Skip to main content
STEM blog
Privacy education
7 min read29 July 2026

Privacy education that students actually use

Telling students to be careful online changes nothing. Auditing the permissions of an app they opened this morning changes a lot.

Fast Emu STEM team

Abstract warnings do not transfer

Students can recite that they should not share personal information and then post their school, suburb and timetable in the same afternoon. The gap is not knowledge — it is that the warning was never attached to anything concrete.

We replace the warning with an audit. Students open the permission screen of an app they already use, list what it can reach, and decide which permissions they would revoke. The decision is theirs, which is why it sticks.

Make the data flow visible

Ask students to draw the journey of one photo: from camera roll, to app, to the company's servers, to whoever the terms allow it to be shared with, to a backup that outlives the account. Most have never pictured the last two steps.

Connect it to Australian context. The Notifiable Data Breaches scheme means organisations must tell people when a breach is likely to cause serious harm, and students have almost certainly received one of those emails at home.

Teach the reporting path, not just the risk

Every student should be able to answer three questions without hesitating: how do I report a message, who at this school do I tell, and what does eSafety do. Rehearse it the way you rehearse a fire drill.

Run this in your school

Curriculum-aligned STEM and cyber safety sessions for Years 3 to 12, delivered by working security engineers.