← Back to Insights
Regulated Industries

Can My School Use AI? A Plain Guide to Student Data and Canadian AI Tools

Yes, schools can use AI — if the tool handles student data properly. Here's what Canadian AI rules require, and how to check before you buy.

By Augure·
A group of people sitting at a table with computers

Yes, your school can use AI. The question that actually matters is where the student data goes, and who can see it.

Most provincial privacy laws don't ban AI outright. They ask you to know what a tool collects, where it's stored, and whether a vendor can hand it to someone else. Get those three answers before you sign up a class, not after.

This matters more in Canada than people think, because a lot of popular AI tools are American. Once student data lands on a US server, US law can reach it — a fact most school boards would rather avoid explaining to parents.

What does provincial privacy law actually require?

Every province handles this a little differently. Ontario has its own freedom-of-information law for public boards. Quebec has its own privacy law, generally considered the strictest in the country. Alberta and BC have their own versions too.

The common thread: schools are custodians of student data, and they can be held responsible for what a vendor does with it. If a teacher signs up for a free AI tool and pastes in a class roster, the board owns that decision, not the app.

Quebec's law goes further than most. It requires a privacy impact assessment before certain data can cross provincial borders, and it gives parents rights over what's collected about their kids. If your board is in Quebec, that assessment isn't optional paperwork. It's the thing that decides whether a tool is allowed at all.

The assessment itself isn't complicated, but it does take real time. Someone at the board has to document what the tool collects, where that data travels, who can access it on the vendor's side, and what happens if the vendor gets acquired or shuts down. For a single classroom tool, this often runs a few pages and a few hours of a privacy officer's time. For a board-wide rollout touching thousands of students, it can take weeks, because you're now assessing every downstream vendor the AI tool itself relies on. Boards that skip this step usually aren't being reckless. They just didn't know the step existed until a parent asked about it.

Is this actually a big deal, or am I overthinking it?

Depends what you're doing with the tool. Using AI to draft a worksheet, with no names or grades involved, carries almost no privacy risk.

Using AI to summarize IEPs, flag at-risk students, or grade essays tied to real names? That's a different category. Now you're processing personal information about minors, and minors get extra protection under almost every Canadian privacy law.

A breach involving student records can trigger mandatory notification to the provincial regulator, and to every family affected. That's the scenario boards want to avoid. Not because AI is dangerous by nature, but because most classroom tools were never built with a ten-year-old's report card in mind.

One objection worth naming: some teachers assume that if a tool is "free," the board hasn't really adopted it, so the rules don't apply yet. They do. A privacy officer doesn't care whether money changed hands. The moment student data leaves the classroom and lands on someone else's server, the board is accountable for that decision, paid tool or not.

What should I check before buying or approving a tool?

This is the one list in this piece, so make it count. Before any AI tool touches student data, confirm:

  • Where the data is stored, and whether that location satisfies your provincial law
  • Whether the vendor trains its models on your data, or keeps it separate
  • Who can access the data — the vendor's staff, subcontractors, or nobody
  • What happens to the data if you cancel

If a vendor can't answer these plainly, in writing, that's your answer. A good privacy policy is short and specific. A vague one usually means the vendor hasn't thought about it either.

Canadian AI platforms tend to have an easier time here, because Canadian data residency is often built into the product rather than bolted on for a school contract. That's not a small thing when you're the one who has to explain the answer to a parent council.

Does using a Canadian AI platform actually solve this?

It helps, but it doesn't make the work disappear. A Canadian AI platform means customer data is stored in Canada, which satisfies the residency rule most provincial laws care about. It does not mean every use of the tool is automatically compliant. That part is still on the school.

Augure is one example of a Canadian AI platform built with this in mind. Customer data is stored in Canada, as Canadian privacy law requires. Inference runs on Canadian infrastructure for some model tiers, and with vetted European partners under strict no-retention agreements for others, including failover — never on US servers. Augure has no US parent company and no US investors, so customer conversations and documents are never handled by a US-jurisdiction provider. That matters for the question school boards keep asking their IT departments: can a US agency reach our data through the vendor? For the actual content of student conversations and documents, the answer is no, because that content never sits with a US-controlled provider. (Payment processing and email delivery do involve some US infrastructure, which Augure discloses in its privacy policy — worth knowing if your board's own assessment needs the full picture.)

Augure starts free, at 50 messages a day, which is enough for a single teacher testing lesson-planning use before committing a whole department. Paid tiers start at $20 a month for a teacher who wants persistent memory and more documents, scaling up for boards that need admin controls and dedicated support.

None of this replaces the privacy impact assessment your board's legal team should run. It just means the infrastructure conversation is shorter, because the residency question is already answered.

What about vendors who say they're "fully compliant"?

Be skeptical of that phrase. No vendor can guarantee your school satisfies a privacy law. Compliance depends on how you use the tool, what data you feed it, and what consents you've collected. A vendor can build a platform that supports compliance. It can't hand you compliance as a finished product.

What a vendor should say, and be able to prove, is where the data lives, who touches it, and whether it trains models on your content. If a rep answers with a slogan instead of a location, ask again.

What to do this week

Pull your board's current AI policy, if one exists, and check whether it mentions data residency at all. If it doesn't, that's the gap to close first.

List every AI tool a teacher is already using, even informally. Free tools slip in fast, and most boards have less visibility here than they think.

Ask one vendor, in writing, where student data is stored and whether it's used to train models. Their answer, or their silence, tells you most of what you need to know.

Start at augureai.ca if you want to see what a Canadian-built answer to that question actually looks like.

Where this comes from: Quebec's privacy law requires a privacy impact assessment before personal information crosses provincial borders (s. 17).

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started