NERPSA Learning | Staff Learning and Practice Framework

Privacy, Confidentiality and Safe Use of Digital Technologies

Protecting children, families, staff and NERPSA through careful information handling, secure systems and child safe digital practice.

Who should complete this

All NERPSA staff, educators, teachers, volunteers and leaders

What it covers

Privacy, confidentiality, records, devices, images and breaches

Completion evidence

Decisions, reflections, assessment and certificate

Estimated time

Approximately 90 to 105 minutes

Purpose

Early childhood work involves sensitive information about children, families, staff and communities. This lesson explains what staff may collect, access, record, use, share, photograph, store and discuss, how digital technologies must be used safely, and what to do immediately when information or a device may have been lost, exposed or misused.

Use current information

This course supports NERPSA policies and procedures. It does not replace them. Use current policies and authorised systems available through Staff Resources. Technology, law and organisational systems change. Do not rely on an old form, saved link, personal account or previous workplace practice.

By the end of this lesson, you should be able to

Recognise personal, sensitive and confidential information.

Apply need to know access and data minimisation.

Record and communicate information professionally.

Use authorised NERPSA systems securely.

Follow current personal and service device requirements.

Handle children’s images and videos safely.

Share information lawfully for child safety.

Respond quickly to suspected privacy or security breaches.

Standards and professional responsibilities

Requirement or frameworkConnection to practice
NERPSA policies and authorised systemsSet the approved processes for privacy, confidentiality, digital technologies, records, images, communication, child safety, complaints and incident escalation.
National Law and RegulationsRequire confidential handling and secure storage of prescribed records and, since September 2025, policies and procedures for safe digital technologies and online environments. Device restrictions commenced on 27 February 2026.
Australian Privacy Principles and applicable privacy lawSupport lawful and transparent collection, limited use and disclosure, data quality, security, access and correction, retention and secure destruction.
NQS Quality Areas 2 and 7Require child safe practice, effective governance, risk management, records and systems that support safe and quality service operation.
Victorian Child Safe StandardsRequire child safety to be embedded in governance and online and physical environments, with suitable policies, information handling and continuous improvement.

Privacy and child safety work together. Protect information from unnecessary access or disclosure, but never use confidentiality to prevent a required report, lawful information sharing, emergency response or action needed to protect a child.

01
Module one

Privacy, confidentiality and professional boundaries

Privacy concerns how personal information is collected, held, used, disclosed, accessed, corrected and destroyed. Confidentiality is the duty to protect information received through a professional role from unauthorised access or disclosure.

Information in early childhood settings may include

  • names, addresses, dates of birth, contact and enrolment information
  • health, disability, cultural, religious, family violence and child protection information
  • photographs, video, audio, voice recordings and online identifiers
  • observations, assessments, learning records and family communications
  • complaints, allegations, investigations and incident records
  • staff employment, qualification, screening, performance and medical information
  • opinions about an identifiable person, whether or not the opinion is accurate

Sensitive information receives greater protection. Children cannot be expected to manage risks created by adults. Staff must use information only for legitimate work purposes and within their authorised role.

Professional confidentiality

Share the minimum necessary information with an authorised person through the approved process.

Not professional

Discuss a child, complaint or colleague with friends, in public, in a group chat or with staff who are curious but do not need the information.

Confidentiality continues after a child leaves the service and after a staff member’s employment, placement or volunteer role ends.

02
Module two

The information lifecycle

Privacy is not one decision at the end of a process. It applies across the whole information lifecycle.

  1. Plan: identify the lawful purpose, the minimum information needed and the authorised system.
  2. Collect: collect fairly and lawfully, usually from the person concerned where appropriate, and provide the required privacy information.
  3. Use: use information for the purpose for which it was collected or another lawful, authorised purpose.
  4. Share: confirm the recipient, authority, purpose and minimum necessary content before disclosure.
  5. Store: protect paper and digital information with approved access, physical security, passwords and system controls.
  6. Maintain: keep information accurate, complete, current and relevant.
  7. Retain or destroy: follow legal and NERPSA retention requirements and authorised secure destruction processes.

