Federal privacy

COPPA and AI Chatbots in Elementary and Middle School: When the School Can Consent

A school can stand in for a parent under COPPA, but only inside narrow limits: the collection must be for the use and benefit of the school and no other commercial purpose, the vendor must give the school direct notice and a review-and-delete path, and the vendor cannot push COPPA compliance onto the district. Most consumer AI chatbots fail that test before the question of consent is even reached.

Audience
District privacy officers, technology directors, elementary and middle school leaders, curriculum teams, and school counsel
Read time
13 min read
Published
Reviewed
Review
TrueMadeAI Engineering
Review scope
Mapping of the FTC school-authorization conditions to district approval, notice, retention, and enforcement workflows

Current status: Last reviewed September 7, 2026. This resource quotes the FTC's COPPA guidance, the 2022 education technology policy statement, the 2025 COPPA Rule amendments, and the FERPA school official regulation as read on that date. It is not legal advice. A district's consent decisions belong with counsel and the responsible administrator.

A fourth-grade teacher wants to use an AI tutor with her class. Nobody in the building can answer whether the district is allowed to say yes. The vendor’s website says it is COPPA compliant. The teacher has already made accounts. The privacy officer has a vague memory that schools can consent for parents. Everyone is half right, and the half that is wrong is the expensive half.

This page is the decision flow. It uses the Federal Trade Commission’s own words about when a school may authorize collection from a child under 13, walks the four questions that decide the answer, and marks the traps that catch districts after the decision looks settled. It covers COPPA specifically. FERPA, state student-privacy law, and the vendor’s own age terms are separate gates, and a tool must pass all of them.

If you would rather work from the district templates than from prose, the tool vetting template, the application register, and the acceptable-use checklist are in the free district AI governance starter kit.

Start here: three gates, not one

Before any consent question, an AI tool for elementary or middle school has to clear three separate gates. Districts routinely argue about the third while failing the first.

Gate The question Where the answer lives
1. The vendor’s own terms Does this product admit a student of this age at all, and on what account type? The vendor’s terms of use and education documentation. The AI product age and consent table records this for thirteen products
2. COPPA May the school authorize collection of personal information from a student under 13 instead of the parent? This page
3. FERPA and state law Does the vendor qualify as a school official, and do state student-privacy rules add notice, agreement, or opt-out duties? The last two sections of this page, plus the state laws and guidance tracker

Gate 1 fails more often than people expect. A school cannot lower a vendor’s age floor by signing up on a student’s behalf. If a product’s terms say 13 and older, or 18 and older, school authorization does not create eligibility; it only substitutes for parental consent in products built to accept students under a school agreement.

The COPPA decision flow

COPPA requires verifiable parental consent before an operator collects personal information from a child under 13. The FTC’s guidance describes a narrow substitute: in the educational context, the school may act as the parent’s agent. Four questions decide whether that substitute is available. A “no” at any point ends the analysis.

Question 1: Is the collection for the use and benefit of the school, and nothing else?

The FTC states that a school’s ability to consent for the parent “is limited to the educational context, where an operator collects personal information from students for the use and benefit of the school, and for no other commercial purpose.”

This is where most consumer AI products fail. If the tool uses student prompts to improve its own models, to build profiles, to personalize advertising, or for any purpose beyond delivering the educational service the district asked for, the collection is not exclusively for the school’s benefit.

Practical test: read the training and product-improvement clause in the plan the district will actually buy, not the marketing page. Ask whether student inputs may be used for anything other than returning an answer to that student.

Question 2: Does the vendor give the school what a parent would get?

The FTC requires that the operator “must provide the school with the same type of direct notice regarding its practices as to the collection, use, or disclosure of personal information from children as it would otherwise provide to the parent.” The school must also be able, on request, to review the child’s personal information, have it deleted, and prevent further use or collection.

If the vendor cannot show the district what it collects, cannot delete a specific student’s data on request, and cannot stop collecting for a specific student, then, in the FTC’s framing, the school cannot consent.

Question 3: Is the decision being made at the right level?

The FTC recommends “that schools or school districts decide whether a particular site’s or service’s information practices are appropriate, rather than delegating that decision to the teacher.” It also notes the consent method must be reasonably calculated to ensure a school is actually providing consent, “and not a child pretending to be a teacher.”

A district that has no approval workflow has, in practice, delegated the decision to whoever creates the account first. That is the failure mode the AI tool vetting and approval template exists to close.

Question 4: Do the disqualifiers apply?

The FTC names two specific disqualifiers. If the operator uses student personal information “in connection with online behavioral advertising, or building user profiles for commercial purposes not related to the provision of the online service,” the school cannot consent. If the operator does not enable the school to review and delete the personal information, the school cannot consent.

If all four answers hold, school authorization is available. The district should then record the decision, the notice it received, the retention terms, and the review-and-delete path, and it should consider telling parents which services it has authorized. The FTC suggests that schools consider providing parents with a notice of the sites and services whose collection the school has consented to on the parent’s behalf.

