Your community college passed its last FERPA review...but the Office of Administrative Law Judges doesn't care about the review you passed; it cares about the six disclosure log entries your SIS vendor made without a legitimate educational interest on record. This FERPA compliance checklist for community college IT teams maps 34 CFR Part 99 to the specific system artifacts, policy documents, and access logs an auditor actually requests, not the statute summaries that dominate every generic guide.
In This Article
- Why Community Colleges Face Disproportionate FERPA Risk
- Education Records & PII Inventory: Know What You're Protecting
- Access Controls & the Legitimate Educational Interest Test
- Third-Party Vendors & School Official Agreements
- Frequently Asked Questions
- Not Sure Your Vendor Agreements and Access Logs Will Hold Up to a FERPA Audit?
Why Community Colleges Face Disproportionate FERPA Risk
Community colleges carry structural risk factors that university-generic FERPA checklists ignore entirely: high adjunct-faculty counts with SIS access provisioned at hire and never reviewed, open-enrollment data volumes that stress recordkeeping systems, dual-enrollment minors whose records sit at the intersection of FERPA and the Protection of Pupil Rights Amendment, and IT staffing ratios that leave compliance execution to whoever has bandwidth.
Adjunct Faculty Access Sprawl
Adjunct faculty — instructors employed on a per-course, non-permanent basis — are often provisioned SIS access equivalent to full-time faculty at onboarding, then retained in the system long after a course ends. An institution with 400 adjuncts teaching in any given term may have years of ghost accounts with live read access to student records. That is an auditor's first stop after the disclosure log.
Dual-Enrollment Minors and the PPRA Intersection
Dual-enrollment students are high school students taking college courses for credit while still enrolled in a K-12 program. Their education records at the community college are governed by FERPA, but because they are minors, certain survey and data-collection activities also trigger the Protection of Pupil Rights Amendment (PPRA). A single miscategorized directory-information disclosure for a dual-enrollment student can implicate both statutes simultaneously.
Lean IT Staffing and the Spreadsheet Gap
The do-it-yourself spreadsheet approach to FERPA tracking — common at institutions without a dedicated compliance role — consistently fails under audit because spreadsheets cannot produce a time-stamped, field-level disclosure log, cannot enforce a permission matrix, and cannot trigger re-attestation workflows. These are exactly the artifacts auditors request. For a closer look at the broader community college IT challenges NewPush addresses, that context applies directly to FERPA readiness.
Education Records & PII Inventory: Know What You're Protecting
Under §99.3, an education record is any record directly related to a student and maintained by the institution or a party acting on its behalf — and auditors verify that the institution can enumerate every system holding such records, not just the SIS. Community colleges routinely miss three record types during inventory.
Early-Alert Intervention Notes
Early-alert systems — platforms used by advisors to flag at-risk students and document outreach — store intervention notes tied to student IDs. These notes are education records under FERPA. If the advising platform vendor can read or export those notes without a qualifying data-use agreement, the institution has an unauthorized disclosure exposure on every record in the system.
LMS Activity Logs
Learning Management System (LMS) activity logs — records of when a student accessed course content, submitted assignments, or participated in discussion forums — are education records when they are tied to a student's identity. Most LMS administrators treat these as system telemetry rather than FERPA-covered data. Auditors do not make that distinction.
Financial-Aid Satisfactory Academic Progress Files
Satisfactory Academic Progress (SAP) files document a student's GPA and credit-completion rate as required for Title IV financial-aid eligibility. These files often live in an ERP module with broader access permissions than the SIS and are rarely included in PII inventory audits. SAP files contain grades, enrollment history, and financial-aid award data — all education record PII under §99.3.
Student ID as Authenticator
Using a student ID number as a sole authenticator — a common pattern in legacy SIS portals — exposes that ID as a FERPA-covered indirect identifier every time it traverses a system. If that ID appears in an LMS log, an advising note, or a financial-aid export, it links back to the student record and must be treated as PII throughout.
Preventing unauthorized movement of these data elements across systems is where preventing unauthorized student data disclosure becomes an operational control, not just a policy aspiration.
Access Controls & the Legitimate Educational Interest Test
The single finding auditors cite most often is role-based SIS access that lacks a documented ""legitimate educational interest"" (LEI) definition. Under §99.31(a)(1), school officials may access education records only when they have a LEI in the records — but without a written, institutionally approved LEI definition, no access grant is defensible during audit.
Written LEI Policy
The LEI definition must appear in a written, board-approved or policy-documented form that auditors can review. Verbal norms and IT-department conventions do not satisfy §99.31(a)(1). The policy must name specific job functions and the corresponding record types each function may access.
