Student privacy guide

Student data privacy and AI tools

The fastest privacy protection is often the simplest: do not place student information into an AI system until the school understands the service, the purpose, and the data lifecycle.

Written and reviewed September 4, 2026

Quick answer

Before a student uses an AI tool, check these questions

  • What information is collected or uploaded?
  • Is every data element necessary for the learning purpose?
  • Where is it processed, stored, and disclosed?
  • Is it used to train models, advertise, or build profiles?
  • How long is it retained, and can the school delete or export it?
  • What age terms, consent, contract, security, accessibility, and local-law requirements apply?
01

Start with data minimization

Remove names and direct identifiers, but do not assume that makes information safe. A combination of details, writing samples, images, voice, location, disability information, behavior, grades, or classroom context may still identify a learner.

Use approved systems and the minimum information needed. Synthetic or invented examples are often better for demonstrations and practice.

02

Trace the whole data lifecycle

  • Collection: typed prompts, uploads, voice, images, device data, identifiers, and usage logs.
  • Purpose: the specific educational function the information supports.
  • Processing and storage: locations, subprocessors, access controls, and cross-border transfers.
  • Secondary use: product improvement, model training, profiling, analytics, or advertising.
  • Retention and deletion: schedule, account closure, contract termination, backups, and export.
  • Incident response: notification, investigation, correction, and support after misuse or breach.
03

Understand the legal and institutional context

In the United States, FERPA, COPPA, PPRA, state student-privacy laws, contracts, and institutional promises may affect a school’s choices. Applicability depends on the institution, learner, data, service, and use. The FTC’s current COPPA guidance says a school may act as a parent’s agent in limited educational circumstances, but the service must use children’s information for the school’s benefit and not another commercial purpose.

This guide is educational information, not legal advice. Schools should confirm their obligations with responsible privacy, legal, security, procurement, and instructional leaders.

04

Give teachers and students a safe default

  • Use only school-approved AI services for school information.
  • Never enter highly sensitive student, health, counseling, disability, behavior, financial, safety, or family records into a general-purpose AI tool.
  • Do not upload another person’s image, voice, messages, or work without authority and a clear purpose.
  • Provide a non-AI path when access, consent, disability, or family expectations make it necessary.
  • Report accidental disclosure promptly; hiding it can make the harm harder to contain.

Primary sources

Continue with the official guidance.

This guide is educational information and a planning aid. Applicable law, contracts, and local policy should be reviewed by the people responsible for them.

U.S. Department of EducationPrivacy and Education TechnologyOpen source ↗Federal Trade CommissionComplying with COPPA: Frequently Asked QuestionsOpen source ↗Federal Trade Commission2025 COPPA Rule AmendmentsOpen source ↗NISTPrivacy FrameworkOpen source ↗
Written and reviewed byBrannon Fissette, Ed.D., MBA

Independent-school educator and technology leader with experience in teaching, faculty development, school operations, responsible AI, and applied educational research.

Last reviewedSeptember 4, 2026

Guidance is checked against primary sources and revised as technology, research, and institutional expectations change.

Research standards and source library →