Educational Technology and AI
Student Data Privacy for Teachers: A Pre-App Checklist and Role Guide

Decision first: An individual teacher can minimize data, use approved services, check local procedures, and stop when a request exceeds the teacher’s role. Approval of contracts, security, legal interpretation, retention schedules, and breach response usually belongs to designated school or district staff. A service operator has separate obligations that cannot be transferred to a teacher by a checkbox.
Resource type: Checklist and role guide
Preparation time: 15–25 minutes before requesting approval
Best for: K–12 staff reviewing a new classroom tool
Scope: General educational information, not legal advice. Requirements vary by jurisdiction, institution, student age, record type, contract, and use.
Start with the role, not the app
On a small screen, scroll this table horizontally to see all columns.
| Role | Typical responsibility | Do not assume |
|---|---|---|
| Individual teacher or staff member | Use approved tools, enter only permitted information, follow account and record procedures, report concerns through the established route, and provide an instructional reason for a request. | A free account, colleague recommendation, vendor claim, or public privacy policy equals district approval. |
| School or district administrator, privacy officer, or legal counsel | Interpret local policy and applicable law; approve uses, contracts, consent routes, records practices, and responsible roles. | A teacher can accept contract terms or make a legal determination for the institution. |
| IT or information-security staff | Review authentication, access, integration, encryption, incident reporting, vendor security, and technical controls. | A privacy statement is a security assessment. |
| Accessibility, special-education, or disability-services staff | Check whether the use and format support required access and whether an alternative is needed. | A product’s accessibility claim confirms a particular learner can use it. |
| Service operator or vendor | Describe collection and use accurately, maintain required protections, follow applicable operator obligations and contracts, and support access or deletion terms. | A school label or educator discount changes what the service actually collects. |
Before using a new classroom app
- Define the instructional purpose. State what students or staff need to do and why an existing approved method is insufficient.
- Check the approved-app list and request process. If the service is not approved for this exact use, stop before creating accounts or uploading records.
- Name the data. List every field, file, identifier, interaction, device signal, and derived record the service may receive.
- Minimize. Remove information that is not necessary for the stated purpose. Do not collect a field simply because a form offers it.
- Check accounts and age. Identify who creates accounts, which terms apply, whether parent or institutional action is required, and how account recovery works.
- Ask about use and disclosure. Determine whether data supports only the requested service or also advertising, profiling, analytics, product development, or model training.
- Ask about retention and deletion. Identify retention periods, backups, export, deletion triggers, account closure, and how the institution confirms deletion.
- Check third parties. Identify subprocessors, integrations, hosting, support access, and international transfers where relevant.
- Check access. Confirm who can view which records, how roles are removed, whether sharing defaults are private, and whether activity is logged.
- Check accessibility and alternatives. Plan a comparable route for a student who cannot or should not use the service.
- Document the decision. Keep the approval record, permitted use, responsible contact, review date, and restrictions in the place your institution requires.
Data minimization in ordinary classroom decisions
On a small screen, scroll this table horizontally to see all columns.
| Teaching need | Higher-risk approach | Lower-data starting point |
|---|---|---|
| Anonymous practice poll | Require full name, school email, birth date, class, and a persistent profile. | Use an approved anonymous response mode or collect only a rotating class code when identity is not needed. |
| Draft feedback example | Upload a named student’s full paper to a public generative tool. | Use a teacher-written fictional excerpt with no link to an actual student, or work inside an approved system under the allowed purpose. |
| Group project scheduling | Collect home addresses, family schedules, and personal phone numbers. | Use the approved school calendar and collect only school-time availability needed for the task. |
| Reading support | Enter a diagnosis, plan, and named work sample into an unapproved service. | Begin with an approved accessible format or a teacher-created generic passage; consult the plan or support team for individual requirements. |
Questions for the approval process
- Collection: What is collected directly, automatically, or inferred? Can optional collection be disabled?
- Purpose: Is each use tied to the requested educational service? Are advertising, profiling, sale, or unrelated product uses prohibited?
- Model training: Are prompts, files, outputs, feedback, or usage logs used to train or evaluate models? Can that use be contractually disabled?
- Retention: How long is each data type kept, including logs and backups? What triggers deletion?
- Deletion and access: Who can request export, correction, or deletion? How is completion verified?
- Third parties: Which subprocessors receive information, for what function, and under what restrictions?
- Accounts: Are student accounts necessary? Who accepts terms, manages consent where required, and removes accounts?
- Security: How are access, authentication, encryption, vulnerability handling, and incident notice addressed?
- Changes: How will the institution be told about a material change in terms, data use, ownership, or subprocessors?
FERPA, PPRA, and COPPA are not interchangeable
FERPA is a federal law concerning education records at covered educational agencies and institutions. PPRA includes protections connected to certain surveys, analyses, evaluations, and marketing-related activities. COPPA applies to operators of certain online services concerning personal information from children under 13. Whether a rule applies and what action it requires depends on facts beyond a page like this. Use the institution’s designated process for interpretation and approval.
A vendor’s COPPA statement does not establish FERPA compliance, district approval, security, accessibility, or instructional value. Likewise, relying on a school exception or contract requires an authorized institutional decision, not an individual teacher’s assumption.
K–12 and postsecondary notes
K–12
District approval, parent-facing procedures, age requirements, operator obligations, and the school’s role in account creation may be central. Teachers should follow the K–12 approved-app and student-record process and should not independently collect consent or accept terms unless specifically authorized.
Postsecondary
FERPA may still apply to education records, but the eligible student ordinarily holds FERPA rights. Institutional procurement, accessibility, security, research, records, and learning-management policies remain relevant. Do not assume that an adult student’s ability to create an account authorizes an instructor to require the service or disclose education-record information to it.
What to do if data may have been exposed
Do not investigate by downloading more records, contacting affected families on your own, deleting evidence, or negotiating directly with a vendor unless the institution’s procedure assigns that task. Stop the questionable use if it is safe to do so, preserve the basic facts you already have, and immediately follow the established district or institution incident-reporting procedure. Use the designated IT, privacy, security, administration, or legal contact. Emergency or safeguarding procedures remain separate and should be followed when applicable.
Sources and limits
- U.S. Department of Education Student Privacy Policy Office: FERPA.
- U.S. Department of Education Student Privacy Policy Office: PPRA.
- Student Privacy Policy Office: Protecting Student Privacy While Using Online Educational Services.
- Federal Trade Commission: Children’s Online Privacy Protection Rule resources.
This guide provides a conservative workflow for routing decisions; it does not determine whether a particular use is lawful. Ask the institution’s authorized staff to apply current federal, state, local, contractual, and institutional requirements.