1. Report snapshot
Objective
This audit assessed how effectively the NSW Department of Education (the department) and NSW public schools (schools) protect the security and privacy of student information.
Key findings
The department has established a range of controls to manage the security and privacy of student information
Over the last 3 years, the department has strengthened its controls by uplifting cyber security capability, centrally contracting key third-party IT vendors, developing specific policy frameworks, and providing professional learning and centralised supports for schools.
Technical responsibilities have been allocated to school principals without sufficient departmental oversight
The department does not clearly define the specific risks to student information that schools must manage, nor provide clear operational guidance or proactive support to monitor how legislative and policy requirements are met in practice at the school level. With principals relying on their own judgement and capacity, practices are inconsistent and in some cases non-compliant.
There are gaps in how schools apply the department’s staff access controls to systems
The department’s controls do not ensure that access to student information is limited to staff who need it for their role. Schools apply access controls inconsistently, and some staff access more information than they need or retain access after they leave a school. The department does not oversee or control staff access to third‑party school administration systems, which hold large amounts of student information.
Some schools use third-party digital products without departmental oversight
The department’s marketplaces give schools a range of approved third-party digital products for school administration and online learning. It centrally manages contracts with third-party vendors, including terms to protect the security and privacy of student information. However, some schools use third-party products outside of these marketplaces and without departmental oversight or controls to protect student information.
The department does not independently assure third-party digital products in its marketplaces
While third-party vendors of digital products in department’s marketplaces are subject to contractual security and privacy controls, the department does not routinely verify vendor compliance.
The department only recently identified key third-party systems as ‘crown jewels’
The department did not classify Compass, SchoolBytes and Sentral – the third-party systems used by more than 98% of schools to manage student information – as ‘crown jewels’ until early 2026. The department is now implementing the higher levels of oversight, assurance and protective controls that apply to crown jewels.
Recommendations
The audit made recommendations for the department to review the allocation of responsibilities to principals, improve the guidance and supports for schools, and strengthen the controls for managing the access to and use of student information.
2. Executive summary
Context
The NSW Department of Education (the department) is the largest provider of public education in Australia, with around 86,500 teachers and 42,000 educational support staff in more than 2,200 public schools serving approximately 780,900 students in 2024–25. NSW public schools (schools) are part of the department.
The department and schools collect and manage sensitive student information to support education delivery including student wellbeing. This information is stored across paper records, department-managed IT systems and third-party digital products. These third-party products support operations, administration and learning. They can be broadly grouped into 3 categories:
- core enterprise platforms (such as Adobe Creative Cloud, Google Workspace and Microsoft 365)
- school administration systems (such as Compass, SchoolBytes and Sentral)
- online learning apps (such as Reading Eggs and Mathletics).
NSW privacy laws control how student personal and health information is collected, used, stored and secured. The department and schools have a legal responsibility to respect students’ privacy. Information can only be used for legitimate educational purposes, accessed on a need-to-know basis, kept accurate and protected from misuse or overexposure.
Audit objective
The audit assessed how effectively the NSW Department of Education including NSW public schools protect the security and privacy of student information.
There were 2 lines of inquiry:
- Are security and privacy risks to student information effectively identified and managed by the department?
- Is the department ensuring security and privacy of student information at the school level and when shared with third parties?
Conclusion
The NSW Department of Education has established policies, systems and centralised supports to manage risks to the security and privacy of student information. Over the last 3 years, the department has strengthened these controls by uplifting cyber security capability, centrally contracting key third-party IT vendors, developing specific policy frameworks and providing professional learning and other supports for schools.
However, there are critical gaps in the translation of departmental policies, systems and supports into day-to-day practice within schools, which frustrates the effective protection of student information.
The department does not ensure the security and privacy of student information at the school level and when shared with third-party IT vendors; it relies on school principals to identify and address risks to student information. However, these are complex technical risks, and the department has not assessed whether schools have the capacity or capability to manage them; nor does it monitor whether mitigations to address these risks are in place.
The department and schools do not consistently apply access controls to ensure student information is only available to staff whose roles require it. Further, the department’s controls do not apply to unassessed or unapproved third-party digital products and it does not have visibility of their use.
Key findings
The department has established a range of controls to manage the security and privacy of student information
The department has established governance structures, cyber security and other IT controls to safeguard the security and privacy of student information. It has processes to monitor and respond to data breaches that are in line with whole-of-government guidance.
The department provides schools with commonly used third‑party enterprise platforms that it centrally contracts, such as Adobe Creative Cloud, Google Workspace and Microsoft 365. It also gives schools access to marketplaces of centrally contracted third‑party school administration systems and online learning apps that it has approved as meeting security and privacy requirements. These digital products support teaching and learning, as well as schools’ administrative and financial functions.
The department also maintains the ‘Assessed IT’ central catalogue to support schools when selecting third-party digital products outside the marketplaces. The department has not entered contracts with these vendors, but has assessed the products against cyber security, privacy, data handling and deployment requirements.
The department allocates responsibility for managing the security and privacy of student information to school principals, without assessing their capability and capacity to meet these obligations
The department assigns principals responsibility for managing the security and privacy of student information at the school level. This includes:
- selecting and operating systems used to store and process student information
- controlling settings for staff access to student information
- managing records and sensitive information.
Many of these responsibilities require complex technical and legal knowledge and skills. However, the department has not assessed whether principals have the capabilities or capacity to meet these obligations alongside their other educational leadership accountabilities.
The department provides general policies, training and central supports to aid principals in their responsibilities. Its Code of Ethics and Conduct provides that principals must understand and apply the laws, policies, procedures and guidelines that underpin their work. However, it does not have a consolidated resource on the specific student information risks that schools must manage, nor monitor how principals carry out these responsibilities in practice. The department’s assurance activities, to check schools are implementing its policies and procedures, do not include student information management. The department does not know whether all relevant risks to student information are being identified, escalated or addressed in a timely way at the school level.
Consulted schools generally feel supported by the department and know where to seek help when needed. However, the audit observed inconsistent practices across schools. In some cases, schools did not protect student information in line with legislative requirements or the department’s policies and procedures.
The department recognises that the allocation of responsibilities between it and schools needs to be revisited. It has work underway to decide which functions and what authority should be centralised in its business units and which should be with principals. However, this work is not yet settled or implemented.
There are gaps in how the department and schools manage the access of staff to student information
The department has implemented several controls for staff access to student information, including:
- policies for schools on restricting access based on staff roles
- a central tool to support schools to manage access to department systems
- an annual principal attestation on user access introduced in June 2025.
These controls do not consistently ensure that access to student information is only available to staff who need it to perform their role at the school level.
Consulted schools do not always understand the department’s access control requirements and apply them inconsistently in the department’s enrolment system and third-party school administration systems.
Principals differ in their views about how much information staff need to perform their roles and how often they should review and revoke access. Some staff retain access to student information beyond their role requirements, including access to department systems at schools where they no longer work.
Over the past year, the department introduced some automated controls over staff access to its enrolment system, including centrally removing access when staff are no longer located at a school. However, these controls do not apply to all staff roles and do not extend to third-party school administration systems that store large volumes of personal, health and other sensitive student information. For these systems, schools manage access individually without the department’s oversight.
The department advises that it is working with third-party IT vendors to enhance access controls in key systems, including Compass, SchoolBytes and Sentral.
The department has established controls for third-party digital products in its marketplaces, but has limited visibility and controls for other products that schools use
The department manages the contracts with third-party vendors of digital products in its marketplaces. Contract terms require vendors to:
- protect student data
- limit user access
- maintain secure backups
- report and address incidents
- comply with privacy laws and departmental security controls.
However, the department does not contract with third-party vendors of all digital products that schools use and does not have controls or oversight to ensure these products protect student information.
In practice, principals select marketplace school administration systems such as Compass, SchoolBytes and Sentral. However, some schools also use online learning apps and other digital products from outside of the marketplaces. These are not monitored by the department.
More than 60% of online learning apps used by consulted schools are not available through the department’s marketplaces. While the department assesses some non‑marketplace apps through Assessed IT, it does not contract with their vendors. These vendors are not required to comply with the department’s security and privacy requirements. Non-marketplace apps usually collect limited student information such as names, class and department-issued email addresses. In some cases, they can collect more sensitive information including student wellbeing data, demographic information, images and audio recordings.
The department expects schools to only share limited student information with these apps, but it does not have oversight to know whether this occurs. The department introduced a requirement in Term 3 2025 for schools to only use marketplace learning apps once existing subscriptions expire. However, this is not yet consistent practice across schools.
The department does not have comprehensive oversight and assurance of third-party digital products in its marketplaces
The department’s contracts with third‑party vendors in its marketplaces require vendors to meet independently certified security standards and provide self‑assessment reports against the department’s security and privacy requirements. However, the department does not routinely use this information to undertake its own assurance activities. This limits its ability to independently verify that vendors meet expected security and privacy standards.
The 2019 NSW Cyber Security Policy introduced a requirement for NSW Government agencies to identify ‘crown jewels’ (an agency’s most critical, sensitive or operationally vital digital assets) to help prioritise cyber security controls and oversight.
The department identified its enrolment system (ERN) as a crown jewel in 2020–21 and its student counselling records system (OSCR) in 2022–23, as these hold large amounts of sensitive student information. In 2022, the department centrally contracted third‑party school administration systems that hold sensitive student information comparable to ERN, but its process to assess these systems against the same threshold did not occur until late 2025.
In early 2026, the department classified Compass, SchoolBytes and Sentral – used by more than 98% of schools in NSW to manage student information – as crown jewels. The department advised it is now applying the higher levels of oversight, assurance and protective controls required for crown jewels to these third-party systems.
Separately, the department has not conducted privacy impact assessments for these systems or implemented a risk‑based approach to determine which other third‑party digital products require assessment. Although not mandatory under legislation, the NSW Information and Privacy Commission recommends agencies undertake privacy impact assessments to identify and minimise privacy risks relating to changes in services, policies and new projects.
The department responds to data breaches in line with whole-of-government guidance but does not proactively detect data breaches
The department has processes to contain, investigate, address and report data breaches and breaches that involve non-compliance with privacy legislation. These align with whole-of-government guidance, but the audit did not assess their effectiveness.
The department has not implemented proactive detection mechanisms for non-cyber data breaches such as:
- periodic simulations to test its Data Breach Response Plan
- monitoring access to student information shared with third-party digital products
- regular school self-assessments
- compliance spot checks.
While the department takes steps to identify lessons learnt from individual breaches, it does not use these systematically to improve student information handling across schools.
