
Product news policy brief: England adds an AI-aware EdTech procurement checklist for schools
UK Department for Education
AI Policy and Learning Report
৫০০-শব্দের সারাংশ

England's Department for Education added a new Procuring educational technology section to its Data protection in schools guidance on July 9, 2026. The parent guidance was first published in 2023, so July 9 is the amendment date rather than the launch of an entirely new manual. The section gives schools a practical sequence for assessing EdTech before purchase and after deployment. Generative AI appears within that broader procurement framework because suppliers may process pupil information, generate content or change how data are reused.
The guidance begins with data protection by design and by default. Schools should identify their educational purpose, limit collection to the minimum necessary data and leave non-core features disabled unless there is a justified reason to enable them. A data protection officer should be involved from the outset. Where processing is likely to create high risks, such as pupil profiling or large-scale biometric use, the school should complete a data protection impact assessment and update it when the product or processing changes.
Procurement teams are told to map the full data lifecycle and establish whether the school and supplier act as controller, processor or joint controllers. They should identify subprocessors and data locations, then place security, access, breach notification, retention, deletion or return, and audit expectations into the contract. The guidance also recommends authentication, encryption and logging, along with an exit plan. These provisions matter because a school may need to recover or delete information when a service changes ownership, terms or technical architecture.
An AI writing-tool example makes the test concrete. The hypothetical supplier could use pupil-entered text to train its AI, store information outside the United Kingdom and offer no way to disable training. The school decides not to proceed. The section also asks AI suppliers to explain moderation, model training, controls, and how they address inaccurate or biased output. Authorized use, human monitoring and review by both the data-protection and safeguarding leads remain necessary after a product passes initial procurement.
This is regulatory and operational guidance, not an EdTech certification or an empirical study. Following its questions does not prove that a system is accurate, accessible, safe in every interaction or educationally effective. Its legal setting is England and UK data-protection law; requirements cannot simply be presented as Hong Kong law. Supplier answers also need verification, while software updates, new subprocessors and changed defaults can invalidate an earlier assessment. Ongoing monitoring is therefore part of the guidance's logic, not an optional final step.
Hong Kong schools can adapt the checklist without importing its legal claims. A local review can document purpose, data minimization, model-training use, cross-border transfers, subprocessors, safeguarding routes, accessibility, audit evidence and deletion at exit, then map each decision to the Personal Data (Privacy) Ordinance and institutional policy. Product quality should be assessed separately through curriculum fit and independent learning evidence. The lasting contribution is a governance pattern: define the educational need, inspect the whole data chain, contract for control and revisit the decision when the product changes.


