Skip to content

Admissions glossary

What is FERPA in college admissions?

FERPA is the US federal privacy law for student education records; for college admissions offices, the key question is when an applicant's file falls under it.

By the higheredcrm.ai product teamReviewed

Every statement about higheredcrm.ai here is checked against the current product before we publish, and the page is reviewed again when the product changes.

FERPA: definition and example

The Family Educational Rights and Privacy Act (FERPA) is a United States federal law covering education records at institutions that receive funds under programs administered by the US Department of Education, including federal student aid. At a college or university the rights belong to the student: to inspect and review their records, to ask for corrections and to control many disclosures to others.

For admissions offices, timing is the central question. FERPA generally does not cover the records of applicants who never attend the institution, while an admitted student's application file usually becomes part of their education record once they enroll. From then on the student can ask to see it, with an exception for recommendation letters where they waived access. The registrar, general counsel and admissions should agree where that line sits for your institution.

Once a student attends college, FERPA rights belong to the student at any age. What staff can share with a parent who calls about an enrolled student therefore depends on the student's consent or on one of the law's exceptions. Vendors that handle records for the institution, including a CRM provider, typically work under the school official exception, which requires the institution to control how the data is used.

A hypothetical call shows why the line needs to be written down. In August, a parent phones the admissions office to ask whether their son, who has deposited and registered for fall classes, sent his final transcript. Whether a counselor may answer depends on the institution's policy on when attendance begins and on any consent the student has given. A short, shared guide for counselors avoids a different answer from each person who picks up the phone.

Which safeguards matter in a CRM? Limit access by role, keep a trail of who changed or exported data, protect sensitive fields, and decide at which stage a record leaves the recruiting system for the student information system. Treat this entry as general information; your general counsel decides how FERPA applies to your institution.

This entry is general information, not legal advice. Talk to your legal counsel or data protection officer about how the law applies to your institution.

How higheredcrm.ai helps

higheredcrm.ai gives your privacy review specific controls: custom roles with per-page permissions, contact masking for the roles you choose, a staff activity trail that includes exports, per-lead audit history, MFA, single sign-on through OpenID Connect, and AES-256 encryption for custom fields you mark as sensitive.

See roles, security and audit logs

See the idea working in an admissions office.

Bring your own FERPA questions to a demo. We'll show how higheredcrm.ai handles them, with sample records shaped like your programs and admissions cycle.