Five data protection essentials for education providers using AI
Using AI does not change an education provider’s obligations under UK data protection lawAny law, statute, declaration, decree, directive, legislative enactment, order, ordinance, regulation, rule or other binding restriction (as amended, consolidated or re-enacted from time to time) that relates to the protection of individuals with regards to the Processing of personal data.. Where an AI tool processes personal data, the UK GDPRThe UK General Data Protection Regulation. Before leaving the EU, the UK transposed the GDPR into UK law through the Data Protection Act 2018. This became the UK GDPR on 1st January 2021 when the UK formally exited the EU. and Data Protection Act 2018The Data Protection Act 2018 is a United Kingdom Act of Parliament which updates data protection laws in the UK (and supersedes the Data Protection Act 1998), and implemented the GDPR into UK legislation. apply, including updates as amended by the Data Use and Access Act 2025.
Here are five of the main areas to address when introducing or using AI tools:
1. Understand how learner data is collected and shared
Before introducing an AI tool, map the personal data that will flow into, through, and out of it. This could include learner records, prompts, uploaded documents, usage data, information inferred by the systems and its outputs.
Establish whether the data will be accessed or shared outside your organisation, including with the AI supplier, government bodies, employers or partner institutions. You should understand:
- What personal data is being processed or shared
- Why that data is needed
- Who is responsible for the data
- The lawful basis that supports the processing
- Where the data is stored and how long it is retained
Update your Record of Processing Activities (RoPA) to reflect these data flows. Where third parties are involved, put the appropriate processor contracts or data sharing agreements in place.
2. Minimise the data your AI tools process
AI tools can processA series of actions or steps taken in order to achieve a particular end. a wide range of learner information, from attendance records and assessment data to special category dataTypes of personal data listed in Article 9(1) GDPR that are considered sensitive and thus require extra protection. Article 9(1) lists data relating to: • racial or ethnic origin • political opinions • religious or philosophical beliefs • trade union membership • genetic data • biometric data • health • sex life • sexual orientation Where these types of personal....
Before deploying AI, start by asking whether personal data needs to be entered at all. The Department of Education recommends avoiding the use of personal data in generative AI tools unless it is strictly necessary. This includes names, grades or safeguarding information.
Where personal data is necessary, limit it to what the tool needs for a specific and lawful purpose. Mapping the data flow will also help you identify where additional safeguardsWhen transferring personal data to a third country, organisations must put in place appropriate safeguards to ensure the protection of personal data. Organisations should ensure that data subjects' rights will be respected and that the data subject has access to redress if they don't, and that the GDPR principles will be adhered to whilst the personal data is in the..., such as pseudonymisation, restricted access controlsA series of measures (either technical or physical) which allow personal data to be accessed on a need-to-know basis., or shorter retentionIn data protection terms, a defined period of time for which information assets are to be kept. periods, may be appropriate.
3. Be transparent about AI use
Learners have a right to understand how their information is used. If AI plays a role in how they are taught, supported, assessed or tracked, your Privacy Notices should say so.
Where AI informs decisions affecting learners, be clear that a human remains meaningfully involved and explain how outcomes can be challenged. Clear communication manages expectations and demonstrates that AI is being used responsibly.
How to update Privacy Notices for AI
4. Strengthen governance before deploying AI
Assess each AI tool before it is introduced, not once it is already processing learner or staff data. Your approval process should establish who owns the decision, what checks are required, and who will monitor the tool after launch.
Data Protection Impact Assessments (DPIAs)
Screen each proposed AI tool to determine whether a Data Protection Impact AssessmentA formal documented assessment which allows decision-makers to identify, manage and mitigate any data protection risks associated with a project. (DPIA) is needed. If the processing is likely to create a high risk to people’s rights and freedoms, you must complete a DPIA before processing begins. Where one is not needed, record your reasoning. Learn more about DPIAs
AI Impact Assessments (AIIAs)
These can sit alongside the DPIA and examine wider issues such as fairness, bias, explainability, and ethical use. It does not replace a DPIA where one is legally required. Learn more about AI Impact Assessments
Supplier checks
Your governance should also cover your suppliers. Before signing a contract, establish where data will be stored and transferred, whether it is used to train AI models, how long the data will be retained, what security and accountabilityPerhaps the most important GDPR principle, which requires controllers to take responsibility for complying with the GDPR and, document their compliance. commitments are included in the contract, and how data will be deleted once the contract ends.
Internal AI Policy
All of the above measures should be supported with a clear internal AI policy. This should set out:
- Which AI tools are approved
- What staff may use them
- What information must not be entered
- Who can approve new tools and uses
- How concerns or incidents should be reported
5. Train staff to use AI responsibly
A policy will have little effect if staff do not know how it applies to their day-to-day work. Training can help staff understand both the opportunities and risks of AI tools and should support them to:
- Recognise the privacy implications of the data they enter into AI tools
- Identify and challenge biased or unreliable outputs
- Protect personal data
- Understand when human judgement should take precedence over AI-generated responses
Training should also be practical and tailored to each role. A curriculum leader using AI for lesson planning has different needs from a data manager analysing learner outcomes, or an administrator drafting communications with AI.