What the vendor owes, in the FTC’s words

The 2022 policy statement on education technology sets four limits that apply whenever a vendor collects under school authorization:

  • No mandatory over-collection. Vendors “must not condition participation in any activity on a child disclosing more information than is reasonably necessary for the child to participate.”
  • Use limited to the service. Providers “may use such information only to provide the requested online education service.”
  • Retention limits. Vendors “must not retain personal information collected from a child longer than reasonably necessary to fulfill the purpose for which it was collected.”
  • Security. Vendors must maintain confidentiality, security, and integrity, and the FTC states that even absent a breach, providers violate COPPA if they lack reasonable security.

The statement also settles who carries the obligation: “The responsibility for COPPA compliance is on businesses, not schools or parents, and agreements must reflect that.” The FTC’s FAQ says operators should not state in terms of service or anywhere else that the school is responsible for complying with COPPA. In 2023 the FTC applied that principle in the Edmodo matter, saying ed tech providers cannot outsource compliance responsibilities to schools, and that the company could not rely on school authorization because it used the information to serve advertising.

What changed in the 2025 amendments, and what did not

The amended COPPA Rule was published on April 22, 2025, took effect June 23, 2025, and carried a compliance date of April 22, 2026 for most provisions. Three changes matter for AI tools:

  • Separate consent for third-party disclosure. The amendments clarify that operators must obtain separate verifiable parental consent for disclosures to third parties. An AI vendor that passes student text to a model provider it does not control should be able to explain where that sits.
  • A written information security program. Operators must establish, implement, and maintain a written program with safeguards appropriate to the sensitivity of the information, a designated coordinator, and at least annual risk assessments.
  • A written retention policy. Personal information collected online from a child may not be retained indefinitely. The operator must maintain a written data retention policy stating the purposes, the business need, and a timeframe for deletion, and publish it in its online notice.

What did not change is the part districts most often assume did. The Commission stated that to avoid conflicting with potential amendments to the Department of Education’s FERPA regulations, it “is not finalizing the proposed amendments to the Rule related to ed tech and the role of schools at this time,” and that it “will continue to enforce COPPA in the ed tech context consistent with its existing guidance.” School authorization is still a guidance-based practice, not codified rule text.

Separately, in September 2025 the FTC issued orders to seven companies operating consumer AI chatbots, seeking information on how they measure and monitor negative impacts on children and teens and whether they comply with the COPPA Rule. That inquiry is a signal about consumer companion-style chatbots rather than a finding about any product.

FERPA is a separate gate

COPPA governs collection from children under 13. FERPA governs education records. A tool can satisfy one and fail the other.

Under the school official exception, an outside party may receive personally identifiable information from education records without consent only if it performs an institutional service or function for which the district would otherwise use employees, is under the direct control of the district with respect to the use and maintenance of education records, uses the information only for authorized purposes, and does not redisclose it. The district must also use reasonable methods to ensure the official gets access only to records in which it has legitimate educational interests, and the vendor must meet the criteria in the district’s annual FERPA notification.

Two AI-specific failure points follow. A vendor that reserves the right to use inputs for its own product development is not under the district’s direct control for that use. A vendor that passes education-record content to a subprocessor without contractual limits has a redisclosure problem. The FERPA and AI guide covers this in depth, and the vendor and DPA review questions turn it into contract language.

One clarification worth making with counsel: the Department of Education has not published FERPA guidance specific to artificial intelligence. Its student-privacy site offers training scenarios, and its 2025 letter on AI in schools mentions attention to user privacy, but a district should not describe an ED position on AI that does not exist.

The state layer

Federal law is the floor. Several states add duties that change the answer for the same product:

  • California prohibits an operator of a K-12 site or service from targeted advertising, amassing a profile except for school purposes, selling student information, or disclosing covered information outside listed purposes.
  • New York requires a parents bill of rights stating that student personally identifiable information cannot be sold or released for commercial purposes and that parents may inspect and review their child’s record.
  • Illinois requires a written agreement before covered information is transferred to an operator, and requires the school to post a list of operators it has agreements with, plus the agreements.
  • Texas bars targeted advertising, profiles other than for school purposes, and selling or renting student covered information.
  • Oklahoma gives parents an opt-out from student-facing AI tools and requires annual disclosure of tools and vendors, effective July 1, 2026.
  • Florida has proposed a rule that would require parent opt-in and a public approved-tool list, with a July 1, 2027 deadline if adopted.

The state laws and guidance tracker keeps these current, and the Oklahoma and Florida guides work through the two consent models in detail.

