FERPA, the Family Educational Rights and Privacy Act, has been in place since 1974. Most people in higher education are aware it exists. Far fewer have a precise understanding of where it applies in a modern digital marketing operation, what it restricts, and what the consequences of getting it wrong actually look like.
In 2026, with AI tools being deployed across marketing workflows, personalisation becoming more sophisticated, and third-party data restrictions tightening platform-by-platform, the practical implications of FERPA for higher education marketing have become more significant than at any previous point. This piece covers what you actually need to know.
What FERPA Actually Covers
FERPA protects the education records of students at institutions that receive federal funding, which covers virtually all accredited US colleges and universities. Education records include not just transcripts and grades but any records that are directly related to a student and maintained by the institution.
The key restriction for marketing purposes is that personally identifiable information from education records cannot be disclosed to third parties without written consent from the student. This is broader than many marketing teams realise. It extends to using student data in advertising platforms, in marketing automation systems, and in any third-party tool that processes information that could be connected to individual student records.
The distinction between enrolled students and prospective students matters here. FERPA applies to enrolled students. Prospective student data is not covered by FERPA, but it is still governed by the privacy policies the institution has published, by state privacy laws in many cases, and in some configurations by GDPR if the institution is recruiting internationally from EU or UK markets.
Where Higher Education Marketing Operations Typically Have Gaps
The most common FERPA gaps in higher education marketing are not the obvious ones. Institutions have usually figured out not to share individual student records with outside agencies. The gaps tend to be more subtle.
Using enrolled student data for lookalike targeting. Platforms like Meta allow advertisers to upload customer lists and create lookalike audiences. Using a list of enrolled students as the seed audience for lookalike modelling involves uploading education records to a third party. That is a FERPA disclosure and requires student consent that institutions almost never have in the form required.
Aggregated data that is not sufficiently anonymised. Sharing data about students in aggregate does not automatically make it FERPA-compliant if the aggregation is small enough that individuals could be identified. A campaign that targets “students who enrolled in our finance programme this year” in a cohort of twelve people is identifiable even as aggregate data.
Retargeting enrolled students through marketing pixels. If a marketing pixel is placed on pages of a student portal or any part of the institution’s digital environment accessible only to enrolled students, the data collected through that pixel connects to education records. Whether that constitutes a FERPA-covered disclosure depends on what data is captured and how it is used, but many institutions have not conducted that analysis for their existing tracking infrastructure.
Third-party marketing tools with insufficient data processing agreements. Any system that handles student data needs a data processing agreement that specifically addresses FERPA requirements. Many institutions have standard vendor agreements that do not cover FERPA adequately because the vendor is not higher education-specific.
What GDPR Adds for Institutions Recruiting Internationally
Institutions recruiting students from EU or UK markets are subject to GDPR for the personal data of those prospective students. This creates a parallel compliance requirement alongside FERPA for any international recruitment marketing.
The practical implications for marketing operations include: consent must be specific, informed, and freely given before most marketing communications can be sent to EU and UK prospects; data cannot be retained for longer than the stated purpose requires; and the use of that data in advertising platforms requires a lawful basis that is not always straightforward to establish.
For institutions running global recruitment campaigns, the question of which privacy regime applies to which segment of the prospective student database is one that many marketing teams have not explicitly resolved. The answer determines what communications can be sent, through what channels, and with what consent mechanisms in place.
AI and the New Privacy Considerations
The deployment of AI tools in higher education marketing is creating new privacy considerations that existing FERPA guidance has not fully addressed.
AI-powered personalisation tools that draw on student behaviour data to tailor marketing communications are operating at the intersection of what FERPA was designed to protect. If the behaviour data that powers the personalisation comes from enrolled student interactions with institutional systems, the question of whether that constitutes a disclosure of education records to the AI system and its operators is one that legal counsel needs to answer before the tool is deployed, not after.
The EU AI Act Article 50 obligations that came into force in August 2026 add a further layer for international-facing marketing. AI-generated content must be marked as such in machine-readable form. For institutions using generative AI to produce communications to prospective students, this creates a disclosure requirement that sits alongside the existing consent and data governance framework.
What Good Data Governance Looks Like in Practice
The institutions managing this well have not necessarily done more compliance work than their peers. They have done better-structured compliance work.
They have mapped their marketing data flows specifically: which data comes from which systems, where it goes, what it is used for, and what the lawful basis is for each use. This mapping exists as a document, not just as an assumption.
They have reviewed their vendor agreements for any tool that handles student or prospective student data and confirmed that each agreement covers the relevant privacy requirements. They have not assumed that a standard vendor contract is sufficient.
They have trained the marketing team on FERPA specifically, not just on general data privacy. The marketing team knows which use cases require student consent, which require legal review, and which are clear for use without additional process.
And they have built a review process that catches new tool deployments before they go live rather than reviewing them after the fact. The number of privacy gaps that arise from a marketing team adopting a new tool without going through the data governance review is significant in higher education.
Why This Matters More Than It Did Before
The consequence of FERPA violations is loss of federal funding. For most institutions, that consequence is severe enough that any genuine risk needs to be taken seriously. The risk has increased in 2026 for two reasons.
The sophistication of marketing data tools has increased. The capabilities that are now routine in digital marketing, real-time personalisation, cross-platform retargeting, AI-assisted content, behavioural modelling, all create more opportunities for data to be used in ways that may not have been contemplated when the institution’s FERPA compliance framework was last reviewed.
The scrutiny on data privacy in education has increased. State-level privacy legislation is expanding. Parental rights in education data have received significant political and legislative attention. The regulatory and reputational risk from a visible data misuse incident is higher than it was three years ago.
For agencies working with higher education institutions, understanding FERPA is not optional. It shapes what data can be used in campaigns, what platforms can be used and how, and what reporting and accountability the agency needs to provide to the institution. An agency that does not understand this is carrying risk into its client relationships without realising it.
At LD, data governance is built into how we approach every higher education engagement. If you want to understand where your current marketing operation has data privacy gaps, our AI Marketing Readiness Audit includes an assessment of your marketing data infrastructure and where the real risk sits.