Student Data: What Leaves the Room
The most common privacy mistake in schools right now is not a breach. It is a teacher pasting a paragraph containing a child's name, year group and learning difficulty into a free chatbot in order to write a better report comment.
That is an ordinary thing to do, done for a good reason, and it is the thing to stop doing.
For comparison with workplace data collection, employee monitoring software makes the monitoring purpose explicit; student data requires a different standard and context.
This page is not legal advice. Rules differ by country, state and district and are changing quickly. What follows is how the structure works and what to ask, so you can have a sensible conversation with whoever does know.
Reviewed August 9, 2026.
For an external perspective on student digital literacy, privacy, and learning, see Student Privacy Compass.
The one rule that covers most of it
Do not put personally identifiable information about a student into a tool your school has not approved.
Names. Initials plus enough context to identify. Grades attached to a person. Behaviour records. Anything about a diagnosis, an education plan, a family situation.
You can almost always get the same help without it. "Write a report comment for a Year 9 student who has improved in written accuracy but still struggles to structure an argument" produces the same output as the version with a name in it, and nothing left the room.
Anonymise first, then ask. That single habit removes most of the exposure and costs nothing — and it applies to the report comments and feedback drafts where the temptation is strongest.
Why the tier matters more than the tool
The most useful thing to understand, because it cuts against how people talk about this.
The same product can be safe or unsafe depending on which version you are using. Consumer and free tiers commonly reserve the right to retain input and use it to improve the underlying models. Enterprise and education tiers, covered by an agreement your district signed, generally do not.
So "is ChatGPT allowed?" is the wrong question. The right one is "which tier are we on, and what does the agreement say?" A teacher signing up personally on a free tier is outside whatever protections the district negotiated, even if colleagues are using the same-named product safely.
How the structure works
Three layers, in the US context, and something structurally similar exists in most jurisdictions.
FERPA protects student education records at institutions receiving federal funding, which is effectively every public district. There is no AI exception — where a tool accesses, processes, stores or generates content based on education records, it applies. Vendors are covered indirectly through the "school official exception," formalised in a data processing agreement that binds them to using the data only for the educational purpose it was disclosed for.
COPPA governs collection of data from children under 13 by third-party services. The amended rule reached full enforcement in April 2026 and reportedly requires separate verifiable parental consent for disclosures to third parties, written retention policies, and treats biometric identifiers as personal information, with substantial per-violation penalties.
State law, and there is a great deal of it — reportedly over 130 student data privacy statutes across the states, which is why a national answer is often not an answer.
Two cautions on the sourcing. Almost all of the accessible written guidance on this is produced by companies selling compliance platforms or AI tools to schools, which does not make it wrong but does mean the framing tends toward "here is what to buy." And specifics change: verify current requirements with the FTC and your state department of education rather than from a vendor's summary, including this one.
What to ask before a tool is used with students
For your district, in writing:
Is there a signed data processing agreement? Does it explicitly prohibit using student data to train the vendor's models? What is retained, for how long, and can it be deleted on request? Who are the sub-processors — the companies behind the company? Is a SOC 2 report being offered as evidence of privacy compliance, because that demonstrates general security practice rather than compliance with education privacy law? And what happens to the data if the vendor is acquired or shuts down?
A vendor who answers these readily is a different proposition from one who sends a marketing sheet.
The equity part
Worth naming because it is not obvious.
The students described in most detail in teachers' prompts are the ones needing most adjustment: students with education plans, English learners, students with behaviour support, students in difficult family circumstances. That is exactly the population whose information is most sensitive and whose exposure carries the most consequence.
So the anonymise-first habit protects, disproportionately, the students who have the least ability to object.
What to do if you have already done it
Most teachers reading this have pasted something they should not have. It is worth being calm and practical about it.
Stop, tell whoever handles data protection, and ask about deletion — many services have a route. Do not quietly hope. A reported early mistake is administrative; an unreported one that surfaces later is something else.
And do not let embarrassment turn into a policy of silence, because the useful outcome here is that your school finds out which tools people are actually using. Most unauthorised use is not defiance; it is a teacher solving a real problem with the thing that was to hand, which usually means the approved route is missing or too slow — the same reasoning that applies to a student stuck at eleven at night.
Teaching students the same habit
They are pasting far more than you are, and nobody has told them either.
The version that works with a class: assume anything you type is stored and could be read by a stranger. Not because that is certainly true of every service, but because it is the right default and it is the habit that transfers to every service they will ever use.
Concretely: not their own full name, not other people's names, not anything about someone else's family or health, not photographs of other students. The same one-page policy is the place to say it, and it fits in two lines.
The short version
- The commonest mistake is pasting an identifiable student into a free tool for a good reason
- Anonymise first, then ask — the output is the same and nothing left the room
- The tier decides the risk, not the brand; a personal free account sits outside your district's agreement
- FERPA applies with no AI exception; the amended COPPA rule reached full enforcement in April 2026; 130+ state laws exist
- Almost all accessible guidance is vendor-produced — verify with the FTC and your state, not a summary
- The students described in most detail in prompts are those with the most to lose