Skip to content

The legal framework

Three current laws and one incoming code govern how schools handle children's photos. Nobody designed any of them for what is happening now.

Privacy Act 1988 (Federal)

Defines photographs of identifiable persons as personal information. Photos of children require "particular care" and "express consent after telling them what the picture will be used for and who will be able to see it." Current consent forms do not disclose AI training, facial recognition, or data scraping.

PPIP Act 1998 (NSW)

The state equivalent for NSW government schools. Covers collection, use, accuracy, security, and disclosure of personal information. Photos are personal information. Disclosure requires a lawful purpose and appropriate consent.

Online Safety Act 2021 (Federal)

Grants the eSafety Commissioner authority over online harms. Includes Basic Online Safety Expectations strengthened in 2024. Establishes that the "best interests of the child is the primary consideration." The under-16 social media ban took effect December 2025.

Children's Online Privacy Code (due December 2026)

Will establish specific protections for children's data online. The OAIC released the exposure draft in March 2026 and closed consultation in June 2026. Expected to include best interests considerations, consent requirements, and the right to deletion.

The federal gap

None of these laws specifically address the use of children's photos from school social media in AI training datasets, facial recognition databases, or deepfake generation. The system was designed for a world where "publishing" meant people could see the photo. In 2026, "publishing" means the photo enters permanent AI systems.

The gap is wider than it looks, because the eSafety Commissioner's powers do not reach much of the resulting harm. A non-sexual deepfake built from a school photo “may fall outside the legal criteria for child cyberbullying, image-based abuse or adult cyber abuse because the threshold for adults is higher than for children”, and in those cases eSafety states plainly that it “may be unable to seek its removal under the law”.

Closing the federal gap needs privacy reform, a strong Children's Online Privacy Code, an Australian opt-out from AI training, and enforcement of the Clearview AI deletion order. All of that is slow, contested, and outside any one state's control. Meanwhile there is one sentence in a NSW procedures document that could change this month, which is why this site aims its asks there.

Where this sits in the wider timeline

None of the three asks waits on any of this. The dates matter because the direction of travel runs one way, and a department that moves now gets ahead of it instead of explaining itself later.

December 2025
The under-16 social media ban took effect
Platforms removed 4.7 million accounts. The ban says nothing about schools publishing children's photos on those same platforms.
March to June 2026
The Children's Online Privacy Code consultation opened, then closed
The OAIC released the exposure draft in March 2026 and closed consultation in June 2026. That window has shut.
July 2026
The Privacy Act reached small businesses
More than 100,000 entities picked up privacy obligations they did not carry before.
28 July 2026
The eSafety Commissioner published the school imagery advisory
It tells schools to post fewer identifiable images, move imagery into a closed or restricted space, and check whether the account is public. That contradicts what NSW currently requires. Both documents, side by side.
December 2026
The Children's Online Privacy Code falls due for registration
It will set specific protections for children's data online. Four months away.
Ongoing
Privacy Act reform continues
The second tranche carries a "fair and reasonable" test for data use and a statutory tort for serious invasions of privacy.

NSW Department of Education Policy PD-2011-0418

This is the policy that requires school Facebook accounts to be public. It is the single change that would matter most.

The department requires schools to stay public

Under the heading “Keep the school account open”, the procedures state that school accounts on public platforms “must not restrict access or be set as ‘private’ or ‘closed.’” The rationale given is that “the main purpose for using a public platform is to reach a broader audience and build a stronger community, which includes extended family and friends of students and people in the local area.” Setting up an account requires schools to “ensure the school account does not restrict access”.

This means every photo posted on a school Facebook Page is visible to every person and every automated system on the internet.

But Facebook is not meant to be how schools talk to parents

The same procedures document also states: “Do not use school accounts on public platforms as a primary method of communicating with parent or carers. Schools must use established channels on department platforms (for example, email, school website, applications from the Administration Marketplace Panel for Schools …) as the primary way to communicate with parents or carers.”

The two rules sit in one document. The department requires the account to be open in order to build community, and separately rules out using that account as the primary way of reaching the actual community. Whatever the open setting achieves, it is not parent communication, because the department has already assigned that to email, the school website and the school app.

The policy already permits restriction, for risk

Three sentences after the prohibition, in the same subsection: “This does not mean that a school cannot restrict access, set as private or closed, or suspend the school account from time to time if required to manage or address any risks or issues.”

So the mechanism to protect children already exists inside the policy. What is missing is a departmental statement that AI scraping and deepfake generation counts as a risk for this purpose. Until that exists, a principal acting on the eSafety Commissioner's advisory of 28 July 2026 is departing from a written instruction on their own judgement.

