Privacy Policy
Australian Training Institute Pty Ltd t/a Australian Training Institute · ABN 22 149 390 616 · RTO 30200
Privacy Policy
Australian Training Institute Pty Ltd t/a Australian Training Institute · ABN 22 149 390 616 · RTO 30200
Your privacy matters.
Australian Training Institute Pty Ltd t/a Australian Training Institute (ABN 22 149 390 616; RTO 30200) — referred to as ‘ATI’, ‘we’, ‘our’ or ‘us’ in this Policy — collects, holds, uses and discloses personal information in the course of delivering nationally recognised training, employing our workforce, operating our campuses at Albion and Ipswich, and running our website. This Policy explains in plain language what we collect, why we collect it, who we share it with, and the rights you have over the information we hold about you.
This is ATI’s privacy policy for the purposes of Australian Privacy Principle 1.4. It covers students and prospective students, employer-clients, our workforce, job applicants, and visitors to our website. It is publicly available, free of charge, on our website and at Reception.
1. Purpose and Scope
This Policy describes how ATI manages personal information about students and prospective students, employees, contractors and trainers, job applicants, employer-clients and suppliers, website visitors, and members of the public.
It applies to information collected through enrolment, training delivery and assessment, employment, business operations, and our online presence (atiaustralia.edu.au and connected platforms). It is supported by ATI’s information security controls (refer OPS-MAN-009 Operations Manual — Information Security) and our Data Breach Procedure, and operates alongside Part 6 (Privacy & Your Information) of the Student Handbook (VET-HBK-002).
2. What Personal Information We Collect
We only collect information that is reasonably necessary for our functions and activities as a registered training organisation and employer. What we collect depends on your relationship with ATI.
2.1 Students and prospective students
- Identity and contact details — name, date of birth, address, email, phone number, emergency contact
- Unique Student Identifier (USI) — required by law before we can issue a nationally recognised qualification or statement of attainment
- Government-issued identification, where required for identity verification (e.g. driver licence, passport)
- Education, employment and language background — including language, literacy, numeracy and digital (LLND) information collected for AVETMISS reporting and to identify support needs
- Course enrolment, attendance, assessment, and completion records, including records of qualifications and statements of attainment issued
- Payment and fee information — card payments are processed by our secure payment gateway, Stripe; ATI does not store card numbers
- Support, welfare and reasonable adjustment information you choose to disclose
- Communications with us — emails, enquiries, and complaint and appeal records
- Photographs and recordings taken during training, only where you have given explicit written consent, and CCTV footage of ATI premises where in operation
2.2 Employees, contractors, and trainers
- Identity, tax file number, superannuation, banking, and emergency contact details
- Work history, qualifications, credentials, and vocational currency evidence (refer VET-REG-001 Trainer Compliance Register)
- Performance, training, and disciplinary records
- Health information where required for fitness-for-work or medical surveillance (e.g. blood lead monitoring and respirator fit-testing for firearms range activities), handled as sensitive information under §2.5
- Police checks and probity information where required by industry licensing or ATI’s Fit and Proper Person obligations (Standards for RTOs 2025, Schedule 1)
Job applicants: we collect applications, résumés, referee reports, and verification of qualifications for recruitment purposes only.
2.3 Employers and business clients
- Business contact details and accounts payable information for quoting and invoicing
- Employee enrolment information where training is arranged or funded by an employer
2.4 Website visitors and digital interactions
- Form submissions — enrolment enquiries, contact forms, feedback forms
- Cookies and analytics data — we use Google Analytics to understand website traffic patterns and improve the site; this includes pages visited, device and browser information, screen resolution, and approximate location. You can disable cookies in your browser settings
- IP addresses and device information collected by our hosting, analytics, and live chat providers when you interact with our website
- Email and SMS engagement data (e.g. whether a message was opened) where you have subscribed to communications
Our website may contain links to external sites. This Policy does not cover third-party websites, and we encourage you to read their privacy policies.
2.5 Sensitive information
Sensitive information (including health information, disability information, criminal history, and racial or ethnic origin) is collected only with your consent and where reasonably necessary — for example:
- Health declarations for safety-critical training (e.g. firearms courses, first aid practical work, lead exposure surveillance)
- Disability or learning support information you disclose so we can make reasonable adjustments
- Criminal history information where required for licensed industry pathways (e.g. security licensing)
- Demographic information collected under the AVETMISS standard for government reporting
Sensitive information is handled with heightened protection. Access is restricted to authorised personnel on a need-to-know basis, and criminal history information is handled only by the Compliance Manager.
