Colleges and universities across the country are experiencing a significant uptick in public records requests from commercial entities whose primary purpose is to harvest institutional data for resale, targeted marketing, or the assertion of False Claims Act claims against schools. Known as “data farming,” this practice exploits state freedom of information, right-to-know, and open records laws to extract valuable procurement, personnel, and operational information from educational institutions at scale. As artificial intelligence (AI) tools make it easier to generate and file these requests, institutions should expect the volume and sophistication of data farming to increase.

What is data farming?

Data farming refers to the systematic, large-scale filing of public records requests by commercial entities seeking to collect and aggregate institutional data for profit. Unlike traditional public records requests filed by journalists, researchers, or concerned citizens, data farming operations are designed to extract specific categories of commercially valuable information – particularly vendor contracts, pricing structures, procurement data, and employee contact information – across dozens or hundreds of institutions simultaneously.

These operations typically share common characteristics. Requests are filed using identical or near-identical templates across multiple jurisdictions. The filing entities often operate under multiple brand names meant to appear as public interest organizations and use mail-forwarding addresses rather than physical offices. Multiple individuals associated with the same entity may file overlapping requests, sometimes using the same phone number or mailing address. The requests target specific, commercially valuable data categories rather than seeking general public accountability information.

Why is data farming increasing?

The volume of public records requests has reached unprecedented levels.

Several factors are driving this increase:

  • Commercialization of public data. A growing industry of data aggregators has recognized that public records laws provide free or low-cost access to valuable institutional data. Procurement records reveal what institutions pay for software, services, and supplies – intelligence that competitors, vendors, and investors find highly valuable. Employee rosters provide ready-made marketing lists for the supplemental benefits industry.
  • Low barriers to filing. Most state public records laws do not restrict who may file a request or for what purpose. As the Pennsylvania Office of Open Records has noted, agencies generally “cannot limit the number of records which may be requested.” This requester-friendly framework, designed to promote government transparency, also enables commercial exploitation.
  • AI and automation. AI is transforming the public records landscape on both sides of the equation. For requesters, AI-assisted tools make it easier to draft stronger, more precisely targeted requests and to generate hundreds or thousands of requests simultaneously. Large language model companies are also seeking government data for AI training purposes, potentially submitting Freedom of Information Act requests for copyright-free datasets. The number of requests is only set to increase as AI enables automated and repeated requests.
  • Crowdsourced expertise. Online communities and AI tools now help requesters craft more targeted requests and more effectively challenge agency responses, further increasing the volume and tenacity of data farming operations.

Key considerations for private institutions

Private colleges and universities are generally not subject to state public records laws. These statutes typically apply to “public agencies,” “governmental bodies,” or specifically enumerated entities – categories that do not include private, nonprofit educational institutions. For example, the Pennsylvania Right-to-Know Law (RTKL) applies to Commonwealth, local, judicial, and legislative agencies. The Pennsylvania Office of Open Records FAQ explicitly states that “[p]rivate universities and colleges are not subject to the RTKL.”

However, private institutions should be aware of narrow exceptions. In Pennsylvania, for instance, specifically enumerated “state-related” institutions may be subject to limited disclosure obligations. Additionally, records related to government contracts or government-funded programs may be subject to disclosure regardless of an institution’s private status.

Despite having no legal obligation to comply, private institutions that receive data farming requests should not ignore the trend entirely. Institutions should, in consultation with counsel:

  • Verify the institution’s status under applicable state law to confirm no disclosure obligation exists;
  • Develop a written protocol for receiving, routing, and determining whether and how to respond to public records requests;
  • Understand that responding to or acknowledging a request that the institution is not legally required to fulfill may invite additional requests from the same entity or others; and
  • Educate relevant campus stakeholders – including the registrar’s office, procurement, information technology, and the president’s office – so that requests are not inadvertently answered by uninformed staff.

Key considerations for public institutions

Public colleges and universities face a more complex calculus. As state agencies or instrumentalities, they are generally subject to their state’s public records law and must respond to valid requests within statutory timeframes. However, many of these laws also provide tools that institutions can use to manage the burden of data farming while meeting their legal obligations.

Public institutions should consider the following strategies, in consultation with counsel:

  • Establish a centralized intake process. Streamline the receipt, tracking, and coordination of responses to all public records requests to prevent ad hoc responses by uninformed staff and ensure consistent responses.
  • Train staff to recognize data farming patterns. Train employees responsible for responding to public records requests on the red flags that indicate data farming attempts.
  • Assert applicable exemptions. Institutions and their counsel should evaluate each request against available exemptions in their state public records laws before producing responsive documents.
  • Use request-narrowing tools. Some states allow agencies to characterize requests as “voluminous” or “unduly burdensome” and require the requester to narrow the scope. Where available, institutions should not hesitate to invoke these provisions for data farming requests that seek years of data across multiple broad categories.
  • Understand fee structures. Many public records laws allow agencies to charge fees for search, review, and duplication. Some states are considering legislation to increase fees specifically to discourage nuisance requests. Work with counsel to understand these options in your state.
  • Review vendor contracts. Examine existing vendor agreements for confidentiality provisions that may limit or prohibit disclosure of pricing terms and other commercial information. Where such provisions exist, institutions should evaluate with counsel whether they have a right or an obligation to withhold that information from public records responses.
  • Consider proactive disclosure. Some institutions have found that proactively publishing certain categories of non-sensitive information can reduce the volume of incoming requests by satisfying legitimate transparency interests without exposing commercially sensitive data. Engage with institutional stakeholders and counsel to evaluate whether proactive disclosure could strengthen your institutional response infrastructure.

Practical steps for all institutions

Regardless of whether an institution is public or private, there are actions colleges and universities can take now, in consultation with counsel, to prepare for the continued growth of data farming:

  • Educate campus stakeholders. Ensure that key offices understand what data farming is and who is responsible for responding to these requests at your institution.
  • Create a centralized response process. Establish clear internal procedures so that all public records requests – regardless of which office receives them – are funneled to a single point of contact with the training and authority to respond appropriately.
  • Protect private data. Institutions should work with counsel to ensure statutorily protected private student and employee data is not inadvertently disclosed in response to a broad public records request.
  • Adopt or update policies on mailing lists. Where state law allows, many public universities have policies explicitly refusing to provide mailing lists or mailing labels to organizations outside the university. Institutions should review their state public records laws with counsel and consider adopting such policies where allowed.
  • Monitor for AI-generated requests. As AI tools become more sophisticated, data farming requests will become harder to identify by template language alone. Institutions should monitor for unusual patterns in requests that may indicate data farming.
  • Engage counsel proactively. Before disclosing commercially sensitive procurement data or employee information in response to a public records request, institutions should consult with counsel to evaluate applicable exemptions, assess potential risks to vendor relationships, and ensure compliance with contractual confidentiality obligations.

Schools should work closely with counsel to stay informed and proactive as they face increasing data farming activity. As always, the Reed Smith Higher Education team is willing and able to assist.

Client Alert 2026-147

Related Insights