Montford International College | RTO 46346 | CRICOS 04334A | Version 2.0 — August 2026
This policy outlines how MIC collects, uses, discloses, stores, and protects personal information in accordance with the Privacy Act 1988, including the Australian Privacy Principles (APPs). The policy ensures MIC staff and students understand their privacy rights and the organisation’s responsibilities in managing personal and sensitive data.
This policy applies to all MIC personnel, students, and third parties who handle or access personal or sensitive information relating to VET operations, including during enrolment, training, assessment, and support services.
| Term | Definition |
|---|---|
| Personal Information | Information that identifies or can reasonably identify an individual (e.g., name, address, phone number, email, USI). |
| Sensitive Information | Information such as health status, racial/ethnic origin, disabilities, and other data requiring a higher level of protection. |
| APPs | Australian Privacy Principles outlined under the Privacy Act 1988. |
| Data Breach | When personal information is accessed, disclosed, or lost in an unauthorised or accidental manner. |
Compliance Requirements (F2025L00355) – Clause 20
Privacy Act 1988 (Cth)
Australian Privacy Principles (APPs)
National VET Data Policy
Student Identifiers Act 2014
MIC is committed to protecting the privacy and confidentiality of all individuals’ personal and sensitive information. MIC will:
Collect only necessary information relevant to enrolment, training, support, and compliance;
Inform individuals about the purpose of collection and how their data will be used;
Obtain written consent before sharing data with third parties unless required by law;
Ensure records are stored securely and retained in accordance with regulatory obligations;
Respond to privacy complaints or requests to access personal data within 10 business days.
Information is collected during the pre-enrolment and enrolment process, including via the Enrolment Form and Pre-Training Review.
Data collected may include:
Identity details (e.g., name, date of birth)
Contact details
USI
Emergency contact details
Health or disability disclosures (with consent)
Citizenship/visa status
This data is used to:
Provide training and assessment
Manage student records
Comply with AVETMISS and other government reporting
Issue AQF certification
All personal data is stored securely using:
Student Management System (SMS) for enrolment and academic records
SharePoint or encrypted cloud storage for administrative files
Access control protocols to restrict data to authorised staff
Backups and IT security measures to protect electronic files
MIC may disclose personal information to:
Commonwealth and State Government departments
NCVER and other regulatory bodies
Third-party service providers only with prior written consent
No data will be sold or disclosed for marketing without permission.
Individuals may request access to their records by contacting the Admin Officer.
Any incorrect or outdated personal information will be updated upon verification.
Responses will be provided within 10 business days.
In the event of a suspected or confirmed privacy breach:
The RTO Manager will conduct an immediate assessment.
Individuals affected will be notified if required.
The breach will be reported to the Office of the Australian Information Commissioner (OAIC), where applicable.
| Step | Action | Responsible Person |
|---|---|---|
| 1 | Collect personal and sensitive information at enrolment with consent. | Admin Officer |
| 2 | Store records in secure systems (SMS, SharePoint, finance tools). | Admin Officer |
| 3 | Restrict data access to authorised personnel. | RTO Manager/ Compliance Manager |
| 4 | Share data with government or third parties only with consent or as required by law. | RTO Manager/ Compliance Manager |
| 5 | Provide access to records upon student request. | Admin Officer |
| 6 | Handle correction requests within 10 business days. | Admin Officer |
| 7 | Investigate and report data breaches promptly. | RTO Manager/ Compliance Manager |
| 8 | Train staff on privacy principles annually. | RTO Manager/ Compliance Manager |
| 9 | Review policy every 12 months or after legislative change. | CEO |
Enrolment Form
Student Handbook
Privacy Consent Form
Data Breach Response Plan
PP34 - Data Privacy and Record Keeping Policy
Academic File Security Procedure
The complete MIC Policy and Procedure Manual is available on request from info@montford.edu.au. See also the Student Handbook.
Questions about this policy? Email info@montford.edu.au or call +61 3 7048 4870.