It can be, under conditions. Use a business-grade tool with a data processing agreement and no model training on your content; keep children's names, photos, health, additional needs and safeguarding details out of general AI chat tools; tell parents what you use; and assess the risks before you start. Free consumer chatbots holding identifiable children's details are not safe.
Children's data needs more care than most business data, and data-protection law says so directly: the GDPR's Recital 38 states that children merit specific protection with regard to their personal data. Much of what a nursery holds, such as allergies, medication, developmental concerns and support plans, is also health-related, which puts it in the special categories that carry stricter rules. In practice the biggest risk is rarely the nursery software. It's a tired practitioner at home at 9pm, pasting the day's observations, children's names included, into a free chatbot on their own phone to get the write-ups done.
Sort your nursery's data into three levels first
Most of the "is it safe?" question answers itself once you know which kind of information you're dealing with.
| Level | What it includes | AI rule |
|---|---|---|
| Low | No child identifiable: menus, newsletters, policies, staff rotas, activity plans, general parent letters | Any business AI tool, with a person checking the output |
| Medium | Identifiable but routine: first names, ages, observations of play, daily care notes, progress summaries | Only in tools covered by a contract and no-training terms, or anonymised before use |
| High | Photos and video, health and allergies, medication, additional needs and support plans, safeguarding records, family circumstances, accident reports | Never in general AI chat tools. Inside nursery software only after a risk assessment and with the provider's written answers |
Put this table in front of every member of staff. It's easier to remember "medium goes in anonymised, high never goes in" than a page of policy.
What makes an AI tool acceptable for children's data
Before any identifiable child's information goes into a tool, you should be able to tick every line here, with evidence rather than a sales promise.
- A signed data processing agreement. The contract that makes the provider handle data only on your instructions. Check: it's in your files, not just a click-through at sign-up.
- No training on your content. Business plans from the main providers don't train on business content by default; consumer plans rely on a setting someone may not have changed. Check: the plan name and the provider's business privacy page.
- A retention period you can live with. How long prompts, outputs and uploads are kept, and whether you can delete them. Check: the settings page or DPA.
- Named sub-processors. Many nursery apps pass text to an AI model provider behind the scenes. Check: the provider's sub-processor list names who.
- Work accounts, not personal ones. Staff sign in with nursery accounts you can switch off when someone leaves. Check: the admin console shows every user.
- A way to switch the AI off. For a particular child if a parent objects, or entirely if something goes wrong. Check: find the setting before you need it.
If a tool fails any of these, it can still be fine for low-level data (newsletters, menus, policies). It just can't hold anything about individual children. For how this fits your wider duties, GDPR and AI tools for a small business covers the basics.
AI already inside your nursery software
Many nurseries meet AI first as a new button in software they already use. Famly, for example, offers Sidekick, an AI writing assistant that works where staff write, including newsfeed posts, messages, observations, assessments and accident or incident forms. Features like this can be the safer route, because the provider already holds the data under a contract with you. But "already in our app" isn't the same as "already assessed". As of September 2026, Sidekick's product page doesn't say which AI provider processes the text, so that's a question to put to the provider in writing.
A short email you can adapt and send to any nursery software provider:
"We're reviewing the AI features in [product] before using them with children's information. Please confirm in writing: (1) which AI model provider processes the text staff enter; (2) whether any of our content is used to train models; (3) how long prompts and outputs are kept, and where; (4) whether photos are ever processed by the AI features; (5) whether we can switch AI off for the whole setting or for an individual child; (6) whether your DPA with us covers these features. Thank you."
Keep the reply with your risk assessment. If the answers are vague, use the AI features only for low-level text until they aren't. When you next compare providers, choosing nursery software with AI sets out what to compare.
Writing up observations without names or identifying details
Observation write-ups are where AI saves practitioners the most time, and where the rules matter most. If you're using a general assistant rather than your nursery software, anonymise before you type. An illustrative before and after:
Before (don't do this): "Write a learning journal entry. [child's full name], 3, in Sunflower Room, who has speech delay and sees a speech therapist, built a tower with 8 blocks and said 'more' twice..."
After: "Write a learning journal entry for Child A, aged 3 years 2 months. Observed: built a tower of 8 blocks, counted to 5 with support, said 'more' twice to ask for blocks. Link to physical development and communication. Warm tone for parents, 80 words, and suggest one next step."
