As AI-powered tools and workplace monitoring become more common, organisations must navigate complex privacy, employment and governance risks.
A practical overview of the key legal considerations and emerging compliance challenges. Most importantly, we answer your burning questions including: What types of surveillance is lawful? and, Even if we can implement surveillance, should we?
Our presenters cover:
This session is presented by Cecelia Irvine-So, Practice Leader of our Privacy & Education teams. Cecelia is joined by Alexandra Gronow, Special Counsel in our Workplace Relations team, and Cassandra Minett, Lawyer in our Privacy and Education team.
This webinar is essential for anyone looking to stay ahead of the legal risks posed by rapidly evolving workplace technology.
On Wednesday 14 January 2026, the Department of Education (DOE) announced that a major cyberattack has compromised the personal information of students from all Victorian government schools.
This news is a timely reminder that all schools are required by law to keep personal information secure. Schools are required to report eligible data breaches to the Office of the Australian Information Commissioner, whether or not these are caused by the school or by a malicious actor.
According to the DOE, an unauthorised external third-party accessed a database containing information about current and past school student accounts, including:
Whilst there is no evidence that any non-government schools were impacted, privacy breaches (including from cyberattacks) do occur at non-government schools – both Catholic and independent. We often support schools in these matters.
In our experience, certain factors tend to correlate with breaches. These include:
Moores supports non-government schools with privacy compliance, data breach response and cyber incident management. In late January 2026, Moores will release its 2026 Privacy Toolkit, designed to assist organisations of all types to meet their obligations under Australian privacy laws.
Our team regularly advises not-for-profits, schools and education providers on privacy compliance, data breach response plans and proactive redesign of processes to implement privacy-by-design.
Please contact us for more detailed and tailored help.
Subscribe to our email updates and receive our articles directly in your inbox.
Disclaimer: This article provides general information only and is not intended to constitute legal advice. You should seek legal advice regarding the application of the law to you or your organisation.
We’ve heard a lot about consent in the news lately, especially in the context of bodily autonomy, and safe and respectful relationships. There is however, another type of consent that is arguably just as important; and which has historically, often been overlooked by school authorities. We speak of course about consent to collect and use personal information.
In the current digital landscape, where AI bots are running wild with our information and intellectual property, Australians are growing increasingly concerned about the control of their personal information, and that of their children. It can be disconcerting at best, to see a photograph of yourself (or worse, your child), published without your express knowledge and/or consent. Under the Privacy Act 1988 (Privacy Act) photographic images and videos (from which you can be reasonably identified) are considered your personal information.
Photos and videos of individuals are therefore subject to protection under Australian privacy laws. Independent schools in Australia are required to manage personal information (including photographs) in accordance with the Australian Privacy Principles (APPs). For government schools, state and territory-based privacy schemes, such as the Victorian Information Privacy Principles (IPPs) set out ostensibly the same requirements.
The APPs (and corresponding state/territory-based schemes) set out numerous requirements regarding how personal information may be collected, stored, used and disclosed. This article is focussed on one aspect of these requirements, being consent. Specifically, we discuss the consent that schools must obtain from individuals in order to lawfully publish (i.e. disclose) their image.
Traditionally, school enrolment agreements have taken the form of ‘take it or leave it’ standard-form contracts. There are of course, good reasons for this (consistency between contracts, fairness, reducing administrative burden etc.). However, the inherent power-dynamics of these kinds of agreements can tend to disempower the consumer (in our case, the parent) from asserting their rights or interests in a transaction. This can, in turn, affect schools’ compliance with the APPs. We discuss how below.
There are a couple of key features of standard-form contracts that can cause problems when it comes to privacy protection and compliance:
In the ‘old-world’ organisations could more or less get away with a kind of set and forget approach to privacy. In relation to student photos, that might look like (1) the school’s enrolment agreement contains a photographic consent pre-condition (2) the parents agree to this at the point of enrolment – and (3) the school proceeds on the basis of rolling consent for the use of the student’s photographs for the duration of enrolment.
