AI in Schools: What Parents Should Know About Student Data and Consent

A parent and teenager review student-data permissions on a school tablet at their kitchen table.

INVESTIGATION | PEOPLE & RELATIONSHIPS

Schools may have legal authority to introduce some AI systems without obtaining an individual signature from every parent. That does not remove their responsibility to explain how student data is collected, used and challenged.

By Andrew McDonald · Immortal AI

Whether parental consent is legally required depends on the system, the student’s age, the data involved and the jurisdiction. Schools should still disclose the provider, purpose, data flows, retention rules and routes for challenging automated decisions.

In the United States, some education records may be shared with a contractor without individual parental consent under FERPA’s “school official” exception. For children under 13, COPPA can also allow a school to act as a parent’s agent for data collection used solely for a school-authorised educational purpose. The important question is broader than whether every parent signed a form: what was the school allowed to authorise, what controls did it retain, and what did families and students understand?

Consent is only one part of the test

Under FERPA, a contractor relying on the school-official exception must perform a function the school would otherwise use its own employees to perform, meet the school’s criteria for a legitimate educational interest, remain under the school’s direct control over the use and maintenance of education records, and face limits on use and redisclosure. Schools must also describe the relevant criteria in their annual FERPA notice.

A written agreement is not always expressly required by FERPA for that exception, but the US Department of Education says it is a best practice because it helps establish the direct control and use restrictions the law requires. That distinction matters: “not always legally mandatory” is not the same as “unnecessary.”

COPPA creates a different pathway. A school may authorise collection from a child under 13 when the service is used for the benefit of the school and for no other commercial purpose. The provider remains responsible for COPPA compliance. School authorisation is not permission to build advertising profiles or use children’s data for unrelated commercial activity.

The vendor cannot borrow the school’s authority for everything

The Federal Trade Commission’s action against Edmodo made this boundary concrete. The FTC alleged that the education-technology provider used children’s personal information for advertising and unlawfully outsourced its consent responsibilities to schools. The company agreed to an order restricting those practices. The lesson is not that every classroom platform behaves the same way. It is that a school’s educational purpose cannot be stretched into a general commercial licence.

The FTC’s 2025 final Children’s Online Privacy Protection Rule strengthened requirements around separate opt-in consent for targeted advertising, data retention, security and biometric identifiers. The final rule did not adopt proposed changes specific to education technology operating in schools. Schools adopting voice, face or behavioural-analysis tools should therefore ask what data enters the system, what derived data leaves it and how long any of it remains.

Notice should describe the real system

A useful family notice should name the tool and the provider; explain the educational purpose; list the categories of student data collected or inferred; state whether the system trains on, profiles or advertises from student data; explain retention and deletion; identify who can see outputs; and give a route to challenge an automated result. It should also say whether an alternative is available and what happens if a family declines it.

Notice is especially important when the technology changes the power relationship at school. An AI tutor may steer a student’s learning. A behaviour system may flag risk. A face-recognition system may make access to lunch feel conditional on providing biometric data. Those uses are not equivalent, and a generic sentence saying the school “uses technology to improve services” does not explain them.

A UK example shows the stakes, while also showing why jurisdictions must not be conflated. In 2024, the UK Information Commissioner reprimanded Chelmer Valley High School over facial-recognition payments in its canteen, finding that it had not completed the required impact assessment before deployment and had not obtained valid explicit consent. The regulator also found that the alternative did not make the biometric choice sufficiently free. That decision applies UK data-protection law, not FERPA or COPPA, but the governance lesson travels: assess high-risk systems before deployment and make the non-biometric route real.

Students need a voice, not just a notice

The US Department of Education’s guidance on AI in teaching and learning calls for notice and explanation, human recourse and the involvement of affected stakeholders. That is not a decorative consultation exercise. Students and teachers often discover failure modes first: incorrect flags, inaccessible interfaces, cultural bias, surveillance pressure or an “optional” tool that is practically impossible to avoid.

The scale of adoption makes governance urgent. A 2025 RAND survey found that 54 percent of students and 53 percent of surveyed subject teachers reported using AI for school during the 2024–25 school year, while policy and training remained uneven. The exact percentage will change. The governance gap is the durable point: classroom use can expand faster than a district’s ability to explain and supervise it.

Questions every school should be able to answer

  • What exact educational function requires this system, and what less data-intensive alternatives were considered?
  • Which law or policy authorises each data flow, and when is individual consent required?
  • Is the provider under the school’s direct control, and what does the contract prohibit?
  • Does the provider train models, target advertising or develop unrelated products from student data?
  • How can a student or parent inspect, correct or challenge an output, and who makes the final decision?
  • When will the data be deleted, and how will the school verify deletion?

Parents should not be told that every school AI system requires a signature when the law is more complicated. Nor should legal authority be used as a substitute for honest communication. A school may have a pathway to adopt a tool and still owe families a much clearer account of what it does.

The right question is not simply whether a box was ticked. It is whether the school can show its purpose, its authority, its controls and a meaningful route for the people affected to say: this is wrong, explain it, and put it right.

Help and safety

Families concerned about the handling of US education records can first ask the school or district for its annual FERPA notice, the vendor contract and the process for inspecting or correcting records. The US Department of Education’s Student Privacy Policy Office publishes complaint information. Immortal AI’s Help & Safety page provides further reporting and support routes. For immediate risks to a child, use the school’s safeguarding route or the relevant local authority or emergency service. This article provides general information, not legal advice.

Related Immortal AI investigations


Principal sources

AI disclosure: Immortal AI uses AI-assisted research and drafting. Sources, claims, framing and final editorial decisions remain the responsibility of Immortal AI.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *