Family Educational Rights and Privacy Act (FERPA)
FERPA compliance is not something that any tech vendor can do for you - student privacy is a team sport and requires partnership to protect students.
nQuest was designed to enable universities to comply with FERPA requirements for investigations of students while using nQuest.
State and local privacy laws may vary, and different universities may interpret their FERPA requirements in different ways. nQuest can work with you to ensure your institution’s specific compliance requirements are met.
Student Records
Section titled “Student Records”nQuest does not make a determination what is and is not part of a student’s record. However, it assists universities in ensuring that potential student records are discoverable for data subject access compliance.
Configuring nQuest for FERPA
Section titled “Configuring nQuest for FERPA”Any institution with FERPA compliance requirements should request that nQuest tag their account as FERPA-protected. Work with your counsel and nQuest’s team to determine if nQuest staff need to be designated as FERPA school officials.
Compartments
Section titled “Compartments”Compartments’ deny-by-default overriding access function is ideal for managing several considerations around FERPA.
Setting up a FERPA Compartment, and then setting the access list as only those users and groups who are designated as FERPA school officials prevents non-school officials from viewing even the existence of cases tagged as FERPA, even if they’re accidentally shared by a school official.
Setting up a FERPA-LEU compartment enables Law Enforcement Unit investigations to be hidden from disclosure even during FERPA compliance activities. We recommend not granting FERPA-LEU compartment access to anyone who is not part of the legal department or a Law Enforcement Unit to reduce misclassification risk.
For more on compartments, see Compartments.
Entities
Section titled “Entities”Investigators should make sure that an investigation of a student includes a reference to a Student FERPA Subject Entity with the Student ID number of the student under investigation, and tagged with a FERPA Direct role. (FERPA Indirect roles are also a concept, and this can potentially help with compliance).
Once that’s done, the case should be tagged at the summary level as directly associated with a Student, enabling speedy FERPA reporting as needed.
For more on entities, see Entity Nodes.
Private Contents
Section titled “Private Contents”The actual contents of a case (rather than its summaries, case reports, and any case-level attachments) are private by default when assigned only to an individual user.
Depending on your institutional policies, you could treat those as personal notes prepared for the investigator’s reference under most circumstances. If you choose to use the product in this way, we can make some customizations to disable/warn when creating a student record.
Automatic Mandatory Access
Section titled “Automatic Mandatory Access”Any account set as a FERPA Admin also has automatic summary viewer access to any case directly related to a FERPA subject entity. They should be added to any compartment used to secure FERPA-eligible student information.
This ensures that they can see any case that is potentially subject to FERPA disclosure, and they can see any cases they may need to disclose.
FERPA Notes
Section titled “FERPA Notes”If an account is tagged as FERPA-protected, FERPA note functionality is enabled.
This allows a FERPA Note - a special type of case attachment - to be uploaded by a FERPA admin to any case they can see (LEU cases can be immune, if configured appropriately).
These notes display at the same level as other case high-level information, helping you to meet requirements to allow students to add notes to their student records.