Skip to content

FERPA: Why It’s Crucial for Higher Education (2026)




FERPA in Higher Education: A Comprehensive Guide to Student Privacy Rights

The Family Educational Rights and Privacy Act (FERPA) stands as one of the most important federal laws protecting student privacy in higher education. Enacted in 1974, FERPA grants students and parents specific rights regarding educational records while imposing strict obligations on institutions to safeguard sensitive information. For students, parents, and education professionals, understanding FERPA is essential in navigating the complex landscape of data privacy, institutional compliance, and student rights in modern higher education.

Key Takeaways

  • FERPA protects student privacy by restricting unauthorized access to educational records and granting students control over their personal information
  • Students have the right to inspect records, request amendments, and control who accesses their information
  • Educational institutions must implement robust security measures, staff training, and compliance procedures to meet FERPA requirements
  • Violations of FERPA can result in loss of federal funding and damage to institutional reputation
  • Understanding FERPA exceptions is critical for addressing emergencies, court orders, and other legitimate educational purposes

What Is FERPA and Why Does It Matter in Higher Education

The Family Educational Rights and Privacy Act represents federal legislation that fundamentally shapes how colleges, universities, and schools handle student information. FERPA creates a legal framework requiring educational institutions to protect student records from unauthorized disclosure while simultaneously granting students unprecedented control over their personal educational information. This balance between privacy protection and necessary information sharing forms the foundation of trust between students and their institutions.

In the context of higher education specifically, FERPA carries heightened importance because college students are legally considered adults with full rights to their own records. Unlike K-12 education where parental access is the default, college students become the primary decision-makers regarding who can access their grades, discipline records, financial information, and other sensitive data. This shift places significant responsibility on both institutions and students to understand privacy rights and obligations.

The relevance of FERPA has intensified in recent decades due to technological advancement and the increasing digitization of educational records. As institutions migrate student data to cloud-based systems, learning management platforms, and third-party vendors, the potential for unauthorized access and data breaches has multiplied. FERPA provides the legal framework for institutions to implement comprehensive data security strategies, including encryption, access controls, vendor compliance requirements, and regular security audits. Without FERPA, educational institutions would lack the regulatory mandate to prioritize data security investments that protect millions of student records annually.

For parents of college students, understanding FERPA involves recognizing that their access to student information may be significantly limited once their child enrolls in higher education. This represents a fundamental shift from K-12 education and often surprises families unprepared for the change. For education professionals, FERPA compliance represents a core operational responsibility with real consequences for institutional failure, including potential loss of federal funding and reputational damage.

FERPA’s structure rests on several interconnected components that work together to create a comprehensive privacy framework. The law defines what constitutes an educational record, establishes who qualifies as an eligible student with full privacy rights, specifies which institutions fall under FERPA’s jurisdiction, and outlines both student rights and institutional obligations. Colleges and universities must understand each component to implement compliant policies and procedures.

An educational record, as defined by FERPA, encompasses any record directly related to a student that is maintained by an educational institution or a party acting on the institution’s behalf. This definition extends far beyond just grades and transcripts. Educational records include attendance records, disciplinary files, special education assessments, correspondence between students and advisors, emails from instructors discussing academic progress, financial aid documents, counseling notes, medical records maintained by campus health services, and even video recordings from classroom lectures. The breadth of this definition surprises many students and parents who initially assume only formal academic records fall under FERPA protection.

Importantly, FERPA establishes specific exemptions from what constitutes an educational record. Personal notes maintained by an instructor solely for their own reference that are never shared qualify as exempt. Records maintained by campus law enforcement in their official capacity and accessible only to law enforcement personnel are excluded. Medical records maintained by health professionals and used solely for treatment purposes, though created by an institution, may receive different protections under HIPAA (Health Insurance Portability and Accountability Act) rather than FERPA. Understanding these exemptions helps institutions correctly classify records and apply appropriate privacy protections.

FERPA applies to all institutions that receive funding under any program administered by the U.S. Department of Education. This creates broad applicability across virtually all accredited colleges and universities in the United States. Private institutions that accept federal student aid funds, whether through direct loans, Pell Grants, or other programs, fall under FERPA’s jurisdiction. Even institutions that decline to accept federal funding cannot escape FERPA entirely, as some state regulations and accreditation bodies incorporate FERPA standards into their own requirements.

