# Can Staff Put Student Data Into ChatGPT? The Rule to Write

Canonical URL: https://blog.theaieducator.io/posts/can-staff-put-student-data-into-chatgpt
Publication: Dan Fitzpatrick Insights
Author: Dan Fitzpatrick
Topic: AI Governance and Responsible Leadership
Published: 2026-09-21T07:16:32.000Z
Modified: 2026-09-21T07:18:52.908Z

Most schools answer this with a sentence staff cannot apply. Here is the test that decides whether a particular sentence may go into a particular tool, and the four lines to put in front of every member of staff this term.

## In brief

Staff can put student data into ChatGPT only inside an account the school controls, under terms the school has signed, and only with text that would not let a stranger identify the child. Compliance is not a property of the product: two schools using the identical tool sit in different positions depending on whose account it is. Dan Fitzpatrick's Named Child Test asks three questions before anyone types: could a stranger work out which child this is, has the school rather than the member of staff signed for the tool, and could the school say today where that text went.

## Key takeaways

- The answer turns on three things, none of which is the tool's marketing: whose account it is, what the school has signed, and what is in the sentence.
- Compliance is not a property of a product. Two schools using the identical tool can sit in completely different legal positions, because one signed for it and one borrowed it.
- OpenAI says data in a ChatGPT for Teachers workspace is not used to train its models by default, which protects a managed workspace and says nothing about a teacher's personal account.
- Deleting the name is not de-identification. FERPA covers any information that would let a reasonable person in the school community identify the student with reasonable certainty, and DfE material updated in May 2026 warns that seemingly anonymous information can still identify a pupil when matched with other information.
- The AFT, UFT and Microsoft standard of 9 September 2026 bars providers from using covered school data to train or benchmark AI models, but it is a promise made to the customer, so it protects only the district that signs it.
- Dan Fitzpatrick's Named Child Test asks whether a stranger could identify the child, whether the school rather than the staff member signed for the tool, and whether the school could say today where the text went.
- A blanket prohibition on personal data in AI tools does not stop the work. It moves it into personal accounts, where the school can neither see it nor account for it.

It is seven in the evening and a teacher is writing a support plan. She has the child's assessment in one window and a chatbot in the other, and she pastes three paragraphs across: the reading age, the two incidents last term, the thing the mother said at parents' evening. Then she types, "turn this into a plan the TA can follow."

Nobody has told her she may do that. Nobody has told her she may not. She is doing the job.

The honest answer to whether staff may put student data into ChatGPT is: sometimes, and it turns on three things, none of which is the tool's marketing. Whose account is it. What has the school signed. And what, exactly, is in the sentence. Get those three right and a teacher can use AI on real work about real children without anyone losing sleep. Get them wrong, or leave them undecided, and the default answer in your school is no, because nobody has said yes, and yet it is happening anyway at seven in the evening.

This piece gives you the test I ask leaders to apply, the four lines to put in front of staff, and the one place where the rule should be narrower than you think.

## Can staff put student data into ChatGPT?

They can, but only inside an account the school controls, under terms the school has signed, and only with text that could not let a stranger identify the child. Outside those three conditions the answer is no.

Notice what that answer is not. It is not "is ChatGPT compliant?" Compliance is not a property of a product. Two schools can use the identical tool and sit in completely different legal positions, because one signed for it and one borrowed it.

Take the wording OpenAI uses for its school product. When it [expanded ChatGPT for Teachers to 55 more districts on 26 August 2026](https://openai.com/index/bringing-chatgpt-for-teachers-to-more-us-school-districts/), it said that "data shared in a ChatGPT for Teachers workspace is not used to train our models by default." Read that twice. Two conditions are doing the work: *in a ChatGPT for Teachers workspace*, and *by default*. A teacher signed in to her own account at her own kitchen table is in neither. Same brand on the screen, different promise entirely.

The UK position starts from the other end and arrives close by. The Department for Education's policy paper [Generative artificial intelligence (AI) in education](https://www.gov.uk/government/publications/generative-artificial-intelligence-in-education/generative-artificial-intelligence-ai-in-education), last updated on 12 August 2025, puts it plainly: "It is recommended that personal data is not used in generative AI tools." Recommended, not forbidden, which leaves the decision where it belongs, with you. Most schools have not made it.

