Guide7 min read

Is It Safe to Use AI for Childcare? (Nurseries, Nannies, Daycare)

Yes for de-identified admin, no with children's data: never paste a child's name, allergy or pickup note into a consumer AI chatbot.

By Pierre de ONYRI

Here is the short answer. AI can help with childcare admin, but never feed it children's data. This is data at its most sensitive. A leak is not only a privacy problem. It is a safety problem. Pickup authorisations, custody arrangements and emergency contacts protect a child from the wrong person. Names, ages, allergies and medical notes are private. Under GDPR, health data is even special-category data. Under COPPA in the US and the Children's Code in the UK, children's data gets the highest protection. The fix is simple. Anonymise children's names before any prompt. Never paste a medical, pickup or custody note tied to a name.

Why children's data gets the highest protection

In the US, COPPA is the rule that protects children's data online. Its full name: the Children's Online Privacy Protection Rule. The FTC (Federal Trade Commission) enforces it. It covers personal information collected online from children under 13. That information is defined broadly. Name, home address, email, phone. Photos or video. Persistent identifiers. Before any collection, operators must give parents notice and obtain verifiable parental consent.

In January 2025, the FTC strengthened the rule. The new version took effect on 23 June 2025. The signal is clear: children's data protection is tightening, not relaxing. A local nursery is not necessarily an “operator” under COPPA. But COPPA sets the principle for the US market. Children's data is the most protected category.

In the UK, the Children's Code plays that flagship role. Its other name: the Age Appropriate Design Code. The ICO (Information Commissioner's Office) issued it. It sets 15 standards built on data protection law. Its first principle: the best interests of the child come first. It is backed by real enforcement powers. Fines can reach 17 million pounds, or 4% of global turnover. The Code mainly targets the design of online services. Day to day, a UK setting is governed by the UK GDPR and the Data Protection Act 2018. But the message is the same: the child comes first.

Safety data, not just privacy data

This is the most important point, and the most sober. A child record does not just hold private data. It holds safety data. Who is allowed to collect the child. Which parent has custody. Who to call in an emergency. This information physically protects the child. A leak here does not just cost a fine. It could help the wrong person collect a child. That is why you never paste a pickup authorisation, a custody note or an emergency contact into a consumer AI.

Allergies and medical notes: health data

Allergies and medical notes deserve a separate mention. Under Article 9 of the GDPR, health data is “special category data”. It carries extra protection. To process it lawfully, you need an Article 6 lawful basis and a separate Article 9 condition. The ICO takes a broad view of health. Any information about physical or mental health counts. Past, present or future. Even where no doctor is involved.

So a nursery's note that “this child needs an inhaler” is special-category health data. The same goes for a nut allergy or a developmental note. High-risk processing, which children's and health data typically is, requires a Data Protection Impact Assessment (DPIA) before it begins. That is what the ICO advises for special category data.

  • The child's first name, last name and age — personal data.
  • Allergies, medication and developmental notes — special-category health data (Article 9).
  • Pickup authorisations and custody arrangements — safeguarding data.
  • Emergency contacts and parents' details — adults' personal data.
  • Photos and video of the child — personal data covered by COPPA.
The moveThe risk
Pasting a name + an allergy into the AISpecial-category health data exposed (GDPR Article 9)
Pasting a pickup authorisationSafety data exposed — physical risk to the child
Sending a child's photo to the AIRegulated personal data (COPPA), not a casual file
“It's only a child's first name”Children's data = the most protected category (COPPA, Children's Code)
The risk isn't using AI for admin — it's the children's data you leave behind in the prompt.

The fix: anonymise before you send

Good news: AI is still useful for a nursery. It can draft the family newsletter. It can plan activities. It can structure an incident report. For all of that, it needs no real child's name. Anonymise the first names before you send. AI writes perfectly well on de-identified text. Mind the wider frame too: get parental consent and pick vetted tools bound by a data processing agreement (DPA).

Two-part diagram: at top, a child record card (name, age, allergy, pickup authorisation) and a small child figure, all in amber, travel toward an AI card that receives the exposed record with an amber high-risk alert; at bottom, the same card anonymized shows only cobalt tokens, and the AI receives only tokens with a checkmark under a shield.
After the FTC's COPPA FAQ, the ICO's introduction to the Children's Code, and the ICO's guidance on special category data.

When you really must describe a real case, anonymise it first. Replace each name with a token. Never attach a medical, pickup or custody note tied to a name. The AI reasons about the shape of the situation, never the real values. You restore the real values afterwards, locally.

  1. 1Spot the children's data: names, ages, allergies, medical notes, pickup.
  2. 2Replace the names with reversible tokens, in the browser.
  3. 3Never send a medical or safety note tied to a name.
  4. 4Send only the de-identified text to the AI.
  5. 5Restore the real values in the reply, locally.

That's what ONYRI Sanitize is for. The engine detects sensitive data — names, allergies, medical notes, contacts — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. The AI finds only tokens, never a child's data. You get the help, without exposing what COPPA, the Children's Code and GDPR ask you to protect.

Frequently asked questions

Is it safe to use AI for childcare?
Yes for de-identified admin, no with children's data. AI can draft a newsletter or plan activities with no real name at all. But never paste a child's name, an allergy, a medical note or a pickup authorisation into a consumer AI. Children's data is the most protected, under COPPA, the Children's Code and GDPR. Anonymise it before you send.
Are a child's allergies and medical notes sensitive data?
Yes. Under Article 9 of the GDPR, health data is special-category data with extra protection. The ICO takes a broad view: any information about physical or mental health, even without a doctor. A note like “nut allergy” or “needs an inhaler” qualifies. Never paste it into an AI tied to a child's name.
Why are pickup authorisations so sensitive?
Because they are safety data, not just privacy data. They say who is allowed to collect the child. A leak could help the wrong person collect them. That is a physical risk to the child. Treat these notes as the most sensitive in your setting, and keep them out of any AI.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next