Skip to main content

Children's Policy

Last Updated: 1 October 2026

1. Purpose, scope and the law that applies

This policy explains how Customer Experience Insight Pty Ltd (ABN 61 634 039 759) trading as WA AI Hub, for the Western Australian AI Hub, protects children. "Child" means anyone under 18, in line with the Convention on the Rights of the Child. It covers our website, membership, events, workshops, programs, online spaces and the people who run them (staff, volunteers and contractors).

We follow:

  • Western Australia: the Children and Community Services Act 2004 (WA), the Working with Children (Criminal Record Checking) Act 2004 (WA), and the Equal Opportunity Act 1984 (WA);
  • Australia: the Australian Privacy Principles (which we follow voluntarily as a small business), the Online Safety Act 2021 (Cth), the Spam Act 2003 (Cth), the Australian Consumer Law, and the National Principles for Child Safe Organisations; and
  • European Union: the General Data Protection Regulation (EU) 2016/679 (GDPR), including Article 8 (children's consent), Article 12 (clear language for children), Article 17 (erasure, including data collected from a child) and Article 22 with Recital 71 (no solely automated decisions about children), and the ePrivacy rules on cookies. We apply these as a standard of good practice, and in full where they apply to us.

Where laws differ, we apply the one that protects the child more.

2. Our commitments

  1. The safety, wellbeing and best interests of children come before the interests of the Hub, its members or any program.
  2. We do not offer memberships, accounts or paid purchases to children, and we do not direct our marketing or website at them.
  3. We involve children only in programs that have been planned and risk-assessed for them, with a parent, guardian or school's authority.
  4. We collect the least personal information about a child that a program needs, keep it for the shortest time, and never use it to profile them, market to them or make automated decisions about them.
  5. We take every concern about a child's safety seriously, act on it, and protect people who raise one from retaliation.
  6. We treat children fairly and without discrimination, including children with disability, First Nations children, children from culturally and linguistically diverse backgrounds, and children who are vulnerable.

3. Age rules

  • Membership, accounts, payments and subscriptions: 18 or over only. A Student membership is for adults enrolled in an educational institution.
  • General events and online spaces: open to adults. A person under 18 may attend only if the event listing says so and a parent or guardian has given written permission or, for a school group, the school has.
  • Programs designed for young people: described in a separate program notice that states the age range, supervision, what personal information we collect, and what consent we need.
  • If we learn that a child has given us personal information without the permission this policy requires, we will stop using it and delete it unless the law requires us to keep it, and we will tell the parent or guardian.

Australian law has no fixed age of consent for privacy. The OAIC's approach is that a person under 18 can consent if they have the maturity to understand what is being asked, and it presumes that a person aged 15 or over has capacity unless there is something to suggest otherwise. For a person under 15, or whenever we are unsure, consent must come from a parent or guardian. Under the GDPR the age of digital consent is set by each EU member state between 13 and 16.

We apply a single, stricter rule: for anyone under 18 we ask for the authority of a parent or guardian (or, for a school group, the school) before we collect their personal information for a program, and for a child under 16 we do not rely on the child's own consent for anything.

  • Consent is specific to the program, in plain language, given by a clear action, and can be withdrawn at any time. Withdrawing does not disadvantage the child.
  • A parent or guardian may ask to see, correct or delete their child's personal information, and a young person may do so for their own. We respond within 30 days (and within one month under the GDPR). We may need to confirm identity first, and we may need to decline where releasing information could put a child at risk.
  • A request to delete a child's information is handled as a priority, including where the child gave it when they were too young to understand the risks.

5. How we handle children's personal information

  • Minimum necessary. We collect only what the program needs (typically a first name, age range or year level, a parent or guardian's contact details, and any health, accessibility or dietary information needed to keep the child safe).
  • Sensitive information. Health, disability or similar information is collected only with consent and only for safety and access. It is shared only with the people running the program who need it, and is deleted after the program unless the law requires us to keep it.
  • No profiling, no advertising. We do not use a child's information for marketing, behavioural advertising, profiling or scoring, and we do not make automated decisions about a child.
  • No data sale or disclosure. We do not sell a child's information or share it for another party's marketing.
  • No tracking. We do not use analytics or cookies to track children on our website. Our website's analytics run only with consent and are not used to identify individuals.
  • Retention. Records about a child's participation are kept for no longer than needed for safety, legal and insurance purposes. Safety-incident records are kept for longer, as the law and insurers require, and held securely.
  • Security and access. Child-related records are restricted to people who need them and who have signed our confidentiality undertaking.
  • Overseas. We apply the same protections wherever information is processed, as described in our Privacy Policy.

This policy adds to, and does not replace, our Privacy Policy. We will provide a short, child-friendly privacy notice for any program that collects information directly from children.

