Skip to main content
  1. Home
  2. About Us
  3. Privacy

Privacy Policy

Our Privacy Policy explains how we handle your personal information.

The Student Identifiers Registrar (Registrar) is the Commonwealth statutory office holder established by the Student Identifiers Act 2014 (SI Act). Under the SI Act, the Registrar is responsible for administering the Unique Student Identifier (USI) initiative. The USI is a linkage key, providing an important foundation for understanding and improving vocational education and training (VET) and higher education performance.

The Registrar is assisted by Department of Employment and Workplace Relations (DEWR) employees in the Office of the Student Identifiers Registrar (OSIR). The Registrar and OSIR’s (‘our’) priority is the privacy and security of individuals’ (‘your’) information collected, held, used and disclosed during the course of administering the USI initiative.

Who should read this privacy policy

You should read this privacy policy if you are:

  • an individual (including students, parents/guardians and USI applicants and account holders)
  • an organisation (or employee, including registered training organisations (RTOs), higher education providers, admissions bodies and organisations involved in the administration of vocational education and training (VET), and higher education that may interact with the USI initiative)
  • a government agency (or employee, including policy, program or regulatory stakeholders that may collect, use, or share information in connection with the administration of the USI).

Purpose of this policy

Under the Privacy Act 1988 (Privacy Act), the Registrar is their own ‘agency’ and an ‘entity’ subject to the Australian Privacy Principles (APPs).

This privacy policy is established in accordance with APP 1 to:

  • describe the types of personal information we collect, hold, use and disclose 
  • explain our authority to collect personal information, and how it is used and protected
  • outline our personal information handling practices 
  • explain when and why personal information may be disclosed to overseas recipients
  • provide information about locations of overseas recipients where it is practicable to do so
  • provide information on how an individual can access the personal information we hold and ask for the information to be corrected
  • explain what an individual can do if they have a query, concern, or complaint about our handling of their personal information.

Privacy Act 1988

The Registrar and OSIR, including DEWR employees, consultants and agents, are subject to the Privacy Act and the requirements of the APPs contained in Schedule 1 of the Privacy Act.

The APPs regulate how federal public sector agencies and certain private sector organisations can collect, hold, use and disclose personal information, and how individuals can access and correct that information.

The APPs only apply to information about living individuals, not information about corporate entities such as businesses, firms or trusts. Detailed information and guidance about the APPs can be found on the Office of the Australian Information Commissioner (OAIC) website.

Definitions

“Personal information” is defined under the Privacy Act as information or an opinion about an identified individual, or an individual who is reasonably identifiable. This includes names, contact details and the USI itself in accordance with APP 9.

USIs are also defined as “protected information” under the SI Act, which limits their collection, use, or disclosure unless authorised by the SI Act. 

This privacy policy does not cover our handling of commercially sensitive information or other information that is not defined in the Privacy Act as personal information.

Personal information we collect and how we collect it

Collection of personal information

We are authorised to collect personal information under legislation, including but not limited to the SI Act.

We will only collect information for a lawful purpose that is reasonably necessary or directly related to one or more of our functions and activities, or where otherwise required or authorised by law.

Types of personal information collected:

We collect a range of personal information in records relating to:

  • the performance of our legislative and administrative functions
  • correspondence from members of the public to us and our Ministers, or correspondence otherwise referred to us by other Ministers or government agencies
  • feedback, compliments and complaints provided to us
  • the management of fraud and compliance matters
  • requests made to us under the Privacy Act and FOI Act
  • the provision of legal advice by internal and external lawyers.

Personal information we collect includes: 

  • full name
  • preferred name
  • mailing address
  • email address
  • home/mobile telephone number
  • date of birth
  • city or town of birth
  • country of birth
  • gender
  • services an individual has received, applied for or enquired about
  • answers to personal account security questions
  • data from previously revoked USI accounts 
  • details of identification - only the type of document used is retained
  • VET training information obtained from the National Centre for Vocational Education and Research (NCVER) to provide authenticated VET transcripts.

How personal information is collected

We collect personal information in different ways, including: 

  • directly from individuals when they access and use our website and online systems, including in relation to applying for a USI and managing their USI account
  • indirectly from individuals when they use our website and online systems such as cookies and clickstream data. As the USI website is hosted within DEWR’s web environment website operations, including the collection of cookies and clickstream data, follow the same technical settings and data practices as DEWR
  • when we, or someone on our behalf (e.g. DEWR staff supporting USI functions within approved roles), talks to a customer on the telephone and in person, including through the USI contact centre and customer surveys
  • in writing by letter, email or online form submission.

