Web Development Guidelines
Resources for Creating a Web Site at Johns Hopkins
Johns Hopkins Institutions Logo
Web Guidelines Home Page Hopkins Guidelines FERPA HIPAA Glossary Section 508
Web Guidelines Site Map

Family Educational Rights and Privacy Act (FERPA)

What is It?

"The Family Educational Rights and Privacy Act (FERPA) is a Federal law designed to protect the privacy of a student's education records. The law applies to all schools which receive funds under an applicable program of the U.S. Department of Education. FERPA gives parents certain rights with respect to their children's education records. These rights transfer to the student, or former student, who has reached the age of 18 or is attending any school beyond the high school level. Students and former students to whom the rights have transferred are called eligible students." When an individual requests student information from a university, the university must respond in accordance with FERPA guidelines. The Department of Education's FERPA guidelines act as the foundation. In other words, JHU/JHM cannot exceed them. However, the university can be more restrictive. JHU/JHM is slightly more restrictive, and some schools within JHU/JHM are more restrictive than the university's guidelines in the directory information they release.

What Information May an Institution Disclose?

JHU/JHM may disclose directory information, or personally identifiable information not deemed harmful to the student if released. This information includes:

What Information May Not Be Disclosed (Protected Under FERPA)?

According to the American Association of Collegiate Registrars and Admissions Officers (AACRAO), the following is not considered directory information and may not be disclosed in any way (except to a school official with a legitimate educational interest, or to a third party with a signed and dated consent from the student): If an individual requests student information not included under the term directory information, the university must obtain written permission (signed and dated) from the student before disclosing this information.

What Information May Universities Collect From Students and What Collection Method May Be Used?

FERPA does not address collection of data, as its emphasis is on maintaining the right of privacy. Basically, the method of collection is whatever fashion the institution determines (e.g., Internet Web form, mail-in survey, over the phone). Inherent in that determination is that in transmitting the information to the institution, the institution ensures that the information is protected and that when disclosing the collected information, the institution follows FERPA guidelines for disclosure. Thus, security in collection is indirectly inferred. See the guidelines on web security for detailed information.

What is JHU/JHM's Policy on FERPA?

JHU/JHM may not disclose education records about students nor allow inspection of student records without written permission by the student. An education record is defined as a record maintained by an educational institution and includes information that makes a student personally identifiable. Examples of personally identifiable information are: name, address, telephone number, or Social Security Number or another student identifier. A record can be information maintained in any way, including (but not limited to) handwriting, film, audio, video, computer media, print, or microfilm.

Who Is the FERPA Contact at JHU/JHM?

The University's General Counsel's Office is the legal advisor for ensuring compliance with the statute. However, the responsibility flows to the administrative offices that deal with student data on a consistent basis. Generally, FERPA questions are referred to each division's registrar. The registrars are viewed as the advisors for FERPA-related issues/questions since they deal with the bulk of student data in various ways. The registrar is also the contact for enrolled students who have questions about privacy rights and access to their information. Internally, they advise administrators, faculty, etc., about properly handling student information to ensure regulatory compliance. If a question or issue confronts the registrar that exceeds the scope of their guidelines, they then involve General Counsel.

For More Information on FERPA

U.S. Department of Education Family Policy Compliance Office
American Association of Collegiate Registrars and Admissions Officers
JHU/JHMI's FERPA policy


Before beginning any Johns Hopkins Institutions web project, please contact the appropriate office in your area for assistance with guidelines, standards or existing programs.

If there is any doubt about the methods for collecting, storing, or displaying sensitive information on web sites, the Johns Hopkins legal departments (410-516-8128) should be contacted for a definitive answer about Hopkins' liability and responsibility.