Trust and Safety
What the Children's Online Privacy Code Means for Your Centre
A new privacy code for children's data must be registered by 10 December 2026. It's aimed at online platforms, not centres, but it will change what families expect from everyone who handles footage of their children. Here's what the draft says, and the questions worth asking your suppliers now.
Last updated 12 August 2026
The code is still a draft. It must be registered by 10 December 2026, and the date it actually starts applying hasn't been set. Nothing on this page is something your centre has to do today.
The short version
It won't land on your centre. It will land on the people you buy from.
Australia is writing its first privacy code dedicated to children. It binds businesses that provide an online service children use, so unless your centre is publishing an app or a platform of its own, the obligation isn't yours.
What changes is the climate around you. The apps your families use will be rebuilt to a higher standard, and the questions parents ask about who holds pictures of their child will get sharper. The centres that come out of this well are the ones already able to answer them.
This guide covers what the draft says, who it covers, and eight questions you can put to any supplier today.
Three dates, and only one of them is fixed
Exposure draft published
The Office of the Australian Information Commissioner released the draft code and an explanatory statement, mandated by the 2024 privacy reforms.
Consultation closed
135 written submissions were lodged, alongside separate consultations with children, parents and carers. The OAIC is working through them now.
Must be registered
A statutory deadline, not a target: the 2024 privacy reforms gave the Commissioner two years from their assent to register the code. What isn't settled is when compliance is enforced after that. The draft's own commencement clause is still marked "to be drafted".
What the draft actually asks for
The code sits under the Privacy Act. It doesn't create a new law so much as spell out, in far more detail than before, how covered businesses must handle information when it belongs to a child. Ten things stand out in the draft.
Consent sits at 15
A child aged 15 or older can consent for themselves. Below 15, consent must come from a person with parental responsibility, and the business has to take reasonable steps to confirm that's who it's dealing with. The child still gets an age-appropriate notice explaining what was agreed.
Consent expires inside 12 months
Every consent runs for a stated period, and that period can never exceed 12 months. Consent signed once and relied on for years stops being consent.
No bundling, no pre-ticked boxes
A request covering several uses at once, without letting someone agree to each separately, isn't voluntary consent. Neither is a pre-ticked box, nor consent assumed from someone continuing to use the service.
Collect only what's strictly necessary
Covered services must build their systems so that, by default, they collect only what's strictly necessary to run the service. Convenient-to-have doesn't qualify.
The child's best interests govern
Information must be collected, used and disclosed consistently with the best interests of the child, a standard drawn from the UN Convention on the Rights of the Child.
Services must know who's a child
Businesses have to take reasonable steps to work out the age of the people using their service before collecting anything, rather than claiming they didn't know.
Documents a 10-year-old could read
Privacy policies, collection notices and consent requests must be age appropriate, which the draft defines as pitched at a child aged 10 to 12 unless the service targets a younger group. It rules out complex, technical and legal language, and suggests diagrams or video where they'd help.
Deletion on request, answered in 30 days
A child, or a parent on their behalf, can ask for information to be destroyed, and the business must do it unless a specific exception applies. A company has to respond in writing within 30 days, or 60 if it explains the delay inside the first 30. Complaints and general enquiries get 30 days too.
Assessments, published
Privacy impact assessments must be run for new services children are likely to use, and for changes that significantly affect children's privacy. The register of them goes online, not in a drawer.
Training and review, annually
Anyone with regular access to children's information trains on it when they start and at least yearly after, with records kept. Privacy practices get reviewed at least annually too.
If that reads like the bar a good early learning service already tries to meet, that's the point. The code takes instincts this sector has held for years and turns them into enforceable rules for the online world. Once it's registered, breaching it is an interference with privacy under the Privacy Act, which the Information Commissioner can investigate.
The businesses in scope are the ones behind the screens
To be caught at all, a business has to be providing a social media service, a messaging or communication service, or an internet service such as an app or a connected device. Those terms are borrowed from the Online Safety Act. On top of that, the service has to be likely to be accessed by children, or primarily concerned with children's activities, and the business must not be providing a health service. Carriage service providers, meaning the businesses that supply telecommunications to the public, are excluded outright.
The draft names its own examples of what it's reaching for, and they'll be familiar:
- Applications that track early childhood development
- Family photo sharing applications
- Online school management systems that monitor how children are going
- Internet-connected baby monitors
Running an education and care service doesn't make you any of those things. Neither does engaging a photographer or a video crew to work in your rooms.
- Your centre, which isn't a provider of those services
- A photographer or video crew working in your rooms
It's also finer-grained than whole companies. The code applies service by service: a bank's pocket money app can be caught while its home loan app isn't. So a vendor being "covered" or not is the wrong question. The right one is whether the particular product you use is.
So a director could file this under "not my problem" and be technically right. We'd argue that's the wrong reading.