Recommendations
By July 2027, the NSW Department of Education should:
- Ensure it has oversight and control of student information management across departmental, school and third-party environments by:
- clarifying department and school level responsibilities, including centralising the functions that require technical or legal expertise within the department and identifying those best placed with principals
- identifying and addressing risks arising from school level practices and risks associated with third-party digital products that schools use
- establishing assurance mechanisms to support departmental understanding of controls and their implementation at the school level
- strengthening breach detection and using lessons learnt to inform the department’s preventative actions across schools.
- Provide schools with practical guidance on school level responsibilities and deliver proactive specialist support to strengthen the capability of schools to manage the risks to student information for which they are responsible or accountable.
- Improve controls for managing the risks of access to student information by ensuring access in department systems and third-party digital products is restricted, role-based, regularly reviewed and promptly removed when staff leave or change roles.
- Improve assurance and oversight of third-party digital products that manage student information by:
- monitoring schools’ use of third-party products to ensure departmental controls apply to those holding student information
- establishing independent assurance over third-party vendor risk management and compliance for those in the department’s marketplaces
- establishing a risk-based approach to determine which department systems and third-party digital products should be subject to a privacy impact assessment and conducting these assessments accordingly.
3. Introduction
3.1. About this report
The NSW Department of Education (the department) and NSW public schools (schools) collect and manage detailed student data, including sensitive and personal information, to deliver education and support student wellbeing. Schools can also require or encourage students and parents1 to use third-party applications (apps) for learning and other school-related activities.
The Audit Office of NSW examined how effectively the department and schools protect the security and privacy of student information in their own systems and in third-party products (where ‘third-party’ refers to vendors that provide both paid and unpaid digital administrative systems and learning apps).
The audit analysed departmental information and data and consulted with department staff and relevant external stakeholders. The audit engaged with 37 schools across the state, including visits to 3 of these schools (the report does not identify these schools). The audit focused on calendar years 2023 to 2025.
NSW public schools are part of the NSW Department of Education. In this audit the term ‘the department’ refers solely to the department as the agency with strategic, policy, regulatory and administrative functions to support statewide public education services delivered through NSW public schools. The term ‘schools’ refers to NSW public schools.
Further detail on the audit scope, exclusions and methodology is in Appendix 4.
3.2. Context
Legislative and policy framework
The department is the largest provider of public education in Australia, with around 86,500 teachers and 42,000 educational support staff in more than 2,200 public schools serving approximately 780,900 students.2
Student records contain highly sensitive data, and mishandling this information can cause genuine harm to students and families. Children are particularly vulnerable if their personal information is exposed; data breaches or poor security controls can lead to:
- identity theft
- online exploitation or harassment
- targeting of vulnerable students
- exposure of medical conditions, sensitive family or custody arrangements.
Both NSW and Australian privacy frameworks protect students’ rights over their personal information. Schools are responsible for respecting those rights and handling data transparently and responsibly. This includes ensuring student information is:
• only used for legitimate educational purposes
• accessed on a need-to-know basis
• accurate and up to date
• protected from misuse or over-exposure.
Education Act 1990
The NSW Education Act 1990 (the Education Act) provides that the NSW Government should, through providing public education, and as far as practicable, ensure every child3 receives an education of the highest quality. This requires the department and schools to collect, generate and use a range of student information.
The Education Act also empowers the department to obtain information from families and other parties:
- to assist the Education Minister, the Department Secretary or schools to assess whether the enrolment or attendance of a particular student at a school is likely to constitute a risk to the health or safety of any person (including the student), and to develop strategies to manage any such risk
- in relation to children who are not participating in education, training or paid work, for the department to administer the compulsory schooling provisions of the legislation and support their re-engagement in education.
Overall, the department and schools collect, use and store a range of information about students and their families during a student’s initial enrolment and time at school. Exhibit 1 below sets out some of the information that the department and schools may collect.
| Category of student information | Examples of information |
| Family information | Parent occupation and education, address and phone number, languages spoken in the home and emergency contact details, family court orders, apprehended violence orders |
| Student details | Age, gender, residency status, ethnicity, first language, religion, Aboriginality, previous schooling and care arrangements |
| Medical and health information | Details of disability, special needs, health care procedures, medication, mental health status, counsellor records, wellbeing information |
| Support services | Services accessed by students including services from outside agencies |
| Child safety and wellbeing | Information in reports to the Department of Community Services and Justice and the department’s Child Wellbeing Unit, information obtained under Chapter 16A of the Children and Young Persons (Care and Protection) Act 1998 |
| Behaviour | Discipline and behaviour records including records of violent behaviour |
| Incidents | Accident/incident records and student witness statements |
| Academic | Results and achievements including awards and assessments |
| Financial | Centrelink benefits or other financial support provided by the Australian Government, credit card details, tax file numbers of students when required to access vocational education and training fee help or loans |
| Insights | Student insights about experiences at school through the NSW Public Schools survey (previously the Tell Them From Me survey) |
| Recordings | Photographs, images, videos or audio footage of students throughout their enrolment at a NSW public school4 |
Source: Audit Office summary of information provided by the NSW Department of Education.
Privacy legislation
In NSW, the collection and handling of student information is governed by the state Privacy and Personal Information Protection Act 1998 and the Health Records and Information Privacy Act 2002. In addition, the Commonwealth Privacy Act 1988 (Cth) may apply to the department when handling Commonwealth-regulated data (such as tax file or Medicare numbers) and to certain private organisations, such as vendors of third-party digital products used by NSW public schools, in particular circumstances.
The NSW privacy laws apply to:
- personal information, which is information or an opinion about an individual from which their identity is apparent or can reasonably be ascertained, such as a written record with name, address or other details; and photographs, images, video or audio footage, and
- health information, which is personal information that is information or an opinion about the physical or mental health or a disability of an individual, or about the provision of health services to an individual.
Both NSW and Commonwealth privacy legislation establish privacy principles that impose obligations on how personal and health information must be collected, stored, used, disclosed and disposed of, as well as the rights of individuals to access and request amendment to their personal or health information.
These statutes also establish mandatory data breach notification schemes (state and national) which apply where NSW public sector agencies, Australian Government agencies or certain private sector organisations experience unauthorised access, disclosure or loss of personal information that is likely to result in ‘serious harm’ to individuals to whom the information relates.
Under the Privacy and Personal Information Protection Act 1998, NSW public sector agencies may adopt their own code of practice to modify the application of one or more of the information protection principles. The department’s Privacy Code of Practice modifies the legislative privacy principles relating to the collection of personal information in the context of NSW education, and gives the department authority to:
- collect a student’s personal information from a student’s parent
- collect a student’s personal information from other students or staff where it is necessary to promote and maintain a safe and disciplined learning environment
- exempt compliance with legislative privacy principles where compliance would prevent the proper exercise of the department’s complaint handling or investigative functions.
State Records Act 1998
The NSW State Records Act 1998 requires public offices – including the department– to ensure the safe custody and proper preservation of state records they control. It includes the following definitions:
- records are any document or other source of information compiled, recorded or stored in written form or on film, or by electronic process, or in any other manner or by any other means
- State records are those made or received by a person in a public office in the course of exercising their official functions, or for the use of a public office.
State Records NSW provides guidance on the applicable standards, codes of best practice and regulations for records management in NSW public offices under this Act. This includes requirements for capture, storage, retention and disposal of different classes of records generated by an organisation. State Records NSW assesses public offices’ reports on their recordkeeping practices and standards and identifies ways to improve performance.
Student information collected and managed by the department and schools falls within this definition and management framework.
NSW Cyber Security Policy
The whole-of-government NSW Cyber Security Policy outlines mandatory requirements to which all NSW Government agencies, including the department and schools, must adhere to ensure cyber security risks to their information and systems are appropriately managed.
The mandatory requirements are the minimum practices expected of agencies. They focus on:
- governance
- identifying risks (including risks posed by third-party vendors)
- detecting, responding and recovering from incidents
- protecting agency systems.
As for all NSW Government agencies, the department provides an annual attestation to Cyber Security NSW on its management of cyber security risks and compliance with the NSW Cyber Security Policy. This includes whether it has met mandatory requirements and how it is continuously improving its management of cyber security governance and resilience.
Agencies must:
- compile and retain evidence that demonstrates the basis of their assurance assessments
- resolve discrepancies and inaccuracies in reporting
- refer to any departures from the NSW Cyber Security Policy.
Other legislation and policies
The Government Information (Public Access) Act 2009 promotes open, accountable, fair and effective government and ensures members of the public have the right to access government information.
The NSW Government Open Data Policy provides authority for NSW Government agencies to proactively release data, unless there is an overriding public interest against disclosure under the Government Information (Public Access) Act 2009.
The Crimes Act 1900 prohibits interference with, and access to, data in computers or other electronic devices held by the department.
The NSW Artificial Intelligence Ethics Policy sets out requirements for NSW Government agencies to ensure best practice use of artificial intelligence (AI), focusing on trust, transparency, customer benefit, fairness, privacy and accountability.
The department’s role in managing student information
Protecting the security and privacy of student information involves different departmental business units, including:
- cyber security (led by the Chief Information Officer)
- data governance (led by the Chief Data Officer)
- privacy (led by the General Counsel in the Legal Services area)
- records management (in Shared Services)
- enterprise risk (led by the Chief Risk Officer).
Other department areas that may be involved depending on processes or matters include:
- Teaching, Learning and Student Wellbeing, in relation to online learning apps, and targeted student services that involve collecting and using personal information like school counselling and disability supports.
- Professional and Ethical Standards, where an allegation of staff misconduct includes unauthorised access to or mishandling of student information.
No specific budget line items capture the department’s expenditure on managing the security and privacy of student information. The department estimates it spends at least $35 million a year on staffing and relevant activities including IT and cyber security, data governance, records management, privacy protection and breach management. This does not include related items in individual school budgets.
Student information in schools
The management of student information varies among schools across NSW: some only use digital systems, a few maintain exclusively paper-based records, and the majority use a combination of both.
Digital student information is spread across many IT systems and products, including those owned and managed by the department and others supplied by third-party vendors.
For example, the department provides schools with a centralised system for managing student enrolment details, known as the Enrolment and Registration Number (ERN) system. Schools also use approved third-party school administration systems (such as Compass, SchoolBytes and Sentral) that pull relevant information from ERN and allow staff to add and store other student information during a child’s time at the school. This includes health care plans, attendance records, payments for school excursions or behaviour records.
Schools use a range of third-party digital products to assist with school operations. The prevalence of these third-party products increased significantly during COVID-19 when schools needed digital tools for remote teaching, learning, administration and communication with students and families.