## The Named Child Test

The Named Child Test is three questions that settle, in about a minute, whether a particular sentence may go into a particular tool.

> **The Named Child Test** is three questions I ask before anyone in a school types anything about a student into an AI tool: Could a person who has never met this child work out who it is from what I am about to type? Has the school, and not the member of staff, signed for this tool, on terms that say the supplier acts only on our instructions? And could the school say today which tool this went into, under whose account, and what that supplier is allowed to do with it? Text that survives all three can be typed. Text that fails any of them is not a member of staff being careless. It is a school that has not yet made a decision.

This is my suggested way of thinking about it, not a validated instrument and not legal advice. Its value is that it moves the question off the product, where nobody in the building can answer it, and onto three things a leadership team can settle in an afternoon.

### Could a stranger work out which child this is?

Deleting the name is not the same as removing the child, and this is where most staff guidance quietly fails.

American law says so in as many words. FERPA's definition of personally identifiable information, at [34 CFR 99.3](https://www.law.cornell.edu/cfr/text/34/99.3), covers not only the name and the identifiers but "other information that, alone or in combination, is linked or linkable to a specific student that would allow a reasonable person in the school community, who does not have personal knowledge of the relevant circumstances, to identify the student with reasonable certainty." The test is not whether the text names a child. It is whether somebody could work out who.

British guidance lands in the same place. When the DfE updated its [Safe use of generative AI in education](https://www.gov.uk/government/publications/safe-use-of-generative-ai-in-education-module-3) material on 19 May 2026, [Schools Week reported](https://schoolsweek.co.uk/dfe-guidance-suggests-schools-use-ai-to-draft-send-support-plans/) on 28 May 2026 that it warns "even seemingly anonymous information can risk identifying a pupil if it is matched with other information."

Here is a hypothetical to make it concrete. A teacher strips out the name and types: "Year 9 student, joined in February, top set for math, wears a hearing aid, missed four weeks in the spring." There is no name in that sentence. In a school of nine hundred there is exactly one person it can be, and every adult in the building knows it.

Schools are small worlds, and small worlds re-identify people quickly. The practical version of this question, the one to give staff, is not "have I removed the name?" It is: *if I read this aloud in the staff room, would anyone say a name back to me?*

### Has the school signed for this tool, or has the teacher?

The account is the whole game, and it is the part leadership teams keep delegating to individuals by accident.

On 9 September 2026 the American Federation of Teachers, the United Federation of Teachers and Microsoft [announced a National AI Safety and Privacy Standard for schools](https://news.microsoft.com/source/2026/09/09/aft-uft-and-microsoft-announce-national-ai-safety-privacy-standard-for-schools-to-protect-students-families-and-educators/). The [standard itself](https://www.aft.org/sites/default/files/media/documents/2026/NAfAI-School_AI_Privacy_Standards.pdf), version 1.0, is blunter than most vendor language: the provider "absolutely may not use any Covered Data ... to train, fine-tune, update, benchmark, or otherwise improve any AI model," save for a narrow safety exception, and that restriction survives the end of the contract. The parties describe it as contractually enforceable and capable of being written into district agreements.

That is a real improvement, and it is worth saying so. But read what it is. It is a promise a supplier will make *to a customer*. It protects the district that signs it. It does nothing at all for the teacher who opened a personal account in August because the school had not given her one.

So the question to ask about any tool is not "is this one of the good ones?" It is: *who is the customer here, and is it us?* If the answer is a member of staff, your school has outsourced its data protection to whatever that person clicked through at eleven at night.

What the school then has to write for itself is a separate job, and I have set it out in [what a school should require before approving an AI tool](https://blog.theaieducator.io/posts/approving-ai-tools-for-schools). The short version: a supplier's signature makes a product safe to use, and only the school can say what it is for.

### Could you say today where this went?

If a parent asked tomorrow which tools hold information about their child, you should be able to answer without a meeting.

The AFT standard gives you the shape of the answer: providers must delete covered data from active systems within 180 days of a school's request, with backups purged on a documented cycle. Deletion rights are only worth having if you can say what to delete and where it is. A school that cannot name the tool, the account and the terms cannot exercise a right it has been given, and cannot tell a family the truth when something goes wrong. That is the same gap I wrote about in [who is accountable when an AI tool gets it wrong](https://blog.theaieducator.io/posts/who-is-accountable-when-ai-gets-it-wrong).