Your obligations under the Privacy Act, the National Quality Framework and the Child Safe Standards already exist today. Since September 2025, the National Regulations have required every service to hold explicit policies on how images and videos of children are taken, used, stored and destroyed. The code changes none of that. What it changes is what families expect, and what "careful with children's data" is going to mean in plain English.
Eight questions worth asking every supplier
The most useful thing in the draft isn't any single rule. It's the posture: know where children's information is, keep it to a minimum, delete it when its purpose ends, and be able to show your work. Any supplier who films, photographs or stores footage of your children can be held to that today. A professional one will have ready answers, and hesitation tells you something.
Where does footage of our children live while you're working on it, and who can open it?
Does anything leave your premises on personal phones, laptops or memory cards?
When the project ends, what happens to the footage, and what proof do we get?
Where do your backups sit, and when do they expire?
Are your editors and contractors bound in writing on confidentiality and child safety?
Does footage of our children go into AI tools, and for what exactly?
If we ask you to take something down, how fast does it come down?
If something went wrong, who calls us, and how quickly?
A supplier asking you to trust them should go first
These are EEVA's answers to our own eight questions, drawn from our child safety and footage handling policies. Hold us to them, and use them as the benchmark for anyone else you engage.
Storage and access
Raw footage transfers to our secure network storage on the day of filming, or as soon as practicable. Access to child-related footage is restricted to our director and approved editor. Editors receive material through secure transfer, not shared drives with open links.
Personal devices
Crew never take or keep images of children on personal devices. Once footage is confirmed on our secure storage, it's permanently deleted from capture equipment. This mirrors the National Model Code position on personal devices in services.
End of project
We retain footage for up to 24 months after delivery, or a shorter period if you ask, then destroy it irretrievably. Moving files to a recycle bin doesn't meet that standard, and we confirm destruction to you in writing, naming what was destroyed and when.
Backups
Our backup copies sit on encrypted storage and follow the same retention ceiling as the master footage. When the master is destroyed, the backup goes with it.
Contractors
Everyone who touches your footage works under a signed agreement covering confidentiality and child safety, and every crew member who enters your centre holds a current Working With Children Check or the equivalent clearance in their state.
AI tools
Our interviews are with adults: educators, directors and parents. That's the footage our professional edit suite assists with, transcribing what was said and helping assemble a first cut. Children appear in b-roll, and no AI tool touches it. We never use AI to generate a child, or to alter any child's face, body or voice.
Takedowns
Ask us to remove something and it comes down within two business days, with no debate about whether the request is reasonable.
If something goes wrong
You'd hear it from us first. Our child safety contact notifies your nominated lead in writing within 24 hours of us becoming aware of any incident involving your footage, before we have the full picture rather than after.
Three things worth an afternoon
- Review your image and video consent. Specific rather than blanket, current rather than signed-once-years-ago, easy to withdraw and actually honoured when it is.
- Ask your app and software vendors what they're doing about the code, in writing. Development-tracking apps, family photo sharing and management systems that monitor how children are going are the draft's own examples of what it's aimed at. Their answer tells you how seriously they take children's data.
- Put the eight questions to every media supplier who works with your children. Including us.
None of that needs a lawyer or a compliance budget. It puts your centre ahead of a standard the rest of the online world is about to be pulled towards.
This guide is general information, not legal advice. The code's final wording may change before registration. For advice on your service's specific obligations, speak with a privacy professional.
Questions directors ask
Is the Children's Online Privacy Code law yet?
No. The Office of the Australian Information Commissioner published an exposure draft on 31 March 2026 and public consultation closed on 5 June 2026. The final code must be registered by 10 December 2026, and the commencement date, including any transition period for businesses to prepare, hasn't been confirmed. Until then it's a draft, not an obligation.
Will the code apply to my centre?
As drafted, almost certainly not. The code binds providers of social media services, communication services and internet services such as apps and connected devices, using definitions borrowed from the Online Safety Act. Running an education and care service doesn't make you one of those, and the draft carries a further carve-out for businesses providing a health service. Worth knowing it also applies service by service rather than company by company, so the question is always about a particular product. Your obligations today come from the Privacy Act, the National Quality Framework and the Child Safe Standards, and those are already substantial.
Does the code cover our photographer or video agency?
Not as drafted. A production company filming in your centre isn't an online service provider in the sense the code uses. But the code is a clear signal of where standards are heading, and the practical questions it raises, where footage lives, who can open it, when it's destroyed, apply to every supplier who handles images of your children. Ask them regardless of whether a code compels it.
What should we do before the code is finalised?
Three things. Review your image and video consent so it's specific, current and easy to withdraw. Ask the vendors behind your family communication and management apps how they're preparing, because they're the businesses most likely to be covered. And put the supplier questions in this guide to anyone who films, photographs or stores footage of your children.