Queensland guideline clarifies child safety information sharing l The Sector | #childsafety | #kids | #chldern | #parents | #schoolsafey


Queensland organisations working with children have received new guidance on how sensitive information can be lawfully shared to identify risks, coordinate safeguarding responses and prevent harm from escalating.

Released by the Queensland Family and Child Commission (QFCC) in July 2026, the new Information sharing guideline supports the operation of the Child Safe Organisations Act 2024.

 

The guideline applies to information sharing connected with Queensland’s Child Safe Standards, Universal Principle and Reportable Conduct Scheme.

 

Its central message is clear: privacy, confidentiality and organisational uncertainty should not prevent necessary child safeguarding action. At the same time, the legislation does not create an unrestricted power to disclose information.

 

Information must be shared for an authorised child safety purpose, with an authorised recipient and only to the extent reasonably necessary.

 

The Child Safe Organisations Act 2024 establishes a preventative, risk-based and intelligence-led system for safeguarding children in organisational settings.

 

A central feature of that system is the recognition that protecting children is a shared responsibility.

 

Information held by one organisation may appear incomplete or inconclusive when considered alone. When combined with information held by another organisation or regulator, however, it may reveal a pattern of behaviour, an emerging systemic issue or an escalating risk to children.

 

Appropriate information sharing can support:

 

  • earlier identification of risks;
  • coordinated action across organisations and sectors;
  • effective management of reportable allegations;
  • oversight of investigations and organisational responses;
  • identification of patterns of concerning behaviour;
  • improved regulatory decision-making; and
  • intervention before risks escalate into harm.

 

The guideline explains that information sharing plays an important role in preventing harm and ensuring concerns are addressed appropriately and effectively.

 

The guideline supports prescribed entities authorised to share information under the Act, including:

 

  • organisations subject to the Child Safe Standards;
  • reporting entities covered by the Reportable Conduct Scheme;
  • sector regulators;
  • Queensland Government departments;
  • Queensland and interstate police services; and
  • prescribed statutory and oversight bodies.

 

The latter group includes the Queensland Ombudsman, Crime and Corruption Commission, Office of the Public Guardian, Public Sector Commission and Office of the Director of Child Protection Litigation.

 

Organisations should confirm whether they are classified as a child safe entity, reporting entity or both. Different information-sharing provisions apply to the Child Safe Standards and Reportable Conduct Scheme.

 

The framework covers information relating to:

 

  • risks to an individual child or group of children;
  • the conduct of workers;
  • reportable allegations and reportable convictions;
  • the prevention, identification, assessment or management of harm;
  • the progress and findings of investigations;
  • action taken in response to investigation findings;
  • patterns of concerning behaviour; and
  • emerging or systemic child safety risks.

 

Information does not necessarily need to be complete or substantiated before it can be shared.

 

Where authorised, information that remains under investigation may be disclosed if it could help another entity identify, assess or manage a risk to children.

 

Any incomplete or unsubstantiated information must be clearly identified as such. It must not be presented as an established fact or finding.

 

Information sharing must also remain relevant, proportionate and limited to what is reasonably required for the safeguarding purpose.

 

Four principles for information sharing

 

The QFCC identifies four principles that should guide decisions about collecting, using and disclosing information.

 

Child-focus

 

The safety, wellbeing and best interests of children should remain central to every information-sharing decision.

 

Workers and other individuals retain rights to privacy and procedural fairness, including the right to understand and respond to allegations. Those rights must be considered alongside the paramount importance of protecting children from harm.

 

The identity of a child should be protected as far as practicable. Before including identifying details, organisations should consider whether the purpose of the disclosure could be achieved without naming the child.

 

Proactivity

 

Organisations should not automatically wait for a formal request before considering whether relevant information needs to be shared.

 

Another organisation or regulator may not know that the information exists or appreciate its significance. Proactive disclosure may be appropriate where information could reasonably assist an authorised entity to assess or manage a risk to children.

 

This does not mean every concern should be circulated. The information must still fall within the Act’s information-sharing provisions and be disclosed for an authorised purpose.

 

Timeliness

 

Delays in sharing relevant information can weaken interim safeguards, compromise investigations or allow a person continued access to children.

 

Organisations should establish procedures that allow relevant information to be identified, escalated and considered without unnecessary delay.

 

Collaboration

 

The framework encourages cooperation between organisations, the QFCC, sector regulators, Queensland Police Service, Blue Card Services and other safeguarding bodies.

 

These entities may hold different pieces of information about the same individual, organisation or risk. Bringing that information together can provide a clearer picture and support a more coordinated response.

 

Direct and indirect information-sharing pathways

 

The guideline describes two pathways through which authorised information may be shared.

 

Direct pathway

 

Under the direct pathway, information is shared with the QFCC.

 

The Commission acts as a central oversight and intelligence body, receiving and analysing information to identify individual, organisational and systemic risks.

 

The QFCC may also share authorised information with regulators, police, screening bodies or other entities that are better placed to investigate or respond to a concern.

 

The direct pathway does not create an additional mandatory reporting obligation. It operates alongside existing notification requirements.

 

Indirect pathway

 

Under the indirect pathway, authorised entities may share information directly with one another without using the QFCC as an intermediary.

