UK GDPR and AI Tools: What Schools Actually Need to Check
Written by David Elliott · · 6 min read
A straightforward checklist for senior leaders assessing an AI tool — lawful basis, data location, sub-processors, retention and what to put in your DPIA.
Most AI compliance questions in schools come down to a handful of checks. None of them require a legal background, but all of them need answering before a tool touches anything identifiable.
Know what the tool does with your input
Ask directly whether prompts are used to train models, how long they are retained, and whether a business or education tier turns that off. Consumer accounts and organisation accounts often behave very differently on exactly this point.
Map the sub-processors
The vendor you contract with is rarely the only party involved. Request the sub-processor list, note where data is processed, and check the transfer mechanism for anything outside the UK or EEA.
Write the DPIA before rollout, not after
A DPIA is far quicker when the scope is narrow. Define the specific use case, the data involved, who has access, and the mitigations in place — then revisit it whenever the use case widens.