How Senturo Supports FERPA-Compliant Device Tracking for Schools

August 11, 2026
August 12, 2026
Explore how Senturo supports FERPA-compliant device recovery with hidden location data, role-based access, dual approval, and security controls.
No items found.

Senturo provides technical controls for K-12 device tracking that support a district's FERPA compliance program by limiting when device location becomes visible, who can access student-linked recovery information, and which staff members can take security actions. 

A missing laptop, tablet, or other school-owned device creates two risks for a district: the loss of a valuable asset and the potential exposure of information stored on the device.

Recovering the device may require access to location data, screenshots, network information, or activity connected to its assigned user. When a device is assigned to an individual student, that information may be sensitive.

Senturo supports a privacy-conscious recovery process by controlling:

  • When device location is visible
  • Who can access location and recovery information
  • Who can mark a device as missing
  • Which staff members can lock, wipe, or message devices
  • Whether location access requires approval from a second administrator
  • Which security protections continue operating while location is hidden

What FERPA Means for School Device Tracking

The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of student education records.

Device information may be protected by FERPA if a school links it to a specific student in its records.

That information may include:

  • Device location and location history
  • Screenshots collected during a recovery investigation
  • Network and IP information
  • Notes associated with the device
  • Device assignment records
  • Missing-device reports
  • Security actions and recovery records

FERPA permits access to personally identifiable information from education records when a school official has a legitimate educational interest. Schools must also use reasonable methods to ensure officials receive access only to the education records for which they have that interest.

For device recovery, districts should define:

  1. The circumstances that justify accessing device information
  2. The staff members who need the information for an assigned responsibility
  3. The actions those staff members may take
  4. The approval and review procedures that apply
  5. The point at which enhanced tracking and access should end

Senturo's location privacy settings, role-based permissions, approval workflows, security modes, and Audit Log can help districts apply those decisions through technical controls.

Three Ways to Control Location Visibility in Senturo

Senturo's privacy-first geotracking gives schools three options for controlling when location information becomes visible.

1. Always View Location

With Always View Location, device location is continuously available to users whose assigned roles include location access.

This option may be appropriate for shared device carts, loaner fleets, equipment that must remain on campus, or programs with a documented operational requirement for ongoing visibility. 

Role permissions continue to determine which users can view location and location history.

2. Privacy by Default

With privacy by default, Senturo collects the location information required for device protection while keeping it hidden from administrators during normal use.

When the device is marked as missing, Senturo reveals its last known location and location history to authorized users.

Privacy by Default Workflow

  1. The device operates normally with location hidden.
  2. The device is reported lost or stolen.
  3. An authorized user or security automation places it into Missing Mode.
  4. Location becomes available to roles with location permission.
  5. Authorized staff investigate and take recovery actions.
  6. The device returns to Secure Mode after the incident is resolved and locations get hidden.

This configuration preserves recovery options while limiting routine access to student-linked location information.

3. Dual-Admin Approval

With Dual-Admin Approval, the location remains hidden until two authorized administrators participate in the access request.

Dual-Admin Approval Workflow

  1. One administrator requests location access.
  2. A second administrator reviews the request.
  3. The second administrator approves or rejects it.
  4. Location becomes visible after approval.

This option adds separation of duties and can be useful for districts that require supervisory review, documented approval, or stronger governance for sensitive investigations.

Senturo configures privacy levels at the organization level. Changes are handled by the Senturo team through the platform's backend rather than through an in-app setting. This prevents an individual administrator from changing the district's overall location-privacy configuration independently.

Device Protection Continues While Location Is Hidden

Privacy by Default and Dual-Admin Approval control when administrators can see location data. Senturo's background security protections can continue to operate while the location remains hidden.

Across all three privacy levels, Senturo can continue using:

  • Geofencing to detect devices entering or leaving defined areas
  • IP fencing to identify connections from unauthorized networks
  • Agent Phone Home policies to identify devices that have stopped communicating
  • Security automations to trigger alerts, messages, locks, wipes, or changes in security status

A geofence violation does not have to immediately expose location. The associated policy could notify the IT team, send a message to the device, lock it, or place it in Missing Mode.

Under Privacy by Default, location becomes visible when the device enters Missing Mode. Security Policy Automations can activate Missing Mode in response to conditions such as a geofence violation or an extended offline period.

How Roles Control Location Access and Device Recovery

The district's privacy level determines when location can become visible. Senturo's roles and permissions determine who can view that information and what each user can do during an incident.

A user whose role includes access to locations still follows the organization's selected privacy workflow. Under Privacy by Default, for example, location remains hidden until the device enters Missing Mode.

Privacy and device-recovery permissions by Senturo user role. Owner, Group Admin, and Admin share full access to every permission listed.
Permission Owner, Group Admin, Admin Helpdesk Investigator Analyst Broadcaster Remote
View location and history when available Yes Yes Yes Yes No No
Mark a device as Missing Yes Yes Yes No No No
View screenshots, network info, and notes Yes Yes Yes Yes No No
Request data or run Automation Pulse Yes Yes Yes No No No
Lock devices Yes Yes Yes No No Yes
View Security Policies Yes No Yes Yes No No
Manage Security Policies Yes No No No No No
View Audit Log Yes Yes Yes Yes No No
View broadcasts Yes Yes Yes Yes Yes No
Create and send broadcasts Yes Yes Yes No Yes No

These permissions allow districts to separate monitoring, investigation, recovery, messaging, and policy-management responsibilities. 

