I have to look at a school system that is using "man in the middle" SSL / TLS decryption for the traffic from a K12 school. This allows the firewall (and who knows who else) to intercept and read traffic that I assume students believe to be private. I've not yet asked for the legal report to see what notification is given to students, parents and so forth and what approval there has been from the legal department. Maybe all the ducks are in a row, maybe they are not. I don't know.
But as a starting point, is anyone familiar with the legality around this? In most situations in the US you can legally do this with employees if they are notified. Then you are free and clear. But students are not employees, in any sense. Nor are they voluntary system users. What legal problems should I be worried about here? Is this normal and no one can sue us if they find out? What if there is a breach of student private communications caused by a mistake by IT or a vendor bug?