The NSW Audit Office examined how student information is protected across the NSW Department of Education and NSW public schools, and found some critical gaps.
Access control
The department's controls do not ensure that access to student information is limited to staff who need it for their role. Schools apply access controls inconsistently, and some staff access more information than they need or retain access after they leave a school.
Shadow IT
The department's marketplaces give schools a range of approved third-party digital products for school administration and online learning. However, some schools use third-party products outside these marketplaces and without departmental oversight or controls to protect student information.
Third-party risk assessments
While third-party vendors of digital products in the department's marketplaces are subject to contractual security and privacy controls, the department does not routinely verify vendor compliance.
Student records often contain some of the most sensitive information a school holds. Protecting that information depends on much more than security technology.
Reading the report, I'd be asking three questions:
- Do we know exactly who has access to student information?
- Do we know every application that stores or processes that information?
- Do we regularly verify that our suppliers are meeting their security obligations?
If the answer to any of those is “not really”, there's probably work to be done.

