Schools · Governance & compliance

NSW school audit finds gaps in student data security and third-party app oversight

The NSW Audit Office found critical gaps in how student information and third-party applications are governed across public schools.

Damien Cantelo

Damien Cantelo

July 18, 2026

NSW school audit security gaps graphic

The NSW Audit Office examined how student information is protected across the NSW Department of Education and NSW public schools, and found some critical gaps.

Access control

The department's controls do not ensure that access to student information is limited to staff who need it for their role. Schools apply access controls inconsistently, and some staff access more information than they need or retain access after they leave a school.

Shadow IT

The department's marketplaces give schools a range of approved third-party digital products for school administration and online learning. However, some schools use third-party products outside these marketplaces and without departmental oversight or controls to protect student information.

Third-party risk assessments

While third-party vendors of digital products in the department's marketplaces are subject to contractual security and privacy controls, the department does not routinely verify vendor compliance.

Student records often contain some of the most sensitive information a school holds. Protecting that information depends on much more than security technology.

Reading the report, I'd be asking three questions:

  • Do we know exactly who has access to student information?
  • Do we know every application that stores or processes that information?
  • Do we regularly verify that our suppliers are meeting their security obligations?

If the answer to any of those is “not really”, there's probably work to be done.

Make Cyber Compliance Simple

See how Apollo Secure can help you manage cyber risk, compliance and customer trust without enterprise complexity.

Book a Demo