🎓 Schools & education
A school carries duties from several directions at once: privacy law that differs depending on whether it is government or non-government, a state education department policy, registration conditions, child-safety standards, and a long tail of EdTech apps holding student data. Most of the guidance a school finds online is written for the wrong sector or the wrong state, so schools either over-comply with rules that do not bind them or miss the ones that do.
Book a demo → Try it on sample docsTier-A breadthStudent privacy · Essential Eight · child safety · EdTech vendors
Frameworks on the engine serving this vertical
Read from the live catalogue at build time — a framework that is not live on the engine never renders here. Depth is badged per framework: consultant-grade only where we go deepest (ISM/IRAP, Essential Eight), Tier-A breadth everywhere else.
Licence-gated catalogues carry control IDs and CyberSentien's own labels only — the full standard text requires your licence and is never reproduced.
Depth today — stated honestly
Tier-A breadth: 168 curated obligations, each traced to a named primary source — legislation, regulator, education department or registration authority — and each stating the SECTOR (government vs non-government) and JURISDICTION it binds. That matters: the federal Privacy Act does not cover government schools, which fall under state privacy law instead, so an obligation shown without its scope would be a duty your school may not actually have. Honest about depth: every theme is now covered in every state and territory — governance, student privacy, cyber controls, incident and breach, child safety (including reportable-conduct schemes, mandatory reporting and working-with-children screening) and EdTech/records. Depth is still greatest for Victoria and NSW. Two findings are recorded as honest negatives rather than padded: the Northern Territory has no publicly verifiable school-binding cyber standard, and no mandatory data-breach notification scheme at all. Essential Eight is assessed across ML1–ML3 on real artefacts. Where an obligation is not covered, the posture says so instead of shading it green.
The global angle
The SOCI Act is Australian, and there is no dedicated SOCI catalogue on the engine yet — this page says so rather than shading it green. The lanes serving the obligations mix Australian depth (Essential Eight, ISM) with internationally used instruments — NIST CSF 2.0, CIS Controls v8 — exactly as live on the catalogue.
See it on the real engine
Run the frameworks above against synthetic sample documents now, or tell us where you sit and we'll send a gated, revocable demo link.
Request the demo →Try it now →