Regulation explainerEducation
Student data privacy rules for AI tutors and learning analytics
Before an AI tutor, writing assistant or analytics tool touches student records, the institution and vendor each need to know which laws apply, who decides how the data is used and what the contract must say. This guide maps FERPA, COPPA, UK GDPR and the Children's code, EU GDPR, the EU AI Act and California's SOPIPA to those roles, then to design controls.
On this page
- Who answers for student data: institution, vendor and sub-processors
- Institution, vendor and model provider duties side by side
- Six legal instruments that can apply to an AI learning tool
- Rules and dates that have moved recently
- Design controls that make an AI tutor defensible
- When a vendor's plans move a tool under stricter rules
- A university pilots an AI writing tutor
- Questions and answers
- Sources
Who answers for student data: institution, vendor and sub-processors
Student privacy law mostly regulates the institution. FERPA binds schools and universities that receive funds under US Department of Education programs; GDPR binds whoever decides why and how personal data is processed. Vendors inherit duties directly when they act on their own account, and through the contract when they act for the institution.
AI tools add a chain: institution, edtech vendor and the model providers or hosts behind it. Each link must be named and bound by terms at least as strict as the one above. The decisive question is who sets the purposes. A vendor that only delivers the requested service acts for the institution; one that also uses student data to train models or market is making its own decisions, and stricter rules apply.
Institution, vendor and model provider duties side by side
| Duty | Institution | AI vendor | Model provider or host |
|---|---|---|---|
| Decide purposes and lawful basis | Sets the educational purpose and approves each use | Only for its own purposes, which carry their own obligations | None for student data; confirm it in writing |
| Contract terms | Data privacy agreement with the vendor | The same terms flowed down to each sub-processor | Limits on training, retention and data location |
| Access and deletion requests | Receives and decides on them | Exports and deletes within agreed times | Deletes on the vendor's instruction |
| Breach notification | Informs families or regulators as the law requires | Informs the institution promptly | Informs the vendor promptly |
Under GDPR one vendor can be a processor for some activities and a controller for others; the contract's label does not decide which.
Six legal instruments that can apply to an AI learning tool
Which apply depends on where learners are, their ages and what the tool does. Check the current text before relying on any summary.
Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99)
United StatesApplies whenThe institution receives US Department of Education program funds and the tool uses personally identifiable information from education records1.
- A vendor may receive records without consent as a school official only if it performs a function staff would otherwise perform, stays under the institution's direct control over the records and follows the redisclosure limits1.
- Access must be limited to records in which the official has a legitimate educational interest1.
- Rights pass from parents to an eligible student: one who has reached 18 or attends a postsecondary institution2.
Children's Online Privacy Protection Rule (16 CFR Part 312)
United StatesApplies whenA service is directed to children under 13, or the operator knows it collects personal information from a child under 133.
- Verifiable parental consent; under FTC guidance a school may consent instead only where data serves the school and no other commercial purpose4.
- Separate parental consent for disclosures to third parties not integral to the service5.
- A written security program and a written retention policy; children's data may not be kept indefinitely67.
- Most amended provisions became mandatory on April 22, 20263.
UK GDPR, the Data Protection Act and the Age appropriate design code (Children's code)
United KingdomApplies whenThe tool processes UK learners' personal data; the code covers online services likely to be accessed by children, including direct-to-consumer edtech8.
EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679)
European Union and EEAApplies whenThe tool processes personal data of learners in the EU, or the provider or institution is established there9.
Artificial Intelligence Act (Regulation (EU) 2024/1689), as amended by Regulation (EU) 2026/1744
European UnionApplies whenAn AI system is placed on the EU market or used in the EU; Annex III lists admission, evaluating learning outcomes, assessing the appropriate level of education and detecting prohibited behavior during tests10.
- Emotion recognition in education institutions is prohibited under Article 5, except for medical or safety reasons10.
