> ## Content Index
> Fetch the complete content index at: https://firegap.org/llms.txt
> Use this file to discover other available public pages before exploring further.

# EdTech Surveillance Part III: The File Follows Them
- URL: https://firegap.org/edtech-surveillance-part-iii-the-file-follows-them/
- Published: 2026-09-23T13:49:39.000Z
- Updated: 2026-09-23T13:49:39.000Z
- Description: What happens after a monitoring alert gets generated about your child? There are at least three separate files, three sets of rules, and one of them lives in a company's database rather than your school. FERPA gives you the right to look at the record and argue with it, not to delete it.
- Author: Ryan Gardner
- Tags: Privacy, EdTech Series, EdTech, Data Collection

I spent some time trying to find out what happens to data after your kid has been flagged. I learned that there isn't one file on them. There's at least three, they sit in three different legal categories, and your school district only fully controls one of them.

⁠*(If you’re just joining:* [*Part I*](https://firegap.org/you-signed-a-surveillance-contract-at-back-to-school-night/) *covered the device consent form — the one you signed at back-to-school night that authorized software to read your kid’s searches, emails, and documents, 24/7, including at home.)*

## One Kid, Three Files

You might be picturing a database record on a school computer, or perhaps a spreadsheet. The reality is closer to three parallel systems that occasionally talk to each other.

| Record                | Where it lives                                       | What governs it                                                                          |
| --------------------- | ---------------------------------------------------- | ---------------------------------------------------------------------------------------- |
| The education record  | District student information system, cumulative file | Family Educational Rights and Privacy Act (FERPA). Inspection and amendment rights apply |
| The discipline record | District, sometimes filed separately                 | FERPA plus state law                                                                     |
| The vendor's database | A company's cloud infrastructure                     | The procurement contract, mostly                                                         |

This article is about the third row.

When you ask the school about your kid's data, you're asking an institution about a decision it made during a budget cycle. Districts accessed an average of [2,982 distinct EdTech tools in a single year](https://thelearningcounsel.com/articles/districts-are-reducing-app-counts-teachers-are-still-building-instruction/?ref=firegap.org), measured across 64 billion interactions and 3.7 million students. Nearly three thousand vendors. There isn't a school district on earth that has the staff to audit that.

## 16 Doors

FERPA's headline rule sounds simple: the school needs your consent before it hands out your kid's records. Then there's the fine print — an exceptions clause with 16 conditions where it doesn't. Consent is the lobby; the 16 doors are around the back. A disclosure just needs to fit through one of them, and then consent stops being required.

The door people have heard of the most is door one, because it's how the software gets in. A vendor can be treated as a "school official" — same access as your kid's teacher, no permission from you — but only if it clears three bars at once.

1. It has to be doing a job the district would otherwise pay a staffer to do.
2. It has to be under the district's direct control over how it uses and stores the data.
3. It has to follow the same rules the district follows about passing that data to anyone else. Three conditions, not one.

Sit with number 2 for a moment.

Picture your district's IT department — about 11 people for a mid-sized district. Now picture the company on the other end of the contract: hundreds of engineers, a venture capital cap table, and a product roadmap nobody in your district has ever seen (let alone approved.) That six-person team is, legally, exercising direct control over that company's data practices. This isn't a loophole buried in one bad contract — it's the load-bearing premise under roughly three thousand tools per district. Everyone signs off on it because the alternative is no software at all.

Even the regulation knows this is thin. It says a district that isn't using physical or technological access controls just has to make sure its "administrative policy for controlling access" is effective. That means a policy that says "be careful" counts. It's an honor system, written into federal law, in a sentence almost nobody reads.

I thought I was looking for one loophole and found 16\. Records also move to other schools, to state education agencies, to juvenile justice, to researchers, under subpoena, during a health or safety emergency, and out the directory-information door below. There's no single loophole to find. Disclosure without your consent isn't a bug in FERPA — it's a normal, routine, exhaustively enumerated part of how the whole thing is designed to run.

