Victorian schools and student privacy: the IPPs, OVIC, and the software gate
The most common misconception in Australian school privacy is that the Privacy Act 1988 covers everyone. It doesn't: the federal Act binds private-sector organisations — non-government schools, and edtech vendors — but not state agencies, and a Victorian government school is a state agency. Government schools in Victoria answer to the Privacy and Data Protection Act 2014 (Vic), its ten Information Privacy Principles (IPPs), and the Office of the Victorian Information Commissioner (OVIC) — with the Health Records Act 2001 (Vic) covering health information (allergies, disability support, psychology reports) under its own Health Privacy Principles. Same territory as the federal APPs, different map — and in a few places, meaningfully different terrain.
The two-track reality in one paragraph
A Victorian government school: PDP Act, IPPs, OVIC, Department of Education policies (including the Schools' Privacy Policy every DE school operates under). A Victorian Catholic or independent school: the federal Privacy Act and APPs, OAIC. The vendor either school buys from: the federal Act (subject to its small-business exemption — ask anyway) plus, for government schools, whatever the school's contract flows down — the PDP Act contemplates agencies binding contracted service providers to the IPPs, which is how a state principle reaches a private vendor. Practical consequence: a vendor serving Victorian government schools should be able to speak IPP as fluently as APP, and a school should expect that.
The IPPs that do the work in edtech decisions
The ten IPPs broadly parallel the APPs; four carry most of the edtech weight:
- IPP 1 (collection) — collect only what is necessary for the school's functions: Victoria's data-minimisation principle, and the legal weight behind "why does this app need a birthday?" in a DE school.
- IPP 2 (use and disclosure) — information collected for teaching shouldn't drift to other purposes: the anti-repurposing principle that makes "we use data to improve our products" a question, not a boilerplate.
- IPP 4 (data security) — protect what's held, and — 4.2 — destroy or permanently de-identify what's no longer needed: Victoria's version of the retention-and-deletion duty.
- IPP 9 (transborder data flows) — the sharpest difference in framing from the federal APP 8: personal information may leave Victoria only under conditions (the recipient upholds substantially similar principles, consent, contractual necessity, and similar). It's the principle behind every "where is the data hosted?" row in a Victorian risk assessment — worked through honestly below, including for our own product.
Access and correction in government schools typically route through Freedom of Information processes alongside IPP 6 — the student-data-rights picture with Victorian plumbing. And on breaches: Victoria has no general individual-notification mandate like the federal NDB scheme — public-sector incident reporting runs through OVIC's protective data security regime — which is precisely why breach-notification clauses belong in the contract rather than being assumed from statute.
The software gate: how a tool actually gets into a DE school
Victoria has done what the OVIC examination of 2020 recommended after finding individual schools poorly placed to assess vendor privacy practices themselves: centralised the assessment. Under the department's Software and Administration Systems policy, before adopting software the department doesn't provide, a school checks the Arc Software Catalogue for a Safer Technologies 4 Schools (ST4S) risk-assessment report; unassessed products go to the department's IT Security team for assessment (usable in the meantime). For teachers this converts due diligence from a solo research project into a lookup — and it means the vendor questions that matter most in Victoria are "what's your ST4S status?" and "are you in the Arc catalogue?", because those answers determine whether adoption is an afternoon or a process.
IPP 9 and offshore hosting, worked honestly (including ours)
The transborder principle is where Victorian assessments and offshore SaaS meet, so here is the reasoning pattern — applied to us, since we host in AWS's US-West region and say so plainly. IPP 9 restricts transferring personal information about an individual outside Victoria. The question for any tool is therefore: what identifiable information actually crosses the border? For a conventional product — names, emails, birthdays on a US server — IPP 9 is squarely engaged and the school needs one of its conditions to hold. For a zero-PII architecture, the analysis is different in kind: what crosses the border is a class code, a generated animal name, and pseudonymous game state; the mapping that makes any of it about an identifiable child — the roster — stays on paper, in the classroom, in Victoria. Our position is that IPP 9's concern has little to attach to when the identifying layer never leaves the school.
And the honest counterpoint, stated with equal weight: pseudonymous data is not anonymous data, Victorian guidance — like every serious privacy regulator — treats re-identifiable information cautiously, and an assessor is entitled to score offshore pseudonymous data rather than wave it through. We don't ask schools to skip the question; we ask them to put it to every vendor and compare the answers' shape: "your child's name, email and progress are on our US servers, but we have a contract" and "an animal name's spreadsheet scores are on our US servers, and your teacher holds the only key" are both offshore stories — they are not the same story. Australian-region hosting remains under consideration as our Victorian pilots grow; if we move, this section gets simpler.
In practice
- Government school? Your citations are IPPs and OVIC — when a vendor's paperwork speaks only APP, ask them to translate; fluency is a competence signal.
- Use the gate: Arc catalogue first, ST4S report second, the eleven questions on anything that passes — centralised assessment is a floor, not a verdict.
- Put IPP 1 to every form field and IPP 9 to every hosting answer — the two questions that expose the most, fastest.
- Contract what statute doesn't give you: breach notification windows, deletion with backup honesty, no repurposing — the flow-down is where a state school's leverage actually lives.
- Catholic and independent readers: your school is federal-track, but your government-school neighbours' gate (ST4S) is shared national infrastructure — use it too.
Reference
- Privacy and Data Protection Act 2014 (Vic) — the Information Privacy Principles (Sch 1) and contracted-service-provider provisions; Health Records Act 2001 (Vic).
- Office of the Victorian Information Commissioner — IPP guidelines; Examination into the use of digital learning tools in Victorian government primary schools (2020).
- Department of Education (Vic) — Schools' Privacy Policy; Software and Administration Systems policy (Arc Software Catalogue, ST4S assessment requirement); Procurement – Schools policy.
- Education Services Australia — Safer Technologies 4 Schools (ST4S).
© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.