Privacy Policy
WA Advanced Training Academy (WAATA) is committed to maintaining the privacy and confidentiality of its RTO personnel and participant records. WAATA complies with the Privacy Act 1988 including the 13 Australian Privacy Principles (APPs) as outlined in the Privacy Amendment (Enhancing Privacy Protection) Act 2012.
As part of its governance, risk management and compliance framework, WAATA regularly assesses privacy risks associated with the collection, use, disclosure, storage and destruction of personal information. Privacy risks are monitored through internal review processes, cyber security controls, staff training, incident reporting systems and documented procedures.
WAATA maintains a Privacy Management Framework, including a Data Breach Response Procedure, to ensure compliance with the Privacy Act 1988, the Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) Scheme. Appropriate controls have been implemented to protect personal information throughout its lifecycle and to ensure that any privacy incident is identified, assessed, managed and reported where required by law.
Providing an overall framework for our privacy practices, WAATA has developed and implemented this APP Privacy Policy.
WAATA manages personal information in an open and transparent way. This is evident in the implementation of practices, procedures and systems outlined in this policy, that ensure our compliance with the APPs and any binding registered APP code and provide suitable procedures for WAATA personnel to be able to deal with related inquiries and complaints that may be received from time to time.
The following sections of this policy outline how we manage personal information.
Australian Privacy Principle 1 – Open and transparent management of personal information
Purposes for information collection, retention, use and disclosure
WAATA retains a record of personal information about all individuals with whom we undertake any form of business activity. WAATA must collect, hold, use and disclose information from our clients and stakeholders for a range of purposes, including but not limited to:
- Providing services to clients;
- Managing employee and contractor teams;
- Conducting internal business functions and activities; and
- Requirements of stakeholders.
As a Registered Training Organisation (RTO), WAATA is regulated by the Training Accreditation Council (TAC) and is required to collect, hold, use and disclose a wide range of personal and sensitive information on participants in nationally recognised training programs.
Unique Student Identifiers (USIs)
As a Registered Training Organisation (RTO), WAATA is required under the Student Identifiers Act 2014 to collect and verify a Unique Student Identifier (USI) for all students undertaking nationally recognised training and assessment, unless an exemption applies.
WAATA collects USIs to:
- Meet Commonwealth legislative requirements;
- Report nationally recognised training activity;
- Issue Statements of Attainment and Qualifications;
- Enable students to access and manage their training records through the national USI system; and
- Verify student identity where required for training administration purposes.
WAATA takes reasonable steps to protect USI information from unauthorised access, use, disclosure, modification or loss. Access to USI information is restricted to authorised personnel who require access to perform their duties.
WAATA may disclose USI information where authorised or required by law, including to:
- The Student Identifiers Registrar;
- The National Centre for Vocational Education Research (NCVER);
- Commonwealth and State Government departments and agencies;
- Regulatory authorities; and
- Other organisations authorised under the Student Identifiers Act 2014.
Further information regarding the collection, use and disclosure of USIs is available from the USI Office at https://www.usi.gov.au.
This information requirement is outlined in the National Vocational Education and Training Regulator Act 2011 and associated legislative instruments. In particular, the legislative instruments:
- Student Identifiers Act 2014;
- Standards for Registered Training Organisations (RTOs) 2025; and
- Data Provision Requirements 2012.
It is noted that WAATA is also bound by various State Government Acts requiring similar information collection, use and disclosure (particularly Education Act(s), Vocational Education & Training Act(s) and Traineeship & Apprenticeships Act(s) relevant to state jurisdictions of WAATA operations).
It is further noted that, aligned with these legislative requirements, WAATA delivers services through a range of Commonwealth and State Government funding contract agreement arrangements, which also include various information collection and disclosure requirements.
Disclosure of Training and Assessment Information
As a Registered Training Organisation, WAATA may be required to collect, use and disclose student information to meet its legislative, regulatory, contractual and reporting obligations.
