Do not send personal data to services outside the school
What needs to be done depends on the type of material. The table summarises the four cases explained in this chapter, and each one links to its section.
| If the material… | Then… |
|---|---|
| is intended for students or for open publication | it needs no data, and should not ask for any |
| is a teacher’s tool with identified students | the data stay on the teacher’s device, in line with the school’s rules |
| collects students’ answers | the results reach the teacher without going through services outside the school |
| is provided by the school to its teachers | the data go to the school’s systems, and the decision belongs to the school |
Personal data in an educational resource
Personal data are any information that makes it possible to identify a person. In an educational resource they include students’ names, email addresses, marks, voices or images, and also the answers to an activity when they are stored linked to a name. A quiz that asks for the name and sends it to a server together with the answers is processing personal data.
Most students are minors, and data protection rules are stricter in that case. In the European Union, the General Data Protection Regulation sets at 16 the age at which a person can consent to the processing of their own data in online services, and allows each country to lower it to 13. In Spain, Organic Law 3/2018 sets it at 14, and below that age consent is given by the families. That age only counts when the processing is based on consent. According to the guide for schools of the Spanish Data Protection Agency, schools do not, as a general rule, need consent to process students’ data in the exercise of their educational function, although they must provide information about that processing.
Even when consent is not needed, or students can give it themselves, good practice advises that families receive accurate information about what their children do and the tools they use. That information should state which materials are used, whether they collect any data and for what purpose, so that the family knows the material before it is used in the classroom. The Orientaciones sobre el uso de herramientas digitales en el ámbito educativo desde la perspectiva de la protección de datos (Guidelines on the use of digital tools in education from a data protection perspective), from Spain’s National Institute of Educational Technologies and Teacher Training (INTEF), consider it good practice, although not compulsory, and ask for that information to reach families through the school’s channels, and not through social networks or instant messaging.
The decision about students' data
Publishing a resource that sends students’ data to a server is not a decision each teacher can take on their own. In Spain, the same guide states that education authorities and schools must have instructions for teachers’ use of technologies, and that teachers must use those provided by the authority or the school. In a state school, the controller of students’ data is normally the education authority. By contrast, for what a teacher publishes outside their teaching role at the school, the controller is the teacher.
The consequence is that a resource created on a teacher’s own initiative must not store students’ data in a service that the school has not provided. INTEF’s guidelines go in the same direction. As a general rule, teachers should not use tools other than those provided by the authority or the school, and any other tool that processes personal data requires a prior evaluation, which the school consults with its data protection office, and the permission of the authority or the school. The document includes an evaluation model that can also be applied to one’s own material. Other countries have different rules, but the precaution is the same: before collecting students’ data, the school must be involved.
Materials that need no data
The simplest way to comply is for the material not to collect data. The European Regulation establishes the principle of data minimisation, according to which data must be limited to what is necessary for their purpose, and requires data protection by design. The Guidance on AI and children of the United Nations Children’s Fund (UNICEF), which has a worldwide scope, recommends the same: minimising data collection and adopting a privacy-by-design approach.
In a resource created with vibe coding, this translates into a few decisions that can be requested from the AI from the start:
- No identification. The material does not ask for the name. If several people need to be told apart, an alias that does not identify them is enough.
- Everything in the browser. Answers and progress are stored on the device itself and are not sent to any server.
- No user accounts. The material is used without registering with any service.
- No analytics. The material includes no visit counters or tracking tools.
With a resource built this way, the person who publishes it receives no data from students, and the data do not leave the device on which it is used. If a teacher stores their students’ marks in it, they are still processing personal data, but they do so within their educational function and without any outside service being involved.
Tools that need to identify students
Some materials need to identify students to do their job, such as a gradebook, a seating plan or a group generator. These tools can be created and published, since monitoring students is part of the educational function. The condition is that the data remain under the control of the teacher and their school.
The Spanish Data Protection Agency’s guide accepts that teachers use applications on their personal devices, provided they respect the privacy policy defined by the school or the education authority. It considers it especially important that such use does not involve transferring students’ data to the service provider, for the provider to use for its own purposes or to store permanently.
In a tool created with vibe coding, this condition is met when the data are stored only on the teacher’s device, either in the browser or in a file that is downloaded and loaded again. The published application contains no data, because each teacher enters their own and they do not leave their computer, so the author of the tool processes nobody’s data. It is also advisable for the tool to allow the information to be shared or printed without the names, and for each teacher to use it in line with their school’s rules, just as they would a paper notebook or a spreadsheet.
One example is the Cuaderno del Profesorado (Teacher’s Gradebook), by Imanol Lostalé, a complete teacher’s gradebook that works without a server: the database is stored in the browser or in a file on the teacher’s disk, with its backups.
Programs that collect students' answers
Another case is the program a teacher creates to check their students’ knowledge, detect misconceptions or follow their progress. The initiative is individual, but the data are generated by students on their own devices and have to reach the teacher. Assessment is part of the educational function, so the program is legitimate, and what needs care is the path the results follow. INTEF’s guidelines reserve data with legal effects, such as the mark for a test, for the school’s tools, so the mark that counts is recorded on the school’s platform. There are several ways to solve this without sending data to services outside the school, which can be combined:
- The result is handed in through the school’s channels. The program shows the result at the end, or saves it in a file, and students hand it in through the school’s platform, like any other assignment. This is what OpenWorksheets does, a free application for interactive worksheets with no server or accounts, in which students download a submission file when they finish.
