1. Purpose
1.1. This policy ensures Australian Clinical Education Services hereinafter referred to ACES or the Company protects the privacy, confidentiality, and security of all personal information collected, stored, and used in the course of providing nationally recognised training and assessment services and any other services that the Company may provide. ACES is committed to providing quality services to all stakeholders and this policy outlines the Company’s ongoing obligations to all stakeholders in respect of how we manage Personal Information which the Company holds and/or processes. It demonstrates compliance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the ASQA 2025 Outcome Standards relating to transparency, governance, and learner protection.
1.2. A copy of the Australian Privacy Principles may be obtained from the website of The Office of the Australian Information Commissioner at https://www.oaic.gov.au/.
2. Scope
2.1. This policy applies to all ACES staff, contractors, trainers, assessors, and third parties who collect or handle personal or sensitive information on behalf of ACES, including learners, employees, clients, and website users. It also applies to any person, entity, organisation and/or other third party whose data is provided to and/or processed by ACES.
3. Relevant ASQA 2025 Outcome Standards
- Outcome 2.1 – The RTO maintains effective systems for governance, data management, and self-assurance.
- Outcome 5.1 – Learners receive accurate and transparent information about how their personal data is collected and used.
- Outcome 5.2 – The RTO protects learner rights and complies with Australian consumer and privacy legislation.
- Outcome 6.1 – Complaints and appeals processes are fair, transparent, and protect confidentiality.
4. Policy Statement
4.1. ACES is committed to protecting the personal information of all individuals in accordance with legal and regulatory requirements. All personal and sensitive information is collected lawfully, used only for legitimate purposes, stored securely, and accessed only by authorised personnel.
5. Types of Information Collected
5.1. Personal Information is information or an opinion that identifies an individual. Examples of Personal Information we collect includes names, addresses, email addresses, phone and facsimile numbers, further details are provided below.
5.2. This Personal Information is obtained in many ways including interviews, correspondence, by telephone and facsimile, by email, via our website www.acesau.com, from your website, from media and publications, from other publicly available sources, from cookies and from third parties. We don’t guarantee website links or policy of authorised third parties.
5.3. We collect Personal Information for the primary purpose of providing our services, providing information to our clients and marketing. We may also use Personal Information for secondary purposes closely related to the primary purpose, in circumstances where you would reasonably expect such use or disclosure. You may unsubscribe from our mailing/marketing lists at any time by contacting us in writing.
5.4. When we collect Personal Information we will, where appropriate and where possible, explain why we are collecting the information and how we plan to use it.
5.5. ACES may collect the following data in line with our provisions of service:
5.5.1. Personal Information
Full name, DOB, contact details; Identification documents; USI; Professional details eg professional registration number, Ahpra number
5.5.2. Sensitive Information
Health conditions (relevant to training safety); Disability or support needs; LLN requirements
5.5.3. Training & Academic Data
Enrolment details; Assessment outcomes; Attendance records; Certification records
5.5.4. Employment Information
Employer details (where training is workplace-based)
5.5.5. Financial data
Invoices; payment history; funding information.
5.5.6 Digital data
Cookies; IP addresses; online submissions; usage analytics
6. Data Collection and Use
6.1. ACES collects and uses personal data only for legitimate operational purposes and in order to provide services and data collection and/or processing may include the following activities such as: enrolment, training administration, certification, compliance reporting, and communication. Information is not shared or used for unrelated purposes without prior express consent of the relevant party(ies).
7. Data Storage and Security
7.1. Personal Information is stored in a manner that reasonably protects it from misuse and loss and from unauthorised access, modification or disclosure.
7.2. When Personal Information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify Personal Information. However, most of the Personal Information is or will be stored in client files which will be kept by us for a minimum of 7 years. This is necessary for the reporting and responding to any requests relating to certification of training and/or compliance.
7.3. ACES stores data on secure, password-protected systems located in Australia. Physical files are kept in locked areas. Access is limited to authorised staff. Regular system backups and security updates are conducted, and staff receive annual training on privacy and information security.
8. Disclosure of Personal Information
8.1. ACES will not disclose personal information to third parties unless the individual provides consent, it is required by law, or it is necessary to prevent or lessen a serious threat to health or safety. When third-party providers access personal data, confidentiality agreements must be in place.
9. AVETMISS & NCVER Compliance
9.1. Student information may be disclosed to NCVER for:
- Statistical reporting
- Research and evaluation
- Policy development
9.2. Students are informed via the NCVER Privacy Notice at enrolment.
10. Access and Correction
10.1. Individuals have the right to access and request corrections to their personal information held by ACES. Requests must be made in writing to the Compliance Manager (Chris.Kurt-Gabel@acesau.com) and will be addressed within 10 business days.
11. Data Retention and Disposal
11.1. Learner records are retained for 30 years as per ASQA requirements. Financial and HR records are retained for seven years. Data is securely destroyed when no longer required using shredding or secure digital deletion methods.
12. Data Breaches
12.1. A data breach occurs when personal information is lost, accessed, or disclosed without authorisation. ACES follows the Data Breach Response Procedure, which includes containment, risk assessment, notification to affected parties, and reporting to the OAIC if required.
13. Complaints
13.1. Privacy complaints should be directed in writing to the Compliance Manager at ACES. Complaints will be investigated promptly and handled confidentially. If unresolved, the complainant may contact the Office of the Australian Information Commissioner (OAIC) via www.oaic.gov.au.

