Privacy Policy
Last Updated: 2026
Our Commitment to Your Privacy
Cardinal Institute of Education Pty Ltd is committed to protecting the privacy, confidentiality, and security of the personal information of our students, staff, and website visitors. We handle all personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Student Identifiers Act 2014, the Data Provision Requirements 2020, and the Standards for Registered Training Organisations (RTOs) 2025. This policy explains what information we collect, why we collect it, and how we keep it safe.
What Personal Information We Collect
We only collect personal information that is necessary for us to perform our functions as a Registered Training Organisation. This may include:
- Your name, date of birth, and contact details
- Your Unique Student Identifier (USI) and identity verification documents
- Demographic and educational background information required for national (AVETMISS) reporting
- Academic records, including results and attendance
- Sensitive information such as disability, language, or support needs — collected only where required by law or needed to provide you with appropriate academic or welfare support
Why We Collect Your Information
- Processing enrolments and student administration
- Delivering training and assessment services
- Providing learner support and wellbeing services
- Issuing AQF certification documentation
- Meeting regulatory and reporting obligations, including AVETMISS and USI requirements
- Communicating with you about your enrolment, progress, and outcomes
We will always let you know why your information is being collected, how it will be used, and whether the collection is required by law. Where lawful and practicable, you may deal with us anonymously or under a pseudonym — however, this is not possible where identification is required for enrolment, certification, or regulatory reporting.
How Your Information Is Used and Disclosed
Your personal information is used strictly for the purpose it was collected, unless a different use or disclosure is required or authorised by law. We may disclose personal information to:
- Government agencies such as NCVER and ASQA for regulatory reporting and compliance
- Authorised third parties, where applicable, for service delivery and operational support
- Regulatory or licensing bodies where required by law
Your personal information is never sold, rented, or traded under any circumstances. Disclosure is limited to what is necessary, and we take reasonable steps to ensure any third parties comply with privacy obligations. We do not routinely send personal information overseas — where this may occur (for example, through cloud-based systems), we take reasonable steps to ensure recipients comply with the Australian Privacy Principles.
Sensitive and Identity Information
Sensitive information and identity documents (such as passports or driver's licences) are handled with enhanced safeguards. This information is collected only where strictly necessary, used solely for verification or support purposes, and accessible only to authorised personnel. We follow a “verification over storage” approach — identity documents are not kept longer than required and are securely destroyed once their purpose has been fulfilled.
Direct Marketing
We do not use your personal information for direct marketing unless you have given consent or the use is otherwise permitted by law. Any marketing communications we send comply with the Spam Act 2003 (Cth) and include clear opt-in and opt-out options, so you stay in control of your information.
Security of Your Information
We apply a layered approach to information security to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Our safeguards include:
- Secure student management systems with password protection, multi-factor authentication, encryption, and system backups
- Locked physical storage and restricted premises access
- Role-based access, so only authorised personnel can view sensitive data
- Staff training, confidentiality obligations, and regular system audits and access reviews
Accessing and Correcting Your Information
You have the right to access and correct your personal information. Requests are handled in a timely, transparent, and secure manner, and we will verify your identity before providing access to protect your records. Viewing your records is free of charge, and correction requests are assessed and actioned promptly to keep your information accurate, complete, and up to date.
How Long We Keep Your Information
We retain personal information only for as long as necessary to meet legal, regulatory, and operational requirements:
- Certification records — minimum 30 years (AQF requirement)
- Student records — minimum 2 years after completion or cancellation
- Assessment evidence — minimum 2 years after completion or cancellation
When information is no longer required, it is securely disposed of — physical documents are shredded and electronic records are securely deleted.
Data Breaches
If a data breach occurs, we act quickly to identify, contain, and resolve the incident and take corrective action to prevent it from happening again. Where required, we comply with the Notifiable Data Breach (NDB) Scheme, including notifying affected individuals and the relevant authorities.
Privacy Complaints and Concerns
If you have a concern about how your personal information has been handled, you have the right to raise it with us. Privacy complaints are managed under our Complaints and Appeals Policy with procedural fairness, and you will never face any adverse treatment for raising a concern. All complaints are recorded, acknowledged, investigated, and the outcome communicated to you transparently.
Contact Us
If you have any questions about this Privacy Policy or the handling of your personal information, please contact us:
Cardinal Institute of Education
Suite 207/30 Campbell St, Blacktown NSW 2148
Phone: 0406 705 649