A member of staff has pasted pupil information into an AI tool. It's one of the most common AI-related incidents in schools — here's whether it's a breach, what to do, and how to stop it recurring.
Is it a data breach?
Potentially, yes. Entering pupil personal data into an AI tool means disclosing that data to a third party. Whether it constitutes a reportable personal data breach depends on the circumstances — the tool, the data involved, any agreement in place, and the risk to the individuals. That assessment is your DPO's to make, and it should be made promptly rather than hoped away.
Special category data raises the stakes considerably. Pasting a pupil's name is one thing; pasting SEND information, medical detail, safeguarding notes or anything about a child's home circumstances is significantly more serious. If that's happened, treat it urgently.
What to do if it's happened
- Tell your DPO immediately — this is the whole first step; don't investigate alone
- Establish the facts — what data, which tool, which account, how often
- Delete what can be deleted — conversation history and, where possible, submit a deletion request to the provider
- Assess the risk to the individuals concerned, with your DPO
- Decide on ICO reporting — DPO's call, within 72 hours if reportable
- Consider informing those affected, where the risk warrants it
- Record it in your breach log regardless of whether it's reportable
- Address the cause — usually training, not misconduct
Treat it as a training failure, not a disciplinary one
In the overwhelming majority of cases, a member of staff pasting pupil details into ChatGPT was trying to do their job well and had never been told not to. Responding punitively guarantees the next incident goes unreported — which is far more dangerous than the incident itself. Fix the system, not the person.
How to prevent it
- Say the rule explicitly and often — "no pupil information goes into AI tools", not buried in a policy
- Show staff the alternative — how to work generically and add details afterwards, which takes no longer
- Provide approved tools so staff aren't improvising with personal accounts
- Cover it in induction for all new staff
- Make reporting easy and blame-free
See staff acceptable use rules and AI and GDPR in schools.
The rule that prevents nearly all of this
Work generically. "Write a report comment for a Year 3 pupil who has found fractions difficult" achieves exactly the same outcome as naming the child, in the same time, with none of the risk. Once staff have seen how easy the safe method is, most incidents stop. See using AI for reports safely.
Want to prevent this happening in your school?
We train staff on the safe method — same time saved, no data risk. AskColin gives schools low-cost monthly support with one-to-one help whenever you need it — so when you're stuck on a real job at 8am, there's someone to ask. Practical, jargon-free, built around your team.
Get one-to-one AI support for your schoolFrequently asked questions
Is putting pupil names into ChatGPT a data breach?
Potentially yes — it discloses personal data to a third party. Whether it's a reportable breach depends on the tool, the data, any agreement in place and the risk to individuals. Your DPO makes that assessment, and should do so promptly.
What should a school do if staff entered pupil data into AI?
Tell your DPO immediately, establish what data and which tool, delete conversation history and request provider deletion where possible, assess risk with your DPO, decide on ICO reporting within 72 hours if reportable, consider informing those affected, log it, and address the cause.
Should staff be disciplined for putting pupil data into AI?
Usually not. In most cases staff were trying to do their job well and had never been told not to. Responding punitively guarantees the next incident goes unreported, which is more dangerous than the incident. Treat it as a training failure and fix the system.
How do schools prevent AI data breaches?
State the rule explicitly and often, show staff how to work generically and add details afterwards, provide approved tools so staff aren't using personal accounts, cover it in induction, and make reporting easy and blame-free.