Children, schools and the data they cannot consent to
A different legal category
Every data protection regime treats children separately, and the reason is not sentiment. A child cannot evaluate a disclosure whose consequences arrive fifteen years later, and the data collected about a nine-year-old will outlive every assumption made when it was collected.
The rules differ, and the differences matter if you are choosing tools.
India's DPDP Act, 2023 sets the bar at 18 — higher than almost anywhere. Processing a child's personal data requires verifiable consent from a parent or guardian. It prohibits processing likely to cause any detrimental effect on a child's well-being, and it prohibits tracking, behavioural monitoring and targeted advertising directed at children outright. There is no consent that makes those lawful.
The GDPR sets a default of 16 for information society services, which member states may lower to 13. It requires that privacy information addressed to children be in language a child can understand.
COPPA in the United States covers under-13s and requires verifiable parental consent, with rules updated in 2025 tightening retention and third-party disclosure.
The UK's Age Appropriate Design Code takes a different approach worth knowing: rather than gating access, it requires that services likely to be accessed by children be designed with high privacy settings by default, minimal data collection, geolocation off, and no nudges towards weaker settings. Several jurisdictions have copied it.
What goes wrong in practice
Age gates do not work. A birth-date field asks a child to type a number. Age estimation from a photograph or a document raises its own serious problems — it requires collecting biometric or identity data from everyone in order to protect some, which is why proposals in this area are so contested.
Homework contains everything. A child's essay is about their family, their fears, their neighbourhood, their health. A teacher pasting thirty essays into a chatbot to speed up marking has disclosed thirty families' circumstances, and no consent screen was involved. This is the single most common school AI incident and it is committed by conscientious people saving time.
School procurement is uneven. A district negotiates terms for one platform, and individual teachers adopt six others they found useful. The approved tool has a data processing agreement; the other six have consumer terms.
Proctoring and monitoring. Systems that watch students during exams or scan school accounts for concerning language collect intensely sensitive data, generate false positives that fall hardest on students who are already surveilled most, and sit close to the EU AI Act's prohibition on emotion recognition in education.
Chatbot companions. Children form attachments quickly, disclose readily, and cannot see the commercial structure behind the conversation. This is covered in its own lesson later; the data point here is simply that a companion product accumulates the most sensitive possible record of a child's inner life.
Practical guidance
For teachers. Do not paste student work containing identifying detail into any tool your institution has not approved for it. Redact names and distinguishing details, or use a local model, which for marking-style tasks is entirely adequate. Ask what the approved tool is; if there is not one, ask for one in writing, because that request is also the record that you raised it.
For schools. The questions to a vendor are specific: is student data used for training, what is the retention period, where is it processed, is there a data processing agreement, what happens to the data when the contract ends, and is there any advertising or profiling. "Free for schools" should prompt the question of what the business model actually is.
For parents. Look at the settings on any AI product a child uses, particularly memory and personalisation features, which turn a series of conversations into a durable profile. Ask what the child is telling it. And know that a child's questions to a chatbot are often the ones they would not ask you, which is both the value and the risk.
The part nobody has solved
The honest position: the evidence base for AI tutoring and companionship in childhood is thin, the products are moving faster than any of the research, and the data being collected today will be governed by rules written later. Designing for reversibility — collect little, retain briefly, let it be deleted — is the only strategy that survives that uncertainty.
The one thing to keep
India's DPDP Act sets the threshold at 18 with verifiable parental consent and an outright ban on tracking children, and the commonest school incident is not a policy breach but a teacher pasting identifiable student work into an unapproved tool.
Before you move on
A teacher pastes thirty student essays into a consumer chatbot to speed up marking. Names have been removed. Under most children's data regimes, what is the central problem?
Pick the one you would defend. Nobody sees your answer.