1. PURPOSE
The Australia and New Zealand School of Government (ANZSOG) is a public purpose organisation established by the governments of Australia and New Zealand and leading universities. ANZSOG delivers executive education, research, and thought leadership to strengthen public sector capability across both countries.
This policy sets out how ANZSOG collects, holds, uses, and discloses personal information. It explains the purposes for which personal information is collected and outlines ANZSOG’s commitment to protecting privacy in accordance with the Privacy Act 1988 (Cth) (Privacy Act (Cth)), and, where applicable, the New Zealand Privacy Act 2020 (NZ Privacy Act).
ANZSOG is an APP entity for the purposes of the Privacy Act (Cth) and is required to comply with the Australian Privacy Principles (APPs). ANZSOG is also subject to the Information Privacy Principles (IPPs) contained in that Act. Where ANZSOG collects or handles personal information of New Zealand individuals in connection with its New Zealand activities, it will comply with the NZ Privacy Act and the Information Privacy Principles under that Act.
Where the requirements of the Privacy Act (Cth) and the NZ Privacy Act differ, ANZSOG will comply with the obligation that provides the highest level of protection for the individual concerned.
This policy supports transparency and accountability in all functions, activities, and services provided by ANZSOG.
2. OWNERSHIP
Policy authority: ANZSOG Board
Policy owner: Company Secretary
3. SCOPE
This policy applies to all employees, officers, faculty members, contractors, Participants and other parties in respect of their interaction with ANZSOG.
This policy governs ANZSOG’s handling of personal information of external parties, including Participants, Alumni, prospective participants, clients, and other individuals who interact with ANZSOG. The personal information of ANZSOG employees is subject to separate internal arrangements.
4. DEFINITIONS
Term | Definition |
Alumni | Participants who have completed ANZSOG programs. |
ANZSOG | Australia and New Zealand School of Government. |
Authorised Third Party | Employers, sponsors, participating universities, academic institutions, and referees who are authorised to provide or receive personal information. |
Collection Notice | A notice provided at or before the time of collection that explains who is collecting the information, the purposes of collection, the consequences of not providing it, the entities to which it may be disclosed, and how the individual may access and correct it. |
Digital Channels | Online platforms, websites, and tools used by ANZSOG to collect or process personal information. |
Employer | In respect of Participants working in any level of the Australian or New Zealand public service, Employer refers to your employing agency, department, commission or jurisdictional entity. |
Participant | An individual enrolled in or attending ANZSOG programs, events, or activities, whether in-person or online. |
Personal Information | Any information or opinion that identifies, or can reasonably identify, an individual. |
Self-Funded Participant | A Participant who is invoiced and pays their own enrolment or registration fee for an ANZSOG program, rather than having fees paid by an Employer or Authorised Third Party. |
Sensitive Information | Information or an opinion about an individual’s: • racial or ethnic origin; • political opinions; • membership of a political association; • religious beliefs or affiliations; • philosophical beliefs; • membership of a professional or trade association; • membership of a trade union; • sexual orientation or practices; • criminal record; • health information; • genetic information; • biometric information; or • biometric templates, that is also personal information. Sensitive Information is subject to additional protections under the Privacy Act 1988 (Cth). |
We, Us or Our | ANZSOG. |
You, Your or Yours | The reader of this Policy. |
5. ROLES AND RESPONSIBILITIES
Role | Responsibility |
ANZSOG Board | Approves this privacy policy as required. |
ANZSOG Executive | As policy authority has oversight and approval of this privacy policy and is responsible for the organisation’s compliance with this policy. |
Company Secretary | As policy owner ensures this policy is up to date and implemented across the organisation. |
Privacy Officer | Handles privacy enquiries, complaints, access/correction requests, and data breach notifications. |
IT Systems Administrators | Ensure secure storage, transmission, and destruction of personal information, and manage data breaches. |
All officers, employees, faculty members and contractors | Comply with this policy and any related procedures. Complete privacy awareness training as required by ANZSOG. |
Participants | Provide accurate personal information, notify ANZSOG of corrections or concerns and respect the privacy of others. |
6. POLICY
6.1 What is Personal Information
Personal information refers to any information or opinion that identifies, or can reasonably identify, an individual. It includes information such as your name, contact details, occupation, and other identifiers. Certain personal information is deemed to be Sensitive Information (as defined in Section 4) and is subject to additional protections.
6.2 Personal Information We Collect
ANZSOG collects personal information and non-identifiable data (e.g. aggregated analytics). The types of personal information ANZSOG may collect include:
Contact details: such as your name, address, email address, phone number;
Professional details: such as your occupation, Employer, position title, areas of work (past, present, anticipated);
Academic details: such as your qualifications and achievements;
Financial and payment information: such as your preferred payment method;
Sensitive Information: such as health and accessibility information provided for program support purposes (including dietary and allergy information provided for in-person programs, which is treated as Sensitive Information where it relates to a health condition);
Other personal information: such as your emergency contact details; and
dentification information: such as your passport and visa details.