Depending on the nature of the training being undertaken, personal information may be disclosed to:
- The National Centre for Vocational Education Research (NCVER);
- The Student Identifiers Registrar;
- The Training Accreditation Council (TAC);
- Commonwealth, State and Territory Government departments and agencies;
- Funding bodies and contract managers;
- Apprenticeship and Traineeship support organisations;
- Employers or workplace supervisors where authorised by the student or required by a training contract;
- WorkSafe Western Australia and other licensing authorities for the administration of High-Risk Work Licence training and assessment activities;
- Third-party service providers engaged to support training, assessment or student administration activities; and
- Other organisations where disclosure is authorised or required by law.
Such disclosures are undertaken only where reasonably necessary to deliver training services, comply with legislative or contractual obligations, issue qualifications or statements of attainment, maintain regulatory compliance, or support student outcomes.
Kinds of personal information collected and held
The following types of personal information are generally collected, depending on the need for service delivery:
- Contact details;
- Employment details;
- Educational background;
- Demographic Information;
- Course progress and achievement information; and
- Financial billing information;
- Unique Student Identifier (USI) information;
- CCTV images and recordings collected at WAATA facilities and training locations;
The following types of sensitive information may also be collected and held:
- Identity details;
- Employee details & HR information;
- Complaint or issue information;
- Disability status & other individual needs;
- Indigenous status;
Where WAATA collects personal information of more vulnerable segment of the community (such as children), additional practices and procedures are also followed. Please refer to WAATA’s Working with Children Policy and Procedures for further information.
How personal information is collected
WAATA’s usual approach to collecting personal information is to collect any required information directly from the individuals concerned. This may include the use of forms (such as registration forms, enrolment forms or service delivery records) and the use of web based systems (such as online enquiry forms, web portals or internal operating systems).
WAATA does receive solicited and unsolicited information from third party sources in undertaking service delivery activities. This may include information from such entities as:
- Governments (Commonwealth, State or Local);
- Australian Apprenticeships Centres;
- Employers (and their representatives), Job Network Providers, Schools, Guardians; and
- Service providers such as credit agencies and background check providers.
How personal information is held
WAATA’s usual approach to holding personal information includes robust storage and security measures at all times. Information on collection is:
- As soon as practical converted to electronic means;
- Stored in secure, password protected systems, such as financial system, student management system; file storage and
- Monitored for appropriate authorised use at all times.
Only authorised personnel are provided with login information to each system, with system access limited to only those relevant to their specific role. WAATA stores information using a combination of secure cloud-based and locally managed systems. Reasonable steps are taken to ensure all systems incorporate appropriate security controls including password protection, multi-factor authentication, encryption, access controls, monitoring and backup processes.
Destruction of paper-based records occurs as soon as practicable in every matter, through the use of secure shredding and destruction services at all WAATA sites.
Individual information held across systems is linked through a WAATA allocated identification number for each individual.
Retention and Destruction of Information
WA Advanced Training Academy (WAATA) retains personal information only for as long as necessary to fulfil its legal, regulatory, contractual and operational obligations.
Student information is primarily stored electronically within WAATA’s secure Student Management System (aXcelerate) and associated authorised business systems. Access to student records is restricted to authorised personnel and protected through appropriate security controls.
In accordance with the Standards for Registered Training Organisations (RTOs), student records relating to nationally recognised training, including Statements of Attainment and Qualifications issued, are retained for the period required by legislation and regulatory requirements. Certain records may be retained permanently where required to meet these obligations.
Where personal information is no longer required and there is no legal requirement to retain it, WAATA will take reasonable steps to securely destroy or de-identify the information in accordance with its records management and privacy procedures.
Paper-based records containing personal information are digitised where appropriate and securely stored or destroyed using approved secure disposal methods. Disposal of records is undertaken in a manner that protects the privacy and confidentiality of individuals.
In the event that WAATA ceases operations as a Registered Training Organisation, student records required by legislation will be transferred to the appropriate regulatory authority or designated repository in accordance with applicable legislative and regulatory requirements.
