Data Protection When Pupil Work Goes Into an AI Tool
Pupil data is sensitive and legally protected. This includes names, ages, attainment levels, special educational needs information, assessment scores, behavioural records, and any other information used to identify a student or reveal information about their learning. When a teacher types a student’s work, quiz responses, essay draft, or performance feedback into an external AI tool, that data leaves the school’s systems and enters the tool provider’s infrastructure. Once data leaves a school’s direct control, the legal situation changes dramatically, and schools become subject to complex data protection requirements that many have not properly addressed.
Data protection law in the UK, under the Data Protection Act 2018 and the retained EU General Data Protection Regulation (UK GDPR), treats such transfers very seriously indeed. Before any pupil data is sent to an external AI tool, the school must have a lawful basis for the processing, the student (or their parents, in the case of younger students) must have given informed consent, and the organisation receiving the data must act as a processor under a formal data processing agreement. Many teachers are completely unaware of these requirements when they casually paste an essay or quiz result into a free chatbot to get summary suggestions or feedback. The gap between what teachers do and what the law requires is significant, and it is not due to teacher negligence but to the absence of clear guidance and training from school leadership.
Why Sending Data Out Matters
When you send data to an external tool, you are transferring it outside the UK and outside the school’s data protection controls. The tool provider may retain the data indefinitely, use it to train their own AI models, share it with other organisations, or store it in countries with different legal protections and standards. Even if the provider promises confidentiality in their marketing materials, the practical risk increases substantially. Free tools like ChatGPT and Claude have terms of service that explicitly permit the company to use input data for system improvement, which means pupil work becomes part of a global dataset used to train future versions of the system. Paid enterprise versions sometimes offer different terms, but a school must check carefully.
Lawful Basis and Consent
A school must identify a lawful basis for sending pupil data to external processors. Common bases include consent from parents (for most routine school activities) or a contract to carry out education (if the tool is part of an approved curriculum). However, consent must be informed, specific, and genuine. Parents must know that AI is being used, what data is being sent, where it will be stored, how long it will be kept, and what the AI tool does with that data. Many schools send generic consent forms that do not specify AI tools or external data transfers, leaving them exposed to justified complaints that consent was not truly informed or specific enough.

Data Processing Agreements
When data is sent to an external processor, a data processing agreement (DPA) must be in place between the school and the service provider. This is a legal contract specifying precisely how data will be handled, where it will be stored, how long it will be kept, what security measures protect it, and who is responsible if something goes wrong. A DPA is non-negotiable under UK GDPR. Teachers often do not see these agreements; they remain between school leadership and vendors. Your responsibility is to check with your school’s data protection lead whether a DPA exists for any external tool you plan to use to process pupil data before you start using it.
Immediate Risk Assessment
If you currently use an external AI tool with pupil work and you are uncertain whether a DPA is in place, stop using it for sensitive data immediately and notify your school’s data protection lead. This is not a disciplinary matter; it is a legitimate governance gap that needs fixing before the school faces regulatory risk. Your school can then either establish a proper DPA with the vendor, implement technical controls such as anonymising data before it leaves school systems, or choose a different tool.