We only collect personal information that is reasonably necessary for our functions, activities, and services. We do not collect personal information simply because it may be useful in the future.
Where it is lawful and practicable, you may interact with ANZSOG without identifying yourself or by using a pseudonym. However, in most cases we will need to verify your identity in order to process course applications, manage enrolments, provide educational services, or respond to specific enquiries.
6.3 Why We Collect Personal Information
We collect personal information that is reasonably necessary to support ANZSOG’s functions, activities, and services, including:
6.3.1 Course and Event Delivery
Assess applications for admission to programs, events, and educational activities.
Manage enrolments and participation in in-person and online ANZSOG programs.
Provide accessibility support services and learning adjustments.
Monitor academic performance and conduct.
Process payments and manage invoicing.
Administer and analyse surveys, polls, and other feedback mechanisms to support course delivery, participant engagement, and continuous improvement.
6.3.2 Scholarships and Awards
Assess applications for scholarships, prizes, and related opportunities.
6.3.3 Alumni Engagement
Manage membership and participation in the ANZSOG alumni programme.
Facilitate alumni networks and promote ANZSOG activities.
Tailor communications about events and alumni benefits to your interests.
6.3.4 Communication and Marketing
Send requested communications by email, SMS, phone, or LinkedIn.
Promote ANZSOG activities and services.
Conduct analysis, planning, and quality assurance.
6.3.5 Compliance and Improvement
Comply with legal obligations.
Improve our services, events, and website.
6.3.6 Payments
To invoice fees and to receive payment.
To process invoices and make payments.
6.3.7 International Event Delivery
To organise international programs and educational activities, including facilitating travel and visa processing.
6.3.8 Safety
To ensure we can reach your emergency contacts in the event of an emergency.
6.3.9 University Credentialing and Academic Administration
To facilitate the award of academic credentials by conferring universities. This includes collecting and holding admissions documents and academic records for the purposes of administering the relevant credential.
6.3.10 Tailored Solutions and Employer-Provided Programs
To arrange enrolments and deliver tailored programs where a client employer or government agency has engaged ANZSOG. In these cases, the client may provide participant information to ANZSOG for the purposes of administering the program.
6.4 How We Collect Personal Information
We collect personal information through a variety of methods. The main channels through which we collect information are set out below. The way we collect information will depend on how you interact with ANZSOG. Where we collect personal information about you from a third party, we will take reasonable steps to notify you, unless doing so would be unreasonable or impracticable. This includes information collected through ANZSOG’s learning platforms (including Canvas and Cahoot Learning) where participants provide information and generate data through their course participation.
6.4.1 Directly from You
When you apply for programs, events, or services;
When you respond to requests for information or subscribe to updates; and
Through direct interactions with ANZSOG staff, including by phone, email, in person, or via social media platforms (including LinkedIn).
6.4.2 From Authorised Third Parties
We may receive information about you from Authorised Third Parties from time to time. This includes:
employers or government agencies who provide participant lists for tailored programs (typically full name, position title, and email address), which ANZSOG holds in its systems including in Salesforce and SharePoint and, where applicable, its learning management system; and
conferring universities and academic institutions who may provide or confirm academic information in connection with credentialing activities.
6.4.3 Through Digital Channels
Please refer to the section below.
6.4.4 Collection Notices
At or before the time we collect your personal information (or as soon as practicable afterwards), we will take reasonable steps to provide you with a Collection Notice that explains: (a) who we are and how to contact us; (b) the purposes for which we are collecting the information; (c) the main consequences if the information is not collected; (d) the organisations or types of organisations to which we usually disclose information of that kind; and (e) how you may access and seek correction of the information. Collection Notices may be provided in different forms depending on the collection method, including on application forms, on our website, or verbally at the time of collection.
6.5 Information Collected Through Digital Channels
When you use our Digital Channels, we may collect certain technical and usage information, including:
Details about your device and browser (e.g., IP address, browser type, operating system);
Information about how you interact with our website, such as pages visited, clicks, and navigation patterns; and
Aggregated demographic and location data (where available).
Information generated through participation in ANZSOG learning platforms (such as Cahoot Learning and Canvas), including interaction data, contributions to discussions, and engagement with learning activities.
6.5.1 Use of Cookies and Analytics
We may use cookies and similar technologies to:
Measure website traffic and usage patterns;
Analyse how visitors use our website; and
Improve our online services.
You may reject or disable cookies through your browser settings. Most browsers allow you to refuse cookies before they are set, as well as to delete cookies that have already been placed.
6.5.2 Third-Party Digital Services
We use third-party analytics, marketing, and program delivery tools to support our services and operations. These include but are not limited to:
Salesforce: for customer relationship management and email marketing. Salesforce collects contact details, email engagement data, and website interaction data. Data is stored in Australia.
Campaign Monitor: for email marketing communications. Campaign Monitor collects contact details and email engagement data. Data is stored in Australia and may also be processed overseas.
Canvas (Instructure): our learning management system for program delivery. Canvas collects participant names, enrolment details, grades, course content and activity data. Data is stored in Australia.