Do not collect information “just in case,” copy records into personal notes, keep duplicate files indefinitely or move information to a convenient personal account. More copies create more access points and greater risk.

A family gives you updated medical information at the gate. What should you do?

Listen discreetly, identify whether immediate health action is needed, and ensure the information is recorded and communicated through the authorised process to the responsible people. Do not leave the only record in a personal notebook, casual message or memory.

03
Module three

Professional records and children’s dignity

A record may later be read by a family, manager, regulator, investigator, court or the person it concerns. Write as though the record may need to explain what occurred without your memory or additional commentary.

Professional records are

  • factual, specific, dated and attributable to the author
  • clear about what was directly observed, what was reported and by whom
  • free from labels, ridicule, gossip and unnecessary judgement
  • limited to information relevant to the record’s purpose
  • completed promptly in the approved form or system
  • corrected transparently without deleting or disguising the original record

Inappropriate

“Mum was difficult again and clearly does not care about the routine.”

Factual

“At 8.45 am the parent stated, ‘I cannot stay to discuss this.’ I provided the written reminder and advised that the teacher could arrange a private time to speak.”

Curriculum documentation must also protect dignity. A photograph, learning story or behaviour record should not embarrass, stereotype or expose a child. Ask whether the record is necessary, respectful and appropriate for its intended audience.

Never place child safety disclosures, medical details, complaint evidence or other confidential material in a public display, group portfolio, open sign in area or family communication platform visible to unauthorised people.

04
Module four

Secure communication and access

Access is based on role and purpose, not familiarity, seniority or curiosity. Before sending, speaking or showing a record, confirm who needs it, why they need it, what authority applies and how it should be transferred.

Everyday safeguards

  • use only approved NERPSA accounts, forms, platforms and storage locations
  • use a unique account and strong passphrase; never share credentials
  • lock screens and secure paper records whenever unattended
  • check recipients, attachments, names and permissions before sending
  • use blind copy only where the approved communication process requires it
  • avoid identifiable discussions in entrances, car parks, cafés, social media and public transport
  • do not photograph a screen or forward information to make work more convenient
  • report incorrect access, unexpected sharing permissions or suspicious messages immediately
A colleague asks to use your login because their access is not working.

Do not share your login or allow work to be completed under your identity. Use the authorised support or escalation process. Shared credentials remove accountability and can expose information beyond the colleague’s approved access.

Family and community enquiries must be answered within your role. Confirm identity where needed. Do not reveal enrolment, attendance, family circumstances, staffing matters or incidents merely because a caller knows a child’s name.

05
Module five

Personal devices, service devices and online safety

From 27 February 2026, the National Law and Regulations restrict personal digital devices and how images of children are captured, stored and transmitted.

Centre based service rule

A personal device is one not owned or supplied by the Approved Provider that can capture, store or transmit images, including a phone, camera, tablet, smart watch or hard drive. Staff, volunteers and students generally must not use or have a personal device in their possession while working directly with children. Limited legal exceptions and written authorisations may apply. Staff must not create their own exception.

Working directly with children means being physically present with a child or children while providing education and care. A short break away from children is treated differently under the national guidance, but NERPSA’s current local procedure and storage arrangements must still be followed.

Service supplied devices

Only service supplied devices used exclusively for education and care may be used to capture, store or transmit images of children. Use them only for authorised purposes, keep them secured, follow access and upload processes and report loss, damage or unusual activity immediately.

Children’s use of technology

  • select age appropriate, purposeful and child safe content
  • supervise actively rather than using a device as a substitute for engagement
  • use privacy protective settings and approved accounts
  • avoid advertising, tracking, chat, open sharing and unnecessary data collection
  • teach children about consent, help seeking, respectful use and safe boundaries
  • respond to concerning content, contact or behaviour through child safety procedures

“It was only for the program,” “I deleted it later” or “my phone has a passcode” does not make capturing a child’s image on a personal device acceptable.

06
Module six

Images, videos, authorisation and children’s rights

Since 1 September 2025, required service policies and procedures for digital technologies and online environments must address taking, using, storing and destroying children’s images and videos; parent authorisation; optical surveillance such as CCTV; service issued devices; and children’s use of digital devices.

