{"resourceId":"dfe-school-ai-data-protection-guidance","versions":[{"version":"external-5720f70db75cc4bd8af9b029f1d7158cb5855b9a849a6fc3a81b31eb867430c4","resource":{"id":"dfe-school-ai-data-protection-guidance","title":"School data guidance extends review beyond text entered into AI tools","organization":"UK Department for Education","sector":"K–12 education","geography":"England; transferable operating ideas, not U.S. legal requirements","publishedAt":"Manual published February 3, 2023; updated July 9, 2026; this section’s exact publication date unknown","publicationDate":null,"eventDate":null,"sourceName":"Generative artificial intelligence (AI) and data protection in schools","sourceLabel":"Department for Education operational guidance","sourceUrl":"https://www.gov.uk/guidance/data-protection-in-schools/generative-artificial-intelligence-ai-and-data-protection-in-schools","evidenceClass":"standards-guidance","outcomeClass":"emerging","topics":["knowledge-work","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"Guidance addresses approved tools, data-officer review, training-data use, age restrictions and transparency about metadata as well as prompts.","sledRelevance":"Interpretation: Newly added to this archive for fall 2026 district decisions. Adds staff-workflow and metadata handling detail to prior product-safety coverage.","evidence":"Its administrative example drafts a parent message without pupil identifiers, adding them afterward. It also identifies location, IP, system and browser information as potential collected data. This is guidance, not an evaluated workload intervention.","architectureImplications":"Interpretation: Separate drafting from insertion of pupil records and map both prompt content and service telemetry. Compare deployment options using actual data paths.","governanceImplications":"Interpretation: Maintain a feature-level approval record and assign a reviewer when a workflow starts using identifiable records.","securityPrivacyImplications":"Interpretation: Verify collection, retention, third-party access and training settings in technical documentation and contracts.","caveats":"The visible dates apply to the manual and do not establish when this section changed. UK obligations must not be restated as U.S. law. No effect size, baseline or evaluation sample is supplied.","streamIds":["k12"],"roles":{"sales":"Interpretation: School administrative and privacy leaders may want assistance with routine communications while controlling pupil-data exposure. Ask what records enter each step, what the supplier collects indirectly and who approves a change. A bounded workflow and data-flow review can test whether useful drafting is possible with less personal information. The value hypothesis is a clearer approval decision and manageable staff practice, not guaranteed time savings or compliance. Apply the operating questions locally; do not market UK guidance as a U.S. legal safe harbor.","engineering":"Interpretation: Prototype drafting with synthetic examples and insert identifying information only within an authorized school system. Prerequisites include an approved supplier, documented telemetry, identity controls and known retention settings. Test copy-paste mistakes, hidden identifiers and deletion behavior. Proposed proof-of-value measures are data-flow completeness, successful handling of representative requests and verified access restrictions. Choose cloud, local or hybrid hosting after reviewing the complete path; removal of names from a prompt alone cannot establish that no personal information reaches a provider.","delivery":"Interpretation: Map the administrative workflow, train staff on representative examples and assign the school office lead to approve outgoing communications. Privacy and IT owners should review vendors and changes before identifiable data is introduced. Proposed acceptance requires each collection path documented, staff completing practical handling exercises and outgoing drafts receiving human review. Check adoption and support effort after launch. Risks include accidental disclosure, unreviewed features, inaccessible outputs and treating a generic training session as lasting operational assurance."},"retrievedAt":"2026-09-11T03:01:41Z","enrichedAt":"2026-09-11T03:04:43Z","enrichmentBasis":"retrieved source","accessibilityWorkforceImplications":"Interpretation: Train staff with realistic communications examples and provide accessible alternatives for staff or families.","procurementImplications":"Interpretation: Require disclosure of telemetry and subprocessors, plus practical deletion and incident procedures.","operatingModelImplications":"Interpretation: School administration owns drafting quality; IT and privacy teams own approved data paths and periodic review.","sourceVerification":{"openedUrl":"https://www.gov.uk/guidance/data-protection-in-schools/generative-artificial-intelligence-ai-and-data-protection-in-schools","referenceExcerpt":"Some AI (artificial intelligence) tools have age restrictions.","promptVersion":"sled-research-v3.1","model":null,"basis":"agent-reported inspection"}}}]}