
What Should We Actually Be Doing Every Day?
It comes up at almost every school visit. The answer is simpler than most people expect: three checks on every service, AM and PM, and fifteen to thirty minutes each morning to work through them.

Australia's first Children's Online Privacy Code arrives in December. Here's what it is, in plain English.
Have a quick count of the online services that hold information about the children at your school.
The learning management system. The student management system. The library catalogue. The canteen ordering app. The photo-sharing tool the sports department set up. The reading app in the junior school. The wellbeing check-in platform. The permission-slip service. The bus tracking app sitting in a few thousand parents' pockets.
Most schools, when they actually write the list down, are surprised by how long it is.
That list is the reason the Children's Online Privacy Code exists.
The Office of the Australian Information Commissioner - the OAIC - has been asked by Parliament to write a set of rules for online services that children use. It came out of amendments to the Privacy Act passed in December 2024, and it must be finalised and registered by 10 December 2026.
The idea behind it is straightforward, and hard to argue with: services that children use should handle children's information in children's interests.
That principle - the OAIC calls it the best interests of the child - sits at the centre of the whole thing. Everything else follows from it.
The draft went out for public consultation between March and June this year. More than 300 children and parents filled in worksheets, and the OAIC received 135 written submissions on the draft alone. It is now working through those responses before the December deadline.
Everything described below comes from the exposure draft. The Code is not yet finalised, and the detail may change.
Mostly, no - and this is the part worth being clear about.
The Code is aimed at online services: social media, messaging apps and games with chat, and a broad category covering things like cloud storage, streaming and connected devices, where those services are likely to be used by children. Health service providers are carved out.
Schools themselves are not the target. Whether particular school-facing platforms are captured - a student management system, say, or an educational app with a chat function - is one of the questions the OAIC has been working through, and the sector has been asking for clarity on it.
But here is the practical point. Even where the Code doesn't land on your school, it lands on the companies your school buys from. Their defaults, their consent forms and their privacy notices will change. Some of that change will arrive on your desk as a form to re-sign or a setting to re-check.
Knowing what is coming makes that a much easier conversation.
Stripped of the legal language, the exposure draft asks online services to do a handful of sensible things.
There is a provision in the draft about location.
It proposes that a service should tell a child when someone is tracking their geolocation - including when that someone is their parent.
Children should be told when they're being located.
Read that again, because it is genuinely novel. The draft treats a child as a person with an interest in knowing where their whereabouts are going, even inside their own family.
For anyone running school transport, that is worth sitting with. Bus tracking exists for good reasons - safety, reassurance, and the simple question of whether the bus is late. Nobody is suggesting otherwise. But the Code invites a question schools have rarely been asked before.
Do the students on your buses understand who can see where they are?
For a Prep student, the answer is reasonably obvious and the parent's judgement carries it. For a seventeen-year-old, it is a different conversation - and one that most schools have never explicitly had.
This provision is still in draft, and the final wording may well shift. But the direction of travel is clear enough to be worth thinking about now.
A few things genuinely aren't decided yet, and it's fair to say so.
The OAIC has been unusually open about this process - the consultation reports are public, and the draft was published for anyone to read. If you want the primary source rather than someone's summary of it, it is all on the OAIC website.
None of this is urgent in the way a security incident is urgent. But the schools that find this easiest in December will be the ones that did a little groundwork in Term 4.
That's a Term 4 afternoon's work, and it makes you better informed than most.
We've been following the Code's development closely, for the obvious reason that we build software used by children and their families every day.
We'll keep working through what the final Code means for the Parent App, for location data and for the information we hold on your behalf - and we'll tell you plainly if anything needs to change on your side. If we need something from you, you'll hear it from us before you hear it anywhere else.
In the meantime, if you have questions about what RollCall stores, who can see it, or how long we keep it, ask us. We'd rather have that conversation than have you guess. You can also read how we handle school data on our trust and security page.
The Children's Online Privacy Code, the exposure draft and the consultation reports are all published on the OAIC website.

It comes up at almost every school visit. The answer is simpler than most people expect: three checks on every service, AM and PM, and fifteen to thirty minutes each morning to work through them.

The new Manage Parent Access feature gives schools greater control over who can access the RollCall Parent App - here is what the parent statuses mean and why the Enable step exists.

Long transit times significantly impact young people's wellbeing and energy levels. RollCall data shows the average student transit time and why measurement matters.