The uncomfortable truth about this approach is that reliance on this alone may not be lawful. As a school, if you do not have valid consent for disclosure, and you publish an individual’s image – you will very likely find yourself in breach of APP 6. In summary, APP 6 sets out that an APP entity (i.e. a school in this case) may only use or disclose personal information for the primary purpose for which it was collected, or if the individual has consented to that use or disclosure. Schools operate to provide education and care, and necessarily collect student information to provide that education and care. It would be a long bow for a school to argue that publishing student photographs on the school’s social media is a primary purpose for the use of student information. Therefore, valid consent it required for that publication to be lawful.
Schools should also consider their duty of care to students when dealing with their personal information. In short, the duty requires schools and teachers to take reasonable steps to reduce the risk of reasonably foreseeable harm occurring. There may be occasions where sharing a student’s image online or in a newsletter could present a risk to their safety – for instance in scenarios where there may be family violence or other complex family dynamics. This is one reason why currency of consent (which we discuss below) is so important. Not only may a school find itself in breach of the APPs due to a social media post – it may be held liable in negligence for failing to protect its students from harm.
This doesn’t mean schools can’t share photos of their students. It is wonderful to share student success and give communities the chance to congratulate and rejoice in our young people’s success; you just need valid consent.
Consent requires more than saying ‘yes’ (or not saying ‘no’). The Privacy Act sets out the four elements of consent, without which – consent is not considered valid:
There are a couple of key reasons why, in consideration of these elements of consent, the traditional approach of consent as a pre-condition may no longer be appropriate, or lawful:
First of all, don’t panic. Many organisations are still catching up to the ‘new world’ of privacy requirements. Taking pro-active steps now can still put you ahead of the curve! Many schools are soon due to update student and parent consents on parent portals. This is a great opportunity to check if your school’s portal consent functions stack up against the requirements of the APPs.
Now is also a great time to review your School’s overall privacy compliance. When was your privacy policy last updated? Do you have in place tailored, compliant collection notices with appropriate consent mechanisms? There are 13 APPs that must be complied with; and we have only discussed one in this article.
If you haven’t already, now is a fantastic time to review your enrolment documentation and privacy practices. Given the recent decision of Brindabella, and changes to the Consumer law, many schools have sought our advice to ensure their enrolment contracts are enforceable, and free from unfair terms that could attract the ire of consumer regulators.
We can review, amend, and re-draft your enrolment policies, terms and conditions, and privacy documents to ensure they are not only compliant, but represent best industry-practice and protect your commercial interests. Contact one of our education and privacy specialists today to discuss how we can optimise and future-proof your school’s enrolment practices.
On 22 October 2024, the Office of the Australian Information Commissioner (OAIC) published updated guidance for charities and not-for-profit (NFP) organisations relating to compliance with the Australian Privacy Principles (APPs).
While the APPs themselves have not changed, updates to official guidance offer a fantastic opportunity for organisations to review their privacy policies and practices. We know that official guidance offers a valuable insight into the mind of the regulator – it tells us how the regulator interprets regulatory obligations, and what they expect from regulated entities. When you implement recommendations contained in official guidance, you are putting yourself on the same page as the OAIC – which can only be a good thing!
This recent guidance update deals predominantly with considerations for engaging third-party providers, such as for fundraising, or software vendors.
When you engage a third party to fundraise for you, or you install new software, you need to take steps to be satisfied that the third party, or third party software system is protecting personal information in line with all relevant privacy obligations. It can be dangerous to assume that other parties will be as privacy-minded as you are – such assumptions could result in data breaches and bad publicity for your organisation (even if it wasn’t technically your organisation that had the data breach).
In releasing the updated guidance, the OAIC noted the issue is “topical in the wake of high-profile data-breaches affecting charities and NFPs”. You may have seen recent news reports about a cybersecurity breach involving Pareto Phone and a number of Australian charities. According to reports, Pareto Phone was contracted by numerous Australian charities to conduct fundraising on their behalf and as such, was provided with personal information of thousands of donors. When Pareto Phone subsequently had a data breach, it was the donors whose personal information was subsequently published on the dark web. This kind of event can be devastating: not just to the individuals whose data has been compromised, but also to the charities, and the very deserving beneficiaries of charity efforts.
Charities and NFPs are right to be concerned about these privacy risks; and we are here to tell you that there are things you can do right now to help safeguard personal information held by your organisation. A great place to start is to familiarise yourself with the APPs, and the OAIC’s guidance on how to implement good privacy practices.