Ten traps

  1. A teacher signs the class up on a consumer account. There is no district agreement, so there is no agency relationship for the school to consent through, and the vendor’s own age terms are usually being broken at the same time.
  2. The vendor’s terms say 13 and older, and the district authorizes younger students anyway. School authorization substitutes for parental consent; it does not create eligibility the vendor’s terms deny.
  3. The terms or the data agreement make the school responsible for COPPA compliance. The FTC says that is the operator’s responsibility.
  4. Consent is obtained, then student prompts are used for model training, product improvement, advertising, or profiling. That is outside the use and benefit of the school.
  5. The vendor cannot review or delete one student’s data on request. The FTC says the school cannot consent in that case.
  6. Chat logs are retained indefinitely or past the educational need, with no published retention timeframe.
  7. The district assumes the 2025 amendments codified a school exception. They did not.
  8. COPPA is satisfied but FERPA is not, because the vendor is not under district control or redisclosed to a subprocessor.
  9. A state overlay is missed: a written agreement and public posting in Illinois, annual disclosure and opt-out in Oklahoma, opt-in if Florida adopts its rule.
  10. The product has companion or relationship-style features. Those are drawing regulatory attention, and Florida’s proposed rule would bar them outright in K-12.

After the decision: making it hold

An approval decision is a promise about what will happen thousands of times a day in classrooms. Two things make it hold.

The first is a record. The decision, the vendor notice, the retention terms, the review-and-delete path, the grade bands, and the review date belong in the AI application register, not in an email thread.

The second is enforcement at the moment of use. Consent limits what a vendor may do with information it receives. It does nothing about what a nine-year-old types into the box. The most common privacy incident in a district is not a vendor violating its agreement; it is a student or a staff member pasting something into an approved tool that should never have left the building.

That is the layer Tenet by TrueMadeAI provides. Tenet Edge applies district and classroom policy on supported direct-use AI surfaces on managed Chrome, runs supported on-device data-loss-prevention checks before student text leaves the device, and can block detected unapproved AI chat and writing interfaces when the district enables that control. It does not decide whether a vendor qualifies for school authorization, and it does not cover every product surface; the dated capability matrix records exactly what is supported and where the boundaries are.

Tenet Basic is free and applies one district-wide baseline without roster setup. Try Tenet Basic, or request a Tenet District conversation to map grade-band rules for elementary and middle school.

What this page does not establish

This page does not determine:

  • whether a specific product qualifies for school authorization in your district;
  • that COPPA compliance satisfies FERPA, state law, or a vendor’s own terms;
  • that a vendor’s public statement matches the contract you sign;
  • that the FTC’s guidance will not change; or
  • that a technical control substitutes for a consent decision.

Those conclusions require the current official sources, the district’s facts, and qualified review.

Sources

Frequently asked questions

Sometimes. The FTC says a school’s ability to consent for the parent is limited to the educational context, where an operator collects personal information from students for the use and benefit of the school and for no other commercial purpose. If the tool uses student information for advertising, profiling, or its own product purposes, or gives the school no way to review and delete, the school cannot consent.

Can a teacher decide to sign a class up for an AI tool?

The FTC recommends that schools or school districts decide whether a site’s information practices are appropriate rather than delegating that decision to the teacher. A teacher signing up a class on a consumer account also usually breaks the vendor’s own age terms, which school authorization cannot override.

No. The Commission stated it is not finalizing the proposed amendments related to education technology and the role of schools, to avoid conflicting with potential FERPA rulemaking, and said it will continue to enforce COPPA in the ed tech context consistent with its existing guidance. School authorization still rests on the FTC’s FAQ and the 2022 policy statement.

No. They are separate. FERPA’s school official exception requires that the vendor perform a service the district would otherwise use employees for, remain under the district’s direct control over the use and maintenance of education records, use the information only for authorized purposes, and not redisclose it. A tool can clear COPPA and still fail that test.

Can a vendor make the school responsible for COPPA compliance in its terms?

No. The FTC states that operators should not say in terms of service or anywhere else that the school is responsible for complying with COPPA, because compliance is the operator’s responsibility. The 2023 Edmodo order made the same point in enforcement.

How long may an AI vendor keep a student’s chat history?

Under the amended rule, personal information collected online from a child may not be retained indefinitely, and the operator must maintain a written retention policy with a timeframe for deletion, published in its online notice. The FTC’s education technology statement adds that information must not be retained longer than reasonably necessary for the purpose it was collected.

After the consent decision

A consent decision only holds if the wrong data never leaves the device.

Tenet Basic is free. It applies one district baseline on supported AI products on managed Chrome and runs supported on-device checks before student text reaches a vendor.

Free district starter kit

Start governing AI this week, not next budget cycle.

The four working documents district leaders ask us for most, sent to your work email. No product setup and no sales call required.

  • AI governance readiness assessmentScore your district across decision rights, inventory, privacy, instruction, controls, and evidence.
  • AI tool vetting and approval templateThe questions to ask before an AI product reaches students or staff.
  • AI application register templateOne place to record every approved AI surface, owner, data boundary, and review date.
  • K-12 AI acceptable use policy checklistWhat a defensible student and staff AI policy must cover.