Federal and State Privacy Regulations. There are numerous federal and state policies associated with student data privacy that are crucial to be aware of when determining policy and guidance for the use of genAI in schools including the
Family Educational Rights & Privacy Act (FERPA), the
Children’s Internet Privacy Act (CIPA), the
Children’s Online Privacy and Protection Act (COPPA) and the
Oregon Student Information Protection Act (OSIPA) under ORS 336.184. The federal and state regulatory landscape related to youth online safety, data privacy, and artificial intelligence continues to evolve, and
districts should plan for ongoing review and periodic updates of local policies and guidance.
COPPA, in particular, impacts technology users under the age of 13 in that companies are not allowed to collect personal information them without parental consent, while OSIPA lays out certain requirements that must be met when using digital platforms of any kind including the following:
- Disclosing any covered information provided by the operator to subsequent third parties, except in furtherance of kindergarten through grade 12 school purposes of the site.
- Engaging in targeted advertising on the operator’s site, service or application.
- Selling a student’s information, including covered information.
When developing district policies and guidance, it is essential to ensure that they are not in violation of COPPA or OSIPA. All schools and districts engaging with genAI technologies (or any technology broadly) should regularly review the company’s usage and privacy policies to ensure that they are not in violation of COPPA or OSIPA. Again, please refer to ODE’s
genAI companion policy and guidance document, a step-by-step guide for Oregon school leaders navigating this uncertain AI landscape.
District leaders are also encouraged to work in coordination with IT, procurement, and legal counsel to
ensure vendor agreements clearly define expectations for data collection, use, retention, security, and third-party sharing, and to verify that only district-approved tools are used for instructional purposes. In evaluating generative AI tools, districts should consider how commercial incentives may shape product design and data practices in ways that may not fully align with educational priorities. Careful review of vendor terms, data practices, and default settings can help ensure student information collection is limited to educational necessity and supports the protection of student privacy, well-being, and instructional integrity.
NOTE: Federal youth online safety and privacy proposals remain under active consideration at the national level. Districts should monitor federal and state developments and consult counsel as policies evolve. One example includes the
Kids Online Safety Act (KOSA), which as of early 2026, has not yet passed through Congress and is still in legislative limbo.
Recommendations And Resources For Student Data Privacy Implications
Whenever new technology is introduced, reviewing the data use and privacy policies are of key importance. For example, for the purposes of ChatGPT, a starting place is to read the
privacy policy of OpenAI, the developer of ChatGPT. The privacy policy includes specific information related to the use of ChatGPT for children:
"7. Children.
Our Services are not directed to, or intended for, children under 13. We do not knowingly collect Personal Data from children under 13... Users under 18 must have permission from their parent or guardian to use our Services."
Schools and districts are also encouraged to look over OpenAI’s Educator Considerations for ChatGPT for additional information.
District IT Role: District IT personnel should participate in the establishment of clear approval processes to vet genAI tools for data privacy, security, and compliance before classroom use. This includes reviewing platforms for risks to personal data and personally identifiable information (PII). Teachers play a critical role by ensuring they only use apps, websites, or tools that have been formally approved. Seeking IT approval before adoption not only protects students but also aligns instruction with district policies, federal regulations, and best practices for safeguarding sensitive information. This vetting should also consider browser-based AI extensions, third-party integrations, and tools accessed through personal staff or student accounts that may collect, transmit, or store student data outside district visibility.
Personally Identifiable Information (PII), oversharing and genAI.
ORS 339.329 (c) defines the state of Oregon’s statewide tip line concerning threats or potential threats to student safety. In it
Personally Identifiable Information (PII) is defined as any information that would permit the identification of a person… and is not limited to name, phone number, physical address, electronic mail address, race, gender, gender identity, sexual orientation, disability designation, religious affiliation, national origin, ethnicity, school of attendance, city, county or any geographic identifier included in information conveyed… or information identifying the machine or device used by the person…”
Users, both school staff and students, should be cautious when entering any personal information into any and all digital applications, including generative AI tools. Entering Personally Identifiable Information (PII) into any generative AI system should always be avoided. This is a particularly important consideration when using generative AI applications such as ChatGPT, as the information entered by users (including prompts and questions posed, etc.) is stored on the application’s server and integrated into the large language model used to respond to user prompts. Essentially, generative AI tools are learning from every single piece of text or other input typed into their platforms.32 While this statement generally still holds true as of the most recent release of this guidance document, many genAI tools are now offering a 'private mode' and / or education versions in which the companies who own then state that they are not retaining data for model training, though this cannot be independently verified.
Oversharing occurs when individuals share too much of that PII or other sensitive information in inappropriate or unsecured contexts. When we think of genAI tools like ChatGPT specifically, oversharing can lead to significant risks. These risks can potentially include:
- Exposure to data breaches
- Misuse of information and
- Unintended data harvesting
GenAI tools, while powerful in processing and generating content based on vast data sets, can retain or expose information in ways that might compromise privacy. This makes understanding and mitigating oversharing critically important in K-12 educational settings where schools are dealing with minors and the federal privacy regulations cited above, like
FERPA and
COPPA.