There’s a wealth of NFP-specific and general privacy guidance at the OAIC’s website. The APP guidance is a great place to start if you’re unsure about what the APPs are, and what they require.
If you are a charity of NFP, the APPs may or may not apply to your organisation – there are a number of threshold requirements to determine who is (or is not) an ‘APP entity’ (i.e. an entity that must comply with the APPs). If you’re not sure whether the APPs apply to you, you can reach out to one of our privacy experts, who can provide you with tailored advice on this issue.
Regardless of whether or not you meet that threshold, it is just good practice to develop sound privacy practices, supported by thorough policies and staff training. It will also help you to build upon your relationship of trust with your members and donors, who will appreciate knowing you take their privacy seriously.
If you are a charity or NFP looking to review, improve or develop your privacy compliance, we can help. We have dedicated privacy specialists who can work with you to design tailored policies, plans and procedures; train your staff; and help set you apart as a best-practice organisation, committed to the privacy of its valued community.
We can also draft tailored contracts for you to engage third parties in a way that aligns with and protects your commercial interests, while also prioritising the privacy of your members and donors.
AI is already a central part of everyday life. When your call is answered by a chat-bot (“press ONE for reception”), that’s AI. When your streaming service recommends a new TV series for you, that’s AI. When your car suggests you avoid the freeway to shave ten minutes off your travel time? Yes, this is AI too. These kinds of AI operate largely in the background – and most of the time we probably don’t even notice that the AI is there, helping us. With the arrival of generative AI, the use of AI more generally has come rightly under scrutiny and required schools and other organisations to balance risk and opportunities inherent in the emerging technology and its ever-changing capabilities.
There is no doubt that AI has arrived, and it’s not going anywhere. Your staff and students are already using AI in every day school life, sometimes without knowing, and at other times knowingly but without adequate safeguards and guidelines.
As with any tool, AI can be used for good, or as a weapon to cause harm. Just last week, a Victorian school student was reportedly expelled for using AI to generate ‘deepfake’ nude images of female students in grades 9-12. A deepfake is a kind of image that takes a persons’ face (for example) and places it on a completely unrelated body. The result is an extremely convincing fake image a person in a situation that never occurred; often engaging in explicit or otherwise harmful activities. The technology can also create very convincing fake videos – recent news reports suggest that AI was used in the United States by an aggrieved school employee to frame a school principal with making racist remarks. The kind of AI that ‘creates’ content like this is called Generative AI. Generative AI can create images, write recipes, poetry, and even compose music. One of the scary things about generative AI is that practically anyone can use it: it is readily available and requires no special skills or training. Young people are increasingly accessing and being harmed by others using generative AI in the school environment.
AI can, on the other hand be used to help you streamline your school’s business operations, support student learning and help you draft documents by giving useful feedback on documents and suggest improvements. However, even when used with good intentions, AI can pose risks to you and your organisation. Schools have a duty of care to protect students from reasonably foreseeable harm. If the proper safeguards are not in place, the use of AI in your school could place your staff and students’ personal information and safety at risk, as well as expose your school to regulatory sanctions, or even legal action.
AI needs to be fed information in order to generate output. For example, AI can’t make a deepfake image without being given somebody’s photos to use and manipulate. It can’t write an article without being told what it is about and the kind of language to use (we assure you this article however is 100% human-authored!) This information in, information out process is where a lot (but not all) of the risk arises. AI is hungry for information, and you can never be sure what will happen to information once you feed it into the system. Some of the key risks that can arise from AI-use are outlined below.
Let’s say you want AI to help you generate a new and more efficient way to prioritise student enrolment offers. To do this, you feed the AI existing student applications and the current rules your school uses to prioritise offers. The AI might then sort through the information you fed it and suggest a new way to organise or use that information to your benefit – wonderful! However, unbeknownst to you, you have just ‘disclosed’ (per APP6) students’ personal information to the internet at large. AI systems could potentially be used to track students’ online activities, infer sensitive information, or make predictions about their future behaviours or outcomes. These scenarios could infringe on students’ privacy rights and autonomy. The second you enter information into AI, you lose control of that information. It is now ‘on the internet’ forever.
