Safe Staff Use of AI

Data protection and GDPR for schools

By Chris Calder, AI Education Consultant | Meta Pedagogy

Staff are already using AI

In most schools, staff are using AI tools without any formal guidance. Teachers are pasting student work into ChatGPT for feedback, writing reports with Copilot, generating lesson plans with Claude and using Gemini to draft parent communications. Some are using school accounts. Many are using personal subscriptions on personal devices.

This creates data protection, safeguarding and compliance risks that most schools have not addressed. The gap between what staff are doing and what the school’s policies cover is significant.

What staff must not enter into AI tools

The simplest rule is this: do not enter anything into an AI tool that identifies an individual student.

That means no student names, no assessment data linked to a named student, no behavioural notes, no SEND information, no safeguarding records and no pastoral case details. If the input could identify a specific child, it should not go into any AI tool, regardless of what the tool’s privacy policy says.

This applies to all AI tools, whether the school provides them or not. A teacher using a personal ChatGPT account on a home laptop is still processing school data if they paste in a student’s essay with their name on it.

Staff should also be cautious with any content that contains personal data about other staff members, parents or third parties. AI tools are not secure communication channels and should not be treated as filing systems for sensitive information.

Why personal subscriptions are a problem

When staff use personal AI subscriptions for school work, the school has no visibility or control over what data is being processed, no data processing agreement with the provider, no ability to audit usage and no way to respond if something goes wrong.

Most consumer AI tools include terms that allow inputs to be used for model training. That means student work, assessment comments or behavioural descriptions entered through a personal account could become part of the training data for a model used by millions of people. The teacher may not realise this. The school certainly cannot prevent it.

The solution is to provide approved AI tools through school accounts with education-specific data processing agreements. If the school has not done this, it needs to, because telling staff not to use AI while providing no alternative is a policy that will be ignored.

Where UK GDPR applies

Any processing of personal data must have a lawful basis under UK GDPR. When a teacher enters student data into an AI tool, that is data processing. The school is the data controller and is responsible for ensuring that processing is lawful, fair and transparent.

Key requirements include completing a Data Protection Impact Assessment (DPIA) where AI tools process personal data, consulting the DPO before approving new tools, ensuring the school’s privacy notice explains how AI tools are used to process personal data and confirming that approved tools have appropriate data processing agreements in place.

The Data (Use and Access) Act 2025 also applies. Schools need to ensure their data processing practices are compliant with the current statutory framework, not the version that was in place when their policies were last updated.

What acceptable use should cover for staff

Most school acceptable use policies were written before AI tools existed. They cover internet use, email, social media and mobile phones. They do not cover what a teacher can and cannot do with a generative AI tool.

An updated acceptable use policy for staff should cover which AI tools are approved for school use and where to access them, what data can and cannot be entered (with specific examples, not just general principles), whether AI-generated content must be reviewed by a human before it is used in assessment, feedback, reports or external communications, how staff should record AI use where it contributes to teaching materials, assessment or external-facing content, copyright and intellectual property expectations (staff should know that some tools’ terms allow inputs to be used for training and that copyright material should not be entered without permission) and expectations around transparency (if AI is used to generate parent communications or assessment feedback, should this be disclosed?).

AI outputs need human review

AI generates plausible content, not verified content. A lesson plan generated by AI may contain factual errors, outdated curriculum references or content that is pitched at the wrong level. Feedback generated by AI may miss what the student actually needs to work on. A report comment generated by AI may sound professional and say nothing meaningful.

Staff using AI for any school-related output should check everything before it is used. This applies to teaching materials, assessment feedback, report comments, communications with parents, policy drafts and anything else that leaves the teacher’s screen and reaches a student, parent or colleague.

The school’s position on this should be explicit: AI is a starting point, not a finished product. Every AI-generated output used in a professional context must be reviewed, edited and approved by the member of staff responsible.

KCSIE 2026 requirements

KCSIE 2026 (paragraph 12) requires all staff to understand their role in filtering and monitoring at induction. This includes understanding what filtering and monitoring systems the school uses, what the four online risk categories are (content, contact, conduct, commerce) and how to report a concern if something bypasses the filter or appears in monitoring alerts.

This requirement applies to all staff, including those who do not work directly with children. It also applies to AI tools, which must be included within the school’s filtering and monitoring review (paragraph 171).

Staff also need to understand the safeguarding implications of AI more broadly: what AI-generated imagery means under the updated nudes and semi-nudes definition, what AI companionship tools are and why they are a contact risk, and how to report AI-related safeguarding concerns to the DSL.

What your school should do

Provide approved AI tools through school accounts with education-specific data processing agreements. Write or update the acceptable use policy to cover AI, with specific guidance on what data staff can and cannot enter. Ensure your DPO has been consulted and that a DPIA has been completed where required. Train all staff on safe AI use as part of their safeguarding and induction training. Make clear that AI outputs must be reviewed before use in any professional context.

If your school needs support with AI data protection, acceptable use policies or staff training on safe AI use, book a free consultation with Meta Pedagogy.

Get In Touch

Get in touch to discuss your school’s AI strategy

admin@metapedagogy.co.uk