The department and schools use 3 functional types of third-party digital products that are most relevant to student information management:
- core enterprise platforms (such as Adobe Creative Cloud, Google Workspace and Microsoft 365) used for online collaboration and file storage
- school administration systems (including Compass, SchoolBytes and Sentral) used for school operational matters like managing student information, communicating with parents, organising calendars, facilitating payments for excursions and so on
- online learning apps (such as Reading Eggs, Mathletics) used by teachers and students in the classroom and at home for educational purposes.
The department holds head contracts with the core enterprise platform vendors. In 2021, it established 2 marketplaces of approved third-party products: one for school administration systems and one for online learning apps. As at April 2026, these marketplaces include 9 school administration systems and 79 online learning apps. The department also holds head contracts with the third-party vendors in these marketplaces. The department’s contract terms set minimum requirements for information security and privacy.
The department expects schools to prioritise using products available through its marketplaces. If schools want to use products that are not available through the marketplaces, it expects them to check ‘Assessed IT’ to determine whether the product has been assessed before deciding whether to use it.
The department established Assessed IT in 2022 as a central catalogue of its assessments of third-party digital products and services against its own cyber security, privacy, data handling and deployment requirements. Products are assigned a rating of ‘allowed’, ‘use with caution’ or ‘do not use’, with conditions to guide their safe use.
The Assessed IT catalogue includes marketplace products, as well as a range of other third-party digital products not on the department’s marketplaces. As at May 2026, the Assessed IT catalogue listed 1,019 digital products, with:
- 461 categorised as ‘allowed’
- 232 categorised as ‘use with caution’
- 326 categorised as ‘do not use’.
The department does not hold contracts with the vendors of products on Assessed IT unless they are in one of its marketplaces. Schools can directly purchase or (where free) obtain subscriptions, or enter into contracts with third-party product vendors outside of the department’s marketplaces.
Most schools also maintain paper-based files, known as student (or pupil) record cards, typically in physical folders for each student. These hold copies of forms printed from digital systems, historical information and documents from other settings (such as disability diagnoses, health care reports from treating specialists and court orders).
Student and family perspectives
Research from Australia in the last 5 years found that students and families value the convenience of digital communication and understand the need for information collection in the context of education, but also have concerns about security and privacy risks.
In 2023, department-commissioned research into communication needs of parents of students in public schools highlighted the need to maintain effective school websites, social media channels and other digital communications.
In 2025, the Office of the Australian Information Commissioner’s national consultations on online privacy with primary and high school students found that students:
- want to be asked more often if their personal information can be collected and used
- want to learn and understand why online companies want their personal information, and think privacy policies should be short and simple to read
- are aware that some online companies can make money from their personal information and find this unfair.
A 2026 NSW Office of Youth poll found that 71% of the approximately 2,300 young people surveyed had used generative AI in the past 12 months and reported positive impacts for education, time management and creativity. However, respondents were also concerned about AI dependence and generative AI’s impacts on critical thinking, jobs and employment, and the environment.
Students who have sufficient understanding and maturity may provide their own consent to the collection and use of their personal information. However, students who are under 16 are generally not considered able to give informed consent; this must be sought from their parents on their behalf.
1 ‘Parent’ is defined in section 3 of the Education Act as including a guardian or other person having the custody or care of a child. This report uses ‘parent(s)’ throughout in accordance with this definition.
2 Figures are drawn from the department’s Annual Report 2024–25. Number of staff and schools is as at 30 June 2025; number of students is as at 2 August 2024.
3 ‘Child’ is not defined in the Education Act, but the Act states that compulsory school age is between the age of 6 and the age at which the child completes Year 10, or the age of 17 (whichever occurs first). This report uses ‘child’ throughout in line with this definition.
4 Generally, the department is required to obtain consent before making recordings of students, though some exceptions apply.
4. Audit findings
4.1. Accountability for managing student information
The department has established governance arrangements that bring responsible officers together to oversee and direct action on the security and privacy of student information
The membership, terms of reference and scope of authority of the department’s various governance groups are clear. They enable responsible officers in the department to come together to consider, decide and direct action relating to the security and privacy of student information.
The Executive Committee, chaired by the Secretary and attended by all deputy secretaries, constitutes the department’s highest level of internal governance. It is responsible for strategic oversight, executive-level compliance with legal and government obligations, and overall delivery of the core departmental commitments.
Senior executive roles that lead functions relevant to managing student information include the Chief Information Officer, the Chief Data Officer and the General Counsel (with respect to privacy management).
Other key roles are the Chief Operating Officer, who leads the operational support functions for the department including technology, shared services and support services for schools; and the Chief Risk Officer responsible for the department’s organisational (enterprise) framework for managing risk and guidance to business units on risk management practices.
The Executive Committee receives periodic reports from these officers and from different departmental governance groups relevant to student information (listed in Appendix 2). These include the:
- Education Support Services sub-Executive Committee
- Information Governance Group
- Cyber Security Working Group.
An Executive Operational Dashboard tracks more than 100 key metrics across the department’s business units including risk rating and controls, audit recommendations, mandatory training completions, and (since 2025) cybersecurity incidents and data breaches.
However, there is no integrated analysis and reporting on these and other metrics (such as privacy reviews, relevant staff misconduct matters and common queries from schools) that would give senior decision-makers a holistic picture of the department’s student information management.
Schools form part of the department’s organisational governance through management reporting lines from the principals to senior managers in the department (Exhibit 2).
External entities are also involved in the governance arrangements:
- The NSW Primary Principals’ Association and the NSW Secondary Principals’ Council function as representatives of school principals. Both have technology reference groups with members participating in quarterly meetings with the department’s IT Directorate and sitting on relevant department steering committees.
- Education Services Australia is a ministerial not-for-profit company owned and established by education ministers across Australia including NSW. It runs the National Schools Interoperability Program that includes data exchange and analytics, and the Safer Technologies 4 Schools Service (ST4S) that evaluates the security, privacy and safety of digital products used in schools.
- Cyber Security NSW runs cross-agency governance groups including its ICT and Digital Leadership Group and the Community of Practice on Cyber Security.
The department assigns school principals responsibility for managing student information without assessing whether principals have the capability or capacity to meet these obligations
Within these departmental governance arrangements, principals are responsible for managing student information at the school level. This includes responsibilities for:
- selecting and operating systems used to store and process student information
- controlling the access of staff to student information
- managing records and sensitive information.
The department’s role description for school principals makes clear they are the senior decision-makers in the school, responsible for legal, executive and operational decisions that meet the needs of their students, in line with relevant legislation, industrial awards and agreements, as well as departmental policies and procedures.
The department’s Code of Ethics and Conduct provides that principals must understand and apply the laws, policies, procedures and guidelines that underpin their work. Its policies and procedures relating to student information set out specific responsibilities for principals and other staff at the school level:
- The Enterprise Risk Management Framework provides that principals are responsible for:
- owning and managing risks within their authority
- ensuring that effective controls are in place and continuously improved
- identifying and assessing emerging risks
- escalating material risks outside the department’s risk appetite
- actively monitoring and reporting on risk treatment plans at the school level.
- The Technology in Schools Procedures set out that principals are responsible for:
- selecting and purchasing third-party digital products
- obtaining parental consent where relevant
- managing and approving access to school technology systems and third-party digital products for appropriate staff members
- meeting data security and privacy standards
- monitoring staff completion of mandatory professional learning modules.
- The Records Management Procedures state that principals must ensure that their school’s business processes and systems comply with the State Records Act 1998 to produce reliable, accessible and authentic evidence of education provision.
However, the department has not determined whether principals have the capabilities or capacity needed to implement these policies and procedures, alongside their other educational leadership responsibilities, or whether specialist advice or service provision is required to help meet these obligations. Many requirements involve complex technical or legal capabilities that may not be present or readily sourced within schools.
While schools operate in different local environments and use different third-party digital products tailored to their individual student cohort, they are subject to the same legislative and departmental policy frameworks that set common requirements for managing and protecting student information.
Local context does not change these obligations nor justify materially different approaches to information protection across schools that would require principals – rather than the department – to determine how to operationalise the requirements.
Unlike individual schools, the department can take a system-wide view. It holds relevant levers (such as key IT systems and controls, and contracts with third-party vendors) and employs specialist staff in business units, including for IT and cyber security, data governance, legal services, privacy and records management, staff conduct and complaints handling functions.
The department recognises that the allocation of responsibilities between it and schools needs to be revisited. It is working to define which functions and powers across the department and schools should be centralised in its business units, and which should sit with principals.
However, this does not cover all aspects of student information management and is not yet settled nor implemented.
The department assessed a range of risks to student information as high risk and identified that existing controls are insufficient to reduce residual risk to target levels
The department’s risk management system captures enterprise risks related to student information security and privacy, including unauthorised access, use or sharing of student data; and the improper use, classification and protection of that data.
The department assessed its controls for most of these risks as being partially effective. After applying these partially effective controls, the department rated the residual risk of the following risks as high, despite a target risk rating of medium:
- unauthorised access, use or disclosure of sensitive data
- that sensitive information held by the department is not used, classified and protected effectively
- non-compliance with NSW records management legislation
- failure to prevent, detect and manage various cyber threats
- breaches of student and staff privacy, misuse of personal data, or unintended ethical and human rights principles because of AI tools.
This indicates the department considers its current controls as insufficient and that it remains likely that these risks could be realised and adversely impact departmental operations or compromise student information.
The department has action plans to address the risks that, after controls are applied, have a residual rating of high. It is implementing these plans with regular reporting to senior management and its independent Audit and Risk Committee.
The department has not identified or accurately assessed all relevant risks associated with managing student information at the school level
The department does not capture all relevant risks to the security and privacy of student information that exist at the school level in its enterprise risk management system, nor does it include the specific controls required to manage them. As a result, the department does not have oversight of all relevant risks arising at the school level or the effectiveness of the controls in place. This increases the likelihood that risks to student information are unmanaged until incidents occur.
Risks to the security of student information at the school level include that schools may:
- lack the capability and capacity to identify security and privacy risks and take appropriate action to manage or mitigate those risks
- fail to consistently inform parents and obtain valid, informed consent for the collection, use and disclosure of student information
- use third-party digital products not evaluated or approved by the department or store or share student information on systems outside of the department’s marketplaces, including some that may host data outside Australia
- fail to identify and report data breaches to the department in a timely way, limiting the department’s ability to assess incidents and manage them in line with legislative requirements.
While these risks are partially covered in the department’s existing enterprise risks, they are not expressly identified as school level risks. The specific controls expected to be in place at the school level are not captured in the enterprise risk management system.
