What records AusISA keeps, how long we keep them, how they are protected, and how you can request your own records, including the limits that apply.
This policy sets out how AusISA creates, stores, protects, retains, provides access to, and disposes of records, including assessment records.
This policy applies to all records created or received by AusISA in the course of its activities, in any format, including enrolment and registration records, assessment and moderation records, attendance records, complaint and appeal records, financial records, vetting records, and correspondence.
This policy applies to all AusISA staff, facilitators, and contractors who create or handle AusISA records.
This policy must be read with the Privacy Policy, which governs the handling of personal information within records, and the Complaints & Appeals Handling Policy.
This policy operates subject to applicable Australian law, including the Privacy Act 1988 (Cth) and tax and corporate record-keeping requirements.
Record means information in any format created, received, or maintained by AusISA as evidence of its activities and decisions.
Assessment Record means a candidate's submitted work, marking records, moderation records, invigilation records, and results.
Participant Record means the records AusISA holds about an individual participant, including enrolment, attendance, assessment, and correspondence records.
Sanitisation means the removal or redaction of parts of a record before release.
Retention Period means the minimum period a record must be kept before it is eligible for disposal.
Records are accurate, attributable, and created at or near the time of the event they document.
Records are stored securely, with access limited to those who need them to perform their role.
Records are retained no longer than needed to meet operational, legal, and endorsement obligations, and are disposed of securely.
Participants can see the records held about them, subject to the limits in section 7.
AusISA Administration is responsible for the record-keeping systems, the retention schedule, and the handling of access requests.
Facilitators must create and submit the records required for their engagement (including attendance, invigilation, marking, and moderation records) accurately and promptly, and must not retain participant records after their engagement ends.
All staff and facilitators must store AusISA records only in AusISA-approved systems, not in personal storage, personal email, or unapproved third-party services.
AusISA records are stored in Australia on Amazon Web Services infrastructure in the Asia Pacific (Sydney) region, consistent with the Privacy Policy.
Records are encrypted at rest and in transit, and administrative access requires multi-factor authentication.
Assessment materials and unreleased results are access-restricted to the marker, moderator, and AusISA Administration.
Backups are maintained with tamper-resistant retention controls.
Records containing security-classified or DISP-sensitive information are handled in accordance with the applicable security obligations, which prevail over this policy to the extent of any inconsistency.
A participant may request a copy of their Participant Record, or other information AusISA holds about them, by emailing privacy@ausinfosec.academy.
AusISA will acknowledge an access request and respond within 30 days (P-015).
AusISA will provide the requested records, but the released records may be sanitised where release would risk the integrity of an ongoing course or assessment (for example, records revealing examination content, marking matrices, or unreleased results), or where the intellectual property in the material does not rest with the participant, including AusISA course materials, assessment instruments, marking guides, and third-party or Endorsing Entity content.
Where a record contains another person's personal information, that information will be redacted unless disclosure is authorised or required by law.
Where AusISA sanitises or declines part of a request, it will tell the participant that material was withheld and the reason, unless the law prevents that disclosure.
A participant's own submitted assessment work is part of their Participant Record; the marking matrix and model answers applied to it are not.
A participant may request correction of inaccurate, incomplete, or out-of-date information in their record, in accordance with the Privacy Policy.
A participant who is dissatisfied with an access or correction decision may complain under the Complaints & Appeals Handling Policy or to the Office of the Australian Information Commissioner.
Course registration, enrolment, and financial records: 7 years from course completion (P-013), consistent with Australian tax record-keeping requirements.
Assessment Records, including marking and moderation records: 7 years from result release, to support endorsement verification, appeals, and audit.
Learning management system accounts: duration of enrolment plus 2 years (P-014).
Complaint and appeal records: 7 years from closure of the matter.
Vetting records: retained in accordance with the Participant Vetting Policy, and no longer than needed for the decision and any review of it.
Notification and marketing subscriptions: until the person unsubscribes, at which point the record is deleted.
Where an Endorsing Entity, law, or legal hold requires longer retention of a record, that requirement prevails.
Records past their Retention Period are disposed of securely: digital records are deleted such that they are not reasonably recoverable, and physical records are destroyed by secure means.
Disposal is suspended for any record subject to a current or reasonably anticipated complaint, appeal, investigation, legal proceeding, or Endorsing Entity inquiry.
Abandoned pre-enrolment uploads (documents uploaded to a registration form that is never submitted) are deleted automatically after 7 days.
AusISA Administration audits record-keeping practices periodically and addresses gaps under the Continuous Improvement Policy.
A suspected loss, unauthorised access, or unauthorised disclosure of records must be reported to AusISA Administration immediately, and is handled under the Privacy Policy where personal information is involved, including any notifiable data breach obligations.
Any exception to this policy must be approved in writing by AusISA Administration before it is relied upon, and will be recorded with the reason and duration of the exception. No exception may reduce a retention period below a legal minimum.
Privacy Policy (GOV-013); Complaints & Appeals Handling Policy (GOV-005); Assessment Policy (GOV-004); Participant Vetting Policy (GOV-011); Continuous Improvement Policy (GOV-012).
Privacy Act 1988 (Cth) and the Australian Privacy Principles; Corporations Act 2001 (Cth) record-keeping requirements; A New Tax System (Goods and Services Tax) Act 1999 (Cth) and Income Tax Assessment Act 1997 (Cth) record-keeping requirements; Notifiable Data Breaches scheme (Part IIIC, Privacy Act 1988 (Cth)).
This policy is reviewed at least every 12 months (P-016), and earlier where an incident, legal change, or continuous-improvement finding warrants an out-of-cycle review.