3. How We Collect Personal Information
We collect personal information directly from you wherever practicable — through enrolment and onboarding forms, applications, in-person discussions, training and assessment activities, online forms, payment systems, and our communication channels.
Where we collect information about you from someone else — for example, an employer enrolling you in funded training, a funding body, the Student Identifiers Registrar, a referee in a recruitment process, or a regulator — we will take reasonable steps to tell you, unless an exception under the Privacy Act applies.
4. Why We Collect, Hold, Use and Disclose
We use your personal information to:
- Enrol you, deliver training, assess competency, and issue AQF qualifications and statements of attainment
- Meet our regulatory obligations under the Standards for RTOs 2025 and the National Vocational Education and Training Regulator Act 2011 — including AVETMISS reporting to NCVER, USI verification, and ASQA audit and regulatory requests
- Confirm enrolment, attendance, and progress to funding bodies, employment-services providers, and government agencies for funded training
- Process payments, issue invoices, manage payment plans and credit accounts, and respond to refund requests
- Employ, manage, train, and pay our workforce in accordance with the Fair Work Act, taxation, and superannuation legislation
- Meet work health and safety obligations — including medical surveillance for at-risk training activities
- Respond to enquiries, feedback, complaints, and appeals (refer VET-POL-003 Complaints and Appeals Policy)
- Send you direct marketing about ATI courses — only with your consent (see §10)
- Improve our services and meet our continuous improvement obligations, using de-identified information wherever possible
- Comply with subpoenas, court orders, regulator notices, and other legal obligations
5. Who We Disclose To
We do not sell personal information. We disclose personal information only where reasonably necessary for the purposes above, where you have authorised it, or where the law requires or permits it. Recipients may include:
- Government and regulators — ASQA, NCVER, the Student Identifiers Registrar, the Queensland Department of Trade, Employment and Training, and other authorities where legally required
- Funding bodies and employer-clients — for funded or employer-paid enrolments, limited to enrolment, attendance, progress, and outcome information
- Our service providers — aXcelerate (student management system, Australian-hosted), Stripe (payments), Microsoft 365 (email, storage and collaboration — Australian data centres), Zoho (CRM, support, and marketing), and iSmart (attendance and learning tools)
- Our professional advisers — accountants, lawyers, auditors, and insurance brokers — under confidentiality obligations
- Other parties you authorise — for example, if you ask us to release a statement of attainment to an employer or licensing body
5.1 The National VET Data Collection (NCVER)
Under the Data Provision Requirements 2020, made under the National Vocational Education and Training Regulator Act 2011 (Cth), ATI is required to collect and disclose your personal information (training activity data) to the National VET Data Collection kept by the National Centre for Vocational Education Research (NCVER). We are also authorised to disclose it to the relevant state or territory training authority.
Your information may be used and disclosed by NCVER for purposes including issuing authenticated VET transcripts, administration of VET, facilitation of statistics and research relating to education (including surveys and data linkage), and understanding how the VET market operates. NCVER may disclose your information to the Australian Government Department of Employment and Workplace Relations, VET regulators, state and territory training authorities, and organisations conducting research on NCVER’s behalf. NCVER does not intend to disclose your personal information to any overseas recipients.
You may receive a student survey (such as the Student Outcomes Survey) from NCVER, a government department, or an authorised agent. You may opt out of the survey at the time you are contacted. For more information, see NCVER’s Privacy Policy (ncver.edu.au/privacy) and the VET Data Use Statement (dewr.gov.au).
6. Overseas Disclosure
ATI does not currently disclose personal information to overseas recipients. Our core systems store data in Australian data centres. If this changes, we will update this Policy and, where required, seek your consent before any overseas disclosure.
7. Storage, Security, and Retention
Personal information is stored in the aXcelerate Student Management System (Australian-hosted) for student records, Microsoft 365 cloud infrastructure (Azure, Australian data centres) for documents and email, and our approved finance and CRM systems. Information is encrypted in transit and at rest and protected by multi-factor authentication, role-based access control, mandatory password standards, a ban on portable storage devices, and clean desk and clean screen practices. These controls form part of ATI’s information security management system, aligned with ISO/IEC 27001:2022 (refer OPS-MAN-009 Operations Manual — Information Security).
