Overview
The Instruction Company (TICRail) is committed to meeting its legal and ethical obligations regarding the collection, use, storage, security, and destruction of personal and sensitive information collected from all stakeholders. TICRail adheres to all legislative requirements outlined in the Privacy Act 1988, Australian Privacy Principles (and any subsequent amendments), as well as the requirements under the ASQA Standards 2025.
Objective
To ensure that TICRail, its staff, and all stakeholders are aware of the measures in place to protect the confidentiality and security of their personal and sensitive information, and how that information will be used.
Scope
This policy applies to the personal and sensitive information of all TICRail stakeholders.
1. Collection of Personal and Sensitive Information
TICRail collects information from students, staff, and other stakeholders during its business operations, in either electronic or hard copy format. Information is collected solely for the purpose of meeting regulatory, legislative, and contractual requirements relating to the training and assessment services TICRail provides.
2. Use and Disclosure of Personal and Sensitive Information
TICRail will ensure that students, staff, and other stakeholders are informed about how their personal and sensitive information will be used and for what purpose.
Personal information — including contact details and course enrolment information — may be disclosed when necessary to assist a regulator or to meet legislative obligations. This includes disclosures to:
- The Australian Government
- Australian Apprenticeship Service Network Provider (AASN)
- National Centre for Vocational Education Research (NCVER)
- Australian Skills Quality Authority (ASQA)
- Training Accreditation Council (TAC)
In accordance with Section 11 of the Student Identifiers Act 2014 (Cth), TICRail will securely store any personal information collected from students solely for the purpose of applying for a Unique Student Identifier (USI) on the student’s behalf. Any person to whom personal information is disclosed is not permitted to use or disclose that information for any purpose other than the purpose for which it was gathered.
3. Storage of Personal and Sensitive Information
TICRail takes all reasonable steps to protect and safely store all personal and sensitive information in a central and secure location. All personal and sensitive information is also stored in our cloud-based student management system, aXcelerate.
TICRail does not permit personal or sensitive information to be stored in staff email accounts, and schedules regular purging of all deleted emails.
4. Data and Information Security
TICRail schedules automatic purging of all deleted staff emails every 30 days to ensure no personal or sensitive information is retained beyond this period.
All personal and sensitive information held by TICRail is protected as follows:
- Electronic information is held on a secure server with restricted access, for the period specified by the relevant regulator, government bodies, and funding contracts.
- Paper-based files are stored in a secure, locked area accessible only to authorised staff, and retained for the period required by the relevant regulator, government bodies, and funding contracts.
5. Access to Personal and Sensitive Information
TICRail ensures that all stakeholders have access to the personal and sensitive information we hold about them upon request.
To request access to your information, you must verify your identity and provide written consent by completing the F-316.6 Student Information Release Form and submitting it to: ticrail@instructionco.com.au
Any third party requesting personal or sensitive information held by TICRail must also complete the F-316.6 Student Information Release Form, signed by the stakeholder granting permission for the information to be released.
All requests will be reviewed by the Compliance Team within 15 business days.
If any personal or sensitive information we hold is found to be incorrect or has changed, individuals may request an update by notifying TICRail in writing and providing proof of the change. This may include changes to your address, name, citizenship, or employment details, or corrections to inaccurate records.
There is no charge for accessing your information; however, document copying incurs a fee of 20 cents per page. Fees may also apply for re-issuing AQF certification documentation.
6. Destruction and De-Identification of Personal and Sensitive Information
TICRail takes all reasonable steps to destroy or de-identify personal and sensitive information once it is no longer needed for any purpose. This forms a key part of our risk mitigation strategy to ensure compliance with all legislative requirements. The destruction process puts information permanently “beyond use,” including ensuring no backup copies of any kind are retained.
7. Data Breaches
TICRail complies with the Notifiable Data Breaches scheme under the Privacy Act 1988. In the event of a data breach involving personal information that is likely to result in serious harm, TICRail will notify the Office of the Australian Information Commissioner (OAIC) within 30 days of the breach occurring.
A notifiable data breach occurs when:
- There is unauthorised access to, unauthorised disclosure of, or loss of personal information held by TICRail; and
- This is likely to result in serious harm to one or more individuals; and
- TICRail has not been able to prevent the likely risk of serious harm through remedial action.
In the event of a breach, TICRail will make every effort to reduce the risk of harm to affected individuals.
Applicable Legislation
TICRail operates in compliance with the following legislation, including but not limited to:
- Privacy Act 1988 (Cth)
- Australian Privacy Principles
- Student Identifiers Act 2014 (Cth)
- Privacy and Data Protection Act 2014 (Vic)
- Health Records Act 2001 (Vic)
- Information Privacy Act 2009 (Qld)
- Privacy and Personal Information Protection Act 1998 (NSW)
- Health Records and Information Privacy Act 2002 (NSW)
- Personal Information Protection Act 2004 (Tas)
- Freedom of Information Act 1992 (WA)
This policy is reviewed annually. Current version: 2.11 | Effective: September 2025 | Next review: September 2026