The first educational AI agent in China lands in Laizhou, Shandong — who bears the data compliance risks for 6,000 teachers? A lawyer explains.

📅 2026-08-27 📂 National Lawyers Hot Topics National Lawyers Hot Topics 🏷️ #Personal Information Protection #Shandong Lawyer #Educational AI Agents #Educational Legal Risks #Data Compliance

In 2025, Laizhou City in Shandong Province announced the launch of the nation's first education intelligent agent project, covering 6,000 local teachers and achieving intelligent coverage of the entire teaching workflow, including lesson preparation, classroom instruction, homework grading, and academic analysis. This news has drawn widespread attention in both the education sector and the technology field, and is regarded as a significant milestone in empowering basic education with artificial intelligence. However, beneath the halo of technology, a critical issue that is easily overlooked has surfaced: when AI becomes deeply involved in the teaching process, how are the personal information of students and teachers collected, used, and protected? And if algorithms make errors or data leaks occur, who should bear the legal responsibility? As a lawyer who has long focused on legal practice in education and technology, I believe it is necessary to conduct a sober examination of this innovative project from a legal perspective.

全国首个教育智能体落地山东莱州,6000名教师数据合规风险谁来担?律师解读

The Legal Identity of Educational Intelligent Agents and the Compliance Basis for Data Processing

Educational intelligent agents are essentially software systems based on artificial intelligence algorithms, whose operation relies heavily on the collection and analysis of large amounts of data. In the Laizhou project, the student grades, classroom performance, psychological assessment results, as well as teachers' lesson plans, teaching videos, and teaching evaluations that the system needs to process all fall within the scope of personal information as defined by the Personal Information Protection Law. Among these, information concerning minor students under the age of fourteen is furthermore classified as sensitive personal information under the law.

According to Article 28 of the Personal Information Protection Law, the processing of sensitive personal information must obtain the individual's separate consent, and must have a specific purpose and be strictly necessary. For minor students, Article 31 of the law further requires that the processing of personal information of minors under the age of 14 shall obtain the consent of the minor's parents or other guardians. This means that when deploying intelligent agents, the Laizhou education department must establish a comprehensive informed consent mechanism, clearly informing students' parents and teachers about what information will be collected, for what purposes it will be used, how long it will be retained, and obtaining explicit authorization.

Additionally, the operator of the educational intelligent agent (which may be a technology company or an education authority) qualifies as a personal information processor and must fulfill the security technical measures obligations under Article 51 of the Personal Information Protection Law, including encrypted storage, access permission control, data masking, and others. If the project involves entrusting third parties with data processing, a strict data processing agreement must be signed in accordance with Article 21, clearly defining the data security responsibilities of both parties. In practice, many educational technology projects focus only on functionality implementation in the early stages while neglecting the data compliance architecture. In the event of a data breach, they may face not only administrative penalties but also potential class-action lawsuits from parents.

The Legal Boundaries of Transparency in Algorithmic Decision-Making and Educational Equity

One of the core functions of educational intelligent agents is diagnosing learning status and providing learning recommendations based on data analysis, which is essentially algorithmic decision-making. When algorithms can predict students' academic performance, recommend learning paths, and even assist teachers in evaluating students, the fairness and transparency of their decisions become a focal point of legal concern.

Article 24 of the Personal Information Protection Law clearly stipulates that when using personal information for automated decision-making, the transparency of the decision-making process and the fairness and reasonableness of the results shall be ensured. This article also grants individuals an important right of resistance: where a decision that has a material impact on an individual's rights and interests is made through automated decision-making, the individual has the right to request an explanation from the processor and has the right to refuse a decision made solely through automated decision-making. Specifically in the educational context, if an intelligent agent automatically classifies students into different learning levels or recommends courses of varying difficulty based on algorithms, this may constitute a material impact on individual rights and interests. In such cases, parents or students should have the right to request manual review.

From a judicial practice perspective, although there have been no litigation cases specifically targeting educational algorithms in China so far, referencing the regulatory provisions on algorithmic recommendations in the E-Commerce Law and the rules on automated decision-making in the EU's General Data Protection Regulation, disputes filed by parents on grounds of "algorithmic discrimination" or "algorithmic opacity" are likely to emerge in the future. For example, if an algorithm mislabels a student as "learning disabled" due to data bias, leading to lowered educational expectations, this could infringe on the student's right to education. When promoting the application of intelligent agents, education authorities should establish an algorithmic impact assessment mechanism, regularly review the fairness of models, and set up channels for human intervention and appeals, ensuring that technological applications do not cross the legal bottom line of educational equity.

Protection of Teachers' Data Rights and Emerging Risks under Labor Law

The project covers 6,000 teachers, meaning that teachers' teaching behaviors will be extensively recorded and analyzed. Do teachers' lesson plans, teaching videos, classroom interaction data, and similar materials constitute works made for hire? How should the data rights and interests be allocated? This involves the intersection of copyright law and labor law.

