zoomgoogle-driveadmineducationferpa

FERPA and Zoom Recordings: What Education Admins Need to Know

By Adam Dobrawy · · 9 min read

FERPA and Zoom Recordings: What Education Admins Need to Know

The question rarely comes from a lawyer. It comes from an instructional-technology director halfway through approving a new tool, pausing to ask: "wait — does this touch student data covered by FERPA?" For a Zoom cloud recording, the honest answer is "sometimes, and it depends on where it ends up" — which is a worse answer to give a security reviewer than a clean yes or no, but it's the accurate one, and it's worth working through properly before you install anything.

What's actually happening

FERPA doesn't regulate recordings as a category. It regulates education records — and the U.S. Department of Education's Student Privacy Policy Office defines those as records that are directly related to a student and maintained by the institution (or by a party acting on the institution's behalf), in any format, explicitly including video and audio.

That two-part test decides more than it looks like it does:

  • A lecture recording where only the instructor speaks, with no student identifiable in video, audio, or chat, isn't a student record at all — there's no student it's "directly related to."
  • The moment a student asks a question on camera, answers a cold-call, or presents to the class, that portion of the recording identifies them — and if the institution keeps a copy, it's now an education record, same as a transcript or grade file.
  • A recording an instructor keeps purely to themselves — never shared, not stored anywhere the institution administers — generally isn't "maintained by the institution" either, under FERPA's carve-out for records kept in an individual's sole possession as a personal memory aid. That's a fragile position to rely on by accident, though: the same recording, the moment it's synced to a departmental drive or shared with a TA, stops being a private note and becomes an education record the institution maintains — whether or not anyone decided that on purpose.

Neither Zoom's nor Google's infrastructure is itself "FERPA compliant" — compliance describes how an institution and its agents handle records, not a feature of software. When a third-party service handles those recordings on the institution's behalf, FERPA's school-official exception (34 CFR 99.31(a)(1)(i)(B)) is the relevant test: the service has to perform work the institution would otherwise do with its own staff, stay under the institution's direct control over how those records are used and maintained, and be bound by 34 CFR 99.33(a)'s limits on redisclosing the personally identifiable information it touches. None of that is automatic — the institution has to be able to demonstrate it, usually through a written agreement plus a setup that actually reflects direct control in practice, not just on paper.

Retention: FERPA doesn't set a clock, your institution does

FERPA itself doesn't specify how long a class recording has to be kept, or how soon it must be deleted — that's a common misread. Once something qualifies as an education record, it falls under whatever records-retention schedule your institution (or your state's public-records law, for public institutions) already applies to education records generally. There's no separate "recording retention" rule to look up; there's only your existing retention schedule, now applying to a new kind of file.

In practice that cuts both ways. A recording archived automatically to Drive doesn't get to sit there forever by default just because it's convenient to keep — if your retention schedule says grade-related materials get reviewed or purged after a set period, an archived class recording that qualifies as one is subject to the same review. And the reverse risk is the one that actually costs people: Zoom's own cloud storage isn't built to preserve anything on your institution's retention schedule — it ages recordings out on Zoom's terms, not yours, which is precisely the gap an institution-owned archive is meant to close.

Why an institution-owned archive is the defensible setup

Direct control is easy to assert and hard to demonstrate once recordings are scattered across individual instructors' personal accounts. If an adjunct's own Google Drive is where a semester of class recordings lives, the institution can't apply access controls to it, can't audit who's opened a file, and has no guarantee the recordings survive after that adjunct's contract ends and their account gets deactivated — the opposite of controlling how records are used and maintained.

An archive that lands in a Drive folder the institution itself owns and administers — a Workspace-managed account, or better, a shared Drive the department controls — is what actually lets IT show a reviewer that student recordings sit somewhere the institution can govern, not somewhere it merely hopes an instructor is being careful.

