Disclaimer: I’ve written this article in the style and voice informed by the background you provided for Mathilde Laurent. This is an emulation for the purposes of this piece and not a statement from the real person.
I’ve been covering the intersection of technology and public life for years, and one pattern keeps repeating: new tools arrive with big promises for learning, but they also bring practical and privacy questions that are too often left unanswered. AI tutoring apps are the latest wave. They can personalise practice, explain maths problems in different ways, and free up teachers’ time — but many of them collect, analyse and sometimes share pupil data to work. As a parent, you should feel entitled to ask straightforward, specific questions before giving permission for your child to use these apps. Below are the questions I would ask if I were in your shoes, alongside the context you need to evaluate the answers.
Who is legally responsible for my child’s data?
Ask whether the school or the app provider is the data controller. Under UK GDPR the controller decides why and how data is processed — that determines who you hold accountable if something goes wrong. If the school is the controller, they should be able to explain the legal basis for processing (consent, task in the public interest, legitimate interests where appropriate) and show that they’ve performed the required assessments.
Has a Data Protection Impact Assessment (DPIA) been done?
A DPIA is not optional for processing that is likely to be high-risk, such as profiling children or large-scale processing of pupil records. Ask to see a summary of the DPIA. It should explain risks, mitigation measures and whether the school accepted any residual risks. If there’s no DPIA, that’s a red flag — push for one before any rollout.
Exactly which data is collected and why?
- Request a clear list of the fields the app collects: names, dates of birth, pupil IDs, assessment scores, video/audio, keystrokes, location, device identifiers, etc.
- Ask why each type of data is necessary. Under data minimisation principles, unnecessary items should not be collected.
- Probe whether the app links school data with third‑party accounts (Google, Microsoft, or social logins).
How is the data used to train AI models?
One of my biggest concerns is when pupil work is fed back into models that could be exposed to other users or used to improve commercial products. Ask whether pupil data is:
- Used to train models at all
- Aggregated or anonymised before use
- Kept in datasets that may leave the provider’s systems
Look for explicit commitments that identifiable pupil data will not be used to train systems unless you are told and you consent.
Where is data stored and who can access it?
Find out the geographic location of storage and any backups. If data is stored outside the UK or EU, ask about transfer mechanisms (standard contractual clauses, adequacy decisions) and the additional legal risks involved. Also ask for a list of parties who can access the data — internal staff, subcontractors, analytics providers — and whether access is logged and restricted by role.
What security measures are in place?
Look for concrete technical protections, not vague assurances. Acceptable answers include:
- Encryption at rest and in transit
- ISO 27001 certification or other recognised security standards
- Two-factor authentication for staff with access
- Regular penetration testing and third‑party audits
- Incident response plan and timelines for notifying the school/parents
How long is data retained and how can it be deleted?
A retention policy should be clear and proportionate. Ask how long different categories of data are kept and the process to request deletion. Under UK GDPR, parents have rights to erasure and to restrict processing in some circumstances — make sure the school explains how those rights will be actioned with the provider.
Is parental consent required and how is it recorded?
Many schools treat educational processing as part of their duties and rely on legitimate interests or public task bases rather than consent. But when apps share data externally or process sensitive categories, explicit parental consent may be needed. Ask whether the school is seeking consent, how that consent will be documented, and whether there is a clear opt-out process that won’t penalise the child.
How does the app handle safeguarding and wellbeing?
AI can produce surprising outputs. Ask what safeguards exist to prevent inappropriate content, misinformation, or advice that might harm a child. Does the app flag safeguarding concerns to school staff? Is there human moderation and escalation? Are families informed promptly if concerning interactions are detected?
What measures prevent bias and ensure accuracy?
AI tutoring systems can reinforce misconceptions if they’re trained poorly. Ask the provider about:
- Testing across diverse pupil groups
- Mechanisms for teachers to review or correct AI feedback
- Transparency about model limitations and confidence scores
How will teachers and parents be involved and informed?
Good deployments treat AI as an assistant, not a replacement. Ask whether teachers receive training and whether parents can access summaries of progress. Find out who you contact with questions or complaints, and how the school audits the app’s educational value over time.
Will the app create inequalities?
AI tools can widen gaps if some pupils have better devices or home internet. Ask the school how they will ensure equitable access and whether use in class is balanced with provision for pupils who cannot use the app at home. Also ask whether the app is designed with accessibility needs in mind (screen readers, captioning).
What happens to data if the provider goes out of business?
It sounds like an edge case, but it’s important. Ask for exit and continuity plans: how will the school retain or retrieve pupil records? Is there a clause that returns or securely deletes data on contract termination?
| Quick checklist to ask for in writing |
|
You don’t need to be a privacy lawyer to ask these questions — they are reasonable and practical. If a school or provider balks at giving clear answers, treat that as a warning sign. At the same time, look for openness: providers who publish privacy policies, DPIA summaries and security audits are signalling they expect scrutiny. My final piece of advice is simple: insist on answers in writing, keep a copy, and ask for periodic reviews. The technology will keep changing — your child’s rights and safety shouldn’t be left to chance.