Simulated workplaceCAQA Department of Community Programs is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
PSPCAQA Department of Community ProgramsSimulated workplace
Back to library
CAQA Department of Community Programs · Simulated workplace

Privacy and Information Handling Policy

PolicyControlled document
DCP-POL-002
v2.4
Document ownerManager, Corporate Services
Version2.4
Approved17 March 2026
Next review17 March 2027
StatusCurrent

Purpose. This policy sets out how the department collects, uses, stores, shares and releases personal, health and sensitive information under the Privacy and Data Protection Act 2014, the Health Records Act 2001 and the Freedom of Information Act 1982.

1.Purpose and scope

The department holds personal information about grant applicants, service users, complainants, provider staff and its own employees. This policy applies to every record in every format, including emails, portal data, paper files, photographs and notes. It must be read with the records management policy and the security classification procedure.

2.Collection and use

Personal information must be collected only where it is necessary for a function of the department, by lawful and fair means, and with a collection notice that explains the purpose. Information must be used only for the purpose it was collected for or a directly related purpose the person would reasonably expect. Sensitive and health information must not be collected without consent unless the law requires it.

3.Security and access

Records containing personal information must be stored in the approved records system, classified under the protective security framework and accessed only by staff who need it for their duties. Staff must not email personal information to private accounts, store it on unapproved devices or leave it visible at front counters. Access to grant, compliance and complaint records is logged and audited.

  • Store personal information only in approved systems
  • Apply the correct security classification to every document
  • Lock screens and clear desks when away
  • Do not discuss individual matters in public areas or lifts
  • Report any suspected breach on the day it is found

4.Disclosure and information sharing

Personal information must not be disclosed outside the department unless the person has consented, the disclosure is required or authorised by law, or it is necessary to lessen a serious threat to life, health or safety. Sharing with other agencies must be documented under an information sharing agreement approved by the Manager, Corporate Services.

5.Access, correction and freedom of information

People have the right to request access to their own information and to ask for corrections. Requests must be registered in the correspondence tracker and referred to the freedom of information officer, who will process them under the Freedom of Information Act 1982 within the statutory timeframe. Staff must not release documents outside this process.

6.Data breaches

Any loss, unauthorised access or disclosure of personal information is a data breach. Staff must report it immediately to their manager and the privacy officer, who will contain the breach, assess the harm, notify affected people and the regulator where required, and record the breach in the risk register.

DCP-POL-002 v2.4 · CAQA Department of Community ProgramsUncontrolled when printed. Simulated document created by CAQA for training and assessment.