CybrIQ · article
Education/Articles/FERPA and device visibility
K-12 + Higher Ed · Privacy

FERPA and device visibility: the boundary that matters

A 5-minute read for K-12 IT directors, university CIOs, and privacy officers.

Whenever a security vendor enters a conversation with a school district or a university, the privacy question gets asked early. It usually arrives in this shape: "If you have visibility into our network, are you a FERPA school-official-with-legitimate-educational-interest, or are you outside FERPA scope entirely?" The answer matters for the data-sharing agreement, for the institution's annual privacy notification, and for the broader question of what the institution is comfortable having on its network.

This article is the short version of the answer. We are not a FERPA school official, because we do not see the data FERPA covers. The reason is structural. Our scope ends at a layer below the systems that hold education records.

What FERPA actually protects

FERPA (the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g) protects "education records" maintained by an educational institution that receives federal funding. The Department of Education definition is specific: records, files, documents, and other materials that contain information directly related to a student and are maintained by an educational agency or institution. In practice, this includes:

What FERPA does not cover is the network metadata about how a student's device connects to the institution's network. The MAC address of a chromebook, the switch port it is plugged into, the time of day it was online: none of these are education records under any reasonable reading of the statute. They contain no information about the student's academic performance, behavior, or any of the other categories the statute names.

What CybrIQ sees

The CybrIQ scan engine reads each managed switch via SNMP with read-only credentials. The data we capture per port:

From this, we identify the device's vendor and model. A chromebook resolves as "Acer C722 chromebook" (or whatever the actual hardware is). A smart display resolves as "Samsung Flip 65-inch" or whatever the actual model is. The MAC OUI is the largest single signal; LLDP fills in model and firmware where the device advertises.

What CybrIQ does not see

The list below is not aspirational; it is structural. We literally cannot see these things because the scan engine does not read them.

What this means for the data-sharing agreement

The institution's data-sharing agreement (DSA), data-protection addendum (DPA), or vendor-management questionnaire usually has a section asking whether the vendor accesses, processes, or stores student personally identifiable information (PII). For CybrIQ in education, the honest answer is no. We do not access education records; we do not store student PII; we do not transmit student PII to any third party. The agreement can attest to this and the privacy officer can sign without reservation.

If your institution prefers a vendor that signs FERPA school-official terms regardless, we can do that as a posture exercise. The substantive answer does not change: we are not a FERPA school official because we do not see the records FERPA protects. The signing is precautionary, not necessary.

A note for higher education specifically

The same analysis holds for higher-education institutions, with two additions worth naming:

If your privacy officer wants the longer version

The working session is a good place to walk this conversation. We can co-review the institution's existing DSA template against what we actually do. Schedule a working session and we will bring an engineer who has been through the FERPA review at peer institutions.