Permission by Roles Workflows

  • An Analyst can review available location, screenshots, network information, notes, policies, and Audit Log activity without receiving authority to mark a device as missing, request updated data, lock it, or wipe it.
  • A Broadcaster can use broadcast messaging for emergency messages, device-return instructions, testing reminders, and other communications without receiving access to location or investigation information.
  • A Remote user can perform selected lock or wipe actions without receiving access to location or investigation information.

Secure Mode and Missing Mode

Senturo uses Secure Mode for normal device operations and Missing Mode for active recovery

In Secure Mode, devices report location at standard tracking intervals. In Missing Mode, location reporting increases to real-time updates. Screenshots can also be collected automatically on supported Windows, macOS, and ChromeOS devices if configured.

Missing Mode is used when a device is lost or stolen, leaves a geofence unexpectedly, or requires a time-sensitive recovery investigation. After the device is recovered or the investigation is complete, an authorized user can mark the device as secured.

Device action compatibility by platform varies across Android, ChromeOS, iOS, macOS, and Windows. Administrators can also use Senturo Lock and Senturo Wipe where supported.

Building a Privacy-Conscious Device-Recovery Process

Senturo provides technical controls for location visibility, permissions, security actions, and administrative review. Each district determines how those controls fit into its FERPA, privacy, security, and device-recovery procedures.

Choose the appropriate location setting

Determine whether the district requires continuous visibility, incident-based visibility, or dual approval. 

Define when a device may enter Missing Mode

Document the events that justify enhanced tracking. These may include:

  • A student or parent reports the device missing
  • IT confirms that the device has stopped checking in
  • The device leaves an approved geofence
  • The device connects through an unauthorized network
  • The district opens a documented recovery or security investigation

Assign roles based on staff responsibilities

Access should match each person's assigned work. Communications personnel can use the Broadcaster role. Monitoring staff can use Analyst. Support staff responsible for active recovery can use Helpdesk. Investigators can obtain visibility and recovery controls without gaining policy management access.

Security Policy management remains limited to the Owner, Group Admin, and Admin roles. User and role management remains limited to the Owner and Group Admin.

Document approval, review, and incident closure

Districts should define who may request location access, who may approve it, what information must support the request, how urgent cases are handled, and how actions will be reviewed. Districts should audit information to investigate unexpected activity and verify that staff followed the approved recovery process.

Districts should also establish documented procedures for data retention and destruction of device location and recovery information. Senturo's tracking data storage and retention policy explains the platform's default retention periods and available deletion options.

Frequently Asked Questions

What is FERPA-compliant device tracking?

FERPA-compliant device tracking is an approach to device location and recovery that limits access to student-linked information based on a defined purpose, staff responsibilities, district policies, and appropriate administrative oversight.

Senturo can support this approach through privacy controls, role-based permissions, approval workflows, and audit records. The district remains responsible for configuring and using those controls within its compliance program.

Does FERPA allow schools to track school-owned devices?

FERPA does not prohibit schools from using technology to locate school-owned devices. Its requirements may apply when the resulting records are directly related to a student and maintained by the school or a party acting on its behalf.

Districts should define the purpose for accessing the location, limit access to authorized staff, document recovery procedures, and consider any additional state law, contractual, and local policy requirements.

Can Senturo hide device location during normal use?

Yes. With Privacy by Default, Senturo collects location information while keeping it hidden from administrators during normal operations. Location becomes available to authorized users after the device enters Missing Mode.

Does geofencing work while location is hidden?

Yes. Geofencing, IP fencing, agent phone-home policies, and automated security actions continue operating across all three privacy levels.

Can a geofence place a device into Missing Mode?

Yes. A Security Policy Automation can activate Missing Mode based on conditions such as a geofence violation or an extended offline period.

Who can access device location or mark a device as missing?

Owner, Group Admin, Admin, Helpdesk, Investigator, and Analyst users can view location history when the organization's privacy level allows it. Owner, Group Admin, Admin, Helpdesk, and Investigator users can change a device's security status.

Broadcaster and Remote users cannot view location. Analyst, Broadcaster, and Remote users cannot mark a device as missing.

Can Senturo require two people to approve access to a location?

Yes. With Dual-Admin Approval, one administrator requests access and a second administrator must approve it before location is revealed.

Can staff perform security actions without viewing location?

Yes. The Remote role can perform selected lock, wipe, MDM, grouping, and tagging actions without receiving access to location or investigation information.

Björn Hall, Co-Founder & CEO @ Senturo

Björn Hall is an experienced software entrepreneur in mobile security fleet management. As Co-Founder & CEO, he has led Senturo’s evolution into a powerful enterprise solution, delivering advanced geo-tracking, compliance automation, and security enforcement across macOS, Windows, iOS, Android, and Chrome OS. More about Björn