Our submission to the Parliamentary inquiry into cybersecurity

Parliament is looking at how small businesses handle cyber security. Childcare centres are small businesses. They also hold children's birth certificate, Medicare number, medical records and photographs, often inside software they didn't build and can't check. To clarify the risks with this approach, we made a submission to the House Select Committee on Cyber Security for Small to Medium Sized Businesses and Organisations.

Here's what we told the Committee:

Centres can't fix what they can't see

A director chooses a software platform to manage the daily centre operations and parent messaging. From then on, thousands of children's records live inside it. But a director can't audit such software, configure it or fix it. While schools have a security standard for the software they buy, childcare has none.

We found our child's documents sitting in the open

We saw primary identity documents in a vendor's public storage. Hundreds of photos without proper security. Documents you can open without logging in. Information you can find on Google. We told the vendor, the centre and the regulators in August 2025. It's still there.

Ticking "no photos" doesn't stop the photo

Platforms record what each family agreed to, then show the educator a note when they upload. Some vendors say plainly that the upload goes ahead anyway. That’s going against a parent’s consent setting. A note someone can miss is not a control.

Nothing gets deleted

Of the six platforms we looked at to inform our submission, not one says it deletes a child's data when the child leaves childcare. Some switch off the parent's login instead. But the data stays. You just can't see it.

Now they're adding AI

One vendor's roadmap adds face recognition to tag children in photos. It's sold to centres on the promise that families only get photos of their own child. That only works if every child's face is scanned. Including the ones whose parents said no.

So we asked for six things:

  1. A minimum security standard for any platform holding children's data; the same idea Australia already applies to smart light bulbs. And make it a condition of claiming childcare subsidy (CCS).

  2. Make permissions work in the software, not in a note to staff.

  3. Delete children's data when the child leaves. Backups included. Unless there’s a clear and unambiguous legal requirement to keep any of the data.

  4. Extend the schools' software standard (ST4S) to childcare platforms, and publish the results.

  5. Train directors and educators in handling this data.

  6. Let families deal with the vendor directly. Whoever holds the data should answer for it.

At Safer Footprint, we believe technology has a real place in education. It just needs to be safer for children and their families. We’re looking forward to working with the Committee, which will have its final report completed by 31 March 2027.

Next
Next

AI arrived at your centre! Here’s a policy to consider