Key Takeaways
- •The amended COPPA Rule (16 CFR Part 312) requires separate, verifiable parental consent before a child's data is used for AI training, targeted advertising, or third-party sharing. The compliance deadline is April 22, 2026.
- •The COPPA school authorization exception lets a school consent on a parent's behalf, but only for educational uses. It does not cover advertising, behavioral profiling, or anything commercial. FTC v. Edmodo confirmed schools cannot stand in for parents on those uses.
- •Biometric data is now squarely in scope. COPPA's definition of personal information now lists facial geometry, voiceprints, fingerprints, and retina scans, and Illinois BIPA already requires written consent for that data with statutory damages of $1,000 to $5,000 per violation.
- •State law often goes further than federal law. California SOPIPA bans selling student data and targeted advertising outright, with no consent workaround. New York bans facial recognition in schools entirely.
- •Google paid $8.75 million to settle a class action over facial and voice models collected from Illinois schoolchildren through Google Workspace for Education. Final approval came October 14, 2025.
- •A signed Data Processing Agreement with the AI vendor is the practical backbone of FERPA compliance. A 2024 CDT survey found 42 percent of districts using AI had no signed DPA, which means no presumption of compliance.
Reviewed for accuracy by the document.com legal team. Educational information, not legal advice.
What Is AI EdTech Parental Consent Form?
An AI EdTech parental consent form is the written notice-and-consent document a school, district, or education-technology vendor uses to lawfully collect and process a child's personal information through an AI tutoring or learning tool. It pairs a plain-language disclosure of what data the tool gathers with a signature line where a parent or guardian grants or withholds permission for specific uses.
The form exists because federal and state law treats children's data as a protected category. Under the Children's Online Privacy Protection Act, an operator of an online service directed to children under 13 generally cannot collect personal information without first giving notice and obtaining verifiable parental consent. An AI tutor that records a child's voice, tracks keystrokes, builds a learning profile, or feeds responses back into a model is collecting personal information in exactly the way the statute contemplates.
What separates a real consent form from a checkbox is specificity. The document has to name the data being collected, name the purposes, and let the parent agree to educational use while refusing commercial use such as advertising or AI training. The 2025 COPPA amendments make that granularity a legal requirement, because they demand a separate consent for those secondary uses.
This document does not replace a privacy policy, a Data Processing Agreement with the vendor, or a school's annual FERPA notice. Of that stack, the consent form is the piece the parent actually reads and signs.
Why This Matters Now
The FTC finalized a substantial rewrite of the COPPA Rule on January 16, 2025. The Federal Register published the final rule on April 22, 2025, the changes took effect June 23, 2025, and the full compliance deadline is April 22, 2026. Any AI tool serving children that is not updated by that date is exposed.
The amendments target exactly what AI tutors do. They require a separate, opt-in parental consent before children's data can be used for AI model training, targeted advertising, or disclosure to third parties. A consent form drafted before 2025 almost certainly bundles these uses into one general agreement, which no longer satisfies the rule.
Biometric collection is now both defined and litigated. COPPA's expanded definition of personal information explicitly includes biometric identifiers, and Illinois BIPA enforcement has produced real money. Google's $8.75 million settlement over facial and voice models from Illinois schoolchildren received final approval October 14, 2025, with class members receiving $30 to $100 each.
The FTC's order in the Edmodo matter (2023 to 2025) established that an EdTech vendor cannot outsource COPPA compliance to schools for non-educational purposes, and in December 2025 the agency brought a fresh action against an education-technology provider for failing to secure student data.
States are legislating fast. MultiState tracked 134 AI-in-education bills across 31 states for the 2026 session. South Carolina's H.B. 5253 proposes written parental opt-in for AI tools, Oklahoma's 2026 bill requires human-in-the-loop review and annual parent disclosure, and Illinois SB 3735 would give families a right to opt out of AI grading. A single national form template no longer fits every jurisdiction without state-specific riders.
The Legal Backbone
COPPA: 15 U.S.C. § 6501-6506 and 16 CFR Part 312
COPPA is the controlling federal statute for children under 13. It requires an operator of a website or online service directed to children, or one with actual knowledge it is collecting data from children, to post a clear privacy notice and obtain verifiable parental consent before collection. The January 16, 2025 amendments made several concrete changes that matter for AI. They require a separate consent before disclosing a child's data for purposes like AI training, targeted advertising, or third-party sharing, so a general yes no longer covers those uses. They expanded the definition of personal information to explicitly include biometric identifiers such as facial geometry, voiceprints, fingerprints, and retina scans. And they limited data retention to as long as is reasonably necessary for the stated purpose, ending the practice of indefinite retention. Verifiable consent methods recognized by the rule include knowledge-based authentication, a government-issued photo ID check, text-message confirmation, or a credit-card transaction. The compliance deadline is April 22, 2026.
