Victorian schools and education providers are now captured by the Child Information Sharing Scheme (CISS). This changes privacy, child safety and regulatory implications and risks. Schools should be aware of how CISS operates and its impact on other parts of school governance and compliance.

What is the CISS?

CISS facilitates the sharing of confidential information between organisations that work with children to promote the wellbeing and safety of those children. CISS aims to remove barriers to information sharing to best facilitate early identification and remediation of child abuse, neglect or other risks to child wellbeing and safety.

The CISS commenced on 3 September 2019. Schools and education providers are captured in phase 2 which commenced on 19 April 2021. (Phase 2 was delayed in 2020 due to COVID-19.)

Which organisations are captured?

With phase 2 now in force, the CISS has expanded to capture:

  • Registered schools: independent, catholic and government
  • Doctors in Schools program
  • Enhancing Mental Health in Schools program
  • Kindergartens
  • Public health services and denominational hospitals
  • Regulators including the Victorian Registration and Qualifications Authority (VRQA), Victorian Curriculum and Assessment Authority and Victorian Institute of Teaching
  • Registered medical practitioners who practises in the medical profession as a general practitioner in Victoria
  • Registered community health centres

Information sharing can occur between any of these organisations. Organisations that are captured are referred to in the CISS as Information Sharing Entities (ISEs).

Key obligations under the CISS

Under the CISS, an ISE can:

  • Share information proactively to other ISEs
  • Make a request for information; and
  • Share information in response to a request from another ISE.

When an ISE receives an information request, it must assess the request against a three step test. 

  1. Would sharing the information promote the wellbeing and safety of the child or children concerned?
  2. Would sharing the information help the receiving ISE either:
    • make a decision, assessment or plan,
    • start or conduct an investigation,
    • provide a service, and/or
    • manage any risk?
  3. Is the information excluded information that cannot be shared under the CISS?

Schools – as ISEs – must respond to requests from other ISEs in a timely manner. If the sharing meets the three step threshold test, you must share the information. If the test is not met, you cannot share the information but you must respond to the request with an explanation in writing.

CISS and Privacy

The CISS regime includes legislative principles to guide the collection, use or disclosure of confidential information. It is a principle of the CISS regime that ISEs give precedence to the wellbeing and safety of a child over the right to privacy.

The use or disclosure of confidential information under the CISS regime in good faith and with reasonable care does not constitute a contravention of any other Act.

For independent and catholic schools that also must comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth), disclosure under the CISS is permitted by APP 6.2(b) where it is authorised by law.

This means that where a disclosure is made in compliance with the CISS, it is not a privacy breach. However, if schools do not meet the regulatory requirements of the CISS, the disclosure may also be a privacy breach.

You may need to review your privacy policy, privacy procedures, and data security protocols, confidentiality policies, and consent and release of information forms.

We recommend that organisations:

  • Train your staff – The CISS needs to be administered by staff members who will need training to understand when to make a request for information and how to respond to requests. For organisations also caught by FVISS, training will be needed for employees on the interaction between the two schemes.
  • Review your policies and procedures – The CISS has significant implications for organisations, particularly in terms of privacy and child safety. These policies and procedures need to be reviewed and amended to align with the CISS, as well as other documents such as enrolment contracts and collection notices.
  • Communicate to your stakeholders – While the CISS assists organisations to better share information for the wellbeing of children, the increased sharing of information could concern children and their families. It is important organisations mitigate any relationship risks that could arise by clearly communicating when it will share information under the CISS and how this will impact confidentiality and privacy.
  • Seek strategic advice – For the organisations captured in the second phase of the CISS, this type of information sharing will likely be a substantial departure from previous practice. Organisations should carefully consider how they will roll out the CISS, embed it into their operations and comply with the complex legislative framework as well as their other obligations.

How we can help

Moores has extensive experience in privacy, child safety and regulation and is well placed to assist schools and other organisations in preparing for and implementing the CISS. For more information, please do not hesitate to contact us.