Student Rights Under FERPA: What College Students Need to Know

College students gain comprehensive privacy rights under FERPA that fundamentally differ from those available to K-12 students. These rights empower students to control their educational narrative and protect personal information from unwanted disclosure. Understanding these rights allows students to advocate effectively for their privacy and make informed decisions about information sharing.

The first and foundational right FERPA grants is the right to inspect and review educational records. Students can request access to any educational record maintained about them, and institutions must provide this access within a reasonable timeframe, typically within 45 days. This right ensures transparency and allows students to understand what information their institution holds about them. Students may request records in person, by mail, or increasingly through secure online portals. Some institutions charge reasonable copying fees for providing records, though no fee may be charged for searching or retrieving records. This inspection right gives students a mechanism to verify accuracy and identify any errors or inappropriate information in their files.

The second critical right involves requesting amendments to educational records. If a student believes their records contain inaccurate, misleading, or inappropriate information, FERPA grants the right to request correction. The amendment process begins with a formal written request explaining the alleged inaccuracy and the basis for the correction. Institutions must then decide whether to make the requested amendment. If the institution agrees the information is inaccurate, it must correct the record. If the institution disagrees, it must inform the student of the decision and explain the student’s right to request a hearing on the disputed information. The amendment right represents a powerful tool for correcting errors, though it applies only to factual inaccuracies rather than subjective judgments like grade disputes.

The third major right allows students to control disclosure of their educational records. Institutions cannot release student records to third parties without prior written consent from the student except in specific circumstances outlined in FERPA regulations. This means a parent, spouse, employer, financial institution, or journalist cannot obtain a student’s records without authorization. Students decide who gets access and can restrict access on an ongoing basis. A student might consent to allow a school’s financial aid office to share information with loan servicers while simultaneously restricting access to disciplinary records. This granular control respects student autonomy and prevents unwanted information sharing.

The fourth right permits students to request an audit trail showing who has accessed their records. While institutions are not required to maintain comprehensive access logs for all records, when they do maintain such logs, students can request to see who viewed their files and when. This transparency helps detect unauthorized access and allows students to identify potential privacy breaches. As institutions increasingly digitize records and implement learning management systems, maintaining accurate access logs becomes increasingly important and technically feasible.

The fifth right allows students to file complaints with the Department of Education’s Family Policy Compliance Office (FPCO) if they believe their institution has violated FERPA. This federal oversight mechanism provides recourse for students whose privacy rights are violated. Students can file complaints describing the violation and requesting investigation. The FPCO conducts investigations and can require institutions to take corrective action, though the office does not award monetary damages to individual students.

Parental Rights and Limitations in College FERPA Context

The relationship between parental rights and student privacy rights represents one of the most significant sources of confusion regarding FERPA implementation in higher education. Parents and students often hold conflicting expectations about information access, creating challenging situations for institutions that must honor legal obligations while managing family relationships.

Under FERPA, parental access to student records is not automatic in higher education. Once a student attains the age of majority (18 in most states) or enrolls in a postsecondary institution, that student becomes an eligible student with full privacy rights. The student, not the parent, controls access to educational records. This represents a fundamental shift from K-12 education where parents generally have automatic access to their minor child’s records. Parents of college students cannot access grades, academic standing, financial aid information, or disciplinary records without the student’s explicit written consent.

This change reflects the legal transition to adulthood and the importance of respecting young adults’ developing autonomy. However, the shift often surprises families who remain accustomed to receiving quarterly report cards and communication about their child’s academic progress. Some parents struggle to accept reduced information access, while some students appreciate the privacy and others wish parental involvement would continue but lack the mechanism to facilitate it within FERPA’s constraints.

Institutions handle this transition differently. Some send communications to both students and parents during the first semester explaining FERPA requirements and the need for student authorization before sharing information. Some provide templates for FERPA release forms allowing students to authorize parental access. Progressive institutions recognize that many students want parental involvement but need the ability to control the specific information shared. By providing simple mechanisms for students to authorize parental access, these institutions bridge the gap between legal requirements and family needs.

Important exceptions exist where institutions can contact parents without student consent. If a student is under 21 and has committed a violation of institutional alcohol or drug policies, the institution may notify parents. This exception reflects federal law’s specific acknowledgment that substance use prevention may warrant parental involvement even in higher education. Institutions must carefully track this exception and ensure it applies only to the specific circumstance of alcohol and drug policy violations involving students under 21.