The COPPA School Authorization Exception
COPPA preserves a narrow exception that lets a school authorize the collection of a student's personal information on a parent's behalf, but only for an educational purpose and only as the school's agent. The exception evaporates the moment the data is used for advertising, behavioral profiling, or any commercial purpose. The FTC drove this home in its action against Edmodo, finding the company had unlawfully relied on schools to provide consent while using children's data for advertising. A school can say yes to an AI tutor being used in class; it cannot say yes to that tutor selling profiles or running ads. For anything outside instruction, the vendor needs consent from the parent directly.
FERPA: 20 U.S.C. § 1232g and 34 CFR Part 99
FERPA governs education records held by schools that receive federal funding. It gives parents the right to inspect records, request corrections, receive notice of disclosures, opt out of directory information, and get an annual notification of their rights. For AI, the pressure point is the school official exception and de-identification. A school can share records with a third-party AI vendor without separate consent only if the vendor acts as a school official under the school's direct control and uses the data solely for the contracted educational purpose. That control is documented through a Data Processing Agreement. A 2024 Center for Democracy and Technology survey found 42 percent of districts using AI had no signed DPA, which leaves them without the presumption of FERPA compliance. FERPA also demands genuine de-identification, and the more data an AI system ingests, the higher the re-identification risk.
PPRA: 20 U.S.C. § 1232h and 34 CFR Part 98
The Protection of Pupil Rights Amendment applies to federally funded surveys, evaluations, and instructional materials that probe sensitive topics such as religion, political affiliation, sexual behavior, mental health, or illegal conduct. It gives parents the right to inspect those materials and, in some cases, to opt their child out. PPRA matters for AI tutors that prompt reflective or personal responses, but it was written in 1978 and does not comprehensively address biometric data, online tracking, or AI model security. That gap is precisely what state student-privacy laws have moved to fill.
California SOPIPA: Cal. Bus. & Prof. Code § 22584-22585
The Student Online Personal Information Protection Act applies to operators of sites, services, and apps used primarily for K-12 school purposes. It is stricter than COPPA in a key respect: several of its prohibitions are absolute and cannot be waived by consent. An operator may not engage in targeted advertising based on student data, may not amass a profile of a student except for school purposes, and may not sell student information. Covered information reaches names, contact details, grades, test scores, discipline and health records, geolocation, and biometric data. Where COPPA asks for consent, SOPIPA simply forbids the commercial use. A consent form cannot rescue a practice California has banned outright.
Illinois BIPA: 740 ILCS 14/1-99
The Biometric Information Privacy Act bars any private entity from collecting, storing, or using biometric identifiers without prior written consent, a published retention and destruction policy, and destruction within three years or when the purpose is satisfied. For children under 13, BIPA stacks on top of COPPA, so an AI tool using facial recognition or voice biometrics in an Illinois school needs verifiable parental consent under COPPA and written consent under BIPA. BIPA carries a private right of action with liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorneys' fees. Google's $8.75 million settlement over facial and voice models collected through Workspace for Education shows the exposure is concrete.
Other State Backbones to Check
Connecticut PA 16-189 restricts third-party use of student data to educational purposes and requires a written agreement before any transfer. The Colorado Privacy Act added biometric provisions effective July 1, 2025 and general provisions effective October 1, 2025, reaching biometric identifiers used for identification. New York, through a September 27, 2023 determination by the State Education Department, bars schools from buying or using facial recognition technology and conditions other biometric tools on an evaluation of privacy, civil rights, effectiveness, and parental input. Massachusetts is a two-party consent state, so anyone whose voice or likeness is captured must agree. Confirm the current text of every statute named here before relying on it, because the 2026 sessions are actively amending this area.
What a defensible AI EdTech consent form actually contains
A consent form that holds up is built around the specific data the AI tool touches, not boilerplate. Start with an inventory. Name the tool, the vendor, and every category of personal information it collects: account identifiers, the content of a student's prompts and responses, performance and progress data, persistent identifiers like device IDs and cookies, geolocation if any, and biometric identifiers if the tool uses voice or facial features. If the tool records audio, say so in the document in those exact words. Vague language about data we may collect is what regulators and plaintiffs' lawyers pull apart.
Separate the purposes, and let the parent answer each one independently. The 2025 COPPA amendments require a distinct consent before data is used for AI training, targeted advertising, or third-party disclosure. That means your form needs more than one signature line or checkbox. A parent should be able to approve educational use of the tool while refusing to let the vendor use their child's responses to train a model or build an advertising profile. Bundling these into a single I agree no longer satisfies the rule, and it is the defect that shows up most often in pre-2025 templates.
Pick a verifiable consent method and document it on the form. COPPA recognizes knowledge-based authentication, a government-issued photo ID check, a signed form returned by mail or scan, a text-message confirmation, or a small credit-card transaction. A clicked checkbox with no verification does not qualify as verifiable parental consent for direct collection from a child under 13. The form should record which method was used and the date, so the school or vendor can prove consent later.
Address the school authorization exception head-on if a school is consenting on parents' behalf. The form, or its school-facing companion, should state plainly that the school's authorization covers educational use only and that the vendor will not use the data for advertising, profiling, or any commercial purpose. This is the line Edmodo crossed. Writing the limitation into the document is both a compliance step and the cleanest evidence that the vendor understood the boundary.
Spell out retention and deletion. State how long data is kept, tie that period to the educational purpose, and describe how a parent or school can request deletion. COPPA now caps retention at what is reasonably necessary, SOPIPA requires deletion on school request, and BIPA requires destruction within three years or on satisfaction of the purpose. A single retention paragraph that references the strictest applicable rule keeps the form portable across states.
Build in the parent rights that FERPA and the newer state laws guarantee: the right to review what the tool has collected, the right to correct it, and the right to opt the child out without academic penalty where state law requires it, as Oklahoma's 2026 bill does. Khan Academy's Khanmigo offers a useful model on the product side, requiring parental signup for users under 18 and letting parents review chat history and receive moderation alerts. Your consent form should describe equivalent access mechanisms so the rights on paper match the rights in the software.
Last, attach or reference the Data Processing Agreement and the privacy policy. The consent form is the parent-facing piece, but FERPA compliance lives in the DPA between the school and the vendor, and COPPA requires a posted privacy notice. The three documents should not contradict each other on retention, purposes, or sharing. Inconsistency between them is an easy target. Have current counsel reconcile the language across all three before deployment, and treat this article as general information rather than legal advice for your specific tool and jurisdiction.
When You Need This
A school or district is adopting an AI tutoring, writing-assistance, or adaptive-learning tool that collects student data, and needs documented parental consent or a defensible school authorization before rollout.
An EdTech vendor is building or updating a product directed to children under 13, or with actual knowledge it collects from them, and must meet the April 22, 2026 COPPA compliance deadline.
The tool records or analyzes a student's voice, face, or other biometric features, triggering both the expanded COPPA definition and state biometric laws such as Illinois BIPA.
A vendor wants to use student responses to train or fine-tune an AI model, which now requires a separate, opt-in consent that a general agreement does not provide.
A district is operating in a state with a strict student-privacy statute, such as California, Illinois, Connecticut, Colorado, or New York, and needs state-specific limitations layered onto a national template.
A parent has requested to review, correct, or delete data collected by a classroom AI tool, and the school needs a documented process that matches the rights the consent form promised.
How to Fill Out AI EdTech Parental Consent Form
1. Map the tool's data flows
Before drafting, get a written answer from the vendor on every category of personal information the AI tool collects, where it is stored, who it is shared with, and whether student inputs feed model training. Confirm specifically whether the tool captures voice or facial data, because that pulls in COPPA's biometric definition and state laws like Illinois BIPA. This map is the factual spine of the form, and an inaccurate one makes the consent worthless.
2. Decide the consent pathway
Determine whether you are relying on the COPPA school authorization exception for educational use, on direct verifiable parental consent, or both. Educational-only use in class can run through the school. Any AI training, advertising, profiling, or commercial sharing must go to the parent directly. Document which pathway covers which purpose, because mixing them is what sank Edmodo.
3. Write the plain-language disclosure
State the tool's name and vendor, then list each data category and each purpose in language a non-lawyer parent can read. Name the educational uses, then separately name any secondary uses such as model training or advertising. Avoid hedging words like may and including but not limited to where you can be specific. If the tool records audio, write that the tool records your child's voice.
4. Add separated, opt-in consent controls
Create distinct signature lines or checkboxes for educational use, for AI training, and for any third-party sharing or advertising. A parent must be able to say yes to the first and no to the others. Do not pre-check any box. Under the 2025 amendments, bundled consent for these secondary uses is no longer valid.
5. Specify the verifiable consent method
Choose a COPPA-recognized verification method: knowledge-based authentication, government ID check, a returned signed form, text-message confirmation, or a credit-card transaction. Record on the form which method was used and the date and identity of the consenting adult, so you can later prove the consent was real and verifiable.
6. State retention, deletion, and parent access rights
Set a retention period tied to the educational purpose, not an open-ended one, and describe how a parent or school requests deletion. Include the parent's right to review and correct collected data, and the right to opt out without academic penalty where state law requires it. Reference the strictest applicable rule across COPPA, SOPIPA, and BIPA so the form travels across jurisdictions.
7. Layer in state-specific riders
Add jurisdiction-specific language for the states where the tool will be used. For California, confirm the form does not purport to consent to anything SOPIPA bans outright, such as selling data or targeted advertising. For Illinois, add BIPA written-consent and retention-policy language for any biometric data. For New York, confirm no facial recognition is involved. Check the current 2026 statutory text before finalizing.
