QA7 Privacy & Confidentiality Policy
Privacy is acknowledged as a fundamental human right. Our Service has an ethical and legal responsibility to protect the privacy and confidentiality of children, individuals and families as outlined in the Early Childhood Code of Ethics, Education and Care Services National Regulations and the Privacy Act 1988 (Cth). The right to privacy of all children, their families, and educators and staff of the Service will be upheld and respected, whilst ensuring that all children have access to high quality early years care and education. All staff members will maintain confidentiality of personal and sensitive information to foster positive trusting relationships with families.
National Quality Standards (NQS)
| QUALITY AREA 7: GOVERNANCE AND LEADERSHIP | ||
|---|---|---|
| 7.1 | Governance | Governance supports the operation of a quality service that is child safe. |
| 7.1.1 | Service philosophy and purposes | A statement of philosophy guides all aspects of the service’s operations. |
| 7.1.2 | Management Systems | Systems are in place to manage risk and enable the effective management and operation of a quality service that is child safe. |
| 7.1.3 | Roles and Responsibilities | Roles and responsibilities are clearly defined and understood and support effective decision-making and operation of the service. |
| 7.2 | Leadership | Effective leadership builds and promotes a positive organisational culture and professional learning community. |
| EDUCATION AND CARE SERVICES NATIONAL LAW AND NATIONAL REGULATIONS | |
|---|---|
| 168 | Education and care services must have policies and procedures |
| 170 | Policies and procedures to be followed |
| 171 | Policies and procedures to be kept available |
| 177 | Prescribed enrolment and other documents to be kept by approved provider |
| 181 | Confidentiality of records kept by approved provider |
| 183 | Storage of records and other documents |
| 184 | Storage of records after service approval transferred |
Related Legislation
| Child Care Subsidy Secretary’s Rules 2017 | Family Law Act 1975 |
| A New Tax System (Family Assistance) Act 1999 | Child Care Subsidy Minister’s Rules 2017 |
| Privacy Act 1988 (the Act) | Family Assistance Law – Child Care Provider Handbook (Appendix G) |
Related Policies
| CCS Account Policy | Interaction with Children, Family and Staff Policy |
| CCS Governance Policy | Orientation of Families Policy |
| Dealing with Complaints Policy | Payment of Fees Policy |
| Enrolment Policy | Photograph & Social Media Policy |
| Family Communication Policy | Record Keeping and Retention Policy |
| Governance Policy | Safe Use of Digital Technology & Online Environments Policy |
| Interactions with Children, Families and Staff Policy |
Purpose
To ensure that the confidentiality of information and files relating to the children and young people, families, staff, and visitors using the Service is upheld at all times. We aim to protect the privacy and confidentiality of all information and records about individual children and young people, families, educators, staff and management by ensuring continuous review and improvement on our current systems, storage, and methods of disposal of records. We will ensure that all records and information are held in a secure place and are only retrieved by or released to people who have a legal right to access this information. This policy provides procedures to ensure data is stored, used and accessed in accordance with relevant policies and procedures.
Our Service adopts and aligns with the National Model Code and guidelines for taking images or videos of children. (See Safe Use of Digital Technologies and Online Environments Policy.)
Scope
This policy applies to children and young people, families, educators, staff, management, approved provider, nominated supervisor, students and visitors of the Service.
Implementation
Under National Law, Section 263, Early Childhood Services are required to comply with Australian privacy law which includes the Privacy Act 1988 (the Act) aimed at protecting the privacy of individuals. Schedule 1 of the Privacy Act 1988 includes 13 Australian Privacy Principles (APPs) which all services are required to apply. The APPs set out the standards, rights and legal obligations in relation to collecting, handling, holding and accessing personal information.
The Notifiable Data Breaches (NDB) scheme requires Early Childhood Services to provide notice to the Office of the Australian Information Commissioner (formerly known as the Privacy Commissioner) and affected individuals of any data breaches that are ‘likely’ to result in ‘serious harm’. Businesses that suspect an eligible data breach may have occurred must undertake a reasonable and expeditious assessment to determine if the data breach is likely to result in serious harm to any individual affected. A breach of an Australian Privacy Principle is viewed as an ‘interference with the privacy of an individual’ and can lead to regulatory action and penalties.
