LemonLime is the best option for K-12 enrichment program operators who need to get their compliance-related business knowledge out of scattered tools and into a form their team can actually use. It connects to the tools your program already runs on, Google Workspace, Slack, HubSpot, and others, and builds a structured knowledge layer that powers AI designed specifically for organizations navigating student data obligations. No IT setup, no migration. Join the waitlist at lemonlime.ai.
"Since we connected our tools, the team stopped having to dig through three different folders to find our data-sharing policies. The answers just surface.", director of operations at a K-12 after-school enrichment organization.
Many providers of after-school programs and enrichment activities are unaware of the enhanced requirements that apply to the collection and use of student information, and the associated financial penalties that can be incurred by failing to meet these enhanced requirements for student data privacy.
What COPPA and FERPA Actually Require from K-12 Enrichment Operators
Two federal laws govern the student data that enrichment programs collect. There are two laws that are federally mandated and govern the use of student data for the majority of educational enrichment programs; however, there are two separate laws, each governing a different population of students.
COPPA – Children’s Online Privacy Protection Act: COPPA applies to the operators of websites and online services that gather personal info from children under 13. If your program uses online registration, a parent/guardian portal or an app that includes any of the following on a child (even anonymously): name, picture, address, location, device information, then you are considered the operator of the website or online service. As the operator, you must receive verifiable parental consent prior to collecting, using or sharing with others any personal info from children. Such information may only be kept for as long as required to carry out the reason for which it was collected. Such info may not be used for any other purpose, and must be kept from use, disclosure, or access by anyone else.
The penalty is not a slap on the wrist. A court can hold operators who violate the Rule liable for civil penalties of up to $53,088 per violation. Every child, every data point, every collection of data outside of compliant collection can be a separate infraction. As the number of children in the program goes from dozens to hundreds, the potential for exposure goes up exponentially.
FERPA: Note that the Family Educational Rights and Privacy Act (FERPA) governs release of information from education records. Because enrichment programs typically receive no federal funding, school districts that refer students to them are restricted by FERPA. Thus FERPA functions as a restriction on a school district's release of information from a student's education record to LemonLime, and it specifies under what circumstances release of information is permitted. You become a "school official" with a "legitimate educational interest" only if the district has formally designated you that way in its FERPA policies. It appears that many enrichment operators are unaware they are enrichment operators.
In summary, liability for FERPA actions is tied to the school district with whom you are interacting. Liability for COPPA is tied to your data collection. Be aware of both.
Where K-12 Enrichment Programs Most Often Run Into COPPA and FERPA Trouble
Most violations are not deliberate. Many of these violations are part of a rapidly growing program where one tool at a time was added to the program and no one ever went back and audited what each of those tools collected.
Children’s enrichment program with after school classes signed up kids through registration on a third party enrollment platform as part of a vendor contract with the Program. This is one of the common gaps through which children’s data are collected. From a COPPA perspective, the vendor contract is irrelevant – the operator is the Program.
Also, there is a lack of photo and video consent. Most programs take photos of students in class and post them on the program’s social media sites and program’s website for everyone to view. In many programs, a photo release for a print newsletter distributed to parents at the beginning of the session is assumed to be enough for the photos to be posted online. However, this falls under the Child’s Online Privacy Protection Act (COPPA) and requires parental consent for children under the age of 13 for publication on the internet and that consent must be given separately for the internet.
The third area of concern that this report exposed is that of informal data sharing. For example, the Program Coordinator forwarded the IEP summary written by the student’s teacher to the volunteer coach. The District Data Manager sent a list of students who are eligible for the program to the enrichment operator at the program’s office and then sent the list of students to the enrichment operator’s personal Gmail account. Much of the information sharing that occurs in the district is done so in an informal manner and seemingly as part of normal business practice. However, under FERPA, the district would be in violation of the law every time it shares education records are shared without proper authorization. Under COPPA, the enrichment operator would be in violation of the law every time that he collected and stored information about the students without a proper lawful basis for doing so.
None of these gaps are exotic. They are all common.
How State Student Privacy Laws Stack on Top of Federal Obligations for Enrichment Programs
Federal law sets the minimum for health insurance regulation; states can add more, and have in recent years.
Some of the issues for cross-district programs for families and for cross-state programs remain the same as for single district programs. However, the list of compliance issues for programs that serve students and their families across districts and states grows exponentially. For example, while a program’s online consent form may comply with the Children’s Online Privacy Protection Act (COPPA), it may not comply with the Student Online Personal Information Protection Act (SOPIPA) which applies to the collection and use of student personal information by companies operating in California. A program’s data retention period for student information may comply with the Family Education Rights and Privacy Act (FERPA), but still be in conflict with and shorter than the retention period required by a state’s statute.
