Procurement and privacy

AI Vendor and DPA Review Questions for School Districts

An AI vendor review should bind the exact product, account, purpose, data, model deployment, and enabled features to enforceable terms. A generic security packet or vendor-level DPA cannot answer every question about a specific district use.

Audience
District procurement, privacy, legal, security, technology, curriculum, accessibility, data governance, and application owners
Read time
14 min read
Published
Reviewed
Review
TrueMadeAI Engineering

Current status: These questions organize district review. They are not legal advice, contract language, or a determination under FERPA, COPPA, or state law.

A school district should review the exact AI deployment it will use, then put the approved boundary into the contract and DPA. The review must identify the product, account type, purpose, eligible users, data elements, model provider and route, enabled connectors and features, retention, training use, subprocessors, safeguards, incident duties, deletion, and exit rights.

This resource focuses on vendor and contract questions. It complements the broader AI tool vetting and approval template, which also covers instructional quality, testing, accessibility, human oversight, and the district decision.

Start with a deployment cover sheet

Before reading legal terms, make the vendor and district complete the same fact pattern.

Field Required answer
Vendor and contracting entity Legal name, product division, and contracting party
Product and feature Exact product, AI feature, version strategy, and administrative console
Account type Consumer, education, enterprise, API, or another named deployment
District purpose Specific educational or operational outcome
Eligible users Roles, grades, schools, departments, and service identities
Source data Systems, fields, documents, files, prompts, and metadata
Prohibited data Data and systems that may not be used
Model deployment Model provider, service, region, account, model family, and route
Connected services Plug-ins, repositories, search, tools, and downstream actions
Human responsibility Who reviews output and who makes the final decision
Term and scale Pilot or production, dates, user count, and volume
District owner Business or instructional owner plus technical owner

If the facts are unknown, contract review is premature. A clause cannot protect a data flow the parties have not identified.

1. Product and scope questions

Ask:

  1. Which legal entity provides the product and which entity signs the DPA?
  2. What exact product, account type, AI features, models, and regions are included?
  3. Which features are enabled by default, and which can a district administrator disable?
  4. Does the product add AI capabilities during the contract term without separate activation?
  5. Does the service use one model provider, several providers, or dynamic routing?
  6. Can the vendor change the model or provider without advance notice?
  7. Are consumer accounts, personal accounts, beta features, and third-party plug-ins excluded from the district agreement?
  8. Which documentation is incorporated into the contract, and can the vendor change it unilaterally?

Contract scope should match the district AI application register. Do not let a broad product name conceal several different data flows.

2. Purpose and authority questions

Ask the district and vendor to state:

  • the service or function being performed for the district;
  • the specific purposes for which data may be used;
  • prohibited secondary purposes;
  • whether the vendor acts only on district instructions for covered data;
  • which district role can change instructions or approve a new purpose;
  • how the arrangement supports any legal basis the district intends to rely on;
  • what happens when a user attempts an unapproved use.

When a district considers FERPA’s school official exception, it should determine with qualified counsel whether the specific arrangement meets the applicable conditions, including direct control and legitimate educational interest. A vendor statement that it is “FERPA ready” or similar does not make that determination for the district.

3. Data inventory questions

Require field-level or document-level answers where practical.

  1. What may a user type, paste, upload, record, photograph, or connect?
  2. What identifiers, account attributes, device data, logs, cookies, and telemetry are collected?
  3. Does the product receive rosters, grades, attendance, assignments, communications, support records, accommodations, or free text?
  4. Does it create new records, profiles, scores, labels, embeddings, summaries, or inferences about a person?
  5. Does retrieval search an entire repository or only approved folders and document sets?
  6. Are files, image metadata, filenames, revision histories, comments, and hidden document content processed?
  7. Which data are necessary for the approved purpose, and which can be removed?
  8. What data appear in administrator logs, support systems, analytics, or error traces?
  9. Can vendor personnel view inputs or outputs, and under which authorization and logging process?
  10. Can the district export a complete description of data held for its account?

Use the K-12 AI data-boundary framework to trace collection, transformation, provider processing, outputs, downstream use, evidence, and end of life.

4. Model training, improvement, and human review questions

Do not accept “no training” without a defined scope.

Ask:

  • Are district prompts, outputs, files, retrieved content, feedback, metadata, and derived data used to train or improve any model or service?
  • Does the answer differ by product, account type, setting, model provider, region, or support case?
  • Is the restriction a contract term, an administrator setting, a provider commitment, or a current practice?
  • Can the setting be changed by an end user, vendor administrator, model provider, or product update?
  • Are covered data used for abuse detection, security, debugging, evaluation, or human review?
  • If human review occurs, who performs it, where, for what purpose, under what access controls, and for how long?
  • Can the vendor create or retain evaluations, embeddings, de-identified datasets, or aggregate statistics from district activity?
  • What standard and process does the vendor use before claiming data are de-identified or anonymous?
  • Do the same restrictions bind every model provider and subprocessor?

