Approving Tools: Data Processing, Age Limits and Contracts
Understanding Data Processing Requirements
Schools must carefully evaluate any AI tool before implementation to ensure proper data processing practices. The General Data Protection Regulation and UK GDPR require that all data processing activities have a lawful basis. When considering AI tools, staff should identify what personal data will be collected, how it will be processed, and who will have access to it. For example, a spelling correction tool might collect student writing samples, which would be considered personal data under data protection laws.
The data controller responsibility lies with the school, not the AI tool provider. Schools must conduct data protection impact assessments for high-risk processing activities. This involves documenting what data is being processed, why it is needed, and what safeguards are in place. A school using an AI chatbot for student support must consider whether the tool collects names, academic records, or behavioural data that could identify individual students.
The school’s data protection officer or designated staff member should review tool providers’ privacy policies and data processing agreements. These documents must clearly state how data is stored, transferred, and deleted. Schools should verify that providers have appropriate technical and organisational measures in place. For instance, if an AI tool processes student data through cloud services, staff must confirm that these services meet UK data protection standards.

Age Limits and Children’s Data Protection
The Children’s Code applies to any data processing involving children under 18. Schools must ensure that AI tools used with students meet these specific requirements. The code requires that data processing is fair, lawful, and transparent. Schools cannot simply assume that existing data protection policies apply to AI tools. Each tool must be assessed against the Children’s Code requirements.
The age of consent for data processing is 13 in the UK, though schools may have stricter internal policies. When using AI tools with younger students, staff must consider whether parental consent is required. For example, a tool that collects data through games or interactive activities for children under 13 may require explicit parental consent before use.
The Children’s Code requires that AI tools designed for children must be age-appropriate and not place children at risk. Schools should avoid tools that might collect excessive data or make decisions that significantly affect children’s rights. A tool that makes automated decisions about student performance or behaviour requires special attention. The school must ensure that such tools have appropriate safeguards and that children have the right to challenge automated decisions.
The Children’s Code also requires that data minimisation principles apply. Schools must only collect data that is necessary for the tool’s purpose. For example, an AI tool that helps with reading comprehension should not collect unrelated data such as students’ favourite colours or music preferences.
Contractual Safeguards and Legal Framework
Schools must establish clear contractual relationships with AI tool providers through data processing agreements. These agreements must specify the responsibilities of both parties regarding data protection. The school remains the data controller, and the tool provider acts as a data processor. The contract should detail how data is processed, stored, and protected.
The data processing agreement must include specific clauses required by UK data protection law. These include obligations for data security, data breach notification procedures, and data deletion requirements. Schools should ensure that providers cannot transfer data to countries without adequate data protection standards. The agreement should also specify that providers cannot use data for their own purposes or share it with third parties without explicit permission.
The contract must address the right to data portability and the right to erasure. Schools should specify how data can be transferred or deleted when the tool is no longer needed. For example, if a school decides to stop using an AI tool, the contract should detail how student data is returned or destroyed.
The contract should also include provisions for regular audits or assessments of the tool provider’s data protection practices. Schools may want to include clauses that allow for contract termination if data protection standards are not maintained. The agreement must specify that providers maintain appropriate technical and organisational measures to protect data. Schools should verify that providers have appropriate staff training and security protocols in place.
- Ensure data protection impact assessments are completed for high-risk AI tools
- Verify that AI tool providers meet Children’s Code requirements
- Establish clear data processing agreements with specific security obligations
- Confirm data minimisation principles apply to all AI tool usage
- Document all data processing activities and maintain records
