Frequently asked questions (FAQs) about privacy relating to the Australian Government Department of Education.
On this page:
What privacy legislation is the department required to comply with?
As a Commonwealth agency, the department must comply with the Privacy Act 1988 (Cth) (Privacy Act), including the Australian Privacy Principles (APPs) set out at Schedule 1 and the Privacy (Australian Government Agencies – Governance) APP Code 2017 (Privacy Code).
For further information about the Privacy Act, APPs, and Privacy Code, visit the Office of the Australian Information Commissioner’s website.
What is personal information?
The Privacy Act 1988 (Cth) (Privacy Act) regulates how the department handles personal information. Under section 6(1) of the Privacy Act, personal information is defined as:
‘Information or an opinion about an identified individual, or an individual who is reasonably identifiable:
- whether the information or opinion is true or not; and
- whether the information or opinion is recorded in a material form or not.’
Personal information can include a wide range of information about an individual, such as their name, signature, address, telephone number, date of birth, photograph, financial information, employment details, mobile device location data, and sensitive information.
Sensitive information is a subset of personal information and includes information, or an opinion, about an individual’s:
- racial or ethnic origin
- political opinions or associations
- religious or philosophical beliefs
- trade union membership or associations
- sexual orientation or practices
- criminal record
- health or genetic information
- some aspects of biometric information.
Sensitive information is generally afforded a higher level of privacy protection under the Australian Privacy Principles than other personal information.
How does the department handle personal information?
The department collects, uses, stores, discloses and otherwise handles personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and the Privacy (Australian Government Agencies – Governance) APP Code 2017.
For more information about how the department handles personal information, see the department’s Complete Privacy Policy.
If you are looking for a summary, you may wish to read the department’s Condensed Privacy Policy which is available on the department's Privacy page.
Does the department consider the privacy impacts of its projects and activities?
The department is required to conduct a privacy impact assessment (PIA) for all high privacy risk projects. A project is a high privacy risk project if it involves any new or changed ways of handling personal information that are likely to have a significant impact on the privacy of individuals.
A PIA identifies the potential privacy impacts of a project and recommends measures to manage, minimise or eliminate those impacts.
A list of the PIAs conducted by the department is available under the Privacy Impact Assessment Register on the department's Privacy page.
What happens if the department experiences a data breach involving my personal information?
The department will take seriously and deal promptly with any unauthorised access, use or disclosure of personal information. The department is required under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth) to notify individuals whose personal information is involved in a data breach that is likely to result in serious harm to those individuals. The department is also required to notify the Office of the Australian Information Commissioner of these data breaches.
How does the department keep my personal information secure?
The department takes all reasonable steps to protect the personal information held in its possession against loss, unauthorised access, use, modification, disclosure or misuse.
Access to personal information held by the department is restricted to authorised persons who are departmental employees or contractors, on a need-to-know basis. Electronic and paper records containing personal information are protected in accordance with Australian Government security policies.
Can I access or correct personal information the department holds about me?
Yes. You have a right under the Privacy Act 1988 (Cth) (Privacy Act) to access personal information the department holds about you. You also have a right under the Privacy Act to request corrections of any personal information that the department holds about you if you think the information is inaccurate, out-of-date, incomplete, irrelevant or misleading.
Information about making an access request is available on the department’s Privacy page.
Alternatively, you can find the relevant contact details under the FAQ on this page titled ‘How do I contact the department if I have an enquiry or complaint about the department’s handling of my personal information, or if I want to access or correct my personal information?'
How does the department’s use of artificial intelligence affect individuals’ privacy?
The department uses artificial intelligence (AI) to support workplace productivity, improve internal efficiency, and enhance the delivery of its functions and services. For example, AI may be used to draft, summarise and refine documents, assist with analysing large volumes of information, support policy development, and improve service delivery.
Where AI is used to handle personal information, the department does so in accordance with applicable legal and policy requirements, including the Privacy Act 1988 (Cth) and Australian Privacy Principles.
More information about the department’s use of AI can be found in the AI Transparency Statement and Complete Privacy Policy.
How do I contact the department if I have an enquiry or complaint about the department’s handling of my personal information, or if I want to access or correct my personal information?
You can contact the department about privacy matters by:
- emailing privacy@education.gov.au
- phoning 1300 566 046
- writing to this mailing address:
Privacy Officer
Legal Services
Department of Education
LOC: C50MA1
GPO Box 9880
Canberra ACT 2601
You can also make a privacy complaint via the department’s online complaint form.
Can I ask the department to destroy the personal information it holds about me?
The Privacy Act 1988 (Cth) does not contain a right for you to request destruction of your personal information. Additionally, the department has specific retention obligations for personal information included in a Commonwealth record. Information the department creates, sends, or receives is generally part of a Commonwealth record.
The retention of Commonwealth records is regulated by the Archives Act 1983 (Cth), which sets out when they may be altered or destroyed. This means the department may not be able to lawfully destroy personal information it holds about you.