A student AI privacy review should establish what information a tool collects, why it collects it, who can access it, how long it retains it, and whether it uses student data for model training, advertising, or other purposes. The review should account for distinct federal rules, including FERPA and COPPA, as well as state requirements and district policies.

The U.S. Department of Education’s August 2026 guidance asks schools and providers to consider what learning problem a tool addresses, who should use it and for how long, and what evidence shows that it improves learning. The need is pressing: in CoSN’s 2024 survey, 45% of responding district leaders identified student-data privacy as a concern about AI use, while 54% said their districts had no AI-use policy.

Key Takeaways

  • A student AI privacy review should document the prompts, files, chat histories, direct and indirect identifiers a tool collects, why the provider uses them, who can access them, how long the information is retained, how deletion works, and whether student data supports model training, advertising, or other purposes.
  • Districts should weigh privacy practices alongside educational value by naming the learning problem, intended users and duration, and evidence of benefit, as the U.S. Department of Education’s August 2026 guidance recommends; CoSN’s 2024 survey found that 45% of responding district leaders identified student-data privacy as a concern about AI use and 54% said their districts had no AI-use policy.
  • FERPA and COPPA address different requirements: FERPA’s school-official exception requires a contracted vendor to remain under the school’s direct control and use education-record information only for the disclosed purpose, while COPPA generally requires verifiable parental consent for covered services collecting, using, or disclosing personal information from children under 13.
  • Districts should assess security, access permissions, incident response, subcontractors, records-request handling, and deletion at contract end; March 2025 reporting described almost 3,500 sensitive, unredacted student documents exposed through a records request involving Vancouver Public Schools’ surveillance technology, not an incident shown to have been caused by AI.
  • Before a pilot begins, districts should request written vendor answers, compare those answers with contracts and applicable rules, define what learning evidence would justify continued use, tell students and caregivers where to ask questions or seek an available alternative, and pause the pilot if key answers remain unclear; Ohio districts should also check the state’s 90-day return-or-destroy rule for covered records after certain contracts expire and its July 1, 2026 AI-policy deadline.

New Federal Guidance Puts AI Reviews in Context

The Department’s guidance is a framework for evaluating a tool, not a verdict on AI. It neither endorses every classroom product nor calls for a blanket ban. Its significance lies in connecting technology choices to educational value and appropriate limits, rather than treating adoption as an automatic response to new technology. The Department sets out this approach in its guidance.

CoSN’s 2024 district leadership survey offers a snapshot of the policy environment surrounding the federal guidance. Its findings show that concerns about student data and gaps in district AI policies are connected challenges for school leaders.

For districts, a tool’s educational value and privacy practices belong in the same adoption discussion. A possible learning benefit does not, by itself, show that a tool’s data practices align with a district’s commitments. Likewise, concern about AI does not mean every classroom use should be rejected. Schools can recognize potential value while still asking for evidence and setting clear boundaries around use.

What A Student AI Privacy Review Checks

A useful student AI privacy review begins with a clear inventory of the information a tool collects. Ask whether it receives prompts, uploaded files, chat histories, direct identifiers such as names or student ID numbers, and indirect identifiers that could identify a student when combined with other data. The U.S. Department of Education’s Student Privacy Policy Office includes both kinds of identifiers in its definition of personally identifiable information in education records.

Purpose matters as much as collection. Ask what the provider may do with student information, whether it may use that information to train models or for advertising, and whether it may use the information for other purposes. A school should compare the answers with the tool’s actual classroom use, rather than relying on a public-facing privacy notice alone.

A review should also ask:

  • Who can see student information, including provider staff and other parties?
  • How long is information retained, and how can the school request its deletion?
  • What happens to the information when the contract ends?
  • What do the contract and access controls permit in practice?

Security and procurement practices belong in the same review as AI-specific data use. Clear privacy language is useful, but it does not answer every question about access, retention, deletion, or the school’s responsibilities.

