Privacy
Version 1.7. Effective from 26 May 2026
Introduction:
Foundation Learning Centre is committed to ensuring the privacy of members and must comply with the:
- the Privacy Act 1988 (Privacy Act) including all amendments as well as the Australian Privacy Principles (APPs) operational from 12 March 2014
- Information Privacy Act 2000 (Vic) (IPA)
- Health Records Act 2001(Vic) (HR Act)
- any additional laws in relation to the appropriate funding bodies.
Purpose:
This Privacy Policy outlines how Foundation Learning Centre (FLC) collects, uses, discloses, and protects personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The purpose of this policy is to ensure transparency in our information handling practices and to safeguard the privacy of students, staff, and stakeholders. It reflects our commitment to delivering high-quality education and training services while complying with the regulatory requirements set by the Victorian Registration and Qualifications Authority (VRQA)
Definitions:
Personal Information: as defined by the Privacy Act 1988 (as amended) is information or an opinion about an identified individual, or an individual who is reasonably identifiable,
whether true or not, and whether recorded in a material form or not
Health Information: refers to details about a person’s medical records, test results, dental history, prescription and other pharmaceutical purchases, genetic data, and their expressed wishes regarding future health care services or potential organ donation.
Sensitive Information: as defined by the Privacy Act 1988 (as amended) is information or opinion (that is also personal information) about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual preferences or practices or criminal record or health, genetic, biometric information or biometric templates, that is also personal information.
Privacy Act: Prohibits any form of interference with individuals’ privacy rights and includes the following 13 principles:
- Open and transparent management of personal information
- Anonymity and pseudonymity
- Collection of solicited personal information
- Dealing with unsolicited personal information
- Notification of the collection of personal information
- Use or disclosure of personal information
- Direct marketing
- Cross-border disclosure of personal information
- Adoption, use or disclosure of government related identifiers
- Quality of personal information
- Security of personal information
- Access to personal information
- Correction of personal information
Data breach: happens when personal information is accessed, shared, or lost without permission. While it can result from deliberate wrongdoing, it’s more commonly caused by accidental human error.
Eligible data breach: is when the following three criteria are satisfied;
- There is unauthorized access to or unauthorized disclosure of personal information, or a loss of personal information
- This is likely to result in serious harm to one or more individuals
- The entity has not been able to prevent the likely risk of serious harm with remedial action
Common data breaches:
- Email mistakes, such as using ‘cc’ instead of ‘bcc’ or attaching the wrong document
- Incorrect mail merges or sending messages to the wrong recipients
- Loss or theft of devices like mobile phones, tablets, or USB drives
- Hard copy files that are misplaced or lost
- Employees accessing information without proper authority
- System errors that allow unintended access to customer data
- Poor control over access and editing rights of records
- Cyber attacks that compromise sensitive information
Open and transparent management of personal information:
FLC has a “Privacy by Design” approach by integrating privacy considerations into their operations from the outset. This includes staff training, internal policies, and education to ensure compliance with the Australian Privacy Principles (APPs).
Collection of personal information:
FLC will collect personal information only when it’s necessary and will do so by lawful and fair means. Wherever reasonable and practicable, the information should be collected directly from the individual. Sensitive information can only be collected in specific circumstances: with the individual’s consent, when required or authorised by law or a court or tribunal order, or in situations where it’s needed to prevent or lessen a serious threat to someone’s life, health, or safety. Collection of data through enrolment is only visible to administrators in aXcelerate. Access is kept to a ‘need to know’ basis. All student welfare and support files are stored in a secure SharePoint page only accessible by the wellbeing team and relevant team leaders. Information collected by our visitor management system, VPASS, is only able to be accessed by senior leadership and facilities coordinator.
Collection of personal information- Collection notice:
As an entity governed by the Australian Privacy Principles (APPs), FLC will take reasonable measures to inform individuals about how their personal information will be managed. Victorian Government VET student enrolment Privacy Notice is presented at time of enrolment.
Use or disclosure of personal information- secondary purposes:
FLC is permitted to use or disclose personal information only for the original purpose it was collected. If we wish to use it for a different purpose, we will first get the individual’s consent or meet a specific exception that allows it. Permitted secondary purposes include:
- With the individual’s consent
- For a related purpose that falls within the individual’s reasonable expectations
- To prevent a serious threat to an individual’s life, health, or public safety
- When required or authorised by law or by a court or tribunal order
- For law enforcement purposes
- For purposes under Child and Family Violence Information Sharing Schemes when
required
NCVER:
FLC is required by law (under the National Vocational Education and Training Regulator Act 2011 (Cth) (NVETR Act)) to disclose the personal information we collect to the National VET Data Collection kept by the National Centre for Vocational Education Research Ltd (NCVER). The NCVER is responsible for collecting, managing, analysing and communicating research and statistics about the Australian VET sector.
We are also authorised by law (under the NVETR Act) to disclose personal information to the relevant state or territory training authority. From time to time, we may also have to disclose your information as a result of a court order, subpoena, warrant or in the course of a legal proceeding or in response to a law enforcement agency request.
We may supply attendance, progress and participation information as well as a copy of outcome of results from training to the parties listed below.
