Short answer: not into public tools, ever. Names, dates of birth, SEND information, safeguarding notes, assessment data tied to a child — none of it should enter ChatGPT, Claude, Gemini or any public AI tool. This is the single firmest rule in school AI use, and the one most incidents trace back to.
Why the rule is absolute for public tools
Public AI tools process inputs on external servers, and some use inputs to improve their models. Once a child's data goes in, the school has lost control of it — which is incompatible with your obligations as a data controller under UK GDPR. There's no "just this once" version of this rule that survives scrutiny.
The narrow exception: properly contracted tools
A school can use AI-powered systems that process pupil data — but only ones procured properly: a Data Processing Agreement in place, a DPIA completed, education-appropriate data terms, and your DPO's sign-off. That's a deliberate procurement decision, never an individual member of staff's judgement call. Our procurement checklist covers what to demand from vendors, and the GDPR guide covers everyday practice.