// schools — Australian Capital Territory
Your school completes its own Privacy Impact Assessment. This is the vendor half — written against Information Privacy Act 2014 (ACT), so it can be attached rather than requested.
Data hosted in
Australia — Azure Australia East (Sydney)
Government schools
Information Privacy Act 2014 (ACT)
Independent & Catholic
Privacy Act 1988 (Cth)
// ACT — your framework
Australian Capital Territory government schools are public-sector organisations under Information Privacy Act 2014 (ACT) and its Territory Privacy Principles (TPPs), regulated by Office of the Australian Information Commissioner (for the ACT).
Independent and Catholic schools are not. They are private-sector organisations bound by Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), regulated by the Office of the Australian Information Commissioner (OAIC). The technical controls are identical either way — the framework you assess them against is not, and it is worth being sure which one your assessment is written against.
On child safety, your obligations sit under the ACT Child Safe Standards. The school remains the responsible entity; our part is making sure the technical controls support your policy — access granted by the school rather than shared between families, consent recorded and bound to the exact content it approves, and an audit trail that answers who could see what, and between which dates.
The legislative references on this page are a starting point for your assessment and have not yet been confirmed by our legal advisers. Please verify them against your own requirements — and if anything here is wrong, tell us and we will correct it for every school in ACT.
Where the data is hosted, how it is encrypted, who can see a document about a named student, how deletion works, and who else processes it — none of that changes by state, so it is written once rather than restated eight times.
// other states