Privacy Policy
1. Purpose and commitment to privacy
Australian Community Education College Pty Ltd (ACEC) is committed to protecting the privacy and confidentiality of personal information it collects, holds, uses and discloses.
ACEC manages personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), applicable VET privacy and data-reporting requirements, its contractual obligations under the NSW Smart and Skilled program, and other relevant legal and regulatory obligations.
This Privacy Policy explains, in general terms:
- the types of personal information ACEC collects and holds;
- how ACEC collects, holds, uses and discloses personal information;
- the purposes for which personal information is used;
- how ACEC protects personal information;
- when personal information may be disclosed to other organisations, including overseas recipients;
- how individuals may access and request correction of their personal information; and
- how individuals may raise a privacy complaint.
This policy applies to personal information collected through ACEC’s website, enrolment and student administration systems, online learning and assessment systems, email and other communications, training and assessment activities, workplace activities and other interactions with ACEC.
ACEC’s privacy arrangements form part of its broader systems for protecting students, supporting quality outcomes and meeting its legal and regulatory obligations.
2.Personal information ACEC collects and holds
The type of personal information ACEC collects and holds depends on an individual’s relationship and interaction with ACEC. This may include:
- name, address, telephone number and email address;
- date of birth and identification information;
- Unique Student Identifier (USI);
- enrolment and course information;
- training, assessment, progress and completion information;
- educational and employment information where relevant;
- information about LLND needs, support needs and reasonable adjustments;
- workplace information relevant to training and assessment;
- information provided through enquiries, applications, complaints, feedback and surveys;
- payment and transaction information;
- information relating to staff and contractors where relevant to their engagement with ACEC; and
- technical information generated through use of ACEC websites, systems and online services.
Where reasonably necessary and permitted or required by law, ACEC may collect sensitive information, including information relating to health, disability or other circumstances where that information is relevant to providing training, assessment, support or reasonable adjustment.
ACEC will only collect sensitive information where permitted or required by law and where it is reasonably necessary for a relevant function or activity.
3.How ACEC collects personal information
ACEC generally collects personal information directly from the individual, including through:
- enrolment and application processes;
- online forms and the ACEC website;
- student and learning systems;
- email, telephone and other communications;
- training and assessment activities;
- workplace observation and assessment activities;
- requests for support or reasonable adjustment;
- surveys, feedback and complaints; and
- other interactions with ACEC.
ACEC may also collect personal information from third parties where permitted or required by law. This may include employers, workplace supervisors, authorised representatives, government agencies, VET data systems, training partners and other organisations involved in providing or administering training.
Where personal information is collected from another person or organisation, ACEC will handle that information in accordance with applicable privacy requirements.
4.Purpose of collection, use and disclosure
ACEC collects, holds, uses and discloses personal information for purposes reasonably necessary for its functions and activities, including:
- assessing and processing enrolments;
- delivering and administering nationally recognised training;
- conducting training and assessment;
- monitoring student participation, progression and completion;
- identifying and responding to student support, LLND and reasonable adjustment needs;
- maintaining assessment and academic records;
- communicating with students, trainers, assessors, employers and workplace personnel where appropriate;
- administering payments and business transactions;
- meeting VET regulatory, data reporting and quality-assurance requirements;
- maintaining student, staff and organisational records;
- responding to enquiries, complaints and appeals;
- conducting validation, review, audit and continuous improvement activities;
- maintaining the security and integrity of ACEC systems;
- managing organisational risks and legal obligations; and
- other purposes permitted or required by law.
ACEC will not use or disclose personal information for a purpose unrelated to the purposes for which it was collected unless permitted or required by law or otherwise authorised.
5.VET data and reporting
As a registered training organisation, ACEC is required to collect and report certain information for VET administration, regulation, monitoring, evaluation and statistical purposes.
Personal information may be provided to relevant government departments, regulators, VET data systems and the National Centre for Vocational Education Research (NCVER) in accordance with applicable VET legislation, policies and data-reporting requirements.
ACEC provides students with the applicable VET Privacy Notice as required under the VET data reporting framework. This notice explains how personal information collected for national VET data purposes may be collected, used and disclosed.