This inadvertent disclosure of information could constitute a Notifiable Data Breach and attract regulatory sanctions from the Office of the Australian Information Commissioner (OAIC); particularly as enrolment applications generally include information about the health, and religious, cultural or racial identities of prospective students. It could also lead to serious harm to the people whose information has been disclosed – not to mention the reputational damage to your school.
Imagine that you would like to use AI to improve your school’s suite of policies and procedures. AI could potentially give useful feedback on how to streamline and otherwise improve your operational documents. However, as with the above example, you can only get out of AI what you put into it. In order to have AI assess and critique your policies, it needs to read them. Once you have given that commercial information to the AI, it will use it again to help it ‘learn’ and respond to other users’ questions. Perhaps your school’s valuable intellectual property will be used by the AI the next time anyone asks it to write a policy. If you don’t want to share your commercial-in-confidence material or intellectual property with the entire internet, beware of feeding it into the AI.
The risk also presents in the other direction. Imagine the AI suggests you re-write your procedures a certain way and you implement that suggestion. Then, to your horror, your school is sued for using another organisation’s intellectual property without their consent. It turns out the AI had given you a copy of someone else’s documents to use, and you had no idea. Without knowing it, your school has now infringed on somebody else’s copyright.
AI can be used in schools to personalise learning, provide real-time feedback and create immersive educational experiences. It can be used to develop teaching and assessment tasks and streamline assessment and grading. Be wary, however, of relying too much on AI to help you grade and assess student work (or to perform any other tasks involving students). Although AI could help you to save time and create engaging materials, keep in mind:
There are countless benefits and risks associated with using AI. Below are some tips to help you prepare for, respond to and use AI, while minimising the risk to your school and community:
Our Education team is in demand for up-to-date, informative and entertaining staff PD on privacy matters including AI. We can prepare all policies and procedures and assist organisations to maintain best practice in privacy and data protection. If you have existing policies, our team can assist with reviewing and updating these policies to ensure your organisation continues to mitigate risks posed by new technologies – you might be surprised by the gaps which exist! We can also provide tailored, interactive training to your organisation on your obligations under the Australian Privacy Principles, and other regulatory schemes in your jurisdiction.
Suppose a parent calls your office and requests their child’s counselling records? Or a court order lands on your desk seeking access to counselling notes? Or perhaps, your school counsellor raises concerns about a student’s wellbeing and wants to discuss information shared in a counselling session? When can you disclose a student’s counselling records and when should you not? This is a question that is becoming increasingly problematic for schools. The answer lies in balancing the duty of care with confidentiality and privacy requirements. This article will set out your legal obligations and answer some common questions in this space.
Schools owe a duty of care to their students and all children under common law and state-based legislation. The duty is generally to take reasonable care to protect students from harm which is reasonably foreseeable. Several states including New South Wales, Victoria, South Australia and Queensland have reversed this onus in relation to child abuse caused by an individual associated with the organisation.
To help facilitate student wellbeing, most schools have a counsellor, psychologist or pastoral care available to students. In these sessions, personal information will be collected by the school including medical information, relationship status, familial issues, disclosure of bullying or mental health concerns and other sensitive information.
Schools are required to handle this information in accordance Privacy Act 1988 (Cth) (Privacy Act), the Australian Privacy Principles (APPs) and state-based legislation. For example, the information collected can only be used for the primary purpose (in this case being the provision of counselling services) unless a permissible secondary purpose exists. Permissible secondary purposes include those related to the primary purpose, where consent is provided, the disclosure is authorised under Australian law or a court order or a permitted health situation exists. The Australian Psychological Society takes the position that a psychologist is obliged to release information when “required by law”, which includes the law which imposes a duty of care on schools.
Do I need the student’s consent to disclose their counselling records to their parents?
It will depend on the age of the student. The Office of the Australian Information Commissioner (OAIC) recognises that a child’s capacity to consent to the handling of personal information needs to be determined on a case by case basis depending on the maturity and ability to sufficiently understand what is being proposed. As a general rule, schools can presume that students aged 15 and over have capacity to consent. While the Privacy Act doesn’t currently specify a specific age, predicted amendments may define a child as 15 or 18. For Victorian schools, the Victorian Privacy and Data Protection Act 2014 (Vic) defines a child as someone under 18 years of age, but does not specify the age when individuals can make their own privacy decisions.
