FERPA Considerations for School SharePoint Sites
What actually goes wrong when student records end up in SharePoint, and what to do about it before an auditor — or a parent — finds it first.
What FERPA actually covers
FERPA protects personally identifiable information in a student's "education record" — and that definition is broader than most people assume. Grades, disciplinary notes, IEPs, health information the school keeps on file — all of it counts. Districts can carve out a small slice as "directory information" (name, grade level, that sort of thing), but the honest truth is that most of what ends up living in a district's SharePoint sites doesn't qualify for that carve-out. It's protected, full stop.
There's also a piece people forget: parents, or students who've turned 18, have a legal right to inspect and correct their own records. That's not just a storage question. It shapes how you build access and retrieval, too.
Where things usually go sideways
The same handful of problems show up again and again across school IT environments — they're common enough to be almost predictable.
Permissions that are way too generous
By far the most common one. A site with student records on it gets shared with "Everyone" or "Everyone except external users" — which sounds harmless until you realize that includes front-office staff, coaches, maintenance, anyone with a district login. FERPA's "school official" exception only covers people with an actual legitimate educational interest in that data. Not "it was easier than setting up proper groups."
External sharing left wide open
"Anyone with the link" is the setting that causes the most heartburn once people understand what it actually means. For anything touching education records, that needs to be off by default at the tenant level, with exceptions made on purpose — not left on because nobody got around to changing it.
Sensitivity labels and DLP policies that were never turned on
Here's the frustrating part: most districts already pay for the tools that would catch this. Microsoft Purview sensitivity labels and DLP policies come with Microsoft 365 for Education licensing. They just sit there unconfigured. Turning them on is often an afternoon of work, not a project.
Vendors with access and no paper trail
FERPA's school official exception can stretch to cover outside contractors, including IT consultants like us — but only with a written agreement spelling out what we can do with the data, how long we can keep it, and how it gets disposed of afterward. If a vendor has access to systems with student records and there's no agreement like that on file, that's a gap worth closing regardless of who the vendor is.
No real retention policy
FERPA doesn't hand you a specific number of years to keep records. What it does expect is that you have a policy at all, and a real process for disposing of what you no longer need. "We've just never deleted anything since we moved to SharePoint" is a familiar story, and an avoidable one.
Where to start
- Audit who actually has access to sites with student records, against who actually needs it
- Turn off open external sharing at the tenant level; handle exceptions case by case
- Turn on sensitivity labels and DLP policies for student PII — you likely already have the license
- Enable audit logging, with retention long enough to satisfy FERPA and your state
- Get written data-handling agreements in place with any vendor touching these systems
- Write down a retention and disposal schedule, then actually follow it
None of this means tearing your SharePoint environment apart and starting over. It's mostly governance work layered on top of what you've already built — the kind of thing that's easy to put off and not that bad once you actually sit down and do it.
Not sure where your organization stands?
Request a free, no-obligation Microsoft 365 / Power Platform audit and we'll tell you plainly.
Request a Quote