6. Photos, video and recordings

  • We take, publish or share a photo, video or recording in which a child can be identified only with written consent from a parent or guardian that names the use (for example, our website, social media or a report).
  • We never publish a child's full name, school, address, or other details together with their image, and we do not tag children.
  • Attendees at our events must not photograph or record children without permission from their parent or guardian and the organiser.
  • A parent or guardian can withdraw consent at any time, and we will remove the image from our own channels promptly and ask others to do the same.

7. Online safety and artificial intelligence

  • Our online spaces for young people are moderated by vetted adults. No adult may contact a child privately through any channel, except through a parent or guardian or an official program channel that another adult can see.
  • We do not ask a child to create an account with any third-party AI or social media service. Third-party tools often set a minimum age (frequently 13 or 18), and we respect those rules. Where a program uses an AI tool, the facilitator uses it, or it runs under adult supervision with a safe configuration.
  • We teach children about safe and responsible AI, including deepfakes, misinformation, privacy and consent. We do not generate, collect or share sexualised or exploitative material involving children, including AI-generated material, and we will report it.
  • A child, parent or anyone else may report harmful online content or behaviour to us, and to the eSafety Commissioner at esafety.gov.au, which can order the removal of cyberbullying, image-based abuse and illegal content.

8. Keeping children safe at our events and programs

We build our approach on the National Principles for Child Safe Organisations (leadership and culture; children's participation; families and communities; equity; safe recruitment; reporting; education; safe physical and online environments; continuous improvement; and clear policies).

  • Risk assessment. Before any program with children, a written risk assessment covers the venue, the activities, the online elements and who will be present. A program does not run without one.
  • Working with Children Checks. Each adult who does child-related work in Western Australia, whether paid or volunteer, must hold a current Working with Children Check under the Working with Children (Criminal Record Checking) Act 2004 (WA), unless an exemption applies, and we verify it before they start.
  • Recruitment and conduct. We check references, and every person involved with a children's program signs and follows a code of conduct. The code prohibits any form of abuse, grooming, favouritism, inappropriate physical contact, giving gifts or contact outside the program, and alcohol or drug use during a program.
  • Supervision. At least two adults are present at all times in any room or online session with children, and no adult is alone with a child out of sight of others. Adult-to-child ratios are set in the risk assessment for the age group.
  • Parents and guardians. Parents and guardians are told where the program is, who is running it, how to reach us, and how to raise a concern. Children are told, in language they understand, who they can talk to.
  • Training. People involved with a children's program are briefed on this policy and on recognising and reporting concerns before they start, and we refresh that briefing at least annually.
  • Inclusion. We make reasonable adjustments for children with disability and respect the cultural safety of First Nations children and children from diverse backgrounds.

9. Reporting a concern

If a child is in immediate danger, call Triple Zero (000).
  • Anyone can raise a concern about a child's safety or wellbeing with us, by contacting our Child Safety Contact through the contact form (choose the subject "Child safety") or the email address below. We treat it as urgent, record it, and decide with the person raising it what is to be done.
  • We report suspected abuse or neglect to the right authority: Western Australia Police (131 444 for non-urgent matters), or the Department of Communities' Child Protection and Family Support. People in certain roles are mandatory reporters of suspected child sexual abuse under the Children and Community Services Act 2004 (WA), and we support them to meet that duty. Our own staff and volunteers must tell the Child Safety Contact as soon as possible of any concern, and they do not investigate it themselves.
  • We may share information about a child to protect their safety where the law allows or requires it, even without consent.
  • We do not retaliate against anyone who raises a concern in good faith. Raising a concern will never affect a person's membership.
  • If a concern is about one of our people, we remove them from contact with children while it is looked into. We cooperate with police and regulators and, where required, notify the Working with Children Screening Unit.
  • Support for children and families: Kids Helpline on 1800 55 1800 (free and confidential, 24 hours), and Crisis Care on 1800 199 008.

10. Children in the EU and EEA

We do not target our Services at children, in the EU or anywhere else, and we do not offer information society services directly to a child. If a program does involve a child in the EU or EEA, we apply the GDPR in the following ways: we rely on the authority of the holder of parental responsibility for a child below the digital age of consent in the child's country; we explain how we use information in language a child can understand (Article 12); we carry out a data protection impact assessment before any program that processes children's information at scale or uses new technology (Article 35); we give the right to erasure particular weight where the child gave the information (Article 17(1)(f)); and we make no solely automated decisions about children (Recital 71).

11. Responsibility, review and contact

The Management Committee is responsible for this policy. The Child Safety Contact, appointed by the Committee, keeps the register of concerns, makes sure the checks and training in section 8 are done, and reports to the Committee at least annually. We review this policy at least every year, after any serious incident, and when the law changes. We are watching the Children's Online Privacy Code that the OAIC must register by 10 December 2026 and will update this policy and our practices if it applies to us.

Contact the Child Safety Contact through the contact form (subject “Child safety”) or at privacy@wahub.ai, or write to PO Box 8400, South Perth WA 6151. Privacy complaints can also be made to the Office of the Australian Information Commissioner at oaic.gov.au, or, for people in the EU, to the data protection authority in their country.