Further, the department has assessed a specific school level risk (inappropriate access to student information) as being effectively managed, with the primary control being mandatory training. This omits other controls that the department expects schools to have in place, including principals routinely reviewing staff access to IT systems and paper records and revoking access promptly when required.
The assessment of effective management suggests to the department’s senior decision makers that controls are working as intended. However, this is inconsistent with this audit’s findings of systemic weaknesses in access controls at the school level, including:
- failures by schools to routinely review access
- delays in removing access when staff roles change
- limited oversight of access in third‑party school administration systems (see section 4.3).
The department does not include student information management in its assurance activities
Assurance activities provide confidence that controls are operating effectively, risks are being managed appropriately, and actions comply with legislative, policy and governance requirements. They may include monitoring, data analysis, compliance reviews, management reporting, internal audit and independent oversight.
The department’s systematic assurance activities that check schools are implementing its policies and procedures do not include student information management.
The department has issued relevant policies and procedures that outline principals’ responsibilities at the school level, but it has not specified minimum implementation, assurance or reporting requirements for these. It is only aware of school practices through ad hoc school data breach reports, periodic internal audits or individual school requests to central business units for support. There is no system-wide perspective on how schools manage student information.
Under the Schools Assurance Program, departmental assurance officers periodically assess the compliance of a sample of schools against its key policies and procedures relating to student safety and wellbeing, and financial and physical assets.
This program does not examine schools’ compliance with policies and procedures about student information management. Although the types of practices reviewed – mandatory training, self-assessment tools, risk registers, access settings, principal approvals and referrals to the department – would be relevant types of evidence to examine for student information management if this was included.
Other relevant departmental assurance activities include internal audits and annual attestations about compliance with privacy and records management legislative obligations.
The department’s Audit, Risk and Operational Governance directorate develops an annual internal audit program. The topics reflect inputs such as business unit feedback, enterprise risk analysis, potential administrative impact on schools, and the views of the department’s Executive Committee and independent Audit and Risk Committee.
There were 5 internal audits relevant to the management of student information in recent years, and 2 of these (from 2021 and 2022) assessed practices at a sample of schools. The department advises that it centrally tracks the implementation of audit recommendations and requires evidence before marking them as complete.
The Legal Services unit coordinates annual attestations, based on input from other business units about staff awareness, documentation, monitoring, reporting, non-compliance, improvements and planned actions in relation to the relevant privacy and records management obligations. These do not check school practices but instead rely on the department’s policies and procedures, mandatory training and breach detection to estimate a ‘medium’ level of assurance about schools’ compliance.
4.2. Departmental guidance and support for schools
The department’s policies and procedures align with legislative requirements, but do not provide schools with consolidated operational advice
The department’s policies, procedures and guidance about handling student information (Appendix 3) align with legislative requirements and most were updated recently. However, these do not provide consolidated operational advice to schools on managing risks to student information.
The department publishes periodic legal bulletins on how relevant statutes and case law apply to schools. These include matters relating to student information such as privacy legislation, cyber security, use of third-party web and cloud-based service providers, permission to publish student images, use of closed circuit cameras and recording devices, family law, school counsellors and confidentiality, information requests from other government agencies and so on. It also provides training to schools to support their implementation of the department’s guidance.
The department’s guidance to schools on handling student information is fragmented between different departmental functions (cyber security and other IT, data governance, legal, privacy and records) and guidance types (policies, procedures, staff updates).
No single resource brings together the disparate advice and gives schools an overarching picture of their responsibilities and expected practices in actively managing student information.
This contrasts with other areas of responsibility where integrated guidance is available, such as the Finance in Schools Handbook, which covers delegations, accountabilities and school budget management.
Without clear and explicit operational guidance, schools may not recognise emerging risks or know when to seek assistance.
School principals can also contact their Director Educational Leadership (DEL) for advice on departmental guidance about student information handling, as DELs are responsible for supporting schools to implement applicable policies and procedures.
Consulted schools indicate that:
- while the department’s written guidance on non-technical topics such as privacy is generally clear, it can be difficult to locate on the department’s intranet
- some prefer to seek advice from other principals, their DEL or from central teams in the department
- some want clearer direction on managing paper records, transferring students records between schools and user access controls.
Schools manage sensitive student information without clear departmental guidance, resulting in inconsistent practices and a risk of legal non-compliance
The department’s guidance to schools on managing personal and health information focuses on legislative requirements and definitions rather than on how to manage the risks associated with sensitive information in day‑to‑day operations. As a result, schools lack specific direction on how this information should be stored, accessed and managed across department systems and third‑party digital products.
Schools routinely collect, manage and store a range of sensitive information about students, including health information (Exhibit 1). Health information is protected by the NSW Health Records and Information Privacy Act 2002 separate from the state privacy statute.
The department’s policies, procedures and guidance do not clearly specify:
- the systems schools should use to store health and other sensitive information
- which staff roles should have access to that information
- any applicable additional safeguards given its sensitive nature
- the need to regularly review personal and health records for completeness and accuracy.
The department told the audit that schools can use approved third‑party school administration systems in a way that meets legislative obligations, but notes it is best practice for schools to store student health and other sensitive information in the department’s systems. This is because schools may not always manage staff access appropriately in these third‑party systems, making it easier for student information to be shared more widely than intended or permitted by department policy. However, this advice is not clearly stated in the department’s policies, procedures or written guidance to schools.
Without clear departmental guidance, schools have their own approaches to managing student health and sensitive information. All consulted schools store and manage this information on third-party school administration systems, primarily to facilitate relevant staff access.
Schools vary in which staff roles have access to health and sensitive information. Some limit access to principals, administrative staff and staff directly involved in providing wellbeing and learning interventions; others grant access to all staff so any staff member can find information if they need to respond to a student’s wellbeing or health concerns.
These inconsistent practices highlight the need for clearer operational guidance for schools to protect sensitive and health information in accordance with departmental expectations and legislative obligations.
The department’s training and awareness programs for schools are not consolidated to specifically guide staff on managing student information
School staff can access departmental training and awareness programs on relevant topics including:
- expected staff conduct
- child protection
- cyber security and data breaches
- privacy
- public interest disclosures
- media
- school record retention and disposal.
No training or awareness programs consolidate the requirements and expected practices across these different areas to specifically guide staff on managing student information.
The training courses on expected staff conduct, child protection, cyber security and data breaches, and public interest disclosures are mandatory for new staff. Once these are completed, staff are eligible to complete an annual competency check.
The department tracks the rates of staff completion of mandatory training, annual competency checks and other non-mandatory professional learning courses. After it previously found low completion rates for mandatory training on cyber security, it prioritised this for action across the organisation.
The department advises that the introduction of annual competency checks from Term 1 2025 drove more than 95% completion of mandatory cyber security training across schools. It indicates that, as at October 2025, its cyber security and data breaches training had an average completion rate of 96% across school staff, education support staff and its executive leadership team. The department also observed improvements in staff completion rates for its mandatory training on its Code of Ethics and Conduct.
Other relevant training courses, including on school records management, privacy and media, are available for staff to opt in to when they have a need and time to complete them.
Schools can also access training on the third-party school administration systems from the relevant third-party vendors. However, awareness of this training varies across consulted schools, and is not specific to protecting student information in line with NSW legislative obligations and departmental policies.
The department initiates several cyber security awareness initiatives for schools each year, including phishing simulation exercises. Schools can also access the national Cyber Marvel program that aims to build staff and students’ cyber safety awareness and skills.
The department does not provide consolidated or targeted training on the security and privacy of student information, nor does it use trend analysis on reported data breaches (section 4.7) or seek feedback from schools to identify training needs and support gaps in relation to managing student information.
The department provides technical support on request to schools but does not ensure schools consistently have sufficient resources or capability to manage risks to student information
The department expects school principals to manage the school and comply with policies, including those relevant to student information handling. The department also expects other school-based staff, such as teachers, to manage and respond to risks relating to student information in accordance with the department’s Code of Ethics and Conduct.
The department provides schools with reactive technical IT support and legal advice on IT and privacy issues in response to incidents and requests. However, the department does not consistently ensure that schools have the resources, capability or specialist support needed to manage the security and privacy of student information.
Schools can access support from the department’s dedicated IT service desk to help resolve cyber and other technical issues. The department also funds IT field services officers to visit every school once a term and assist with their IT hardware and software. However, consulted schools indicate that neither support plays a direct role in helping them to manage and respond to risks relating to student information.
The department does not provide schools with dedicated funding for IT support staff roles (known as technology support officers in secondary schools and IT coordinators in primary schools). Principals decide on these roles based on their school’s requirements and capacity to fund from the school budget. Of the 37 consulted schools, 21 have a technology support officer or an IT coordinator, one school has both positions, and 15 do not have either position.
These roles are generally highly valued by principals and administrative officers for providing technical IT advice and services. However, they often do not have a direct role in managing the security and privacy of student information. For consulted schools without the need or budget for these roles, day‑to‑day support usually comes from school administrative staff or teachers with prior experience or a specific interest in IT.
The department provides legal advice to schools on matters concerning the privacy of student information. In 2025, it received 690 requests for legal advice on privacy from schools and staff. Schools required advice on:
- sharing information about students with third parties
- consent to publish images of students
- authorised recording and surveillance (e.g. closed circuit cameras)
- data breaches.
Several consulted schools report they receive good support from the department when requesting assistance on legal matters.
The department advises that its Chief Data Office also provides targeted support to schools on request, in response to data breaches or where complex data governance issues arise, particularly in managing sensitive student information.
Overall, consulted schools tend to rely on local staff capacity, ad hoc arrangements or requests to the department to manage the operational aspects of security and privacy risks associated with student information.
Schools continue to use paper alongside digital records and report challenges in appropriate archiving and disposal
Most schools use paper and digital formats to store student information. Each school is responsible for managing these records in line with departmental policies and procedures.
In recognising an inconsistent application of records management policies at the school level, which increases the risk of security and privacy breaches, the department has a digitisation project underway to address this.
Consulted schools describe a hybrid model of storage for student information, with core student information held in digital systems and paper records used for individual student record cards, archives, and some sensitive files.
Schools that primarily store student information digitally also maintain physical student record cards or files that contain copies of forms printed from digital systems, historical reports and documents from other settings (such as disability diagnoses or health care reports from treating specialists). All consulted schools report they hold paper records for the designated periods under state records requirements.
Schools consistently report storing student paper records in locked filing cabinets for current files and in locked compactus or storage rooms for archived files with access by keys held by the office staff and school executive.
