Quick answer: FERPA-compliant SMS means texting students without disclosing protected education records to unauthorized parties, obtaining documented consent before any message references non-directory information, and using a vendor bound by a written data use agreement with encryption in transit (TLS 1.3) and at rest (256-bit AES). Schools can text students under FERPA; the law restricts what the message contains and how the platform handles student data, not the act of texting itself.
What FERPA actually covers, and why SMS fits into it
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records at institutions that receive federal funding. An education record is broadly defined: any record, file, document, or other material that contains information directly related to a student and is maintained by an educational institution or a party acting for the institution.
Most compliance teams immediately think of transcripts, grades, and financial aid files. But FERPA's scope extends further. A text message that references a student's enrollment status, academic standing, financial aid disbursement, disciplinary matter, or health record held by the institution can contain education record information, and it must be handled accordingly.
This does not mean institutions cannot text students. It means the content of those messages, and the platform carrying them, must meet FERPA's handling standards. General outreach such as event reminders, campus alerts, and enrollment deadline notices typically does not disclose protected records. Messages that reference individual student data require closer scrutiny.
Directory information, consent, and the opt-in question
FERPA distinguishes between two categories of student information. Directory information (typically name, enrollment status, and institution-designated public fields) can be disclosed without consent unless the student has filed a FERPA hold. Non-directory information requires written consent before disclosure to any outside party.
For SMS programs, this distinction matters in two ways. First, the content of any message referencing non-directory data requires that a proper consent process be in place. Second, the phone number itself may be considered education record information depending on how it was collected and what your institution's FERPA policy designates as directory information.
Separate from FERPA, the Telephone Consumer Protection Act (TCPA) requires affirmative opt-in consent before sending marketing or promotional text messages to any individual. Institutions running SMS programs for financial aid, enrollment, or student services should capture and document opt-in at the point of collection: for example, during application, enrollment, or account creation. This note is general guidance, not legal advice; consult your institution's counsel for compliance determinations specific to your programs.
Can schools text students under FERPA?
Yes. FERPA does not prohibit schools from texting students. It regulates the disclosure of education record information, so the question is what the text contains, who receives it, and whether the platform protects student data. Get the content, the consent, and the vendor contract right and a school can text with confidence.
Texting college and university students
In higher education, FERPA rights belong to the student regardless of age. Institutions communicate directly with students about deadlines, advising, and financial aid steps, and disclosing record details to parents generally requires the student's written consent. Two-way texting works well here because students initiate many conversations themselves. See how campuses put this into practice on our higher education solutions page.
Texting K-12 students and parents
In K-12, FERPA rights belong to the parent or guardian until the student turns 18 or enrolls in a postsecondary institution. Districts should direct record-specific conversations to the parent of record and keep broadcast texts free of individual student details. Our K-12 education solutions page covers district texting in more depth.
Texting applicants and prospective students
FERPA protections attach to the records of students in attendance, so applicant outreach is usually governed by your institution's own privacy policies plus TCPA consent rules. Capture opt-in on the inquiry or application form and honor opt-outs from the first message.
What to require from an SMS vendor
Choosing the right platform is as important as crafting the right policies. When evaluating vendors, your compliance and IT teams should look for the following:
- Written data use agreement. FERPA requires that third-party vendors who access student education records operate under a formal agreement limiting their use of that data to the contracted purpose. Ask every vendor for their standard data use agreement before procurement.
- Encryption in transit and at rest. Student data transmitted through the platform should be protected by encryption in transit (TLS 1.3) and at rest (256-bit AES). Ask vendors to confirm these specifications in writing.
- No data sale or secondary use. Vendors must not sell, share, or use student data for their own commercial purposes. This should be explicit in the contract, not implied.
- Access controls and audit logs. Staff access to student contact information within the platform should be role-based. Audit logs should record who sent what, and when, for compliance review purposes.
- 10DLC registration support. Since 2023, commercial SMS in the United States routes through registered 10-digit long code (10DLC) numbers. A compliant vendor should handle 10DLC registration on your institution's behalf and maintain current carrier compliance.
- Opt-out management. The platform must honor STOP requests instantly and maintain suppression lists so opted-out students are never re-messaged without fresh consent.
FERPA student texting checklist
Before the first campaign goes out, walk through this list with your registrar, IT, and counsel.
- Confirm your directory information designation and whether phone numbers are included in it.
- Document how each phone number was collected and where the consent record lives.
- Capture TCPA opt-in at application, enrollment, or account creation, and store proof.
- Write a content standard: no grades, award amounts, disciplinary details, or health information in message bodies.
- Sign a written data use agreement with your SMS vendor before any student data moves.
- Confirm encryption in transit (TLS 1.3) and at rest (256-bit AES) in writing.
- Restrict platform access by role and turn on audit logging from day one.
- Test STOP handling and suppression lists before launch, not after.
- Schedule an annual program review with your registrar and legal counsel.
Where higher ed institutions use compliant SMS effectively
Institutions that operate with clear FERPA policies and a properly contracted vendor can use SMS across a wide range of student-facing programs without disclosing protected records:
- Enrollment and registration reminders: deadline alerts that do not reference individual academic standing
- Financial aid action reminders: prompting students to complete steps, without disclosing award amounts in the message body
- Campus safety and emergency notifications: mass alerts and closures where no individual student data is included
- Advising appointment reminders: confirming times without disclosing the reason for the appointment
- Orientation and onboarding sequences: step-by-step guidance for new students through welcome, housing, and ID processes
- Two-way advising conversations: when students initiate contact, staff can respond within the platform maintaining an auditable record
The common thread: compliant use keeps message content general and action-oriented, rather than surfacing specific protected data points in the message body. Where a student needs personalized information, the best practice is to direct them to a secure portal rather than transmitting sensitive details over SMS.
