Frequently Asked Questions

Who Does FERPA Affect?

Back To All FAQs

FERPA applies to any educational institution that receives funding from the U.S. Department of Education. If an institution does not comply with FERPA, the government may take action under 34 CFR §99.67(a), including:

  • Withholding further funding for applicable programs
  • Issuing a complaint to enforce compliance via a cease-and-desist order
  • Terminating the institution’s eligibility to receive funding

Read More

While Massachusetts businesses have operated under strict data security regulations (like 201 CMR 17.00) for more than a decade, the legislative landscape is about to become more complex. Lawmakers are currently advancing the Massachusetts Data Privacy Act (MDPA), a comprehensive privacy law designed to give residents more control over their personal information. With an anticipated

Read Article

While businesses have long navigated federal privacy regulations like HIPAA or the GLBA, a new era of state-level enforcement has arrived in the Ocean State. The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) officially took effect on January 1, 2026. The requirements for how you handle, share, and disclose customer data have fundamentally

Read Article

For most auto dealerships, meeting the FTC Safeguards Rule requirements is a settled matter. You’ve hired a Qualified Individual, updated your software, and implemented multi-factor authentication. However, there is often one vulnerability that still remains: paper records. While Dealer Management Systems (DMS) and finance platforms have been secured, legacy deal jackets and physical service records

Read Article