## The Rights That Don't Include an Eraser

You have the right to inspect and review your child's education records. The district has to comply within a reasonable time and [no more than 45 days](https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-B/section-99.10?ref=firegap.org) after you ask. Some states require faster.

If something in there is wrong, you can request an amendment. If the district refuses, you get a hearing. If it still refuses after the hearing, you can place a statement in the file explaining why you disagree, and that statement has to travel with the record. So, you can look, argue and attach a note, but you cannot delete anything.

And the amendment right is narrow, because it targets records that are inaccurate or misleading. A flag that accurately records that your thirteen-year-old searched a phrase at 9:40pm isn't inaccurate — it's just permanent. [This is the same architecture I found in medical records](https://firegap.org/medical-data-part-i-the-illusion-of-hipaa/). You get transparency and a voice, but not an eraser. Once a system is built to preserve, the strongest right available to you is the right to add context to something that isn't going anywhere.

## The Record That Isn't a Record

Here's where I hit a wall.

A monitoring vendor's alert is an education record if it's directly related to a student and maintained by the district or by a party acting for the district. If the vendor is operating as a school official under direct control, the argument is strong. But if the alert was generated, reviewed, and acted on inside the vendor's own dashboard, and never got ingested into district systems, the answer gets genuinely murky.

I went looking for Department of Education guidance that resolves this. I read the regulations, the FAQ library, the guidance documents, and I couldn't find it. So I went to the vendors instead, and they publish more than I expected. GoGuardian's documentation says they retain report data for [up to 6 months](https://docs.goguardian.com/products/admin/reporting-overview?ref=firegap.org), and reports can't be generated for dates outside that window. Gaggle is more specific: it [purges non-incident data after 30 days](https://www.gaggle.net/trust-and-privacy-center?ref=firegap.org), and holds incident data until one of three things happens — the district ends the relationship, the student graduates or withdraws, or the district requests a full purge.

That's a real policy, publicly posted. But if you look at the three triggers, every one of them belongs to the district. A parent who wants incident data about their own child deleted has no listed path to it. You'd be asking your district to ask the vendor, on a timeline the contract sets.

The part that bothers me is that a record can exist about your child, drive a real consequence in their life, and sit in a category the only applicable federal law never clearly addresses.

The second version of this is that records created by a school's law enforcement unit for a law enforcement purpose, and maintained by that unit, [are excluded from the definition of education records entirely](https://studentprivacy.ed.gov/faq/what-law-enforcement-unit-record?ref=firegap.org). FERPA doesn't cover them. The regulation also says [FERPA neither requires nor prohibits](https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-A/section-99.8?ref=firegap.org) a school from disclosing them. So the moment a flag becomes a police contact, the record of that contact may leave the protected category altogether. In [2022, a CDT survey](https://cdt.org/insights/report-hidden-harms-the-misleading-promise-of-monitoring-students-online/?ref=firegap.org) work found that 44% of teachers knew of a student who had been contacted by law enforcement as a result of monitoring software.

## The Directory Information Trapdoor

This one really irritates me.

Schools can publish a category of information called directory information without your consent. Name, address, phone, photo, and similar. They have to give public notice of which categories they've designated, tell you that you can refuse, and give you a [deadline to opt out](https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-D/section-99.37?ref=firegap.org). That notice usually lives inside the annual packet [Part I was about](https://firegap.org/you-signed-a-surveillance-contract-at-back-to-school-night/) — the one everybody signs in September.

Two things worth knowing. If a district doesn't disclose directory information generally, it still has to give names, addresses, and phone listings to [military recruiters](https://studentprivacy.ed.gov/faq/if-lea-has-not-provided-notice-relating-directory-information-may-it-release-students-name?ref=firegap.org) on request, and notify parents of the opt-out. A parent opt-out does apply to recruiters.  
  
