Purple and FERPA-Protected Data Usage Guidelines


Use of FERPA-Protected Information in Purple 

Purple is designed to align with federal student privacy requirements under FERPA, which means University employees may use FERPA-protected education records within Purple when doing so as part of legitimate University business. 

When using Purple with student education records, users must follow these requirements: 

1. Use Student Information Only for Legitimate University Purposes

FERPA-protected information may only be entered into Purple when it directly supports your authorized University responsibilities, including academic, administrative, advising, or operational work performed on behalf of the University. 

2. Do Not Share Education Records Inappropriately

Education records entered into Purple, as well as any outputs incorporating them, must not be shared with individuals who do not have a legitimate educational or business need to access that information under FERPA.

3. Treat Purple Outputs as Protected Records 

Purple is not meant for long-term storage. If an output needs to be retained as an official record, you must handle, store, transmit, and share this record in the same way as any other FERPA-protected record.

4. Verify Accuracy Before Acting on AI-Generated Content

Content generated by Purple may contain inaccuracies, omissions, or incorrect interpretations. Users are responsible for independently reviewing and verifying all outputs before using them to make decisions, communicate with students, or incorporate them into official University processes.

5. Do Not Delegate Decision-Making to AI 

Purple may assist with drafting, summarizing, or analyzing information, but it should not be relied upon as the sole basis for decisions affecting students, academic standing, advising, or other official institutional actions.

6. Maintain Professional Judgment and Accountability

Users remain fully responsible for how FERPA-protected information is used within Purple and for ensuring compliance with University privacy policies, FERPA requirements, and institutional data stewardship expectations. 

Examples of FERPA Violations 

Exposing student records to people without legitimate educational interest.

Example: An advisor builds a Purple agent that can answer questions about grades, academic standing, disciplinary history, or advising notes and includes education records as grounding material.

Problem: Staff, student workers, and faculty who do not have a legitimate educational need to know use the agent and are presented with some of the contents of those records.

Sharing AI-generated summaries that contain FERPA-protected information. 

Outputs can themselves become education records.

Example: A department uploads advising notes and asks Purple to list students who are “academically struggling” and suggest ways to help. The list with recommendations is then emailed broadly within the department.

Problem: The original records may have been accessed appropriately, but the generated output is now being shared beyond authorized personnel.

Purple may be used with FERPA-protected data only when the user already has authorized access to that information, uses it solely for legitimate university business, limits disclosure of outputs to authorized individuals, and verifies that AI-generated outputs are accurate before relying on or sharing them. 

Additional Resources