## What I See in Practice

The most common mistake is not a teacher typing something they should not have typed. It is a leadership team writing the sentence "do not put personal data into AI tools" and believing it has made a rule.

Across the leadership teams I work with on AI strategy, that sentence appears in almost every draft policy I read. It fails for a reason that is obvious the moment you look at the work rather than the document. The tasks where AI helps most are precisely the tasks that are most about a named child: reports, support plans, behavior logs, reference letters, the email to a parent that has to be right. A rule that forbids all of it has not restricted a practice. It has declared the most useful half of the job off limits and left the other half unaddressed.

What happens next is predictable and quiet. The work does not stop, because the work has a deadline. It moves to the personal account, where nobody can see it, and the school's position gets worse rather than better. I have written about that pattern at more length in [what leaders should do about shadow AI](https://blog.theaieducator.io/posts/what-to-do-about-shadow-ai).

The second pattern is more hopeful. Schools that have written one clear permission, naming a tool and a boundary, get far fewer questions than schools that have written three pages of warnings. Staff are not looking for reassurance. They are looking for a line.

## The four lines to put in front of staff

A staff rule about AI and student data should fit on one side of paper and survive being read once, in a hurry, in September. These four lines are the ones I would put on it.

1. **Use only the tools on our approved list, signed in with your school account.** Never a personal account, for any task involving a student, ever.
2. **Before you type, take the name out and then read it back.** If a colleague could still say who it is, it is still that child's information. Change it or do not send it.
3. **Nothing about special educational needs, safeguarding, behavior records or medical information goes into any tool** until [named person] has confirmed which tool may be used for it.
4. **The output is a draft and you are the author.** Your name goes on it, so the checking is part of the job, not an optional extra.

Then two more lines that make the rule work: who to ask when the answer is not obvious, and who to tell when something has gone into the wrong place. Both need to be a named person, not a mailbox.

## Where the rule should be narrower: SEND and safeguarding

This is the one area where I would tighten the rule rather than trust the test, because the pressure to use AI is highest exactly where the data is most sensitive.

The DfE's updated material, as reported by Schools Week on 28 May 2026, permits staff to use AI to draft initial versions of support plans and template communications, and in the same breath tells them to be "extremely cautious" about entering information on a child's special educational needs, disabilities and additional support needs. It also draws a line at statutory documents: contributions to an education, health and care plan should not be written without significant professional review.

Both halves of that are right, and the tension between them is the actual leadership problem. The teacher writing a support plan at seven in the evening is being told, in effect, "this is the best use of the tool, and it is the most dangerous data you hold." She cannot resolve that on her own. Somebody senior has to decide which tool, in which account, with which text removed, and write it down.

Which decisions should never be handed over at all is a separate question, and I have answered it in [which decisions AI should never make](https://blog.theaieducator.io/posts/which-decisions-should-ai-never-make).

## The honest counterargument

Some leaders will read this and conclude that the safe move is a blanket ban on student information in any AI tool. It is a defensible position, and for a small school with no managed accounts and nobody to own the decision, it may be the right one this term.

But be clear about what it protects and what it gives up. A ban you cannot support with an alternative does not stop the work; it relocates it. If you are going to say no, say it alongside a date by which you will say something better, and name the person who is working on it. A prohibition with an expiry date is a decision. A prohibition without one is a way of not deciding, and staff can tell the difference.

## What to do this term

Four things, none of which needs a working group.

1. **Name the tools.** One short list, with the account type written next to each one. If the list is empty today, say so out loud rather than letting people assume.
2. **Run the Named Child Test on the three tasks staff actually use AI for.** Not on a hypothetical. On this term's reports, plans and letters.
3. **Write the four lines** and put a named person at the end of them.
4. **Set the SEND and safeguarding boundary explicitly**, because if you do not, it will be set by whoever is most tired on a Thursday night.