FERPA Compliance Checklist: Access Control Items
- Written LEI policy: Adopted by policy, names specific roles and their permissible record types.
- SIS permission matrix: Role-to-record-type matrix documented and version-controlled; current version matches live SIS permissions.
- Quarterly access reviews: Attestation by each role-owner that assigned permissions still match current job function; completed and time-stamped.
- Adjunct offboarding workflow: SIS access revoked within one business day of course-end date; revocation logged.
- Student-worker access scope: Student employees provisioned with minimum necessary access only; separate from general student record access.
- Privileged-account logging: All SIS administrator actions logged with user ID, timestamp, record accessed, and action taken; logs retained per institutional records schedule.
Adjunct faculty and student workers are the two access categories most frequently out-of-scope in community college permission reviews. Both groups turn over rapidly, and neither is consistently included in quarterly attestation cycles.
Third-Party Vendors & School Official Agreements
Under §99.31(a)(1)(i)(B), a vendor qualifies as a ""school official"" with legitimate access to education records only when the institution maintains direct control over the vendor's use of the data and restricts use to the contracted purpose. An unsigned, expired, or sub-processor-silent data-use agreement fails this test outright.
What Auditors Look for in a Data-Use Agreement
Data-use agreements (DUAs) — contracts that govern how a vendor may access, use, and store education records — must contain specific language for FERPA purposes. Auditors pull the DUA and check for four elements:
- Direct-control clause: Institution explicitly retains authority over how the vendor uses student data; vendor may not use data beyond the contracted scope.
- Redisclosure prohibition: Vendor is prohibited from redisclosing education records to sub-processors or third parties without written institutional authorization.
- Sub-processor disclosure: Vendor must enumerate sub-processors with access to education records and notify the institution of any changes before they occur.
- Annual re-attestation: DUA is reviewed and re-executed or attested annually; expired agreements leave the institution without a valid school-official designation for that vendor.
Vendor Coverage Gap at Community Colleges
Most institutions execute a DUA for their SIS vendor and stop. The LMS, ERP, early-alert platform, cloud storage provider, and any third-party identity provider with access to student records all require executed DUAs. Each constitutes a separate school-official designation that must be independently defensible.
FERPA Compliance Checklist: Vendor Agreement Items
- DUA inventory: Every vendor with access to education records appears in a documented inventory with DUA execution date and renewal date.
- Sub-processor clause present: Each DUA names or requires disclosure of sub-processors; institution can produce a current sub-processor list for each vendor.
- Annual re-attestation completed: Each DUA reviewed within the last 12 months; re-attestation time-stamped and stored.
- Termination data-return clause: Each DUA specifies that vendor returns or destroys education records within a defined period upon contract termination.
Colorado community colleges served by NewPush carry an additional obligation under CRS § 22-16-107, the Student Data Transparency and Security Act, which imposes data-inventory and breach-notification requirements that overlap with — and in some cases exceed — FERPA's vendor-agreement expectations. A DUA built only to FERPA minimums may not satisfy the Colorado statute.
Frequently Asked Questions
What records does FERPA actually cover at a community college?
FERPA covers any record directly related to a student and maintained by the institution or a party acting on its behalf — including SIS records, LMS activity logs tied to student IDs, advising notes, financial-aid SAP files, and disciplinary records. Records in a professor's sole possession and not shared with anyone else are excluded.
Does FERPA apply to dual-enrollment high school students?
Yes. Dual-enrollment students taking college courses are covered by FERPA at the community college, not by FERPA at their K-12 school for those records. Because dual-enrollment students are minors, certain data-collection activities involving their records also implicate the Protection of Pupil Rights Amendment (PPRA).
Do our SaaS vendors (LMS, ERP, advising tools) need signed FERPA agreements?
Yes. Every SaaS vendor with access to education records must be designated a school official under §99.31(a)(1)(i)(B) via a signed data-use agreement. The agreement must restrict use to the contracted purpose, prohibit redisclosure, name sub-processors, and be re-attested annually. A vendor without a current DUA is not a qualifying school official.
How do we document FERPA disclosures to satisfy an audit?
Each disclosure log entry under §99.32 must include the requestor's name and their legitimate interest in the records, the date of the disclosure, and the specific records disclosed. Entries for disclosures to school officials and vendors acting under DUAs are exempt from the log requirement — but all other non-consensual disclosures require a logged entry.
Not Sure Your Vendor Agreements and Access Logs Will Hold Up to a FERPA Audit?
Schedule a 15-minute discovery call with NewPush and we'll identify the specific FERPA control gaps most common in community college environments — no generic assessment template, no sales pitch.
Schedule Your 15-Minute Discovery Call