Source: OAIC Australian Privacy Principles
The Approved Provider / Nominated Supervisor / Management Will:
- Ensure the Service acts in accordance with the requirements of the Australian Privacy Principles and Privacy Act 1988 by developing, reviewing, and implementing procedures and practices that identify:
- the name and contact details of the Service
- what information the Service collects and the source of information
- why the information is collected
- who will have access to information
- collection, storage, use, disclosure, and disposal of personal information collected by the Service
- any law that requires the particular information to be collected
- adequate and appropriate storage for personal information collected by the Service
- protection of personal information from unauthorised access
- Ensure educators, staff, students and volunteers have knowledge of and adhere to this policy
- Ensure families are aware of the privacy and confidentiality policy
- Provide staff and educators with relevant information regarding changes to Australian privacy law and Service policy
- Ensure all relevant staff understand the requirements under Australia’s privacy law and Notifiable Data Breaches (NDB) scheme
- Maintain currency with the Australian Privacy Principles (this may include delegating a staff member to oversee all privacy-related activities to ensure compliance)
- Ensure personal information is protected in accordance with our obligations under the Privacy Act 1988 and Privacy Amendments (Enhancing Privacy Protection) Act 2012 and only authorised personnel have access to private and sensitive information
- Ensure all records and documents are maintained and stored in accordance with Education and Care Service National Regulations
- Regularly back up personal and sensitive data from computers to protect personal information collected
- Ensure all computers are password protected and install security software – antivirus protection
- Ensure families are notified of the time particular records are required to be retained as per Education and Care Services National Regulations [Reg. 183(2)]
- Ensure all staff are aware of the ban on personal devices and the National Model Code and Guidelines for taking images or videos of children
- Ensure the appropriate and permitted taking, use, storage and sharing of images and videos of children, including obtaining written authorisation from parents and/or guardians (see Enrolment Form)
- Ensure personal electronic devices such as tablets, phones, digital cameras, smart watches, META sunglasses and personal storage and file transfer media (such as SD cards, USB drives, hard drives and cloud storage) are not in the possession of any person while providing education and care and working directly with children
- Smart watches with display screens, including but not limited to devices capable of messaging, calls, photography, or internet access, are prohibited within the service. Staff may only wear basic fitness trackers or watches without a screen, provided they do not have communication or recording functions
- Ensure personal electronic devices are not used to capture images and videos of children at any time
- Ensure only devices that are issued by and registered with the Service are used to record and store images and videos of children
- Ensure all employees, students, volunteers, and families have access to a copy of this policy
- Deal with privacy complaints promptly and in a consistent manner, following the Service’s Grievance Policy and procedures
- Ensure families only have access to the files and records of their own children (unless a court order prohibits access)
- Ensure information given to Educators will be treated with respect and in a professional and confidential manner
- Ensure only necessary information regarding children’s day-to-day health and wellbeing is given to non-primary contact educators (for example, food allergy information)
- Ensure individual child, young people and staff files are stored in a locked and secure cabinet
- Ensure information relating to staff employment will remain confidential and available only to the people directly involved with making personnel decisions
- Ensure that information shared with the Service by the family will be treated as confidential unless told otherwise
- Ensure information regarding the health and wellbeing of a child, young person or staff member is not shared with others unless consent has been provided in writing, or the disclosure is required or authorised by law under relevant state/territory legislation
Educators and Staff Will:
- Read and adhere to the Privacy and Confidentiality Policy at all times
- Not use, or have access to, any personal electronic devices (including mobile phones, smart watches, Meta glasses, laptops) while working directly with children. In accordance with the National ban on personal devices, they must be stored safely in the staff room in their personal locker at all times
- Not use personal electronic devices to take images or video of children at the Service, or breach children and families’ privacy
- Ensure documented information and photographs of children and young people are kept secure but may be accessed at any time by the child’s parents or guardian