For a detailed breakdown of platform capabilities designed for higher education contexts, see our guide to the best texting platform for higher education.
How to keep FERPA-protected student information out of message bodies
The cleanest compliance strategy is content discipline: if protected record details never appear in a message, most FERPA disclosure questions never arise.
Patterns that generally work:
- "Your financial aid file has an item that needs attention. Log in to the portal to review it."
- "Reminder: registration for fall term closes Friday."
- "Your advisor has an opening tomorrow at 2 pm. Reply YES to confirm."
Details that belong behind a secure login instead:
- Award amounts, account balances, GPA, grades, or academic standing
- Disciplinary actions or conduct proceedings
- Health, counseling, or disability services information
- Immigration or citizenship status
A simple staff test: if the message would be a problem on a lock screen in a crowded lecture hall, it belongs behind a login.
How FRANSiS™ supports FERPA-aware SMS programs
FRANSiS™ is an AI-powered two-way SMS platform built for mission-driven organizations including higher education institutions. The platform is designed with data governance as a foundation, not an afterthought.
Data in transit is protected with TLS 1.3 encryption; data at rest uses 256-bit AES encryption. FRANSiS supports formal data use agreements for institutional clients. The platform's AI Powered Helper automates outreach sequences such as enrollment reminders, financial aid nudges, and orientation messages, while maintaining opt-out compliance automatically: a student who texts STOP is immediately removed from all automated sends.
Pricing is flat, predictable, unlimited messaging, so institutions can run high-volume outreach campaigns without per-message cost surprises that create pressure to skip compliance steps. 10DLC registration is handled as part of onboarding, and FRANSiS supports TCPA-aligned opt-in capture within the platform.
FRANSiS supports FERPA-aware operations rather than certifying them; the compliance determination depends on how your institution configures its programs and what your legal counsel advises. What FRANSiS does provide is a platform architected to support compliant operations, with the data agreements, encryption, access controls, and audit trails that compliance teams expect from a higher education vendor. Institutions operating in healthcare contexts may also find our overview of HIPAA-compliant text messaging relevant for crossover use cases such as campus health and counseling services.
Frequently asked questions
Is SMS covered by FERPA?
It depends on what the message contains. A text message that includes or references a student's protected education record information is subject to FERPA's handling requirements. General outreach messages, such as deadline reminders, event notices, and campus alerts, that do not disclose individual student record data typically fall outside FERPA's direct restrictions, though your institution's legal counsel should make that determination for your specific programs.
Is it a FERPA violation to text a student?
No, texting a student is not by itself a FERPA violation. A violation occurs when protected education record information is disclosed to someone not authorized to receive it, which can happen over any channel. Keep record details out of message bodies, confirm the recipient, and use a platform with proper access controls.
Do we need a data use agreement with our SMS vendor?
Yes, if the vendor will have access to student education record information. FERPA requires that school officials, including contracted third-party service providers, operate under a formal agreement that limits data use to the contracted educational purpose, prohibits secondary use or sale of the data, and holds the vendor to the same standards as institution employees. Request the vendor's standard data use agreement before signing any contract.
Does a student's phone number count as a FERPA-protected education record?
Possibly. Whether a phone number is treated as an education record depends on how it was collected. If it was provided during enrollment or stored in a student information system, it is likely an education record. Some institutions designate phone numbers as directory information, which changes the consent requirement. Review your institution's FERPA policy and directory information designation with your registrar and legal counsel.
What makes an SMS platform FERPA compliant?
Strictly speaking, no platform is FERPA compliant on its own, because compliance depends on how the institution uses it. What a platform can do is support compliance: a written data use agreement, encryption in transit (TLS 1.3) and at rest (256-bit AES), role-based access controls, audit logs, and automatic opt-out handling. Ask vendors to commit to those items in writing.
Can colleges text students about financial aid under FERPA?
Yes, when the message is framed as an action prompt rather than a disclosure. A text saying a financial aid item needs attention, with a link to the secure portal, does not reveal award amounts or eligibility details. Keep figures and decisions in the portal and let SMS do the nudging.
Can teachers or staff text students from personal phones?
It is risky. Personal-device texting leaves student communications outside institutional records and makes consent and opt-out tracking nearly impossible to prove. Most institutions route student texting through an official platform where messages are logged and access is role-based.
What is the difference between FERPA consent and TCPA opt-in for SMS?
These are separate legal requirements. FERPA governs disclosure of education record information and applies to how institutions handle student data. TCPA governs consent to receive text messages and applies to how institutions contact individuals by phone or SMS. An institution may satisfy FERPA requirements for a given message while still needing to demonstrate TCPA opt-in consent before sending it. Both frameworks apply independently and your institution should have processes to document compliance with each.
Related guides: 7 Best ParentSquare Alternatives for School Communication. · What Is SHAFT Compliance in SMS? Content Rules, FERPA Directory Information: What Schools May Release
Sign up for our mailing list for insights, perks, and more!