The contract should distinguish service delivery, security operations, support, product analytics, evaluation, and model improvement. Broad phrases such as “improve our services” can hide materially different uses.

5. Retention and deletion questions

Ask for a lifecycle by data type:

Data type Questions
User content Default retention, configurable minimum, history controls, and deletion trigger
Provider logs Content and metadata retained, purpose, location, access, and expiry
Safety or abuse records Data included, decision owner, retention, and legal or security basis
Backups Backup period, restoration behavior, eventual deletion, and access
Support cases Copies, attachments, personnel access, and closure deletion
Derived data Embeddings, evaluations, labels, statistics, and linkability
Termination data Export format, return period, deletion certificate, and residual obligations

Clarify deletion from active systems, search indexes, connected repositories, caches, logs, backups, subprocessors, and restored backups. Require a schedule and accountable process rather than an absolute claim that every copy disappears instantly.

6. Access, correction, and records questions

Ask:

  1. How can the district find, access, export, correct, restrict, and delete covered records?
  2. Can the district respond to a parent or eligible student request for records maintained on its behalf?
  3. What identity verification and district authorization are required?
  4. Are AI-generated profiles, summaries, labels, or recommendations included in export and correction processes?
  5. Can the vendor place a hold or preserve records when the district lawfully requires it?
  6. Who owns district inputs, outputs, configurations, and custom materials?
  7. What license does the vendor receive, and does it end when the service purpose ends?
  8. Which records can the district retrieve after suspension or termination?

The U.S. Department of Education recommends clear contract provisions for data access, use, retention, disclosure, destruction, security, modification, duration, and termination in online educational service arrangements.

7. Subprocessor and data-location questions

Require a current list that identifies:

  • legal entity and service;
  • function performed;
  • data categories processed;
  • processing and storage locations;
  • model-provider role;
  • effective date;
  • link to relevant privacy or security information.

Ask how the vendor performs diligence, flows contract terms down, monitors subprocessors, and responds to a material change. Define advance notice, a district review period, an objection path, and termination or transition rights when a new subprocessor changes the risk.

8. Security and product-security questions

Independent reports can support due diligence. They do not answer every product-security question.

Ask:

  • Does the product support district single sign-on, multifactor authentication, role-based administration, and prompt deprovisioning?
  • How are tenant boundaries designed, tested, and monitored?
  • What content, configuration, and administrative actions appear in audit logs?
  • Can district administrators export logs without vendor assistance?
  • How does the vendor manage vulnerabilities in the product and dependencies?
  • What is the vulnerability disclosure process and remediation policy?
  • Are security features available by default and without an added fee?
  • How does the vendor prevent cross-tenant retrieval, unintended data exposure, and unauthorized tool use?
  • How are model prompt manipulation, unsafe file processing, and exposed credentials addressed?
  • Which independent assessments cover the actual product and period in scope?
  • How can the district disable the AI feature, revoke credentials, isolate an integration, or export data during an incident?
  • How often are recovery and incident procedures exercised?

CISA’s Secure by Demand guide recommends that software customers examine product security, not only the vendor’s enterprise controls or general compliance reports.

9. Incident and notification questions

Define “incident” broadly enough to cover the approved use. Questions should include:

  1. What events trigger notice to the district?
  2. Does notice cover unauthorized access, disclosure, loss, misuse, cross-tenant exposure, model-provider incidents, and material failures of agreed controls?
  3. When does the notification clock begin, and what is the outside deadline?
  4. Which named district contact and backup contact receive notice?
  5. What facts are included in the first notice and later updates?
  6. Will the vendor preserve relevant evidence and provide a timeline, affected data, affected people, containment, and corrective action?
  7. Who coordinates communications to families, regulators, insurers, law enforcement, and the public?
  8. Can the vendor notify affected people directly without district authorization?
  9. What cooperation, costs, and services are provided?
  10. How are subprocessor incidents handled?

Align these answers to the district’s K-12 AI incident response playbook. A DPA notice clause is not a complete response plan.

10. AI behavior and change-management questions

Contracts cannot guarantee correct model output, but they can establish responsibilities and change controls.

