Privacy
Uploading student work to an AI tool: what to check first
A scanned test is a student's name next to their handwriting. That makes it personal information, and the ordinary rules apply — the same ones that cover every other student record you handle.
The question arrives the moment you find something that might save an evening: am I allowed to put student work into this? It depends on what the tool does with the papers, and on the rules where you teach. What follows is the order the people who assess these tools use.
This is general information, not legal advice. The Office of the Australian Information Commissioner publishes plain-English guidance on Australian privacy law at oaic.gov.au, and your school or department's privacy officer is the person who can tell you what applies in your classroom.
Start from what a test paper is
Under the Privacy Act 1988 (Cth), personal information is information about an identified or reasonably identifiable individual. A paper with a name on it is squarely that: a class set of marked papers is a record, not scrap.
Who the rules land on is often misread. The regulated organisation is usually your school or department and the provider of the tool — not you personally. Government schools in most states and territories are covered by state or territory privacy laws rather than the Commonwealth Act; many independent and Catholic schools are covered by the Commonwealth Act. The provider is usually regulated in its own right as well. Either way, what you do with the class set is how your school meets its obligations — so in practice the checking falls to you.
The questions that matter, in order
1. Is the tool approved where you work?
Start here, because it can end the conversation. Many education departments and school systems require approval before student data goes into a new online tool, and several maintain catalogues of products already assessed. Some require the school to do its own privacy assessment; some require parental consent for third-party online services. The rules differ by jurisdiction and by sector — read your own policy, and ask where it isn't obvious.
The name you'll run into is Safer Technologies 4 Schools (ST4S), a national assessment run by Education Services Australia for Australia's education departments and school sectors. It checks a product against a shared security and privacy framework and publishes the result to the people who decide what runs on school networks. A badge is often what gets an allowlist request through — but assessments are prioritised and take time, so an unassessed product isn't automatically rejected; it just means your school does its own checking.
2. Where is the data stored, and does any of it leave Australia?
Two questions, not one: where the data rests, and where it is processed. A tool can store everything in Australia and still send the contents overseas for a processing step. That isn't automatically a problem, but you're entitled to know.
Sending personal information to an overseas recipient counts as a disclosure, and Australian privacy law puts conditions on it. An organisation covered by the Act generally has to take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, and it stays accountable for what that recipient does. Its privacy policy has to say whether overseas disclosure is likely and, where practicable, which countries. So look for that list — providers, countries, what each receives. A tool that can't produce it has answered your question.
3. What is it collected for, and is it used for anything else?
The purpose you hand data over for is the purpose it should be used for. Under the Australian Privacy Principles, information collected for one purpose generally shouldn't be used for an unrelated one without consent — and "we may use your content to improve our services" does a lot of quiet work.
The specific thing to ask about is model training. Is student work used to train or fine-tune any model, by the provider or by anyone it passes the work to? Ask it as a yes-or-no question, in writing. It's the question most likely to produce a vague answer — and the vagueness is the answer.
4. How long is it kept, and how do you delete it?
Australia doesn't currently have a general right to erasure of the European kind — at the time of writing it's proposed, not legislated. What it has instead is an obligation to destroy or de-identify personal information once the organisation no longer needs it. So ask about defaults: how long are scans kept, can you delete a class or a run yourself, and what happens when you close the account? "As long as necessary" isn't an answer. A number of days is.
5. Who makes the decision that affects the student?
A system that reads a paper and writes a mark into a record with nobody looking is making a decision about a child. One that marks against the teacher's key, shows what it couldn't verify and then waits is assisting a decision the teacher makes.
The law is moving the same way. From December 2026, changes to the Privacy Act require privacy policies to spell out where computer programs make decisions that could significantly affect someone — and, separately, where a program does something substantially and directly related to making one. A human confirming the output doesn't remove that obligation; it changes which description applies. The classroom version is simpler: can a mark reach a student's record without you agreeing to it?
6. The everyday hygiene
- Keep names out of support requests. Screenshots and "here's the paper that went wrong" attachments are the commonest way student information reaches somewhere nobody assessed.
- Use your work email address, so the account isn't invisible to your school and impossible to hand over.
- Mind the copies. The scan left on the staffroom copier, the PDF in your downloads, the photos in your camera roll — same information, no retention policy.
If you're just trying something out: a de-identified class set answers nearly every question about a tool without putting anything at stake. The one thing it can't test is whether the tool matches each paper to the right student — save that for after the approvals are in.
How AutoMark answers these
The detail is on the student data page and in the privacy policy, which names every provider and what it receives. AutoMark is hosted in Australia: scans, marks and backups stay in an Australian region. Reading the handwriting involves one overseas processing step by our OCR provider in the United States, disclosed there, and no provider we send student work to trains models on it. Scan images are purged automatically 180 days after a run is committed, by default, while the marks are kept. And a marking run ends with you: you confirm every mark before it's recorded.
One thing to say plainly: AutoMark has not been assessed under ST4S, and it isn't procured or endorsed by any education department or school system. It's a personal tool teachers sign up for themselves — which is why checking your own policy first matters. The domains to allowlist are written up for your IT team, and common questions are on the FAQ.
The checklist, if it's easier to ask than to read
Paste this into an email to your IT lead, with the tool's name at the top. A tool worth using answers all eight.
- Is this product on our approved or assessed list? If not, what's the process?
- Has it been assessed under ST4S, and can I see the result?
- Where is student data stored, and does any of it go overseas — which countries and providers?
- Is student work used to train any model, by the provider or anyone it passes work to?
- How long are scans kept, and can I delete a class or the whole account myself?
- Can a mark be recorded without a teacher confirming it first?
- Do we need parental consent, or does an existing consent cover it?
- Who do I tell if something goes wrong?
Mark your next class set in minutes.
The beta is full for now — leave your address and we'll tell you when a place opens. Free for two months when it does.
Join the waiting list