Data breaches and privacy failures are frequently attributed to weak technical controls, yet a large share of institutional risk originates upstream, in how confidently and correctly staff and users operate the systems that hold sensitive data. This study draws on qualitative case-study evidence from a Ghanaian school using a school management information system to examine information literacy as a human security layer rather than a purely operational competency. Interviews with 25 stakeholders reveal that user unfamiliarity with the system, including difficulty with navigation, resistance to change, and reliance on legacy paper-based habits, was widespread during and after adoption, even among staff directly responsible for records and data entry. The findings are discussed in relation to literature on information literacy, human-factors security, and technology-adoption curves, and situated within a security lens: low system literacy does not only slow adoption, it creates the conditions for data-handling errors, workaround behaviours, and inconsistent application of privacy and security practices that a system’s technical controls cannot compensate for on their own. The study closes by outlining directions for artificial-intelligence-assisted, adaptive literacy training, drawing on recent work in usability-centred design for privacy-preserving configuration, as an underexplored way to close competency gaps in resource-constrained institutions without dedicated training budgets.