Skip to main content
Bookcase Pro
Guide · 15 min read

FERPA and GDPR in a multi-tenant cloud: what auditors ask

The specific questions institutional counsel and auditors raise about shared-infrastructure SIS platforms, and the documentation that answers each one.

Key takeaways

  • Tenant isolation must be demonstrable, not asserted
  • Disclosure logging is the control auditors test most often
  • GDPR data subject requests need tooling, not a process document
  • Legitimate educational interest should be enforced by field-level permissions

Tenant isolation questions

Auditors rarely accept "logically separated" as an answer. Be ready to show the enforcement point — how a query for one institution cannot return another’s rows — and the test evidence that proves it.

Ask any vendor for their penetration test summary, their tenant isolation test methodology, and their SOC 2 Type II report covering the relevant period.

Disclosure logging

Under FERPA, the obligation to record disclosures is the control most often tested and most often failed, because in legacy environments the log is a paper form. A system-generated log of every access to a student record, queryable by student and by staff member, converts a scramble into a five-minute report.

  • Who accessed the record and when
  • Which fields were viewed or exported
  • The stated legitimate educational interest
  • Retention of the log independent of the record

GDPR for institutions with UK and EU students

Data subject access, rectification and erasure requests need tooling that assembles a complete response across modules, including documents and communication logs. Manual assembly across five systems is where institutions miss statutory deadlines.

See your own records in a working pilot

Start a 14-day sandbox with sample data, or bring your enrollment profile and we will model the migration and the cost with you.

No card required · Sandbox includes all five modules · Migration is part of the platform fee