Can Schools Use Generative AI Tools Under UK GDPR?

Written by Data Protection People

Understand what schools need to know about GDPR compliance when using generative AI and how to keep pupil and parent data safe.

Are generative AI tools GDPR compliant for use in schools graphic

Generative AI tools like ChatGPT, Microsoft Copilot and Gemini can be used in schools under UK GDPR if used safely and effectively, with appropriate data protection policies in place.

To remain GDPR-compliant, schools should avoid using free versions of generative AI tools, as they may lack the necessary safety features. Instead, schools should use enterprise tools integrated into a broader workspace of educational tools, such as Copilot in Microsoft 365 or Gemini in Google Workspace.

What Data Risks Do Generative AI Tools Present in Schools?

Generative AI tools themselves don’t pose data protection risks; the risks depend on how they are used. These include:

  • Data Breaches – If staff members paste sensitive data into AI tools without notifying parents and pupils that their data will be used in this way, it may constitute a data breach.
  • GDPR Compliance Risks – Many AI tools are operated by US companies, so without data residency controls, personal data may be processed and stored outside the UK, creating GDPR compliance risks.
  • Intellectual Property – When a student completes a piece of work, the intellectual property belongs to them. Submitting this work to a free generative AI tool for feedback could result in the data being used to improve the AI’s systems, potentially raising issues regarding intellectual property rights and data protection compliance.

What Data Protection Policies Should Schools Follow When Using Generative AI Tools?

Consult a Data Protection Officer

Before using generative AI for any activity, schools should consult their appointed Data Protection Officer (DPO). A DPO can review the chosen AI tool(s), ensure that appropriate data policies are in place and advise staff on how to use them effectively.

Carry Out a DPIA

The ICO requires a Data Protection Impact Assessment (DPIA) before using AI in high-risk processing activities, including any use of AI involving children’s personal data. A DPIA should outline how the data is processed and its purpose, assess necessity and identify and mitigate risks.

Be Transparent About Data

Government advice recommends that personal data not be used in generative AI tools in educational settings.

If it is necessary for schools to use personal data in AI tools, they must:

  • Be open and transparent about how they are considering using automation and AI
  • Ensure that pupils, parents and guardians understand that their personal data is being processed using AI
  • Seek consent to use data within AI

Use The Right Tools

Government advice further recommends that staff members only use AI tools provided by their institution. This is likely to include:

  • Microsoft Copilot under a Microsoft 365 for Education licence
  • Gemini under a Google Workspace for Education licence

These paid tools keep data within a managed school environment, don’t use data to train public AI models and respect existing security and privacy controls.

Provide Data Protection Training to Staff

Data protection training can help staff understand UK GDPR compliance and what constitutes a data breach. Staff must understand what data should never be entered into AI tools and which AI platforms are approved for work use.

Ensure Your School Is GDPR Compliant with Data Protection People

Generative AI can transform education, but it must be balanced with the responsibility to protect personal data and meet GDPR requirements.

At Data Protection People, we have extensive experience working with the education sector and can help schools implement generative AI securely. From outsourced DPO services to ongoing data protection advice, we can ensure your use of AI is compliant. Contact us today to understand how we can support you.