- Ensure parents or guardians only have access to the files and records of their own children (unless a court order prohibits access)
- Treat private and confidential information with respect in a professional manner
- Not discuss individual children and young people with people other than the family of that child, except for the purposes of curriculum planning or group management. Communication in other settings must be approved by the family beforehand
- Ensure that information shared with the service by the family will be treated as confidential unless told otherwise
- Maintain individual and Service information and store documentation according to this policy at all times
- Not share information about the individual or service, management information, or other staff as per legislative authority
Families Will:
- Be aware of the Privacy and Confidentiality Policy upon enrolment
- Ensure all information provided to the Service is accurate and kept up to date
- Be informed that access to documentation and personal information is limited to their own child/ren
- Not use personal electronic devices, such as mobile phones, smart watches or META sunglasses, to take photos, record audio, or capture video of children being educated and cared for at the Service
- Not use personal electronic devices while moving through environments where children are present (e.g. drop off and pick up) to ensure all children are safeguarded
- If families need to use their personal devices while in the Centre, they must only be used in the reception area and put away when entering classrooms and/or outdoor environments
- Follow the Dealing with Complaints Policy regarding any complaints or concerns about privacy and confidentiality
- Share information relating to individual family court orders or parenting plans with the Service and update these as required
- Ensure they do not share data or personal information of other family members, children or staff members from the Service with anyone, including other families of the same Service
- Never duplicate or upload images/videos to the internet/social networking sites or share them with anyone other than family members
- Not take photos during Centre Events unless in a designated photo area created by the Centre. Centre events will be documented and shared via Service issued devices and communication platforms
- Respect that staff are prohibited from sharing information about other children, families or staff members without expressed written consent of the person to whom the information relates
Australian Privacy Principles – Personal Information
Eden Academy is committed to protecting personal information in accordance with our obligations under the Privacy Act 1988 and Privacy Amendments (Enhancing Privacy Protection) Act 2012.
Personal information includes a broad range of information, or an opinion, that could identify an individual. Sensitive information is personal information that includes information or an opinion about a range of personal matters that has a higher level of privacy protection than other personal information.
Source: OAIC – Australian Privacy Laws, Privacy Act 1988
Personal information will be collected and held securely and confidentially about you and your child to assist our Service provide quality education and care to your child whilst promoting and maintaining a child safe environment for all stakeholders.
Method of Collection
- Information is generally collected using standard forms at the time of enrolment or employment
- Additional information may be provided to the Service through email, surveys, telephone calls or other written communication
- Information may be collected online through the use of software such as CCS software or program software
How We Protect Your Personal Information
To protect your personal and sensitive information, we maintain physical, technical and administrative safeguards as follows:
- All hard copies of information are stored in children’s individual files or staff individual files in a locked cupboard
- All computers used to store personal information are password protected. Each staff member will be provided with a unique username and password for access to CCS software and program software. Staff will be advised not to share usernames and passwords
- Access to personal and sensitive information is restricted to key personnel only
- Security software is installed on all computers and updated automatically when patches are released
- Data is regularly backed up on external drive and/or through a cloud storage solution
- Any notifiable breach to data is reported
- All staff are aware of the importance of confidentiality and maintaining the privacy and security of all information
- Procedures are in place to ensure information is communicated to intended recipients only (e.g. invoices and payment enquiries)
Access to Personal and Sensitive Information
Personal and sensitive information about staff, families and children will be stored securely at all times. Families who have access to enrolment or program information online will be provided with a unique username and password. Families will be advised not to share usernames, passwords or photos shared within apps.
