Parents: Do You Know Who Has Accessed Your Child's School Records?
Parents: Do You Know Who Has Accessed Your Child's School Records?
Most parents review their child's grades, attendance, test scores, and teacher communications. Parents of children with an IEP may spend even more time reviewing educational records.
There is another question I believe parents should consider asking:
Who has accessed my child's information, and why?
I did not fully appreciate the importance of that question until I had a reason to examine access to my own child's educational information. What I learned changed the way I think about student privacy, cybersecurity, and the amount of access technical and administrative employees may have behind the scenes.
My experience is also why I believe parents should consider making review of their child's records, including available access and audit information, part of an annual privacy check.
FERPA Gives Parents Important Rights
The Family Educational Rights and Privacy Act (FERPA) gives parents of eligible K-12 students important rights concerning their children's education records. Among them is the right to inspect and review education records maintained by the school.
Schools generally must comply with a parent's request to inspect and review education records within a reasonable period of time, but no later than 45 days after receiving the request. State law may provide a shorter deadline (U.S. Department of Education, n.d.).
FERPA also requires schools to maintain records of many requests for access to and disclosures of personally identifiable information from a student's education records. Where the requirement applies, the record must identify the parties who requested or received the information and their legitimate interests in requesting or obtaining it (34 C.F.R. § 99.32).
There is an important limitation parents should understand: FERPA contains exceptions to this disclosure-record requirement. For example, schools generally do not have to record a disclosure to a school official made under FERPA's school-official exception.
That means asking only for the FERPA "record of disclosures" may not tell the entire story.
Ask for the Records That Already Exist
Parents can be more specific when making a records request. In addition to requesting their child's education records and FERPA record of disclosures, they can ask the district whether it maintains existing electronic records showing access to the child's information.
Depending on the systems used by the school, potentially relevant existing records could include:
Application audit logs showing access to the student's records
Administrative event logs
Authentication or sign-in records associated with relevant access
Records identifying accounts or administrative roles involved
The FERPA record of requests and disclosures required by 34 C.F.R. § 99.32
Policies defining which employees or roles are authorized to access the type of information involved
Existing records documenting the legitimate educational or operational reason for access, where such records are maintained
The wording existing records matters. FERPA does not generally require a school to create a new record simply because a parent requests one. A district also may not retain every type of technical log indefinitely.
This is one reason I believe asking periodically can matter.
Why Technical Access Deserves Attention
A person does not necessarily have to be your child's teacher, principal, counselor, psychologist, or special-education provider to have powerful access within a school information system.
IT administrators, network engineers, system administrators, vendors, and other technical personnel may need elevated privileges to operate school technology.
The cybersecurity question is whether those privileges are appropriately limited.
Having permission to administer a computer system is not necessarily the same thing as having a legitimate educational need to view every piece of information stored inside that system.
This is the principle of least privilege: users should receive only the access necessary to perform their assigned responsibilities.
A 2024 audit by the New York State Office of the State Comptroller demonstrates why this matters. Auditors examining the Charter School of Educational Excellence found that 12 of 125 tested users of its cloud-based Student Information System had excessive or unnecessary permissions to view and modify sensitive student data. Some users could modify information when their responsibilities required only viewing it. The auditors recommended limiting access to sensitive student data according to need and job responsibilities (New York State Office of the State Comptroller, 2024).
Parents therefore do not have to assume that inappropriate access could never happen simply because a school has cybersecurity policies.
They can ask questions.
The Difference Between an Account and a Person
There is another issue parents may never see from the outside: shared or generic administrator accounts.
Imagine an audit record that says:
Administrator accessed Student Record
That may tell you which account was used.
It does not necessarily tell you which human being used it.
If multiple people can use the same generic administrative credentials, establishing individual accountability becomes much harder. This is one reason unique identities, authentication controls, least privilege, and reliable audit records matter.
When reviewing records, parents should therefore pay attention not only to what account accessed information, but whether the school can identify the individual associated with that activity.
If the answer is, "We know an administrator account accessed it, but we cannot determine who was using that account," that is information worth documenting and asking the district to explain.
Consider an Annual Student-Privacy Check
There is no federal requirement that parents perform an annual review. This is simply a practice I believe parents should consider.
Once each school year, consider asking:
What records does the school maintain about my child?
Who has access to those systems?
What existing records show requests, disclosures, or electronic access to my child's information?
What roles or policies authorize that access?
For children receiving special-education services or whose records contain particularly sensitive information, parents may have additional reasons to understand how that information is being protected.
Keep copies of your requests and the school's responses.
Dates matter.
What If the School Says, "We Can't Give You That"?
First, ask the school to clarify the reason in writing.
There is an important difference between:
"That record does not exist."
and
"The record exists, but we will not provide it."
There is also a difference between a FERPA education-record request and a request made under a state's public-records law.
Federal FOIA is generally not the mechanism for obtaining records from a local public school district. FOIA applies to federal agencies. States have their own public-records or open-records laws, and the rules vary by jurisdiction.
If the district denies your request, ask it to identify the legal or policy basis for the denial and identify which records it maintains that are responsive to your request.
Parents can also escalate concerns within the school system through the district's records custodian, superintendent's office, privacy official, special-education administration, or other appropriate district official.