We may also collect personal information from other people (relevant third parties), including: 

  • other Australian, state and territory government agencies
  • law enforcement agencies
  • education and training providers
  • entities that provide services to us
  • authorised third parties who assist an individual with USI-related enquiries or transactions, including creating a USI on the individual's behalf, and parents or guardians acting on behalf of children aged 14 years and under.

Taking the above into account, we will generally collect personal information directly from an individual. However, we may collect personal information from a third party if: 

  • the individual consents (including where they have authorised an entity under section 9 of the SI Act to apply for a USI on their behalf)
  • we are required to or are authorised to collect the information by or under an Australian law, or a court or tribunal order.

When we collect personal information, we are required under the APPs to notify the individual of: 

  • the purposes for which we collect the information 
  • whether the collection is required or authorised by law 
  • any person or body to whom we usually disclose the information, including if those persons or bodies are located overseas
  • our privacy notices on our forms and website.

At times, personal information may be provided to us without us having requested it. When we receive unsolicited personal information, we will assess whether we would have been permitted to collect the information if it had been sought. If so, the information will be handled in accordance with the requirements of the Privacy Act. If we determine that collected information is not required for our functions or activities, subject to the requirements of the Archives Act 1983 (Archives Act), we will destroy or de-identify the information.

Collecting personal information from children and young people

In carrying out our functions and activities we may collect personal information about children and young people, either directly from them or through their parents or guardians. Where children and young people are aged 15 or over, our general policy is to collect information directly from them as they are likely to have the capacity to understand any privacy notices provided to them and to give informed consent to the collection.

For children under the age of 15, we will generally seek consent from a parent or guardian before collecting personal information. 

In limited circumstances, parental or guardian consent may not be required where:

  • seeking consent is unreasonable or impracticable 
  • the collection is required or authorised by or under an Australian law
  • the collection is required or authorised by a court or tribunal order.

Regardless of age, an individual’s capacity to provide informed consent may be affected by factors such as:

  • cognitive or intellectual disability
  • mental illness affecting decision‑making
  • acute medical situations
  • temporary incapacity (e.g. serious illness).

Where there is uncertainty about and individual’s capacity to provide informed consent, we will consider where consent should be obtained from a parent, guardian, or other authorised representative, unless an exception applies.

How we use personal information

We use personal information for several purposes as part of our legislative and administrative functions, including:  

  • processing an application for a USI 
  • verifying and/or assigning a USI 
  • resolving problems with an USI
  • identifying a USI account holder and maintaining that account
  • creating an authenticated VET transcript 
  • providing services to USI account holders and sending notifications 
  • responding to enquiries and providing information or advice about the USI initiative
  • maintaining accurate and up to date USI account holder details
  • processing and responding to feedback, compliments and complaints
  • data sharing and/or data integration with other Commonwealth, state and territory government agencies
  • preventing, detecting, investigating or dealing with misconduct and fraud, cyber-attacks against the Commonwealth, or other unlawful activity relating to the Commonwealth
  • administering requests received under legislation, including the Privacy Act and the Freedom of Information Act 1982 (FOI Act)
  • providing policy advice and support to our Ministers
  • management of correspondence 
  • for approved research purposes relating to education or training, as permitted under the SI Act and subject to any conditions or requirements specified by the Ministerial Council.

Disclosure

Who we may disclose personal information to

We may disclose personal information to authorised organisations, government departments, regulators and other persons where this is necessary for the Registrar to perform their functions or exercise their powers under the SI Act, including in accordance with the information handling and disclosure provisions in sections 18 to 22 of the SI Act.

Disclosure of personal information authorised or permitted by law

In some circumstances, we may disclose personal information where permitted or authorised under the SI Act, the Privacy Act or another law, including where the individual has consented to or would reasonably expect the disclosure, or where another legal basis or exception applies. 

Such circumstance may include: 

  • giving information to our service providers to allow them to assist in providing our services 
  • complaints handling, quality control and assurance
  • assisting others where relevant and allowable by law for investigations of fraud or misconduct, data sharing, data integration, or data matching
  • in connection with measures to prevent, detect, investigate or respond to misconduct, fraud, cyber-attacks against the Commonwealth, or other unlawful activity relating to the Commonwealth
  • administering our obligations under legislation, including in relation to privacy and FOI
  • the request and provision of internal and external legal advice.

Disclosure of personal information overseas

We will, on occasion, disclose personal information to overseas recipients, including in the following situations:

  • the provision of personal information to overseas researchers or consultants (where consent has been given for this or we are otherwise legally able to provide this information)
  • the provision of personal information to foreign governments and law enforcement agencies (in limited circumstances and if authorised by law)
  • where you or your authorised representative is located overseas.

