Regulation explainerEducation

Student data privacy rules for AI tutors and learning analytics

Before an AI tutor, writing assistant or analytics tool touches student records, the institution and vendor each need to know which laws apply, who decides how the data is used and what the contract must say. This guide maps FERPA, COPPA, UK GDPR and the Children's code, EU GDPR, the EU AI Act and California's SOPIPA to those roles, then to design controls.

Reviewed 8 min read

On this page
  1. Who answers for student data: institution, vendor and sub-processors
  2. Institution, vendor and model provider duties side by side
  3. Six legal instruments that can apply to an AI learning tool
  4. Rules and dates that have moved recently
  5. Design controls that make an AI tutor defensible
  6. When a vendor's plans move a tool under stricter rules
  7. A university pilots an AI writing tutor
  8. Questions and answers
  9. Sources

Who answers for student data: institution, vendor and sub-processors

Student privacy law mostly regulates the institution. FERPA binds schools and universities that receive funds under US Department of Education programs; GDPR binds whoever decides why and how personal data is processed. Vendors inherit duties directly when they act on their own account, and through the contract when they act for the institution.

AI tools add a chain: institution, edtech vendor and the model providers or hosts behind it. Each link must be named and bound by terms at least as strict as the one above. The decisive question is who sets the purposes. A vendor that only delivers the requested service acts for the institution; one that also uses student data to train models or market is making its own decisions, and stricter rules apply.

Institution, vendor and model provider duties side by side

DutyInstitutionAI vendorModel provider or host
Decide purposes and lawful basisSets the educational purpose and approves each useOnly for its own purposes, which carry their own obligationsNone for student data; confirm it in writing
Contract termsData privacy agreement with the vendorThe same terms flowed down to each sub-processorLimits on training, retention and data location
Access and deletion requestsReceives and decides on themExports and deletes within agreed timesDeletes on the vendor's instruction
Breach notificationInforms families or regulators as the law requiresInforms the institution promptlyInforms the vendor promptly

Under GDPR one vendor can be a processor for some activities and a controller for others; the contract's label does not decide which.

Rules and dates that have moved recently

Design controls that make an AI tutor defensible

These controls turn the obligations above into product requirements. Build them into tools you develop and ask for them in tools you buy.

0 of 7 checked

When a vendor's plans move a tool under stricter rules

These situations most often shift an AI tool from one regime into a stricter one, usually after the first contract is signed.

  • If

    The vendor wants to use student work to improve its models.

    Then

    Treat it as a separate purpose: explicit institutional opt-in and de-identification meeting FERPA's standard, without relying on school consent under COPPA.

    School consent does not reach commercial purposes, and in the UK the vendor becomes a controller for that processing48.

  • If

    The tool will score graded essays or tests for students in the EU.

    Then

    Plan for high-risk obligations: provider documentation, deployer oversight, logging and notice to students.

    Evaluating learning outcomes is listed in Annex III.

  • If

    A proctoring feature infers stress or emotion from webcam video.

    Then

    Remove the inference for EU deployments and review the rest as high-risk test monitoring.

    Emotion recognition in education is prohibited; detecting prohibited behavior during tests is high-risk.

  • If

    A district offers to share directory information instead of signing a school-official agreement.

    Then

    Decline; use the school-official route with a contract, or obtain consent.

    Directory information is narrow, families can opt out of it and it gives no control over the vendor's use.

A university pilots an AI writing tutor

Questions and answers

Is an AI vendor a school official under FERPA?

It can be. The institution must have outsourced a function its own staff would otherwise perform, keep direct control over how the vendor uses and maintains the records, and bind the vendor to FERPA's redisclosure limits. A vendor using student data for its own purposes, such as training general models, falls outside that arrangement.

Can a school consent under COPPA on behalf of parents for an AI tool?

Under the FTC's existing guidance, yes, but only where the operator collects children's data for the use and benefit of the school and no other commercial purpose, and gives the school the notice parents would otherwise receive. The amended rule does not codify this. Commercial uses such as model training or advertising need consent from parents themselves.

Can an edtech vendor train its AI model on student data?

Only with clear authority, and rarely on identifiable data. In the US that usually means records de-identified to FERPA's standard and a contract permitting the use; school consent under COPPA does not cover it. In the UK and EU, training for the vendor's own products makes it a controller for that processing, needing its own lawful basis and transparency.

Does the EU AI Act ban AI proctoring?

Not outright. Systems that detect prohibited behavior during tests are high-risk, so they need provider documentation, conformity assessment, human oversight and logging, and students must be informed. Emotion recognition in education institutions is banned outside medical or safety reasons, so features that infer stress or attention from faces or voices cannot be used in the EU.

Sources

  1. 34 CFR § 99.31: Under what conditions is prior consent not required to disclose information? — Legal Information Institute, Cornell Law School · checked 10 October 2026
  2. 34 CFR § 99.3: What definitions apply to these regulations? — Legal Information Institute, Cornell Law School · checked 10 October 2026
  3. Children's Online Privacy Protection Rule, final rule (Federal Register, April 22, 2025) — Federal Trade Commission · checked 10 October 2026
  4. Complying with COPPA: Frequently Asked Questions (section N, COPPA and schools) — Federal Trade Commission · checked 10 October 2026
  5. 16 CFR § 312.5: Parental consent — Legal Information Institute, Cornell Law School · checked 10 October 2026
  6. 16 CFR § 312.8: Confidentiality, security, and integrity of personal information collected from children — Legal Information Institute, Cornell Law School · checked 10 October 2026
  7. 16 CFR § 312.10: Data retention and deletion requirements — Legal Information Institute, Cornell Law School · checked 10 October 2026
  8. The Children's code and education technologies (edtech) — Information Commissioner's Office · checked 10 October 2026
  9. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
  10. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
  11. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI) — EUR-Lex · checked 10 October 2026
  12. California Business and Professions Code § 22584 (Student Online Personal Information Protection Act) — California Legislative Information · checked 10 October 2026

More in Education

Back to Education

Next step

Have an AI tool's student data terms reviewed before you sign

Send the vendor's data processing terms and a short description of the feature. We will map which instruments apply, flag terms that conflict with them and list the design controls to ask for.

Request a privacy review