Current status: These questions organize district review. They are not legal advice, contract language, or a determination under FERPA, COPPA, or state law.
A school district should review the exact AI deployment it will use, then put the approved boundary into the contract and DPA. The review must identify the product, account type, purpose, eligible users, data elements, model provider and route, enabled connectors and features, retention, training use, subprocessors, safeguards, incident duties, deletion, and exit rights.
This resource focuses on vendor and contract questions. It complements the broader AI tool vetting and approval template, which also covers instructional quality, testing, accessibility, human oversight, and the district decision.
Start with a deployment cover sheet
Before reading legal terms, make the vendor and district complete the same fact pattern.
| Field | Required answer |
|---|---|
| Vendor and contracting entity | Legal name, product division, and contracting party |
| Product and feature | Exact product, AI feature, version strategy, and administrative console |
| Account type | Consumer, education, enterprise, API, or another named deployment |
| District purpose | Specific educational or operational outcome |
| Eligible users | Roles, grades, schools, departments, and service identities |
| Source data | Systems, fields, documents, files, prompts, and metadata |
| Prohibited data | Data and systems that may not be used |
| Model deployment | Model provider, service, region, account, model family, and route |
| Connected services | Plug-ins, repositories, search, tools, and downstream actions |
| Human responsibility | Who reviews output and who makes the final decision |
| Term and scale | Pilot or production, dates, user count, and volume |
| District owner | Business or instructional owner plus technical owner |
If the facts are unknown, contract review is premature. A clause cannot protect a data flow the parties have not identified.
1. Product and scope questions
Ask:
- Which legal entity provides the product and which entity signs the DPA?
- What exact product, account type, AI features, models, and regions are included?
- Which features are enabled by default, and which can a district administrator disable?
- Does the product add AI capabilities during the contract term without separate activation?
- Does the service use one model provider, several providers, or dynamic routing?
- Can the vendor change the model or provider without advance notice?
- Are consumer accounts, personal accounts, beta features, and third-party plug-ins excluded from the district agreement?
- Which documentation is incorporated into the contract, and can the vendor change it unilaterally?
Contract scope should match the district AI application register. Do not let a broad product name conceal several different data flows.
2. Purpose and authority questions
Ask the district and vendor to state:
- the service or function being performed for the district;
- the specific purposes for which data may be used;
- prohibited secondary purposes;
- whether the vendor acts only on district instructions for covered data;
- which district role can change instructions or approve a new purpose;
- how the arrangement supports any legal basis the district intends to rely on;
- what happens when a user attempts an unapproved use.
When a district considers FERPA’s school official exception, it should determine with qualified counsel whether the specific arrangement meets the applicable conditions, including direct control and legitimate educational interest. A vendor statement that it is “FERPA ready” or similar does not make that determination for the district.
3. Data inventory questions
Require field-level or document-level answers where practical.
- What may a user type, paste, upload, record, photograph, or connect?
- What identifiers, account attributes, device data, logs, cookies, and telemetry are collected?
- Does the product receive rosters, grades, attendance, assignments, communications, support records, accommodations, or free text?
- Does it create new records, profiles, scores, labels, embeddings, summaries, or inferences about a person?
- Does retrieval search an entire repository or only approved folders and document sets?
- Are files, image metadata, filenames, revision histories, comments, and hidden document content processed?
- Which data are necessary for the approved purpose, and which can be removed?
- What data appear in administrator logs, support systems, analytics, or error traces?
- Can vendor personnel view inputs or outputs, and under which authorization and logging process?
- Can the district export a complete description of data held for its account?
Use the K-12 AI data-boundary framework to trace collection, transformation, provider processing, outputs, downstream use, evidence, and end of life.
4. Model training, improvement, and human review questions
Do not accept “no training” without a defined scope.
Ask:
- Are district prompts, outputs, files, retrieved content, feedback, metadata, and derived data used to train or improve any model or service?
- Does the answer differ by product, account type, setting, model provider, region, or support case?
- Is the restriction a contract term, an administrator setting, a provider commitment, or a current practice?
- Can the setting be changed by an end user, vendor administrator, model provider, or product update?
- Are covered data used for abuse detection, security, debugging, evaluation, or human review?
- If human review occurs, who performs it, where, for what purpose, under what access controls, and for how long?
- Can the vendor create or retain evaluations, embeddings, de-identified datasets, or aggregate statistics from district activity?
- What standard and process does the vendor use before claiming data are de-identified or anonymous?