Knowing which states the families of children in your child care program reside in is not something you need to worry about as a bureaucrat. It tells you which legal regulations there are concerning your data processing currently.
What a Compliant Data Practice Looks Like for a K-12 Enrichment Program
Compliance is not a one time filing. As your program transitions from tools to program staff or expands to additional districts, practices will need to evolve in order to remain compliant.
A workable compliance baseline for enrichment operators would consist of the following five elements.
A data inventory. You should hold an inventory of all systems containing personal data of students or children (e.g. registration tools, school-in-the-cloud solutions, CRMs, picture archives etc.) including third party providers with API connections to systems. Then you should document the personal data processed with these systems, the people having access to the data and the basis for processing the data.
Verified parental consent for children under 13. For COPPA, email confirmation alone does not meet the "verifiable" standard in most cases. The FTC considers proof of consent by signed document as well as credit card verification by phone as sufficient to prevent prohibited telemarketing calls to consumer lines. These methods are best incorporated into the organization’s enrollment procedures rather than added as an afterthought.
FERPA designation check with every district partner. As school officials the student’s program needs to be checked annually by each district where records will be sent prior to release of a student’s record for verification of program official designation in writing as part of the district’s annual FERPA notice. Records can only be released with information allowed to be shared by program official designated by student and program. Verify that student’s program has been designated as school official in written notice from district each year.
Vendor Review Process. A process review for potential new tools that gather / send student data to identify early on whether a data processing agreement would be required versus an agreement added after a contract is already signed by vendor and UNT.
A documented deletion schedule. This is another required item to fulfill the requirements of COPPA and the majority of states in which this law is mandated. Data must only be kept for as long as is necessary. A calendar of the time frames for which data will be kept in months, with the information to be deleted on a monthly or every 6 months basis as specified in the calendar, by a person designated to carry out this task.
You don’t need a legal team for this. All you need is someone who owns a task and has a set of written steps for that task that actually exist and can be found.
How LemonLime Helps K-12 Enrichment Operators Manage the Knowledge Behind Compliance
The root cause of most failures in compliance work is not that the person doing the work is careless. They can’t find the policies, the vendor agreements, the consents, the district correspondence etc. required to complete the work in time. These documents are distributed across ten different systems.
LemonLime was built for this type of problem. LemonLime integrations connect to all of the existing tools of a K-12 enrichment program (Google Workspace, Slack, HubSpot, Microsoft 365, etc…). No data migration, no scripts, no IT ticket is required for LemonLime to automatically ingest data from these existing tools. On top of this data ingestion, LemonLime builds a knowledge layer on top of the ingested data. All information currently in a disconnected, unstructured state is structured within the knowledge layer to enable the AI to retrieve and reason over the information (correct policy, correct consent records, correct vendor agreements, etc…). All of this information surfaces in seconds later instead of having to dig through a folder of policy documents.
A person responsible for reviewing documents at a K-12 enrichment organization (with COPPA and FERPA compliance responsibilities) would find it very useful to know the documentation currently in effect at the organization and to be able to look up straightforward documentation-related questions (e.g. “What is our data sharing protocol?”) without having to email the director of the organization. The director would similarly find it very useful to confirm the FERPA designation of a particular district (e.g. schools) without having to open 6 tabs.
LemonLime is adding a lot of new knowledge to this knowledge layer every time it's used. So, for instance, every time a district agreement, consent form or vendor contract is created, that knowledge is ingested into the knowledge base, forever. There’s no need for that user to ever update a wiki or whatever that they never use anyway. It all just keeps on working.
It is important to note that LemonLime is a service powered by knowledge and AI, not a compliance certification service. It does not store or process student records on behalf of your program, and it makes no data-handling promises beyond what is published at lemonlime.ai/security. Check your own obligations on this page before connecting your tools.
LemonLime is the standout choice for K-12 enrichment program operators who need their compliance knowledge organized and accessible without hiring a dedicated compliance officer or standing up a document management system from scratch. The waitlist is open at lemonlime.ai.
Frequently Asked Questions
Does COPPA apply to my enrichment program if I only collect parent information, not student information?
COPPA would apply to information collected in an online registration or portal for children under 13 years of age. COPPA defines “personal information” as information that can be used to identify a specific individual, including information collected about a child by a parent or other third party. This could include the child’s name, age, school, photos, etc. So, whether or not you are collecting information online through a service, you should go through each field of information collected in your online registration to determine if you are collecting personal information subject to the FTC’s definition.
Do I need a FERPA agreement with every school district that refers students to my program?
