AI in Education

How do you keep student data safe when using AI tools in NZ?

Keep student data safe by treating student work as personal information under New Zealand's Privacy Act 2020: know what a tool does with anything you enter, remove or minimise identifying details, choose vendors with clear data terms, and get the right permissions before uploading. Your school board remains accountable for that information.

What counts as student data under NZ privacy law?

Under New Zealand’s Privacy Act 2020, almost anything that identifies a student is personal information: their name, their grades, their photo, and the work they hand in. A piece of student writing is not just an assignment; it can reveal a great deal about the young person who wrote it. Once you recognise student work as personal information, the rules for handling it become much clearer.

Your school is an ‘agency’ under the Act, and your board of trustees is ultimately accountable for the information the school holds. That accountability does not disappear when you paste a paragraph into an online tool. The thirteen Information Privacy Principles set expectations for how personal information is collected, used, stored and disclosed, and those expectations follow the data wherever you send it.

This matters for AI tools because entering student work into one is a form of disclosing personal information to a third party. The question is not whether privacy law applies, but how you meet it. Treating student data privacy as a starting point, rather than an afterthought, makes the practical decisions that follow far more straightforward.

What are the privacy risks of entering student work into AI tools?

The main risk is that student information leaves your control the moment it is entered into an external tool. Depending on the service, that text may be stored on overseas servers, kept for long periods, reviewed by staff, or used to train future models. Each of those is a different privacy question, and a single tool can involve several of them at once.

Re-identification is another quiet risk. Even work with the name removed can identify a student through a distinctive topic, a personal anecdote, or details about their family or health. Sensitive information about wellbeing, disability or cultural background deserves particular care, because the consequences of a leak are far higher than for an ordinary spelling test.

There is also the risk of drifting into uses no one agreed to. A tool adopted to save marking time can quietly become a store of years of student writing. Naming these risks up front, including offshore storage, training on your data, retention and re-identification, lets you weigh them deliberately instead of discovering them later.

How do you check what an AI tool does with your data?

Read the tool’s privacy policy and terms with four questions in mind: does it train on what you enter, how long does it keep your data, who else can access it, and where is it stored. A trustworthy tool answers these in plain language, and vague or missing answers are themselves a warning sign worth taking seriously.

Look specifically for whether there is an option to opt out of model training, whether data is deleted on request, and whether the vendor lists its sub-processors. For a school it is also worth asking whether the provider will sign an agreement about how data is handled, rather than relying only on a public policy that can change without notice.

  • Does the tool use your inputs to train its models, and can you turn that off?
  • How long is entered data retained, and can you delete it on request?
  • Where is the data stored, and does it leave New Zealand?
  • Who can access the data: staff, contractors, or other sub-processors?
  • Does the vendor offer clear terms or an agreement suitable for a school?

Should you remove identifying details before using AI?

Yes, the safest habit is to give a tool only what it genuinely needs, and student names are rarely part of that. De-identifying work before you enter it, or using a tool that never asks for identifying details, sharply reduces the harm if anything goes wrong. This is the practical form of the principle to minimise the personal information you disclose.

Remember that de-identification is not foolproof. Removing a name does not remove a vivid personal story or a description that points to one student. For sensitive pieces, consider whether the work should go into an external tool at all, or whether a more contained approach is wiser. Pseudonyms and referring to students by a class code are simple habits that help.

The goal is proportionality. Routine marking of a practice essay carries less risk than a reflective piece about a student’s home life. Matching how much you de-identify to how sensitive the work is keeps the process manageable while still protecting the students who need it most. A quick pause to ask how sensitive a piece is before uploading is often all the judgement a situation requires.

In most cases you need transparency and a clear school policy more than a signed form for every task, but this is a decision for your school leadership rather than an individual teacher. The Ministry of Education encourages schools to use digital tools responsibly and to be open with their communities about how student information is handled.

Being open means students and whanau can understand, in plain terms, that AI may be used to help mark or give feedback on work, what that involves, and how their information is protected. For many communities this is also a question of trust and cultural responsibility, including Maori data sovereignty, the principle that Maori have interests in how data about Maori is governed.

Practically, check whether your school already has a policy on AI or on third-party online services, and work within it. If one does not exist, that gap is worth raising, because a shared policy protects teachers as much as students. Consistency across a school is far safer than each teacher making a private call in isolation.

How do you choose and use AI tools that keep you in control?

Choose tools designed to keep the teacher in control of both the judgement and the data. The safest AI tools for education are transparent about data use, limit what they collect, and position the teacher, not the model, as the decision-maker. A tool that drafts feedback for you to review and edit keeps you in charge of what students actually receive.

This is the approach behind JeddAI, which is built in Australia and used across Australia and New Zealand. Teachers mark against their own rubric, success criteria and comment banks; JeddAI drafts aligned feedback, and the teacher reviews and edits before anything is finalised. It saves marking time while keeping professional judgement, and the handling of student work, with the teacher. If you want to see how that works in practice, you can Get started with JeddAI.

Whatever tool you use, the same habits apply: know what happens to the data, minimise what you disclose, be transparent with your community, and work within your school’s policy. Applied consistently, these steps let you gain the time-saving benefits of AI without putting student data privacy at risk. Good practice is not about avoiding AI; it is about using it deliberately, on your terms.

Higher-risk versus lower-risk ways to use AI tools on student work
Consideration Higher-risk approach Lower-risk approach
Identifying details Paste work with names and personal details intact De-identify or use class codes before entering work
Vendor terms Rely on a free tool with vague or no data policy Choose a tool with plain-language terms and an opt-out of training
Data location Unknown or offshore storage with no retention limit Known storage, clear retention, and deletion on request
Oversight Ad hoc use with no school policy Use within an agreed school policy, transparent to whanau
Teacher control Tool sends final feedback straight to students Teacher reviews and edits every draft before it is shared

Frequently asked questions

Is it legal to use AI tools on student work in New Zealand?

There is no blanket ban, but you must handle student work in line with the Privacy Act 2020 and your school's policies. The key is knowing what the tool does with the data and being transparent about it.

Can free AI chatbots be used to mark student work safely?

Often not without care, because many free tools may retain inputs or use them to train models. Check the terms, avoid entering identifying details, and prefer tools with clear, school-suitable data terms.

Who is responsible if student data is exposed through an AI tool?

Your school, as the agency holding the information, remains accountable under the Privacy Act 2020. That is why working within a school-wide policy matters more than making individual decisions.

Does removing a student's name make their work anonymous?

Not always. Distinctive content can still identify a student, so treat de-identification as risk reduction, not a guarantee, especially for sensitive pieces.

What should our school do before adopting an AI tool?

Review the vendor's data terms, decide on rules for identifying details, set a clear policy, and communicate with students and whanau. Involving leadership keeps the approach consistent and defensible.

Get started with Jeddle

Jeddle gives teachers and students instant, syllabus-aligned feedback powered by JeddAI.

Get started with JeddAI

Looking for study material? Browse Jeddle's Australian-English subject resources, or explore more articles on AI in Education.

Shopping cart0
There are no products in the cart!