If You Believe Your FERPA Rights Were Violated
The U.S. Department of Education's Student Privacy Policy Office (SPPO) administers FERPA.
A parent who believes their FERPA rights have been violated may file a written complaint with SPPO. The Department strongly encourages parents to try to resolve a FERPA concern with the educational institution first, although doing so is not required before filing a FERPA complaint.
There is also a deadline parents need to know.
A FERPA complaint generally must be filed within 180 days of the alleged violation or within 180 days after the parent knew or reasonably should have known about the alleged violation.
Parents can obtain information about FERPA rights and the complaint process directly from the U.S. Department of Education's Student Privacy Policy Office.
Don't Assume. Ask.
Most parents will never need to investigate suspicious access to their child's educational information.
That does not mean we should ignore who has access to it.
Schools increasingly depend on cloud applications, student information systems, learning platforms, administrative tools, and interconnected technology. Those systems can provide tremendous benefits, but they also mean that sensitive information may be accessible to people parents never interact with.
My own experience taught me something simple:
Access matters. Accountability matters. Logs matter.
Parents should know what information their child's school maintains, understand their rights to inspect education records, and ask what evidence exists showing how sensitive information has been accessed and disclosed.
We routinely teach our children to protect their passwords and personal information.
We should be willing to ask the institutions holding some of their most sensitive information how they are protecting it too.
https://studentprivacy.ed.gov/file-a-complaint
https://studentprivacy.ed.gov/contact
References
New York State Office of the State Comptroller. (2024, June 7). Charter School of Educational Excellence: Information technology (2023M-174). Office of the New York State Comptroller.
U.S. Department of Education, Student Privacy Policy Office. (n.d.). Family Educational Rights and Privacy Act (FERPA). Protecting Student Privacy.
U.S. Department of Education, Student Privacy Policy Office. (n.d.). File a complaint. protecting Student Privacy.
U.S. Department of Education, Student Privacy Policy Office. (n.d.). Inspect and review. Protecting Student Privacy.
Family Educational Rights and Privacy Act regulations, 34 C.F.R. Part 99.
The Myth of “Safe by Default”
We all want to believe that when our kids log in at school, they’re safe, that the tools, platforms, and people behind those glowing screens are trustworthy.
But “approved by the district” doesn’t automatically mean “protected.” In fact, most parents would be shocked at how much data flows through K–12 systems, and who actually has the keys to it.
Schools Are Using More Tech Than Ever. However, in Many Cases Oversight Hasn’t Caught Up
Our students use technology for everything: assignments, testing, attendance, counseling, even behavior tracking. Every one of those clicks generates data, data that can identify your child, track behavior patterns, and follow them long after graduation.
The assumption is that there are experts behind the scenes keeping everything secure. But in many districts, the people with the most access to student systems don’t necessarily have backgrounds in education, cybersecurity, or child protection. Sometimes, they’re promoted internally without formal training, yet have “God Mode” access to every student account, file, and digital communication.
That’s not paranoia. It’s poor oversight.
Why Oversight of Tech Staff Matters
Technology isn’t inherently dangerous - unchecked access is.
When staff with limited training or accountability controls can view, export, or even modify student data, it opens the door to mistakes, misuse, and, in rare but real cases, abuse.
Districts should treat tech access like financial access. You wouldn’t let one person manage the books, sign the checks, and approve the audits, yet that’s exactly what happens in some IT departments.
Oversight protects everyone: students, staff, and even the tech administrators who want to do their jobs ethically. It ensures transparency and reduces the risk of inappropriate access to children’s private digital spaces.
What “Being Tech-Informed” Really Means as a Parent
You don’t need to be an IT expert. You just need to be informed enough to ask the right questions.
Here’s where to start:
1. Who has full administrative access?
Ask your district who can see or export student data, messages, and activity logs. There should be a clear, documented process, not “whoever handles it.” By law, IT departments are to keep a log of access with the 'Educational' purpose for the access. For example, an interim director accessing your child's chat logs, YouTube searches, conversations between classmates should be well documented.
2. Are there access logs or audits?
Most systems - Infinite Campus, Google Workspace for Education, LineWize, Canvas - can produce reports showing who accessed what, and when. Parents have the right to request this information. There is a major difference between a records request and an access request. Click here for more information on that.
3. What training do tech staff receive?
Ask if those managing student accounts are trained on FERPA, COPPA, and ethical handling of minors’ data. You’d be surprised how often the answer is “no.” or worse parents are lied to because staff being questioned do not know.
4. Are third-party apps vetted?
Just because an app is “approved” doesn’t mean it’s safe. Request to see the district’s privacy evaluation checklist for third-party tools. Then review the applications privacy policy for alignment.
These aren’t “nosy” questions - they’re responsible ones. And asking them builds a culture of accountability that protects every student, not just your own.
This Isn’t About Distrust - It’s About Partnership
Parents who ask questions aren’t troublemakers - they’re advocates.
The same systems that connect our kids to the world also collect and store pieces of their identity. That deserves oversight, transparency, and respect.
When we stay informed, we don’t just protect our children’s privacy, we strengthen trust in our schools. Because true safety doesn’t come from silence; it comes from awareness.
So keep asking. Keep learning. Keep showing up.
Your curiosity is the best safeguard your child has.