No consulted schools have electronic access controls for their physical student files (for example, a swipe pass linked with individual staff credentials) or a register of staff requesting the key. This means there is no log of who accesses the paper records.
Schools can request training and guidance from the department on school record keeping and information management. The department advises that it has delivered 78 training sessions on school records management to more than 3,000 staff since July 2025. These sessions aim to increase awareness of appropriate records management including digitising existing paper records.
However, consulted schools often experience challenges with storing paper-based student records in line with NSW State Records standards and retention schedules. For example:
- some lack appropriate facilities to archive paper student records for the period of time required after students finished schooling
- schools cite insufficient space and storage rooms that are unprotected from heat and humidity as barriers to properly storing paper records
- some schools do not feel they have departmental support to efficiently dispose of large volumes of student records after the record retention period.
The department identifies the lack of digital record keeping infrastructure and volume of physical records at schools as a risk for non-compliance with NSW records management requirements.
Under its 5-year Records Management Strategy, it is developing a digital content management system to consolidate the student records held across department systems, third-party school administration systems and paper-based records. It has already digitised more than 36,000 student welfare files and 11,000 student files.
4.3. Access to student information
The department has not clearly translated its access control requirements into operational school guidance, and schools inconsistently manage staff access to student information
The department defines access control principles through its Identity and Access Management Standard. The standard requires staff to hold only the minimum access needed to perform their duties. Principals are responsible for applying these requirements across department systems and the third‑party enterprise platforms, school administration systems and online learning apps.
The department has not translated these requirements into clear, operational guidance that schools can follow to set specific access levels for common staff roles across these systems, which have different access‑control settings. This assumes a level of technical capability that is not always available in schools.
In practice, schools apply different interpretations of the level of access staff required for their roles. Consulted schools did not refer to the department’s standard when explaining how they assign, review or remove staff access. With individual schools making different decisions, there are inconsistent approaches to managing staff access to student information in the department’s enrolment system and third‑party digital products.
In some schools, principals and administrative staff generally have access to all student information, while classroom teachers only access information for students in their classes. Other schools advise that all teachers have access to information for all students to record and view information related to learning and wellbeing interventions, behaviour management and health conditions. Schools do not always formally document how they assign, review or remove staff access in their different systems.
Some consulted schools do not fully understand what different user access roles mean in the department’s enrolment system and third‑party school administration systems, and what information those settings allow staff to see. They cannot always explain why some staff are granted certain levels of access that do not align with their role.
These weaknesses are evident in the management of elevated or privileged access, which involves permissions beyond those of a standard user and can enable staff to access or change sensitive student information or manage other users’ access. In the department’s enrolment system and third‑party school administration systems reviewed by the audit, several staff hold principal‑level access that does not align with their roles.
Exhibit 3 illustrates a data breach that occurred when access control requirements for a core enterprise platform were not translated into operational guidance for schools.
In August 2025, the department became aware of unusual access activity affecting departmental files stored in Microsoft 365, a core enterprise platform. The department found that 2 high school students had accessed around 2,000 files over the previous 3 months. Some files contained personal and highly sensitive information relating to other students’ mental health diagnoses, behavioural concerns, family circumstances and disabilities. The unauthorised access occurred because the core enterprise platform’s built-in access controls were undermined by the department’s configuration choices during the rollout across the organisation and schools. During rollout, the department set default file-sharing permissions that allowed files to be shared publicly or with all users within the organisation. This meant that when staff in individual schools collaborated on documents, they unknowingly and inadvertently gave access to students and staff across all schools and the department. Student information was not adequately protected from unauthorised access. When the breach was identified, the department addressed and contained the breach and worked to reduce further risk. The department disabled the accounts of the students who accessed the files, reset their passwords and required them to delete any files not related to their schoolwork. The department also removed broad sharing permissions in the core enterprise platform. The department assessed the incident as an ‘eligible data breach’ under the NSW Information and Privacy Commission’s mandatory data breach notification scheme and reported it accordingly. |
Source: Audit Office summary of information provided by the NSW Department of Education.
The department updated its guidance for schools in March 2026 to provide more practical and accessible advice on managing staff access to student information when using core enterprise platforms. There is no equivalent tailored guidance on managing access in the key third-party school administration systems.
The department’s access management tool does not cover key third-party school administration systems
The department’s Manage Staff Access application enables principals to grant, adjust and remove individual staff access to student information in key department systems. However, this tool does not include the third-party school administration systems.
The department advises that these third-party systems have the technical capability to support access controls that meet its requirements. However, it has not developed system‑specific guidance with vendors to explain different access level settings in each system or how schools should use these settings to comply with departmental requirements.
In addition, the department has not worked with vendors to:
- enable features like automatically turning access on or off when staff start, change roles or leave a school
- establish standard profiles in systems with varying access permissions for common categories of school staff roles.
Consequently, schools manage staff access to student information across multiple systems with different tools, access settings and guidance. This increases reliance on local judgement and manual processes, particularly for third-party school administration systems. It also increases the work involved for schools, as they must interpret the department’s technical guidance and then determine how to apply system‑specific access settings in practice.
The department advises that it is working with vendors to enhance access controls and oversight of its contracted third-party school administration systems, such as Compass, SchoolBytes and Sentral.
The department does not have sufficient assurance processes in place to assess whether schools remove staff access to student information in a timely way
All consulted schools expect that access to the department’s enrolment system and third-party school administration systems is removed when staff leave the school. However, this is difficult to manage in practice due to the number of systems in place and the frequent movement of casual and temporary staff.
Schools typically review staff access to student information at the beginning or end of the school year. However, consulted schools do not conduct reviews consistently, particularly for third‑party school administration systems. In some schools, access reviews found that current or former staff had retained inappropriate access for up to 12 months. Although these schools remove access once identified, they do not routinely review system logs to determine if student information is accessed unnecessarily during these periods.
In the past year, the department introduced more automated controls over staff access to its enrolment system ERN. These controls automatically remove staff access when a staff member is no longer recorded as being located at a particular school.
While this reduces reliance on manual action, it does not apply in all circumstances. If a principal assigns a staff member a different level of access from their default onboarding role, the system does not remove access automatically. Principals must remove access manually or notify the department so it can remove the access centrally.
Some consulted schools manually assign and remove access for many staff roles in the department’s enrolment system. This indicates that access removal often relies on school level action, despite the department’s more centralised controls. Some principals reported retaining access to the department’s enrolment system at schools where they no longer work, in some cases for months or many years after leaving.
For third-party school administration systems, access management is entirely manual. The department does not have visibility of who can access student information in these systems and does not apply any central controls to remove access when no longer required.
Between June and August 2025, the department introduced an annual attestation process for principals to confirm that access to department systems is limited to staff who require it to perform their role. The process requires principals to confirm they have checked who has access to department systems at their school and that they have changed access permissions where these were not accurate or necessary.
While intended as a prompt for principals to review staff access to departmental systems and to reinforce their accountability for access settings, the first cycle of attestations had low completion rates. This suggests the process is not yet driving compliance across all schools.
Department data indicates that, at the end of the first attestation cycle from June to August 2025, 601 of 2,247 NSW public schools (26.7%) reviewed user access for all of their staff and 838 schools (37.3%) had not reviewed access for any staff. The remaining schools had completed access reviews for some, but not all, staff.
The attestation process is limited by its reliance on self reporting by principals, with no systematic validation by the department to confirm whether access reviews have been completed or whether identified issues have been appropriately addressed.
Further, the attestations only cover staff access to department systems, not the third-party school administration systems, despite these systems holding personal, sensitive and health information about students.
While the department has improved automated control over access to its enrolment system, it does not yet have sufficient assurance that schools:
- consistently review staff access
- remove access promptly when it is no longer required
- effectively manage access to student information, particularly for information held in third-party school administration systems.
4.4. Schools’ use of third-party digital products
The department provides schools with access to third-party digital products through its marketplaces to help manage student information
The department assesses and manages a range of third-party digital products used for school administration, teaching and learning, and school operations. It manages two online marketplaces and an ‘Assessed IT’ catalogue that include the main types of third‑party products used by schools.
The department recommends that if schools wish to purchase a third-party product beyond the core enterprise platforms (Adobe Creative Cloud, Google Workspace and Microsoft 365), they select these products from its marketplaces. Products on the marketplaces meet the department’s data security and privacy requirements.
Schools can use the marketplaces to view information about the products and purchase subscriptions using their individual school budgets. While schools hold subscriptions, the department holds the head contract with the core enterprise platform vendors and third-party vendors of marketplace products. The contracts establish minimum information security standards and privacy obligations. Departmental contract managers regularly meet with vendors to monitor adherence to these contracts.
Assessed IT, the central catalogue of cyber security assessments for paid and free third-party products assigns a rating – ‘allowed’, ‘use with caution’ or ‘do not use’ – to guide schools in purchasing and using third‑party products not offered through the marketplaces.
An ‘allowed’ rating indicates the product meets the department’s cyber security requirements.
- A ‘use with caution’ indicates that the product meets most, but not all, requirements and may present risks that schools need to manage.
- A ‘do not use’ rating indicates that the product presents an unacceptable risk to department data, including student information.
The department expects schools to prioritise using third-party products available through its marketplaces over products listed in the Assessed IT catalogue. Where schools use products outside the marketplaces, they are advised to avoid those rated ‘do not use’ and limit the disclosure of student information to the minimum necessary when using products rated ‘allowed’ or ‘use with caution’.
The department has limited visibility over school use of third-party digital products outside its marketplaces and how these products handle student information
The department does not routinely monitor schools’ use of third‑party digital products outside of the marketplaces, nor how they collect and use student information.
In practice, almost all schools use third‑party school administration systems (such as Compass, SchoolBytes and Sentral) from the department’s marketplaces to manage large volumes of student information. Although the department has not made it mandatory to use these systems, most schools had adopted them before the marketplaces were introduced, and continue to use them.
By contrast, the department does not know how many schools use third-party online learning apps and other digital products outside its marketplaces.
The department expects schools to request an assessment before using third-party products not listed in its marketplaces or on the Assessed IT catalogue. Schools can access the department’s risk assessments and advice for a range of non‑marketplace products through Assessed IT. However, the department does not monitor whether schools comply with the requirement to request an assessment before use and could not advise the audit how many schools use products outside its marketplaces.
The department also lacks oversight where schools choose to use digital products that have not been assessed or that have been assessed as not meeting the department’s information security and privacy requirements.
From Term 3 2025, the department made its marketplace for online learning apps mandatory. This means schools can continue to use existing apps until the current subscription expires; after this, they are expected to purchase these apps only from the marketplace.