Closure of the school gates may have brought relief from some concerns, but moving to online learning and keeping the school afloat bring continuing obligations.

School boards need to continue to meet and govern the school, even when students are not on campus.

These challenging times are also a test of the Board’s effectives. It’s easy to be a leader when everything is going well. But, in the words of a fellow cancer survivor, Mary Tyler Moore, You can’t be brave if you’ve only had wonderful things happen to you.

Here are our top tips for Boards and the leadership team of key considerations to keep in mind as schools move online.

Child Safety

This does not stop. The requirements of Ministerial Order 870 include that the Board (or other governing authority) develop strategies for embedding a culture of child safety at the school. The Board needs to (among other things) develop risk management strategies pertinent to the online environment, and still vet teachers, still have reporting channels for reports of suspected child abuse and deliver education to children about standards of behaviour. 

Some immediate tips to consider:

  • Are teachers allowed to separately tutor students one-on-one?
  • Is there a protocol about students and staff creating chat rooms or study groups (potentially on unsecure platforms) and/or creating separate Zoom groups within a current Zoom virtual classroom?
  • Do your policies, procedures and codes of conduct need to be updated to reflect an online teaching environment?
  • Do your staff need training on how to maintain a child safe environment and their continuing obligations?

Privacy

Zoom-hosted and other virtual classrooms raise issues of privacy. Parents should not participate or conduct conversations in virtual classrooms, even if present to supervise. Similarly, educators should not refer to ill students or family members other than “they are away from school today”.

Risk Management

Groups of children online need to be reminded about cyber-bullying.  The usual rules need to be emphasised, as does parent control over devices.  They should be inaccessible at night, despite the changes. Consider if teachers are able to monitor conversations between students that occur on school sanctioned online platforms, recognising that it is likely that the school’s duty of care will extend to any cyber-bullying or inappropriate messaging that occurs on school platforms.

Cancellation Fees & Refunds

Check all provider contracts and their cancellation clauses. Do not assume a refund is available.  Earlier termination may be considered better, but beware fixed term contracts – you may have to pay them out in full, unless you can point to “frustration” or external factors.

Building Projects

Many contracts will allow the builders to walk offsite and make this the school’s problem. Check the force majeure clause to see whether the school has rights to terminate and/or receive back deposits paid.

Leases

Check lease terms to understand the implications of non-payment of rent. Re-negotiate rent holidays early.

Enrolments, behaviour and payment terms

Consider what you will do if an enrolment agreement allows the school to terminate, particularly around behaviour. Will the duty of care mean you have to find another school for any students that the school terminates? If terminating for non-payment, what is the school’s credit policy? Does this need to be reviewed? Will the school prefer to keep enrolments, and the funding? Note you will need a sufficient number of non-parent board members to vote on any changes to fee or credit policies, because parent board members will need to declare a conflict of interest.

Holding board meetings electronically

Does your constitution actually allow this? Many are too old and were drafted before emails and telemeetings existed. You may need to amend the constitution to ensure your resolutions are valid in online meetings (query if you can hold a members’ meeting). Furthermore, given the need for fast decision making during these critical times, consider if your constitution allows resolutions to be made by circulation and ensure you are complying with the requisite notice requirements before voting on resolutions.

Solvency and Deeds of Indemnity

Directors must ensure the school is solvent – this is a directors’ duty. Even though the law has been temporarily changed to allow insolvent trading in the ordinary course of business for a period of 6 months, the usual rules of good decision making apply. The laws have been relaxed, not repealed, so directors are still required to exercise sound judgment and not breach other directors’ duties. For example, causing school insolvency by entering into a prohibited arrangement would still be an issue. Entering into a modelled temporary insolvency to pay staff who are still working and who will be needed after the crisis, in the context of considered and suitable cost cutting, would be much less problematic.

Workplace Relations

Flexibility and workforce restructuring need to be considered.

