ComplianceFERPACOPPA

The FERPA & COPPA Checklist Every District Should Run Before Signing an EdTech Contract

The DueDilly Team · July 22, 2026

The FERPA & COPPA Checklist Every District Should Run Before Signing an EdTech Contract

Four practical steps to vet an EdTech vendor for student-data compliance — from data inventory to automated ongoing monitoring.

Every EdTech tool your district adopts touches student data — and that means FERPA and COPPA are on the line with every contract you sign. Here is the checklist our team uses to evaluate a vendor before it ever reaches a classroom.

Start with the data inventory

Before you can judge a vendor, you need to know exactly what student data the product collects. Ask for a written data inventory covering:

  • Directory information such as names, grade levels, and school assignments
  • Behavioral and usage data the platform records during instruction
  • Third-party sharing — who else touches the data downstream

If a vendor cannot produce this quickly, treat it as a red flag.

Map each data flow to a legal basis

FERPA governs education records, while COPPA governs data collected from children under 13. For each data element, confirm which framework applies and how the vendor complies. Watch for the school official exception under FERPA — it only holds if the vendor is under your direct control and uses the data solely for the contracted purpose.

Pin down retention and deletion

A contract that never ends is a liability that never ends.

Require a clear retention window and a guaranteed deletion process when the agreement terminates. Get it in writing, with a timeline.

Automate the ongoing monitoring

Compliance is not a one-time gate at signing — vendor practices drift over time. DueDilly continuously scans your active vendors against FERPA and COPPA requirements so you catch a problem when it appears, not at your next audit.

Run every prospective tool through these four steps and you will spend far less time firefighting later.