School Staff Oversharing. For school staff, the dangers of oversharing with generative AI tools can have potential professional and legal ramifications. Staff might inadvertently, or even intentionally, enter sensitive information such as student performance data, behavioral reports, or even personal health information into AI systems. Staff should also avoid entering any student information into AI tools when drafting feedback, behavior documentation, communications, or instructional materials unless the tool has been formally approved and vetted for compliance with privacy requirements. All staff need to understand they should not enter this type of personal information into AI systems.
Doing so poses potential risks of violating privacy regulations like FERPA, which could lead to legal consequences for the school and the individual. Moreover, such data breaches can damage the trust between educators and students and potentially harm the school’s reputation. It is crucial for all school staff to be trained on the appropriate use of AI tools and the types of information that should never be entered into such systems.
Student Oversharing
Students are at heightened risk when it comes to data privacy, not because of carelessness, but because they are still developing an understanding of how personal information can be stored, shared, or misused in digital spaces. This is particularly true with genAI chatbots who are programmed and train to respond like humans.33,34 When students disclose personal anecdotes, family details, or sensitive identifiers in generative AI tools and other online platforms, that information may be retained, logged, or exposed through data breaches, weak security practices, or misuse across platforms. Such exposure can create opportunities for cyberbullying, identity theft, online sextortion, trafficking, or other forms of exploitation. To reduce these risks, educators and schools should proactively teach safe digital practices as a part of a larger effort to teach AI and information literacy, embed privacy awareness into learning experiences, and ensure strong protections through secure platforms, strict privacy settings, and clear usage policies. Safeguarding student data is a shared responsibility that requires both systemic protections and ongoing staff and student guidance. Districts should incorporate explicit instruction on privacy, consent, and digital identity protection into existing digital citizenship, health education, and AI literacy learning so students understand how synthetic media and data sharing can affect their safety and well-being.
While there is a growing number of online resources for teacher professional development resources and K-12 student lessons that focus on these issues, including many listed below, Oregon has a number of resources helpful in this specific area.
Oregon’s Health Education Standards include age-appropriate requirements related to social media, AI, and data privacy in order to promote student safety with skills-based education. Also created specifically for Oregon youth,
SafeOregon, Oregon’s statewide tipline, provides a curriculum and accompanying
teacher’s guide for middle and high school students on topics of recognizing and analyzing risky online behavior and seeking help through trusted adults. These resources, free to all Oregon schools and districts, align to standards and are easily implemented in classrooms. Another valuable resource worth highlighting here is the Commonsense.org Quick
Digital Citizenship Lessons for Grades K-12, which includes lessons that are divided up by grade level.
The Implications of Synthetic Media and Deepfakes
Synthetic media refers to digital content that is created using genAI tools like OpenAI’s
Dall-E (image generation) and
Sora (video generation) to audio tools from
Lovo AI (audio generation). GenAI’s ability to make these media appear real (i.e. photorealistic) and / or authentic (i.e. portray known people, events, etc.) is increasing at a rapid pace. These online tools allow anyone to take images, photos, etc. from social media or other online platforms and manipulate them using genAI tools. A 2024 study from the
University of Waterloo found that a large number of participants (39%) struggled to correctly identify synthetic media versus real photographs of people and that many participants overestimated their own ability to recognize synthetic media.35
The continued development of genAI tools able to produce realistic synthetic media offers educators some promising opportunities for student learning. For example, teachers could use these genAI tools to:
- Create engaging and interactive learning materials, such as virtual simulations and educational videos that can enhance students’ understanding of complex concepts,
- Create personalized learning experiences by generating customized content tailored to individual student needs and interests,
- Work with students to explore digital storytelling, multimedia projects and other creative endeavors that foster critical thinking as well as digital citizenship and information literacy skills.
Analyzing and understanding synthetic media can help encourage students to think critically about authenticity, bias and manipulation.36
School district leaders can help staff and students alike by prioritizing the understanding of the risks posed by deepfakes and other synthetic media, which include potential risks of
harassment, intimidation, bullying and cyberbullying as defined in Oregon’s ORS 339.351. More resources are becoming available regularly around this topic; one good option available from AI for Education is their
Classroom Guide on Uncovering Deepfakes.
School district policies, guidance and student codes of conduct designed to address the use and misuse of genAI tools will want to include clear definitions and prohibitions of the creation and dissemination of deepfakes and other synthetic media designed with the intention to harm or harass others. These efforts should include mechanisms for reporting such incidents, as
mandated by ORS 339.356, which requires schools to have a uniform procedure for reporting and investigating acts of harassment, intimidation, bullying and cyberbullying. Oregon’s anonymous school safety tip line,
SafeOregon, is available to all districts and schools and should be a part of reporting procedures to ensure safety for all students and school communities.
