A federal judge has dismissed a proposed class-action lawsuit against classroom software giant Renaissance Learning. The ruling throws out claims that the company collected and shared K-12 student data without consent. This decision shows a stark reality: federal student privacy laws do not give families the right to sue EdTech companies directly.
What Happened
On September 11, Judge Fred W. Slaughter of the U.S. District Court for the Central District of California granted Renaissance Learning's motion to dismiss the lawsuit without allowing the plaintiffs to amend their complaint. The lawsuit, led by plaintiffs Nicole Reisberg and Amy Warren, argued that the software company wrongfully gathered and shared students' personal information. Judge Slaughter ruled that the families' allegations did not meet the legal requirements for any of the state or federal claims.
The Bigger Picture
To understand why the court dismissed this case, parents must understand how school data sharing works. Under the Family Educational Rights and Privacy Act (FERPA), schools must generally get written parental consent before sharing student records. However, a major legal loophole called the "school official" exception allows districts to bypass parents.
Under this exception, school districts can legally share personally identifiable student information with third-party vendors without parental consent. To do this, the vendor must perform a service the school would otherwise handle itself, and the vendor must remain under the "direct control" of the school.
FERPA does not contain a "private right of action", which means parents cannot sue companies or schools directly for violating the law. Instead, only the U.S. Department of Education's Student Privacy Policy Office can enforce FERPA, primarily by threatening to pull federal funding from schools. Similarly, the Children's Online Privacy Protection Act (COPPA), which regulates online data collection for kids under 13, does not allow private parental lawsuits against vendors. As we previously reported, these regulatory gaps leave districts to police their own technology agreements.
What This Means for Families
Because parents cannot sue, the burden of protecting student data falls almost entirely on school district administrators. Districts attempt to protect families by signing Data Protection Addenda (DPAs) with technology providers. However, experts warn that these contracts do not automatically guarantee that a vendor has a legitimate educational purpose or prevent schools from oversharing student data.
This lack of direct parental control comes during a rise in school data breaches. For instance, a cyberattack on K-12 vendor Illuminate Education compromised the highly sensitive personal records of more than 10 million students. The stolen data included student grades, health histories, and dates of birth. The Federal Trade Commission (FTC) later stepped in, ordering the company to implement strict data minimization standards and delete unnecessary student data. While federal agencies can penalize companies after a breach, parents cannot stop their child's data from being shared in the first place.
What You Can Do
Parents can take several steps to protect their children's information. First, ask your school board or principal for a list of approved EdTech vendors and demand to see the active Data Protection Addenda signed by the district.
You should also monitor subpoena notices. While schools can release student records under a legal subpoena, FERPA requires them to make a reasonable effort to notify parents in advance, which gives you a chance to challenge the disclosure in court.
Finally, encourage your school district to adopt strict procurement policies. Districts should make FERPA and COPPA compliance a mandatory requirement for every app used in classrooms.