Skip to main content
FERPA · USA

What is FERPA and how does Klarway protect student data in the USA?

Updated April 23, 2026

In summary

FERPA is the US federal law that protects the privacy of educational records. Klarway operates as the institution's agent, with explicit contractual data use restrictions, encryption in transit and at rest, and FERPA compliance documentation available on request.

What is FERPA and why is it relevant to proctoring?

The Family Educational Rights and Privacy Act (FERPA) is the US federal law that protects the privacy of student educational records. Enacted in 1974, it establishes that records directly related to a student's academic performance and maintained by the educational institution are private and cannot be disclosed without the student's consent (or parents' consent if the student is a minor).

Online proctoring falls within FERPA's scope in two ways: first, exam recordings and incident reports are records directly related to academic performance. Second, biometric data collected during the identity verification process is linked to the student's record at the institution.

For institutions receiving federal funds from the US Department of Education, complying with FERPA when using proctoring services is not optional — it is a condition of federal funding. Providers acting as contractors for the institution are treated as 'school officials' under FERPA and must comply with the same restrictions.

How does Klarway protect student data under FERPA?

Klarway operates as the institution's agent in processing student data. This means it acts under the institution's instructions as controller and cannot use the data for any purpose other than delivering the contracted service — including marketing, proprietary research or selling data to third parties.

Klarway's service contract includes explicit FERPA compliance clauses for institutions in the USA or with US students. These clauses cover: data use restrictions, access controls, breach notification obligations and retention periods aligned with the institution's policies.

Student data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to data is restricted to institution staff with a legitimate educational need, and to a minimal Klarway technical team for service support. Access is logged in audit trails.

FERPA and GDPR: how they operate together

For institutions operating in both the USA and the European Union or Spain (or with students from both jurisdictions), FERPA and GDPR coexist. Although they have different origins and mechanisms, their core principles are compatible: controlled access, specific purpose, limited retention and data subjects' rights.

The main practical difference is that GDPR requires explicit consent before collecting biometric data, while FERPA primarily regulates access to existing records. In practice, complying with GDPR at the collection phase and with FERPA at the access and disclosure phase covers the obligations of both frameworks.

Klarway documents compliance with each framework separately. For institutions with dual presence, we can provide combined FERPA + GDPR documentation as part of the onboarding process.

Frequently asked questions

FERPA and proctoring

Protect the integrity of your assessments

A Klarway specialist will be in touch with you shortly.