12 Privacy Questions to Answer Before You Touch Student Data
The privacy and security items to check before adopting an AI tool, gathered into a checklist a classroom teacher can actually use.
AI learning tools handle students' names, answers, learning patterns, and sometimes their voices and faces. Rush to sign up because the convenience is appealing, and you end up in a situation where nobody can say where the student data went. Thirty minutes of checking before adoption prevents one incident. When a parent asks, "we didn't check" is not an answer that protects the school.
The 12 items to confirm before adopting
Do this with the contract and the privacy policy open in front of you, not the vendor's sales deck. Trust only the sentences written in the documents, not a sales rep's verbal assurance.
- Scope of collection: what fields are collected? Does it stay within the bare minimum the lesson requires? If it asks for faces or location data, demand a reason.
- Where data is stored: is the data on domestic servers, or does it go abroad? If it leaves the country, confirm which country and whether the consent process is in place.
- Retention period: when is it destroyed after graduation or account deletion? Is there automatic deletion? If it says "retained indefinitely," treat that as a red flag.
- Use for AI training: are student inputs reused to train the vendor's model? Is there a way to opt out? Student answers becoming training data for an outside model is especially sensitive.
- Third-party sharing: who are the sub-processors (cloud providers, analytics vendors)? Confirm that data is not flowing somewhere you do not know about.
- Access rights: at your school, who can see how much? Excessive permissions raise the risk of an internal leak.
The remaining six items are the consent process, guardian consent for students under 14, proof of destruction, breach notification obligations, whether data is encrypted in transit, and a guarantee that data is returned or deleted when the contract ends. Guardian consent for students under 14 in particular becomes the central issue, so make a point of raising it for any elementary adoption.
Keep the review on a single page
If you checked but kept no record, it is the same as not having checked.
- Write the items above out as sentences rather than a table, and note the review date and the name of the person who did it.
- For anything that falls short, put the question to the vendor in writing and keep the reply. One email can settle where responsibility lies later on.
- Review again at the start of each school year. A vendor's policy may have quietly changed.
Privacy protection is less an exam you pass once than a license you renew every year.
Common mistakes when collecting consent
- The blanket consent trap: lumped-together consent such as "I agree to all uses of data" is easily voided in a dispute. Break it out item by item.
- No right to decline: explain the alternative that lets a student who does not consent still take part in the lesson.
- Too little explanation: spell out what is being consented to in language families can follow.
Key takeaways
Even with a good tool, if it cannot explain its data flows, it is safer to put adoption on hold. Get clear answers on just three things, minimal collection, where and how long data is held, and whether it is reused for AI training, and you cut half the risk. Turn the checklist into a shared school document and apply it identically to every adoption.

Be the first to comment.