The VET Privacy Notice is provided in addition to this Privacy Policy.
6.Disclosure of personal information
ACEC may disclose personal information where reasonably necessary to provide training and support, meet legal or regulatory obligations, administer its functions or where otherwise permitted or required by law.
Depending on the circumstances, information may be disclosed to:
- Australian Skills Quality Authority (ASQA);
- relevant Commonwealth, state or territory government departments and agencies;
- NCVER;
- relevant VET data and reporting systems;
- Unique Student Identifier (USI) systems and relevant authorities;
- funding and training authorities;
- employers and workplace supervisors where relevant to training, assessment or workplace requirements;
- trainers, assessors and other ACEC personnel where necessary to perform their authorised functions;
- authorised contractors and service providers;
- technology, cloud, student administration and learning system providers;
- professional advisers where reasonably necessary; and
- other parties where the individual has authorised the disclosure or disclosure is otherwise permitted or required by law.
ACEC will only provide personal information to personnel and service providers where access is reasonably necessary for an authorised purpose.
7.Website, cookies and online services
When individuals use the ACEC website or online services, ACEC may collect technical information such as IP address, browser type, device information, access information and information about use of the website.
ACEC may use cookies and similar technologies to support website functionality, security and analytics.
Individuals may be able to restrict or reject cookies through their browser settings. Some website functionality may be affected as a result.
Third-party websites accessed through links from the ACEC website are subject to the privacy practices of those organisations. Individuals should review the relevant privacy policy before providing personal information to an external website.
8.Artificial intelligence and automated technologies
ACEC recognises that artificial intelligence (AI) and other automated technologies may be used to support administrative, educational, quality-assurance and organisational activities.
Approved AI technologies may be used for purposes such as:
- administrative assistance;
- document drafting and review;
- learning-resource development;
- quality-assurance activities;
- data and trend analysis;
- compliance and reporting support;
- communication support; and
- other authorised organisational purposes.
Where AI or an automated system is proposed to process personal information, ACEC will consider the privacy, security, accuracy, fairness, transparency and other risks associated with the proposed use.
ACEC will minimise personal information provided to AI systems and will only use AI systems approved for organisational use.
8.1 Human oversight and assessment decisions
ACEC does not use AI to independently determine:
- competency or assessment outcomes;
- the awarding of qualifications or statements of attainment;
- course completion;
- student progression; or
- disciplinary outcomes.
Where AI is used to assist with a process, appropriately authorised ACEC personnel remain responsible for applying professional judgement and making any decision.
AI-generated information, recommendations or outputs do not, by themselves, constitute an ACEC assessment decision.
AI tools must not be used as a substitute for the professional judgement of an appropriately authorised trainer, assessor or decision-maker.
8.2 Privacy and AI risk
ACEC will not knowingly enter sensitive personal information into unauthorised public AI systems.
Before implementing an AI system that processes personal information, ACEC will consider:
- the purpose of the proposed use;
- the type and amount of personal information involved;
- whether the use is reasonably necessary and lawful;
- information-security arrangements;
- whether information may be stored or processed overseas;
- risks to individuals;
- transparency and accountability requirements;
- human oversight; and
- appropriate controls, monitoring and review.
Where applicable privacy law requires ACEC to provide additional information about the use of automated decision-making, ACEC will provide that information in accordance with the applicable requirements and update this Privacy Policy where required.
ACEC’s use of AI is also governed by its AI Governance Policy.
9.Holding and security of personal information
ACEC holds personal information in electronic and, where applicable, physical records.
Electronic records may be held in student administration systems, learning and assessment systems, document-management systems, email systems, cloud services and other systems used to perform ACEC’s functions.
ACEC takes reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Security measures may include:
- access controls and user permissions;
- authentication and password controls;
- secure storage and transmission;
- encryption where appropriate;
- system and network security controls;
- restricted access to sensitive information;
- monitoring and review of information-security arrangements; and
- staff and contractor requirements relating to privacy and information security.
Access to personal information is limited to authorised persons who require the information for legitimate organisational purposes.