We retain records in line with our regulatory obligations:
- Records of AQF qualifications and statements of attainment issued — at least 30 years (Standards for RTOs 2025 Compliance Requirements)
- Student enrolment and assessment records — retained for up to 30 years to support qualification verification and re-issue
- Financial and fee records — 7 years (taxation law)
- Employee records — 7 years post-employment (Fair Work Act)
When information is no longer required to be retained, it is securely destroyed or de-identified.
8. Your Unique Student Identifier (USI)
Your USI is collected, used and disclosed in accordance with the Student Identifiers Act 2014 (Cth). By law, ATI cannot issue a nationally recognised qualification or statement of attainment unless we hold your verified USI, and we must verify your USI with the Student Identifiers Registrar before using it. Your USI is never printed on qualifications or statements of attainment.
If you ask us to create a USI on your behalf, we collect your identity details (including an identity document) for that purpose and will provide you with the Registrar’s privacy notice. You can manage which providers can access your USI account at usi.gov.au. Your USI is treated as personal information under this Policy, and misuse of a USI can be investigated by the Office of the Australian Information Commissioner (OAIC).
9. Automated Tools and AI
ATI uses approved digital tools, including AI-assisted marking within our student management and learning systems, to support efficiency and consistency. No decision that significantly affects your rights or interests — including any assessment outcome — is made by a computer program alone. A qualified trainer/assessor reviews, makes, and signs every assessment decision, and a person reviews any automated output before it is acted on. We publish this information consistent with the automated decision-making transparency requirements introduced by the Privacy and Other Legislation Amendment Act 2024 (APPs 1.7–1.9).
10. Direct Marketing, Photos, and Testimonials
We send marketing about ATI courses, events, and offers — by email, SMS, or post — only where you have consented or would reasonably expect it. Every message includes a clear opt-out, and you can withdraw consent at any time by using the unsubscribe link or contacting us (see §14). We comply with the Spam Act 2003 and the Do Not Call Register Act 2006.
Your photo, story, or testimonial is used in ATI marketing only with your explicit written consent. You may withdraw consent at any time; we will stop future use, although we cannot retract material already lawfully published before your withdrawal. Marketing content is managed under ATI’s marketing compliance processes and the Standards for RTOs 2025.
11. Access and Correction
You have the right to:
- Ask what personal information we hold about you and request access to it (APP 12)
- Request correction of information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading (APP 13)
To make a request, contact the Privacy Officer (see §14) or Student Support. We will respond within 30 days. There is no fee for making a request; if access requires significant retrieval work we may charge a reasonable cost-recovery fee and will tell you before proceeding. If we decline access or correction, we will give you written reasons and tell you how to complain about that decision.
12. Data Breaches
If a data breach occurs that is likely to result in serious harm to any individual, ATI will:
- Contain and investigate the breach immediately, in accordance with our Data Breach Procedure
- Assess the breach against the Notifiable Data Breaches threshold within 30 days
- Notify the Office of the Australian Information Commissioner (OAIC) and affected individuals where the threshold is met, in accordance with Part IIIC of the Privacy Act
If you suspect your information has been lost, accessed, or disclosed without authority, report it immediately to [email protected] or to Student Support.
13. Privacy Complaints
If you believe ATI has breached the Australian Privacy Principles or this Policy, please raise it with us first — contact the Privacy Officer (see §14). We will acknowledge your complaint in writing within 5 business days and provide a written response within 20 business days. Privacy complaints can also be raised through ATI’s Complaints and Appeals process (refer VET-POL-003), at no cost.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
- Web: oaic.gov.au
- Phone: 1300 363 992
14. Contact — Privacy Officer
ATI’s Privacy Officer is the Compliance Manager.
- Email: [email protected]
- Phone: 1300 100 284 (1300 100 ATI)
- Post: Privacy Officer, Australian Training Institute Pty Ltd, Shop 1, 10 Albion Road, Albion QLD 4010
- In person: Reception at our Albion or Ipswich campus
Last updated: 01 July 2026