<
Step 4: Identify the rights holder — the US detail that catches people
Institutions operating in the United States work under FERPA, the Family Educational Rights and Privacy Act, with the statute at 20 U.S.C. § 1232g. It gives parents rights of access to their children’s education records, the right to seek amendment, and some control over disclosure of personally identifiable information from those records.
The provision that matters for higher education: when a student turns 18 or enters a postsecondary institution at any age, the rights transfer from the parents to the student, who becomes an “eligible student.”
So in a university the rights holder is the student — including a dual-enrolment sixteen-year-old taking college courses. Vendor arrangements, notice, and any consent mechanism must be built around the student. Institutions that have imported a K-12 template will have the wrong party in the wrong place throughout.
Step 5: Cover the AI-specific obligations, not just the data ones
Data protection is necessary and no longer sufficient. For institutions in the EU, Article 4 of Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures ensuring, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf — proportionate to their technical knowledge, experience, education and training, the context of use, and the people the systems are used on.
A university adopting an AI writing platform is a deployer. Practically, that means your review should produce a training record alongside the risk register, and the two should name the same population.
Step 6: Write down what you decided, and who accepted the risk
The purpose of the exercise is not a clean sheet. It is a record showing that the institution identified the risks, applied mitigations, and that a named person with authority accepted whatever remained.
Your output should state, for each identified risk: the mitigation applied, the residual risk after mitigation, the named accepting officer, and the review date. A DPIA with no residual risk recorded anywhere is usually a DPIA that was completed to be filed rather than to be used.
A workable checklist
| Area | What to establish | Where it must live |
|---|---|---|
| Roles | Who is controller, who is processor, for which processing | Data processing agreement |
| Sub-processors | Named list, and notice obligations before changes | DPA annex |
| Location | Storage and processing jurisdictions, including failover | DPA |
| Training use | Whether content trains any model; whether it is contractual | DPA, not marketing copy |
| Retention and exit | Retention periods; deletion and export at termination | Contract |
| Rights requests | How the vendor supports access, amendment and deletion requests | DPA and internal procedure |
| Security | Certifications, penetration testing cadence, incident notification timescales | Contract schedule |
| Accessibility | Conformance statement and known exceptions | Procurement file |
| AI literacy | Who is trained, when, and how it is recorded | Training record |
| Residual risk | What remains, who accepted it, review date | DPIA |
Sequencing it so it does not become the bottleneck
Start the review in the same week you start the academic evaluation. Send the vendor questionnaire and the DPIA data-mapping request together. By the time the academic side reaches a view, you will have the answers that determine whether that view is actionable — and if a vendor cannot answer basic sub-processor and training questions in a fortnight, you have learned something useful about the support you would receive as a customer.
The specific questions to send are set out in our procurement question bank, and the surrounding pilot structure in our guide to running a departmental pilot.
If it would help to have the data protection documentation package for an evaluation up front — data flow, sub-processor list, retention and training position — request an institutional evaluation.
Frequently asked questions
Do we need a DPIA for every edtech tool?
No, but you must assess whether one is required against the regulator’s criteria rather than assuming. The ICO publishes both the criteria and examples of high-risk processing.
Is a pilot exempt from a DPIA?
Not inherently. The requirement turns on the nature of the processing, not the number of participants.
Is UK DPIA guidance changing?
The ICO states its DPIA guidance is under review due to changes made by the Data (Use and Access) Act and may be subject to change, so check the live page before relying on an internal template.
Who holds FERPA rights for a university student?
The student. Rights transfer from parents when the student turns 18 or enters a postsecondary institution at any age.
Does FERPA apply to a UK or EU institution?
Not directly, but multi-campus and transnational providers frequently have obligations under more than one regime, and vendor terms are usually written to one. Check which.
What is the most important contract term?
Whether submitted content is used to train models, expressed contractually rather than as current practice.
Does data residency in the EU satisfy GDPR?
Residency is one factor. Lawful basis, transparency, retention, sub-processing and data subject rights all still apply regardless of where the servers sit.
Who signs off the residual risk?
A named officer with authority to accept it on the institution’s behalf, recorded in the assessment with a review date.
What about student work that contains research participants’ data?
Treat it as in scope and align the vendor arrangement with what participants were told during ethics approval.
Should students be able to opt out?
If the tool is mandatory for assessment, an opt-out implies an equivalent alternative route must exist. Decide this before launch, not after the first request.
How does this interact with our detection contract?
They are separate processing operations with separate assessments. Both send student work to third parties, and the evidential weight you place on the detection output is a policy question covered in our analysis of AI detection reliability.
]]>
