Student Radar
All articles
SEND articlesSchool data and operations

Using AI with pupil records: a SENCo's due-diligence checklist

Use eight checks before putting pupil records into AI: test purpose, minimisation, suppliers, retention, access, transparency and human review.

Founder, Student Radar

Sources last checked .

  • AI in education
  • Pupil data
  • Data protection
  • SENCo practice

Before putting pupil-record information into an AI tool, define the task, prove that personal data is necessary, identify every recipient and retention route, and agree the human review. If any answer is missing, pause. Use invented or fully anonymised material where the task can be completed without personal data.

This checklist is for SENCos, school leaders, trust leaders and data protection leads in England. It is accurate on 16 August 2026, supports local due diligence and isn't legal advice. Follow the school's approved process and involve the DPO, IT lead and DSL where their remit applies.

Use this eight-question release gate

Treat the checklist as a release gate for one defined use, not as a badge for the whole product. A tool approved for drafting a generic letter is not thereby approved to summarise a SEND plan. Bureaucracy sometimes multiplies forms; here, the separate question is doing useful work.

Paper-cut pupil-record cards pass through minimisation, provider, retention, access and human-review gates
Editorial illustration: pupil-record content passes through separate purpose, minimisation, provider, retention, access and human-review gates before use.
  1. What exact task is being supported? Write one sentence naming the user, input, output and decision. Record the expected benefit and why a lower-data method will not do. An attractive demonstration is not a purpose.
  2. Does the task need personal data? Start with no pupil information. If the task cannot work that way, remove names, identifiers and unnecessary free text. Pseudonyms can still be personal data when the school can reconnect them to a child.
  3. Where do prompts, files and outputs go? Identify the contracted supplier, model provider, hosting location, sub-processors, support access, international transfers and whether input or output is used to train or improve a model.
  4. Has the school documented the lawful route? Ask the DPO to record the lawful basis, any special-category condition, necessity, transparency information and whether the use changes the DPIA. Consent should not become a convenient guess in a drop-down list.
  5. Who can use, view and export it? Check real permissions, strong authentication, support access and audit evidence. Test the staff role and pupil scope involved. A role name alone does not prove that access is limited to the job.
  6. How long does each copy remain? Set retention and deletion rules for prompts, uploads, outputs, logs, backups and local downloads. Confirm what happens at contract end and how deletion can be evidenced.
  7. What must a person review? Name the professional who checks source accuracy, missing context, bias, unsuitable language and the proposed action. Keep the source record available. Give pupils and families a clear correction or challenge route where relevant.
  8. What will trigger another review? Record an owner and date, plus triggers such as a new model, feature, sub-processor, data field, retention term or use case. Stop the use if the supplier changes the processing before the school has assessed it.

DfE's school data-protection manual was updated on 9 July 2026 after changes under the Data (Use and Access) Act 2025 came into force. The Act amended the existing framework; it did not remove the need for lawful, transparent and secure processing or accountable complaint routes.

DfE's AI guidance recommends avoiding personal data in generative AI tools. Where its use is strictly necessary, the school must protect the data and align the product and procedure with data-protection law and local policy. The March 2026 school guidance also says to establish whether pupil data can be used for model training before use.

Walk one made-up record through the gate

The details below are synthetic and do not describe a pupil, customer or school. A SENCo wants an approved staff-facing tool to draft questions for a support review. The proposed input links attendance, provision delivery and selected classroom context.

The first signal is lower attendance across four weeks. On its own, that pattern cannot explain cause or need. The provision record then shows that several planned sessions were missed on absent days, while classroom notes place difficulty around one noisy transition rather than across the timetable.

The additional evidence changes the professional question: which access barriers, timetable arrangements and missed support should staff review with the pupil and family? It does not show that SEND caused absence, that the provision works, or that a particular response is required.

Separate attendance, provision and classroom-context paths converge under a human review lens with an evidence gap left open
Editorial illustration: attendance, provision and classroom context meet at human review, while the open evidence gap prevents a confident automated conclusion.

Apply the gate before any data enters the tool. The DPO confirms the approved use and minimum fields; the SENCo removes unrelated narrative; access is limited to the authorised team; the output stays a draft; and the review record links back to the source evidence and human decision.

If the school cannot establish the provider route, training use, retention or access evidence, use a blank template instead. A fluent summary is not worth an unknown disclosure path.

Keep automated output away from significant decisions

The ICO's children and UK GDPR guidance was updated on 15 May 2026 for the Data (Use and Access) Act. It says children merit specific protection and organisations should avoid solely automated significant decisions about them wherever possible, with required safeguards where such use is lawful.

For a school, the safer operating rule is simple: AI may help organise material for review, but it must not decide SEND status, diagnose need, determine support, infer safeguarding harm, set a referral threshold or settle access to education. A nominal click is not meaningful human review if the reviewer lacks the evidence, authority or freedom to disagree.

The ICO's broader AI risk toolkit currently warns that parts are under review following the Act. Use the live guidance with the DPO and record the version relied upon. A downloaded checklist can age quietly; software is not the only thing that receives updates.

Where Student Radar fits

Student Radar's public SEND catalogue describes assisted drafting with source, review and decision trails, role-aware access and human-edited suggestions. In the current Intimate Care Plans flow, an AI-assisted plan cannot be activated at creation and must first be saved as a draft for review.

That flow is designed to log an AI-draft event with the model label, generation time, source-field groups, safety flags, reviewer role and accepted sections. It is one implementation example, not proof that every AI surface has identical audit evidence. Check the actual workflow being used.

Review the AI processing and transfer overview, the SEND technology DPIA guide and the security evidence before approval. For the underlying records, use the separate SEND retention and transfer guide. To examine a proposed school workflow, request a SEND-focused walkthrough.

Sources and further reading