Skip to main content

Privacy Policy and Procedure

Version 2.0 · issued 2026-09-05

Download PDF

How your personal information and student records are collected, stored, used and protected.

Policies for:

Who this document applies to

This document applies to Edway Training Pty Ltd (RTO 91401). In this document, "we", "us" and "the RTO" mean the entity that delivers and certifies your course — the issuing RTO is shown on the course page and on your enrolment confirmation.

This policy covers the personal information the RTO collects and holds about its students — such as enrolment records, identity documents, and assessment results. How the edway.edu.au website handles visitor data is set out separately in the Website Privacy Policy.

Policy objective

To ensure personal information is collected, used, stored, disclosed, and managed in compliance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Freedom of Information Act 1982, and the 2025 RTO Standards — particularly those addressing transparency, student protection, and continuous improvement.

Scope

This policy applies to all RTO staff, contractors, students, and third-party providers. It covers all formats of personal data (electronic and hard copy).

Responsibility

The Compliance Manager oversees implementation and review. Departmental managers must ensure all staff understand and adhere to the policy.

Policy statement

  • The RTO collects personal information solely for legitimate RTO operational purposes.
  • We are committed to transparency, integrity, and accountability in data handling.
  • All reasonable steps will be taken to protect personal information from misuse, interference, loss, or unauthorised access.
  • Consent will be sought for any non-standard or marketing-related data use.

Procedures

1. Managing personal information

  • Personal information is managed in line with legal and regulatory frameworks.
  • Data handling is documented in the RTO's Document and Records Register.
  • Individuals may request access or correction through a defined process (see sections 6 and 7 below).

2. Collection and use of information

  • Collected data must be necessary, lawful, and fair.
  • The RTO collects data for student administration, enrolment, training delivery, AVETMISS reporting, and regulatory compliance.
  • Information is not used for marketing unless explicit consent is provided.

3. Identity images and session recordings

In addition to enrolment records, some courses involve collecting:

  • a selfie of you holding your identification document (demolition courses);
  • a photo captured during online assessment, which is forwarded to the assigned trainer/assessor;
  • a signed statutory declaration and a certified copy of your identification (online courses where required);
  • recordings of online video sessions, kept as evidence of participation for ASQA audit purposes.

These are collected for identity verification and regulatory compliance, and are handled as student records under this policy. When each applies is set out in the Terms and Conditions and the Student Handbook.

4. Storage and security

  • Information is protected using secure IT systems, locked physical storage, and access controls.
  • Personal data no longer needed is securely destroyed or de-identified unless required by law.
  • Staff are trained on data security expectations.

5. Disclosure of personal information

  • Data may be shared with regulators, government bodies, or employers (for example, for placements) where necessary.
  • Disclosure to third parties occurs only with consent, or under lawful exemptions (for example, serious threat, court orders, or statutory obligations).
  • Additional protections apply for students under 18.

6. Correction and update

  • Students may request updates to personal data.
  • If a request is refused, the RTO will provide written reasons and the appeal mechanism.
  • On request, the RTO will notify third parties of corrected data where practical.

7. Access to personal information

  • Individuals may request access to their data in writing.
  • Requests are processed within 10 business days. There is no charge to request or access your records; a charge of 20 cents per page may apply for copying, and any applicable fees will be advised before copies are made.

Send access, correction, or privacy-complaint requests in writing to the issuing RTO — the RTO shown on your course page and enrolment confirmation. Include your name, your contact details, and what you are requesting.

Complaints and continuous improvement

  • Complaints regarding privacy breaches are managed via the Complaints and Appeals Policy and Procedures. A Complaint and Appeal Form is available on request (see the Complaints and Appeals Policy and Procedures).
  • Systemic privacy issues identified through complaints will be reviewed for continuous improvement.

Review and improvement

This policy is reviewed biennially or as required to ensure alignment with Outcome Standards, legislative changes, and organisational best practice.