The estate is centrally administered

School Facebook accounts are not set up by schools. The department's social media team creates them on request through EDConnect, and “all school accounts on Facebook must be linked to the department's Business Manager”, a system the procedures note was “previously referred to as the NSW Facebook Schools Project”.

This matters for who can fix it. The 1,713 verified school Pages are one centrally administered estate, not 1,713 independent decisions. The department can change the standard once.

The platform rules point the other way

NSW Government agencies are banned from installing TikTok on government-issued devices, and the procedures direct schools away from YouTube for school accounts. The two supported platforms are Facebook and Instagram, and on those two the account must be open.

eSafety reports that much of the harmful school-related material it saw between January and March 2026 appeared on TikTok and Instagram. The department restricts the platform it does not use and mandates openness on the ones it does.

Moderation covers school hours only

Schools must submit an EDConnect Online Social Media Request. The principal is responsible. Each account needs at least two administrators, one of them the principal or an executive. Schools moderate accounts during school hours only: 9am to 3pm weekdays. Content posted or accessible outside those hours is unmoderated.

Student images

Student images require a signed "Permission to Publish" form. Tagging and naming are prohibited without specific consent. Even photos where students cannot be identified require consent. Staff cannot share student content on personal social media.

Victoria takes a different approach

Victoria's education department encourages restricted access for school social media accounts. NSW is an outlier in requiring public settings. The department can update the policy administratively. No legislation is required.

The audit proves the system works as designed

An audit of every NSW government school verified that 79% operate public Facebook Pages. The result is consistent: 77% metro, 82% inner regional, 83% outer regional, 89% remote. 1,713 schools serving 596,069 students follow the same pattern. This is not the sum of individual decisions. It is what the system produces when the policy says accounts “must not restrict access or be set as ‘private’ or ‘closed.’”

Only approximately 100 schools use private Groups. The alternative exists. The system does not produce it.

The consent form

Binary choice

The NSW "Permission to Publish" form offers one choice: consent to all public publishing (school website, newsletter, Facebook, newspapers, external media) or none of it. There is no option to say "yes to the newsletter, no to Facebook."

No AI disclosure

The form warns that online content "can be discoverable online" and may be "cached by search engines." It says nothing about AI training, facial recognition databases, training datasets, or deepfake generation. Somebody wrote it before any of this existed.

No expiry

Consent remains in effect "until I advise the school otherwise." There is no annual renewal. A form signed in 2019 still governs what happens to a child's photo in 2026, in a threat landscape that did not exist when the parent signed the form.

Children have no voice

The children in the photos get no say in the decision. A 2024 peer-reviewed study found that school social media practices violate Article 12 of the UN Convention on the Rights of the Child, which guarantees children the right to express views on matters affecting them.

What each level of protection actually stops

There is no single action that eliminates all risk. Here is an honest breakdown.

Level 1: Private Facebook Group

The minimum first step

Stops: Third-party scrapers, search engine indexing, random public access.

Does not stop: Meta's own AI training (unclear under current terms), member screenshots, historical scraping of already-public content.

A private Group immediately removes the biggest exposure: unrestricted public access. It prevents the mass-scale automated harvesting that facial recognition companies and dataset builders rely on.

Level 2: Leave Facebook entirely

The next step

Stops: Everything in Level 1, plus Meta's AI training.

Does not stop: Historical scraping. Other platforms' AI training (depends on alternatives).

Alternatives include dedicated school apps (Compass, Sentral, Skoolbag, ClassDojo, Seesaw), password-protected school website sections, email newsletters, and school-controlled parent portals. The question: does the school control the platform, or does a data-mining company?

Level 3: Stop publishing identifiable photos

Most protective

Stops: All scraping, all AI training, all facial recognition capture, all deepfake source material.

Does not stop: Historical scraping of already-public content.

This is the most protective option but not the recommended first step. Parents value seeing their children's school life. The goal is to protect children while preserving the community communication that schools and families rely on. A private Group achieves that balance.

What about photos already posted publicly?

Photos already scraped cannot be unscraped. AI models already trained on those photos cannot unlearn them. But deleting historical posts still matters: it prevents future scraping, removes photos from search results once caches expire, reduces the number of publicly available images of each child, and shows families the school takes protection seriously.

The system wasn't built for this. Now we know.

The policy, the consent form, the legal framework: none of them contemplated what happens to a child's photo on a public Facebook Page in 2026. Now we have the evidence. The question is what we do with it.