FERPA And COPPA Ask Different Questions

FERPA and COPPA ask different questions, so districts should not treat compliance with one as a substitute for reviewing the other. Under FERPA’s school-official exception, a school may disclose education-record information to a contracted vendor performing a function the school would otherwise perform, provided the vendor remains under the school’s direct control and uses the information only for the disclosed purpose. District privacy or legal staff can assess whether a specific vendor relationship meets those conditions.

COPPA focuses on covered online services that collect, use, or disclose personal information from children under 13. The Federal Trade Commission generally requires verifiable parental consent for those practices. District staff can use the FTC’s COPPA frequently asked questions to assess whether a service and its particular use fall under COPPA, and whether school authorization is appropriate.

In January 2025, the FTC finalized COPPA amendments addressing separate parental opt-in for covered third-party disclosures, limits on data retention, and biometric identifiers. State laws and district policies may add requirements, too. Qualified district privacy or legal staff should check current federal, state, and local rules for the students and tools involved. No single rule necessarily covers every student or AI service. The FTC’s announcement describes the amendments.

Privacy Review Must Include Security

A student AI privacy review should examine the security and records-handling systems surrounding a tool, not only what its model does. In March 2025, the Associated Press and The Seattle Times reported that a records request involving Vancouver Public Schools’ surveillance technology exposed almost 3,500 sensitive, unredacted student documents. The reporting describes a records-handling exposure, not evidence that AI itself caused it.

Procurement provides context, too. The Associated Press reported a 2024 contract price of $328,036 for Vancouver Public Schools’ Gaggle student-monitoring service over three school years. That figure describes this contract, not a typical price.

Districts can ask who has access permissions, how incidents are handled, who reviews and redacts records-request disclosures, which subcontractors can access student data, and how vendors securely delete data when contracts end. NIST’s voluntary AI Risk Management Framework 1.0 offers an organizing structure: Govern, Map, Measure, and Manage.

Give Students A Clear Developmental Explanation

Monitoring can affect students’ feelings about privacy and trust in school, but reactions vary. A student’s questions or discomfort do not, by themselves, indicate wrongdoing or conflict at home.

Lisa Damour, PhD provides practical, research-backed guidance for families and educators navigating the emotional and developmental challenges of tweens and teens. Her contribution to a student AI privacy discussion focuses on adolescent development and communication, not technical privacy or legal evaluation of a product.

Students benefit from age-appropriate explanations of a tool’s purpose, what information it handles and how that information is used, its limits, and any available alternatives. Schools can also give families a clear contact for questions, helping students and caregivers understand the tool without dismissing ordinary privacy concerns.

What Districts Should Do Next

Before adopting a tool, districts should document the learning problem, intended users, duration of use, evidence of benefit, data practices, and contract protections. This record can support a decision to adopt, limit, or reject the tool. Districts can revisit the decision when the product, its terms, or applicable rules change.

State rules can add duties. Ohio generally requires providers to return or destroy covered education records within 90 days after certain contracts expire, unless renewal is reasonably anticipated. Ohio also sets state and district AI-policy milestones, including a district policy deadline of July 1, 2026.

Families can ask how students may raise questions or access an alternative when appropriate. School AI governance is still developing, which makes transparent reviews and regular policy updates especially important.

What Districts Should Do Next

At the next procurement meeting, name a district lead to oversee the review and set a decision date before a pilot begins. Ask the vendor to answer in writing whether prompts or student files are used for model training, which subcontractors can access them, and how deletion is confirmed when the agreement ends. Have privacy or legal staff compare the answers with the contract and applicable state requirements, and ask the instructional team to identify what learning evidence would justify continued use.

Then tell students and caregivers where to direct questions and how to request an available alternative. If a vendor cannot provide clear answers, pause the pilot until the district resolves the gap. For help framing conversations with students and families, explore Lisa Damour, PhD’s “Why Teenagers Reject Parents’ Solutions to Their Problems.”