We will not disclose personal information to an overseas recipient unless at least one of the following applies:

  • the recipient is subject to a law or binding scheme mostly similar to the APPs, including mechanisms for enforcement
  • the individual consents to the disclosure after being expressly informed that we cannot confirm the overseas recipient does not breach the APPs
  • a permitted general situation exists as set out in section 16A of the Privacy Act (e.g. to lessen or prevent a serious threat to life, health or safety)
  • disclosure is required or authorised by or under an Australian law, a court or tribunal order, or an international agreement relating to information sharing to which Australia is a party
  • disclosure is reasonably necessary for an enforcement related activity conducted by, or on behalf of, an enforcement body and the recipient performs similar functions.

Remaining anonymous or using a pseudonym

An individual may wish to remain anonymous or use a different name (pseudonym) when interacting with us, for example, to make an enquiry or complaint.

Individuals will be able to remain anonymous or use a pseudonym in some situations. There will be occasions where it will be impractical for an individual to remain anonymous and we will advise the individual when this occurs. For example, the Registrar is unable to assign a USI when the application is made anonymously, as under the SI Act, the Registrar needs to be satisfied the individual’s identity has been appropriately verified.

There may also be situations where the Registrar is required or authorised by law to deal only with an identified individual, in which case it may be necessary for an individual to identify themselves. This means that personal information is handled securely and only provided to the correct individual in accordance with the Privacy Act and other relevant legislation. Where adequate identification is not provided, the Registrar may be unable to process a request or provide access to information. 

Storage and data security

Storage

We store personal information in a range of electronic records, including in cloud storage, using DEWR’s information management environment.

USI records, including personal information held within the USI Registry System and records relating to current and revoked USIs, are retained, managed and disposed of in accordance with the Australian Government’s records management framework, including the Archives Act, general disposal authorities, and other whole-of-government policies and standards issued by the National Archives of Australia. Retention arrangements support ongoing evidentiary, administrative, accountability and privacy obligations. 

The USI Registry System collects and uses VET training information provided by the NCVER for the purpose of generating and providing authenticated VET transcripts to you through the USI Registry System. This information is not retained by the USI Registry System once the transcript generation process has been completed. Further information about NCVER's handling of personal information is available in NCVER's privacy policy.

Data security 

We take all reasonable steps to protect the personal information held in our possession against loss, unauthorised access, use, modification, disclosure or misuse. USI data is held in approved DEWR systems that apply protective‑security, cyber security and access‑control measures appropriate to the sensitivity of the information. 

Within this DEWR environment, we work collaboratively with relevant departmental business areas to apply secure storage practices that support the confidentiality, integrity and availability of USI data, including appropriate monitoring, audit logging and control of access and system changes. Access to individuals’ personal information held by us is restricted to authorised persons who are departmental staff on a need-to-know basis. Authorised personnel must comply with the Confidential Access and Information Undertaking, departmental policies, confidentiality obligations, and mandatory privacy and security training, to support the appropriate handling and protection of personal information.

Electronic records containing personal information are protected in accordance with Australian Government security policies, including the Attorney-General’s Department’s Protective Security Policy Framework (PSPF) and the Australian Signals Directorate’s Information Security Manual (ISM). Storage arrangements also incorporate resilience measures such as backup and recovery mechanisms consistent with departmental and whole of government security requirements.

Data quality

We take all reasonable steps to make sure that the personal information we collect, use and disclose is accurate, up to date, complete and relevant, consistent with our obligations under APP 10 of the Privacy Act. 

Reasonable steps include responding to your request to correct personal information when it is reasonable and appropriate to do so. For further information on correcting personal information see section 9 of this policy).

Automated Processing

The USI Registry System uses automated, rule‑based processing to support the performance of some of the Registrar’s functions and powers. This includes activities such as identity validation, data integrity checks, and the application of approved business rules to enable the creation and management of USIs.

These processes are designed to promote accuracy, consistency and efficiency in the handling of personal information. For example, system checks may: 

  • verify information against authoritative data sources
  • reduce the likelihood of duplicate or inconsistent records
  • support the consistent application of legislative and business rules.

The automated processes operate according to predefined approved human designed rules and do not involve adaptive or artificial intelligence techniques. They are narrowly scoped to administrative and validation functions and are proportionate to the purpose being performed.

These processes do not replace human judgement where discretion, case‑by‑case assessment, or interpretation is required. We may intervene or review automated outcomes, particularly where:

  • inconsistencies or anomalies are identified
  • a USI record cannot be verified
  • an individual raises a query for review or correction
  • there are potential privacy, data quality or other concerns.

