Compliance Guide

Personal Devices, Photos and Videos in Childcare: The 2026 Rules Explained

From 27 February 2026, strengthened National Quality Framework requirements limit the use of personal digital devices in education and care services and place tighter controls on how images and videos of children are captured, stored and transmitted.

By Oiva Compliance Intelligence Team · Reviewed by Child safety and privacy specialist · 15 July 2026

Key takeaways

  • From 27 February 2026, staff in centre-based services must not use or have personal devices while working directly with children, subject to defined exceptions.
  • Smart watches, tablets, cameras and other connected devices capable of capturing or transmitting images are all within scope, not just mobile phones.
  • Service devices must not be connected to personal Apple IDs, Google accounts, cloud backups or messaging apps. Provider-controlled identities are required.
  • A written policy alone is insufficient: providers must control the full image lifecycle from capture and storage through to deletion, with verifiable evidence at each step.
  • Family authorisations must separately address learning documentation use and marketing use. Broad bundled consent is not adequate.

Important: Requirements differ between centre-based and family day care settings, and exceptions may apply. Providers should use current ACECQA guidance and seek jurisdiction-specific advice where needed.

These changes are not just about mobile phones. They require providers to examine smart watches, tablets, cameras, storage media, messaging, cloud platforms, authorisations, access controls and everyday staff behaviour.

The safest approach is to treat every image of a child as sensitive operational information that must have a clear purpose, approved device, authorised user, controlled storage location and defined deletion process.

What changed in centre-based services?

ACECQA guidance states that staff in centre-based services must not use or have personal devices while working directly with children, subject to defined exceptions.

The controls can apply to devices capable of taking, storing or transmitting images or videos, including:

  • mobile phones
  • tablets
  • cameras
  • smart watches
  • laptops
  • removable storage
  • other connected or recording devices.

Service-supplied devices can be used for legitimate education and care purposes, including approved photography and video, provided the provider has suitable controls.

What about family day care?

In family day care, personal devices cannot be used to take, store or share images or videos of children.

A provider can supply or authorise a device for education and care purposes. A service-authorised device must be used exclusively for those purposes and not for personal activity.

Family day care requires careful separation because the service environment and personal environment can overlap.

Policy requirements started before the device restrictions

From 1 September 2025, regulation 168 changes required policies and procedures addressing the safe use of digital technologies and online environments.

The policy scope includes:

  • taking, using, storing and destroying images and videos of children
  • obtaining authorisation from parents
  • optical surveillance devices such as CCTV
  • service-issued digital devices
  • children’s use of digital devices.

By 2026, providers need to show that these policies are operating in practice.

Why a policy alone is not enough

A written rule can fail if:

  • staff do not understand which devices are prohibited
  • smart watches are overlooked
  • personal phones remain in pockets
  • service devices use personal Apple or Google accounts
  • images automatically back up to personal cloud storage
  • photos are sent through unapproved messaging apps
  • former staff retain access
  • parent authorisation is vague or outdated
  • images are kept indefinitely
  • deletion cannot be verified.

Regulators and families will reasonably expect the provider to control the full lifecycle of an image, not merely the moment it is taken.

A practical implementation checklist

1. Define the device boundary

Create an approved-device register showing:

  • device identifier
  • service
  • owner
  • authorised users
  • purpose
  • applications installed
  • storage location
  • security configuration
  • date issued
  • date returned or retired.

Unregistered devices should not be used for children’s images.

2. Control personal devices physically

Decide where personal devices are stored during direct work with children.

Consider:

  • secure lockers
  • designated staff areas
  • emergency contact arrangements
  • medical or accessibility exceptions
  • approval records
  • relief staff and contractors
  • excursions
  • breaks and room transitions.

A rule that cannot be followed during a normal shift needs a better operating design.

3. Remove personal accounts

Service devices should not be connected to an employee’s personal:

  • Apple ID
  • Google account
  • photo library
  • cloud backup
  • email
  • messaging application
  • file-sharing account.

Use provider-controlled identities and access.

4. Map every image pathway

Document how an image moves from capture to deletion.