 

This may be appropriate when another organisation or regulator has direct responsibility for children’s safety and is best placed to assess the risk or take immediate protective action.

 

The QFCC may subsequently become aware of the disclosure through initial, interim or final Reportable Conduct Scheme reports or other regulatory arrangements.

 

The guideline makes an important distinction between discretionary information sharing and mandatory reporting.

 

Informally or proactively sharing information does not replace an organisation’s obligation to formally notify the QFCC of a reportable allegation or reportable conviction under the Reportable Conduct Scheme.

 

It also does not replace requirements to report suspected criminal conduct to the Queensland Police Service or make notifications required under other legislation.

 

Organisations should clearly identify the different reporting and information-sharing pathways within their policies and procedures.

 

The guideline provides an early childhood example in which information about reportable conduct in a childcare centre may be shared with the ECEC Regulatory Authority to support its functions under the Education and Care Services National Law (Queensland).

 

For ECEC providers captured by the Child Safe Organisations Act, information sharing may involve the QFCC, the Regulatory Authority, Queensland Police Service, Blue Card Services or another prescribed entity.

 

Providers will need procedures that help decision-makers determine:

 

  • whether the organisation is authorised to share the information;
  • whether the intended recipient is an authorised entity;
  • the child safeguarding purpose of the disclosure;
  • what minimum information is necessary;
  • whether the information is substantiated or remains under investigation;
  • whether identifying the child is necessary;
  • how the information will be shared securely; and
  • what record must be retained.

 

The guideline places important limits on information shared about workers.

 

The framework cannot be used for general employment screening, reference checking or the broad circulation of concerns.

 

Under the Reportable Conduct Scheme provisions, information may be shared with the head of another reporting entity if the person concerned is currently performing work for that entity and the disclosure is otherwise authorised.

 

The definition of worker is broad. It includes employees, volunteers, contractors, subcontractors, consultants, labour-hire workers, trainees, work-experience participants and people involved in an organisation’s management.

 

If an organisation holds serious concerns about someone seeking employment elsewhere, it cannot simply provide the information to a prospective employer under these provisions. The appropriate pathway may instead be to contact the QFCC or the relevant sector regulator.

 

Consent from a child, parent, worker or another person is not always required before information can be lawfully shared under the Act.

 

Information may be disclosed without consent where the disclosure is authorised and reasonably necessary for a permitted child safeguarding purpose.

 

This may include situations where:

 

  • a child is at risk of harm;
  • the information is required for a safeguarding or regulatory function;
  • seeking consent could prejudice an investigation;
  • seeking consent could place a child or another person at risk; or
  • consent has been refused but the disclosure remains necessary and legally authorised.

 

There may still be circumstances in which seeking a person’s knowledge or agreement supports transparency, participation and trust.

 

Consent does not create an unrestricted right to disclose information. The purpose, recipient and scope of the disclosure must still comply with the Act.

 

Although the Act authorises certain disclosures, organisations must continue to consider privacy, confidentiality, human rights, recordkeeping and procedural fairness.

 

Each disclosure should be:

 

  • connected to an authorised child safeguarding purpose;
  • made only to an authorised recipient;
  • limited to the minimum necessary information;
  • proportionate to the sensitivity of the information and level of risk;
  • clear about whether information is alleged, unsubstantiated or established;
  • transmitted and stored securely; and
  • properly documented.

 

The Act provides liability protections for information shared in good faith and without negligence.

 

Those protections do not extend to information that is knowingly false, disclosed recklessly or shared for a purpose unrelated to the Act.

 

The head of entity has a critical role

 

For information sharing connected with the Reportable Conduct Scheme, the Chapter 4 disclosure power rests with the head of the reporting entity.

 

The guideline explains that this information-sharing function cannot be delegated under the Child Safe Organisations Act.

 

Employees may identify information that should be considered for disclosure, but the decision and disclosure must be made by the head of entity.

 

Organisations should therefore have clear internal escalation pathways so relevant information reaches the head of entity promptly.

 

What should organisations do now?

 

Organisations covered by the Act should consider whether they have:

 

  • confirmed their status under the Child Safe Standards and Reportable Conduct Scheme;
  • identified their head of entity;
  • documented who is authorised to share information;
  • created clear internal escalation pathways;
  • distinguished discretionary information sharing from mandatory reporting;
  • updated child protection, privacy and reportable conduct procedures;
  • trained relevant staff in information-sharing responsibilities;
  • implemented secure storage and transmission arrangements;
  • reviewed privacy statements, complaint forms and employment documents; and
  • established an information-sharing decision record.

 

Records should document what information was shared, with whom, for what purpose, under which legal authority and why the disclosure was considered necessary and proportionate.

 

Organisations should also record any considerations relating to urgency, privacy, procedural fairness and risks to children.

 

Formal information-sharing agreements may be useful when information is exchanged regularly, multiple agencies are involved or responsibilities need clarification.

 

However, the absence of a formal agreement should not delay a disclosure that is otherwise authorised and necessary to protect children.

 

The full QFCC Information sharing guideline is available from the Queensland Family and Child Commission.

————————————————


Source link