In health and safety emergencies, institutions may disclose information to parents without consent if necessary to protect the student. If a student experiences a mental health crisis or expresses suicidal ideation, an institution might contact parents to ensure proper support and care. This exception prioritizes student welfare over privacy and reflects recognition that parental involvement may be essential in genuine emergencies.

Educational Records Defined: What FERPA Actually Protects

A comprehensive understanding of what constitutes an educational record is essential for both institutions seeking to comply with FERPA and students seeking to protect their information. The definition is broader than many people initially assume, extending to nearly any record that identifies a student and relates to their education.

Type of Record Status Under FERPA Key Considerations
Official transcripts, grade reports, enrollment verification Protected educational records Core academic documents protected by default
Disciplinary records, conduct files, violation documentation Protected educational records Institutional conduct systems create FERPA-protected records
Financial aid documents, FAFSA information, loan records Protected educational records Even when maintained by financial aid offices, these are educational records
Email correspondence from instructors about grades or academic progress Protected educational records Communication maintained by institution about student academic performance
Accessibility accommodations documentation, disability records Protected educational records (additional ADA protections apply) Highly sensitive; separate privacy protections often required
Counseling notes, mental health records from counseling center Educational records with potential HIPAA overlap May qualify for greater protection under HIPAA if health professionals maintain
Campus health records maintained by student health services May be protected as educational record or health record Depends on whether maintained by health professionals; HIPAA may apply
Personal notes written by instructor for own reference, not shared Not protected (FERPA exempt) Only applies if notes remain personal; once shared, status changes
Records maintained by campus law enforcement Not protected (FERPA exempt in some contexts) Law enforcement records have different status under FERPA
Directory information (unless student restricts) Protected but may be disclosed without consent if not restricted Name, address, phone, email are commonly designated as directory information

Directory information represents a specific category of educational records that institutions handle differently. Directory information typically includes name, address, telephone number, email address, enrollment status, and graduation date. Unlike other educational records, directory information may be disclosed without student consent unless the student specifically restricts it. However, institutions must inform students of what constitutes directory information and provide opportunity to restrict disclosure. Many students don’t realize that restricting directory information prevents not only external inquiries but also may limit institutional use for commencement programs or other communications.

A common misconception suggests that information published on a university website is automatically exempt from FERPA protection. However, if that information identifies a student and relates to their education, it remains an educational record subject to FERPA. Many institutions have faced challenges when student photos, academic achievements, or other identifying information appears online without consent. Students should review what information appears about them online and request removal if not authorized.

Educational records exist in multiple formats, and FERPA protects all formats equally. Digital records maintained in student information systems, learning management platforms, or cloud storage receive the same protection as paper files in locked filing cabinets. Video recordings of classroom lectures, audio recordings of discussions, photographs from campus events, and other multimedia records all qualify as educational records if they identify students and relate to their education. The format does not diminish FERPA protection; digital records actually increase vulnerability and require enhanced security measures.

While FERPA’s default position restricts disclosure of educational records without consent, the law recognizes several important exceptions where institutions may share information without authorization. Understanding these exceptions is critical for both institutions and students, as misapplication of exceptions represents a common source of FERPA violations.

The most significant exception applies to school officials with a legitimate educational interest. Institutions may disclose educational records to faculty, administrators, staff, and other school officials who need the information to perform their job duties. An academic advisor needs access to transcripts to help a student plan courses. An admissions officer needs access to application materials. A residence life staff member needs access to conduct records to address roommate conflicts. These disclosures don’t require student consent because the recipients have legitimate educational purposes for accessing the information. However, institutions must define what constitutes a legitimate educational interest and ensure staff understand they can access only information relevant to their specific duties.

The directory information exception allows institutions to share commonly designated information without consent, provided students are informed and given the opportunity to restrict. As mentioned, directory information typically includes name, address, phone, and email, though institutions decide what qualifies. Some institutions add high school attended, class year, or major to directory information. This exception permits institutions to share information with external parties like reunion planners, donors, or alumni magazines without individual consent.