For each approved use, identify:

  • why the image is needed
  • who captures it
  • which device is used
  • where it is stored
  • who can view it
  • whether it is shared with a family
  • whether it is used in documentation or marketing
  • how long it is retained
  • how it is deleted
  • who verifies deletion.

5. Separate operational and marketing consent

A family may agree to images being used for learning documentation but not public marketing.

Authorisation should distinguish between uses rather than bundle them into one broad consent.

6. Apply least-privilege access

Not every staff member needs access to every child’s images.

Access should reflect:

  • role
  • room
  • service
  • business need
  • employment status.

Access should be reviewed when a person changes room, service or role, and removed immediately when engagement ends.

7. Train and test staff

Training should include realistic examples:

  • a parent asks an educator to take a photo on the parent’s phone
  • a personal smart watch receives image notifications
  • a service tablet backs up to an unknown cloud account
  • an educator sends a photo through a private messaging group
  • a device is lost
  • an image is captured accidentally
  • a staff member observes a possible breach.

Use scenario-based confirmation rather than relying on a policy acknowledgement alone.

8. Prepare for incidents

A suspected image or device breach should trigger:

  • immediate containment
  • preservation of relevant evidence
  • internal escalation
  • child safety assessment
  • privacy assessment
  • notification assessment
  • family communication where required
  • corrective action
  • documented closure.

Privacy and child safety must work together

Images of children can reveal identity, location, routines, relationships, health information, cultural information and other sensitive context.

The Privacy Act protects personal information regardless of age. Providers covered by the Act must take reasonable steps to protect personal information and should collect only what is reasonably necessary.

Even where a provider is outside part of the Privacy Act, strong privacy controls remain fundamental to child-safe practice and community trust.

How Oiva relates

Oiva is privacy-aware by design. Personal information is minimised before AI processing, data is stored in AWS Sydney, and AI-generated work requires human review.

For device and image compliance, Oiva’s broader value is the ability to connect an official change with provider actions, updated policies, staff briefings, acknowledgements and evidence. The goal is not to store more information. It is to ensure the right information is controlled and the required action is provable.

Final message for providers

The 2026 device rules are not an inconvenience to work around. They respond to a serious child safety risk.

Providers should make the compliant behaviour easier than the non-compliant behaviour. That means approved devices, clear physical arrangements, controlled identities, limited access, reliable authorisations and evidence that staff understand the rules.

Frequently asked questions

Can educators keep a personal phone while working directly with children?

In centre-based services, the strengthened rules generally prohibit staff from using or having personal devices while working directly with children, subject to specific exceptions. Check current ACECQA guidance.

Can a service-issued tablet be used?

Yes, where it is supplied or authorised by the provider and used within the required controls for education and care purposes.

Can staff use a personal cloud account on a service device?

This creates serious privacy and control risks and should be prevented through provider-controlled accounts and configuration.

Do the rules cover smart watches?

Providers should treat smart watches and other devices capable of capturing, storing or transmitting information as part of the device-control framework.

Official sources

  • ACECQA, Safe use of devices in education and care services (acecqa.gov.au)
  • ACECQA, Using digital devices in centre-based education and care services (acecqa.gov.au)
  • ACECQA, NQF child safety changes from 1 September 2025 and 1 January 2026 (acecqa.gov.au)
  • ACECQA, National Model Code for Taking Images in Early Childhood Education and Care (acecqa.gov.au)
  • OAIC, Australian Privacy Principles (oaic.gov.au)
  • OAIC, APP 11 Security of personal information (oaic.gov.au)

Know what changed. Know what to do next.

Oiva helps Australian early learning providers turn official regulatory updates into clear actions and evidence records, with human review built in.

Join the Waitlist →

Related articles

Compliance Guide

NQF Child Safety Reforms 2026

Compliance Guide

Early Childhood Worker Register: Provider Guide

Technology & Trust

AI in Childcare: Trust, Privacy and Oversight

Compliance Strategy

From Regulatory Change to Evidence

This article provides general information for Australian ECEC services and approved providers. It does not constitute legal, regulatory or professional advice. Requirements vary by jurisdiction, service type and individual circumstances. Providers should confirm their obligations with ACECQA, their state or territory regulatory authority and qualified professional advisers.