FERPA and school testing: a practical guide for Australian parents
When American parents talk about the Family Educational Rights and Privacy Act, conversations in school pick-up queues from Carlton to Cottesloe can feel a long way from home. The law is American, but the questions it raises travel well: who owns your child's school records, how is test data stored, and at what point does outside access cross the line?
FERPA, passed in 1974, sets federal rules for how US schools handle student information. It grants parents the right to inspect and review education records, request corrections, and control the disclosure of identifiable information to third parties. Many Australian families would be surprised to learn how closely these ideas mirror protections already sitting inside the Privacy Act 1988.
Standardised testing has pushed these questions into the foreground. With NAPLAN results feeding the My School website and a national data collection that widens each year, parents in Brisbane, Adelaide, and Perth now navigate comparable territory to their counterparts in New York State.
This guide walks through what FERPA actually covers, where Australian law lines up, and what families can do when a school's data practices feel short of the mark.
Understanding FERPA's scope and limits
FERPA applies to any education agency that receives US Department of Education funding. It covers a wide range of records: grades, disciplinary files, school-held health information, and the personally identifiable detail that turns up in test booklets, answer sheets, and online learning platforms.
The law grants parents the right to view their child's records within 45 days of a written request. Schools must allow corrections if information is inaccurate or misleading and must obtain written consent before releasing identifiable information, with narrow exceptions for school transfers, financial aid applications, or court orders. Directory information such as names, addresses, honours, and awards can be released without consent unless parents opt out, while aggregate de-identified data typically falls outside the law entirely.
How US privacy rules compare to Australian protections
Australia's framework rests on the Privacy Act 1988 and the 13 Australian Privacy Principles underneath it. Public schools in each state and territory are also covered by local regulations, and Catholic and independent schools operate within the federal Notifiable Data Breaches scheme.
Under these principles, parents can usually request access to personal information held about their child by writing to the school or the relevant department. Schools generally have 30 days to respond, and the Office of the Australian Information Commissioner can investigate complaints. The differences lie in the fine grain: American parents have federally guaranteed rights that travel with their child across districts, while Australian families lean on a patchwork of state-level and school-level policies and federal complaint mechanisms.
What NAPLAN data collection means for your family
Every May, students in Years 3, 5, 7, and 9 sit the National Assessment Program – Literacy and Numeracy. The Australian Curriculum, Assessment and Reporting Authority collects individual student responses, links them to enrolment records, and feeds summary information into My School.
ACARA's published policy states that data is de-identified when released at school level, yet individual responses travel to ACARA alongside names, dates of birth, and language background. Parents who skip the consent portion of the form may have agreed to participation by default unless the school runs an opt-out process.
Families who feel the testing regime is disproportionate can adapt the how to write a letter to your state assembly member about high-stakes testing template, which works equally well for federal senators and state members. Similar worries surface in Australia around the Student Background Data Collection, which captures parental schooling, family occupation, and other sensitive items.
Reading school privacy policies with a sharp eye
Most state education departments publish privacy policies online. They read as dry, but a careful pass reveals what happens to NAPLAN responses, how long records are kept, and which third-party vendors might receive information for marking or analysis.
Worth looking for in any policy:
- The retention period for test booklets and digital records.
- Whether the school relies on third-party platforms that store data offshore.
- The procedure for withdrawing a child from research projects.
- Contact details for the school's privacy officer or designated person.
When anything is unclear, write to the principal or the relevant department and ask for clarification in writing. Keep a copy of the reply, as it becomes important if a complaint is later needed. Parents who want to see exactly what is on file can follow guidance on how to request your child's complete student data file from the district, adapted to a local school letterhead.
Steps parents can take locally and politically
Across suburban Melbourne and outer Sydney, parents have pushed councils to pass resolutions on student privacy, and community frameworks such as the vocational training initiative in Pitas show how youth-focused advocacy can shape local priorities even in distant settings.
Speaking up at parent committee meetings, asking principals hard questions before signing consent forms, and joining opt-out movements are reasonable starting points. Practical habits worth keeping in mind:
- Save copies of every consent form you sign or decline.
- Note dates of tests and any unusual requests for family background data.
- Keep your child's student ID handy when writing to schools.
- Subscribe to newsletters from your education union or parent body for early warnings.
This week, ring the school office and ask for a copy of your child's current records. The reply will tell you more than any policy document about how seriously the institution treats the data already in its hands.