The health and safety emergency exception permits institutions to disclose educational records without student consent when necessary to protect the health or safety of the student or other individuals. If a student reports to a counselor that they’re considering suicide, the counselor may contact parents or emergency services without the student’s authorization. If campus security learns of a threat on campus, they may warn community members without regard to FERPA. This exception prioritizes immediate safety over privacy and reflects the principle that no privacy right is absolute when genuine emergencies threaten welfare.

The parental notification exception for alcohol and drug violations allows institutions to notify parents when a student under 21 violates institutional alcohol or drug policies. This specific exception reflects federal policy encouraging institutional communication with parents about substance use. Some students are surprised to learn that what they consider a personal conduct matter may result in parental notification, highlighting the importance of understanding this exception.

The court order or subpoena exception permits disclosure when a properly issued court order, subpoena, or judicial demand requires disclosure. If a student is involved in civil litigation and the opposing party subpoenas educational records, an institution must comply. Similarly, if law enforcement presents a search warrant for records, institutions must comply. These legal demands override FERPA protection, though institutions typically notify students of the legal demand and may seek to limit the scope of requested information.

The interinstitutional transfer exception allows disclosure to institutions where a student seeks to enroll or attend. When a student applies to graduate school or transfers to another college, both institutions may share relevant educational records to facilitate the transfer. The student typically authorizes this through the application process. This exception reflects recognition that student mobility requires information sharing across educational institutions.

The financial aid exception permits disclosure of educational records to agencies and entities involved in administering federal financial aid programs. Students applying for loans must disclose educational information to lenders. Veterans Administration must receive educational records for veterans’ education benefits. These disclosures occur without the need for individual student consent because federal law requires them as part of aid administration.

The research exception allows disclosure of educational records for research purposes if appropriate safeguards protect student privacy. Institutions conducting research on educational outcomes may use student records if individual identifying information is removed or the researcher obtains student consent. This exception acknowledges the importance of research while maintaining privacy protections through anonymization or authorization.

Perhaps most importantly, students should understand that FERPA exceptions represent narrow circumstances, not broad categorical exceptions. Each exception has specific requirements and limitations. An institution cannot disclose information simply because someone requests it; a legitimate exception must exist. Institutions that broadly apply exceptions beyond their scope commit FERPA violations that expose them to federal enforcement action.

Implementing FERPA Compliance: Institutional Responsibilities and Best Practices

Colleges and universities bear primary responsibility for FERPA compliance. The Department of Education enforces FERPA through the Family Policy Compliance Office, investigating complaints and requiring corrective action from non-compliant institutions. Institutions that violate FERPA face potential loss of federal funding, representing a severe financial consequence that motivates institutional compliance.

Developing comprehensive FERPA compliance policies represents the foundation of institutional responsibility. Policies should clearly define what constitutes an educational record, specify student rights, explain the institution’s procedures for providing record access, outline authorization processes for disclosure, and address the mechanisms for handling records requests and complaints. These policies should be accessible to students, parents, and staff. Many institutions publish FERPA policies in student handbooks, on institutional websites, and in campus security authority reports, ensuring broad awareness.

Providing annual FERPA notices to students and parents is a legal requirement under FERPA regulations. Institutions must notify students of their rights to inspect records, request amendments, and seek restrictions on disclosure. Many institutions send these notices electronically to student email addresses or post them on institutional websites. However, institutions must ensure these notices actually reach the audience and use language that students understand rather than dense legal jargon. Some research suggests that many students delete or ignore FERPA notification emails without reading, defeating the purpose of the notice.

Appointing a FERPA compliance coordinator or designating responsibility for FERPA administration ensures clear accountability. The FERPA coordinator develops institutional policies, responds to record access requests, handles amendments and disputes, addresses student complaints, and coordinates training for relevant staff. In larger institutions, separate FERPA liaisons may be designated within colleges or functional areas, with coordination through a central compliance office. This distributed responsibility ensures that FERPA receives attention at all institutional levels.

Staff training on FERPA requirements is essential but often receives insufficient institutional attention. Staff members handling student records, from registrars to residence life coordinators to advisors, need to understand FERPA basics, know what information they can access and share, and recognize when to seek guidance on uncertain situations. Effective training goes beyond passive online modules; it involves scenario-based discussion allowing staff to apply FERPA to specific institutional contexts. For example, discussing how to handle a parent calling to check on a student’s academic progress helps staff understand the practical application of the principle that parental consent is required before sharing information.