- Do the same restrictions bind every model provider and subprocessor?
The contract should distinguish service delivery, security operations, support, product analytics, evaluation, and model improvement. Broad phrases such as “improve our services” can hide materially different uses.
5. Retention and deletion questions
Ask for a lifecycle by data type:
| Data type | Questions |
|---|---|
| User content | Default retention, configurable minimum, history controls, and deletion trigger |
| Provider logs | Content and metadata retained, purpose, location, access, and expiry |
| Safety or abuse records | Data included, decision owner, retention, and legal or security basis |
| Backups | Backup period, restoration behavior, eventual deletion, and access |
| Support cases | Copies, attachments, personnel access, and closure deletion |
| Derived data | Embeddings, evaluations, labels, statistics, and linkability |
| Termination data | Export format, return period, deletion certificate, and residual obligations |
Clarify deletion from active systems, search indexes, connected repositories, caches, logs, backups, subprocessors, and restored backups. Require a schedule and accountable process rather than an absolute claim that every copy disappears instantly.
6. Access, correction, and records questions
Ask:
- How can the district find, access, export, correct, restrict, and delete covered records?
- Can the district respond to a parent or eligible student request for records maintained on its behalf?
- What identity verification and district authorization are required?
- Are AI-generated profiles, summaries, labels, or recommendations included in export and correction processes?
- Can the vendor place a hold or preserve records when the district lawfully requires it?
- Who owns district inputs, outputs, configurations, and custom materials?
- What license does the vendor receive, and does it end when the service purpose ends?
- Which records can the district retrieve after suspension or termination?
The U.S. Department of Education recommends clear contract provisions for data access, use, retention, disclosure, destruction, security, modification, duration, and termination in online educational service arrangements.
7. Subprocessor and data-location questions
Require a current list that identifies:
- legal entity and service;
- function performed;
- data categories processed;
- processing and storage locations;
- model-provider role;
- effective date;
- link to relevant privacy or security information.
Ask how the vendor performs diligence, flows contract terms down, monitors subprocessors, and responds to a material change. Define advance notice, a district review period, an objection path, and termination or transition rights when a new subprocessor changes the risk.
8. Security and product-security questions
Independent reports can support due diligence. They do not answer every product-security question.
Ask:
- Does the product support district single sign-on, multifactor authentication, role-based administration, and prompt deprovisioning?
- How are tenant boundaries designed, tested, and monitored?
- What content, configuration, and administrative actions appear in audit logs?
- Can district administrators export logs without vendor assistance?
- How does the vendor manage vulnerabilities in the product and dependencies?
- What is the vulnerability disclosure process and remediation policy?
- Are security features available by default and without an added fee?
- How does the vendor prevent cross-tenant retrieval, unintended data exposure, and unauthorized tool use?
- How are model prompt manipulation, unsafe file processing, and exposed credentials addressed?
- Which independent assessments cover the actual product and period in scope?
- How can the district disable the AI feature, revoke credentials, isolate an integration, or export data during an incident?
- How often are recovery and incident procedures exercised?
CISA’s Secure by Demand guide recommends that software customers examine product security, not only the vendor’s enterprise controls or general compliance reports.
9. Incident and notification questions
Define “incident” broadly enough to cover the approved use. Questions should include:
- What events trigger notice to the district?
- Does notice cover unauthorized access, disclosure, loss, misuse, cross-tenant exposure, model-provider incidents, and material failures of agreed controls?
- When does the notification clock begin, and what is the outside deadline?
- Which named district contact and backup contact receive notice?
- What facts are included in the first notice and later updates?
- Will the vendor preserve relevant evidence and provide a timeline, affected data, affected people, containment, and corrective action?
- Who coordinates communications to families, regulators, insurers, law enforcement, and the public?
- Can the vendor notify affected people directly without district authorization?
- What cooperation, costs, and services are provided?
- How are subprocessor incidents handled?
Align these answers to the district’s K-12 AI incident response playbook. A DPA notice clause is not a complete response plan.
10. AI behavior and change-management questions
Contracts cannot guarantee correct model output, but they can establish responsibilities and change controls.
Ask:
- What known limitations apply to the intended users, languages, subjects, and tasks?
- Which evaluation evidence is available for conditions similar to the district use?
- How does the vendor communicate a model, safety-policy, retrieval, or moderation change?
- Can the district pin or validate a model version or receive release notes?
- What happens when a feature begins taking actions, connecting to new data, or producing a new type of output?