An illustrative output: "Child A built an impressive tower of eight blocks today, concentrating carefully as it grew taller. With a little help, they counted to five, and twice asked for 'more' blocks, using words to get what they needed. Next step: we'll play stacking and counting games together, encouraging Child A to count the blocks aloud as they go." The practitioner then pastes it into the child's record in the nursery app, where the name goes back in, and checks every sentence matches what they actually saw. The speech delay and therapist never went near the AI tool, and didn't need to. More ways to do this well are in using AI for childcare observations and learning journals.
Removing the name isn't the whole job. "Child A, whose parents are separating, was upset at drop-off and wouldn't let go of her dad" contains no name and still carries family circumstances, which sit in the high level of the table above, and in a nursery of 40 children the staff and some parents would know exactly who it means. The anonymised prompt should describe only what was observed in the activity: "Child A was upset at drop-off and settled after ten minutes with a favourite book." The context stays in the child's record, written by the key person.
One realistic slip to watch for: the AI adds a flattering detail that wasn't observed ("showed excellent turn-taking with friends"). Parents read these entries closely, and an observation that didn't happen undermines every other entry. The practitioner's check is for invented detail as much as spelling.
A manager can check the habit is holding with a monthly sample. Pick ten AI-assisted observations across the rooms and compare each with the practitioner's original note. In an illustrative first sample, two of ten had gained a detail nobody wrote down: one child "shared resources kindly" and another "showed great pride in their work". Neither was wrong in spirit, and neither was observed. The fix was feedback at the next staff meeting and one added line in the prompt: "Use only what is in the notes; add no behaviour or feelings that aren't written there." The next month's sample had none.
Photos, video and face recognition
Children's photos are the highest-risk data most nurseries hold, and the easiest to mishandle with AI. Three rules:
- Never upload children's photos to general AI image or chat tools, whether to "make them brighter", remove a background, or generate a caption. Once uploaded, you've lost control of an image of a child.
- Treat automatic face tagging as a separate, high-risk decision. Some apps can recognise children's faces to sort photos. Recognising a person from their face is biometric processing, which data-protection law treats as special category. Leave it off unless you've done a proper assessment and taken advice.
- Keep photo permissions specific. A parent who agreed to photos in their child's learning journal hasn't agreed to them appearing in AI-edited marketing. If you want marketing photos, ask separately, and consider using AI to generate illustrative images of activities rather than editing real children.
If you do generate images, keep them obviously illustrations. An illustrative prompt: "Soft watercolour illustration of small hands stacking wooden blocks on a play mat, no faces, bright natural light." Check the result before posting: no realistic child faces that a parent could mistake for their own, none of your nursery's signs or uniforms, and a caption that says it's an illustration. A photorealistic generated toddler on your website invites exactly the question you don't want: "Is that one of the children?"
Telling parents in plain words
Parents are more worried by finding out than by being told. A short, specific paragraph in your privacy notice and parent handbook does more than a long legal one. An example you can adapt:
"How we use AI: our practitioners sometimes use the writing assistant built into [nursery app] to help turn their notes into clear observations and daily updates. It works inside [app], under our contract with [provider], and is not used to train AI models. A practitioner always checks and edits the text before you see it. We never put children's photos, health information or safeguarding records into AI tools, and we don't use AI to make decisions about your child. If you'd rather we didn't use the writing assistant for your child, tell your key person."
Adjust it to what you actually do. If you use a general business assistant with anonymised notes, say that instead. Parents who get daily AI-assisted updates will also value knowing how those are written; how nurseries use AI for daily reports shows a workflow that keeps the key person's voice.
A risk review for a 40-place nursery, filled in
Where you plan to use AI with children's information, data-protection law generally expects a data protection impact assessment (DPIA) when processing is likely to be high risk, and children's data plus new technology usually points that way. It needn't be long. Here is an illustrative one-page version for a 40-place nursery with 12 staff, planning to use its nursery app's writing assistant.