Implementing secure data handling practices protects records from unauthorized access and potential breaches. Institutions should encrypt digital records, use access controls limiting record access to authorized personnel, implement secure login systems with strong authentication, and maintain audit trails documenting who accessed records and when. Paper files should be stored in locked facilities with restricted access. When records are transported or shared, institutions should use secure methods preventing interception.

Establishing clear procedures for record access requests ensures students can exercise their rights. Institutions should have online or paper mechanisms allowing students to request their records, specify which records they need, and receive them within the required timeframe. Some institutions maintain centralized record request offices while others allow departments to handle their own requests. Regardless of structure, institutions must track requests to ensure timely response and maintain records documenting compliance with access requests.

Developing amendment procedures allows institutions to address student requests to correct inaccurate information. Clear policies should explain what constitutes an inaccuracy, how students initiate amendment requests, how institutions investigate disputed information, how institutions make amendment decisions, and what happens if the institution disagrees with the amendment request. These procedures should be transparent and provide students opportunity to respond if the institution refuses an amendment before the record is finalized.

Establishing a complaint resolution process demonstrates institutional commitment to addressing FERPA violations and student concerns. Students should know how to file formal complaints about FERPA violations, expect timely investigation, and receive notification of findings. Addressing complaints promptly may prevent escalation to federal enforcement, as the Department of Education considers institutional remediation when investigating violations.

Technology, Data Security, and Modern FERPA Challenges

The digitization of educational records and migration of student data to cloud-based systems and third-party platforms have transformed FERPA compliance from a records management challenge to a comprehensive data security responsibility. Modern higher education institutions maintain student information across multiple systems, from student information systems (SIS) to learning management systems (LMS), to financial systems, to residence life management platforms, to email systems. Each system represents a potential vulnerability where unauthorized access could occur or data could be breached.

Encryption technology provides essential protection for digital educational records. When data is encrypted, even if intercepted, it remains unreadable without the decryption key. Institutions should encrypt educational records in transit (when being transmitted between systems or accessed remotely) and at rest (when stored on servers or devices). Many institutions now require encryption as a baseline standard for any system storing FERPA-protected information. However, implementing encryption across legacy systems and multiple platforms presents technical and operational challenges, and institutions must balance security requirements with functional usability.

Access controls and authentication systems limit who can access educational records and prevent unauthorized individuals from viewing sensitive information. Systems should require strong passwords, multi-factor authentication for sensitive system access, and role-based access controls limiting records visibility to staff with legitimate need. A financial aid counselor shouldn’t be able to access disciplinary records. A registrar shouldn’t have visibility to mental health counseling notes. Access should be granular enough to support job responsibilities without providing unnecessary visibility to unrelated information.

Third-party vendor relationships create significant FERPA compliance challenges. Colleges increasingly contract with external vendors to manage student data through cloud storage, learning management systems, data analytics platforms, and other specialized services. These vendors require access to educational records to provide their services. However, vendors themselves may lack FERPA expertise or appropriate data security measures, creating vulnerability. FERPA compliance is the institution’s responsibility, not the vendor’s, even when data is stored with external parties. Institutions must thoroughly vet vendors before contracting, require data use agreements specifying FERPA compliance obligations, conduct regular audits of vendor data security practices, and maintain awareness of where student data is stored and who has access.

Some vendors pursue specific FERPA certifications or compliance certifications from third parties. The Vendor Family Data Privacy Certification, offered through SchoolStatus and other organizations, involves third-party assessment of vendor practices against FERPA and other privacy standards. While certification provides some assurance, institutions cannot rely solely on vendor certifications; they must conduct independent due diligence before entrusting student records to external parties.

Social media and technology-facilitated information sharing create new FERPA vulnerabilities. Faculty members may photograph students or classroom activities and share on personal social media accounts. Students may post images of classmates or discussions from classes. Institutions struggle to control information sharing when technology enables easy dissemination. While FERPA applies to institutional records, not personally created content, institutions increasingly incorporate social media and technology-use policies into FERPA education, helping community members understand privacy implications of technology-enabled sharing.

Data breach notification represents an emerging FERPA-related challenge. When institutions experience security incidents potentially exposing educational records, they must notify affected individuals and the Department of Education. Institutions should develop incident response plans specifying how to discover breaches, investigate scope, notify affected individuals, remediate vulnerabilities, and coordinate with federal authorities. Most states require notification of breaches involving personal information, and FERPA adds educational record protections. Institutions unable to respond effectively to data breaches face public relations damage, potential legal liability, and federal investigation.