Appropriate escalation pathways are in place to support the review of matters requiring human assessment by trained staff. This approach supports accurate and fair handling of personal information and enables decisions to be made subject to human determination.

Our website and other digital platforms

Passive collection

Individuals’ information is collected through several software applications, services and platforms used by the users’ device and by us to support us to deliver services. This type of information collection is ‘passive’ as we are not collecting this information directly and it does not directly relate to our provision of services. Individuals’ consent for their information to be collected and shared in this way when using an application or service on their device.

Information may be collected byType of information collectedInformation collected to
  • Internet browsers
  • Cookies
  • Google Analytics
  • technical and usage data such as the user’s browser type and language, server address, and location (if location services are enabled on a device)
  • date and time a user accessed a page on our site
  • the URL of the pages accessed and/or documents viewed on our site
  • how our website was accessed (e.g. from a search engine, link or advertisement).
  • measure the effectiveness of our content
  • better align our website content with user needs
  • identify technical issues and support system administration
  • support security, fraud detection and protection of the website and its users.
Social media platforms
  • information generated through page visits, likes, shares or interactions
  • viewing publicly available profile information associated with a user account
  • aggregated usage information and analytics which is made available by the relevant social media platform.
  • identify any emerging risks
  • understand what users know or misunderstand about the USI
  • support service delivery indirectly
  • analyse what information users engage with.

Individuals may be able to opt out of some of these passive data collections by:

  • disabling/refusing cookies 
  • disabling JavaScript 
  • opting out of Google Analytics 
  • disabling location services on their device.

Additional advice regarding how to protect users online can be found at Stay Smart Online.

Active collection 

We directly collect individuals’ information via our website. This information is primarily collected to enable us to carry out our functions and deliver certain services to users.

Information may be collected byType of information collectedInformation collected to
Social media platforms
  • information contained in comments, posts, replies or direct messages
  • any documents, screenshots or other personal information voluntarily provided by you.
  • respond to enquiries and requests for information
  • understand what users know or misunderstand about the USI
  • provide assistance relating to USI services and processes
  • analyse what information users engage with.
Qualtrics form
  • name
  • email address
  • phone number
  • any other information voluntarily provided in the form.
  • provide support in relation to USI services and processes
  • communicate with individuals about their enquiry, request or feedback
  • refer matters to the appropriate business area for action or response.

Use of authoritative digital identity and verification platforms 

We use authoritative Australian Government digital identity and verification services, including myID and the Relationship Authorisation Manager (RAM) administered by the Australian Taxation Office, Visa Entitlement Verification Online (VEVO) administered by the Department of Home Affairs, and the Document Verification Service (DVS) administered by the Attorney-General's Department, to verify an individual's identity and facilitate access to USI-related functions. These services support the administration of the USI scheme and assist the Registrar to perform their functions and exercise their powers in accordance with the SI Act.

These platforms rely on trusted and authoritative source records and operate within established legislative, security and assurance frameworks. Their use supports the integrity, security and lawful administration of the USI initiative and enables accurate, reliable decision‑making.

We limit the collection, use and disclosure of this information to what is reasonably necessary, apply strict access controls, and make sure that information is handled in accordance with privacy, security and data governance requirements. Decisions informed by these platforms remain subject to human oversight, accountability and review.

Postal mail service provider

We use a postal mail service provider to prepare and distribute written letter notifications to your postal address where you do not have, or do not wish to provide us with, an email address or mobile phone number.

To facilitate this service, we may disclose limited personal information to the provider, including your name, postal address and details necessary to prepare and send the communication. The provider acts on our behalf and is authorised to use this information only for the purpose of printing, preparing and delivering mail communications in accordance with our instructions. We take reasonable steps to protect personal information disclosed through contractual, administrative and technical safeguards, including secure data transfer arrangements and access controls that limit access to authorised personnel who require the information to provide the service. We require the provider to handle personal information in accordance with applicable privacy laws and to implement appropriate measures to prevent unauthorised access, use, disclosure, alteration or loss.

Online forms

We use online forms hosted by the approved DEWR platform Qualtrics, to collect information. 

Information collected through DEWR’s Qualtrics environment is stored in Australia on cloud infrastructure approved for Australian Government use. Qualtrics does not have access to data collected through forms. However, personal information may be shared with Qualtrics as part of Qualtrics providing support services to us. Qualtrics Privacy Policy provides further detail on how they manage collected information.

We may collect personal information including names, email addresses and other information relevant to the purpose of the form.