Many secondary schools state in their policies or counselling intake or permission forms that all students from year 7 will be required to give consent for the release of their counselling records (unless an exception applies). We recommend that schools decide what their policy will be and embed this into their documents to ensure there is clarity amongst students and parents.
What if one parent is requesting the information but the other parent or student does not agree?
Schools can be caught in a tricky situation where parents disagree on the disclosure of counselling records, especially if the parents are separated or in the process of separating. First and foremost, if the student is able to consent, the school should seek the student’s consent. This rings true with other child safety obligations for the empowerment of children. If the student does not, or is unable to, consent, schools should seek consent from both parents before disclosing any records. This is particularly where the records contain sensitive information. If the parents cannot agree on the disclosure, the school should request a court order before disclosing any records.
What about requests from third parties?
Schools should be careful about releasing counselling records or information to third parties without the proper consent from the student or their parents. Schools should always require any such request to be in writing. If the student or their parents do not consent, it may be that the school requires further advice on whether or not they are required to provide the records. Most states (Victoria, NSW, Queensland, South Australia) have introduced information sharing schemes, as recommended by the Royal Commission into Institutional Responses to Child Sexual Abuse, which permit the sharing of confidential information to organisations in limited circumstances for the purpose of safeguarding children. We explain the Victorian Child Information Sharing Scheme here. In the absence of an applicable information sharing scheme or court order permitting a disclosure to a third party, refer to APP 6.
What about requests from former students about their own records?
We have received queries from schools concerned about providing former students with their own counselling records, especially where the former student may be considering a historical child abuse claim or other claim against the school. APP 12 requires organisations give individuals access to their own information on request. While there are some exceptions to this, they are limited. One such exception is if the record includes personal information belonging to other individuals and the sharing of that information would have an unreasonable impact of those other individuals. If an exception applies, the school may have grounds to refuse or redact information. More information about handling information access requests is here.
The counsellor, psychologist, wellbeing officer or chaplain is concerned about a student – what should we do with this information?
Where a staff member is concerned about a student’s wellbeing, that staff member can share that information within the school with other limited and appropriate staff for the purpose of the student’s safety or the discharge of the duty of care. Always share information in accordance with your policies and procedures. While the privacy obligations under the Privacy Act apply to the school not the individual, internal sharing of the information should be on a need to know basis. At the same time, the school needs to ensure that it is fulfilling its duty of care. Where concern for a student’s wellbeing rises to the level of needing to make a report to an external organisation such as Child Protection, this should be done and is an exception to obligations under the Privacy Act (see below).
When do I have to provide counselling records?
There will be situations when the school is required to disclose the information held in counselling records. This includes:
The above situations (amongst others) are exceptions under the Privacy Act and the disclosure of information without consent is permitted.
Managing requests and disclosures of counselling records is a difficult topic and often requires decisions to be made in short timeframes. Where records are incorrectly disclosed, schools could find themselves at risk of various claims including breach of privacy (with increased significant maximum penalties) or negligence. To mitigate these risks, we recommend that schools:
At Moores we have a specialised team that supports the education sector on a variety of areas including privacy and data security. This makes us well placed to assist schools in the careful balance of duty of care with confidentiality and privacy requirements.
We are more than happy to guide you through the process of determining your obligations in disclosing a student’s counselling or pastoral care records.
This article was originally published November 2019. Updated June 2024.
Are you a not-for-profit organisation entrusted with sensitive client data? Are you concerned about the potential fallout from a data breach and its impact on your organisation’s reputation?
Tune into an empowering webinar on data security, where we provide you with practical tips to enhance your confidence in protecting your valuable data. In this webinar, Moores Practice Leader, Cecelia Irvine-So and Senior Lawyer, Penny Liberogiannis, will equip you with practical strategies and actionable steps to secure your client data.
Discover how to:
Watch our recording to take the first step towards peace of mind in protecting your community.
As part of the stronger regulatory approach of the Office of the Australian Information Commissioner (OAIC), there is a renewed focus by the national privacy regulator on organisations reporting more than 30 days after a data breach. This comes with a clarification that the clock starts ticking (the 30-day reporting obligation) from the moment “a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates”, and not when an investigation is completed. This means, if, at any time during a cyber incident investigation, the organisation has enough information to reasonably conclude that the data breach would be likely to result in serious harm to any of the individuals to whom the information relates – the clock has started.
