Digital Technology Policies for Childcare Services: What Your Regulation 168 Policy Must Include
28 January 2026 · 12 min read
From 1 September 2025, every approved education and care service in Australia must have a written policy and procedures covering the safe use of digital technologies and online environments. This is a requirement under Regulation 168 (Education and care service must have policies and procedures) of the Education and Care Services National Regulations (the National Regulations). If your service wrote a policy to meet the September 2025 deadline, there is a strong chance it needs to be updated again — because further changes to the Education and Care Services National Law (the National Law) regarding personal devices came into effect from 27 February 2026. This article explains exactly what your policy must cover, and what each section needs to say.
Why the Policy Requirement Exists
Digital technology — tablets, cameras, mobile phones, CCTV systems, and online platforms — is embedded in daily life at most education and care services. Educators use devices to capture learning, document programs, and communicate with families. Children use tablets for learning activities. CCTV operates in common areas.
The same technology that supports quality education and care also creates risk if not carefully managed. Critical incidents involving personal devices being used to capture and transmit images of children have caused severe harm. The policy requirement under Regulation 168(2)(ha) is a direct response to this. ACECQA has also released an NQF Online Safety Guide to support services in embedding child-safe practices across all digital environments.
What Regulation 168(2)(ha) Requires Your Policy to Cover
Free download
80 activities, mapped to the frameworks you already use
Free download: 80 activities mapped to EYLF v2.0 and MTOP v2.0 outcomes — ready to use this week.
Your digital technology policy must specifically address each of the following five areas. These are set out in Regulation 168(2)(ha) of the National Regulations. A general "technology use" statement or a social media policy does not satisfy this requirement.
1. The taking, use, storage, and destruction of images and videos of children
This is the most detailed requirement. Your policy must document:
- Who at the service is authorised to take images and videos of children, and using which devices
- What images and videos may be used for (for example, documenting learning in observations, sharing in the parent portal, displaying in newsletters)
- Where images and videos are stored — the specific platform, device, or folder — and who has access to that storage
- How long images and videos are retained before being deleted
- How images and videos are permanently destroyed or deleted when no longer needed, including from cloud backups and shared folders
ACECQA released the National Model Code for Taking Images in ECEC and accompanying guidelines in July 2024. Services are encouraged to adopt the Model Code when developing this section of their policy.
2. Obtaining authorisation from parents and guardians
Your policy must set out the process your service uses to obtain permission from parents and guardians before taking, using, or sharing images or videos of their child. This includes:
- When authorisation is obtained (at enrolment, or at specific points such as before sharing images publicly)
- The form in which authorisation is recorded (signed consent form, enrolment record, digital platform)
- How the service manages withdrawal of consent if a family changes their mind
- Whether consent to share images applies to all contexts (observations, newsletters, social media) or is specific
Review your current enrolment consent forms to ensure they specifically address images and videos and are worded clearly enough to constitute genuine, informed consent.
3. The use of digital devices by children at the service
Your policy must address how children access and use digital devices at the service. This includes:
- What types of devices children may use (tablets, computers, interactive whiteboards)
- The circumstances and supervision arrangements for children using devices
- What content or platforms children are permitted to access
- How the service manages risks associated with internet access, including inappropriate content and online communication
- Age-appropriate considerations (what is appropriate for school-aged children in OSHC will differ from early childhood settings)
4. The use of digital devices issued or owned by the service
If your service provides devices for educator use — cameras, tablets, laptops, or smartphones — the policy must address:
- How service-supplied devices are managed and stored when not in use
- Who is authorised to use service-supplied devices
- What service-supplied devices may be used for and any restrictions on use
- Record-keeping processes for service-supplied devices
- What happens to images and data stored on service-supplied devices when a staff member leaves
ACECQA encourages approved providers to establish and maintain records of all service-supplied devices as part of good governance practice.
5. Optical surveillance devices
If your service uses CCTV or any other optical surveillance equipment, the policy must address:
- Where surveillance devices are located and what areas they cover
- Who has access to footage and under what circumstances
- How long footage is retained before being deleted
- How families and staff are informed that surveillance is in operation
- How footage is used if an incident occurs
If your service does not currently use CCTV, it is still worth acknowledging this in the policy and stating that any future installation would be reviewed in light of this policy.
The February 2026 Update: Personal Device Restrictions Now Apply
If your service wrote a Regulation 168 digital technology policy in September 2025, it may not yet reflect the personal device restrictions that came into effect from 27 February 2026 under changes to the National Law.
From 27 February 2026:
Personal devices are banned for staff working directly with children in centre-based services. Staff must not use or possess a personal device — including mobile phones, personal cameras, smart watches, USB drives, or personal tablets — while working directly with children.
Only service-supplied devices may be used to capture, store, or transmit images of children in a centre-based service.
Limited exceptions apply, including:
- During excursions (where personal devices may be used for essential communication and safety purposes)
- When children are being transported
- In genuine emergency situations
- When the approved provider specifically authorises use for a limited essential purpose
"Working directly with children" for the purposes of these device restrictions is defined in Section 175G of the National Law. Importantly, this definition is different from the general NQF definition — if a staff member is on a break and is not physically present with children, they are not considered to be working directly with children and may use their personal device.
Your policy needs to reflect these National Law requirements alongside the Regulation 168 requirements. A policy that addressed devices generally without specifically restricting personal device use does not meet current obligations.
What your policy should say on this point:
State clearly that staff working directly with children in the service are not permitted to have personal devices on their person, and that only service-supplied devices may be used for any purpose involving the capture, storage, or transmission of images of children. Include the process for authorising exceptions and how those authorisations are recorded.
