NERPSA Learning | Staff Learning and Practice Framework
Privacy, Confidentiality and Safe Use of Digital Technologies
Protecting children, families, staff and NERPSA through careful information handling, secure systems and child safe digital practice.
All NERPSA staff, educators, teachers, volunteers and leaders
Privacy, confidentiality, records, devices, images and breaches
Decisions, reflections, assessment and certificate
Approximately 90 to 105 minutes
Purpose
Early childhood work involves sensitive information about children, families, staff and communities. This lesson explains what staff may collect, access, record, use, share, photograph, store and discuss, how digital technologies must be used safely, and what to do immediately when information or a device may have been lost, exposed or misused.
Use current information
This course supports NERPSA policies and procedures. It does not replace them. Use current policies and authorised systems available through Staff Resources. Technology, law and organisational systems change. Do not rely on an old form, saved link, personal account or previous workplace practice.
By the end of this lesson, you should be able to
Recognise personal, sensitive and confidential information.
Apply need to know access and data minimisation.
Record and communicate information professionally.
Use authorised NERPSA systems securely.
Follow current personal and service device requirements.
Handle children’s images and videos safely.
Share information lawfully for child safety.
Respond quickly to suspected privacy or security breaches.
Standards and professional responsibilities
| Requirement or framework | Connection to practice |
|---|---|
| NERPSA policies and authorised systems | Set the approved processes for privacy, confidentiality, digital technologies, records, images, communication, child safety, complaints and incident escalation. |
| National Law and Regulations | Require confidential handling and secure storage of prescribed records and, since September 2025, policies and procedures for safe digital technologies and online environments. Device restrictions commenced on 27 February 2026. |
| Australian Privacy Principles and applicable privacy law | Support lawful and transparent collection, limited use and disclosure, data quality, security, access and correction, retention and secure destruction. |
| NQS Quality Areas 2 and 7 | Require child safe practice, effective governance, risk management, records and systems that support safe and quality service operation. |
| Victorian Child Safe Standards | Require child safety to be embedded in governance and online and physical environments, with suitable policies, information handling and continuous improvement. |
Privacy, confidentiality and professional boundaries
Privacy concerns how personal information is collected, held, used, disclosed, accessed, corrected and destroyed. Confidentiality is the duty to protect information received through a professional role from unauthorised access or disclosure.
Information in early childhood settings may include
- names, addresses, dates of birth, contact and enrolment information
- health, disability, cultural, religious, family violence and child protection information
- photographs, video, audio, voice recordings and online identifiers
- observations, assessments, learning records and family communications
- complaints, allegations, investigations and incident records
- staff employment, qualification, screening, performance and medical information
- opinions about an identifiable person, whether or not the opinion is accurate
Sensitive information receives greater protection. Children cannot be expected to manage risks created by adults. Staff must use information only for legitimate work purposes and within their authorised role.
Professional confidentiality
Share the minimum necessary information with an authorised person through the approved process.
Not professional
Discuss a child, complaint or colleague with friends, in public, in a group chat or with staff who are curious but do not need the information.
The information lifecycle
Privacy is not one decision at the end of a process. It applies across the whole information lifecycle.
- Plan: identify the lawful purpose, the minimum information needed and the authorised system.
- Collect: collect fairly and lawfully, usually from the person concerned where appropriate, and provide the required privacy information.
- Use: use information for the purpose for which it was collected or another lawful, authorised purpose.
- Share: confirm the recipient, authority, purpose and minimum necessary content before disclosure.
- Store: protect paper and digital information with approved access, physical security, passwords and system controls.
- Maintain: keep information accurate, complete, current and relevant.
- Retain or destroy: follow legal and NERPSA retention requirements and authorised secure destruction processes.
Do not collect information “just in case,” copy records into personal notes, keep duplicate files indefinitely or move information to a convenient personal account. More copies create more access points and greater risk.
A family gives you updated medical information at the gate. What should you do?
Listen discreetly, identify whether immediate health action is needed, and ensure the information is recorded and communicated through the authorised process to the responsible people. Do not leave the only record in a personal notebook, casual message or memory.
Professional records and children’s dignity
A record may later be read by a family, manager, regulator, investigator, court or the person it concerns. Write as though the record may need to explain what occurred without your memory or additional commentary.
Professional records are
- factual, specific, dated and attributable to the author
- clear about what was directly observed, what was reported and by whom
- free from labels, ridicule, gossip and unnecessary judgement
- limited to information relevant to the record’s purpose
- completed promptly in the approved form or system
- corrected transparently without deleting or disguising the original record
Inappropriate
“Mum was difficult again and clearly does not care about the routine.”
Factual
“At 8.45 am the parent stated, ‘I cannot stay to discuss this.’ I provided the written reminder and advised that the teacher could arrange a private time to speak.”
Curriculum documentation must also protect dignity. A photograph, learning story or behaviour record should not embarrass, stereotype or expose a child. Ask whether the record is necessary, respectful and appropriate for its intended audience.
Secure communication and access
Access is based on role and purpose, not familiarity, seniority or curiosity. Before sending, speaking or showing a record, confirm who needs it, why they need it, what authority applies and how it should be transferred.
Everyday safeguards
- use only approved NERPSA accounts, forms, platforms and storage locations
- use a unique account and strong passphrase; never share credentials
- lock screens and secure paper records whenever unattended
- check recipients, attachments, names and permissions before sending
- use blind copy only where the approved communication process requires it
- avoid identifiable discussions in entrances, car parks, cafés, social media and public transport
- do not photograph a screen or forward information to make work more convenient
- report incorrect access, unexpected sharing permissions or suspicious messages immediately
A colleague asks to use your login because their access is not working.