We use this information to evaluate and improve USI services and processes, understand stakeholder experiences and needs, inform policy and operational improvements, respond to feedback and enquiries, and support the administration of the USI initiative. We limit the collection, use and retention of personal information to what is reasonably necessary for these purposes and handle the information in accordance with privacy and data governance requirements. 

Email service provider

We engage DEWR’s third-party email service provider to manage certain distribution lists and email subscription services. To provide these services, the provider may collect personal information, including names, email addresses and other information required to manage subscriptions and communications.

We use this personal information to personalise content and for internal reporting, including evidence-based compliance activities. This service provider may also track location, device and operating systems, as well as interactions with the email sent using the service provider’s platform including the timestamp for when an email or link was accessed. Personal information collected by our email service provider is stored on servers located within Australia.

For further information about personal information in relation to DEWR’s third-party email service provider, please refer to their Privacy Policy.

DEWR’s third-party email service provider and its hosted servers are located within Australia. Your personal information collected by them will be stored in Australia.

Our website includes links to other websites. We are not responsible for the content and privacy practices of these sites and recommend that users examine each site’s privacy policy separately. 

We may use external social media and social networking services to communicate and engage with the public. When individuals interact with us through these platforms, the relevant service provider may collect and handle personal information for its own purposes, in accordance with its own privacy policy. Individuals should refer to the privacy policies of the relevant service provider for information about how their personal information is managed.

Accessing and correcting personal information

How to seek access to and correction of personal information

In accordance with APP12 (Access to personal information), you have a right under the Privacy Act to access personal information we hold about you. 

You also have a right under the Privacy Act to request corrections of any personal information that we hold about you if you think the information is inaccurate, out-of-date, incomplete, irrelevant or misleading.

To access or seek correction of personal information held by us, you can:

Access and correction process

Upon receipt of a valid request, we will, within a reasonable period and no later than 30 calendar days, provide access to the requested personal information in a manner that is reasonable and appropriate, unless a ground for refusal applies under the Privacy Act. 

Where you request the correction of personal information held by us, we will respond within 30 calendar days, in accordance with APP 13 – Correction of personal information. We will take reasonable steps to keep your information accurate, up to date, complete, relevant and not misleading.

While the Privacy Act requires us to provide access to, or correct, personal information on request, it also sets out circumstances in which we may refuse access or decline to correct personal information. If we refuse to provide access or decline to correct personal information, we will provide you with a written notice that provides our reasons for refusing the request. 

You may also seek access to, or amendment of, documents held by us under the FOI Act. Further information about making an FOI request is available on our Freedom of Information webpage. 

Privacy Impact Assessment

A Privacy Impact Assessment (PIA) is an assessment of a project that identifies the impact the project might have on the privacy of individuals, and makes recommendations for managing, minimising or eliminating that impact.

The Privacy (Australian Government Agencies — Governance) APP Code 2017 (Privacy Code) requires us to undertake a PIA in certain instances and to maintain a register of those PIAs from 1 July 2018. In accordance with the Privacy Code, you can view our PIA register.

Unauthorised Access, Use or Disclosure of Personal Information

Raising a concern you think there has been a breach of your privacy

If you think your privacy has been breached, you can raise the matter with us as a potential privacy incident.

We take privacy matters seriously and will promptly address any potential unauthorised access, use or disclosure of personal information. We adhere to the OAIC’s Notifiable Data Breaches (NDB) scheme.

We also follow relevant guidance material issued by the OAIC including data breach preparation and response guidance when responding to any incidents involving the unauthorised access of, use or disclosure of personal information. 

If you’re not satisfied with our response

If you’re not satisfied with our response, you can make a complaint, either directly to us (see our contact details below) or to the Office of the Australian Information Commissioner.

Privacy enquiries, complaints, requests for access or correction

Contact us if you wish to:

  • query how your personal information is collected, held, used or disclosed
  • request access to or seek correction of your personal information
  • ask a question about this privacy policy
  • make a privacy complaint
  • request a hard copy of this privacy policy (free of charge).

By mail:

Attention: Privacy Officer
Office of the Student Identifiers Registrar 
GPO Box 9828 
Adelaide SA 5001 
Australia

By email:

Attention: Privacy Officer

PolicyDataCompliance@usi.gov.au

By phone:

USI contact centre

Accountability

We have a designated Privacy Officer, as required under section 10 of the Privacy Code. The Privacy Officer is responsible for regularly reviewing this privacy policy and updating the privacy policy as required. We also have a Privacy Champion, as required under section 11 of the Privacy Code. The Privacy Champion is responsible for promoting a culture of privacy within the OSIR and providing leadership on strategic privacy issues.

Did you find the information you were looking for on this page?

Acknowledgement of Country

We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging.