Lesson 26Module 6: Safety, evaluation and hard limits 13 min· Level: Foundation

Privacy, bias and copyright — a school's AI ethics checklist

Turning the three ethical topics that meetings discuss in the abstract into checklists a school can act on, covering what must never be pasted in, what bias looks like in a classroom, and how to handle copyright and academic integrity.

以繁體中文閱讀

Short answer: privacy, bias and copyright get waved through in meetings as three abstract words, but each of them breaks down into a checklist a school can use today. This lesson provides those three checklists and the judgement behind them.

It starts with a staff meeting

At the June staff meeting, one agenda item read "AI usage guidelines". After forty minutes of discussion the conclusion was to "be careful with privacy, avoid bias and respect copyright", and the meeting closed.

Three weeks later, a teacher pasted a whole class's SEN learning support records into a free chat tool, hoping for help writing a summary.

The problem was not carelessness on that teacher's part. It was that the guidance never said what may and may not be pasted. Abstract principles do not change behaviour; a concrete list does.

Checklist one: privacy

Ask one question first

Before pressing send, ask only this: is there a single word in this text that would let someone identify which student it is?

If there is, and that word serves no purpose in the task you are trying to complete, delete it. This rule is called data minimisation, and it matters more than any encryption, because data that was never sent needs no protection.

What may and may not be pasted

CategoryExamplesPractice
Never pasteIdentity card numbers, home addresses, parent phone numbers, SEN diagnostic reports, counselling case notesNot into any platform
Paste after de-identifyingStudent compositions, answer scripts, presentation notesRemove name, class and student number, then use the school platform
Generally fineCurriculum outlines, textbook units, past public exam papers, lesson plansWatch the copyright on textbook content
School platform onlyMarking records that must stay linked to a student identityUse a platform with encryption, an audit trail and retention settings

Three technical questions you must be able to answer

Ask any vendor: where is the data stored, is it used for training, and who decides how long it is kept. If a vendor cannot answer, do not put students on it. For a Hong Kong reference point, the Privacy Commissioner has published a model framework on artificial intelligence and personal data protection.

Checklist two: bias

Bias in a classroom is not abstract; it has a recognisable shape. These four come up most:

  • Default gender for occupations. Ask for a short passage about a nurse and the character defaults to a woman; an engineer defaults to a man. This is especially visible in English writing examples, visual materials and scenario questions.
  • Assumptions attached to names. Names from different ethnic backgrounds shift the background, occupation and speech patterns the AI assigns to a character. Generating dialogue scenarios brings this out quickly.
  • Geographic and cultural skew. Training data leans towards English and Western content, so the defaults for festivals, food and family structure are often not Hong Kong's. Asking for "a typical family dinner" may not give you a picture you want in General Studies.
  • Low marks for unconventional answers. When AI assists with marking, tidily structured answers using common vocabulary score well, while creative but unusually expressed answers are underrated.

Where bias comes from is covered in lesson 9. Here, three classroom countermeasures:

  1. Specify explicitly in the prompt. Writing "Hong Kong setting", "balance the gender of characters" and "use local festivals and food" costs less than fixing it afterwards.
  2. Spot-check rather than review everything. Look at three items at random after each batch. Systematic tendencies show up quickly and you do not need to read every piece.
  3. Marking is always the teacher's decision. The AI gives instant feedback and the teacher confirms before anything is final. This matters most in subjects that reward originality.

In an AI context, copyright has three entirely separate strands, and discussing them together guarantees no conclusion:

  1. Copyright in the training data. Models were trained on vast amounts of online content, and litigation and legislative debate continue in several jurisdictions. A school cannot resolve this and should not be the one making the judgement. Choose vendors with clear terms and keep the records.
  2. Material the school puts in. Scanning a whole textbook and pasting it in is an ordinary reproduction question that has nothing to do with AI. Textbooks, past papers and purchased materials remain bound by their original licences.
  3. Use of generated output. Internal teaching use is generally uncontroversial. External publication, posting on the school website or commercial use raise two issues: what the vendor's terms say, and whether the generated text contains protected passages — song lyrics, poetry and exam questions are the usual culprits.

Hong Kong's statutory framework is the Copyright Ordinance (Cap. 528), and the provisions on educational use are worth a read by panel heads and the librarian.

An example from the classroom

While reviewing school-based assessment, one secondary school's Chinese panel hit a genuine dilemma.

