Article

FERPA and Career Readiness Data: What Actually Applies

September 2, 2026 · 7 min read

FERPA and Career Readiness Data: What Actually Applies
Photograph by Hanna Pad on Pexels.

FERPA can apply to career readiness data when the school maintains the data as part of a student’s education records, and a vendor does not get a pass simply because the data came from an assessment platform. The practical questions are: who created the record, where it is maintained, who can access it, and whether an employer or faculty rater’s comments are being treated as part of the student’s education record.

What counts as an education record

Under FERPA, an education record is broadly defined as a record that is directly related to a student and maintained by an educational agency or institution, or by a party acting for the institution. That can include a career readiness assessment result if the school keeps it in a student record system, uses it in advising, or retains it for program review in a way that ties it to an identifiable student.

The phrase “directly related to a student” does not require grades or transcripts. A rubric score, a competency rating, a supervisor comment, or a student self-assessment can all be education records if the institution maintains them as student records. The key limit is maintenance by the school or its agent. A student-furnished document that the school never keeps is not an education record, but once the institution stores it, the analysis changes.

Examples that usually fit

A few common examples help show the boundary:

  • A student completes a career readiness assessment and the institution stores the results in its advising platform.
  • An internship office keeps employer evaluations tied to named students for program oversight.
  • Faculty supervisors submit rubric ratings through a university-managed system and the school retains them.

In each case, the material is likely to be part of the education record because the school maintains it and it relates to an identifiable student.

Examples that usually do not, by themselves

Not every piece of career-related information becomes an education record:

  • Aggregate reports with no student identifiers.
  • Data that a third party keeps solely for its own internal operations, without acting for the school.
  • Anonymous feedback that cannot reasonably be linked back to a student by the institution.

Those distinctions matter because FERPA is about the institution’s records. A vendor’s database is not automatically a FERPA problem, but it can become one if the vendor is acting on the school’s behalf and holding student data for the school.

The school official exception and what it requires of a vendor

The school official exception is the main reason a vendor can receive FERPA-covered data without getting separate consent in many campus workflows. A contractor can qualify as a “school official” if it meets the institution’s criteria and performs an institutional service or function for which the school would otherwise use employees.

That exception is not open-ended. It depends on the school’s control over the vendor relationship and on a legitimate educational interest in the data.

What a vendor typically needs to satisfy the exception

A vendor relationship is more likely to fit the exception when all of the following are true:

  • The vendor performs a service the institution would otherwise do itself, such as collecting internship evaluations or administering competency assessments.
  • The school uses the vendor for a legitimate educational purpose, such as advising, program improvement, or accreditation reporting.
  • The institution has direct control over how the vendor uses the data.
  • The vendor agrees to use the data only for the contracted service and not for unrelated purposes.
  • Access is limited to personnel who need it to perform the service.

If those conditions are not present, the school official exception is weaker. A vendor that wants to reuse student data for product development, marketing, or building cross-client benchmarks needs a careful legal review. Some uses may be possible if the data are de-identified, but “de-identified” has a real standard, and casual stripping of names is not enough when re-identification remains possible.

What schools should look for in the contract

Schools often focus on the privacy policy and miss the contract. The contract is where the operational limits belong. It should address, at minimum:

  • Permitted uses of the data.
  • Whether the vendor may disclose data to subcontractors.
  • Security controls and breach notification.
  • Data retention and deletion.
  • Whether the vendor may aggregate or de-identify data, and under what conditions.
  • Whether the school can access, correct, or export the student records.

If a vendor is acting as a school official, the institution still owns the FERPA responsibility. The school cannot outsource compliance.

Where employer-provided ratings sit

Employer-provided ratings are usually treated the same way as faculty-provided ratings once the institution maintains them in a student file. The fact that an employer entered the rating does not remove it from FERPA if the school keeps it as part of the student’s record.

That said, there is an important distinction between the source of the information and the record that the institution maintains. The employer’s original copy may not be a school record. The version stored by the institution usually is, if it is directly related to the student and maintained by the school.

Why this matters in internships and co-ops

Internship programs often collect three kinds of information:

  • Student self-assessments.
  • Supervisor ratings from employers or site mentors.
  • Faculty evaluations or reflections.

Once the institution retains these materials tied to a student’s identity, they are likely education records. A supervisor’s candid comment about communication or professionalism can therefore become part of a FERPA-protected file if the school keeps it.

That has two practical consequences. First, schools need a clear process for access requests, correction requests, and disclosure decisions. Second, they should avoid promising employers that ratings will never be seen by students unless the school’s actual practices and policies support that promise. In many cases, students have a right to inspect records about them, subject to FERPA’s exceptions.

A common misconception

Some campuses assume employer evaluations are “outside FERPA” because the employer is not the school. That is too broad. The better question is whether the school maintains the evaluation as a record directly related to the student. If yes, FERPA likely applies to the school’s copy, regardless of who authored it.

Practical boundaries for assessment data

Career readiness data often includes a mix of identifiable and aggregated information. FERPA analysis should separate those layers instead of treating everything the same.

Identifiable student-level data

These records are the most likely to fall within FERPA:

  • Student self-ratings tied to an ID number or name.
  • Supervisor evaluations connected to a student.
  • Competency scores used in advising.
  • Narrative comments that identify a student.

Aggregated or de-identified data

These can sometimes be used more freely, but only if they are truly not personally identifiable. If a report covers five students in a small internship site, the identities may still be apparent. Small-n data can be hard to de-identify in practice, especially when the field placement is unique or the cohort is small.

Operational questions to ask before sharing

Before sharing career readiness data, ask:

  • Is the recipient acting for the institution, or independently?
  • Will the data be maintained by the school or a vendor on the school’s behalf?
  • Does the recipient need student-level information, or would aggregate data suffice?
  • Could the student reasonably be identified from the report?
  • Does the school’s policy already cover this use?

These questions usually get you closer to a defensible answer than a label like “assessment data” or “employer feedback.” The label does not control the FERPA analysis.

What schools should document

For programs that collect student, faculty, and employer ratings, the safest approach is to document the record flow. Know what is collected, who can see it, how long it is kept, and which disclosures are routine. If a vendor hosts the data, the institution should document why the vendor qualifies as a school official and what limits apply to the vendor’s use.

That documentation is also useful for accreditation and internal audits. It helps a school explain why one dataset is treated as an education record and another is not, instead of making ad hoc decisions later.

For institutions that use a career readiness platform, vendor terms should match the school’s FERPA analysis, not the other way around. Products can support compliance, but they do not define it.

General information, not legal advice

This overview is general information, not legal advice. FERPA questions are fact-specific, and the answer can change based on a school’s policies, the exact data fields collected, the vendor contract, and how the institution actually uses the records. When a program is expanding data collection, sharing ratings with employers, or using a vendor for reporting, the safest course is to have institutional counsel review the workflow before it goes live.

The Career Readiness Report is free for every college and university. Open now, in beta.

Create your institution