Australia's proposed privacy reforms: what independent schools should do now
Australia’s next round of privacy reform has reached the exposure draft stage, and independent school leaders have a short window to help shape it. The Attorney-General’s Department opened consultation on the Privacy Amendment (Personal Data Protection) Bill 2026 on 31 August. Submissions close on 18 September 2026. The proposals remain subject to government consideration. Consultation details.
For independent schools, the proposals raise questions about the whole life of student and family information: why it is collected, how it is used, who receives it, how long it is retained and what happens after a breach.
Principals, boards and IT leaders need to understand which responsibilities already apply, which changes have a confirmed start date and which proposals remain unsettled. That is the starting point for deciding what work to fund now and what to track as the legislation develops.
Status checked on 12 September 2026. The discussion below distinguishes existing law, scheduled changes and proposals still under consultation.
Lead photo by Philipp Katzenberger on Unsplash.
What has already happened, and what comes next
There are several reform timelines to keep on the school calendar.
| Development | Position as at 12 September 2026 |
|---|---|
| First reform legislation | Parliament passed the Privacy and Other Legislation Amendment Act 2024 in November 2024, establishing the framework for the Children’s Online Privacy Code and a statutory privacy tort. Attorney-General’s Department. |
| Serious invasions of privacy | The statutory tort commenced on 10 June 2025, creating an additional avenue for individuals to seek redress through the courts. OAIC explanation. |
| Automated decision transparency | New privacy-policy obligations commence on 10 December 2026 for covered uses of personal information in automated decision making. OAIC issues paper. |
| Children’s Online Privacy Code | The OAIC must register the final Code by 10 December 2026. Registration is a separate milestone from the obligations and transition arrangements in the final instrument. OAIC consultation page. |
| The new 2026 package | Consultation is open. The exposure draft’s commencement table has no dates filled in, so schools cannot yet plan against a settled commencement date for this package. Exposure draft, clause 2. |
The December automated-decision changes deserve immediate attention. They concern computer programs using personal information to make, or do something substantially and directly related to making, decisions reasonably expected to significantly affect an individual’s rights or interests. The privacy policy must describe relevant kinds of information and decisions. A human making the final decision does not automatically put a system outside scope. OAIC issues paper, pp. 12–15 and 25–26.
My starting point for a school would be to identify software that scores or recommends outcomes for admissions, scholarships, student interventions or staff recruitment, then assess the actual decision process against that threshold.
The Children’s Online Privacy Code also deserves its own review. Its statutory scope concerns specified online service providers likely to be accessed by children. A school should assess the services it provides and procures against the final scope and any exceptions. Simply having students is insufficient to determine how the Code applies. OAIC background.
Independent schools already have privacy responsibilities
The OAIC says the Privacy Act usually covers private schools. Coverage can arise through turnover, connection to a larger organisation, or providing a health service and holding health information. That last category can include first aid and medication support. Government schools generally sit under different arrangements. OAIC guidance on education and childcare.
Schools should establish their own position now. Waiting for the proposed reforms would leave existing responsibilities unattended.
The OAIC’s current Guide to securing personal information already addresses senior management oversight, information registers, cloud-provider assessment and breach preparation. The organisational foundations for this work are well established.
The proposed changes that matter most for schools
Emerging devices make it important to examine the information a service collects and infers. Photo by Vitaly Gariev on Unsplash.
A fair and reasonable test for handling information
The draft would replace several existing collection, use and disclosure rules with a fair, reasonable and lawful handling requirement, subject to exceptions. Factors include reasonable expectations, transparency, data minimisation, choice, proportionality and children’s best interests as a primary consideration. Exposure draft, Schedule 2.
My reading for schools is that a broad enrolment consent should never become the end of the assessment. A compulsory classroom platform gives a student very different choices from an optional activity.
If an app requests a full date of birth, a voice recording and persistent location access, the school should be able to explain the educational need for each. It should also consider whether a less intrusive configuration or another service would meet that need.
Personal information extends beyond the obvious fields
The proposed definition covers information that relates to an identified or reasonably identifiable person, including identifiers and behavioural patterns. Collection expressly includes generating or deriving information. Defined precise geolocation tracking data would become sensitive information. Exposure draft, Schedule 1.
For an IT review, I would therefore include analytics, inferred learning profiles, device identifiers and app telemetry alongside names and email addresses. Removing a student’s name may still leave a record that can be linked back to them.
Where consent is required, the draft would expressly require it to be voluntary, informed, current, specific and unambiguous. Sensitive-information collection would still generally require consent, with exceptions. White & Case’s analysis.
