Privacy Policy

Complete Property Training Pty Ltd · RTO No. 31828 · Version 2.0 · July 2026

Purpose

Complete Property Training Pty Ltd (CPT) is committed to providing quality training and assessment in accordance with the Standards for Registered Training Organisations 2025. This policy explains how CPT complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) when collecting, holding, using and disclosing personal information, and how individuals can access or correct their information or make a privacy complaint.

Scope

This policy applies to all CPT employees, trainers, assessors and contractors, and covers the personal information of all individuals CPT deals with, including learners and prospective learners, clients, employers, website visitors, personnel and contractors. Due diligence by everyone involved with CPT is crucial to minimising privacy risk.

Policy Statement

CPT collects, uses, secures and discloses personal information in accordance with the Privacy Act 1988 and the APPs, and is committed to safeguarding all confidential information held by the RTO. CPT will ensure:

  • it maintains a current Privacy Policy, published on its website and available free of charge in an accessible format on request;
  • information gathered for training and assessment purposes is not disclosed to a third party without the individual’s consent, except where required or authorised by law (including reporting obligations described in this policy);
  • all records are stored securely; and
  • the confidentiality of all information on all records is maintained.

Definitions

Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether it is recorded in a material form or not.

Sensitive information means personal information about an individual’s racial or ethnic origin; political opinions or membership of a political association; religious beliefs or affiliations; philosophical beliefs; membership of a professional or trade association or trade union; sexual orientation or practices; or criminal record. It also includes health information, genetic information and biometric information or templates.

Anonymity and pseudonymity mean dealing with CPT without identifying yourself, or under a name other than your own, as described in APP 2.

Data breach means unauthorised access to, unauthorised disclosure of, or loss of personal information held by CPT.

Eligible data breach means a data breach likely to result in serious harm to any individual to whom the information relates, triggering notification obligations under Part IIIC of the Privacy Act.

Policy Responsibilities

Responsible Officer

Responsibilities

Head of Operations (Privacy Officer)

Acts as CPT’s Privacy Officer and first point of contact for privacy enquiries, access and correction requests, and complaints.

Maintains this policy and ensures it remains current, published on the CPT website and available free of charge.

Coordinates data breach assessment and notification under the Notifiable Data Breaches scheme.

Ensures personnel and learners have access to, and awareness of, this policy.

Reviews third-party and cloud service arrangements for privacy compliance, including overseas storage.

Compliance Administrator

Maintains the register of privacy enquiries, access requests, complaints and any data breaches.

Ensures enrolment forms and collection notices remain consistent with this policy and the Data Provision Requirements 2020.

All employees, trainers and contractors

Comply with the principles outlined within this policy and all applicable privacy laws and VET regulations.

Only access personal information needed to perform their role, and report any suspected privacy breach to the Privacy Officer immediately.

Legislation

CPT abides by the following, as amended from time to time:

  • Privacy Act 1988 (Cth) and the Australian Privacy Principles, including the Notifiable Data Breaches scheme (Part IIIC);
  • National Vocational Education and Training Regulator Act 2011 (Cth) and the Standards for RTOs 2025;
  • Data Provision Requirements 2020 and the National VET Data Policy (AVETMISS reporting);
  • Student Identifiers Act 2014 (Cth);
  • Spam Act 2003 (Cth) and Do Not Call Register Act 2006 (Cth) in relation to marketing communications.


Open and transparent management (APP 1)

CPT fosters open and transparent management of personal information. CPT keeps this policy up to date, maintains practices and procedures for handling privacy enquiries and complaints, and makes available information about: the kinds of information collected and held; how it is collected and held; the purposes of collection, holding, use and disclosure; how individuals may access and correct their information; how to complain about a breach of the APPs and how CPT deals with complaints; and whether CPT is likely to disclose information to overseas recipients and the countries where they are likely located.

Anonymity and pseudonymity (APP 2)

You may deal with CPT anonymously or using a pseudonym when making general enquiries about our courses and services. However, CPT is required by law to collect and verify full personal details for enrolment, USI verification, AVETMISS reporting and the issuance of nationally recognised certification, so anonymity is not available once you enrol.