Accessing and seeking correction of personal information
WAATA confirms all individuals have a right to request access to their personal information held and to request its correction at any time. In order to request access to personal records, individuals are to make contact with:
WAATA Compliance Manager / Privacy Officer
08 92506022
The Compliance Manager acts as WAATA’s nominated Privacy Officer and is responsible for overseeing privacy compliance, data breach management and privacy-related enquiries.
A number of third parties, other than the individual, may request access to an individual’s personal information. Such third parties may include employers, parents or guardians, schools, Australian Apprenticeships Centres, Governments (Commonwealth, State or Local) and various other stakeholders.
In all cases where access is requested, WAATA will ensure that:
- Parties requesting access to personal information are robustly identified and vetted;
- Where legally possible, the individual to whom the information relates will be contacted to confirm consent (if consent not previously provided for the matter); and
- Only appropriately authorised parties, for valid purposes, will be provided access to the information.
Complaints about a breach of the APPs or a binding registered APP code
If an individual feels that WAATA may have breached one of the APPs or a binding registered APP Code, they should refer to the Privacy Complaints Procedure contained within this policy.
Likely overseas disclosures
Personal information may be stored, processed or backed up in overseas jurisdictions through approved cloud-based service providers. WAATA takes reasonable steps to ensure such providers maintain privacy, confidentiality and security protections consistent with Australian privacy requirements.
Making our APP Privacy Policy available
WAATA provides our APP Privacy Policy available free of charge, with all information being publicly available from the Privacy link on our website at www.waata.com.au/privacy. This website information is designed to be accessible as per web publishing accessibility guidelines, to ensure access is available to individuals with special needs (such as individuals with vision impairment).
In addition, this APP Privacy Policy is:
- Prominently displayed at WAATA’s premises;
- Included within our RTO Handbook;
- Noted within the text or instructions at all information collection points (such as informing individuals during a telephone call of how the policy may be accessed, in cases where information collection is occurring); and
- Available for distribution free of charge on request, as soon as possible after the request is received, including in any particular format requested by the individual as is reasonably practical.
If, in the unlikely event the APP Privacy Policy is not able to be provided in a particular format requested by an individual, we will explain the circumstances around this issue with the requester and seek to ensure that another appropriate method is provided.
Review and Update of this APP Privacy Policy
WAATA reviews this APP Privacy Policy:
- This policy will be formally reviewed at least annually and whenever legislative, regulatory or operational changes occur;
- As a part of any external audit of our operations that may be conducted by various government agencies as a part of our registration as an RTO or in normal business activities; and
- As a component of each and every complaint investigation process where the complaint is related to a privacy matter.
Where this policy is updated, changes to the policy are widely communicated to stakeholders through internal personnel communications, meetings, training and documentation, and externally through publishing of the policy on WAATA’s website and other relevant documentation (such as our RTO Handbook) for clients.
Australian Privacy Principle 2 – Anonymity and pseudonymity
WAATA provides individuals with the option of not identifying themselves, or of using a pseudonym, when dealing with us in relation to a particular matter, whenever practical. This includes providing options for anonymous dealings in cases of general course enquiries or other situations in which an individuals’ information is not required to complete a request.
Individuals may deal with us by using a name, term or descriptor that is different to the individual’s actual name wherever possible. This includes using generic email addresses that does not contain an individual’s actual name, or generic user names when individuals may access a public component of our website or enquiry forms.
WAATA only stores and links pseudonyms to individual personal information in cases where this is required for service delivery (such as system login information) or once the individual’s consent has been received.
Individuals are advised of their opportunity to deal anonymously or by pseudonym with us where these options are possible.
Requiring identification
WAATA must require and confirm identification however in service delivery to individuals for nationally recognised course programs. We are authorised by Australian law to deal only with individuals who have appropriately identified themselves. That is, it is a Condition of Registration for all RTOs under the National Vocational Education and Training Regulator Act 2011 that we identify individuals and their specific individual needs on commencement of service delivery, and collect and disclose Australian Vocational Education and Training Management of Information Statistical Standard (AVETMISS) data on all individuals enrolled in nationally recognised training programs. Other legal requirements, as noted earlier in this policy, also require considerable identification arrangements.