If your leadership team wants to know where it actually stands before it writes any of this down, that is the work I do through the [School AI Readiness](https://theaieducator.io/school-ai-readiness?utm_source=blog.theaieducator.io&utm_medium=referral&utm_campaign=can-staff-put-student-data-into-chatgpt) process, and it starts with what your staff would say if you asked them today. I also write about this each week in [my newsletter](https://theaieducator.io/?utm_source=blog.theaieducator.io&utm_medium=referral&utm_campaign=can-staff-put-student-data-into-chatgpt#newsletter).

The teacher at seven in the evening is not your risk. She is your evidence. She has shown you which job needs the tool and which decision nobody has made. Make it.

## Sources and further reading

- OpenAI, [Bringing ChatGPT for Teachers to more U.S. school districts](https://openai.com/index/bringing-chatgpt-for-teachers-to-more-us-school-districts/), 26 August 2026.
- American Federation of Teachers, United Federation of Teachers and Microsoft, [AI Safety and Privacy Standard for Schools, version 1.0](https://www.aft.org/sites/default/files/media/documents/2026/NAfAI-School_AI_Privacy_Standards.pdf), September 2026, and the [announcement](https://news.microsoft.com/source/2026/09/09/aft-uft-and-microsoft-announce-national-ai-safety-privacy-standard-for-schools-to-protect-students-families-and-educators/), 9 September 2026.
- Department for Education, [Generative artificial intelligence (AI) in education](https://www.gov.uk/government/publications/generative-artificial-intelligence-in-education/generative-artificial-intelligence-ai-in-education), GOV.UK policy paper, last updated 12 August 2025.
- Department for Education, [Safe use of generative AI in education: module 3](https://www.gov.uk/government/publications/safe-use-of-generative-ai-in-education-module-3), published 10 June 2025, last updated 19 May 2026.
- Schools Week, [DfE guidance suggests using AI to draft SEND support plans](https://schoolsweek.co.uk/dfe-guidance-suggests-schools-use-ai-to-draft-send-support-plans/), 28 May 2026.
- Family Educational Rights and Privacy Act regulations, [34 CFR 99.3](https://www.law.cornell.edu/cfr/text/34/99.3), definition of personally identifiable information.

*Dan Fitzpatrick is the founder of The AI Educator, a Forbes contributor and a bestselling author on AI in education, and has advised the UK Department for Education, KHDA Dubai and the Ministry of Education in Kazakhstan. [More about Dan](https://www.theaieducator.io/about).*


## Frequently asked questions

### Can teachers put student names into ChatGPT?

Not into a personal account, and not into any tool the school has not approved. Inside a school-controlled workspace on signed terms, a named student may sometimes be appropriate for a specific task, but that is a decision a leader makes in advance and writes down, not one a teacher makes at seven in the evening.

### Is ChatGPT FERPA compliant?

That is the wrong question, because compliance is not a property of a product. What matters is the agreement behind the account. OpenAI offers district workspaces and a multi-state data privacy agreement; a teacher's own account carries none of that. The same software can be compliant in one school and not in another.

### Does removing a student's name make the data safe to use?

Often not. FERPA's definition covers information that would let a reasonable person in the school community identify the student with reasonable certainty, and DfE material warns that seemingly anonymous information can identify a pupil once matched with other information. In a small school, a year group and a detail are usually enough.

### What should a school's rule about AI and student data actually say?

Four lines: use only approved tools signed in with a school account; remove the name and then check a colleague could not still identify the child; put nothing about special educational needs, safeguarding, behavior or medical information into any tool until a named person confirms which one; and treat every output as a draft you author.

### Can staff use AI to draft SEND support plans?

DfE material updated in May 2026 permits AI to draft initial versions of support plans and template communications, while telling staff to be extremely cautious with information about a child's needs and not to write statutory documents such as education, health and care plan contributions without significant professional review. Leaders should name the permitted tool explicitly.

### Should we simply ban student data in AI tools?

It is defensible for a school with no managed accounts and nobody owning the decision, but only as a stated position with an end date. A prohibition you cannot support with an alternative relocates the work into personal accounts rather than stopping it, which leaves the school in a worse position.

---
Source: [Can Staff Put Student Data Into ChatGPT? The Rule to Write](https://blog.theaieducator.io/posts/can-staff-put-student-data-into-chatgpt)
Publisher: [The AI Educator](https://theaieducator.io)
