Short answer
There is no absolute ban on university staff using AI tools in their work, but they cannot lawfully upload material that contains your personal data to an external AI tool without a proper legal basis, and in most cases without being transparent about it. Whether a particular use is lawful depends on what was uploaded, why, which tool was used, and what the university has already told you about how it processes your data. The mere fact that they did not specifically tell you in advance does not automatically make it unlawful, but a failure to inform you at all is a strong indicator that the transparency requirements of data protection law have not been met.
The data protection framework
The relevant law is the UK GDPR together with the Data Protection Act 2018. Your coursework, a complaint you have made, and other information about you will normally be personal data because it relates to you and identifies you. A complaint in particular may contain special category data (for example about health, disability or beliefs) or information that is sensitive in context, which attracts stronger protection.
When staff put that data into an AI tool, that is a form of processing. Under Article 5 of the UK GDPR the university, as data controller, must process personal data lawfully, fairly and transparently, only for specified purposes, and must keep it secure. It needs an identified lawful basis under Article 6 (and, for special category data, an additional condition under Article 9) for each distinct processing operation. The ICO’s guidance on AI and data protection makes clear that each separate purpose needs its own lawful basis and cannot simply be assumed.
The transparency principle is central to your question. Articles 13 and 14 require the university to tell people, usually through a privacy notice, what data it collects, the purposes and lawful basis, and who it shares data with. If the university feeds student data into a third-party AI system, that should ordinarily be reflected in its privacy information. If nothing anywhere told you this could happen, the university has a transparency problem, even if the underlying purpose was legitimate.
Why uploading to a public AI tool is a particular concern
The biggest risk arises with public, consumer-grade tools such as the free version of ChatGPT. With those tools, data entered may be transmitted to servers outside the UK and, depending on settings, may be retained or used to train the model. That raises issues of security (Article 5(1)(f)), international transfers (Chapter V of the UK GDPR), and loss of control over the data. This is exactly why UK universities’ own guidance typically prohibits staff and students from entering personal or confidential information into public generative AI. Reading, Oxford, Liverpool and others tell staff not to submit restricted or personal information to generative AI unless it is necessary and proper safeguards, including a Data Protection Impact Assessment, are in place. Uploading someone else’s work is also flagged as an intellectual property and copyright concern quite apart from data protection.
By contrast, an enterprise or institutionally licensed AI product, procured with a data processing agreement, data held in the UK or EU, and training on inputs switched off, can be a lawful and secure processor acting on the university’s instructions. In that situation the use may be entirely proper. So the identity and configuration of the tool matters a great deal.
Does it make a difference that it was your complaint or coursework?
Yes, potentially. A few distinctions matter:
Coursework marked or checked through an approved plagiarism or AI-detection system that the university has told students about, and that is covered by its policies and privacy notice, is generally a legitimate and disclosed processing operation. Pasting your essay into a public chatbot to help write feedback or to check for AI use, without any institutional authorisation, is a very different matter and is much harder to justify.
A complaint is more sensitive. Complaints often contain allegations, third-party information and sometimes special category data. Putting that into an external AI tool to summarise or draft a response could disclose sensitive information inappropriately, undermine confidentiality, and breach the university’s own complaints procedure. The more sensitive the content, the harder it is to justify processing it through an AI tool without clear safeguards and a lawful basis, and the greater the fairness expectation that you would be informed.
Alternative innocent explanations
Before treating this as a breach, it is worth establishing what actually happened, because there are legitimate possibilities. The staff member may have used an institutionally approved and contractually secured AI tool that is covered by the university’s privacy notice, in which case there may be no breach and no separate duty to tell you each time. The data may have been anonymised before it was entered, so that it was no longer personal data. Or the AI use may have been limited to generic drafting that did not include any information identifying you. Equally, it is possible that a staff member pasted identifiable material into a public tool contrary to policy, which would be a genuine compliance failure. You cannot usually tell which of these occurred from the outside, so the sensible first step is to find out the facts rather than assume the worst.
What you can do
1. Check the university’s student privacy notice, its complaints procedure, and any policy on the use of generative AI. See whether these disclose AI processing and which tools are approved. This tells you whether what happened was within the disclosed framework.
2. Make a subject access request under Article 15 of the UK GDPR to the university’s data protection officer. Ask what personal data about you has been processed, the purposes, the recipients, and specifically whether any of your data has been entered into or shared with any AI or automated tool, which tool, and under what safeguards. The university must normally respond within one month and free of charge.
3. Ask directly and in writing. You can ask the department or the data protection officer to confirm whether your coursework, complaint or personal data was uploaded to any AI tool, whether that tool is institutionally approved and covered by a data processing agreement, and what has happened to the data. A clear written question often resolves the matter quickly.
4. Complain internally first. If you believe your data was mishandled, raise it through the university’s data protection complaint route and, if relevant, its student complaints procedure. Give the university the chance to investigate and remedy the issue.
5. Escalate to the Information Commissioner’s Office. If you are not satisfied with the university’s response, you can complain to the ICO, which regulates data protection in the UK. The ICO will usually expect you to have raised it with the university first. It can investigate and require changes, though it does not generally award compensation.
6. Consider the Office of the Independent Adjudicator. If the AI issue is bound up with a wider student complaint about how the university handled your coursework or grievance, you may be able to take that to the OIA once you have exhausted the internal process and received a Completion of Procedures letter.
Remedies and realistic expectations
If there has been a breach, the practical remedies are usually an explanation, an apology, deletion of the data from the tool where possible, changes to practice, and reassurance about security. A claim for compensation under the data protection legislation is possible in principle where you have suffered material damage or genuine distress, but the courts require more than a trivial or purely technical breach, so damages are often modest or unavailable for minor incidents. For most people the more valuable outcomes are getting clear answers, ensuring the data is removed or secured, and preventing it happening again.
Key facts that would change the answer
The analysis turns on several things you may not yet know: exactly which tool was used and whether it was an approved institutional product with a data processing agreement; whether the data was identifiable or anonymised; whether the university’s privacy notice and policies already disclosed this kind of processing; how sensitive the content of your complaint was; and whether the data was retained or used for model training. Establishing these points through the questions and subject access request above will tell you whether this was a legitimate, disclosed use or a genuine breach that merits escalation.
This answer draws on broad legal knowledge and checks current law, guidance and procedure against relevant sources.
How do we ensure lawfulness in AI?ico.org.ukData Protection and AIreading.ac.ukUse Generative AI services safely | Information Securityinfosec.ox.ac.ukUniversity Guidance on the use of Generative Artificial Intelligence (GenAI) in learning, teaching, and assessmentliverpool.ac.ukKNOW WHERE YOU STAND
Ready to stop guessing?
The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.