There are also other occasions also within our service delivery where an individual may not have the option of dealing anonymously or by pseudonym, as identification is practically required for us to effectively support an individual’s request or need.
Australian Privacy Principle 3 — Collection of solicited personal information
WAATA only collects personal information that is reasonably necessary for our business activities.
Closed Circuit Television (CCTV)
WAATA utilises Closed Circuit Television (CCTV) systems at selected training facilities and operational locations for legitimate business purposes including:
- Maintaining the safety and security of students, staff, contractors and visitors;
- Protecting WAATA property, equipment and assets;
- Assisting with the investigation of incidents, complaints, accidents, misconduct or security breaches;
- Supporting workplace health and safety obligations; and
- Assisting with regulatory, insurance or legal requirements where applicable.
CCTV surveillance is conducted in a manner that is reasonable, proportionate and consistent with applicable privacy obligations. Signage is displayed at monitored locations to notify individuals that CCTV is in operation.
Access to CCTV recordings is restricted to authorised personnel and recordings are only viewed, used or disclosed where there is a legitimate operational, legal, regulatory or safety-related purpose.
CCTV recordings are securely stored and retained only for as long as reasonably required, unless a longer retention period is necessary for the investigation of an incident, legal proceedings, insurance matters or compliance obligations.
We only collect sensitive information in cases where the individual consents to the sensitive information being collected, except in cases where we are required to collect this information by law, such as outlined earlier in this policy.
All information we collect is collected only by lawful and fair means.
We only collect solicited information directly from the individual concerned, unless it is unreasonable or impracticable for the personal information to only be collected in this manner.
Australian Privacy Principle 4 – Dealing with unsolicited personal information
WAATA may from time to time receive unsolicited personal information. Where this occurs we promptly review the information to decide whether or not we could have collected the information for the purpose of our business activities. Where this is the case, we may hold, use and disclose the information appropriately as per the practices outlined in this policy.
Where we could not have collected this information (by law or for a valid business purpose) we immediately destroy or de-identify the information (unless it would be unlawful to do so).
Australian Privacy Principle 5 – Notification of the collection of personal information
Whenever WAATA collects personal information about an individual, we take reasonable steps to notify the individual of the details of the information collection or otherwise ensure the individual is aware of those matters. This notification occurs at or before the time of collection, or as soon as practicable afterwards.
Our notifications to individuals on data collection include:
- WAATA’s identity and contact details, including the position title, telephone number and email address of a contact who handles enquiries and requests relating to privacy matters;
- The facts and circumstances of collection such as the date, time, place and method of collection, and whether the information was collected from a third party, including the name of that party;
- If the collection is required or authorised by law, including the name of the Australian law or other legal agreement requiring the collection;
- The purpose of collection, including any primary and secondary purposes;
- The consequences for the individual if all or some personal information is not collected;
- Other organisations or persons to which the information is usually disclosed, including naming those parties;
- Whether we are likely to disclose the personal information to overseas recipients, and if so, the names of the recipients and the countries in which such recipients are located.
- A link to this APP Privacy Policy on our website or explain how it may be accessed; and
- Advice that this APP Privacy Policy contains information about how the individual may access and seek correction of the personal information held by us; and how to complain about a breach of the APPs, or any registered APP code, and how we will deal with such a complaint.
Where possible, we ensure that the individual confirms their understanding of these details, such as through signed declarations, website form acceptance of details or in person through questioning.
Collection from third parties
Where WAATA collects personal information from another organisation, we:
- Confirm whether the other organisation has provided the relevant notice above to the individual; or
- Whether the individual was otherwise aware of these details at the time of collection; and
- If this has not occurred, we will undertake this notice to ensure the individual is fully informed of the information collection.
Website, Online Services and Digital Tracking
WAATA’s website and online services may collect certain information automatically when individuals visit or interact with our websites, portals, online forms or digital communications.