Before capturing or using an image

  • confirm there is a legitimate educational or operational purpose
  • use an approved service supplied device and authorised platform
  • check the current parent authorisation and any limits on use
  • consider the child’s views, assent, dignity, culture and safety
  • check the background for other children, names, attendance lists or sensitive information
  • capture only what is necessary and avoid private, vulnerable or undignified situations
  • store, share, retain and destroy the image only through approved processes

Parent authorisation does not require an educator to take or publish an image, and it does not override child safety or dignity. A child’s refusal, distress or withdrawal should be respected. Children should understand, in a way appropriate to their age and communication, what is happening and who may see the image.

Purposeful documentation

A small number of images supports a clear learning record, uses current permissions and is stored in the approved system.

Unnecessary exposure

Large numbers of images are taken routinely, kept on devices, duplicated across platforms or used because they are attractive rather than necessary.

Never post or comment about NERPSA children, families, incidents or workplace information on personal social media. Privacy settings, closed groups, disappearing messages and deleted posts do not remove the risk.

07
Module seven

Information sharing, breaches and immediate response

Privacy rules permit or require information sharing in particular circumstances, including where authorised by law. Child protection reporting, emergency response, the Child Information Sharing Scheme, Family Violence Information Sharing Scheme, regulator notifications and lawful investigation processes may apply. Follow the specific current procedure and share only through authorised channels.

Protect privacy

Limit access, verify authority, record the reason and share the minimum information needed.

Do not obstruct safety

Do not refuse or delay a required report because the information is “confidential” or because a family has not consented.

Possible breaches include

  • an email or attachment sent to the wrong recipient
  • a lost device, USB, file, notebook or printed record
  • unauthorised access, shared passwords or an account left open
  • a child’s image captured, stored or shared outside approved systems
  • malware, phishing, suspicious login or unexpected system activity
  • records discussed where unauthorised people can hear
  • information retained, copied or destroyed contrary to requirements

If a breach or near miss occurs

  1. take safe immediate steps to contain it without deleting evidence
  2. notify the responsible person and the designated NERPSA contact immediately
  3. follow child safety, incident, privacy and technology escalation requirements
  4. record facts: what happened, information involved, people affected, time, systems and containment
  5. do not contact recipients, families, media or external authorities unless authorised or personally required by law
  6. cooperate with assessment, notification, recovery and prevention actions

Report near misses too. Early reporting can reduce harm. Hiding an error, quietly deleting a message or waiting to see whether anyone notices increases risk and prevents an effective response.

Practice decisions

Select the strongest professional response. All three must be correct.

You realise an email containing a child’s medical plan was sent to the wrong family.

You want one photograph for a learning record while working directly with children.

A child safety report requires relevant information to be provided through an authorised process.

Complete all three decisions.

Required learning activity

Apply the learning to your service

Drafts stay in this browser on this device.

Knowledge check

Answer all questions. At least seven out of eight is required.

1. What is the strongest basis for accessing personal information?
2. What is the centre based personal device rule from 27 February 2026?
3. Which device should capture a child’s image for an authorised service purpose?
4. What should a professional record contain?
5. Does confidentiality prevent a required child safety report?
6. What should you do after sending confidential information to the wrong person?
7. What does parent authorisation for images mean?
8. What is appropriate when a colleague asks to use your login?

Policies and official resources

NQF child safety changes

Open the commencement information

Digital technology policies

Open the policy requirements

Australian Privacy Principles

Open OAIC guidance

Protecting personal information

Open OAIC practical guidance

Completion requirements

  • Read every module and scenario.
  • Complete all three practice decisions correctly.
  • Complete four written responses of at least 20 characters.
  • Achieve at least seven out of eight.
  • Complete the participant declaration.
  • Submit the complete PDF through the NERPSA Document Submission Form.

Generate your completion record

Complete all requirements to unlock your record.

Choose Save as PDF, then submit the complete file through the NERPSA Document Submission Form in the NERPSA Connect App or Staff Resources website.

This is the only acknowledgement required. Please do not email the certificate or responses separately.

Protect information and protect children

Use only what you need, keep it secure, follow approved systems, report mistakes early and share lawfully when safety requires action.