- Schools – if you are a secondary student undertaking VET training as part of a school program
- Employers – if you are enrolled in training paid for by your employer
Third Party:
Any third-party arrangements are subject to strict privacy and confidentiality obligations.
Where personal information is shared for service delivery, we ensure that:
- The third party’s privacy practices align with our own standards and legal obligations
- Information is used only for the agreed purpose
- Personal data is securely deleted or returned at the end of the engagement
We remain committed to protecting the privacy of individuals and maintaining transparency in all third-party relationships. This also applies with our use of our Document Verification Service (DVS) in conjunction
with Pharmacy ID. FLC will inform relevant parties of any privacy or security breaches that occurs.
Skills First:
We must notify the Department of Jobs, Skills, Industry and Regions (DJSIR) via the Skills Victoria Training System (SVTS) as soon as practicable if we become aware of any of the following:
- a breach of our contractual privacy obligations relating to the Skills First Program;
- any unauthorised disclosure, use, modification or access to personal information, or any attempted unauthorised disclosure, use, modification or access, including misuse or loss of personal information collected or held for the purposes of the Skills First Program; or
- any act or practice by us that causes, or may cause, the Department to fail to comply with its obligations under Victorian privacy or health records legislation.
Security of personal information
FLC will take reasonable steps to protect personal information from misuse, interference, loss, and unauthorized access, modification, or disclosure. When the information is no longer needed for any permitted purpose under the Australian Privacy Principles (APPs), we will take reasonable steps to destroy it or ensure it is de-identified, unless a legal exception applies. Personal Information will be retained digitally for a minimum of 7 years, SOA and Qualifications for 30 as per FLC policy. Exceptions to the obligation to destroy or de-identify personal information apply when:
- The information is part of a Commonwealth record.
- The APP entity is legally required to retain the information, such as by statute or court/tribunal order.
Student information, including enrolment information, training progression and internal notes are stored on the LMS, aXcelerate. aXcelerate are ISO accredited and use AWS for on-shore hosting. Further information on aXcelerate’s security and privacy controls can be found here: Trust Center – aXcelerate
FLC’s Information Technology is managed by Majestic Computer Services, ensuring internal information is kept secure and minimising risk to external cyber security threats to personal information.
Access to and Correction of Personal Information:
FLC Staff and students have the right to request access to the personal information that Foundation Learning Centre holds about them, as well as the right to request that any information found to be inaccurate, incomplete, or out-of-date be corrected. To make a request for access or correction they should make a request in writing to the Compliance Manager. The Compliance Manager will respond to the request within a reasonable timeframe and in accordance with the Privacy Act.
How to Make a Complaint
If someone believes that Foundation Learning Centre (FLC) has breached the Australian Privacy Principles (APPs) or a binding registered APP code, they have the right to make a complaint.
FLC encourage them to contact the Compliance Manager directly in the first instance so they can address your concerns promptly. Details of our internal complaints handling process are outlined in our dedicated Complaints and Appeals Policy, which provides comprehensive information on how we manage, investigate, and resolve complaints.
Contact details;
Unit 1, 4a Malcolm Crt, Narre Warren, VIC, 3805.
compliance@flc.vic.edu.au
03 9704 7388
Data security- reasonable steps:
FLC will take reasonable steps to safeguard personal information from loss and unauthorised access. This includes:
- Physical safeguards: Locking filing cabinets or securing storage areas to protect paper-based records.
- Computer security: Using passwords, access controls, and outsourced IT contractor to manage cyber security.
- Communication protocols: Ensuring sensitive information shared via email, text message, or other channels is protected and directed only to intended recipients.
o If an email is sent to a non-intended recipient, the email is to be recalled as soon as possible
o In all other occurrences of communications being delivered to a non-intended recipient, the Compliance and Quality Manager is to be informed within 24 hours including what was sent, time of delivery and mode of delivery.
Data Breach Response Plan:
Foundation Learning Centre (FLC) is committed to promptly managing any data breach involving personal information. A data breach occurs when personal information is lost, accessed, or disclosed without authorisation. Under the Privacy Act 1988, certain breaches must be reported under the Notifiable Data Breaches (NDB) scheme.
Identification and Containment
- Immediately assess and confirm the breach.
- Take steps to contain the breach (e.g., disable compromised accounts, recover lost devices, recall misdirected emails).
Assessment
- Within 30 days, evaluate:
o The type and sensitivity of information involved.
o The cause and extent of the breach.
o The risk of serious harm to affected individuals.
Notification
- If the breach is an eligible data breach (likely to cause serious harm and cannot be remedied):
o Notify affected individuals as soon as practicable.
o Provide details of the breach, what information was involved, and steps they should take.
o Notify the Office of the Australian Information Commissioner (OAIC) using the official NDB form: OAIC Web Form
Remediation
- Implement measures to prevent recurrence (e.g., system patches, staff retraining).
- Review and update security protocols.
Documentation
- Record all details of the breach, actions taken, and outcomes
- Report internally to the Compliance and Quality Manager within 24 hours of
detection.
Further Information:
For more detailed information about The Acts, contact the Privacy Commissioner’s Office or visit the Privacy Website at http://www.privacy.vic.gov.au