AI is useful. But student data isn't a toy.
You want to use an AI tool to create lesson plans, exercises, grading rubrics. That's legitimate. It saves time and can make your work better. The problem starts when you dump student information into that tool without knowing where it goes.
This article is about what you need to check first.
What can happen (and why you should care)
When you type "create an exercise for my 7th graders, include their names" into a generic AI (like open ChatGPT), that data enters the company's servers. It doesn't disappear.
Some AI tools use your data to train new models. Others keep it for business reasons. Others are secure but don't make it clear. Most teachers don't read the terms of service (nobody does anyway).
The risk isn't paranoia. It's regulation.
In Brazil, LGPD (General Data Protection Law) is clear: data from minors has reinforced protection. Schools are responsible for ensuring that third parties — including AI tools — respect that protection. If they don't, the school (and you, as an educator) can be held accountable.
In Europe, GDPR is even stricter. If you work with European students or platforms that use European data, the same logic applies.
I'm not saying don't use AI. I'm saying: know what you're doing.
The questions you should ask
Before using any AI tool to plan your lesson, ask (the tool, your school, the vendor):
1. Is my data used to train the AI? Many free AI tools use everything you type as training material. If you write "assess Maria, who has dyslexia," that sentence might become part of the AI model. Unacceptable.
The answer you want: "No. Your data goes in, but we don't use it to train new models."
2. Who has access to my data? Where are the servers? Which country? Who works there? Does the company share data with third parties?
Serious tools have a clear privacy policy that says exactly this. If it's not written, it's because they don't guarantee anything.
3. How long does the company keep my data? Ideally, your data should be deleted automatically after a period (30 days, 90 days, etc.) or on request. If the company says "we keep it forever," be careful.
4. Does the tool have security certifications? Look for ISO 27001 (information security), SOC 2 (security audit), or explicit LGPD/GDPR compliance. This means someone audited their security.
5. Can I use the tool offline or on my school's private cloud? The most secure solution is one you control. If your school uses a secure server, the AI should be able to run there, not on public cloud.
What NOT to do
Don't put student names into generic public AI tools.
Don't write details about vulnerable situations (students with disorders, in treatment, with financial difficulty) into tools you don't trust.
Don't assume free = insecure or paid = secure. Always check.
Don't ignore the privacy policy. If it's too long and confusing, that's a red flag.
What to do
Look for AI tools built specifically for education. They have LGPD/GDPR compliance built in.
If your school uses a learning management platform (like Google Classroom, Moodle, etc.), look for AI integrations within it. Security is usually already handled.
Use pseudonyms. Instead of "John, age 12, dyslexia," write "Student A, intermediate reading level." AI works the same. Data stays protected.
When in doubt, ask your school's IT or administration. They should have an approved tools list.
Read the privacy policy summary (you don't need the whole document). If it says "your data helps us improve our services," that means they're using your data. Next.
The truth about responsible AI
AI is a tool. A good tool, if used correctly. But a tool involving minor data needs care. It's not paranoia. It's professionalism.
Your school has legal responsibility for student privacy. But you do too. You're the one typing it. You're the one who knows what's sensitive.

Thiago Chaer
Editor Chief and Founder of Future Education
Related Reads for You
Discover more articles that align with your interests and keep exploring.