As this requirement was introduced late in the audit review period, the audit did not assess how the department is enforcing it.
Schools’ confusion about which third-party digital products are on the marketplaces increases risk
Consulted schools use more than 100 different third‑party digital products. They generally seek to use third-party products from the marketplaces, which they understand as being assessed and approved for safe use. They are reluctant to assume the risk and due diligence requirements associated with using unapproved or unassessed third-party products.
However, the audit found that while these schools use marketplace school administration systems, more than 60% of the digital products they reported using for learning and other classroom purposes are not available through the marketplaces.
Most of these non-marketplace products collect limited information, such as a student’s name, class and school email address. However, some collect personal and contact details, demographic characteristics (such as ethnicity and religion), attendance and wellbeing information; images, audio or video recordings; or personal information about parents or guardians.
The online learning apps used by consulted schools that are not on the marketplaces have varied ratings in the Assessed IT catalogue:
- 21 are ‘allowed’
- 25 are rated as ‘use with caution’
- 4 are rated as ‘do not use’
- 13 were neither listed on Assessed IT nor available through the marketplaces.
The mix of marketplaces and the Assessed IT catalogue creates a complex environment for schools. In practice, many consulted schools incorrectly assume that products on Assessed IT are managed through departmental contracts and subject to the same controls as marketplace products. This has implications for how student information collected by these products is protected and monitored by the department.
The marketplace products are assessed against syllabus, pedagogical, data privacy and cyber security requirements and supported by contractual arrangements requiring suppliers to maintain these standards; third-party products on Assessed IT are assessed only against data protection and cyber security requirements and are not subject to the same contractual obligations.
Where schools use products outside the marketplaces, risks to student information – including the risk that data may be shared with other parties for commercial or other purposes – are not mitigated by departmental contractual terms and must be managed by schools. However, if schools believe that products on Assessed IT are protected to the same level as marketplaces products, they may not be managing these risks.
In addition, while third-party products from the marketplaces are required to host student data in Australia, this does not apply to Assessed IT products, where student data is often hosted offshore. This makes student data subject to foreign legislation that may differ from NSW standards and legislation. There is a risk of weaker privacy protections and limited ability for schools and the department to respond to incidents or enforce NSW privacy, security and accountability requirements.
Some consulted schools seek parental consent for Assessed IT products, while others believed these products are included on the marketplaces and do not require such consent. The department’s guidance does not require schools to seek parental consent for third‑party products in its marketplaces, but does require it for non‑marketplace products (see section 4.6).
Exhibit 4 illustrates the types of student information that may be collected by ClassDojo, a third-party product not available through the marketplaces as it hosts data in the United States. ClassDojo is rated as ‘use with caution’ on the Assessed IT catalogue.
ClassDojo is a third-party app used by some schools in NSW, for enabling communication between classroom teachers and parents. It can collect the following information about students and their parents:
|
Source: Audit Office summary of information provided by the NSW Department of Education.
Some schools manage student information in their own IT environment outside of the department’s oversight and security controls
The department has not implemented a standard IT environment across schools. Under the department’s previous Local Schools, Local Decisions Policy (2012–2020), schools were empowered to adopt their own technology solutions and support arrangements.
Although the policy has been replaced, decisions made under it continue to affect school level technology environments, particularly in relation to cyber security risk and the department’s ability to maintain effective oversight.
While the department recognises that school‑managed systems increase cyber security risk, costs and reliance on specialist skills that are difficult to sustain at the school level, there is not a standard IT environment across all schools. The department has identified that less than 20 schools continue to operate systems and use software outside its approval and security controls.
These arrangements have resulted in cyber security incidents. For example:
- In 2024, unapproved software at 2 schools was not operating on department‑managed servers. This resulted in installation of malware on staff devices and the theft of sensitive information.
- In another case, the use of a locally managed server prevented the department from ensuring compliance with mandatory cyber security policies and controls.
4.5. Departmental oversight of third-party digital products
The department does not apply comprehensive oversight and assurance to third-party digital products in its marketplaces
The department’s contractual and monitoring arrangements to manage security and privacy risks for the third‑party school administration systems and online learning apps in its marketplaces rely on third-party vendors:
- maintaining independently certified security frameworks
- completing self‑assessments
- reporting on their compliance with the department’s security and privacy requirements.
However, the department could not demonstrate that it routinely reviews the certifications, or assurance reports it receives to better understand issues identified or how third-party vendors address them. The department does not routinely supplement vendor assurance with independent spot checks, periodic audits or external reviews.
The NSW Cyber Security Policy requires NSW Government agencies manage third-party risks through risk-based reviews that verify compliance with contractual agreements and security measures. The department’s contracts with third-party vendors require independent certification that the vendor:
- meets internationally recognised security standards
- restricts data access to approved personnel and locations
- maintains regular secure backups
- promptly reports and remediates security incidents.
Vendors are also expected to comply with privacy laws, audit their own compliance with the department’s security requirements, and continuously improve their security measures.
The contracts allow the department to seek additional independent assurance where needed, including independent audit reports or other security assurance information from vendors. Contract managers meet with vendors to oversee compliance, with vendors self-reporting against the information security and privacy requirements.
The department could make more use of its contractual rights and assurance tools to further verify vendor compliance, particularly for third-party school administration systems that handle large volumes of student information.
The department advises that it has removed some online learning tools from its marketplaces because vendors did not meet specific mandatory security requirements, such as requiring users to access the product through a central department‑managed login system rather than separate vendor accounts.
However, the department’s monitoring and assurance arrangements are limited. The department identified non‑compliance in one centrally contracted third‑party school administration system.
In this case, the department identified security and privacy control issues that were inconsistent with the vendor’s contractual requirements. These included inadequate audit logging, which limits the ability to reliably detect, investigate and respond to data breaches; and the absence of certification confirming that student data had been securely deleted after schools stop using it. If data deletion cannot be verified, there is a higher risk of ongoing exposure or misuse of student information.
In response, the department advised schools to limit the student information they share with this system. However, this has practical limitations because it is one of the most widely used school administration systems across schools and is necessary for school operations. The audit did not see evidence of how the department is addressing these issues with the third‑party vendor, or how it is monitoring and enforcing compliance with information security obligations from other third‑party school administration systems.
Exhibit 5 summarises independent research highlighting instances where the practices of third‑party vendors do not align with their stated privacy policies. This illustrates the limitations of relying on vendor self‑attestation and the importance of independent verification.
Data collection and privacy practices in department-recommended apps (2026) Researchers from the University of New South Wales (Jin et al. 2026) examined data collection and privacy practices in 200 learning apps recommended by Australian schools and education departments, including the NSW Department of Education. The study found 84% of apps began transmitting data to third parties immediately on launch, before any user interaction. This included device identifiers, location metadata and other sensitive information. It also found that 68% of apps contained embedded analytics or tracking tools with no clear educational purpose. The privacy policies of these apps often did not explain these data-sharing practices. Only 3% were considered easy to read. Some apps that explicitly stated they did not collect personal data transmitted identifiable information within seconds of launch. This indicates that privacy policies frequently did not reflect actual app behaviour and could not be relied on to accurately describe how students’ data was handled. Tracking and profiling of children through education technology (2022) In 2022, Human Rights Watch reviewed 163 education apps and websites endorsed by governments in 49 countries, including Australia (NSW and Victoria). It found widespread collection and sharing of children’s data for purposes unrelated to education. The research identified extensive use of tracking technologies, with 45 products transmitting children’s personal information to 196 other third-party companies, including advertising technology providers, often without meaningful notice or consent from parents or students. These practices could allow third-party vendors to combine data about a child’s device, location and online behaviour to build profiles predicting their interests and actions. This could be used for commercial purposes such as targeted advertising across multiple apps and websites. Data sharing practices were rarely transparent and were frequently not disclosed, or not fully disclosed, in the products’ privacy policies. Human Rights Watch highlighted that this type of profiling is particularly concerning for children, as it can influence their online experiences and choices at a stage when they are more vulnerable to manipulation. |
Source: Audit Office summary of external research, Jin, S, Masood, R, Lee, JS & Paik, HY (2026), ‘Analysing privacy risks in children's educational apps in Australia’, Symposium on Usable Security and Privacy (USEC), San Diego, CA, US; Human Rights Watch (2022), “How dare they peep into my private life?”: children’s rights violations by governments that endorsed online learning during the COVID-19 pandemic’, Human Rights Watch.
The department only recently identified key third-party school administration systems that store sensitive student information as ‘crown jewels’
In 2019, the NSW Cyber Security Policy introduced a requirement for agencies to identify their most valuable or operationally vital systems or information, known as crown jewels, and to apply appropriate controls based on their importance.
The department identified its enrolment system, ERN, as a crown jewel in 2020–21 and its Online Student Counselling Records system, OSCR, as a crown jewel in 2022–23. It established cyber security oversight and protective control arrangements for these systems.
The department contracts with third-party vendors that provide schools with around 90 third‑party products through its marketplaces. It applies cyber security requirements and contractual controls to these vendors, consistent with its broader cyber security framework. School administration systems have been available through the department’s marketplaces since 2022 and hold comparable volumes of sensitive student data to the department’s internal crown jewels (ERN and OSCR). However, the department did not develop an approach to identify which third-party products should be classified as crown jewels until late 2025.
The department designated three school administration systems (Compass, SchoolBytes and Sentral), used by more than 98% of schools to manage student information, as crown jewels in early 2026. It is developing a third-party assurance framework to protect and manage these 3 crown jewels. It intends to embed the framework into its existing contract management arrangements and extend it to any other third-party digital product in its marketplaces that store or process a significant quantity of sensitive information, where it designates these as crown jewels.
The department conducts privacy impact assessments for some new initiatives involving student information but not routinely for existing processes and systems
Although not mandatory under legislation, privacy impact assessments (PIAs) identify and minimise privacy risks relating to changes in services, policies and new projects.
While the department has conducted PIAs for some major initiatives that involve student information, it does not have a standard, risk-based approach for PIAs of existing processes and systems that hold student information. In not conducting PIAs for any of the key third-party digital products schools use to store student information, the department lacks sufficient assurance that privacy risks across these products are being systematically identified and managed.
The NSW Information and Privacy Commission recommends NSW Government agencies to undertake PIAs for any new project or initiative, or when making changes to existing initiatives, that involves handling personal or health information.
