07-12 | Initial public version. |