| Use | Data involved | Main risk | Safeguard | Decision |
|---|---|---|---|---|
| Observation write-ups in the app | Medium: names, ages, what was observed | Invented detail; data sent to unknown AI provider | Provider's written answers on file; practitioner checks every entry | Go ahead |
| Daily updates to parents | Medium | Tone or facts wrong | Key person reviews before sending | Go ahead |
| Accident and incident forms | High: injuries, sometimes health | Wording changes the facts of a record that may be relied on later | Not used; staff write these themselves | Not now |
| Support plans for additional needs | High | Sensitive detail processed unnecessarily | Not used | No |
| Newsletter and menus | Low | Minor errors | Manager proofreads | Go ahead in any business tool |
The "not now" on accident forms is worth explaining to staff with an example, because it's the decision they'll question. A practitioner's note: "Fell from second rung of climbing frame at 10:40, bumped back of head on mat, no mark, cried for about 2 minutes, then played normally. Parent told at pick-up." An illustrative AI "tidy-up": "Child had a minor slip while playing on the climbing frame and was quickly comforted." The new version reads more kindly, drops the time, the height and the head injury, and would be useless if a parent or inspector asked about it a week later. Accident records need the practitioner's own plain facts.
In this illustration, the nursery's rooms produce roughly 25 observations a week each across four rooms. If AI help saves five minutes per write-up, that's over eight hours of practitioner time a week, time that goes back to the children. That's a real benefit, and the review above is what lets the manager take it without worrying. Whether you need a DPIA before using AI tools explains the threshold in more detail.
When to get professional advice
Most of this is manageable in-house. Get advice from a data-protection adviser or solicitor if you're considering any of these: AI that assesses or scores children's development automatically; face recognition or other biometric features; putting health, additional needs or safeguarding information into any AI feature; a parent formally objecting or making a subject access request that covers AI outputs; or any suspected breach, such as a staff member having used a personal chatbot account with children's details. In that last case, act quickly: find out exactly what was entered, delete what you can, and take advice on whether it needs reporting.
Here's how that plays out in practice, as an illustration. On Monday morning a practitioner mentions she wrote up Friday's observations at home in a free chatbot. The manager sits with her the same morning and opens the chat history: three observations, with first names and ages, and one mention of a child's hearing test. The manager records what was entered and when, checks whether the model-training switch in the account's privacy settings was on (it was), switches it off, deletes the chats, and notes that deleting a chat doesn't necessarily remove it from the provider's systems straight away. Then the call to the data-protection adviser, the same day, with the facts written down, because any reporting deadline under data-protection law runs from when you became aware. Finally, the practitioner gets a work account and the three-level table, not a telling-off, so the next slip gets reported too.
Children's data and AI: what nursery managers ask
Can staff use ChatGPT at home to write up observations?
Not with personal accounts, and not with children's names or photos. Work done on a personal consumer account sits outside your nursery's control, contracts and deletion processes. If AI helps with write-ups, give staff a work account on a business plan or use the AI built into your nursery software, and keep children anonymised in any general tool.
Do we need parents' consent to use AI with their child's information?
Not always. Consent is only one of several lawful bases under data-protection law such as the GDPR, and for routine record-keeping another basis may apply. What you always need is transparency: parents should know what tools you use and why. Photos and anything unusual are different. Ask your data-protection adviser which basis fits your use.
What if a parent asks us not to use AI for their child?
Take it seriously and answer honestly about what you actually do. If the request is reasonable and practical, for example writing their child's observations without the AI assistant, agree and record it. If AI is built into a system you can't avoid, explain the safeguards in plain words. Refusing without explanation damages trust more than the AI does.
Are Microsoft Copilot or Gemini safer than ChatGPT for a nursery?
The product name matters less than the plan. Business plans from Microsoft, Google, OpenAI and Anthropic don't train on business content by default and come with contract terms; free consumer plans don't give you those. Whichever you choose, the rules about names, photos and sensitive details still apply.
Further reads
- AI Chatbots for Nursery Enquiries and Visit Bookings — Answer parents' enquiries with AI without touching children's records.
- What to Check in an AI Tool's Privacy Policy and Terms — What to look for in any AI tool's privacy policy and terms.
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How the main AI assistants handle data protection.
- Zero Data Retention: What It Means When You Choose an AI Tool — What 'zero retention' really means when choosing a tool.
- How to Roll Out an AI Policy So Staff Actually Follow It — Get staff to follow the rules once they're written.
- Tutoring Centre Admin With AI: Enquiries, Timetables, Invoices — Enquiry replies from a fact sheet, AI-proposed timetables checked for clashes, and invoices built from attendance: a tutoring centre's admin, step by step.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: GDPR text (Recital 38 on children, Article 9 special category data, Article 35 impact assessments); Famly Sidekick product page; vendor documentation for business AI plans (checked September 2026).