Clearer responsibility for outsourced processing
The proposed processor framework applies where both parties are entities covered by the Australian Privacy Principles. Handling under a controller’s written instructions can shift responsibility for relevant breaches to that controller. Processors retain direct obligations under APP 1 and APP 11; acts outside instructions fall outside the exception. Consultation paper, Schedule 6.
For a school, that makes the supplier agreement especially important. Record what a provider may do with student information, who else may receive it and what happens when the contract ends. Investigate whether optional analytics, advertising or AI training involve the supplier using information for its own purposes.
A provider’s role needs to be assessed for the particular activity. Calling every supplier a processor would obscure those differences.
A tighter breach-response timetable
Breach preparation connects system access, supplier contacts and decisions about notifying affected people.
The proposal requires notification to the Information Commissioner within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has occurred. The existing requirement to take reasonable steps to complete assessment of a suspected eligible breach within 30 days remains. The package also proposes explicit preparedness and harm-mitigation duties extending beyond eligible breaches. Consultation paper, Schedule 3.
The 72-hour clock has a specific trigger. Staff need to escalate concerns promptly so the school can assess them, act to protect people and meet whichever notification obligations apply.
I would rehearse a supplier incident that arrives on a Friday afternoon during school holidays. Identify who can activate the response, contact the provider, obtain advice and authorise communications. Give those roles deputies. A plan that depends on the principal being available will be difficult to operate under pressure.
Knowing what is held, and reviewing whether it should remain
Proposed APP 11 changes require identification of relevant personal information, consideration of destruction when information is no longer needed, and regular evaluation of security and disposal compliance. Retention required by Australian law or a court or tribunal order is protected. Exposure draft, Schedule 3, Part 2.
For schools, I would start with abandoned trials, historic class exports, old accounts and duplicate records in shared drives. Establish an approved retention schedule that accounts for education, child-safety and other applicable requirements, then make disposal work across the systems that actually hold the information.
What remains unsettled
The proposed erasure right targets large digital platforms. It should not be read as a general right to demand deletion of every school record. The draft also leaves broader removal of the small-business and employee-records exemptions outside this package. White & Case’s analysis.
The consultation paper separately canvasses measures still under development, including a 60-day complaint-response requirement and additional regulatory powers. Those proposals are not all expressed in the exposure draft. Consultation paper, pp. 38–40.
Schools can use the consultation to describe practical issues: supplier cooperation, contractual changes, record retention and the time needed to assess their existing systems. Meanwhile, leadership can fund the preparatory work that is useful under both current law and the proposed framework.
Use established assessments to help prepare
Supplier reviews are one practical part of this broader privacy work, and education already has a substantial foundation in Safer Technologies 4 Schools (ST4S).
Administered by Education Services Australia for participating Australian education sectors and New Zealand, ST4S provides a shared assessment process covering security, privacy, interoperability and online safety. Suppliers provide responses and, where required, supporting documents. The ST4S team analyses and validates the responses, with results shared through approved stakeholders. ST4S general information.
I would use relevant ST4S findings as evidence when reviewing an existing service or considering a new one. The school still needs to assess its particular use, configuration and obligations as the law changes.
Queensland’s Department of Education illustrates how review evidence feeds into consent. Step 1 of Process: Obtaining consent, on page 7 of its guideline, directs staff to identify services requiring consent and collate the name, URL, onshore or offshore hosting, purpose, terms and privacy-policy links, data disclosed and extra consent requirements. Staff should draw on an Online Service Risk Review, where available; these reviews are marked for DoE employees only. Online-services consent guideline.
Principals oversee the approved-service register, and incoming principals are expected to review it. Guideline, page 5. These are departmental arrangements; independent schools can adapt the governance approach to their own legal obligations.
Turn review evidence into school decisions
Service assessments should give school leaders clear evidence for decisions about student information.
For a SaaS platform, iOS app or software package, I would bring that evidence into a third-party privacy and technology risk register. The following fields are suggested preparation steps. The proposed legislation does not prescribe this template. The Queensland Audit Office’s third-party risk checklist offers further governance questions.
| Record | What the school should capture |
|---|---|
| Service and use | Product name, URL, supplier, edition, student cohort, school owner and intended purpose. Include free services and trials. |
| Data and location | Information collected or inferred; hosting, backup and support countries; subcontractors; any advertising or AI-training uses. |
| Evidence | Dated privacy policy and relevant clauses, contract, processing terms, assessment findings and unresolved questions. Distinguish supplier claims from verified evidence. |
| Safeguards | Access controls, incident reporting, retention, export and deletion; a link to restricted student consent records where required. |
| Decision | Likelihood and impact of harm, remaining risk, reasons, approved use, conditions, approving person and date. |
| Review | Next review date and triggers such as changed terms, new features, ownership changes or an incident. |
Rate the specific use and configuration. For example, a fictional reading app receiving identified student audio could be deferred until its AI-training terms and deletion arrangements are resolved. A subsequent approval should record the remaining risk and the conditions under which students may use it.
