Is it safe? A teacher's guide to AI and student data
Most teachers I meet are not reckless with AI — they are worried, and rightly so. The good news: staying on the right side of data protection does not require a law degree. It requires knowing which rules apply to you, and three habits applied without exception.
The rules that matter, in one minute
- In the UK, learner information is personal data under UK GDPR, and the Department for Education expects schools to know where data goes when staff use generative AI. Safeguarding duties apply online exactly as they do in the corridor.
- In the US, FERPA protects education records, and COPPA restricts what online services may collect from children under 13. Many districts also keep an approved-tools list — if a tool is not on it, that is your answer.
- Everywhere: the moment a learner can be identified from what you typed, you have shared personal data with a third party. The question is never "is the tool famous?" but "has my school approved this use?".
The three habits that keep you compliant
1. Anonymise before you type. Describe situations, never people. "A 7-year-old reader who confuses b and d" gives the AI everything it needs; a name, a photo or a full record gives it things it must never have. Changing the first name is not anonymisation — patterns identify children too.
2. Use approved tools for anything near learners. Your personal account on a free tool has not signed an agreement with your school; the school's licensed version usually has. When in doubt, ask who holds the contract — one email to your data lead settles it.
3. Keep AI out of protection decisions. Safeguarding concerns, special-needs decisions, and anything about a child's welfare follow your school's human procedures, immediately and without an AI intermediary. AI can draft a worksheet; it must never assess a disclosure.
Never paste into an AI tool: names with any other detail, photos or recordings of learners, medical or family information, behaviour or safeguarding notes, full academic records, or login credentials. No exceptions, including "just this once to save time".
What you can do freely
Everything that contains no personal data: drafting lessons and quizzes, levelling texts, generating examples, rephrasing your own writing, preparing parent-meeting talking points described in general terms. That is most of the value, with none of the risk.
Five quick scenarios: can I…?
- "Can I paste an anonymised student essay to get feedback ideas?" Yes, if truly anonymised: no name, no school, no details that identify the writer. Better still, retype the two paragraphs you want help with rather than uploading the scanned original, which may carry a name in the header or metadata.
- "Can I ask AI to draft comments from my grade spreadsheet?" Not by uploading the spreadsheet — that is a full academic record. Describe the profile instead: "a student strong in analysis but weak in structure, who improved this term". One profile at a time, no names.
- "Can I use AI to write a behaviour plan for a specific child?" Draft generic strategies for a described situation, yes. But the plan for that child — with their history and context — belongs in your school's human procedures, not in a chatbot.
- "Can I generate images of my class for the school newsletter?" Never upload photos of learners to a generative tool. Generate generic illustrations instead, and follow your school's image-consent policy for real photos.
- "Can I let students use AI in class?" That is a curriculum and policy question for your school — but if the answer is yes, the same data rules apply to them: accounts, ages (many tools require 13+), and what they are allowed to type about themselves and others.
What to ask your school (one email)
If your school has no visible AI policy, one message to your data lead or headteacher unblocks everything: "Which AI tools are approved for staff use? Is there a data agreement behind our licensed tools? And where should I direct questions about learner data and AI?" You are not asking permission to think — you are asking who holds the contracts. If the answer is "we don't know yet", suggest starting from the Department for Education guidance (UK) or your district's instructional-technology office (US). Schools move faster when a teacher asks a precise question.
Frequently asked questions
Can teachers use ChatGPT with student data? Not with identifiable student data on a personal account. The moment a learner can be identified from what you typed, you have shared personal data with a third party. Describe situations, never people, and use only tools your school has approved.
Does changing a student's name make the data safe? No. Swapping the first name is not anonymisation — a combination of age, class, diagnosis or family details can still identify a child. True anonymisation means describing the situation generically.
What do GDPR and FERPA actually require of me? Practically: know whether your school has approved the tool and the use. UK GDPR treats learner information as personal data; FERPA protects US education records; COPPA restricts collection from under-13s. Your data lead handles the legal machinery — your job is the three habits above.
One-page rule for your desk: No names. Approved tools only. Humans decide anything that matters about a child. Print it, and AI becomes a colleague you can trust with the photocopying — not the register.
How solid are your AI-ethics reflexes? The free diagnostic includes real classroom scenarios on data and safeguarding — see where you stand in 12 minutes.
Take the free diagnostic