The panel head wanted AI to give instant feedback on junior secondary compositions so students could revise once before submitting a formal version. Three worries arrived together: the compositions carry student names (privacy), the AI might undervalue unconventional writing (bias), and students might simply copy the AI's suggestions (integrity).

Their solution is worth borrowing:

  • Privacy: use the school platform rather than a public tool. Students submit inside the platform, which sends only the composition text to the AI and not the student's identity, with personal-data fields encrypted in the database.
  • Bias: the AI gives only "three specific suggestions for improvement" and no score. Scores come from teachers, always. That single design decision removes the step where bias risk is highest.
  • Integrity: students attach a hundred-word note with the formal version explaining which suggestions they accepted, which they rejected and why. That note became part of the assessment in its own right.

The third worked best. It turned "did AI help you" from something to catch into something to think about and write down.

What this means for your classroom

  1. Turn principles into lists. "Be careful with privacy" changes nothing; "never paste these five things into AI" does. The list should be short enough to pin up in the staff room.
  2. Offer a compliant option. Banning without providing an alternative means teachers do the same thing on their phones and the school sees none of it.
  3. Bias is found by spot-checking, not avoided by promises. Reviewing a few generated items at random each month is the most practical quality control available.
  4. Write academic integrity policy around honest use. Graded levels, declaration and a process note beat "not allowed" — and they are closer to the world students will graduate into.

How this works inside Edor.ai

The platform's position on all three strands is specific enough to check.

Privacy: input gating detects and masks personal data such as phone numbers, identity card numbers and addresses before a message is sent; student personal-data fields are encrypted at rest and only learning content is transmitted when calling the AI; conversations and AI logs are purged on the school's retention schedule; and provider calls run under no-training terms. The data belongs to the school, with a free one-click full export (JSON, CSV or original files) at any time.

Bias: the marking module gives instant feedback but requires teacher review before anything is final; the scaffolded tutor gives hints rather than answers, with the hint-level ceiling set by the teacher; and every interaction is written to ai_audit_logs, so when a questionable output appears the school can trace which interaction and which model produced it.

Copyright: knowledge-base answers must carry citations so a teacher can go back to the source rather than accept text of unknown origin, and material the school uploads remains bound by its original licence, which the platform does not change.

Further reading: the security and privacy page and the student AI safety net.

In summary

Ethics discussions spin because they stop at the level of principle. Turn privacy into a table of what may and may not be pasted, turn bias into a monthly spot-check habit, and split copyright into three strands handled separately. Then teachers have something to follow, and the school's risk actually falls.

The next lesson takes on another topic that is usually left vague — how to judge whether a model is genuinely good: automated evaluation and leaderboards. The previous lesson is jailbreaks and prompt injection.

Key takeaways

  • The first rule of privacy is not encryption but not pasting in personal data you do not need. Everything technical after that is damage limitation.
  • Bias in a classroom is not abstract. It shows up as default genders for occupations, assumptions attached to names, and low marks for unconventional answers.
  • Copyright has three separate strands — the training data dispute, the material a school puts in, and the use of generated output — and they need handling separately.
  • An academic integrity policy has to describe honest use, not only ban use, or it simply pushes the use somewhere nobody can see.

FAQ

It depends on whether the text carries identifying information and where it is being sent. A composition stripped of name, class and student number is much lower risk; pasting it together with student details into a consumer chat tool is high risk. A school should list explicitly what may and may not be pasted, and provide a compliant platform so teachers have somewhere to work.

That depends on the vendor's terms and on copyright law in your jurisdiction, and practice is still evolving. Internal teaching use is generally uncontroversial, while external publication or commercial use warrants legal advice first. The more common practical issue is that generated material may contain protected passages, which needs a human check.

It should not be a blanket rule. A workable approach grades tasks — some where AI is not permitted at all, some where it may be used for ideas but must be declared, and some where use is required and the process must be submitted. The policy has to define each level and how to declare, or students cannot follow it.

Sources, trust labels and disclaimers
  • · All prices, features and specifications follow the official documentation linked above. Vendors may change them at any time — verify before you purchase.
  • · Product names and trademarks mentioned belong to their respective owners. Edor.ai has no partnership, agency or sponsorship relationship with these companies.
  • · This article is an independent review compiled for educational purposes and is not procurement advice or legal advice.
  • · For any use involving student personal data, assess it against your school policy and the Personal Data (Privacy) Ordinance (PDPO) before rollout.
Subscribe to the AI in Education newsletter

One email a month: practical AI teaching articles for Hong Kong schools, platform updates and grant news. Unsubscribe any time.

We only use this address for the newsletter and never share it.