Even if a district designates nothing as directory information, they're still required (if it takes federal funds) to hand over names, addresses, and phone listings to military recruiters by default. Parents can opt out — once a year, via a form most will never see. Silence is treated as consent.

The other thing is that a district may disclose directory information about *former* students without complying with the notice and opt-out conditions at all. Your opt-out is a thing you maintain while your child is enrolled, and its protection is gone the moment they aren't.

## The Fresh Start That Isn't

Before data retention, there's data transfer. One of the 16 conditions permits disclosure to another school where your child seeks or intends to enroll. That's the mechanism behind a records transfer — transcripts have to move.

Discipline moves differently. Federal law requires every state taking federal education money to have a procedure for transferring disciplinary records like suspensions and expulsions to any public or private school your child enrolls in, seeks to enroll in, or is instructed to enroll in. *Instructed to enroll.* The statute anticipates the case where a child is sent somewhere, which is exactly where the disciplinary record matters most.

This is the part I'd want a parent to actually absorb. Changing districts is a move families might make specifically to give a kid a fresh start. New town, new school, nobody knows them. The federal government has required, since 2002, that states build a procedure to make sure the disciplinary record arrives *first*.

This is how buried all of this is: the current regulation still cites the law by its old name — Section 4155(b) of the No Child Left Behind Act of 2001\. The [Every Student Succeeds Act](https://en.wikipedia.org/wiki/Every%5FStudent%5FSucceeds%5FAct?ref=firegap.org) renumbered it in 2015\. The requirement didn't change, but a parent chasing the citation lands on a statute that just says "Transferred."

You'd think there's a federal retention schedule and there just isn't. FERPA sets rights, not timelines, and retention gets decided state by state and district by district. Chicago Public Schools retains permanent student records for [82 years](https://www.cps.edu/sites/cps-policy-rules/policies/700/706/706-1/?ref=firegap.org) after the student's date of birth, and temporary records for five. South Carolina's schedule holds record cards, health, and legal records for [75 years](https://www.law.cornell.edu/regulations/south-carolina/R-12-906.1?ref=firegap.org) after the student separates from school.

The practical takeaway isn't a number, because your number depends on where you live. It's that the schedule exists, it's a public document, and almost no parent has been told to go look at it.

On what colleges can see, there's been real forward movement, and then real movement backwards. Common App [removed its school discipline question](https://www.commonapp.org/blog/common-app-removes-school-discipline-question-college-application/?ref=firegap.org) starting with the 2021-22 cycle — from both the application and the school report — after finding that Black applicants reported disciplinary records at more than twice the rate of white peers. Individual colleges then added the question back in their own supplements, enough of them that Common App now maintains a [list of college-specific discipline questions](https://www.commonapp.org/blog/new-resource-college-specific-school-discipline-questions/?ref=firegap.org) so applicants can find them.

## The Tools Nobody Approved

Everything above assumes the district knows where the data is.

A teacher finds a free tool on a Tuesday, signs up a class, and gets a genuinely better lesson out of it. No procurement, no data agreement, nobody acting in bad faith. With three thousand tools in circulation per district, this happens constantly.

That data is unreachable by an inspection request, because you can only request records the district knows it has.

## What I'd Start Asking For

I'd want to get the vendor list in writing, with each company's retention period, and the state's records retention schedule. But ask specifically whether what you're shown includes vendor-generated monitoring alerts, and if not, where those live And know that asking freezes the clock: once you request to inspect a record, the district can't destroy it while the request is pending. 

## The Part That Doesn't Resolve

I started this looking for a deletion mechanism and there isn't one. Not in FERPA, not in most state schedules, and not in the vendor contracts I could read.

What exists is a set of rights built on the assumption that preservation is the default and the best a parent can do is see the file and add to it. That assumption was written when the file was paper and a district generated maybe a dozen documents about a child over thirteen years. It's now the operating rule for a system that generates alerts continuously, across three thousand tools, for children who won't finish paying it off until they're in their eighties.