RollCall
Back to News
Knowledge1 September 2026

Who's Looking After Your Students' Data?

R
RollCall Team
RollCall Team
Who's Looking After Your Students' Data?

Australia's first Children's Online Privacy Code arrives in December. Here's what it is, in plain English.

Have a quick count of the online services that hold information about the children at your school.

The learning management system. The student management system. The library catalogue. The canteen ordering app. The photo-sharing tool the sports department set up. The reading app in the junior school. The wellbeing check-in platform. The permission-slip service. The bus tracking app sitting in a few thousand parents' pockets.

Most schools, when they actually write the list down, are surprised by how long it is.

That list is the reason the Children's Online Privacy Code exists.

So what is it?

The Office of the Australian Information Commissioner - the OAIC - has been asked by Parliament to write a set of rules for online services that children use. It came out of amendments to the Privacy Act passed in December 2024, and it must be finalised and registered by 10 December 2026.

The idea behind it is straightforward, and hard to argue with: services that children use should handle children's information in children's interests.

That principle - the OAIC calls it the best interests of the child - sits at the centre of the whole thing. Everything else follows from it.

The draft went out for public consultation between March and June this year. More than 300 children and parents filled in worksheets, and the OAIC received 135 written submissions on the draft alone. It is now working through those responses before the December deadline.

Everything described below comes from the exposure draft. The Code is not yet finalised, and the detail may change.

Does it apply to schools?

Mostly, no - and this is the part worth being clear about.

The Code is aimed at online services: social media, messaging apps and games with chat, and a broad category covering things like cloud storage, streaming and connected devices, where those services are likely to be used by children. Health service providers are carved out.

Schools themselves are not the target. Whether particular school-facing platforms are captured - a student management system, say, or an educational app with a chat function - is one of the questions the OAIC has been working through, and the sector has been asking for clarity on it.

But here is the practical point. Even where the Code doesn't land on your school, it lands on the companies your school buys from. Their defaults, their consent forms and their privacy notices will change. Some of that change will arrive on your desk as a form to re-sign or a setting to re-check.

Knowing what is coming makes that a much easier conversation.

What the draft actually asks for

Stripped of the legal language, the exposure draft asks online services to do a handful of sensible things.

  • Collect less by default. A service should collect only what is strictly necessary to do its job. Anything beyond that needs to be something the user opts into.
  • Explain things in language a child can follow. Privacy policies written for children, not for lawyers.
  • Stop the nudging. No repeatedly re-asking until someone gives in, no bundling several consents into one tick box, no design tricks that push a child toward sharing more.
  • Get consent from the right person. The draft proposes 15 as the age at which a young person can consent for themselves. Below that, a parent or guardian consents - with sensible exceptions for a child seeking health or legal support. This age is a draft proposal, not settled law.
  • Tell children when a parent has consented for them. Not to undermine the parent, but so the child understands what has been agreed on their behalf.
  • Let children ask for their information to be deleted. And answer within a set timeframe.
  • Take reasonable steps to know how old users are. And destroy anything collected purely to check age, rather than keeping it.

The one that will interest transport teams

There is a provision in the draft about location.

It proposes that a service should tell a child when someone is tracking their geolocation - including when that someone is their parent.

Children should be told when they're being located.

Read that again, because it is genuinely novel. The draft treats a child as a person with an interest in knowing where their whereabouts are going, even inside their own family.

For anyone running school transport, that is worth sitting with. Bus tracking exists for good reasons - safety, reassurance, and the simple question of whether the bus is late. Nobody is suggesting otherwise. But the Code invites a question schools have rarely been asked before.

Do the students on your buses understand who can see where they are?

For a Prep student, the answer is reasonably obvious and the parent's judgement carries it. For a seventeen-year-old, it is a different conversation - and one that most schools have never explicitly had.

This provision is still in draft, and the final wording may well shift. But the direction of travel is clear enough to be worth thinking about now.

What's still unsettled

A few things genuinely aren't decided yet, and it's fair to say so.

  • The exact boundaries of which services are captured.
  • How school-mediated consent works when a teacher, not a parent, is the one choosing the tool.
  • When the Code actually commences after it is registered. The 10 December deadline is the date the Code must be registered by - not the date obligations start.

The OAIC has been unusually open about this process - the consultation reports are public, and the draft was published for anyone to read. If you want the primary source rather than someone's summary of it, it is all on the OAIC website.

Six things worth doing before December

None of this is urgent in the way a security incident is urgent. But the schools that find this easiest in December will be the ones that did a little groundwork in Term 4.

  • Write the list. Every online service that holds information about your students. Include the ones a single department signed up for without telling anyone. Especially those.
  • For each one, ask what it collects and why. If a supplier can't answer that clearly and quickly, that is itself an answer.
  • Look at the defaults. What is switched on when a new student account is created? Would you switch it on deliberately if asked?
  • Check who can see location data - in every tool that has it, not just transport. Ask how far back it is kept.
  • Re-read your collection notices and consent forms with fresh eyes. Would a parent understand what they agreed to? Would a Year 10 student?
  • Decide who owns this. In most schools, no single person is responsible for the whole list. Someone should be.

That's a Term 4 afternoon's work, and it makes you better informed than most.

Where RollCall sits

We've been following the Code's development closely, for the obvious reason that we build software used by children and their families every day.

We'll keep working through what the final Code means for the Parent App, for location data and for the information we hold on your behalf - and we'll tell you plainly if anything needs to change on your side. If we need something from you, you'll hear it from us before you hear it anywhere else.

In the meantime, if you have questions about what RollCall stores, who can see it, or how long we keep it, ask us. We'd rather have that conversation than have you guess. You can also read how we handle school data on our trust and security page.

Read it yourself

The Children's Online Privacy Code, the exposure draft and the consultation reports are all published on the OAIC website.

Want to Learn More?

Get a quote to see how RollCall can transform your school transport.