Skip to main content
All posts

FERPA and WCAG Compliance: What Colleges Should Demand From Equipment Checkout Software

Zeckout Team September 16, 2026

Your checkout system knows things

Who borrowed the camera. Their name, their email, their student ID. What they took, when it's due back, and whether they returned it on time. The moment a department starts logging that information, its checkout software is handling student records — and that puts the software squarely in FERPA territory.

Most departments don't pick equipment checkout software with that in mind. They compare features, price, and ease of use. But if the system tracks students — and any checkout system worth using does — then data privacy and accessibility compliance belong on the requirements list from day one.

Here's what FERPA and WCAG actually mean for equipment checkout software, what colleges should demand from any vendor, and where Zeckout stands.

Why equipment checkout software is a FERPA issue

FERPA — the Family Educational Rights and Privacy Act — governs how schools handle student education records. It applies to virtually every college and university that receives federal funding, and it covers far more than transcripts. A checkout log that ties a student's name, email, and ID to equipment they borrowed is an education record under FERPA.

Here's the part that surprises people: FERPA binds the institution, not the vendor. But when your department loads student data into a third-party system, your institution is responsible for how that vendor handles it. That's why colleges require a Data Processing Agreement (DPA) with any vendor that touches student data. A DPA formalizes the vendor's obligations in writing: who owns the data, how it can be used, who can access it, what happens in a breach, and what happens to the data when the contract ends.

If a checkout software vendor can't or won't sign a DPA, that's a signal to stop the evaluation — regardless of how good the features look.

What to demand on the data side

  • A FERPA-ready DPA, signed before any student data is loaded
  • Clear data ownership: the school's data stays the school's data
  • Role-based access controls, so staff only see records relevant to their department
  • No selling or secondary use of student data — spelled out in writing, not promised verbally
  • Defined breach notification commitments with timelines

WCAG 2.2: accessibility is a legal requirement, not a nice-to-have

FERPA protects student privacy. WCAG — the Web Content Accessibility Guidelines — protects access. WCAG 2.2 is the current version of the standard that defines how digital products must work for people using screen readers, keyboard navigation, and other assistive technologies.

This is not optional for colleges. Under Title II of the ADA, the Department of Justice's 2024 rule requires public entities — including public colleges and universities — to make their web content and mobile apps conform to WCAG, with compliance deadlines that began in 2026. Private institutions face similar obligations under Section 504 and the ADA. When a student browses gear, books a reservation, or checks out a laptop through your department's checkout system, that system is part of the institution's digital footprint — and its accessibility is the institution's responsibility.

Two things colleges often miss:

First, the compliance obligation follows the tool, not the vendor. If the checkout portal is inaccessible, the vendor's "not our problem" doesn't protect the institution when a complaint arrives. The college chose the tool; the college owns the outcome.

Second, there is no official WCAG certification. WCAG conformance is established through testing — internal, third-party, or both — and documented in an accessibility conformance report. Any vendor who claims to be "WCAG certified" is either confused or overselling. The right questions are: which WCAG version do you build to, how do you test, and can you show me the results?

What to demand on the accessibility side

  • Built to WCAG 2.2 (or at minimum, WCAG 2.1 Level AA)
  • Regular testing, including assistive technology like screen readers and keyboard-only navigation
  • Honest, specific answers about conformance documentation
  • A way to report accessibility issues and a commitment to fix them

Questions to ask any vendor before you sign

Bring this checklist to your next evaluation call:

  1. Will you sign our FERPA DPA before we load any student data?
  2. Who owns the data in your system, and what happens to it if we leave?
  3. Do you sell or use student data for any secondary purpose?
  4. What are your breach notification commitments?
  5. Which WCAG version do you build to, and how do you test for conformance?
  6. Can you provide accessibility documentation or a conformance report?
  7. How do you handle accessibility bug reports, and what's your fix timeline?

A vendor who answers these clearly — including where they're still working on things — is a vendor you can build a compliant program on. A vendor who waves the questions away is a risk your institution doesn't need.

Where Zeckout stands

Zeckout was built for colleges and universities first — its earliest deployments were in real higher-ed departments running student checkout at scale. Student data and accessibility weren't retrofits; they were part of the original design brief. Here's our status, stated plainly:

  • FERPA: Zeckout offers a FERPA Data Processing Agreement to any institution — it's available on our website. Student checkout data belongs to the institution: no selling, no secondary use, period.
  • WCAG 2.2: Zeckout has been built to WCAG 2.2 standards and audited against them as part of our development process. We have not yet completed a formal third-party accessibility audit, and we won't claim one. If your institution needs documentation, ask — we'll tell you exactly where things stand and put our commitments in writing.

We'd rather be the vendor with honest answers than the one with a claim it can't back up. Ask every vendor — including us — the same questions, and pick the one that gives you straight answers.

The bottom line

Equipment checkout software for schools isn't just a convenience tool — it's a system that holds student records and sits inside your institution's legal footprint. FERPA compliance starts with a signed DPA. Accessibility compliance starts with software built and tested to WCAG 2.2. Demand both from every vendor you evaluate, in writing, before you sign anything.

Get started free at zeckout.app — and ask us about our FERPA DPA before you load a single student record.

Are you ready to try Zeckout?

Ditch the spreadsheets and paper forms — get your department's inventory organized in minutes.