How exposed is
your institution?
Select your institution type and check every data category you collect. Your compliance gap appears instantly — no sign-up required.
01 · Institution Type
02 · Data You Collect
Compliance Risk Score
No account required · Results in 48 hours
The violations
already happening
at your institution.
Each card shows a real violation scenario on the front. Hover or tap to see the compliant alternative. Cards escalate from common oversights to catastrophic breaches.
You email grade reports as unencrypted PDFs
Plain-text email attachments containing student academic records violate FERPA §99.30. Any interception exposes protected education records.
Potential Penalty
$0–$50K + loss of federal funding
AES-256 parent portal with role-based access
Encrypted parent portal with individual login credentials, audit log of every access event, and automatic session expiration after 15 minutes.
✓ Audit-ready documentation included
Your enrollment form collects photos without COPPA disclosure
Collecting images of students under 13 without verifiable parental consent and a clear privacy notice violates COPPA §312.4. No checkbox counts as consent.
Potential Penalty
$51,744 per violation per day
Tiered consent form with age-gate and FTC-approved notice
Age-gated enrollment with separate consent for each data category, written in plain language, with a direct link to your full privacy policy.
✓ Audit-ready documentation included
Cafeteria uses fingerprint scanners without written consent
Biometric identifiers collected from minors require explicit written consent under BIPA (Illinois), CUBI (Texas), and equivalent state laws — plus FERPA notification.
Potential Penalty
$1,000–$5,000 per student per violation
Written biometric consent with opt-out alternative
Separate biometric consent form, PIN-code alternative for non-consenting students, annual re-consent requirement, and documented destruction schedule.
✓ Audit-ready documentation included
Your SIS vendor accesses student data without a signed FERPA agreement
Third-party vendors with access to education records must have a current Data Processing Agreement designating them as a "school official" under FERPA §99.31(a)(1). No agreement = direct liability.
Potential Penalty
Loss of ALL federal funding + civil litigation
Vendor DPA with FERPA school-official designation
Executed Data Processing Agreement naming the vendor as a school official, limiting data use to educational purpose, with annual review and right-to-audit clause.
✓ Audit-ready documentation included
Health records stored in the same system as academic records
Medical and health records maintained by a school are subject to FERPA, not HIPAA — but commingling them with academic records creates dual-liability exposure and breaks access-control requirements.
Potential Penalty
HIPAA: $100–$50K per violation
Segregated health record system with separate access tiers
Health records in a HIPAA-compliant system accessible only to nurse and designated staff, with a separate FERPA-compliant SIS for academic records and no cross-system data sync.
✓ Audit-ready documentation included
Directory information published without annual opt-out notice
FERPA requires schools to notify parents annually of directory information categories and provide a reasonable opt-out window before any publication — including yearbooks and sports programs.
Potential Penalty
Complaint triggers ED investigation
Annual directory notice with documented opt-out tracking
Annual notice sent to all families at enrollment, 30-day opt-out window, opt-out tracking in SIS, and suppression of opted-out students from all public-facing lists.
✓ Audit-ready documentation included
DIY template
vs. professionally
audited policy.
The difference between a downloaded template and a PolicyGuard-audited policy isn't formatting — it's the 35 clauses your board doesn't know are missing.
DIY Template
Downloaded free
PolicyGuard
Professionally audited
Policy Completeness
Audit Readiness
Legal Protection
Overall Verdict
34/100
FERPA Score
97/100
FERPA Score
Or download the free FERPA checklist → No account needed
From compliance gap
to audit-ready.
Schools Audited
Policy Clauses Reviewed
Avg. Post-Audit FERPA Score
Hour Turnaround
“Our enrollment form had 11 COPPA violations we didn't know existed. PolicyGuard found them in 48 hours. We updated before our state audit.”
Margaret Chen
Head of School
Westlake Academy, Austin TX
94
Post-audit score
“I brought the audit report to our board meeting. The gap analysis alone justified the cost — we had zero FERPA-compliant vendor agreements.”
David Okafor
IT Director
Horizon Charter Network, Chicago IL
98
Post-audit score
“As a new private academy founder, I had no idea our online enrollment collected biometric data. The compliance checklist was our first real policy document.”
Priya Nair
Founder & Director
Meridian Learning Center, Atlanta GA
91
Post-audit score
Trusted by institutions across every education category
Close the gap.
Today.
Submit your current policy for a full FERPA/COPPA audit, or grab the free checklist to show your board you're taking action right now.