- Ask who can access student behavior data.
- Review how parent links are created, revoked, and audited.
- Clarify what exports become part of the student record.
- Confirm how the tool fits district privacy policy.
- Treat FERPA, role-based access, and a signed data agreement as the floor, not the finish line.
Compliance reviews are easier when the team knows what to ask. Use this guide to prepare questions about access, sharing, records, parent communication, and data exports.
Ask about access control
Who can view a student? Who can create charts? Who can transfer ownership? Who can see district rollups? These questions matter before broad roster imports.
Ask about exports and records
Clarify when PDFs, reports, and communication logs become records under district policy. The software can support workflow, but the district defines record practices.
Questions for the vendor and the security review
Bring concrete questions to the vendor conversation rather than accepting a marketing sheet. Ask where student data is stored, who at the vendor can access it, and under what circumstances. Ask whether they will sign your district data privacy agreement, such as an NDPA, and whether they are listed with any state or regional student data privacy alliance your district honors. Ask how authentication works, whether single sign-on is supported, and how access is removed when a teacher leaves the district.
Press on the boundaries between roles. A useful answer describes exactly what a teacher, an administrator, and a district-level viewer can each see, and confirms that a teacher cannot browse students outside their caseload. Ask what happens to the data if the district stops using the product: can you export everything, and is it deleted on request. Treat FERPA compliance, role-based access, and a signed agreement as the floor every serious vendor should clear, then judge the product on what it does above that line.
Edge cases worth raising before they happen
The questions that get skipped are usually the ones that bite later. What happens when a student transfers between schools in the district: does the behavior history travel with the record, and who controls that handoff? What about a custody situation where one parent should have access and another should not, since a parent link that cannot be scoped or revoked is a real problem? How are corrections handled when a log entry was a mistake, and is there an audit trail showing what changed?
Raise the adversarial scenario too, because it is exactly when compliance matters. If a dispute leads to a records request or a due-process hearing, can the district produce a clean, timestamped, exportable record of the behavior data and the parent communication? The reason objective, defensible evidence matters is that it has to hold up precisely when a relationship has broken down. A review that confirms the data can be produced cleanly, scoped correctly, and revoked when needed is a review that protects students, families, and staff alike.
Frequently asked questions
Is this legal advice?
No. This is a planning checklist. District policy and legal counsel should guide final compliance decisions.
Should technology staff join the review?
Yes, especially for SSO, data access, security documentation, and vendor review.
Should teachers be involved?
Yes. Compliance review should understand the actual classroom workflow the tool will support.
What is the minimum a vendor should clear before we consider them?
FERPA alignment, role-based access that keeps teachers within their own caseload, and willingness to sign your district data privacy agreement, such as an NDPA. Treat that as the floor, then evaluate the product on what it does above it.
What if we stop using the product later?
Ask the vendor up front whether you can export all student data and have it deleted on request. Knowing the exit terms before you sign is part of a sound compliance review, not an afterthought.