Visitor procedures also need to be addressed. Visitors to the service must agree in writing, as a condition of entry, that they will not take images or videos of children during their visit. A simple written acknowledgement at sign-in satisfies this requirement.
Common Gaps in Services' Existing Policies
Based on what the policy requirement covers, the most common gaps are:
An existing social media policy has not been updated. A social media policy typically covers what can be posted publicly. Regulation 168(2)(ha) covers a much broader range — storage, destruction, internal use, device management, surveillance. These are different documents addressing different risks.
The policy was written for September 2025 but not updated for February 2026. The personal device restrictions under the National Law changes are a significant addition. Services need to review their policies in light of these requirements.
Visitor procedures are missing. The requirement for visitors to consent in writing not to take images is often overlooked, particularly for committee-run services where committee members or guests regularly attend.
Destruction procedures are vague. Many policies state that images will be "deleted when no longer needed" without specifying a timeframe, a responsible person, or a process for ensuring deletion from cloud backups and shared drives.
CCTV is ignored. Services with surveillance systems often omit it from their digital technology policy entirely, despite Regulation 168(2)(ha) explicitly naming optical surveillance devices.
Children's device use is not addressed. Services that allow children to use tablets or computers for learning activities need to specify the supervision arrangements and content restrictions that apply.
What an Authorised Officer Will Look For
Under Quality Area 2 (Children's Health and Safety) and the updated Element 2.2.3 (Child Safety and Protection), digital technology policies sit within the broader child safety evidence picture. During an assessment and rating visit, authorised officers may:
- Sight your written digital technology policy and confirm it addresses all required areas
- Discuss with staff how they understand and apply the personal device restrictions
- Observe whether personal devices are visible on educators while they are working with children
- Ask how the service manages consent for images and how that consent is recorded
- Ask how images are stored and who has access to them
The policy needs to exist, but staff also need to be able to explain it and demonstrate that it is being followed.
How One Child Supports Photo Consent Management
One Child includes a built-in photo and media consent feature that directly supports one of the requirements under Regulation 168(2)(ha). Parents can opt out of photo sharing for their child, and that consent status is visible to educators within the platform when they are creating observations or attaching media. This creates a documented record of consent decisions linked directly to each child, visible at the point where images are being used.
For the broader policy requirements — device management, destruction schedules, CCTV procedures, and visitor consent — these need to be managed in your written service policies outside of the documentation platform.
Frequently Asked Questions
Does a family day care service need the same digital technology policy as a centre-based service? The Regulation 168(2)(ha) requirement applies to all service types, including family day care. However, the personal device restrictions from 27 February 2026 differ for family day care — family day care educators may have personal devices present but cannot use them to take images or videos of children. Check with your state or territory regulatory authority and refer to ACECQA's specific information sheet for family day care services.
We have a social media policy. Does that satisfy Regulation 168? Not on its own. A social media policy typically addresses what can be shared publicly on platforms like Facebook or Instagram. Regulation 168(2)(ha) requires a policy covering the entire lifecycle of images and videos — taking, use, storage, destruction, consent, devices, and surveillance — which goes well beyond social media.
Can a parent use their phone to take photos of their own child at the service? Parents interacting primarily with their own child may retain their personal devices during that interaction — for example, during a transition or pick-up. However, the policy should address this and note the expectation that parents do not take images of other children. Check your state or territory guidance as some jurisdictions have specific requirements about parent device use on site.
Do we need to tell families about our CCTV system? Yes. If your service uses CCTV or other optical surveillance devices, your digital technology policy must address how families and staff are informed that surveillance is in operation. Most services note the presence of surveillance in their enrolment documentation and display signage at entry points.
Our educators use a shared iPad for documentation. Does that count as a service-supplied device? Yes, a tablet provided by the service and used for the purpose of education and care (including documentation) is a service-supplied device. Your policy should address how that device is managed, stored, and who is authorised to use it.
We are an OSHC service — do the same device rules apply to us? Yes. The personal device restrictions from 27 February 2026 apply to all centre-based education and care services, including OSHC. Staff working directly with school-aged children in before and after school care are subject to the same restrictions as staff in long day care settings.
This article is part of One Child's NQF 2025–2026 compliance series. For the full overview of NQF changes, read our NQF Changes 2025–2026: What Australian Childcare Services Need to Do Right Now.
*Related articles:
- NQF Changes 2025–2026: What Australian Childcare Services Need to Do Right Now
- The new Element 2.2.3 Child Safety and Protection: what it means for your documentation
- Preparing for NQS Assessment and Rating: What Australian Services Need
References
-
ACECQA. Regulatory changes from 1 September 2025 and 1 January 2026.
-
ACECQA. NQF child safety changes from 1 September 2025 and 1 January 2026 (Information Sheet).
-
ACECQA. Safe use of digital technologies and online environments — Policy and procedure guidelines.
-
ACECQA. National Model Code — Taking images in early childhood education and care (July 2024).
Free download
80 activities, mapped to the frameworks you already use
Free download: 80 activities mapped to EYLF v2.0 and MTOP v2.0 outcomes — ready to use this week.
More in NQF Compliance
View all NQF Compliance articles →
The National Early Childhood Worker Register: What Approved Providers Need to Do Before 27 March 2026
A practical guide to the National Early Childhood Worker Register, including who must be registered, what information is required, and the 2...
01 Mar 2026 · 11 min read
NQF Changes 2025–2026: What Australian Childcare Services Need to Do Right Now
A complete guide to the National Quality Framework changes rolling out from September 2025 through 2026, including digital technology polici...
28 Jan 2026 · 15 min read
Finding time to document for the NQF
Time is the number one reason Australian early childhood educators give for not documenting. Here are practical, realistic strategies to hel...
30 Jul 2026 · 9 min read