Collection of personal information (APPs 3 and 5)

CPT only collects personal information that is reasonably necessary for its functions or required by law. The kinds of information we collect include: identity and contact details; date of birth; USI; citizenship, schooling and employment information required for AVETMISS reporting; language, literacy, numeracy and digital capability information; information about disability, health conditions or support needs you choose to share so we can provide support and reasonable adjustments (sensitive information, collected only with your consent); assessment and participation records; payment details; and images or recordings where you have consented under our media consent process.

We collect information when you register interest online or by phone, apply for enrolment, use our website, complete assessments or surveys, or otherwise contact or do business with us; from enrolment forms, certified documents, calls, emails and letters; and, with your permission, from third parties such as other training providers confirming prior training. At or before collection, we take reasonable steps to make you aware of who we are and how to contact us, why we are collecting the information, any law requiring collection, who we usually disclose it to, the consequences of not providing it, and how to access it. Where information is collected from a third party we take the same steps, unless doing so would pose a serious threat to the life or health of any individual.

Use and disclosure (APP 6)

CPT uses personal information to: process applications and manage enrolments; deliver and administer training and assessment; record and maintain training outcomes; issue certification; provide learner services and support; notify you of relevant events and opportunities; seek your feedback; communicate with you; and report to authorities as required by law. CPT does not use or disclose personal or sensitive information for any other purpose unless you consent, you would reasonably expect the use or disclosure and it relates to the purpose of collection, it is required or authorised by law or a court/tribunal order, a permitted general or health situation exists, or it is reasonably necessary for enforcement-related activities of an enforcement body.

Disclosure required by VET law. Under the Data Provision Requirements 2020, CPT is required to collect and disclose your personal information (including enrolment information) to the National Centre for Vocational Education Research (NCVER). Your information may be used or disclosed for statistical, regulatory and research purposes to: your school (if you are a secondary student); your employer (if your training is employer-funded); Commonwealth and State/Territory government departments and authorised agencies (including ASQA); NCVER; and organisations conducting student surveys on behalf of the Department. You may receive an NCVER survey or be contacted by an approved researcher, and may opt out at that time. NCVER handles personal information in accordance with the Privacy Act 1988 and the VET Data Policy (ncver.edu.au).

Licensing regulators. Where required to support your licence or registration application, and with your authority, CPT may confirm your training outcomes to the Office of Fair Trading (QLD), the Business Licensing Authority / Consumer Affairs Victoria, or NSW Fair Trading.

Service providers. CPT uses trusted third-party providers to operate its business — including our student management and learning platform, customer relationship management and communications platform, payment processors, videoconferencing, survey and website analytics providers. These providers may handle personal information on our behalf and are required to handle it consistently with this policy and the APPs.

Direct marketing (APP 7)

CPT may use your name, contact details and preferences to tell you about our courses and services where you have consented or would reasonably expect it. Every direct marketing communication includes a simple, free opt-out (for example, an unsubscribe link), and we will stop marketing to you promptly if you opt out or ask us to. CPT complies with the Spam Act 2003 for electronic marketing. Opting out of marketing does not affect communications we must send about your enrolment.

Cross-border disclosure (APP 8)

CPT does not routinely disclose personal information to overseas recipients. However, some of the cloud platforms CPT uses to deliver its services may store or process data on servers located outside Australia, including the United States — e.g. CRM/communications, payment processing, survey and analytics platforms. Before using any such platform, CPT takes reasonable steps to ensure the provider protects personal information in a manner consistent with the APPs, including through contractual terms and security certifications. Where a disclosure is not covered by these arrangements, CPT will seek your consent first.

Government identifiers — your USI (APP 9)

CPT is required by the Student Identifiers Act 2014 to collect, verify and report your Unique Student Identifier (USI). CPT cannot issue nationally recognised certification unless you hold a verified USI. Your USI will not be printed on your certification documents, will not be disclosed for any other purpose, and will not be adopted by CPT as its own identifier for you. Where you authorise CPT to create a USI on your behalf, identity documents you provide are used solely to verify your identity and are securely destroyed once verification is complete.

