AI for teachers

Student Data Privacy for AI Teaching Tools: A Practical Teacher Checklist

AI teaching tools can reduce repetitive work, but they also create new decisions about what student information is shared, who can access it, and how long it remains available. Use this checklist to ask better questions before adopting an AI tool in a classroom, tutoring practice, or education business.

A teacher reviewing an AI privacy checklist beside a laptop and anonymised student work documents, with a small lock symbol in a classroom workspace.

AI teaching tools can help educators draft resources, organise feedback workflows, and reduce repetitive administrative tasks. But convenience should not become a reason to share more student information than a task genuinely requires. Before using an AI-enabled platform with learners, teachers, tutors, and education businesses need a clear process for assessing student data privacy.

This is not only a technical issue. It is a teaching decision. The information entered into a tool may affect learners' privacy, trust, participation, and willingness to take academic risks. A sensible approach starts with a simple principle: use the least student information needed to achieve a clearly defined educational purpose.

The checklist below is designed to support practical conversations with school leaders, data-protection colleagues, parents or guardians where appropriate, and software vendors. It does not replace an organisation's policies, contracts, or legal advice. Requirements can vary by location, learner age, institution, and the type of information involved.

Start with the educational purpose

Before comparing privacy settings or reading a vendor's terms, define why the tool is being considered. A precise purpose makes it easier to decide whether student data are necessary at all.

  • What teaching problem are we trying to solve? For example, are you trying to create practice questions, structure feedback, support lesson planning, or help students revise?
  • Can the same outcome be achieved without identifiable student data? A teacher may be able to use an invented example, an anonymised extract, or a class-level pattern instead of a named student's work.
  • Which users need access? Distinguish between teachers, students, tutors, administrators, parents, and external support staff.
  • What is the minimum information required? Avoid collecting names, dates of birth, contact details, account identifiers, or full learning histories merely because a tool accepts them.

Write the purpose in one or two sentences. If the purpose cannot be stated plainly, the data use is unlikely to be easy to explain to students and families. It may also indicate that the proposed workflow needs redesigning.

Checklist 1: Minimise the data before it enters the tool

Data minimisation means limiting information to what is relevant for the stated task. In everyday teaching, this often begins with changing habits at the point of entry.

  • Use a student code, initials approved by your organisation, or a temporary label rather than a full name where practical.
  • Remove direct identifiers from pasted work, screenshots, documents, and filenames.
  • Do not include personal contact details, login credentials, family information, or unrelated behaviour notes.
  • Use short extracts when a full assignment is unnecessary for the task.
  • Consider whether the same teaching question can be asked with a synthetic or composite example.
  • Check whether metadata may reveal more than expected, such as author names, comments, document histories, or image location information.

Minimisation is especially important when educators use general-purpose AI tools. A prompt that says, “Give feedback on this Year 8 essay” may require less personal information than a prompt containing a student's name, school, learning profile, attendance history, and full work folder.

Useful habit: Before submitting anything, pause and ask: “Would the tool still help if I removed this detail?” If the answer is yes, remove it.

Checklist 2: Identify sensitive or high-risk information

Not all educational information carries the same level of risk. Some details may be particularly personal, confidential, or harmful if mishandled. Build a clear escalation route for cases involving information that your organisation treats as sensitive or restricted.

Examples may include detailed support plans, health-related information, safeguarding concerns, disciplinary records, financial information, identity documents, or information about a learner's family circumstances. Even when an AI tool appears useful, these materials should not be uploaded informally or used in an unapproved workflow.

Ask the following questions:

  • Does the material include information beyond academic performance?
  • Could an individual be identified from context even if their name is removed?
  • Would the learner, parent, or guardian reasonably expect this information to be handled only by specific staff?
  • Does the proposed use need approval from a designated school or business lead?

When in doubt, stop the upload and seek guidance through your organisation's established process. It is usually easier to select a safer workflow before data are shared than to resolve uncertainty afterwards.

Checklist 3: Make consent and communication meaningful

“Consent” is often used as a shorthand for permission, but a responsible privacy process requires more than a checkbox. Teachers should understand what their organisation expects before relying on consent as the basis for a tool's use. In some settings, an institution may use another documented basis or follow a specific policy instead.

Whatever process applies, communication should be understandable. Students and families should be able to grasp what tool is being used, what information is involved, why it is needed, who may access it, and what alternatives exist if participation is not appropriate or possible.

  • Use plain language rather than technical descriptions alone.
  • Explain the educational purpose and the limits of the activity.
  • State whether students are expected to create accounts or submit work directly.
  • Provide an approved non-AI or low-data alternative where your organisation requires one or where it is educationally appropriate.
  • Keep a record of the communication and any permissions or decisions required by your organisation.

Teachers should avoid making informal promises about privacy that they cannot verify. Instead of saying, “Your data is completely private,” explain the approved process and direct questions to the person or team responsible for privacy decisions.

Checklist 4: Ask how long information is retained

Retention is the question of how long information remains stored or accessible. It matters because a tool can be low-risk for a brief, controlled activity but less suitable for building a long-term record of individual learners.

Before adoption, ask whether the platform stores prompts, uploads, generated outputs, account data, usage records, or backups. Then ask whether teachers or administrators can delete records, whether deletion applies across connected systems, and whether the vendor describes any exceptions.