What to check before you rely on any recording archive

How RecordFlow fits

Here's the part worth stating plainly, because it's the part a vendor is tempted to blur: nothing below makes your institution FERPA-compliant, and we don't claim it does. RecordFlow is infrastructure your institution configures within its own compliance posture, not a certification that stands in for your own legal review. Whether a given recording is an education record, who needs a legitimate educational interest to see it, and what your written agreements say — that's a determination for your institution and its counsel, not for our marketing page.

What RecordFlow's admin-managed app does give you is the shape FERPA's school-official test rewards. One Zoom account admin installs it once, connects a single Google Drive folder the institution owns as the archive root, and enrolls instructors from a dashboard — nobody's recordings start archiving until an admin flips their toggle on. Every enrolled instructor's sessions land in their own named sub-folder under that institution-controlled root, the same layout our universities and colleges guide walks through for semester turnover. And RecordFlow itself never stores a recording's bytes on its own infrastructure — files stream from Zoom straight into the Drive folder your institution controls, detailed end to end in how RecordFlow handles your data. The institution-owned destination and the admin-only enrollment toggle are what make direct control demonstrable — the pieces your reviewer actually asks about, running automatically instead of depending on someone remembering to do it by hand.

An archive your institution actually controls.

RecordFlow's admin-managed app archives every enrolled instructor's Zoom recordings into a Google Drive folder your institution owns — one install, admin-only enrollment, nothing stored on our infrastructure. Free during beta.

Frequently asked questions

Is a recorded Zoom class session automatically a FERPA education record?
Only if it's directly related to an identifiable student and maintained by the institution or someone acting on its behalf — the two conditions the U.S. Department of Education's Student Privacy Policy Office sets for any education record, in any format including video and audio. A recording of an instructor lecturing alone, with no identifiable student audio, video, or chat, doesn't meet that bar. The moment a student's voice, image, or name is in the recording and the institution keeps a copy, it does.
Can a university's IT department let a third-party tool like Zoom or a backup service handle recordings without violating FERPA?
Yes, under FERPA's school-official exception (34 CFR 99.31(a)(1)(i)(B)), as long as the vendor performs a service the institution would otherwise handle with its own employees, stays under the institution's direct control over how those records are used and maintained, and is bound by 34 CFR 99.33(a)'s limits on redisclosure. The institution — not the vendor — is responsible for confirming those conditions hold, typically in a written agreement.
Does storing Zoom recordings in a personal Google Drive create a FERPA risk?
It creates a custody problem, which is the practical risk FERPA's direct-control requirement is pointing at. A recording sitting in an adjunct's personal Drive is outside any account the institution administers — it can't apply access controls, can't audit who's viewed it, and loses the recording entirely if that person's account is deleted or they simply stop cooperating. An institution-owned Drive (personal-workspace or shared) that IT actually administers is what lets the school demonstrate the direct control 34 CFR 99.31(a)(1)(i)(B) requires of a school official.
Does RecordFlow make an institution FERPA-compliant?
No, and we don't claim it does. FERPA compliance is a determination your institution makes with its own counsel, based on your policies, your Workspace configuration, and how your staff actually use recordings — not on any single vendor's marketing page. What RecordFlow does is infrastructure: it archives enrolled instructors' Zoom recordings into a Drive folder your institution owns and administers, never stores a recording's bytes on its own servers, and makes enrollment an admin-only toggle. Those properties support a FERPA-aware setup; they aren't a substitute for your institution's own compliance review.
How long does a FERPA-covered class recording need to be retained?
FERPA itself doesn't set a retention period for class recordings — that's a common misread. Once a recording qualifies as an education record, it falls under whatever records-retention schedule your institution (or your state's public-records law, for a public institution) already applies to education records generally; there's no separate rule just for recordings. What FERPA does affect is custody in the meantime: Zoom's own cloud storage ages recordings out on Zoom's schedule, not your institution's, which is the gap an institution-owned archive is meant to close before your own retention schedule ever gets a chance to apply.

More from the blog