IT can coordinate the evidence with educational and privacy leads. The principal or delegated executive should approve use within the school’s risk appetite, escalating significant exceptions under board arrangements. Approval cannot authorise unlawful handling.
Hosting location is one input to that decision. Australian hosting alone cannot establish trustworthiness, and overseas processing requires assessment of applicable obligations and safeguards. The OAIC’s APP 8 guidance explains overseas disclosure, contractual protections and exceptions.
Future tools could make policy comparisons and draft assessments easier. I would want any generated rating to show its evidence, reasoning and unknowns, with a named person responsible for reviewing it.
Quick sheet: priorities for school leadership
These are suggested preparation steps, with owners to adapt to the school’s structure.
| Priority | Practical next step | Suggested owner |
|---|---|---|
| Establish accountability | Confirm coverage, appoint an operational privacy lead and agree approval delegations. | Principal and governance lead |
| Find the services | Reconcile purchasing, device-management and sign-in records with staff declarations of free apps and trials. | IT and business manager |
| Triage the risk | Review services handling health, wellbeing, safeguarding, biometric or location information first. | Privacy lead and student-services leaders |
| Review suppliers | Gather terms, assessment evidence and answers on processing, incident reporting and exit. | IT, procurement and privacy lead |
| Manage consent | Where required, connect approved uses with current student consent and make changes or withdrawals actionable for staff. | Privacy lead and school administration |
| Prepare for December | Assess relevant automated decisions and required privacy-policy changes; track the final Children’s Code. | Governance lead and system owners |
| Practise a breach | Exercise a supplier incident with executive deputies and communications responsibilities. | Executive and IT |
| Control retention | Agree retention requirements, remove unnecessary duplicates and test vendor deletion arrangements. | Records owner and IT |
| Keep oversight active | Report unresolved risks, overdue reviews and approvals with conditions to leadership. | Privacy lead and executive |
This connects with the governance, risk and compliance work at Suburban Secure, the technology advisory business I founded: documented risks, clear ownership and technical controls that support the decisions leadership makes. School-specific legal interpretation belongs with the school’s legal advisers, informed by an accurate account of how its systems operate.
Put privacy reform on the next leadership agenda with three deliverables: an account of the school’s most significant data-handling risks, a plan for the December requirements and a list of proposals to track as the legislation develops. Assign owners and resources so that preparation continues beyond the next policy review.
References
Government reform documents
Attorney-General’s Department. (2026, August 31). Privacy reform: Consultation on exposure draft legislation [Consultation portal; closes 18 September 2026].
Attorney-General’s Department. (2026). Exposure draft: Privacy Amendment (Personal Data Protection) Bill 2026 [Draft legislation]. See clause 2 and Schedules 1–4 and 6. Accessible Word version.
Attorney-General’s Department. (2026). Privacy reform: Consultation paper [Consultation paper]. See pp. 9–18, 23–30 and 37–40.
Attorney-General’s Department. (n.d.). Privacy [Overview of the reform process]. Accessed 12 September 2026.
Regulator guidance
Office of the Australian Information Commissioner. (2025, June 19). Statutory tort for serious invasions of privacy.
Office of the Australian Information Commissioner. (2026, May). Automated decision-making transparency obligation (APP 1): Issues paper.
Office of the Australian Information Commissioner. (2026). Draft Children’s Online Privacy Code: Consultation for industry, civil society, academia.
Office of the Australian Information Commissioner. (2026). OAIC releases exposure draft of the Children’s Online Privacy Code [Media release].
Office of the Australian Information Commissioner. (n.d.). Children and young people; Guide to securing personal information; and Chapter 8: APP 8, Cross-border disclosure of personal information. Accessed 12 September 2026.
Education and governance resources
Queensland Department of Education. (n.d.). Guideline for obtaining and managing online services consent, pp. 5–8. Accessed 12 September 2026.
Queensland Department of Education. (2025, November 28). Obtaining and managing student and individual consent procedure [Version 6.15; effective date].
Queensland Audit Office. (2026, March). Checklist for managing third-party cyber security risks [Better practice resource].
Education Services Australia. (n.d.). Safer Technologies 4 Schools: General information [Assessment scope and process]. Accessed 12 September 2026.
Legal analysis
Boyle, N., Kermond, C., & Moore, A. (2026, September 8). Australia privacy update: Proposed privacy law reform. White & Case LLP.