Do not share your login or allow work to be completed under your identity. Use the authorised support or escalation process. Shared credentials remove accountability and can expose information beyond the colleague’s approved access.
Family and community enquiries must be answered within your role. Confirm identity where needed. Do not reveal enrolment, attendance, family circumstances, staffing matters or incidents merely because a caller knows a child’s name.
Personal devices, service devices and online safety
From 27 February 2026, the National Law and Regulations restrict personal digital devices and how images of children are captured, stored and transmitted.
Centre based service rule
A personal device is one not owned or supplied by the Approved Provider that can capture, store or transmit images, including a phone, camera, tablet, smart watch or hard drive. Staff, volunteers and students generally must not use or have a personal device in their possession while working directly with children. Limited legal exceptions and written authorisations may apply. Staff must not create their own exception.
Working directly with children means being physically present with a child or children while providing education and care. A short break away from children is treated differently under the national guidance, but NERPSA’s current local procedure and storage arrangements must still be followed.
Service supplied devices
Only service supplied devices used exclusively for education and care may be used to capture, store or transmit images of children. Use them only for authorised purposes, keep them secured, follow access and upload processes and report loss, damage or unusual activity immediately.
Children’s use of technology
- select age appropriate, purposeful and child safe content
- supervise actively rather than using a device as a substitute for engagement
- use privacy protective settings and approved accounts
- avoid advertising, tracking, chat, open sharing and unnecessary data collection
- teach children about consent, help seeking, respectful use and safe boundaries
- respond to concerning content, contact or behaviour through child safety procedures
Images, videos, authorisation and children’s rights
Since 1 September 2025, required service policies and procedures for digital technologies and online environments must address taking, using, storing and destroying children’s images and videos; parent authorisation; optical surveillance such as CCTV; service issued devices; and children’s use of digital devices.
Before capturing or using an image
- confirm there is a legitimate educational or operational purpose
- use an approved service supplied device and authorised platform
- check the current parent authorisation and any limits on use
- consider the child’s views, assent, dignity, culture and safety
- check the background for other children, names, attendance lists or sensitive information
- capture only what is necessary and avoid private, vulnerable or undignified situations
- store, share, retain and destroy the image only through approved processes
Parent authorisation does not require an educator to take or publish an image, and it does not override child safety or dignity. A child’s refusal, distress or withdrawal should be respected. Children should understand, in a way appropriate to their age and communication, what is happening and who may see the image.
Purposeful documentation
A small number of images supports a clear learning record, uses current permissions and is stored in the approved system.
Unnecessary exposure
Large numbers of images are taken routinely, kept on devices, duplicated across platforms or used because they are attractive rather than necessary.
Never post or comment about NERPSA children, families, incidents or workplace information on personal social media. Privacy settings, closed groups, disappearing messages and deleted posts do not remove the risk.
Information sharing, breaches and immediate response
Privacy rules permit or require information sharing in particular circumstances, including where authorised by law. Child protection reporting, emergency response, the Child Information Sharing Scheme, Family Violence Information Sharing Scheme, regulator notifications and lawful investigation processes may apply. Follow the specific current procedure and share only through authorised channels.
Protect privacy
Limit access, verify authority, record the reason and share the minimum information needed.
Do not obstruct safety
Do not refuse or delay a required report because the information is “confidential” or because a family has not consented.
Possible breaches include
- an email or attachment sent to the wrong recipient
- a lost device, USB, file, notebook or printed record
- unauthorised access, shared passwords or an account left open
- a child’s image captured, stored or shared outside approved systems
- malware, phishing, suspicious login or unexpected system activity
- records discussed where unauthorised people can hear
- information retained, copied or destroyed contrary to requirements
If a breach or near miss occurs
- take safe immediate steps to contain it without deleting evidence
- notify the responsible person and the designated NERPSA contact immediately
- follow child safety, incident, privacy and technology escalation requirements
- record facts: what happened, information involved, people affected, time, systems and containment
- do not contact recipients, families, media or external authorities unless authorised or personally required by law
- cooperate with assessment, notification, recovery and prevention actions
Practice decisions
Select the strongest professional response. All three must be correct.
You realise an email containing a child’s medical plan was sent to the wrong family.
You want one photograph for a learning record while working directly with children.
A child safety report requires relevant information to be provided through an authorised process.
Complete all three decisions.
Apply the learning to your service
Drafts stay in this browser on this device.
Policies and official resources
NERPSA policies
Use current NERPSA policiesSafe use of devices
Open current ACECQA requirementsNQF child safety changes
Open the commencement informationDigital technology policies
Open the policy requirementsAustralian Privacy Principles
Open OAIC guidanceProtecting personal information
Open OAIC practical guidanceCompletion requirements
- Read every module and scenario.
- Complete all three practice decisions correctly.
- Complete four written responses of at least 20 characters.
- Achieve at least seven out of eight.
- Complete the participant declaration.
- Submit the complete PDF through the NERPSA Document Submission Form.
Generate your completion record
Choose Save as PDF, then submit the complete file through the NERPSA Document Submission Form in the NERPSA Connect App or Staff Resources website.
This is the only acknowledgement required. Please do not email the certificate or responses separately.