- High-risk providers need risk management, documentation, logging, human oversight and conformity assessment; deployers assign oversight, keep logs and inform students10.
- Stand-alone Annex III obligations now apply from December 2, 2027 instead of August 2, 202611.
Student Online Personal Information Protection Act (Cal. Bus. & Prof. Code § 22584)
California, United StatesApplies whenAn operator knows its service is used primarily for K–12 school purposes and was designed and marketed for them12.
Rules and dates that have moved recently
Design controls that make an AI tutor defensible
These controls turn the obligations above into product requirements. Build them into tools you develop and ask for them in tools you buy.
When a vendor's plans move a tool under stricter rules
These situations most often shift an AI tool from one regime into a stricter one, usually after the first contract is signed.
- If
The vendor wants to use student work to improve its models.
- If
The tool will score graded essays or tests for students in the EU.
ThenPlan for high-risk obligations: provider documentation, deployer oversight, logging and notice to students.
Evaluating learning outcomes is listed in Annex III.
- If
A proctoring feature infers stress or emotion from webcam video.
ThenRemove the inference for EU deployments and review the rest as high-risk test monitoring.
Emotion recognition in education is prohibited; detecting prohibited behavior during tests is high-risk.
- If
A district offers to share directory information instead of signing a school-official agreement.
ThenDecline; use the school-official route with a contract, or obtain consent.
Directory information is narrow, families can opt out of it and it gives no control over the vendor's use.
A university pilots an AI writing tutor
Questions and answers
Is an AI vendor a school official under FERPA?
It can be. The institution must have outsourced a function its own staff would otherwise perform, keep direct control over how the vendor uses and maintains the records, and bind the vendor to FERPA's redisclosure limits. A vendor using student data for its own purposes, such as training general models, falls outside that arrangement.
Can a school consent under COPPA on behalf of parents for an AI tool?
Under the FTC's existing guidance, yes, but only where the operator collects children's data for the use and benefit of the school and no other commercial purpose, and gives the school the notice parents would otherwise receive. The amended rule does not codify this. Commercial uses such as model training or advertising need consent from parents themselves.
Can an edtech vendor train its AI model on student data?
Only with clear authority, and rarely on identifiable data. In the US that usually means records de-identified to FERPA's standard and a contract permitting the use; school consent under COPPA does not cover it. In the UK and EU, training for the vendor's own products makes it a controller for that processing, needing its own lawful basis and transparency.
Does the EU AI Act ban AI proctoring?
Not outright. Systems that detect prohibited behavior during tests are high-risk, so they need provider documentation, conformity assessment, human oversight and logging, and students must be informed. Emotion recognition in education institutions is banned outside medical or safety reasons, so features that infer stress or attention from faces or voices cannot be used in the EU.
Sources
- 34 CFR § 99.31: Under what conditions is prior consent not required to disclose information? — Legal Information Institute, Cornell Law School · checked 10 October 2026
- 34 CFR § 99.3: What definitions apply to these regulations? — Legal Information Institute, Cornell Law School · checked 10 October 2026
- Children's Online Privacy Protection Rule, final rule (Federal Register, April 22, 2025) — Federal Trade Commission · checked 10 October 2026
- Complying with COPPA: Frequently Asked Questions (section N, COPPA and schools) — Federal Trade Commission · checked 10 October 2026
- 16 CFR § 312.5: Parental consent — Legal Information Institute, Cornell Law School · checked 10 October 2026
- 16 CFR § 312.8: Confidentiality, security, and integrity of personal information collected from children — Legal Information Institute, Cornell Law School · checked 10 October 2026
- 16 CFR § 312.10: Data retention and deletion requirements — Legal Information Institute, Cornell Law School · checked 10 October 2026
- The Children's code and education technologies (edtech) — Information Commissioner's Office · checked 10 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI) — EUR-Lex · checked 10 October 2026
- California Business and Professions Code § 22584 (Student Online Personal Information Protection Act) — California Legislative Information · checked 10 October 2026