- Can the district test changes before broad rollout?
- Which administrator controls, rollback options, and disable paths exist?
- How can users report inaccurate, harmful, discriminatory, or inaccessible behavior?
- What correction, appeal, and support processes exist?
Define material changes in both the contract and approval record. Reopen district review when the purpose, user group, data, model route, provider terms, tools, action capability, or observed performance changes.
11. Accessibility and implementation questions
Ask for evidence about keyboard access, screen-reader behavior, captions, contrast, language access, cognitive load, assistive-technology compatibility, known defects, remediation timelines, and support.
Clarify:
- whether accessibility documentation covers the current AI feature;
- how the district reports a barrier and receives status updates;
- whether a non-AI or alternate workflow is available;
- which party trains users and administrators;
- whether implementation requires sharing disability or accommodation records with the vendor.
Use AI, accommodations, and student privacy to separate an instructional support from the records used to implement it.
12. Pricing, renewal, and exit questions
Ask:
- Which AI features, security controls, logs, support, and data exports are included in the price?
- Are usage limits, model rates, storage, or support costs variable?
- Can the vendor use district content or activity to create a lock-in dependency?
- What notice applies to price, feature, model, or term changes?
- Can the district export data and configuration in a documented, usable format?
- How long does transition access remain available?
- Who removes integrations, credentials, connectors, and local copies?
- What deletion and certification evidence is provided?
- Which obligations survive termination?
- What assistance is available if the product is discontinued or materially changed?
Contract red flags that require resolution
Pause or escalate when:
- the DPA does not identify the exact product or account;
- the vendor may use covered data for any business purpose;
- “no training” excludes metadata, feedback, derived data, or a model provider without explanation;
- retention is indefinite or controlled only by each end user;
- material terms can change by posting a new webpage with no district remedy;
- subprocessors are undisclosed or can change without notice;
- security obligations are limited to a general certification unrelated to the product;
- incident notice has no deadline, content, or cooperation duty;
- the vendor can contact students or families for advertising or unrelated commercial purposes;
- deletion excludes derived data or active indexes without explanation;
- the district cannot export records maintained on its behalf;
- a consequential AI feature has no human-review or disable process;
- termination removes district access before export and transition are complete.
A red flag is a question to resolve, not an automatic legal conclusion. Document the vendor answer, district reviewer, accepted condition, and remaining risk.
A concise decision record
End review with one page that states:
- use and accountable owner;
- exact deployment and term;
- approved users and purposes;
- approved and prohibited data;
- provider and model route;
- training, retention, deletion, and subprocessor terms;
- security and incident commitments;
- accessibility and human-review conditions;
- open risks and compensating controls;
- approvers, expiry, and material-change triggers;
- disable, export, and exit path.
The contract, DPA, security packet, and decision record should agree. If they describe different products or boundaries, the district does not yet have a complete approval.
Frequently asked questions
What should a school district ask an AI vendor before signing a DPA?
Ask about the exact product and account, approved purpose, data elements, collection paths, model provider, training and improvement use, retention, deletion, subprocessors, security, incidents, access, audit evidence, product changes, accessibility, termination, and enforceable contract terms.
Is a data protection agreement enough to approve an AI tool?
No. A DPA is one part of review. The district also needs to evaluate the intended educational or operational use, actual data flow, configured deployment, accessibility, quality, security, human responsibility, implementation, and applicable requirements.
What does no training mean in an AI contract?
The phrase should identify which district inputs, outputs, files, metadata, feedback, and derived data are excluded, which models or services are covered, whether human review occurs, how the configuration is enforced, and what exceptions remain.
Should a district accept a vendor’s standard consumer terms for student use?
Do not assume consumer terms fit district use. Compare the exact account’s age eligibility, data practices, retention, training use, advertising, administrative controls, deletion, support, and contract authority with district requirements.
How should a district review changes to an AI vendor or model?
The agreement and approval record should define material changes, advance notice, evidence review, district objection or termination rights, revalidation, and what happens if a model, provider, feature, data use, subprocessor, or term changes.
Sources
- Protecting Student Privacy While Using Online Educational Services: Model Terms of Service, U.S. Department of Education
- Protecting Student Privacy While Using Online Educational Services, U.S. Department of Education
- Complying with COPPA: Frequently Asked Questions, Federal Trade Commission
- Secure by Demand Guide, CISA and FBI
This resource is educational information, not legal advice or a substitute for district-specific privacy, security, procurement, accessibility, instructional, and legal review.