Privacy & data

“Staff are putting student data into tools we've never vetted.”

The riskiest surface isn’t the vendor database — it’s the prompt box. Classify before you type.

The clear-eyed read

What's actually going on

A well-meaning teacher pastes an IEP draft into a free chatbot to "clean it up." Nothing looks wrong; nothing gets reported; the data is now outside your control. This is prompt-layer risk — the newest and least governed surface in school data privacy — and it is happening in your district this week. Roughly 60% of special-education teachers report using AI for IEP or 504 work without formal guidance.

The legal scaffolding was not built for this. FERPA dates to 1974 and has not been revised for AI; consumer tools may retain and train on whatever they receive. Meanwhile the stakes have been demonstrated at scale — the 2024 PowerSchool breach exposed data on more than 60 million students, and 41% of schools report AI-related cyber incidents.

The fix is not prohibition; staff will simply go underground. The fix is a small set of rules everyone can actually follow. Five Rules of AI Privacy: approved tools only; classify before you type; describe the need, not the student; AI supports your judgment — it does not replace it; report mistakes quickly. And one classification habit — Green, Yellow, Red, Black — that fits on a laminated card. When in doubt, leave it out.

First moves

30 / 90 / 365 days

Sequenced, not simultaneous. The 30-day moves cost little and buy you room; the year is where the change becomes structure.

First 30 days

  • Publish the approved-tools list, even if it is short. An imperfect list beats silence.
  • Put the data-classification card in every classroom and the Five Rules in every staff room.
  • Stand up a no-blame incident report path — you want mistakes reported in hours, not discovered in audits.

By 90 days

  • Run the privacy PD session with all staff, with role-specific do/don’t lists (the special-education rule is absolute: IEP documents never go into unapproved tools).
  • Review data-processing agreements for every AI tool in real use; send parent notices where required.

Within the year

  • Fold AI privacy review into procurement and add a vendor feature-change check so quiet AI additions to existing tools get caught.
  • Rehearse the incident response protocol once a year, the way you rehearse fire drills.

Carry the work

The tools that carry this