The OAIC demonstrated its stronger regulatory approach to the Notifiable Data Breach (NDB) Scheme in 2023 by making two determinations against organisations who reported under the NDB Scheme but did not meet the 30 day reporting requirement:
Specifically, the OAIC determined that both Pacific Lutheran and Datateks failed to:
In both Pacific Lutheran and Datateks, the data breach was caused by an email address of a staff member of the organisations being subject to unauthorised access by a third party who then used that email account to send phishing emails to other staff in the organisation and external contacts. More information about cybercrime statistics is here. The unauthorised access to the email accounts was identified within one day and both organisations swiftly commenced investigations.
This swift identification of the data breach and commencement of an investigation was not sufficient to demonstrate all reasonable steps had been taken to complete the assessment of the data breach within 30 days.
The Privacy and Data Security Team at Moores also publish summaries of the NDB statistics reported by the OAIC each year: 2022 NDB statistics and 2023 NDB statistics.
The OAIC clarified that the reporting obligation arises when an eligible data breach is identified and not:
Critically, the OAIC determined that organisations cannot wait for the investigation to be concluded to make the determination as to the requirement to report and cannot “pause” the 30 day period by appointing an IT company to conduct an investigation into the breach.
An eligible data breach includes unauthorised access to information that a reasonable person would conclude would be likely to result in serious harm to any of the individuals to whom the information relates. This means if, any at point during a data breach investigation, the organisation receives information that means there is a reasonable belief the unauthorised access is likely to result in serious harm to an individual to which the affected information relates – the 30 days starts.
A key factor is that the organisation does not need to know that serious harm has or will result from the unauthorised access – it is enough that serious harm is likely.
We can help you through the process of managing data breaches: from preventative security audits and training, to implementing a data breach response plan, to making the assessment as to your reporting obligations and implementing learnings from the breach and privacy-by-design. Get in touch with our Privacy and Data Security Team to arrange a time to meet.
Organisations, including not-for-profit organisations and schools, are on notice that the Office of the Australian Information Commissioner (OAIC) is going to take a “stronger regulatory approach” to enforcement of the Notifiable Data Breach (NDB) Scheme from 2024. The national privacy regulator announced the stronger regulatory approach is due to information security being a regulatory priority in its bi-annual report publishing statistics of reporting trends under the Scheme.
We recommend organisations prepare for this new, stronger regulatory approach from the OAIC by:
In 2023, 892 notifications were made to the OAIC under the NDB Scheme.
Health service providers made the most notifications under the NDB Scheme, making 18% of all notifications. In addition, 37% of notification involved health information being subject to the breach. This is significant, because the regulatory response and imposition of civil penalties against organisations takes into account the emotional harm caused by privacy breaches, and the breach of health data can generally have a heightened negative impact on individuals; not to mention the possibly discriminatory consequences.
Cyber security incidents represented 42% of notifications:
Human error represented 28% of notifications:
In July to December 2023, compromised or stolen credentials were a leading cause of all data breaches. The OAIC identifies that the large-scale data breaches in recent years have put organisations at heightened risk of cyber incidents from compromised passwords because those passwords have previously been compromised. In addition to implementing multi-factor authentication and strong password requirements (including regular changing of passwords), organisations can:
The privacy and data security team at Moores can help you prepare for data breaches through privacy training, privacy audits and designing custom privacy and data protection procedures and internal tools for staff. We can help you respond to a data breach by assessing the breach under the Notifiable Data Breach Scheme, and helping you implement a Data Breach Response Plan.
This webinar focuses on lessons from Safer Internet Day 2024 and learnings from high profile matters related to online harm and safeguarding in the education and not-for-profit sectors.
In this webinar Moores Practice Leaders, Skye Rose and Cecelia Irvine-So, explore developments and emerging issues in relation to:
The webinar is relevant for anyone working in the education or not-for-profit sectors who want to better understand the current online safety risks.
Trigger warning: This webinar will address abuse, harassment, and online harm. Viewer discretion is advised.