Student privacy in Australian schools: the Privacy Act, ST4S, and the incoming Children's Code
Australia's rules for children's data in schools are a layered system with no single children's-privacy statute (yet): a federal Privacy Act governing private-sector entities, state laws governing public schools, a nationally coordinated vendor-assessment scheme, and a safety regulator with no close overseas equivalent. Here's the map.
Layer 1: the Privacy Act 1988 and the APPs
The federal Privacy Act and its thirteen Australian Privacy Principles govern "APP entities" — which includes private schools and, importantly for procurement, edtech vendors (note: the small-business exemption — generally under $3M turnover — has notable carve-outs, including businesses that trade in personal information; the 2024 reform program has also signalled the exemption's days may be numbered). The APPs most relevant to school tools:
- APP 3 (collection): collect only what's reasonably necessary for a function — Australia's data-minimisation principle, and legally grounded backing for the question "why does a maths app need a birthday?"
- APP 5 (notification): individuals must be told what's collected and why — the transparency our 11-question checklist operationalises.
- APP 8 (cross-border disclosure): an entity sending personal information overseas generally remains accountable for it — the principle behind school assessors' offshore-hosting questions.
- APP 11 (security & destruction): protect it; destroy or de-identify when no longer needed.
The Notifiable Data Breaches scheme (since 2018) makes eligible breaches reportable to the OAIC and affected individuals — one more reason the best breach posture is an empty inventory.
Unlike the US (COPPA), Australia has had no dedicated children's online privacy law — children's data is just personal information, with OAIC guidance noting capacity/consent considerations. That's the gap the next item fills.
Layer 2: the Children's Online Privacy Code (incoming)
The Privacy and Other Legislation Amendment Act 2024 — the first tranche of the long-running Privacy Act review — directs the OAIC to develop a Children's Online Privacy Code, an enforceable APP code for online services likely to be accessed by children, explicitly modelled on the territory pioneered by the UK's Age Appropriate Design Code: best-interests design, data minimisation, high-privacy defaults. It's moving: the OAIC published an exposure draft in March 2026 (consultation closed mid-year), with the final Code required to be registered by 10 December 2026 — commencement and transition timing still to be set. The same amendment package introduced a statutory tort for serious invasions of privacy. For schools, the practical takeaway is directional: Australian expectations for children's services are converging on minimisation-by-default — procurement choices made on that basis today won't need unwinding.
Layer 3: public schools and state law — the two-track reality
Government schools aren't governed by the federal Act at all: they're state agencies, under state and territory privacy regimes administered alongside each education department's own policies — while Catholic and independent schools sit under the federal Act. Since roughly two-thirds of Australian students attend government schools, the state track is the majority track, and it's a patchwork: Victoria has the Privacy and Data Protection Act 2014 (IPPs, regulator OVIC) — our full Victorian page covers it natively, including the department's software-assessment gate; NSW the PPIP Act 1998 (with a mandatory breach-notification scheme for the public sector since 2023); Queensland moved to APP-style "QPPs" from mid-2025; WA passed its first general privacy statute in 2024; SA runs on administrative instruction rather than legislation; the ACT's Act closely mirrors the APPs. The direction of travel is convergence toward APP-shaped principles — but today, the operative citations differ by state.
Two operational consequences regardless of state: department approved/assessed software processes (Victoria's Arc catalogue + ST4S check being the most developed) are often mandatory for public schools, and several departments express strong preferences — sometimes requirements — around Australian data residency for student information, under transborder principles (like Victoria's IPP 9) that are framed more sharply than APP 8. Know which regime you're in before evaluating any tool; the vendor conversation should match your track, not the vendor's marketing.
Layer 4: ST4S — the shared assessment most teachers haven't heard of
Safer Technologies 4 Schools (ST4S), run by Education Services Australia for the national/state education bodies, assesses edtech products against a standardised privacy-and-security framework and shares results with education departments and school sectors — a genuinely useful piece of national coordination that saves each school re-running the same diligence. If you're evaluating a vendor: ask whether they've completed an ST4S assessment, and read it. (Our checklist remains worth running regardless — ST4S tells you a product's answers; you still want to understand them.)
Layer 5: the eSafety Commissioner
Australia's eSafety Commissioner (Online Safety Act 2021) is a regulator with no direct overseas twin: complaint schemes for cyberbullying material targeting children and image-based abuse, industry codes, and — most useful day-to-day — an extensive, free classroom resource library (the eSafety Education materials, Toolkit for Schools, parent resources). For the classroom-conduct half of digital citizenship, eSafety materials pair naturally with the judgment-practice half (group chats, scams) — one supplies the Australian reporting pathways, the other supplies the reps.
What this means for choosing tools (and where we stand)
An Australian-context evaluation adds three questions to the universal eleven: (1) Where is the data hosted, and if offshore, what's the APP 8 story? (2) Has the product been ST4S-assessed? (3) Would its defaults survive the incoming Children's Code (minimisation, no tracking, high-privacy defaults)?
Our own answers, stated plainly: Wiz Kids collects no personal information from students or teachers — a class code, a generated animal name, a picture-secret, and pseudonymous game progress (the full inventory). We currently host in AWS's US-West region; our position is that APP 8's concern — personal information leaving Australian oversight — has little to attach to when no personal information is stored, and the incoming Code's minimisation-by-default direction is our architecture's starting point rather than a compliance retrofit. We state the hosting fact rather than bury it, because that's what we'd want from any vendor; Australian-region deployment is under consideration as Australian school pilots grow, and an ST4S assessment is on our roadmap as pilots formalise.
In practice
- Identify your regime (state Act + department policy for government schools — Victorians, here's yours; federal Act for most non-government) before evaluating anything.
- Ask for ST4S status on every shortlisted product; read assessments rather than filing them.
- Use APP 3 language in vendor conversations — "reasonably necessary for your function" is a question with legal weight behind it.
- Pull eSafety classroom materials into your digital citizenship provision — they're free, Australian, and kept current with local reporting pathways.
- Buy for the Code that's coming: minimisation-by-default vendors won't need re-procurement in two years.
Reference
- Privacy Act 1988 (Cth), including the Australian Privacy Principles (Sch 1); OAIC APP Guidelines.
- Privacy and Other Legislation Amendment Act 2024 (Cth) — Children's Online Privacy Code provisions; statutory tort.
- OAIC — Notifiable Data Breaches scheme; guidance on children and young people's privacy.
- State regimes: Privacy and Personal Information Protection Act 1998 (NSW); Privacy and Data Protection Act 2014 (Vic); equivalents in other jurisdictions.
- Education Services Australia — Safer Technologies 4 Schools (ST4S) initiative.
- Online Safety Act 2021 (Cth); eSafety Commissioner education resources.
© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.