FERPA and GDPR in a multi-tenant cloud: what auditors ask
The specific questions institutional counsel and auditors raise about shared-infrastructure SIS platforms, and the documentation that answers each one.
Key takeaways
- Tenant isolation must be demonstrable, not asserted
- Disclosure logging is the control auditors test most often
- GDPR data subject requests need tooling, not a process document
- Legitimate educational interest should be enforced by field-level permissions
Tenant isolation questions
Auditors rarely accept "logically separated" as an answer. Be ready to show the enforcement point — how a query for one institution cannot return another’s rows — and the test evidence that proves it.
Ask any vendor for their penetration test summary, their tenant isolation test methodology, and their SOC 2 Type II report covering the relevant period.
Disclosure logging
Under FERPA, the obligation to record disclosures is the control most often tested and most often failed, because in legacy environments the log is a paper form. A system-generated log of every access to a student record, queryable by student and by staff member, converts a scramble into a five-minute report.
- Who accessed the record and when
- Which fields were viewed or exported
- The stated legitimate educational interest
- Retention of the log independent of the record
GDPR for institutions with UK and EU students
Data subject access, rectification and erasure requests need tooling that assembles a complete response across modules, including documents and communication logs. Manual assembly across five systems is where institutions miss statutory deadlines.