District leaders should be aware that Oregon law (ORS 163.472) prohibits the unlawful dissemination of an intimate image. Recent revisions to this law now include images that have been digitally created, generated, manipulated or altered without consent. This law has implications for school response when AI-generated or manipulated intimate images are created or shared in ways that harm students or staff.
Additionally, school district leaders should be aware of a growing number of cases involving AI-generated media (e.g. video, images, audio etc.) being characterized as
“child sexual abuse material” (CSAM). Although Oregon does not currently have laws specifically targeting synthetic or deepfake
CSAM, existing federal laws criminalize the creation, distribution, and possession of such material, including
18 U.S.C. § 2256 and the
PROTECT Act of 2003. These laws have been used to prosecute individuals even when no real child was involved, and federal law enforcement agencies have affirmed their continued applicability.
In May 2024, the
Federal Bureau of Investigation stated, “CSAM generated by AI is still CSAM, and we will hold accountable those who exploit AI to create obscene, abusive, and increasingly photorealistic images of children.”
While several states, such as
Pennsylvania with Act 36 of 2024, have enacted laws addressing deepfakes and nonconsensual synthetic media, efforts at the federal level, including the previously introduced H.R. 5586 (DEEPFAKES Accountability Act), have not yet resulted in enacted legislation. In the absence of new federal or Oregon-specific laws, school districts should consult legal counsel regarding related policies and ensure staff are trained to recognize the dangers and legal implications of AI-generated CSAM and other synthetic media.
Specific recommendations for school districts include:
- Examining district policies about how permission is obtained and how media (audio, video and digital photographs) of staff, students and other community members is used for posting online through district websites and social media.
- Policy makers will want to have clarity and understanding regarding the determination of jurisdiction for how and when a school can investigate cases of potential technology misuse. This includes the basic understanding of whether the incident occurred inside or outside of school hours, whether it was on district equipment and what impact the post potentially had on the school community. Policies and training should also clarify when incidents occurring off campus may still require school response due to impact on student safety, school climate, or the learning environment.
- Consulting with organizations that have expertise in harassment, intimidation, bullying, cyberbullying, and
child sexual abuse as well as local law enforcement (as appropriate), when developing district plans and policies that relate to artificial intelligence, synthetic media, deepfakes and school safety. Incorporating risks associated with deepfakes, online exploitation and grooming into existing threat assessment efforts.
- Ensuring district policies relating to harassment, intimidation, bullying, cyberbullying, and mandatory reporting as required by
ORS 339.356 include procedures and consequences relating to incidents involving deepfakes of school staff, students and/or their families or caregivers, including the
SafeOregon Tip Line Specifically, connection and possible referral to Behavioral Safety [threat] Assessment Teams or Sexual Incident Response Committees should be considered on a case by case basis. Policy makers and district leaders should ensure the use of inclusive practices when it comes to consequences, supporting student mental health and wellbeing and prohibiting or limiting exclusionary practices such as suspension or expulsion if the law allows.
- Implement training for all school staff which focuses on the identification of synthetic media and deepfakes and how to respond appropriately according to district policy and reporting requirements, including details for appropriate reporting when potential incidents occur. Encourage staff to be vigilant in their ongoing monitoring. Because this technology is changing rapidly, training for staff should be provided on a regular and ongoing basis. Training should also address AI-generated voice cloning, impersonation, and manipulated audio/video intended to deceive or harm others.
- Ensure that there is a process in place to respond to incidents where non-consensual intimate images have been generated and/or shared to support the person or people harmed, including providing trauma-informed care and accountability. District response procedures should include timely reporting, coordination with families, and consultation with appropriate authorities when non-consensual intimate images or harmful synthetic media are involved, along with trauma-informed supports for impacted students.
- Implement regularly occurring learning opportunities for students of all grade levels that emphasize responsible creation and consumption of synthetic media and the risks and ethical implications involved. This should be a part of a larger body of digital ethics and information literacy learning being offered to all students. Lessons may include:
- Connecting to student mental health and well-being, incorporating Oregon’s
Transformative Social and Emotional (TSEL) framework and
Health Education standards whenever possible
- Building skills and knowledge related to consent, boundaries, and legal rights that emphasize the importance of consent in all interactions, both online and offline, when sharing images and videos. This content is often included within a district’s comprehensive sexuality education program
(OAR 581-022-2050).
- Identifying steps to help recognize common signs of deepfakes
- Understanding the long-lasting harm that sharing non-consensual intimate images has on the victim, including deep mental health impacts, social harm, privacy violations, and negative academic outcomes.
- Understanding restorative justice practices to support the people involved when non-consensual intimate images have been generated and/or shared.
- Understanding the potential impact synthetic media and deepfakes can have on misinforming society
- Reviewing of student codes of conduct, potential consequences for misuse, privacy violations, expectations around bullying and harassment
- Teaching of how students are to report incidents of misuse, bullying and harassment to school staff
- Promoting the use of the Safe Oregon tip line
safeoregon.com (ORS 339.329).