Report snapshot
Objective
This audit assessed how effectively the NSW Department of Education (the department) and NSW public schools (schools) protect the security and privacy of student information.
Key findings
The department has established a range of controls to manage the security and privacy of student information
Over the last 3 years, the department has strengthened its controls by uplifting cyber security capability, centrally contracting key third-party IT vendors, developing specific policy frameworks, and providing professional learning and centralised supports for schools.
Technical responsibilities have been allocated to school principals without sufficient departmental oversight
The department does not clearly define the specific risks to student information that schools must manage, nor provide clear operational guidance or proactive support to monitor how legislative and policy requirements are met in practice at the school level. With principals relying on their own judgement and capacity, practices are inconsistent and in some cases non-compliant.
There are gaps in how schools apply the department’s staff access controls to systems
The department’s controls do not ensure that access to student information is limited to staff who need it for their role. Schools apply access controls inconsistently, and some staff access more information than they need or retain access after they leave a school. The department does not oversee or control staff access to third‑party school administration systems, which hold large amounts of student information.
Some schools use third-party digital products without departmental oversight
The department’s marketplaces give schools a range of approved third-party digital products for school administration and online learning. It centrally manages contracts with third-party vendors, including terms to protect the security and privacy of student information. However, some schools use third-party products outside of these marketplaces and without departmental oversight or controls to protect student information.
The department does not independently assure third-party digital products in its marketplaces
While third-party vendors of digital products in department’s marketplaces are subject to contractual security and privacy controls, the department does not routinely verify vendor compliance.
The department only recently identified key third-party systems as ‘crown jewels’
The department did not classify Compass, SchoolBytes and Sentral – the third-party systems used by more than 98% of schools to manage student information – as ‘crown jewels’ until early 2026. The department is now implementing the higher levels of oversight, assurance and protective controls that apply to crown jewels.
Recommendations
The audit made recommendations for the department to review the allocation of responsibilities to principals, improve the guidance and supports for schools, and strengthen the controls for managing the access to and use of student information.
Read the PDF report
Parliamentary reference - Report number #430 - released 29 June 2026