Ask:

  • What known limitations apply to the intended users, languages, subjects, and tasks?
  • Which evaluation evidence is available for conditions similar to the district use?
  • How does the vendor communicate a model, safety-policy, retrieval, or moderation change?
  • Can the district pin or validate a model version or receive release notes?
  • What happens when a feature begins taking actions, connecting to new data, or producing a new type of output?
  • Can the district test changes before broad rollout?
  • Which administrator controls, rollback options, and disable paths exist?
  • How can users report inaccurate, harmful, discriminatory, or inaccessible behavior?
  • What correction, appeal, and support processes exist?

Define material changes in both the contract and approval record. Reopen district review when the purpose, user group, data, model route, provider terms, tools, action capability, or observed performance changes.

11. Accessibility and implementation questions

Ask for evidence about keyboard access, screen-reader behavior, captions, contrast, language access, cognitive load, assistive-technology compatibility, known defects, remediation timelines, and support.

Clarify:

  • whether accessibility documentation covers the current AI feature;
  • how the district reports a barrier and receives status updates;
  • whether a non-AI or alternate workflow is available;
  • which party trains users and administrators;
  • whether implementation requires sharing disability or accommodation records with the vendor.

Use AI, accommodations, and student privacy to separate an instructional support from the records used to implement it.

12. Pricing, renewal, and exit questions

Ask:

  1. Which AI features, security controls, logs, support, and data exports are included in the price?
  2. Are usage limits, model rates, storage, or support costs variable?
  3. Can the vendor use district content or activity to create a lock-in dependency?
  4. What notice applies to price, feature, model, or term changes?
  5. Can the district export data and configuration in a documented, usable format?
  6. How long does transition access remain available?
  7. Who removes integrations, credentials, connectors, and local copies?
  8. What deletion and certification evidence is provided?
  9. Which obligations survive termination?
  10. What assistance is available if the product is discontinued or materially changed?

Contract red flags that require resolution

Pause or escalate when:

  • the DPA does not identify the exact product or account;
  • the vendor may use covered data for any business purpose;
  • “no training” excludes metadata, feedback, derived data, or a model provider without explanation;
  • retention is indefinite or controlled only by each end user;
  • material terms can change by posting a new webpage with no district remedy;
  • subprocessors are undisclosed or can change without notice;
  • security obligations are limited to a general certification unrelated to the product;
  • incident notice has no deadline, content, or cooperation duty;
  • the vendor can contact students or families for advertising or unrelated commercial purposes;
  • deletion excludes derived data or active indexes without explanation;
  • the district cannot export records maintained on its behalf;
  • a consequential AI feature has no human-review or disable process;
  • termination removes district access before export and transition are complete.

A red flag is a question to resolve, not an automatic legal conclusion. Document the vendor answer, district reviewer, accepted condition, and remaining risk.

A concise decision record

End review with one page that states:

  • use and accountable owner;
  • exact deployment and term;
  • approved users and purposes;
  • approved and prohibited data;
  • provider and model route;
  • training, retention, deletion, and subprocessor terms;
  • security and incident commitments;
  • accessibility and human-review conditions;
  • open risks and compensating controls;
  • approvers, expiry, and material-change triggers;
  • disable, export, and exit path.

The contract, DPA, security packet, and decision record should agree. If they describe different products or boundaries, the district does not yet have a complete approval.

Frequently asked questions

What should a school district ask an AI vendor before signing a DPA?

Ask about the exact product and account, approved purpose, data elements, collection paths, model provider, training and improvement use, retention, deletion, subprocessors, security, incidents, access, audit evidence, product changes, accessibility, termination, and enforceable contract terms.

Is a data protection agreement enough to approve an AI tool?

No. A DPA is one part of review. The district also needs to evaluate the intended educational or operational use, actual data flow, configured deployment, accessibility, quality, security, human responsibility, implementation, and applicable requirements.

What does no training mean in an AI contract?

The phrase should identify which district inputs, outputs, files, metadata, feedback, and derived data are excluded, which models or services are covered, whether human review occurs, how the configuration is enforced, and what exceptions remain.

Should a district accept a vendor’s standard consumer terms for student use?

Do not assume consumer terms fit district use. Compare the exact account’s age eligibility, data practices, retention, training use, advertising, administrative controls, deletion, support, and contract authority with district requirements.

How should a district review changes to an AI vendor or model?

The agreement and approval record should define material changes, advance notice, evidence review, district objection or termination rights, revalidation, and what happens if a model, provider, feature, data use, subprocessor, or term changes.

Sources

This resource is educational information, not legal advice or a substitute for district-specific privacy, security, procurement, accessibility, instructional, and legal review.

Choose your Tenet path

Start with one district baseline. Add context when you need it.

Tenet Basic is free. Tenet District adds roster, classroom, teacher, grade, and schedule context.