AI Privacy Policy for Teachers: A Practical Template for Safer AI Workflows
Use this plain-English AI privacy policy template to decide what learner, parent, assessment, and business information should stay out of generative AI tools. Includes a traffic-light decision system, workflow examples, and a pre-prompt checklist for independent teachers and course creators.

Generative AI can help independent teachers and course creators turn rough ideas into lesson outlines, feedback drafts, activity variations, and clearer communications. But before an AI tool can help with a task, someone has to decide what information is safe to enter.
That decision should not rely on memory, a hurried judgement call, or the assumption that an AI account is automatically appropriate for learner information. An AI privacy policy for teachers creates a shared rule: use AI for the work, not for identifiable learner records.
This article gives you a practical policy you can adapt for tutoring, small teaching businesses, and course-creation workflows. It is designed to support professional judgement, not replace it. You remain responsible for deciding whether a prompt, output, or workflow is appropriate.
Why every teacher and course creator needs an AI privacy policy
Teaching work often combines information that feels routine but can become identifying when put together: a first name, age, timetable, learning need, piece of written work, family situation, attendance pattern, or assessment result. The U.S. Department of Education describes personally identifiable information as information that can distinguish or trace a person directly or indirectly, including through links with other information. That is a useful practical standard even when you are not working in a U.S. school setting.
A policy turns a vague instruction such as “be careful with data” into repeatable decisions. It tells you:
- which tasks are suitable for AI assistance;
- which information must be removed, generalized, or replaced before prompting;
- which subjects require a human-only process;
- who checks outputs before they are sent or used; and
- what to do when a collaborator accidentally includes sensitive information.
It also helps you communicate consistently with teaching assistants, co-tutors, editors, virtual assistants, and contractors. A good policy is short enough to use during a busy week and specific enough to guide a difficult decision.
What the recent research suggests
A 2026 preprint study of 224 workers who used ChatGPT examined privacy concerns, ChatGPT proficiency, organizational policies, and actual use. The authors report that organizational policies were positively associated with privacy-related proficiency, while overall proficiency was low. The study is not specific to educators, and it should not be treated as proof that a policy alone prevents mistakes. It does, however, support a sensible operational lesson: clear workplace rules may help people make better privacy decisions than informal expectations alone.
Education needs this kind of operational clarity. UNESCO has warned that the rapid growth of publicly available generative AI has outpaced many regulatory and institutional responses, leaving important privacy questions unresolved. A simple policy gives an independent educator a starting point while they also check the rules, contracts, and privacy expectations that apply to their own setting.
A traffic-light system for AI prompts
Use this system before pasting anything into an AI tool. When in doubt, move one colour toward more caution.
| Colour | Decision | Examples | Action |
|---|---|---|---|
| Green | Usually suitable to share | Generic lesson objectives, invented examples, public curriculum topics, anonymized class scenarios, your own non-confidential teaching notes | Use AI, then review the output for accuracy, tone, inclusion, and suitability. |
| Amber | Pause, reduce, and review | De-identified learner work, generalized feedback needs, draft parent messages, internal course plans, non-public business processes | Remove identifying details, minimize the information, use placeholders, and confirm the tool and account are approved for this use. |
| Red | Do not enter into a general AI prompt | Names with performance data, contact details, records, passwords, payment data, safeguarding concerns, health information, disability documentation, full parent communications, identifiable images, recordings, or confidential business documents | Keep the task in a human-only workflow or use an approved system after obtaining appropriate organizational and legal guidance. |
Important: replacing a learner’s name with “Student A” does not automatically make material safe. A distinctive combination of age, location, incident details, work samples, diagnosis, schedule, or family context may still identify someone. Data minimization means using only information directly relevant and necessary for the purpose, rather than sharing the entire record.
AI decision tree: use this before every prompt
Save or print this one-page decision tree for your teaching workspace.
- Is this task about a real learner, parent, colleague, or client?
If no, proceed with ordinary professional review. If yes, continue. - Does the prompt contain direct or indirect identifiers?
Look for names, initials, email addresses, phone numbers, dates of birth, IDs, addresses, photos, voice recordings, unique incidents, schedules, grades, or combinations that make the person recognizable. - Can the AI complete the task using a fictional or generalized version?
If yes, replace details. For example, change a pasted essay into a short invented extract showing the same writing issue. - Is the remaining information still sensitive, confidential, or likely to cause harm if mishandled?
If yes, do not prompt a general AI tool. Use a human-only process and follow your organization’s escalation route. - Is the tool, account, and intended use approved for this kind of information?
If you cannot answer clearly, treat the task as amber or red. Do not assume that an individual account, a free account, or a tool’s marketing statement is sufficient approval. - Will a qualified human review the output before use?
If no, stop. AI output is a draft or input to your judgement, not an automatic decision about a learner.
