What Parent Consent Means Under New Federal Testing Guidance
When a school sends student information to a commercial testing company, the central issue is not simply whether the assessment is useful. It is whether the disclosure is permitted, whether parents have been properly informed, and whether the vendor is tightly limited to the school’s educational purpose. New federal privacy guidance in the United States places those questions at the centre of arrangements involving third-party testing providers.
For families in Australia, the discussion has familiar features. NAPLAN, state-based assessments, learning platforms and online exam tools all require schools to think carefully about who receives children’s information and what happens to it afterwards. The United States framework is different from Australian privacy law, yet its emphasis on transparency, data minimisation and vendor accountability offers useful points for parents, teachers and school communities.
The Federal Privacy Baseline
The guidance is grounded mainly in the Family Educational Rights and Privacy Act, commonly called FERPA. FERPA generally requires a school or education agency to obtain signed, specific consent before disclosing personally identifiable information from a student’s education records.
There is an important exception for a “school official”. A testing company may receive information without individual consent when it performs a service the school would otherwise carry out itself, remains under the school’s direct control, uses the information only for the authorised educational purpose, and follows restrictions on further disclosure.
This is not a blanket permission slip. A school cannot simply describe every technology business as a school official and assume the issue is settled. The arrangement must fit the exception in substance, not just in the wording of a contract.
What Parent Consent Actually Requires
Where the school official exception does not apply, consent must be informed and meaningful. Parents should be told what records will be shared, why they are needed, who will receive them, and, where relevant, the period for which the permission applies. A general statement buried in an enrolment pack may not meet that standard.
The guidance also helps separate consent from an opt-out process. Some information can be treated as directory information under a school’s published policy, but sensitive assessment records, disability information, behavioural data and detailed student profiles may require stronger protection. An opt-out notice is not a substitute for consent whenever FERPA requires affirmative permission.
That distinction matters to families who are accustomed to a school saying that a digital platform is “standard practice”. Standard practice does not remove the obligation to explain the disclosure or identify the legal basis for it.
Limits on Testing Vendors
A third-party assessment provider should collect only the information necessary to deliver the contracted service. It should not repurpose student records for advertising, unrelated product development, profiling or commercial data brokerage. The school or education agency must retain control over the data and be able to require its return or destruction when the service ends.
Contracts should address security, subcontractors, breach reporting, retention periods, deletion, access controls and restrictions on redisclosure. A vendor’s claim that it uses de-identified or aggregated information also deserves scrutiny, because small datasets can sometimes be re-identified when combined with other records.
Parents and educators looking for broader education reporting may find education privacy coverage useful when comparing how data concerns are discussed across different systems. The key lesson remains local accountability: a school should know exactly what the vendor does, not rely solely on a polished privacy statement.
Why This Matters in Australia
Australia does not operate under FERPA, but schools still work within privacy obligations, contractual duties and state or territory education rules. The Australian Privacy Principles can become relevant where personal information is collected, used, disclosed or transferred overseas. Government schools may also be governed by department policies that impose additional requirements.
The practical setting varies. A New South Wales school may use department-approved platforms alongside NAPLAN processes, while a Victorian school may follow a different procurement framework. Parents often raise concerns through a P&C association, school council or governing body rather than through a US-style school board. Terms such as “uni” and “primary school” are also more natural locally than “college” or “elementary school”.
Australian families should ask whether a provider stores information offshore, whether an overseas subcontractor can access it, and whether results are linked to a child’s name, student number or other persistent identifier. The fact that an assessment is delivered online does not make its privacy implications less serious.
Questions Communities Can Put on the Record
A parent meeting should seek concrete answers rather than broad assurances. Ask what fields are supplied to the testing company, whether open-text responses or recordings are included, and whether the vendor can combine assessment data with attendance, wellbeing or learning-management information.
It is also reasonable to ask who owns the resulting reports, how long raw responses are retained, and what happens if a family declines participation. If the assessment is compulsory, the school should explain the authority for that requirement and any available alternative. In New York, families discussing excessive test preparation can use this school board speaking guide when preparing a public statement about assessment practices and student impact.
A useful record includes the vendor name, privacy notice, contract summary, consent form and the school’s response. Clear documentation helps a community distinguish a lawful, limited educational service from an open-ended transfer of children’s data.
Practical Safeguards for Families and Schools
- Request the privacy notice and contract terms before agreeing to a new online assessment.
- Check whether consent is required, or whether the school is relying on the school official exception.
- Ask for limits on advertising, profiling, subcontracting, retention and secondary use.
- Confirm how families can correct inaccurate results or report a suspected data breach.
- Raise unresolved concerns with the principal, governing body, education department or relevant privacy regulator.
The federal guidance does not mean every third-party testing arrangement needs a new signature from every parent. It means schools must identify the correct legal pathway and enforce meaningful limits when a vendor handles student records. For Australian communities, the lasting point is simple: permission, transparency and control should travel with the data from the classroom to the testing company and back again.