8. Reconcile with the DPA and privacy policy, then have counsel review
Cross-check the consent form against the Data Processing Agreement with the vendor and the posted privacy policy so retention periods, purposes, and sharing terms match. Resolve any conflict. Then route the full package to current counsel licensed in your states for review, because the law in this area is changing across the 2026 sessions and this guidance is general, not legal advice for your specific deployment.
Key Terms Defined
- Verifiable Parental Consent
- The COPPA standard for confirming that the person granting permission is actually the child's parent or guardian. Recognized methods include knowledge-based authentication, a government-issued photo ID check, a returned signed form, text-message confirmation, or a credit-card transaction. A bare checkbox with no verification does not meet the standard for direct collection from a child under 13.
- School Authorization Exception
- A narrow COPPA provision allowing a school to consent on a parent's behalf to a vendor's collection of student data, but only for educational purposes and only as the school's agent. It does not extend to advertising, behavioral profiling, or any commercial use. The FTC's Edmodo action confirmed a vendor cannot use this exception to cover non-educational uses.
- Personal Information (COPPA)
- The category of data COPPA protects for children under 13. The 2025 amendments expanded it to explicitly include biometric identifiers such as facial geometry, voiceprints, fingerprints, and retina scans, alongside names, contact details, persistent identifiers, geolocation, and audio or video of the child.
- Data Processing Agreement (DPA)
- The written contract between a school and a third-party vendor that limits the vendor's use of student data to the contracted educational purpose and places the vendor under the school's control. A signed DPA is the practical basis for treating a vendor as a school official under FERPA. A 2024 CDT survey found 42 percent of districts using AI had none.
- De-identification (FERPA)
- The removal or alteration of personally identifiable information from education records so a student cannot reasonably be identified, including by someone in the school community using other available information. De-identified data can be used more freely, but feeding more data into an AI system raises the risk of re-identification, which can defeat the protection.
- Biometric Identifier
- Data derived from a person's physical or behavioral characteristics used to identify them, such as a faceprint, voiceprint, fingerprint, or retina scan. Now named in COPPA's definition of personal information and separately regulated by laws like Illinois BIPA, which requires prior written consent, a published retention policy, and statutory damages for violations.
Related Documents
AI EdTech Parental Consent Form
The parent-facing notice-and-consent document for an AI tool that collects student data. It discloses the data and purposes and captures separated, opt-in consent for educational use versus AI training or advertising. This is the document a parent reads and signs, and the one that operationalizes COPPA's consent requirement at the point of collection.
Data Processing Agreement (DPA)
The contract between the school and the AI vendor that limits the vendor's use of student data to the contracted educational purpose and places it under the school's control. The DPA is what supports FERPA's school official exception. It is vendor-facing and contractual, where the consent form is parent-facing. A 2024 CDT survey found 42 percent of AI-using districts had no DPA in place.
Website Privacy Policy
The general, posted statement of how an operator collects and uses data across all users. COPPA requires a children's privacy notice as part of this, but a privacy policy is broad and informational rather than a per-student consent instrument. The consent form is specific, signed, and tied to one tool and one child; the privacy policy is the public-facing baseline disclosure.
Workplace AI Use Policy
An internal policy governing how staff may use AI tools and handle data, including student data. It sets rules for employees rather than collecting consent from families. A district often needs both: a staff-facing AI use policy for educators and a family-facing consent form for the students whose data the AI tools process.
Biometric / Voiceprint Consent
A specialized consent focused on collection of biometric identifiers such as faceprints or voiceprints, often drafted to satisfy Illinois BIPA's written-consent and retention-policy requirements. When an AI tutor records voice or uses facial features, this consent is folded into or attached to the EdTech consent form, because biometric data carries heightened obligations and statutory damages.
Legal Authorities & Sources
This page is grounded in primary law. The statutes and official resources below are the authorities behind the guidance above. Verify the current text of any statute before relying on it.
- FTC: COPPA Rule Amendments Press Release (Jan 16, 2025)
- Federal Register: COPPA Final Rule (April 22, 2025)
- Cornell Law: 20 U.S.C. § 1232g (FERPA)
- California SOPIPA Statutory Text (SB 1177)
- Illinois BIPA (740 ILCS 14)
- New York State Education Department: Biometric Technology Determination (Sept 27, 2023)
- U.S. Department of Education: Protecting Student Privacy
- FTC: Children's Privacy (COPPA) Business Guidance
- Future of Privacy Forum: Student Privacy State Laws Tracker
- MultiState: 2026 State AI in Education Legislative Trends
Frequently Asked Questions
Create your AI EdTech Parental Consent Form in minutes.
Answer a few questions and download a clear, attorney-drafted document that cites the controlling law and is ready to sign.