Retention questionWhy it matters
What information is stored?You cannot manage retention well without knowing what is retained.
How long is it kept?A clear timeframe supports informed decisions and internal record-keeping.
Who can request deletion?Teachers need to know whether they, an administrator, or the vendor controls removal.
What happens when an account closes?Closure may not automatically mean all associated information disappears.
Can users export relevant records?Access to records can support continuity, review, and appropriate handover.

A practical classroom rule is to avoid treating a conversational AI history as the official record of learning. Keep required assessment records, feedback records, and student work in the approved systems your school or business has chosen for those purposes.

Checklist 5: Control access, accounts, and sharing

Privacy depends not only on what a vendor does, but also on how people use the tool. A platform with sensible settings can still create avoidable exposure if accounts are shared, permissions are too broad, or work is pasted into the wrong space.

  • Use organisation-approved accounts rather than personal accounts when available and required.
  • Do not share passwords or allow students to work through a staff member's account.
  • Check who can view a class space, uploaded files, prompts, and generated feedback.
  • Review whether student work is visible to other students by default.
  • Remove access for people who no longer need it, such as departed staff or completed cohorts.
  • Use the strongest sign-in and account-security practices required by your organisation.

Access is also an equity question. If a tool requires an account, device, email address, or home internet connection, consider whether every learner can participate fairly. A privacy-conscious implementation should not pressure students to use personal accounts or disclose information they would not otherwise need to share.

Checklist 6: Ask vendors clear, practical questions

Vendor documentation can be dense. The goal is not for every teacher to become a contract specialist; it is to ask questions that help an authorised decision-maker assess the tool. Record the answers, note the date checked, and ask for clarification when language is vague.

  1. What categories of student and teacher data does the product collect?
  2. Is identifiable student information necessary for the intended classroom workflow?
  3. Where can we find the product's privacy information, terms, and education-specific documentation?
  4. Who can access submitted content and account information?
  5. Does the vendor use submitted content to improve, test, or develop its services?
  6. What choices or controls are available to our organisation?
  7. How are data retained, exported, corrected, and deleted?
  8. Does the vendor use other service providers to process information, and how is that communicated?
  9. What security and incident-response information can the vendor provide to authorised reviewers?
  10. What support is available if a teacher, student, or parent raises a data question?

Watch for answers that are broad but not specific to education use. A statement that a product “values privacy” is not a substitute for clear information about data categories, access, retention, controls, and the intended use of submitted content.

Create a repeatable approval workflow

A checklist is most useful when it becomes part of a repeatable process rather than a one-time exercise. Schools and education businesses can use a short intake form for proposed tools, including the teaching purpose, expected users, data categories, alternatives considered, required approvals, vendor answers, and a review date.

Teachers should not be left to make high-impact privacy decisions alone. A good workflow assigns responsibilities: educators define the learning need, an authorised reviewer checks policy and vendor information, leaders decide whether and how the tool may be used, and staff receive practical guidance for implementation.

SubSchool is designed to automate repetitive teaching work while teachers retain authorship and the final educational decision. As with any teaching workflow, consider what learner information is actually needed before introducing it into a digital process, and use your organisation's approved privacy and access procedures. To learn more about SubSchool's approach, visit our About page.


A final teacher-ready privacy check

Before using an AI teaching tool with student information, confirm that you can answer these five questions:

  1. What specific educational purpose does this use serve?
  2. What is the minimum information needed?
  3. Who can access the information and outputs?
  4. How long will the information remain available, and how can it be removed?
  5. Has the proposed use been checked through the appropriate school or business process?

If any answer is unclear, do not fill the gap with assumptions. Use a smaller-data workflow, seek approval, or choose a different method. Careful privacy practice does not prevent thoughtful use of AI in education; it helps ensure that teaching convenience remains aligned with student trust.

Sources and methodology

{'approach': "Reviewed the draft as untrusted text and selected a small set of primary U.S. government sources that directly address student-data privacy, online educational services, vendor terms, children's online privacy, FERPA, and AI implementation in education.", 'source_selection': ['Prioritized official U.S. Department of Education and Federal Trade Commission materials over vendor, blog, or secondary commentary.', 'Selected sources that support reusable checklist themes rather than trying to source every operational example individually.', 'Excluded product-specific claims about SubSchool because no authoritative SubSchool privacy, security, retention, or data-processing documentation was supplied or independently verified.', 'Treated legal applicability as jurisdiction- and context-dependent; the evidence pack is U.S.-focused and is not legal advice.'], 'coverage_limit': 'The sources support a cautious pre-adoption workflow for school or district contexts. They do not establish that every recommendation applies identically to private tutors, education businesses, higher-education providers, non-U.S. institutions, or every AI product.'}

  1. Protecting Student Privacy While Using Online Educational Services: Requirements and Best Practices
  2. Protecting Student Privacy While Using Online Educational Services: Model Terms of Service
  3. Policy Statement of the Federal Trade Commission on Education Technology and the Children's Online Privacy Protection Act
  4. FERPA: 34 CFR Part 99—Family Educational Rights and Privacy
  5. Empowering Education Leaders: A Toolkit for Safe, Ethical, and Equitable AI Integration
Put the idea to work

Related tool, workflow, and guide

Free toolAI lesson plan generator

Draft an objective, teaching sequence, practice, and exit check.

Product workflowAI course creator

Turn approved sources into editable course entities.

Guide hubPractical teaching guides

Use complete, reviewable workflows rather than isolated prompts.

Continue with the next teaching step

Use the relevant SubSchool workflow while keeping the result editable and teacher-reviewed.

Open workflow →
SubSchool Editorial Team