This information may include:
- Internet Protocol (IP) addresses;
- Browser type and device information;
- Date and time of website visits;
- Pages viewed and resources accessed;
- Referral websites and search terms used; and
- Information submitted through online forms.
WAATA may use cookies, analytics tools and similar technologies to:
- Improve website functionality and user experience;
- Monitor website performance and security;
- Analyse website traffic and usage patterns;
- Support marketing and communication activities; and
- Improve the delivery of training and administrative services.
Individuals may configure their web browser settings to refuse or manage cookies. However, doing so may affect the functionality of some website features.
Where third-party services such as social media platforms, online advertising providers, learning management systems or analytics providers are used, information may be collected and processed in accordance with the privacy policies of those providers.
WAATA does not use website tracking technologies to collect sensitive personal information unless it is voluntarily provided by the individual through an online form or service.
WAATA may use digital communication and marketing platforms to communicate with prospective and current students. Individuals may opt out of marketing communications at any time using the unsubscribe options provided or by contacting WAATA directly.
Australian Privacy Principle 6 – Use or disclosure of personal information
WAATA only uses or discloses personal information it holds about an individual for the particular primary purposes for which the information was collected.
Artificial Intelligence and Automated Technologies
WAATA may utilise approved Artificial Intelligence (AI) and automated technologies to support administrative, educational, compliance, marketing and business operations.
Where AI tools are used, WAATA takes reasonable steps to ensure that:
- Personal information is only used for legitimate business purposes;
- Confidential or sensitive information is not disclosed to unauthorised third-party systems;
- Appropriate security and privacy controls are in place;
- Information entered into AI systems is limited to what is reasonably necessary for the intended purpose;
- WAATA will not knowingly use personal information obtained from students, staff, contractors or clients to train publicly available Artificial Intelligence models;
- Human oversight is maintained over decisions affecting students, staff, contractors or clients; and
- The use of AI technologies remains consistent with applicable privacy, confidentiality and regulatory obligations.
WAATA personnel are required to follow organisational policies and procedures governing the use of AI and other emerging technologies. The use of AI does not replace professional judgement, regulatory obligations, training and assessment requirements, or decision-making responsibilities.
WAATA regularly reviews emerging technologies to ensure their use remains appropriate, secure and aligned with industry best practice and legislative requirements.
Secondary purposes in cases where:
- An individual consented to a secondary use or disclosure;
- An individual would reasonably expect the secondary use or disclosure, and that is directly related to the primary purpose of collection; or
- Using or disclosing the information is required or authorised by law.
Requirement to make a written note of use or disclosure for this secondary purpose
If WAATA uses or discloses personal information in accordance with an ‘enforcement related activity’ we will make a written note of the use or disclosure, including the following details:
- The date of the use or disclosure;
- Details of the personal information that was used or disclosed;
- The enforcement body conducting the enforcement related activity;
- If the organisation used the information, how the information was used by the organisation;
- The basis for our reasonable belief that we were required to disclose the information.
Australian Privacy Principle 7 – Direct marketing
WAATA does not use or disclose the personal information that it holds about an individual for the purpose of direct marketing, unless:
- The personal information has been collected directly from an individual, and the individual would reasonably expect their personal information to be used for the purpose of direct marketing; or
- The personal information has been collected from a third party, or from the individual directly, but the individual does not have a reasonable expectation that their personal information will be used for the purpose of direct marketing; and
- We provide a simple method for the individual to request not to receive direct marketing communications (also known as ‘opting out’).
On each of our direct marketing communications, WAATA provides a prominent statement that the individual may request to opt out of future communications, and how to do so.
An individual may also request us at any stage not to use or disclose their personal information for the purpose of direct marketing, or to facilitate direct marketing by other organisations. We comply with any request by an individual promptly and undertake any required actions for free.
We also, on request, notify an individual of our source of their personal information used or disclosed for the purpose of direct marketing unless it is unreasonable or impracticable to do so.
Australian Privacy Principle 8 – Cross-border disclosure of personal information
Before WAATA discloses personal information about an individual to any overseas recipient, we take reasonable steps to ensure that the recipient does not breach any privacy matters in relation to that information.
