FERPA COPPA checklist AI tools teachers can follow before using ChatGPT or Claude with student data

FERPA COPPA Checklist AI Tools: What Teachers Need to Know in 2026

A student’s IEP goal, pasted into ChatGPT to help draft a progress note. A parent’s email, run through Claude to soften the tone. A grade book screenshot, dropped into Gemini to catch pattern-of-failure trends before conferences. None of these feel like legal risk in the moment. They feel like Tuesday.

This is a one-page reference for the individual teacher — not the district, not the IT department — on what FERPA and COPPA actually require before student information touches an AI tool, and what a ferpa coppa checklist ai tools decision looks like in practice. Most guidance online is written for superintendents. This one is written for the person actually typing.

Who Regulates What, in Plain Terms

FERPA and COPPA get mentioned together so often that they start to sound like one law. They aren’t, and the difference matters for what you, personally, are responsible for.

FERPA (the Family Educational Rights and Privacy Act) governs what schools and school employees can disclose about students. It applies to you directly, every time you share a student’s education record with a third party — including an AI tool.

COPPA (the Children’s Online Privacy Protection Act) governs what companies can collect from children under 13. It’s a rule for the AI vendor, not for you. The FTC finalized amendments to COPPA in April 2025, with full compliance required by April 22, 2026 — but notably, the FTC explicitly declined to add school-specific provisions, leaving that ground to the Department of Education’s FERPA process instead. Practically, this means COPPA is why a free ChatGPT account requires you to be 13 or older to sign up — it isn’t a compliance obligation that sits on your shoulders as a teacher.

So the checklist below is really a FERPA checklist with a COPPA footnote. That’s a more honest starting point than most versions of this list you’ll find.

The FERPA Test: Direct Control, Not Paperwork

The rule that actually governs your AI use is the “school official” exception, at 34 CFR § 99.31(a)(1)(i)(B). For a vendor — including an AI company — to legally receive student data without individual parental consent, four conditions have to hold at once:

  1. The vendor performs a service the school would otherwise handle itself.
  2. The vendor stays under the school’s direct control regarding how the data is used and kept.
  3. The vendor is restricted from using the data for anything beyond that authorized purpose.
  4. The school has designated the vendor as a “school official” under its own published criteria.

Free, personal-tier ChatGPT, Claude, or Gemini accounts fail this test — not because the companies are careless, but because there’s no data processing agreement putting the district in control of what happens to the data afterward. The moment you paste identifiable student information into a consumer account, you’ve made a disclosure the exception doesn’t cover.

Two corrections worth making, because a lot of the checklist content circulating online gets these wrong:

  • A written contract isn’t strictly required by the statute. What FERPA requires is that the vendor stays under the district’s direct control and uses the data only for the authorized purpose. A signed data processing agreement is how districts document and enforce that control in practice — and state law or district policy often mandates one — but “no contract” and “no direct control” aren’t automatically the same failure.
  • A FERPA violation is institutional, not personal. The district is the regulated party, not you individually. That doesn’t mean there’s no consequence for a teacher — internal discipline and loss of trust are both real — but it does mean the framing “you could get sued under FERPA” is usually inaccurate. The exposure is to your school, and by extension to your job.

The Safe-Input Rule: FERPA COPPA Checklist AI Tools

If you only remember one line from this page, make it this: the question isn’t which AI tool you’re using — it’s which tier, and whether your district has a signed agreement covering it.

CategoryFree/personal AI accountDistrict-licensed AI (with signed DPA)
Student full name + any identifying detail (grade, class, behavior note)Not FERPA-safeSafe within the agreement’s scope
IEP, 504, or special-education contentNot FERPA-safe, regardless of tier — use a purpose-built toolOnly if the tool is specifically contracted and district-approved for this
Disciplinary or behavioral recordsNot FERPA-safeSafe within the agreement’s scope
Individual grades or assessment scores tied to a named studentNot FERPA-safeSafe within the agreement’s scope
Aggregate, de-identified data (“the class average was 74%”)Generally fineFine
A hypothetical or composite student with no real identifying linkGenerally fineFine
The safe-input rule for using AI tools with student data

The middle column is where almost every risky use actually happens, because the free tier is the one teachers reach for by default — it’s the one that’s already open in another tab.

What to Do Instead, This Week

The realistic fix isn’t “stop using AI.” It’s changing three habits:

Anonymize before you paste, every time. Swap the real name for “a student,” strip the grade and school, and remove any detail specific enough to re-identify the person. Most of what you actually need AI for — drafting language, generating options, restructuring a note — works fine on a de-identified version of the problem.

Ask what your district has actually licensed. ChatGPT Edu, Gemini for Education (through a Workspace domain), and Claude for Teachers all include data protections that free consumer accounts don’t. If your district hasn’t signed anything, assume you’re on the free tier even if the branding looks institutional — check for yourself rather than assuming IT already handled it. Our comparison of ChatGPT, Claude, and Gemini for teachers breaks down what each tier’s data policy actually says.

Keep IEP and disciplinary content off general AI entirely, even on a licensed tier, unless the tool was specifically built and contracted for that purpose. This is the one category where “probably fine” isn’t a good enough standard — the sensitivity of the record is too high to treat like a grading question.

If You’re Outside the US

The specific statutes are different — the UK runs on UK GDPR and the Data Protection Act 2018, Canada on PIPEDA and provincial laws, Australia on the Privacy Act 1988 — but the underlying principle holds everywhere: student data carries protections that consumer AI accounts weren’t built to satisfy, and the safe-input rule above is a reasonable default until your school tells you otherwise.

Frequently Asked Questions

Does anonymizing a student’s name make AI use automatically safe? It substantially reduces the risk, but only if you also strip other identifying details — grade, school, a specific incident, a distinctive circumstance. A first name alone in a large class is low-risk; a first name paired with a grade and a behavior note is often still identifiable.

My district hasn’t given any AI guidance. What’s the default? Treat the safe-input rule as the floor: no identifiable student information into any tool without a documented district agreement. Everything else is generally fine to use.

Is Gemini different from Google Workspace for Education’s version of Gemini? Yes, meaningfully. Standard consumer Gemini follows Google’s general consumer data policies. Gemini inside a school’s Workspace for Education domain carries FERPA-aligned protections — same product name, different data handling underneath.

Do I need to read the vendor’s full privacy policy myself? No — that’s what a district-level data processing agreement is for. Your job is knowing which tier you’re on, not auditing the vendor’s legal terms yourself.

What actually happens if a teacher accidentally shares identifiable student data with a free AI tool? It depends on the district and the sensitivity of what was shared. Most cases result in a conversation and a correction, not a legal action — but IEP or disciplinary content raises the stakes considerably, which is why that category gets a stricter rule above.


This article is for informational purposes only and does not constitute legal advice. Privacy law changes, and requirements vary by state, province, and institution. If you have a specific situation, your district’s data privacy officer or legal counsel is the right resource — this checklist is a starting point, not a substitute.

For the fuller picture of how AI privacy policies actually compare, our student data privacy guide goes deeper into vendor-by-vendor policies. And if the reason you’re looking at AI at all is that you’re stretched too thin to think clearly about any of this, start with the burnout piece — the privacy question gets easier once the exhaustion question is handled.

Sources

Leave a Comment

Your email address will not be published. Required fields are marked *