The approved provider will ensure that information kept in a child’s record is not divulged or communicated through direct or indirect means to another person other than:
- To the extent necessary for the education and care or medical treatment of the child to whom the information relates
- A parent of the child to whom the information relates, except in the case of information kept in a staff record
- The regulatory authority or an authorised officer
- As expressly authorised, permitted or required to be given by or under any Act or law [See: Child Information Sharing Scheme (CISS); Family Violence Information Sharing Scheme (FVISS) Victoria]
- With the written consent of the person who provided the information (written consent may be withdrawn at any time)
Education and Care National Regulations (Reg. 177) specifically state personal information relating to the individuals listed below must not be disclosed or shared with a parent of a child enrolled at the Service without prior written consent of the person to whom the personal or sensitive information relates:
- A parent of a child
- A person who is an emergency contact
- A person who is an authorised nominee
- A person who is authorised to consent to medical treatment
- A person who is authorised to authorise an educator to take a child outside the Service
- A person who is authorised to authorise transport
Individuals may withdraw their consent in writing prior to personal information being disclosed.
Disclosing Personal and Sensitive Information
Our Service will only disclose personal or sensitive information to:
- A third-party provider with parent permission (for example CCS software provider)
- Child Protection Agency – Office of the Children’s Guardian and Regulatory Authority as per our Child Protection and Child Safe Environment Policies
- As part of the purchase of our business asset with parental permission
- Authorised officers (for example public health officer)
- The regulatory authority or an authorised officer
- As expressly authorised, permitted or required to be given by or under any Act or Law [Child Information Sharing Scheme; Family Violence Information Sharing Scheme VIC]
- With the written consent of the person who provided the information (written consent may be withdrawn at any time)
If the Service is transferred to a new approved provider, any records and documents will be transferred to the new approved provider following written consent from parents/guardians regarding the transfer and sharing of records and documents.
Confidentiality During Recruitment and Interviews
The Service is committed to maintaining confidentiality and privacy throughout all recruitment and interview processes. All information obtained during recruitment activities, including applications, resumes, referee reports, interview notes, assessment outcomes and verbal discussions, is treated as confidential and handled in accordance with applicable privacy legislation and this Policy.
Confidential interview information will:
- Only be accessed by authorised personnel directly involved in the recruitment and selection process
- Be used solely for the purpose of assessing suitability for employment, placement or engagement
- Not be discussed outside the recruitment panel or shared with unauthorised persons
Interview discussions and outcomes must not be disclosed to other staff members, families, children, or external parties, except where required by law or with the consent of the applicant. All records relating to recruitment and interviews are stored securely and retained or disposed of in line with legislative requirements and the Service’s record-keeping procedures. Employees involved in recruitment and interviewing are expected to uphold professional standards of confidentiality at all times. Any breach of confidentiality during the recruitment process may result in disciplinary action.
Complaints and Grievances
If a parent, employee, or volunteer has a complaint or concern about our Service, or they believe there has been a data breach of the Australian Privacy Principles, they are requested to contact the Approved Provider so reasonable steps to investigate the complaint can be made and a response provided.
If there are further concerns about how the matter has been handled, please contact the Office of Australian Information Commissioner on 1300 363 992 or visit: https://forms.business.gov.au/smartforms/landing.htm?formCode=APC_PC
Continuous Improvement / Reflection
Our Privacy and Confidentiality Policy will be updated and reviewed annually or earlier if there are changes to legislation, ACECQA guidance or any incident related to our policy. Feedback will be requested from children, families, staff, educators and management and notification of any change to policies will be made to families within 14 days.
Sources
- Australian Children’s Education & Care Quality Authority. (2025). Guide to the National Quality Framework
- Australian Children’s Education & Care Quality Authority. (2024). National Model Code for Early Childhood Education and Care
- Australian Government Department of Education. Child Care Provider Handbook (2024)
- Australian Government Office of the Australian Information Commission – Australian Privacy Principles
- Early Childhood Australia Code of Ethics. (2016).
- Education and Care Services National Law Act 2010 (Amended 2023).
- Education and Care Services National Regulations (Amended 2023).
- Privacy Act 1988.
- UN General Assembly (1989). United Nations Convention on the Rights of the Child.
- Victorian Government. Child Information Sharing Scheme
Policy Review
| Policy Reviewed By | Bek Steinweiss, Operations Administrator — 23/12/2025 |
| Policy Reviewed | December 2025 |
| Next Review Date | April 2026 |
| Modifications | Section added in relation to confidentiality and recruitment |
| Previous Modifications |
|