Australian Privacy Principle 9 – Adoption, use or disclosure of government related identifiers
WAATA does not adopt, use, or disclose a government related identifier related to an individual except:
- In situations required by Australian law or other legal requirements;
- Where reasonably necessary to verify the identity of the individual;
- Where reasonably necessary to fulfil obligations to an agency or a State or Territory authority; or
- As prescribed by regulations.
Australian Privacy Principle 10 – Quality of personal information
WAATA takes reasonable steps to ensure that the personal information it collects is accurate, up-to-date and complete. We also take reasonable steps to ensure that the personal information we use or disclose is, having regard to the purpose of the use or disclosure, accurate, up-to-date, complete and relevant. This is particularly important where:
- When we initially collect the personal information; and
- When we use or disclose personal information.
We take steps to ensure personal information is factually correct. In cases of an opinion, we ensure information takes into account competing facts and views and makes an informed assessment, providing it is clear this is an opinion. Information is confirmed up-to-date at the point in time to which the personal information relates.
Quality measures in place supporting these requirements include:
- Internal practices, procedures and systems to audit, monitor, identify and correct poor quality personal information (including training staff in these practices, procedures and systems);
- Protocols that ensure personal information is collected and recorded in a consistent format, from a primary information source when possible;
- Ensuring updated or new personal information is promptly added to relevant existing records;
- Providing individuals with a simple means to review and update their information on an on-going basis through our online portal;
- Reminding individuals to update their personal information at critical service delivery points (such as completion) when we engage with the individual;
- Contacting individuals to verify the quality of personal information where appropriate when it is about to used or disclosed, particularly if there has been a lengthy period since collection; and
- Checking that a third party, from whom personal information is collected, has implemented appropriate data quality practices, procedures and systems.
Australian Privacy Principle 11 — Security of personal information
WAATA takes active measures to consider whether we are able to retain personal information we hold, and also to ensure the security of personal information we hold. This includes reasonable steps to protect the information from misuse, interference and loss, as well as unauthorised access, modification or disclosure.
Information Security Controls
WAATA implements a range of technical, physical and administrative security controls to protect personal information. These controls may include:
- Role-based access controls to ensure personnel can only access information necessary for their duties;
- Strong password requirements and password management practices;
- Multi-factor authentication (MFA) for systems containing personal information where available and appropriate;
- Endpoint protection, antivirus and malware detection software;
- Secure backup and disaster recovery processes;
- Encryption and secure transmission of information where appropriate;
- Security monitoring and audit logging; and
- Regular cyber security awareness training for personnel.
These controls are reviewed periodically to ensure they remain effective and aligned with current cyber security threats and industry best practice.
We destroy or de-identify personal information held once the information is no longer needed for any purpose for which the information may be legally used or disclosed.
Access to WAATA offices and work areas is limited to our personnel only – visitors to our premises must be authorised by relevant personnel and are accompanied at all times. With regard to any information in a paper based form, we maintain storage of records in an appropriately secure place to which only authorised individuals have access.
Regular staff training and information bulletins are conducted with WAATA personnel on privacy issues, and how the APPs apply to our practices, procedures and systems. Training is also included in our personnel induction practices.
We conduct ongoing internal audits (at least annually and as needed) of the adequacy and currency of security and access practices, procedures and systems implemented.
Notifiable Data Breaches Scheme
WAATA is committed to protecting the personal information it holds from misuse, interference, loss, unauthorised access, modification and disclosure.
In the event of a suspected or actual data breach involving personal information, WAATA will take immediate steps to contain and assess the incident in accordance with its Data Breach Response Procedure.
Where WAATA determines that an eligible data breach has occurred and is likely to result in serious harm to affected individuals, WAATA will comply with the Notifiable Data Breaches Scheme established under the Privacy Act 1988 by:
- Undertaking a prompt assessment of the breach;
- Taking reasonable steps to contain and remediate the breach;
- Notifying affected individuals where required;
- Notifying the Office of the Australian Information Commissioner (OAIC) where required;
- Maintaining records of data breaches and corrective actions implemented.