Common workflows: safer ways to get useful help
Lesson planning
Safer prompt: “Create three 20-minute activities for teaching fractions to a mixed-attainment group aged 10–11. Include one hands-on option and one low-printing option.”
Avoid: “Plan a lesson for Maya, who has dyscalculia, missed school after surgery, and is currently working below expected level.”
The first prompt focuses on the instructional problem. The second includes personal and potentially sensitive details that are not necessary to generate a starting activity plan.
Feedback drafts
Safer workflow: identify the skill gap yourself, write a fictionalized extract that demonstrates it, ask for three feedback sentence stems, then adapt them after reviewing the learner’s actual work privately.
Avoid: uploading a full named assignment, rubric, grade history, or notes about behaviour and circumstances. Even if the intended output is only a warmer feedback message, the input can contain far more information than the task needs.
Parent or client communication
Safer prompt: “Draft a concise, supportive message inviting a parent to discuss a learner’s recent progress and next steps. Do not mention a specific child or situation.”
Then add the factual details manually in your usual communication system. Do not paste a complete thread containing names, contact information, payment questions, conflict, health matters, or safeguarding information into a general-purpose AI tool.
Learner support and wellbeing
Use AI to produce generic resources: a study-planning worksheet, a list of calm revision routines, or neutral phrases for encouraging persistence. Keep individualized wellbeing, health, disability, family, and safeguarding matters in a human-led workflow. If a learner discloses an immediate risk, follow your organization’s safeguarding process or local emergency procedures rather than using AI to assess the situation.
Editable one-page AI privacy policy template
Copy this template into your staff handbook, course operations guide, or tutor agreement. Replace the bracketed text before use.
[Business name] AI Privacy Policy
Purpose. We may use AI tools to support planning, drafting, editing, and administrative work. AI does not replace professional judgement, human review, or our responsibility to learners and families.
Approved use. AI may be used for green-light tasks and carefully de-identified amber-light tasks, provided the user follows this policy and reviews every output before it is shared or used.
Information we do not enter into general AI prompts. We do not enter identifiable learner, parent, staff, or client information; contact details; passwords; payment or bank information; education records; assessment histories; safeguarding information; health or disability information; identifiable images or recordings; confidential contracts; or private communications.
Data minimization. Before using AI, we use the smallest amount of information needed for the task. We remove names and unnecessary context, use placeholders or fictional examples where possible, and do not upload complete records when a short generalized description will do.
Human review. A qualified person checks AI-assisted work for factual accuracy, teaching quality, bias, tone, accessibility, confidentiality, and relevance before use. AI output is never used as the sole basis for high-impact decisions about a learner.
Tool checks. Before using a new AI tool or account for work, [business name] checks its terms, privacy information, access settings, retention controls, and any contractual or organizational requirements that apply.
Incident response. If sensitive information is entered into an AI tool by mistake, the user stops sharing further information, records what happened, preserves relevant details, and informs [named contact/owner] promptly so that the appropriate next steps can be decided.
Review date. This policy is reviewed every [three/six/twelve] months and whenever we introduce a new AI tool or materially change an AI workflow.
Introduce the policy without creating fear
Start with a short explanation: “We use AI to reduce repetitive drafting work, but we do not use it as a place to store learner information.” Give collaborators three examples of green, amber, and red prompts. Ask them to practise rewriting one realistic red prompt into a green or amber one.
For learners and parents, describe the principle in plain language. Explain what kinds of teaching work may be AI-assisted, confirm that a teacher remains accountable for decisions, and state that identifiable personal information is not entered into general AI prompts. Do not make claims about privacy protections that you have not verified for your specific tools and contracts.
Pre-prompt checklist
- What is the educational purpose of this prompt?
- Could I get the same help with a fictional example or generalized description?
- Have I removed direct and indirect identifiers?
- Am I sharing only the minimum information needed?
- Is this tool and account appropriate for this type of work under my organization’s rules?
- Could this output affect a learner’s opportunity, grade, wellbeing, or relationship with a family?
- Who will check the output before it is used?
A workable AI privacy policy is not a one-time document. It is a habit: minimize, generalize, verify, and keep people responsible for educational decisions. If you want a more structured way to turn your own teaching processes into reviewable AI-assisted workflows, explore SubSchool. Automation can reduce repetitive work, while the teacher retains authorship and the final educational decision.
Sources and methodology
Prepared from the supplied editorial brief and a targeted review of the cited 2026 arXiv preprint, UNESCO guidance on generative AI in education, U.S. Department of Education material defining personally identifiable information, and Information Commissioner's Office guidance on AI data minimisation. The article intentionally provides operational guidance rather than jurisdiction-specific legal advice, avoids claims about any individual AI vendor's current settings, and treats AI output as subject to human review.
Use the relevant SubSchool workflow while keeping the result editable and source-grounded.