10.Third-party service providers and overseas disclosure
ACEC uses third-party technology and service providers to support its functions. These may include providers of student administration, learning systems, document management, email, cloud storage, payment and other business services.
Some service providers may store or process personal information outside Australia.
Where ACEC is likely to disclose personal information to overseas recipients, ACEC will consider its obligations under applicable privacy law and take reasonable steps to ensure that the information is handled appropriately.
The countries in which overseas recipients may be located can vary depending on the technology and services used by ACEC.
Where practicable, ACEC will identify relevant overseas locations and consider the privacy, security and contractual arrangements associated with the relevant provider.
11.Access to personal information
Individuals may request access to personal information ACEC holds about them.
Requests should be made using the contact details provided below. ACEC may need to verify the identity of the person making the request before providing access.
ACEC will respond to requests within a reasonable period and may refuse access in circumstances permitted by law. Where access is refused, ACEC will provide reasons where required.
12.Correction of personal information
Individuals may request that personal information held by ACEC be corrected where it is inaccurate, out-of-date, incomplete, irrelevant or misleading.
Where available, individuals may update certain information through the relevant ACEC system.
Correction requests may also be made by contacting:
Email: [email protected]
ACEC will take reasonable steps to correct information where appropriate and will respond within a reasonable period.
13.Privacy complaints
An individual who believes ACEC has mishandled their personal information may make a privacy complaint. Complaints should be directed to:
Australian Community Education College Pty Ltd
Email: [email protected]
Phone: 1300 363 954
ACEC will acknowledge and investigate privacy complaints in accordance with its complaints and privacy procedures and applicable privacy requirements.
ACEC will aim to resolve complaints within a reasonable period and will communicate the outcome to the complainant.
If an individual is not satisfied with ACEC’s response, they may be able to make a complaint to the Office of the Australian Information Commissioner (OAIC).
14.Privacy breaches and information security incidents
ACEC will respond to suspected or confirmed privacy breaches and information-security incidents in accordance with its information-security and incident-management procedures.
Where applicable, ACEC will assess whether a privacy breach is required to be notified under the Notifiable Data Breaches scheme or other applicable legal requirements.
ACEC will take reasonable steps to contain, investigate and remediate privacy incidents and will review relevant controls to reduce the likelihood of recurrence.
15.Anonymity and pseudonymity
Where lawful and practicable, individuals may have the option of dealing with ACEC without identifying themselves or by using a pseudonym.
This may not be practicable where ACEC is required by law or by the nature of the service to identify the individual, including for enrolment, VET reporting, assessment or certification purposes.
16.Privacy and student support
ACEC recognises that students may need to provide personal or sensitive information when seeking support, reasonable adjustment or assistance with participation in training and assessment.
ACEC will only collect and use information reasonably necessary to respond to the student’s circumstances and provide appropriate support.
Information about a student’s support needs will be accessed only by authorised personnel who require the information for the relevant purpose.
ACEC will seek to balance appropriate student support with the protection of the student’s privacy and the integrity of assessment requirements.
17.Related policies and documents
This Privacy Policy should be read in conjunction with relevant ACEC policies, procedures and documents, including:
- AI Governance Policy;
- VET Privacy Notice;
- Student Handbook;
- Complaints and Appeals Policy;
- Student Support and Reasonable Adjustment procedures;
- Information Security / Data Protection procedures;
- Records Management Policy; and
- relevant enrolment, assessment and student administration procedures.
18.Review and continuous improvement
ACEC will review this Privacy Policy at least annually and earlier where required. The review may consider:
- changes to privacy legislation and the Australian Privacy Principles;
- changes to VET legislation, data requirements or regulatory expectations;
- changes to ASQA requirements and guidance;
- changes to OAIC guidance;
- introduction or significant changes to AI or automated technologies;
- privacy or information-security incidents;
- changes to third-party service providers;
- complaints, feedback and identified risks;
- audit or monitoring findings; and
- changes to ACEC’s functions, systems or methods of delivering training and support.
Where the review identifies a need for improvement, ACEC will implement appropriate corrective or improvement actions.
Last updated: 30 September 2026