- Students identify themselves with a code. The program does not ask for the name, but for a code that only the teacher can link to a particular student. The European Regulation calls this technique pseudonymisation, and requires that correspondence to be kept separately. INTEF’s guidelines give this same example of pseudonymised use through a code, on condition that it does not allow students to be identified again. In the Plantilla correctora digital (PCD) (Digital answer-sheet marker), for multiple-choice exams, the only identification field accepts a code instead of the name.
- The results are collected in a school spreadsheet. When automatic collection is needed, each teacher deploys their own copy of the program in the account the school provides them with, and not in a personal account, so that the results reach a spreadsheet that only they control. The program’s author publishes a template and receives no data. The school should be aware of it. An example is the Quiz del Sistema Solar (Solar System Quiz), by Pablo G. Guízar, designed for each teacher to deploy with their own spreadsheet, which keeps the correct answers out of the browser. The same author explains how to do it safely in his security guide for applications with Google Sheets.
- The submission travels encrypted. The program encrypts the result with a key belonging to the teacher, so that students can encrypt but not decrypt, and only the teacher reads it with their password. Even if the file is sent through an insecure channel, its content is unreadable. OpenWorksheets offers this encryption as an option, and also warns if a submission file has been tampered with.
- The mark is managed by the school’s platform. The program is exported in a standard format and uploaded to the platform the school already uses, which is the one that records the results. One of these formats is SCORM (Sharable Content Object Reference Model). This is what the Generador SCORM de Certificado de Finalización (SCORM completion certificate generator) does, by Pablo G. Guízar, which obtains the student’s name from the platform itself and records there that the course has been completed.
- Answers travel directly between devices. In live activities, such as a classroom quiz game, students’ devices can connect to the teacher’s without the answers being stored on any server. An intermediary service usually helps to establish the connection, and it sees technical identifiers but not the content. This is how the Buzzer WebRTC works, by Pablo G. Guízar, a buzzer for quick-response activities. WebRTC (Web Real-Time Communication) is the browser technology that allows that direct connection.
These programs are deterministic, that is, they always apply the same rules to the answers, and the analysis is done on the device itself. The situation changes if the program sends the answers to an AI service to assess them. In that case the data reach a third party and, in addition, the European AI Regulation classifies AI systems intended to evaluate learning outcomes as high-risk, which entails significant obligations for their provider and for the school that uses them. Following the amendment approved in July 2026 through Regulation (EU) 2026/1744, those obligations will apply from 2 December 2027.
Programs provided by the school to teachers
A school or an education authority may decide that a program should manage students’ data in its own systems, for example some shared spreadsheets with marks. In that case the data leave the browser, and that is legitimate, because the decision is taken by the controller of those data. The Spanish Data Protection Agency’s guide states that schools must know the applications they are going to use, their privacy policy and their terms of use before using them. When an external provider is involved, it acts as a processor and may only process the data in accordance with the school’s instructions.
A program created with vibe coding can fulfil this function with three precautions. The first is that the data are stored on the platform the school already uses, without adding new services. The second is that the decision goes through the school management and the data protection officer, and not through an individual teacher. The third is security: the code of these programs was written by the AI and usually nobody has reviewed it, so a program that handles real data deserves a review by a person with technical knowledge before it is put into use.
When the program is published as a template for other schools to use, it is advisable to accompany it with a notice stating who is responsible for the data. One model is that of IAGuar, an application for managing teachers’ cover duties, whose author states that he has no access to the data of copies deployed by third parties and that the controller is the school that sets up its own copy.
Sending data to other servers
Another risk lies in code that sends information without its author knowing. The article «Mantener la “A” de abierto en los REA en tiempos de IA» (Keeping the “O” of open in OER in times of AI), which the National Centre for Curriculum Development in Non-Proprietary Systems (CEDEC) devotes to open educational resources (OER), describes an illustrative case: a mathematics quiz that, on completion, sent the answers to an external domain. The teacher thought it was a usage counter, and in fact that domain was collecting minors’ data without the consent required by the Regulation. The same article warns about materials that ask for permission to use the camera, the microphone or the location without a clear educational purpose.
App-building platforms deserve special attention, since they easily add user accounts and databases, and the data are then stored on a company’s servers. The same happens when the material is opened within a chatbot’s website: students enter a third party’s service, which may require registration or a minimum age. If they are used, INTEF’s guidelines recommend that the servers be in the European Union and that the provider clearly state who the data controller is, for what purpose it uses the data, to whom it discloses them and for how long it keeps them.
To check a resource it is not necessary to read the code. A first check consists of asking the AI to list all the external addresses that appear in it and to explain what each one is for, as the VCER evaluation asks. An address that is not recognised is reason enough not to publish until it has been clarified. If the material has user accounts or connects to a server, it is also advisable to ask the AI to review how those data are accessed and how they are protected.