What measures do you need to ensure wellbeing and connectedness? Will children be in uniform/complying with dress code? (Some schools say uniform only required on the visible top half). How will distressed students access school counsellors?

How we can help

Moores is still working and available 24/7 to support you. For more information or guidance, please do not hesitate contact us.

The Commission for Children and Young People (CCYP) has announced that the Reportable Conduct Scheme (Scheme) has been extended to include youth organisations that provide overnight camps for children as part of its primary activity. This includes organisations such as the Scouts and Girl Guides and may also include sporting, recreational and summer camp organisations. The changes will take place from 1 May 2020 and youth organisations that may be captured should begin preparations.

What is the Scheme?

The Scheme began on 1 July 2017 and is administered by the CCYP. It aims to ensure allegations of misconduct involving children in relevant organisations that exercise care, supervision and authority over children are properly investigated. The Scheme includes reportable allegation involving an employee, volunteer, minister of religion, contractor or other person associated with the organisation.

A reportable allegation means any information that leads a person to form a reasonable belief that an individual associated with the organisation has committed:

  • reportable conduct; or
  • misconduct that may involve reportable conduct,

whether or not the conduct or misconduct is alleged to have occurred within the course of the person’s employment. This is a wide scope and captures conduct before the individual became an employee (such as historical allegations) and conduct by the employee in their personal lives outside of work.

Reportable conduct means:

  • a sexual offence, sexual misconduct or physical violence committed against, with or in the presence of, a child;
  • any behaviour that causes significant emotional or psychological harm to a child; or
  • significant neglect of a child;

Is my organisation captured?

The Scheme was rolled out in three initial phases. It captures a wide range of organisations including schools, religious bodies, disability service providers, education and care services and children’s services.

The new changes are set out in the Child Wellbeing and Safety Amendment Regulations 2019. It states that “a youth organisation that provides overnight camps for children as part of its primary activity” will be captured by the Scheme from 1 May 2020.

A youth organisation is defined as a youth organisation:

  • in which children participate; and
  • that provides activities in which children participate.

What does it mean if my organisation is captured?

If your organisation is captured by the Scheme, significant amendments need to be made to your policies, procedures and operations.

The Scheme imposes obligations on the head of organisations to:

  • have in place systems to prevent child abuse and, if child abuse is alleged, to ensure allegations can be brought to the attention of appropriate persons for investigation and response;
  • ensure that the Commission is notified and given updates on the organisation’s response to an allegation within strict timeframes including a:
    • 3 day notification;
    • 30 day update report;
    • investigation and outcome report; and
  • investigate the allegation while managing risks to children.

Organisations need to ensure that they have the proper policies and procedures in place to comply with the above requirements. It is important to note that the CCYP has begun to take compliance action against organisations that fail to comply with their obligations under the Scheme.

Next steps

Youth organisations that are now captured by the Scheme need to prioritise preparation to ensure they are compliant by 1 May 2020. We recommend that organisations captured by the Scheme take the following steps.

  1. Assess the application of the Scheme – organisations should assess the application of the Scheme to confirm if it is captured. It is important to note that if one branch of your organisation is captured by the Scheme, your organisation as a whole will need to comply with the requirements of the Scheme.
  2. Amend your policies and procedures – organisations captured by the Scheme will need to amend their documents including their child safety policy, child safety reporting procedure and child safety code of conduct. These documents will need to align with the requirements under the Scheme and capture your investigation obligations.
  3. Train your staff – in particular, organisations will need to train their child safety officers to understand how they assess child safety allegations under the Scheme. Staff will also need to understand when allegations need to be escalated to the head of the entity to allow reports to be made to the CCYP.
  4. Investigation strategy – one of the most significant requirements under the Scheme is the requirement for organisations to investigate reportable allegations. Organisations need to consider how they will manage these investigations, whether they will be done internally or externally and how they can best manage any child safety risks. We recommend organisations review our tips on running a child safety investigation.

For more information or guidance regarding the Reportable Conduct Scheme, please do not hesitate to contact us.