Quality of personal information (APP 10)

CPT takes reasonable steps to ensure the personal information it collects is accurate, up to date and complete, and that information it uses or discloses is accurate, up to date, complete and relevant having regard to the purpose of the use or disclosure.

Security of personal information (APP 11)

CPT takes reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Measures include role-based access controls on our student management and business systems, password and multi-factor authentication requirements, secure cloud storage with reputable providers, staff privacy training, and confidentiality obligations for personnel and contractors. When personal information is no longer needed for any purpose for which it may be used or disclosed, and is not required to be retained by law (including VET records retention requirements), CPT securely destroys or de-identifies it.

Data breach response (Notifiable Data Breaches scheme)

CPT maintains a data breach response process. Any suspected breach must be reported immediately to the Privacy Officer, who will contain the breach, assess the risk of serious harm within 30 days, and take remedial action. Where an eligible data breach is likely to result in serious harm, CPT will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, including recommendations about steps individuals should take. All breaches and near-misses are recorded and reviewed for continuous improvement.

Access to, and correction of, personal information (APPs 12 and 13)

CPT provides learners with electronic access to their own records through our learning platform, where personal details can be viewed and updated. You may also request access to your personal information by contacting the Privacy Officer. CPT responds to access requests within 30 days and provides access in the manner requested where reasonable and practicable, free of charge (a fee applies only for reprints of certification documents previously supplied). Your records are not released to any third party without your written authority, except as required by law.

Access may be refused only on the limited grounds set out in APP 12 — for example where access would pose a serious threat to life, health or safety, unreasonably impact another person’s privacy, prejudice legal proceedings, negotiations or enforcement activities, be unlawful, or reveal commercially sensitive evaluative information. If access is refused, CPT will give you written reasons and the available complaint mechanisms.

If you believe information we hold is inaccurate, out of date, incomplete, irrelevant or misleading, we will take reasonable steps to correct it. If CPT refuses to correct information, we will give you written notice setting out the reasons, the complaint mechanisms available, and any other matter prescribed by the regulations, and, on request, we will attach a statement to the record noting you consider it inaccurate.

Website, cookies and analytics

Our website uses cookies and similar technologies, including analytics and advertising tools [e.g. Google Analytics, Google Ads and Meta advertising tags], to understand how visitors use the site and to measure and improve our advertising. These tools may collect device and usage information such as IP address, pages visited and referral source. You can manage cookies through your browser settings and opt out of personalised advertising through Google and Meta ad settings. Enquiry forms on our website feed into our customer relationship management system so we can respond to you.

Photography and media

CPT only uses images or recordings of individuals for marketing and promotional purposes with express consent, obtained before or at the time of capture. Consent is optional, is not a condition of enrolment, and may be withdrawn at any time by contacting CPT. See our Website & Enrolment Terms and Conditions and Media Consent Procedure.

Privacy complaints

If you believe CPT has breached the APPs or mishandled your personal information, please contact the Privacy Officer at info@completepropertytraining.com.au or 1800 518 258. We will acknowledge your complaint promptly, investigate it under our Complaints and Appeals Policy, and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.

Records Management

All personal information and records are maintained, retained and disposed of in accordance with the CPT Records Management Policy and applicable VET records retention requirements, including the retention of AQF certification records for 30 years.

Monitoring and Improvement

All privacy practices are monitored by the Privacy Officer, and areas for improvement are identified and actioned as part of CPT’s self-assurance system under the Standards for RTOs 2025, including an annual review of this policy.

Document Control

Version

Date

Change Description

Author

1.0

July 2025

Policy generated

Education Manager

2.0

July 2026

Full review against Privacy Act 1988, APPs, Notifiable Data Breaches scheme, Data Provision Requirements 2020 and Standards for RTOs 2025. Scope extended to all individuals; sensitive information definition completed; cross-border disclosure corrected; data breach response, website/cookies, marketing platform and complaint escalation sections added.

Head of Operations