All WAATA personnel are required to immediately report any actual or suspected privacy breach, cyber security incident or unauthorised disclosure of personal information to the Privacy Officer.
WAATA will regularly review and test its data breach response processes to ensure ongoing compliance with legislative requirements and industry best practice.
Australian Privacy Principle 12 — Access to personal information
Where WAATA holds personal information about an individual, we provide that individual access to the information on their request. In processing requests, we:
- Ensure through confirmation of identity that the request is made by the individual concerned, or by another person who is authorised to make a request on their behalf;
- Respond to a request for access:
- Within 14 calendar days, when notifying our refusal to give access, including providing reasons for refusal in writing, and the complaint mechanisms available to the individual; or
- Within 30 calendar days, by giving access to the personal information that is requested in the manner in which it was requested.
- Provide information access free of charge.
Australian Privacy Principle 13 – Correction of personal information
WAATA takes reasonable steps to correct personal information we hold, to ensure it is accurate, up-to-date, complete, relevant and not misleading, having regard to the purpose for which it is held.
Individual Requests
On an individual’s request, we:
- Correct personal information held; and
- Notify any third parties of corrections made to personal information, if this information was previously provided to these parties.
In cases where we refuse to update personal information, we:
- Give a written notice to the individual, including the reasons for the refusal and the complaint mechanisms available to the individual;
- Upon request by the individual whose correction request has been refused, take reasonable steps to associate a statement with the personal information that the individual believes it to be inaccurate, out-of-date, incomplete, irrelevant or misleading;
- Respond within 14 calendar days to these requests; and
- Complete all actions free of charge.
Correcting at WAATA’s initiative
We take reasonable steps to correct personal information we hold in cases where we are satisfied that the personal information held is inaccurate, out-of-date, incomplete, irrelevant or misleading (that is, the information is faulty). This awareness may occur through collection of updated information, in notification from third parties or through other means.
Request for Records Access Procedure
Individuals or third parties may at any stage request access to records held by WAATA relating to their personal information. The following procedure is followed on each individual request for access:
- A request for access is provided by the requester, with suitable information provided to be able to:
- Identify the individual concerned;
- Confirm their identity; and
- Identify the specific information that they are requesting access to.
This request may be in any form, or preferably using WAATAs Records Access or Update Request Form.
- Upon receiving a request for access, WAATA then:
- Confirms the identity of the individual or party requesting access;
- Confirms that this individual or party is appropriately authorised to receive the information requested;
- Searches the records that we possess or control to assess whether the requested personal information is contained in those records; and
- Collates any personal information found ready for access to be provided.
Confirming identity
WAATA personnel must be satisfied that a request for personal information is made by the individual concerned, or by another person who is authorised to make a request on their behalf. The minimum amount of personal information needed to establish an individual’s identity is sought, which is generally an individual’s name, date of birth, last known address and signature.
When meeting the requesting party in person, identification may be sighted.
If confirming details over a telephone conversation, questions regarding the individual’s name, date of birth, last known address or service details may be confirmed before information is provided.
- Once identity and access authorisation is confirmed, and personal information is collated, access is provided to the requester within 30 calendar days of receipt of the original request. We will provide access to personal information in the specific manner or format requested by the individual, wherever it is reasonable and practicable to do so, free of charge.
Where the requested format is not practical, we consult with the requester to ensure a format is provided that meets the requester’s needs.
- If the identity or authorisation access cannot be confirmed, or there is another valid reason why WAATA is unable to provide the personal information, refusal to provide access to records will be provided to the requester, in writing. Our notification will include reason(s) for the refusal, and the complaint mechanisms available to the individual. Such notifications are provided to the requester within 30 calendar days of receipt of the original request.
Request for Records Update Procedure
Individuals or third parties may at any stage request that their records held by WAATA relating to their personal information be updated. The following procedure is followed on each individual request for records updates:
- A request for records update is provided by the requester, with suitable information provided to be able to:
- Identify the individual concerned;
- Confirm their identity; and
- Identify the specific information that they are requesting be updated on their records.
