Why Parents Can't Sue EdTech Giants Over Student Data Privacy

A federal court dismissed a student privacy lawsuit against Renaissance Learning, highlighting why parents cannot directly sue EdTech companies under FERPA.

Monday, September 14, 2026

Key Takeaways

  • A federal court dismissed a class-action lawsuit against Renaissance Learning. The ruling confirms that families cannot sue educational technology vendors directly for collecting K-12 student data without parental consent.
  • Under the Family Educational Rights and Privacy Act (FERPA), school districts can share student data with third-party software vendors without parental consent. They do this under the "school official" exception.
  • Neither FERPA nor the Children's Online Privacy Protection Act (COPPA) gives parents a private right of action. Enforcement falls entirely to federal regulatory agencies.
  • When educational technology vendors suffer data breaches, such as the 10-million student breach at Illuminate Education, only federal agencies like the FTC have the authority to mandate security corrections and data minimization schedules.

A federal judge has dismissed a proposed class-action lawsuit against classroom software giant Renaissance Learning. The ruling throws out claims that the company collected and shared K-12 student data without consent. This decision shows a stark reality: federal student privacy laws do not give families the right to sue EdTech companies directly.

What Happened

On September 11, Judge Fred W. Slaughter of the U.S. District Court for the Central District of California granted Renaissance Learning's motion to dismiss the lawsuit without allowing the plaintiffs to amend their complaint. The lawsuit, led by plaintiffs Nicole Reisberg and Amy Warren, argued that the software company wrongfully gathered and shared students' personal information. Judge Slaughter ruled that the families' allegations did not meet the legal requirements for any of the state or federal claims.

The Bigger Picture

To understand why the court dismissed this case, parents must understand how school data sharing works. Under the Family Educational Rights and Privacy Act (FERPA), schools must generally get written parental consent before sharing student records. However, a major legal loophole called the "school official" exception allows districts to bypass parents.

Under this exception, school districts can legally share personally identifiable student information with third-party vendors without parental consent. To do this, the vendor must perform a service the school would otherwise handle itself, and the vendor must remain under the "direct control" of the school.

FERPA does not contain a "private right of action", which means parents cannot sue companies or schools directly for violating the law. Instead, only the U.S. Department of Education's Student Privacy Policy Office can enforce FERPA, primarily by threatening to pull federal funding from schools. Similarly, the Children's Online Privacy Protection Act (COPPA), which regulates online data collection for kids under 13, does not allow private parental lawsuits against vendors. As we previously reported, these regulatory gaps leave districts to police their own technology agreements.

What This Means for Families

Because parents cannot sue, the burden of protecting student data falls almost entirely on school district administrators. Districts attempt to protect families by signing Data Protection Addenda (DPAs) with technology providers. However, experts warn that these contracts do not automatically guarantee that a vendor has a legitimate educational purpose or prevent schools from oversharing student data.

This lack of direct parental control comes during a rise in school data breaches. For instance, a cyberattack on K-12 vendor Illuminate Education compromised the highly sensitive personal records of more than 10 million students. The stolen data included student grades, health histories, and dates of birth. The Federal Trade Commission (FTC) later stepped in, ordering the company to implement strict data minimization standards and delete unnecessary student data. While federal agencies can penalize companies after a breach, parents cannot stop their child's data from being shared in the first place.

What You Can Do

Parents can take several steps to protect their children's information. First, ask your school board or principal for a list of approved EdTech vendors and demand to see the active Data Protection Addenda signed by the district.

You should also monitor subpoena notices. While schools can release student records under a legal subpoena, FERPA requires them to make a reasonable effort to notify parents in advance, which gives you a chance to challenge the disclosure in court.

Finally, encourage your school district to adopt strict procurement policies. Districts should make FERPA and COPPA compliance a mandatory requirement for every app used in classrooms.

Share: