Not legal advice. This post explains how FERPA applies to ClassWatcher in plain language. For district-specific guidance, consult your privacy officer or legal counsel. Canadian teachers should read the PIPEDA guide for Canadian tools instead.
If you're a teacher or administrator at a US school using D2L Brightspace, FERPA compliance is the first question your IT department will ask about any third-party tool. This post answers it directly: what FERPA requires, how it applies to ClassWatcher, and what to share with your district when evaluating it.
What is FERPA?
The Family Educational Rights and Privacy Act (1974) is a federal law that protects the privacy of student education records. It applies to any school that receives federal funding, which includes virtually all public K-12 schools and most colleges and universities in the US.
FERPA gives parents (and students over 18) the right to access their education records and requires schools to obtain consent before disclosing personally identifiable information from those records to third parties.
The key concept for classroom tools is the "school official" exception: FERPA permits disclosure of education records to school officials (including third-party vendors) who have a legitimate educational interest and are performing a service the school would otherwise perform itself. This is the legal basis under which most ed-tech tools operate.
What counts as an "education record" under FERPA?
FERPA defines education records broadly: any record directly related to a student that is maintained by the school or by a third party acting on the school's behalf. This includes grades, transcripts, attendance records, and assignment submission data.
The key phrase is "maintained by." Data that a teacher views on screen but that is never transmitted to or stored by a third party is treated differently from data that a vendor stores on their own servers.
How ClassWatcher handles student data
ClassWatcher is a Chrome extension. When a teacher opens an assignment or quiz page in Brightspace, the extension reads the submission status that Brightspace is already displaying, the same information the teacher can see with their own eyes. Here's exactly what happens with that data:
- Submission status is processed locally. The scan happens in the teacher's browser. Student names and per-student results are not transmitted to ClassWatcher's servers โ only a scan summary (page and missing/total counts, with no student names) is stored to power the scan history feature.
- Grade data stays in the browser. When a teacher opens a marks view or parent report, ClassWatcher reads grades from Brightspace through the teacher's own session and displays them locally. Grades are never stored on ClassWatcher's servers.
- No connection to your SIS. ClassWatcher reads only from Brightspace, using the teacher's own access. It has no connection to your student information system.
- Parent contact data is teacher-entered. Phone numbers and email addresses for parents come from the teacher directly. ClassWatcher does not pull contact data from student records.
- Message logs and contact notes are retained 365 days then deleted. Records of SMS and email messages sent, and any notes the teacher adds, are stored on ClassWatcher's servers for 365 days, then automatically purged.
- No data is sold or shared. Student information is never disclosed to advertisers, data brokers, or other third parties.
The FERPA analysis
| FERPA question | ClassWatcher's position |
|---|---|
| Does ClassWatcher access education records? | It reads submission status โ and grades, when the teacher opens a marks view โ through the teacher's own Brightspace access. Per-student results are processed and displayed locally; only scan summaries without student names are stored on ClassWatcher servers. |
| Does ClassWatcher store education records? | Class lists and watch list data are stored locally in the teacher's browser via Chrome storage. Message logs (who was contacted, when), teacher contact notes, and scan summaries (no student names) are stored on ClassWatcher's servers for up to 365 days. |
| Is there a legitimate educational interest? | โ Tracking missing assignments and contacting parents about missing work is a core teacher function with clear educational purpose. |
| Does ClassWatcher disclose data to third parties? | โ No. Data is never shared with advertisers, data brokers, or other vendors. |
| Does ClassWatcher access grades or transcripts? | Grades only at the teacher's request (marks view, parent report), read through the teacher's own Brightspace access and displayed locally โ never stored on ClassWatcher servers. No transcript or academic-history access. |
| Can the district sign a DPA? | โ Yes. Contact [email protected] to discuss a Data Processing Agreement for your district. |
What about TCPA and parent SMS?
The Telephone Consumer Protection Act (TCPA) governs SMS messaging in the US. (In Canada, the equivalent question is CASL.) It's a separate law from FERPA but relevant if you're using ClassWatcher to text parents.
The TCPA requires prior express consent before sending marketing or promotional texts. Teacher-to-parent communication about a student's missing assignments is generally considered informational/transactional rather than marketing, which puts it in a lower-risk category. However, best practice is to inform parents at the start of the year that you may contact them by text about their child's academic progress, and to honour any request to stop.
ClassWatcher has a built-in opt-out system: if a parent replies STOP, they are added to an opt-out list and will not receive further messages from that teacher.
Recommended practice for US teachers: include a line in your back-to-school communication that you may occasionally send text messages about missing assignments, and that parents can reply STOP at any time to opt out.
What to share with your district IT or privacy officer
- ClassWatcher processes submission status and marks locally in the teacher's browser; student names and per-student results are never transmitted to ClassWatcher's servers during a scan (only summary counts, with no names)
- No connection to your SIS; all reading happens inside Brightspace using the teacher's own access
- Parent contact information is teacher-entered, not pulled from student records
- Message logs retained 365 days then automatically deleted
- No student data sold or shared with third parties
- Data Processing Agreements available on request
- Full technical and security documentation: classwatcher.com/it.html
- Direct contact for security questionnaires: [email protected]