Consistent with this guidance, the department has completed or is undertaking PIAs for several major department‑led initiatives and AI‑enabled tools and datasets that may impact student information, including work undertaken in response to the NSW AI Assurance Framework. Some PIAs, due to their complexity, were completed by the NSW Crown Solicitor’s Office or external legal firms on behalf of the department. Given the expertise, funding and resourcing required to undertake a PIA, the department does not advise schools to conduct PIAs themselves.
The department’s cyber assessment process partly informs its PIAs. This considers the need for parental consent, security features, whether information is transferred to third parties and data sovereignty. In addition, the standard terms used for departmental contracts with third-party vendors include measures requiring compliance with privacy legislation and dealing with key considerations raised as part of its cyber assessment process.
However, the department has not implemented a risk-based approach to embed privacy considerations in processes and systems that impact student information, including for third-party products commonly used by schools. While these products are subject to security assessments and contractual privacy requirements, these controls apply after procurement and do not provide a systematic assessment of broader privacy risks.
The department’s oversight of AI in schools is not keeping pace with technological innovation
AI is increasingly embedded in the third‑party digital products that may collect, store or process student information. AI can introduce risks to security and privacy by collecting more information than authorised, retaining it indefinitely or re-using it for purposes such as model training or commercial use.
While the department aims to enable AI use while managing risk, current arrangements do not provide assurance that all AI‑enabled tools used in schools are identified, assessed and monitored in a timely way.
In 2024, the department established a Chief AI Office to oversee AI use and assess selected tools against the NSW AI Assessment Framework. These arrangements operated separately from broader IT, procurement and cyber security processes, limiting integration with existing controls and reducing visibility of AI tools used across schools.
The department has prioritised assessments for third-party online learning apps in its marketplace, while third‑party school administration systems in a separate marketplace have not been subject to an AI assessment.
Resourcing constraints have created a backlog of assessments, and procurement processes do not systematically identify AI functionality for review. The department is taking steps to address these issues by consolidating AI governance within its central IT function and aligning with whole-of-government AI arrangements.
The department advises that it requires third-party vendors in its marketplaces to notify the department before enabling or introducing AI features that may affect how student data is collected, used or processed. Once notified, the department can assess the risks by applying the NSW AI Assessment Framework, considering privacy impacts and checking alignment with relevant laws and policies.
This is not the case, however, when schools adopt third-party digital products outside the marketplaces. The department requires schools to only use AI tools and features that have been approved, and assesses additional tools and features on request. However, the department does not monitor whether schools consistently follow this process; further, the assessment process can take considerable time, which may discourage schools from seeking approval.
Consulted schools are generally unsure about how to identify AI features in third‑party products they use. Some became aware of AI functionality only after its introduction, most commonly through vendor or department updates, staff observations, or colleagues in principal networks.
This increases the risk that student information is processed by AI‑enabled systems before privacy, security and ethical risks are identified and controls are put in place.
The department’s security and safety assessments of AI tools and features used by schools do not keep pace with the speed of technological innovation.
Fragmented central oversight combined with an evolving understanding of AI make it difficult to maintain an accurate and up to date view of AI tools used across more than 2,200 schools.
4.6. Information provided to parents
The department informs parents about the information it collects about students
At the point of enrolment in a school, the department informs parents about the broad range of personal, sensitive and health information it collects about students to meet its statutory functions and obligations.
This reflects the requirements of NSW privacy legislation, which permits collection of information where it is for a lawful purpose and reasonably necessary for an agency’s functions.
The department’s information collection notice and standard enrolment form explain that student information is collected to deliver education services, support student learning, manage wellbeing and health needs, and ensure student safety. It also advises parents of the categories of information collected, including family and contact details, educational background, health and disability information, wellbeing and behavioural information, and participation in learning and support programs.
The collection notice also explains how the department and schools use this information to:
- respond to students’ educational needs
- tailor teaching and learning and identify students who may require targeted support
- provide students with appropriate wellbeing supports
- manage student and staff health and safety risks.
Parents are advised that choosing not to provide some information about their child may have a detrimental impact on their child’s enrolment, the resourcing of the school, or the school’s ability to meet their child’s learning and support needs. This approach is consistent with NSW privacy legislation, which requires agencies to explain the consequences of not providing requested information.
In addition, the department’s Privacy Management Plan describes:
- the types of personal and health information it manages
- how it complies with legislation
- the department’s approach to privacy management, including how it communicates its privacy obligations and how individuals may access or request a correction of their information
- information on how the department handles privacy complaints and internal reviews.
The audit did not assess the department’s Privacy Management Plan against NSW Information and Privacy Commission requirements.
The department does not provide complete information to parents about third-party vendors in its marketplaces
The department does not specify at enrolment, or require schools to specify, when student information is stored in third-party digital products in the department’s marketplaces. Parents may not realise their child’s information is stored in these products.
At enrolment, the department explains to parents that personal and health information about students may be disclosed to other government agencies where permitted or required by law, including for national reporting purposes. It also explains that, with parental consent, student information may be stored with third-party providers outside the department’s network, as well as in department systems.
However, the information provided to parents to support this consent is limited to the core enterprise platforms (Adobe Creative Cloud, Google Workspace and Microsoft Office 365). The department does not disclose its contracts with other third‑party vendors, nor does it explain the types of student information that may be stored in these products.
In practice, the department relies on individual schools to provide parents with information about the third-party digital products they use, and how student information is collected and stored in those products.
The department’s guidance and templates for schools on obtaining parental consent for third-party products is ambiguous:
- One document states that schools may not need to obtain parental consent for marketplace third-party products, but that it is best practice to inform parents about their use.
- Other guidance – and the consent template the department developed specifically for third‑party products – directs schools to seek parental consent only for products that are not on the marketplaces.
The department requires schools to obtain product specific parental consent when using a third‑party product outside the marketplaces. In these cases, schools are expected to use consent templates developed by the department that explain what data is collected, where it is stored and whether it is shared with other third parties.
This variability in advice and requirements means consulted schools take different approaches to parental consent for the third-party products. Some schools inform parents about all third-party products and obtain consent annually; others follow the department’s guidance and seek consent only for third-party products not available through the department’s marketplaces.
While the department considers third-party products available through the marketplaces as meeting its security and privacy requirements, by not applying equivalent information or consent requirements to marketplace products, the department creates a situation where parents are not routinely informed about how student information is stored with commonly used third-party vendors.
This does not align with the NSW Information and Privacy Commission’s best practice guidance on obtaining valid consent, which emphasises that consent should be informed by clear advice about how personal information will be used, including who will have access to it and the intended recipients.
The department’s bundled consent approach to obtaining parental permission to publish student information does not align with NSW Information and Privacy Commission guidance
The department seeks consent from parents at enrolment to publish information about their child for the purposes of:
- sharing their experiences with other students
- informing the school and broader community about school and student activities
- recording student participation in noteworthy projects or community service.
This consent is ‘bundled’ which means it combines multiple uses and disclosures of student information into a single consent.
The bundled approach prioritises administrative efficiency. However, it does not allow parents to choose for which purposes, or publication channels their child’s information may be disclosed on. For example, enabling parents to agree to school newsletters shared primarily within the school community, but not to social or external media shared publicly.
After enrolment, the department recommends schools obtain bundled consent to publish student information at the beginning of each school year. Some consulted schools told the audit they use consent approaches that allow parents to choose specific publication channels for their child’s information. Others follow the department’s guidance and rely on bundled consent in most circumstances.
The NSW Information and Privacy Commission’s guidance states that bundled consent is not best practice and that valid consent to information sharing should be specific, informed and granular.
In terms of media engagement, the department recommends schools consider specific permission to publish student information in certain circumstances. This includes where a media organisation contacts a school directly or where the department’s Media Unit visits a school to interview or film students as part of a public information campaign. It also provides training to schools on managing media engagement and responding to media enquiries.
4.7. Detecting and addressing data and privacy breaches
The department has processes to contain, investigate and address suspected data and privacy breaches involving student information in line with whole-of-government guidance
Privacy legislation and whole-of-government guidance requires the department to take reasonable steps to safeguard personal information against unauthorised access or disclosure. The department has established processes to ensure that suspected data breaches involving student information are recorded, investigated and addressed in a timely manner in line with these requirements. The audit did not assess the effectiveness of the department’s data breach processes.
Once the department is notified of a suspected data breach, the incident is triaged and assessed, including whether it requires notification to the NSW Information and Privacy Commission under the NSW Mandatory Notification of Data Breach Scheme. This scheme requires NSW Government agencies to inform the commission, and notify affected individuals, if an ‘eligible’ data breach involving their personal or health information has occurred.
An eligible data breach is one where personal information held by a public sector agency (whether in digital or hard copy) is subject to unauthorised access, unauthorised disclosure or is lost in circumstances where the loss is likely to result in unauthorised access or unauthorised disclosure. This may or may not involve disclosure of information external to the agency or publicly.
Not all data breaches will be an eligible data breach, and not all data breaches involve personal information. Exhibit 6 provides common examples of data breaches.
Human error
System failure
Malicious or criminal attack
|
Source: NSW Information and Privacy Commission, Mandatory Notification of Data Breach Scheme: Guide to managing data breaches in accordance with the PPIP Act, July 2024.
Staff must report all suspected data breaches to the department’s Legal Services unit, which assesses whether they meet the threshold to constitute an eligible data breach under the scheme and reports them to the commission if they do so.
Before November 2023, the department’s process involved the relevant data owner in the department (including principals) assessing, addressing and reporting suspected breaches to the commission directly, with legal support on request.
After this date, while responsibility for responding to potential data breaches is often shared across the department to ensure the involvement of staff with appropriate knowledge, the Legal Services unit oversees the assessment, response to and reporting of suspected breaches. Both the department and the commission say this has improved the consistency and quality of breach handling and reporting.
The department’s Data Breach Response Plan outlines that while all data breaches will be considered a privacy breach, not all privacy breaches will meet the threshold to constitute a data breach (whether classified as an eligible data breach or not). Data breaches only occur where there is unauthorised access to or unauthorised disclosure of personal information or where personal information is lost or stolen in circumstances where unauthorised access or disclosure is likely to occur.
In contrast, a privacy breach occurs if privacy legislation is not complied with. Since all data breaches are privacy breaches, a data breach entitles an affected individual to request an internal review of conduct under the Privacy and Personal Information Protection Act 1998. This may include a right for an individual to claim compensation from the department.
The number of suspected data breaches and privacy matters involving student information identified by the department is low
The department’s recorded suspected data breaches and privacy matters are low relative to the number of students and staff in the public school system. It is not clear whether this is due to a low number of breaches, or a low rate of detection.
