
Further education and skills providers are rapidly adopting artificial intelligence into everyday tasks, from lesson planning and learner support tools to timetabling, assessment support and workforce administration. As this reliance on AI grows, so does the need for robust data protection services to keep learner and staff information secure. This uptick in use is not likely to stall any time soon, either - the UK Government's Post-16 Education and Skills White Paper, published in October 2025, signals that AI use across England's education and skills sector will keep expanding.
The pace of adoption is outstripping, in many cases, the governance built to support it. As a result, providers are increasingly finding themselves asking the same set of questions: what personal data is going into these tools, where does it end up, who can see it, and how long is it kept? When a third-party AI supplier is involved, where does responsibility for compliance actually sit? And can the organisation explain clearly to learners and staff when AI is being used and what happens to their information as a result?
These questions tend to surface late, often reactively - once a tool is already in use - rather than proactively, before it's introduced. Getting ahead of these issues is a vital aspect of governance, both for compliance and for maintaining learner and staff trust.
Five priorities for FE/skills providers using AI
Adopting AI does not change a provider's obligations under UK data protection law. Wherever an AI tool processes personal data, the UK GDPR and Data Protection Act 2018 apply, including the amendments introduced by the Data Use and Access Act 2025. Five areas in particular are essential when a provider is introducing or already using AI tools.
Build governance in before deployment, not after
AI governance work is the foundation for other priorities. and is the best place to start.
Every AI tool should be assessed before it's introduced, not once it's already processing learner or staff data. A clear approval process should establish who owns that decision, what checks are required, and who monitors the tool once it's live.
Part of that is screening for whether a Data Protection Impact Assessment (DPIA) is required, and completing one before processing begins if the tool is likely to create a high risk to people's rights and freedoms. Where a DPIA isn't needed, that reasoning should still be recorded. An AI Impact Assessment can sit alongside a DPIA and look at broader questions of fairness, bias and explainability, but it doesn't replace a DPIA where one is legally required.
Supplier due diligence deserves equal weight. Before any contract is signed, providers should establish where supplier data will be stored and transferred, whether it's used to train the supplier's models, how long it's retained, what security and accountability commitments are written into the contract, and how data is deleted once the relationship ends.
All of this should sit within a clear internal AI policy setting out which tools are approved, who can use them, what information must never be entered, who can sign off new tools and uses, and how staff should report concerns.
Train staff for their specific role, not AI in general
A policy only works if staff understand how it applies to their day-to-day work. Training should help staff recognise the privacy implications of what they're entering into AI tools, spot and challenge unreliable or biased outputs, protect personal data appropriately, and know when human judgement needs to override an AI-generated response.
That training needs to be tailored. A curriculum leader using AI to plan lessons has different needs from a data manager analysing learner outcomes, or an administrator drafting learner communications with AI assistance.
With approval and training processes in place, the next step is one of understanding.
Identify how learner data moves through AI tools
Before any AI tool goes live, map what personal data will flow into it, through it, and out the other end. This can include learner records, prompts entered by staff, uploaded documents, usage data, and anything the system infers or generates as output.
It's also worth establishing whether that data will be accessed or shared beyond the organisation, whether that's with the AI supplier itself, government bodies, employers, or partner institutions. Providers need a clear line of sight on what personal data is processed, why it's needed, who's responsible for it, the lawful basis relied on, and where it's stored and for how long. That mapping exercise should feed directly into an updated Record of Processing Activities, and any third-party involvement should be backed by the appropriate processor contract or data sharing agreement.
Minimise the data AI tools need to process
AI tools in an FE or skills context can end up processing a wide range of learner information, from attendance and assessment data to special category data such as safeguarding records. The starting question should always be whether personal data needs to be entered into the tool at all. The Department for Education recommends avoiding the use of personal data in generative AI tools unless it's strictly necessary - which includes names, grades, and safeguarding information.
Where personal data is genuinely necessary, it should be limited to what the tool needs for a specific, lawful purpose. The data mapping exercise above is useful here too, as it can help identify where unnecessary data can be removed, or measures such as pseudonymisation, tighter access controls, or shorter retention periods would help.
Be upfront about AI's role
Learners are entitled to understand how their information is used, and if AI plays a role in how they're taught, supported, assessed, or tracked, that needs to be reflected clearly in Privacy Notices. Where AI feeds into decisions that affect learners, providers should be explicit that a human remains meaningfully involved, and explain how a learner can challenge an outcome if they disagree with it. This shouldn’t be seen as just a compliance box to tick - it's what demonstrates to learners and staff that AI is being used responsibly, rather than bolted on without due care and consideration.
What To Do After Reading This Article
Expectations around data sharing, accountability, and AI governance in the post-16 space are only going to increase, with bodies such as Skills England and Ofsted likely to take a growing interest in how providers use and govern learner data. Providers don't need every legal or technical detail settled before acting. Understanding what personal data is being processed, assessing the risks, scrutinising suppliers, communicating clearly with learners and staff, and training people properly are the fundamentals that put a provider in a stronger position, whatever changes come next.