Montford International College  |  RTO 46346  |  CRICOS 04334A  |  Version 2.0 — August 2026

PP47 – Privacy Policy

1. Purpose

This policy outlines how MIC collects, uses, discloses, stores, and protects personal information in accordance with the Privacy Act 1988, including the Australian Privacy Principles (APPs). The policy ensures MIC staff and students understand their privacy rights and the organisation’s responsibilities in managing personal and sensitive data.

2. Scope

This policy applies to all MIC personnel, students, and third parties who handle or access personal or sensitive information relating to VET operations, including during enrolment, training, assessment, and support services.

3. Definitions

TermDefinition
Personal InformationInformation that identifies or can reasonably identify an individual (e.g., name, address, phone number, email, USI).
Sensitive InformationInformation such as health status, racial/ethnic origin, disabilities, and other data requiring a higher level of protection.
APPsAustralian Privacy Principles outlined under the Privacy Act 1988.
Data BreachWhen personal information is accessed, disclosed, or lost in an unauthorised or accidental manner.

4. Legislative References

Compliance Requirements (F2025L00355) – Clause 20

Privacy Act 1988 (Cth)

Australian Privacy Principles (APPs)

National VET Data Policy

Student Identifiers Act 2014

5. Policy Statement

MIC is committed to protecting the privacy and confidentiality of all individuals’ personal and sensitive information. MIC will:

Collect only necessary information relevant to enrolment, training, support, and compliance;

Inform individuals about the purpose of collection and how their data will be used;

Obtain written consent before sharing data with third parties unless required by law;

Ensure records are stored securely and retained in accordance with regulatory obligations;

Respond to privacy complaints or requests to access personal data within 10 business days.

6. Collection and Use of Information

Information is collected during the pre-enrolment and enrolment process, including via the Enrolment Form and Pre-Training Review.

Data collected may include:

Identity details (e.g., name, date of birth)

Contact details

USI

Emergency contact details

Health or disability disclosures (with consent)

Citizenship/visa status

This data is used to:

Provide training and assessment

Manage student records

Comply with AVETMISS and other government reporting

Issue AQF certification

7. Storage and Security

All personal data is stored securely using:

Student Management System (SMS) for enrolment and academic records

SharePoint or encrypted cloud storage for administrative files

Access control protocols to restrict data to authorised staff

Backups and IT security measures to protect electronic files

8. Disclosure

MIC may disclose personal information to:

Commonwealth and State Government departments

NCVER and other regulatory bodies

Third-party service providers only with prior written consent

No data will be sold or disclosed for marketing without permission.

9. Access and Correction

Individuals may request access to their records by contacting the Admin Officer.

Any incorrect or outdated personal information will be updated upon verification.

Responses will be provided within 10 business days.

10. Breach Management

In the event of a suspected or confirmed privacy breach:

The RTO Manager will conduct an immediate assessment.

Individuals affected will be notified if required.

The breach will be reported to the Office of the Australian Information Commissioner (OAIC), where applicable.

11. Procedure – Step-by-Step

StepActionResponsible Person
1Collect personal and sensitive information at enrolment with consent.Admin Officer
2Store records in secure systems (SMS, SharePoint, finance tools).Admin Officer
3Restrict data access to authorised personnel.RTO Manager/ Compliance Manager
4Share data with government or third parties only with consent or as required by law.RTO Manager/ Compliance Manager
5Provide access to records upon student request.Admin Officer
6Handle correction requests within 10 business days.Admin Officer
7Investigate and report data breaches promptly.RTO Manager/ Compliance Manager
8Train staff on privacy principles annually.RTO Manager/ Compliance Manager
9Review policy every 12 months or after legislative change.CEO

12. Related Documents

Enrolment Form

Student Handbook

Privacy Consent Form

Data Breach Response Plan

PP34 - Data Privacy and Record Keeping Policy

Academic File Security Procedure

13. Flow chart

Policy flow chart

The complete MIC Policy and Procedure Manual is available on request from info@montford.edu.au. See also the Student Handbook.

Questions about this policy? Email info@montford.edu.au or call +61 3 7048 4870.