The department’s register of suspected data breaches records:
- whether suspected data breaches involved students, parents, and/or staff members
- whether eligible data breaches were referred to the commission under the scheme
- the corrective actions taken to minimise harm and prevent future data breaches.
The department reports on suspected data breaches and eligible data breaches to its Audit and Risk Committee. It also publicly reports on its internal privacy reviews or those conducted by the NSW Civil and Administrative Tribunal where an application is made under the Privacy and Personal Information Protection Act 1998. While the department reported publicly on the number of suspected data breach notifications in 2023–24, it did not do so in 2024–25. The department does not report publicly on the number of eligible data breaches it has experienced.
Exhibit 7 summarises the 491 suspected data breach and 13 privacy matters the department dealt with from 2023 to 2025 that relate to student information. This appears low compared to the approximately 780,900 students, 86,500 teachers and 42,000 educational support staff in schools, and 9,000 corporate staff in the department in 2024–25 (by headcount).5
Data breaches
Privacy breaches
|
Note 1: The audit was unable to determine whether all 435 non-eligible data breaches involved students’ personal information.
Source: Audit Office analysis of information provided by the NSW Department of Education.
The department has experienced several data breaches involving student information that were due to human error, system failures or malicious or criminal attacks. Exhibit 8 provides some examples of data breaches involving student information which occurred during the audit review period.
Unauthorised access to information
Unauthorised disclosure of information
|
Source: Audit Office summary of information provided by the NSW Department of Education and media.
Staff misconduct matters may involve student information
The department has committed to identifying and taking action to mitigate risks to child safety in physical and online environments in its 2023–2026 Child Safe Action Plan, developed under the national Child Safe Standards. It reflects these commitments in its Code of Ethics and Conduct, which specifies that reporting security and data breaches – including the unauthorised access and disclosure of confidential information – are key responsibilities of staff.
The department’s Professional and Ethical Standards unit is responsible for assisting schools to manage staff conduct and performance, and for investigating and addressing allegations of staff misconduct.
Separate to its data breach register, the department records staff misconduct matters handled by the Professional and Ethical Standards unit. Its data on misconduct matters does not consistently record whether student information was an element of the alleged misconduct nor whether third-party digital products were involved.
Noting this limitation, a manual keyword search on the department’s staff misconduct matters data for the audit review period suggests that around 30 of 1,352 matters with sustained findings6 involved student information. These included:
- six (0.44%) related to the disclosure/misuse of confidential student information
- eight (0.59%) related to dishonest record keeping of student information
- one (0.07%) related to a failure to maintain records involving student information
- other allegations involving student information included crossing professional boundaries and unprofessional conduct towards a child (for example, a staff member accessing a student’s phone number to make personal contact outside of school hours).
The department advises that the Professional and Ethical Standards unit shares relevant information it has identified through investigations of alleged staff misconduct with other departmental areas as needed. This includes the Legal Services unit and the IT Directorate with respect to suspected data and privacy breaches.
These teams may also be involved in the misconduct investigation, to help identify how controls have been circumvented and how relevant processes, training and governance may be strengthened.
The Professional and Ethical Standards case management system will be enhanced in 2026 to formally record systemic issues and the actions taken to involve other business units, to feed into the department’s broader audit and governance processes.
Some student information breaches may go undetected due to the department’s reliance on reporting of data breaches by staff and other parties
While the department has automated systems to detect cyber incidents (see section 4.8), like many NSW Government agencies it primarily relies on reporting from staff or other parties to identify suspected data and privacy breaches. It does not conduct proactive data breach surveillance.
The department advises that its data breach training encourages the reporting of data breaches. This is consistent with advice from consulted schools that breaches are typically identified through staff reports or by parents and students.
While some consulted schools have not experienced a data breach involving student information, there are apparent misunderstandings of what constitutes a breach. For example, some of these schools do not view a misdirected email accidentally sent to another NSW public school as a data breach.
The department does not proactively conduct breach surveillance such as:
- periodic simulations to test its breach response plan
- regular school self-assessments
- monitoring access to student information held by third-party digital products
- compliance spot check reviews.
Its reliance on self-reporting means detection is affected by variation in schools’ awareness of what constitutes a breach and in the strength of their speak up cultures. This raises the risk that the department is not detecting all relevant data or privacy breaches.
While the department identifies lessons learnt from individual breaches, these are not used to systematically improve student information handling across schools
The department takes steps to capture lessons learnt from individual breaches at the school level but does not regularly generate systematic insights to improve practices at schools across the state.
The department’s incident response plans and incident report templates include requirements to identify lessons learnt from incidents and breaches. The department’s data breach register records actions to prevent similar future breaches, including updating policies and communications to staff.
The department advises that insights from data breaches are:
- reported to its Information Governance Group and relevant operational business areas, such as the NSW Public Schools Division
- used to target ad hoc training to schools in response to data breaches
- used to inform statewide legal advice provided by the department’s Legal Services unit to schools
- routinely fed into policy and capability projects across the department.
The department does not systematically use the information it collects on privacy breach and data breach incidents involving student information as insights or case studies to improve awareness and practice across all schools. Nor does it consistently use insights from other types of breaches, such as staff misconduct, cyber security incidents and breaches involving third-party digital products, to improve student information handling practices.
The department advises that it is exploring opportunities to expand its data loss prevention capabilities across school-based staff, focusing on the core enterprise platforms Google Workspace and Microsoft 365. This initiative aims to protect sensitive information, including student information, from malicious threats and accidental exposure, and to educate users on secure data handling practices. However, this initiative does not currently include data loss prevention involving third-party digital products that hold student information.
4.8. Detecting and addressing cyber incidents
The department has systems to detect cyber incidents involving student information
The department’s cyber security uplift program was established in 2020 to strengthen the governance, detection, response and protection of its digital systems and information. Since then, the program has expanded its focus from central corporate initiatives to school environments.
The NSW Cyber Security Policy defines a cyber incident as ‘an occurrence or activity that may threaten the confidentiality, integrity or availability of a system or the information stored, processed or communicated by it’.
The department detects cyber security incidents through 2 mechanisms:
- automated monitoring tools that identify and alert on suspicious or unusual activity across systems and devices
- manual processes, including reports from corporate staff, schools and third parties.
These strategies align with the Australian Signal Directorate Cyber Threat Report 2024–25 and its guidance for agencies to manage event logging, legacy technology and third-party cyber security risks.
During the audit review period, the department’s data indicates automated and manual processes identified 517 cyber security incidents affecting student information. This includes:
- attempted and successful access to student information
- compromised student credentials or accounts
- compromised school staff credentials or other accounts with access to student information.
The number of incidents increased each year, with an 89% increase between 2023 and 2024, and a further 161% increase between 2024 and 2025. The department attributes this to:
- the increase in systems and devices being actively monitored, including school systems and devices as well as department-managed systems and infrastructure
- tuning and improving the cyber security monitoring tools that automatically detect and alert security incidents
- establishing dedicated teams to support the identification, investigation and responses to security incidents.
Under the NSW Cyber Security Policy, the department is required to report cyber incidents and provide information on threats to Cyber Security NSW. In 2024, the department identified that inconsistent reporting of its cyber incidents to Cyber Security NSW was an issue. In 2025, the department attested that it met the requirement to report all cyber incidents to Cyber Security NSW.
The Auditor-General’s Cyber Insights 2025 report states that, based on audits of cyber security management within NSW Government agencies and others between 2018 and 2025, third-party cyber risk management is a challenge. These entities are accountable for managing cyber risks, including when outsourcing.
The department recognises that it needs to continue efforts to strengthen oversight and controls across school environments and third‑party digital products to consistently identify and manage cyber security risks to student information.
The department has processes to identify cyber-related data breaches
The department’s Cyber Incident Response Plan identifies that containing and assessing potential data breaches are crucial steps when responding to cyber incidents. Under the plan, if a cyber incident involving a data breach is confirmed and there are indicators of a serious loss of sensitive data, the department’s Data Breach Response Plan must be activated.
Cyber security incidents are broader than data breaches. Not all cyber incidents result in a data breach, as many are detected and contained before student information is accessed, disclosed or lost.
Conversely, some data breaches may occur without a cyber security incident, for example through human error or accidental disclosure.
While not always related, cyber security incidents can lead to data breaches if they are not addressed promptly and result in unauthorised access to, theft of, or disclosure of student information. Exhibit 9 outlines examples of data breaches caused by cyber incidents during the audit review period.
| Category | Summary |
| Unauthorised or inappropriate access to student information | A student accessed a school’s technical support officer account that had global access in an approved third-party school administration system. This gave the student access to the information of other students in the system. The department advises that it traced the account and documented the information accessed for data breach investigation and reporting. Data saved by the student using the account was deleted and there was no evidence it was sent outside the department. The school was advised to treat the granting of school application access with due care and to assign privileged roles strictly for operational need rather than convenience. The officer’s elevated access to the external school administration system was revoked. |
| Inappropriate collection of biometric data from students | A Microsoft Teams feature enabling the collection of student voice and facial biometric data was turned on without the department’s knowledge. The department advises that it identified the affected users and contained the breach. It investigated the origin of the feature enablement and generated a list of the users enrolled in it. The feature was disabled and the biometric profiles were deleted. It found there was no risk of the data leaving the department, nor of it being accessed or used by a third-party. The department advised it has since enhanced its oversight of upcoming features in its Microsoft platform, as Microsoft often enables these for all customers. The department determined that the events were not an eligible data breach under the NSW Mandatory Data Breach Notification Scheme. The data could not have been accessed by any human or machine technology other than the original users (staff and students) themselves and the Microsoft Teams recognition feature. |
Sources: Audit Office summary of information provided by the NSW Department of Education and media.
Of the 517 cyber security incidents recorded during the audit review period, 31 were assessed as meeting the department’s threshold for a data breach and were referred to its Legal Services unit.
Both the Australian Signals Directorate and Cyber Security NSW report that the tactics of cyber actors are evolving, with more advanced hacking tools such as AI. Although only 3% of data breach incidents reported by the department in 2024–25 resulted from a cyber incident, this suggests an ongoing risk that the department must monitor.
The department’s Cyber Incident Response Plan, aligned to its Data Breach Response Plan, relies on staff in its IT Directorate to assess if a cyber-related data breach has occurred, and involve the Legal Services unit if it is assessed as a data breach. The audit has not assessed the effectiveness of the department’s cyber security incident processes.
Appendices
Appendix 1 – Response from entity
Appendix 2 – Relevant governance groups
Appendix 3 – Key departmental policies
Appendix 5 – Performance auditing
© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.
Parliamentary reference - Report number #430 - released 29 June 2026