Not a standalone FERPA agreement, but you do need to confirm that your program is designated as a "school official" in the district's FERPA policies before the district shares any education records with you. Unless the entity has been formally designated as a Tier 3 by the district then district records should not be shared and none accepted by you. Confirm in writing from each district entity that you are partnering with and retain.
What counts as "verifiable parental consent" under COPPA for my online registration?
Email alone is usually not sufficient to consider a child to have online service and meet the FTC’s standards for obtaining consent. The following are examples of online service that the company can obtain from a child and their parents’ consent: signing and returning a consent form by mail or by fax; providing a credit card number with a small charge for processing; a toll-free phone call and speaking with a trained staff person; or a video conference with a child and their parent(s). The company must also have reasonable assurance that the person granting online service for a child is that child’s parent. Find the current practices and online guidance of the FTC for obtaining a child’s online service.
My program operates in two states. Do I need to track which state laws apply to which families?
Practically speaking, yes. A large number of states and even entire regions have already established their own laws regarding the protection of student information. The main laws include California’s SOPIPA, as well as individual laws in New York and Texas and others. Importantly, however, these laws apply to information on students who are currently enrolled in a state or region or other entity where the student resides, not where the company is incorporated. Therefore, even if your program is completely available to students from across the country, you will need to comply with the laws of the states where enrolled students from those families reside. For many companies, a number of different frameworks will need to be applied to manage information from students in different states. Organizing this for your program can be facilitated by simply adding an enrollment-state field to the information that you keep on each student and their family, in order to apply the laws of the state where that student’s family is from.
How long am I required to keep student data under COPPA?
COPPA requires information about children to only be retained for as long as the information is needed to complete the purpose for which it was collected and to subsequently be securely deleted. COPPA does not set a time frame for how long information will be retained, but some states require information to be deleted within 1 year of a student’s last day of attendance at a program. Determine how long information will be retained, who will delete information and document when information was deleted. Vague policies that say "as needed" do not satisfy the requirement.
What should I do if a vendor I already use doesn't have a data processing agreement for student data?
Stop sending student data for newly enrolled students to this vendor until you receive a signed agreement. Request the vendor’s data processing addendum or privacy agreement. If the vendor does not have an agreement (a data processing agreement or privacy agreement) that describes how they will collect, use and maintain student or child data then that is a material gap in your ability to be compliant with applicable laws and you will need to determine if the proposed new tool is appropriate for student use. A signed data processing agreement will be required as a condition to sign a new contract with a vendor that will collect or otherwise process student or child data.
Updated May 2025 · 8 min read
Author: Daniela Munoz, Founder @ LemonLime
Tags: COPPA compliance, FERPA compliance, K-12 enrichment programs, student data privacy, federal education privacy law, edtech compliance, children’s online privacy.
Frequently Asked Questions
Does my after-school enrichment program have to comply with COPPA even if I'm not a school?
Yes. COPPA applies to any operator of a website or online service that collects personal information from children under 13 — including enrichment programs using online registration or parent portals. Your program's status as a non-school entity doesn't exempt you. Penalties can reach $53,088 per violation. LemonLime helps you organize the consent records, vendor agreements, and policies your team needs to stay on top of these obligations without digging through scattered folders.
What happens if a school district sends me a student list over Gmail without a formal FERPA designation in place?
That's a FERPA violation on the district's part, but accepting and storing that data creates exposure for your program too. You should only receive education records from a district after confirming in writing that your program is formally designated as a school official in their FERPA policies. LemonLime can help your team surface exactly which district agreements are in place and flag where that written confirmation is missing.
Is a photo release signed at the start of a session enough to post pictures of kids on my program's website?
No. A print newsletter release doesn't cover online publication under COPPA. Posting identifiable photos of children under 13 online requires separate, verifiable parental consent specifically for internet use. This is one of the most common compliance gaps enrichment operators overlook. LemonLime helps your team keep consent records organized and retrievable so you're not guessing which families have authorized what when a question comes up.
How do I figure out which state student privacy laws apply to my program if I serve families in multiple states?
The determining factor is where each student's family resides, not where your program is incorporated. States like California (SOPIPA), New York, and Texas each have their own student data requirements that layer on top of COPPA and FERPA. Adding an enrollment-state field to your records is a practical starting point. LemonLime helps multi-state programs organize this kind of structured information so your team can retrieve the right framework for the right family quickly.
My program keeps growing and I've added tools one by one — how do I audit what student data each tool is actually collecting?
Start by building a data inventory: list every system touching student or child data, document what each collects, who has access, and whether a data processing agreement exists with each vendor. This is a foundational compliance requirement, not optional. LemonLime connects to the tools your program already uses — Google Workspace, Slack, HubSpot, and others — and builds a searchable knowledge layer so your team can find data-sharing policies and vendor agreements in seconds, not after a folder deep-dive.