This request may be in any form, or preferably using WAATAs Records Access or Update Request Form.
- Upon receiving a request for records update, WAATA then:
- Confirms the identity of the individual or party to whom the record relates;
- Searches the records that we possess or control to assess whether the requested personal information is contained in those records; and
- Assesses the information already on record, and the requested update, to determine whether the requested update should proceed.
Assessing Update
WAATA personnel assess the relevant personal information we hold, and the requested updated information, to determine which version of the information is considered accurate, up-to-date, complete, relevant and not misleading, having regard to the purpose for which it is held.
This may include checking information against other records held by us, or within government databases, in order to complete an assessment of the correct version of the information to be used.
- Once identity and information assessment is confirmed, personal information is:
- Updated, free of charge, within 14 calendar days of receipt of the original request; and
- Notified to any third parties of corrections made to personal information, if this information was previously provided to these parties.
- If the identity of the individual cannot be confirmed, or there is another valid reason why WAATA is unable to update the personal information, refusal to update records will be provided to the requester in writing, free of charge, within 14 calendar days.
Our notification will include the reasons for the refusal and the complaint mechanisms available to the individual.
- Upon request by the individual whose correction request has been refused, we will also take reasonable steps to associate a ‘statement’ with the personal information that the individual believes it to be inaccurate, out-of-date, incomplete, irrelevant or misleading. This statement will be applied, free of charge, to all personal information relevant across WAATA systems within 30 calendar days of receipt of the statement request.
Privacy Complaints Procedure
WA Advanced Training Academy (WAATA) is committed to protecting the privacy of personal information and responding promptly and fairly to any privacy concerns or complaints.
If an individual believes that WAATA has breached its obligations under the Privacy Act 1988, the Australian Privacy Principles (APPs), or has otherwise mishandled personal information, they may lodge a privacy complaint.
Step 1 – Contact WAATA
Individuals are encouraged to raise privacy concerns directly with WAATA in the first instance to allow the matter to be reviewed and resolved promptly.
Privacy complaints should be submitted in writing and include as much detail as possible regarding the circumstances of the complaint.
Privacy Officer
WA Advanced Training Academy
Email: admin@waata.com.au
Phone: (08) 9250 6022
PO Box 1181
Midland WA 6936
Step 2 – Investigation
Upon receipt of a privacy complaint, WAATA will:
- Acknowledge receipt of the complaint;
- Investigate the circumstances of the matter;
- Review relevant records, policies and procedures;
- Consult with relevant personnel where required; and
- Provide a written response outlining the findings and any corrective actions identified.
WAATA aims to respond to privacy complaints within 30 calendar days of receiving the complaint. Where additional time is required, the complainant will be advised of the expected timeframe.
Step 3 – External Privacy Complaint
If the complainant is not satisfied with WAATA’s response, they may refer the matter to the Office of the Australian Information Commissioner (OAIC).
Office of the Australian Information Commissioner (OAIC)
Website: https://www.oaic.gov.au
Phone: 1300 363 992
The OAIC may investigate complaints relating to the handling of personal information and privacy matters under the Privacy Act 1988.
Other Complaints
Complaints relating to training, assessment, customer service, enrolment, fees, qualifications, statements of attainment, or other non-privacy matters should be managed through WAATA’s Complaints and Appeals Policy and Procedure.
Where appropriate, individuals may also seek information regarding complaints against Registered Training Organisations from the Training Accreditation Council (TAC).
Training Accreditation Council (TAC)
Website: https://www.tac.wa.gov.au
The TAC website provides current information regarding complaints about Registered Training Organisations and the circumstances in which TAC may become involved.
Continuous Improvement
WAATA records and reviews all privacy complaints as part of its continuous improvement, risk management and compliance monitoring processes. Outcomes of investigations may result in improvements to policies, procedures, systems, training or security controls to reduce the risk of future privacy incidents.