According to Article 18 of the Copyright Law, for works created primarily using the material and technical resources of a legal person or unincorporated organization, for which the legal person or unincorporated organization bears responsibility, the author enjoys the right of attribution, while all other rights are enjoyed by the legal person or unincorporated organization. Lesson plans created by teachers to fulfill teaching tasks typically constitute works made for hire. However, intelligent agent systems may conduct secondary processing or algorithmic optimization of lesson plans, which could potentially generate new derivative data or works, and the ownership of rights therein needs to be clarified in agreements between teachers and educational institutions. In practice, when many schools promote smart education, they have not entered into detailed agreements with teachers regarding data rights and the scope of work usage, leading to subsequent disputes.

Furthermore, the quantitative evaluation of teachers' work performance by educational agents may touch upon the bottom line of the Labor Contract Law concerning working conditions and assessment systems. If automatically generated evaluation results directly affect teachers' performance-based pay, professional title evaluation, or contract renewal, educational institutions should ensure that the evaluation standards are lawful and reasonable, and that they have been publicly announced through democratic procedures in advance. Pursuant to Article 4 of the Labor Contract Law, when an employer formulates, modifies, or decides on rules and regulations or major matters that directly involve the vital interests of workers, it shall discuss them with the workers' congress or all employees, solicit proposals and opinions, and determine them through equal consultation with the trade union or worker representatives. If teachers believe that the evaluation by the agent is unfair, they have the right to assert their rights in accordance with Article 89 of the Labor Law; however, the burden of proof is relatively heavy, and lawyers need to be involved to assist in collecting and preserving evidence.

Legal Liability and Emergency Response Plans for Data Security Incidents

Educational intelligent agents aggregate massive amounts of sensitive data; once a leak occurs or the data is maliciously exploited, the consequences would be catastrophic. In 2024, a data breach in a certain region's education system led to the illegal sale of tens of thousands of students' information, and the responsible personnel were held criminally liable. The Laizhou project should take this as a cautionary lesson and establish a comprehensive emergency response mechanism for data security incidents.

Under Article 27 of the Data Security Law, data processing activities shall be conducted in accordance with the provisions of laws and regulations, with sound full-process data security management systems established, data security education and training organized, and appropriate technical and other necessary measures taken to ensure data security. Article 45 of the said Law also provides for legal liability for failure to fulfill data security protection obligations, including orders for correction, warnings, and fines, and in serious circumstances, may result in substantial fines or even revocation of relevant business licenses.

For educational authorities and technology service providers, it is crucial to clearly define the boundaries of data security responsibilities. In practice, the common approach is: the education department, as the data controller, bears overall responsibility, while the technology company, as the processor, fulfills security obligations in accordance with the contract. However, once a data breach occurs, regulators often hold the controller accountable first. Therefore, the Laizhou education department should clearly specify in the project contract the technology company's security protection obligations, liability for breach of contract damages, and insurance arrangements, while also establishing an internal data classification and grading system, with the highest level of access control implemented for core data. Lawyers recommend that educational institutions should also conduct regular data security audits and purchase cybersecurity insurance to mitigate risks.

The future of educational intelligent agents: Law first, so that technology can be used with peace of mind.

The education AI agent project in Laizhou, Shandong is undoubtedly a bold and forward-looking exploration that may reshape the form of basic education and improve teaching efficiency. However, the more advanced the technology, the more complex the legal risks. From personal information protection to algorithmic fairness, from teachers' rights to data security, every aspect requires the support of a legal framework.

For other education departments and schools planning to follow suit across the country, the Laizhou project provides an important reference: legal compliance review should be introduced at the very beginning of a project rather than as a post-hoc remedy. Specific recommendations include: First, conduct data protection impact assessments to identify high-risk processing activities; Second, develop detailed personal information processing rules and implement informed consent mechanisms; Third, sign rigorous contracts with technical service providers, clearly defining data ownership and security responsibilities; Fourth, establish complaint and manual review mechanisms for teachers and students to ensure the fairness of algorithmic decision-making; Fifth, organize regular legal training to enhance data compliance awareness among faculty and staff.

The future of educational intelligent agents is worth anticipating, but the boundaries of law must be clearly defined. As legal practitioners, we welcome technological innovation and, more importantly, hope to see every innovation advance steadily along the track of the rule of law. Guangdong Zhiming Law Firm has long focused on data compliance and dispute resolution in the field of educational technology, and has provided legal consulting services to numerous educational institutions and technology enterprises. If you encounter legal questions during the deployment or use of educational intelligent agents, we welcome in-depth discussions with us. Law is not an obstacle to innovation, but a guardrail that enables innovation to go far and steady.

⚖️ Start Your Professional Legal Service Journey Now

📍 Address: Room 1802, Block A, Xintian Century Business Center, Shixia North 2nd Street, Futian District, Shenzhen

  • @ Email: zhiminglawfirm@126.com
  • WeChat ID: zhiminglawyer01
  • 💬 WeChat Official Account: gd_zhiming

Administrative Disputes · Marriage and Family Matters · Civil and Commercial Litigation · Criminal Defense - Free Online Consultation

Consultation QR Code

Scan to add consultation QR code

Law Firm Official Account

Scan to follow us

"WeChat Help"
微信二维码
"Press and hold on QR code"
"Add WeChat Inquiry"
×
微信二维码
"Press and hold on QR code"
"Add WeChat Inquiry"