Higher education institutions must navigate multiple overlapping privacy laws and regulations beyond FERPA. Understanding how FERPA relates to HIPAA, GDPR, state privacy laws, and other regulations is essential for comprehensive data protection.

HIPAA (Health Insurance Portability and Accountability Act) creates privacy protections for protected health information held by covered entities and business associates. Campus health centers and counseling services operated by institutions may function as HIPAA-covered entities if they provide health services. When HIPAA applies, it may provide greater privacy protections than FERPA. For example, HIPAA includes specific protections for psychotherapy notes that FERPA does not explicitly protect. When both FERPA and HIPAA apply, institutions must comply with the more restrictive law. Determining when HIPAA applies versus FERPA creates complexity, as the same institution may have some operations governed by HIPAA and others governed by FERPA.

GDPR (General Data Regulation) creates stringent privacy requirements for personal data of European Union residents, including EU students studying in the United States. If a U.S. institution serves EU students, GDPR may apply to those students’ personal data. GDPR requires explicit consent for data processing, provides enhanced data subject rights, requires data protection impact assessments, and mandates notification of data breaches. GDPR protections exceed FERPA protections in many respects. Institutions with significant international enrollment must implement GDPR-compliant processes, which may include creating separate data handling procedures for students subject to GDPR.

State privacy laws increasingly create requirements exceeding FERPA. California’s Consumer Privacy Act (CCPA) and similar state laws grant residents the right to know what data companies collect, delete personal information, and opt out of sale. Virginia’s Consumer Data Protection Act, Colorado’s Privacy Act, and emerging privacy laws in other states create overlapping requirements. Institutions must track applicable state laws for students’ home states and implement compliant practices. In many cases, implementing compliant practices for the most stringent jurisdiction may be simpler than creating state-specific procedures.

The Children’s Online Privacy Protection Act (COPPA) creates specific protections for online privacy of children under 13. While higher education students rarely fall under COPPA, institutions offering online K-12 services or maintaining data about younger individuals must comply. Similarly, the Gramm-Leach-Bliley Act creates financial privacy protections applicable when institutions handle financial information, and the Telephone Consumer Protection Act restricts how institutions can contact students via phone.

State open records laws create tension with FERPA. Many states have public records laws requiring government entities to disclose records upon request. However, FERPA exempts educational records from disclosure under public records laws. Institutions must balance public access principles with FERPA privacy protections, often declining public records requests for information qualifying as educational records while releasing other institutional information.

Common FERPA Violations and How to Avoid Them

Understanding common FERPA violations helps institutions strengthen compliance and avoid federal enforcement action. The Department of Education publishes investigation summaries detailing violations institutions have committed, providing valuable guidance on practices to avoid.

Unauthorized disclosure represents the most common category of FERPA violations. Institutions disclose educational records without proper authorization through various mechanisms. A parent calls and asks about their adult child’s academic standing, and a staff member provides information without verifying consent. An instructor emails a student’s family member about grades without authorization. A residence life coordinator shares disciplinary information with a roommate to explain a student’s absence. A clerical error causes educational records to be mailed to the wrong person. These incidents all constitute unauthorized disclosure, even when the disclosure is inadvertent or well-intentioned.

Failing to provide record access represents another category of violations. Students request to review their records, and institutions delay providing access beyond the reasonable timeframe or deny access without justification. Some institutions charge excessive fees for copying records. Some provide incomplete records or refuse access to certain record types. These failures violate students’ basic FERPA rights and may indicate institutional confusion about obligations.

The Bottom Line

Failing to maintain adequate security for educational records creates vulnerability to breaches and potential FERPA violations. Institutions with inadequate access controls allowing staff to view records unrelated to their work, with unencrypted systems storing educational data, with outdated systems vulnerable to hacking, or with unclear policies on data retention may face federal scrutiny if breaches occur. The Department of Education increasingly focuses on institutional cybersecurity practices as part of FERPA oversight.

Refusing reasonable amendment requests represents a less common but serious violation. When a student requests to correct an inaccuracy in their records, institutions must respond substantively. Some institutions reflexively refuse all amendment requests, claiming records reflect accurate information while refusing to engage with student concerns. Proper