The person who stopped our January direct-to-teacher launch never gave their name.
We could have gone ahead. We couldn't in good faith. Every NCCD record names a child's disability, and under the Privacy Act and the health records acts of Victoria, New South Wales and the ACT, that makes it a health record. A health record carries its own rules on consent, purpose, security, retention, transfer and who may hold it at all.
The launch we stopped
It was January. Our calls for expressions of interest resulted in 44 teacher sign-ups in 48 hours, and 59 in the first 10 days. We used the example of noting a recess incident where a student was injured. Two minutes for a voice note as the teacher walked back from duty resulted in the agent drafting notes for the teacher, the nurse and draft emails to the parents, ready for teacher review and approval.
We were confident in our security stack. Our risk assessments indicated students' information would be as safe or better than required.
An anonymous post emerged. The person asked, "What about the FOI Act?"
We chatted further. The more we did, the more I felt like a rock was lodging in my gut.
Every NCCD record is a health record. Every injury, every incident, every mention of a diagnosis like ADHD or dyscalculia. A health record. And in Victoria, New South Wales and the ACT, a teacher does not have the authority to put a child's health record into an app, even a secure one. Only the school does.
We researched all the states and territories and stopped the launch. We could have launched in other states and territories, leaving it to the teachers to understand their limits of authority.
But I was a principal and a teacher and knew that would put them at risk. I lived the 50+ hour weeks that leave no time to look into state and territory health regulations.
We spent the next seven months doing everything possible to comply not just with privacy law but with the health records law of each state and territory. It was not easy. I still hold my teacher registration, and I wanted an assistant I would have trusted in my own school.
When we talk about AI governance in schools, we usually discuss data and security. We don't discuss health.
But we should.
Is NCCD evidence health information?
Yes. Each of the four acts defines health information, and each one names disability. The wording, quoted from the current compilations:
| Law | Definition of health information |
|---|---|
| Privacy Act 1988 (Cth), s 6FA | "information or an opinion about: (i) the health, including an illness, disability or injury, (at any time) of an individual" |
| Health Records Act 2001 (Vic), s 3 | "information or an opinion about (i) the physical, mental or psychological health (at any time) of an individual; or (ii) a disability (at any time) of an individual" |
| Health Records and Information Privacy Act 2002 (NSW), s 6 | "personal information that is information or an opinion about (i) the physical or mental health or a disability (at any time) of an individual" |
| Health Records (Privacy and Access) Act 1997 (ACT), dictionary | "any personal information, whether or not recorded in a health record (a) relating to the health, an illness or a disability of the consumer" |
An NCCD record is built from exactly this material. The NCCD Guidelines allow a school to impute a disability where no diagnostic report exists: "An imputed disability is an undiagnosed disability the school team considers a student to have" (NCCD Guidelines effective 2026, C.4.2). An opinion about a disability is health information under every definition above. So is the diagnosis when there is one, the adjustment record, and the incident note that explains why the adjustment was needed.
The Victorian Department of Education says the same to its own schools: "Individual Education Plans, behaviour support plans and other learning or educational assessments" and "notes about student behaviour or wellbeing recorded in school systems" are health information records a school may hold (Policy and Advisory Library, Health information, updated 10 July 2025).
And no, you can't just put student initials or invent a pseudonym for them. Still a breach.
What changes when a record is a health record
Six things. None of them is visible on vendors' required security pages.
Consent to collect it. Health information is sensitive information (Privacy Act, s 6). An organisation "must not collect sensitive information about an individual unless" the individual consents and the information is reasonably necessary, or the collection is required or authorised by law (APP 3.3 and 3.4). The OAIC's guidance: an entity "should generally seek express consent" before handling sensitive information, and "An individual aged under 15 is presumed not to have capacity to consent" (APP Guidelines, B.44 and B.61). For a Year 3 student, that consent comes from a parent, through the school.
The purpose it may be used for. Information collected for one purpose "must not" be used or disclosed for another without consent or an exception (APP 6.1). NCCD evidence is collected so a school can support a child and report the adjustment. Product analytics, benchmarking across schools and training a model are other purposes.
How it must be secured. This is the one every vendor answers. Encryption and Australian servers, which most do.
How long it must be kept. A Victorian organisation that is not a health service provider "must take reasonable steps to destroy or permanently de-identify health information if it is no longer needed" (HPP 4.5). A health service provider may not delete a child's health information until the child turns 25 (HPP 4.2). The Commonwealth rule is destroy or de-identify once no longer needed (APP 11.2).
Whether it may leave the state. Victoria's HPP 9.1 allows transfer of health information "to someone … who is outside Victoria only if" the recipient is bound by substantially similar principles, the individual consents, or another listed condition applies. Sydney is outside Victoria. "Hosted in Australia" answers the Commonwealth question but not the Victorian one.
Who may hold it at all. Victoria's Act binds any organisation that collects, holds or uses health information, with no size threshold. The Commonwealth Act has a small business threshold. Which act a vendor sits under decides whether its "Privacy Act compliant" line is an obligation or a courtesy.
Can a teacher put NCCD evidence into an app the school has not approved?
In Victoria, New South Wales and the ACT, no. That decision belongs to the school as an organisation. A teacher on a personal account has not been given it.
Victorian government schools, "prior to adopting new software or an administration system that is not provided by the department", must first check the Arc software catalogue and whether an ST4S risk assessment report exists, and cannot adopt products rated non-compliant, non-participating or high risk (Policy and Advisory Library, Software and administration systems, updated 28 January 2025). The health information guidance adds: "If a school needs to use third-party software to store health information, it must meet security, privacy and records management requirements."
In New South Wales, "Schools should not use software or devices that have failed a security assessment" and "Principals are accountable for the risks and issues that arise from using such software or devices" (Technology in schools procedures, PD-2024-0481-01, updated 18 June 2026). The NSW Auditor-General found in June 2026 that "Some schools use third-party products outside of these marketplaces and without departmental oversight or controls to protect student information" (Security and privacy of student information, 29 June 2026).
The ACT Act adds four words the others leave out. Personal health information is any personal information about a person's health, illness or disability "whether or not recorded in a health record". A note about a child's diagnosis is inside the Act wherever it is kept, including a teacher's personal app.
So consider the free tools. If a product offers a freemium plan or low-cost plan to individual teachers and that plan includes an individual education plan writer, the teachers using it may be putting a child's health record somewhere the school never approved and cannot see.
They're not trying to do the wrong thing. The same app may give them great lesson ideas and teachers are simply trying to survive the admin load. They likely don't know.
We didn't know. Until we did.
Why "secure" is a different question
Safer Technologies 4 Schools is the sector's assessment scheme, and it is honest about its edges. Its excluded and high-risk list names "Applications or services which process health and wellbeing data" as outside assessment, and its AI exclusions include "determining or predicting emotions, student disability, learning difficulties etc." (ST4S, What we do not assess, updated 28 January 2026). A school approving any NCCD product with AI in it has a question to ask beyond the badge. A vendor with no ST4S engagement at all has likely skipped both.
What a principal can do this week
"Thou shalt not…" conversations have happened in most schools. Teachers know they should not put names into AI tools. My experience is that teachers want to do the right thing and they don't want to put their students or families at risk.
But they don't know the health regulations or how their state or territory might differ from others.
If teachers are asking for ways to ease the collection of NCCD data, look for vendors that are committed to helping you protect your students, their families and your school.
Ask this question of every product that touches NCCD evidence: does the company know it is holding health records?
Three ways to tell from the outside:
- The privacy policy names disability or health information as sensitive information, and names the state health records act that applies to your school.
- The contracting party is the school, under a signed agreement, and individual teacher accounts cannot hold student information. Even for schools outside VIC, NSW and the ACT, this is good practice.
- Retention and deletion follow the school's obligation, in writing, and the vendor says where the record sits and under which law when it crosses a state line.
Teacharo's answer, from our privacy policy: "Some student information (for example, health information, disability information, and information about learning needs and adjustments) is sensitive information under the Privacy Act. We only collect and handle this information where authorised by the school and in accordance with our Data Privacy Agreement and applicable privacy and education laws." Individual plan users cannot store student personal information. On a school plan, personal information is de-identified before any AI model processes it, and all processing happens on servers in Australia.
If your teachers are struggling to write down NCCD evidence, we have a way for them to do it inside those rules.
Where do the diagnoses live in your school right now, and who could open the drawer? Reply and tell me. I read every one.
Frequently asked questions
Is NCCD data health information?
Yes. The Commonwealth, Victorian, NSW and ACT definitions of health information each name disability. A record of a student's NCCD category, diagnosis or adjustments is health information under all four.
Is a student's disability sensitive information under the Privacy Act?
Yes. Section 6 of the Privacy Act lists "health information about an individual" as sensitive information, and s 6FA defines health information to include a disability at any time.
What privacy law applies to NCCD evidence?
The Privacy Act 1988 (Cth) and, depending on the state, the Health Records Act 2001 (Vic), the Health Records and Information Privacy Act 2002 (NSW) or the Health Records (Privacy and Access) Act 1997 (ACT).
Do schools need consent to record a student's disability?
Collecting sensitive information needs consent plus necessity, or a legal authority (APP 3.3 and 3.4). Children under 15 are presumed unable to consent, so it comes from a parent through the school.
Can a teacher use a free app for NCCD or IEP notes?
In Victoria and NSW, department policy places software approval with the school, and NSW principals are accountable for unassessed software. A personal account sits outside that approval.
Does ST4S cover health and disability data?
No. ST4S lists services that process health and wellbeing data as excluded, and names student disability and learning difficulties among its AI exclusions. Schools are told to run their own risk assessment.
Does "hosted in Australia" satisfy the health records acts?
It answers the Commonwealth cross-border rule. Victoria's HPP 9 restricts transfers outside Victoria, so a Victorian record on a Sydney server still needs a legal basis.
How we check this guide
Last reviewed 7 September 2026 against: Privacy Act 1988 (Cth), Compilation No. 104, 4 June 2026 (legislation.gov.au); Health Records Act 2001 (Vic), Version 050, 1 May 2026 (legislation.vic.gov.au); Health Records and Information Privacy Act 2002 (NSW), in force version (legislation.nsw.gov.au); Health Records (Privacy and Access) Act 1997 (ACT), Republication 32, 16 November 2025 (legislation.act.gov.au); OAIC APP Guidelines Chapter B (21 December 2022); NCCD Guidelines effective 2026 onward; Victorian PAL Health information (10 July 2025) and Software and administration systems (28 January 2025); NSW Technology in schools procedures PD-2024-0481-01 (18 June 2026); NSW Auditor-General, Security and privacy of student information (29 June 2026); ST4S excluded and high-risk list (28 January 2026); Teacharo Privacy Policy (1 March 2026). Reviewer: Janet Moeller.