Cahoot Learning: for program delivery and learning engagement. Cahoot Learning collects and processes participant information including name, profile details, enrolment and cohort information, and learning activity data (such as participation, posts, assessments, and feedback). This information is used to deliver interactive learning experiences, support facilitation and engagement, evaluate learning progress and outcomes, and provide reporting to ANZSOG and, where applicable, participant employers or sponsoring organisations. All data is hosted on Amazon Web Services (AWS) infrastructure located in Sydney, Australia.
Curio Group (Learner Journal): Curio Group provides an optional Learner Journal tool accessible via Canvas. Curio collects limited personal information scoped to administrative users only (full name, email address, IP address at time of access, internal account identifiers, and encrypted authentication credentials). Learner Journal content is not accessed by Curio unless ANZSOG explicitly authorises this for a specific support request. All data is stored in Sydney, Australia on AWS infrastructure (AWS RDS), encrypted at rest (AES-256) and in transit (TLS).
Zoho Backstage: An event management platform used to plan, promote, register, and manage programs, conferences, and events. It supports attendee registration, ticketing, payment processing, event communications, session management, attendance tracking, and event reporting. It stores attendee, registration, ticketing, payment, attendance, and event data. Data is stored in Sydney, Australia.
Zoho PageSense: for registration page analytics. Zoho PageSense collects anonymised browsing data including pages visited, session duration, referral sources, and form completion rates. Data is stored in Sydney, Australia.
Google Analytics: for website analytics. Google Analytics collects anonymised browsing data including pages visited, session duration, and referral sources. Data is processed on Google’s global infrastructure and may be stored or processed outside Australia, subject to Google’s privacy policy and applicable data protection frameworks.
MYOB: for invoicing and registration records and processing invoices and making payments. MYOB collects individual registration and financial information, including bank account details for suppliers. MYOB’s privacy policy discloses that personal information may be processed overseas by MYOB’s sub-processors, including in New Zealand, the Philippines, and the United States. MYOB data is otherwise held in Australia.
Prospend: for issuing purchase orders, scanning invoices, electronic approval workflow and validating banking details. Data is stored in Australia.
6.5.3 Digital Advertising and Remarketing
We may use remarketing tools and tracking technologies on our website. As a result, you may see ANZSOG content or advertisements on other online platforms after visiting our site. These tools use cookies and pixels to understand how visitors interact with our website, but they do not use your personal information for any purpose other than presenting ANZSOG content. You may manage, reject, or disable cookies through your browser settings.
6.5.4 Data Handling by Third-Party Services
Some services we use may operate internationally and comply with the laws of their respective jurisdictions. Where required, they may disclose information to law enforcement or regulatory authorities.
ANZSOG engages third-party providers, including Cahoot Learning, to support the delivery of its services. ANZSOG takes reasonable steps to ensure these providers handle personal information in accordance with applicable privacy laws, including the Privacy Act 1988 (Cth), and applies appropriate contractual, technical, and organisational safeguards.
6.6 What Happens If We Cannot Collect Personal Information
Providing accurate and complete personal information to us enables us to carry out our functions and deliver our services effectively. If we do not have the information we need, we may be unable to:
offer you the full range of programs, events, or services for which you may be eligible;
share tailored information about opportunities, research, or activities that matter to you;
tailor our communications and online content to your circumstances;
contact your emergency contacts when required; and/or
arrange travel opportunities when you are engaged in one of our international programs.
6.7 How We Use and Disclose Your Personal Information
We use and disclose your personal information for the primary purpose for which it was collected, as described in section 6.3. We use your personal information for the following lawful purposes:
6.7.1 Providing Services
Delivering programs, events, and related activities.
Managing enrolments, alumni engagement, and communications you request.
Delivering and supporting learning experiences through ANZSOG’s digital learning platforms, including Cahoot Learning.
6.7.2 Service Improvement
Responding to enquiries and tailoring information to your interests.
Assessing and improving our website and services.
Keeping your details accurate and up to date.
6.7.3 Compliance and Administration
Processing complaints and meeting legal or regulatory obligations.
Supporting reporting requirements for partner organisations and government agencies.
6.7.4 Government Workforce Management Disclosures
In carrying out our usual activities, ANZSOG provides aggregated reporting to government agencies about program participation and completion rates for their employees. The following rules apply:
We may provide aggregated program participation and completion data to government agencies. We take reasonable steps to ensure that aggregated data is presented at a level that does not identify individual participants. Where a cohort is too small to prevent identification, we will either seek consent from the relevant participants or decline to provide disaggregated data.
For agency-funded enrolments, we may provide individual-level reporting (including participant names and program outcomes) to the Participant’s direct Employer, parent department, or relevant Public Sector Commission, as required for workforce management purposes.
For self-funded enrolments, individual-level data will only be shared with a government body or employer where the Participant has provided explicit consent. This will be made clear in the Collection Notice at the time of enrolment.
Position title information will only be included in any disclosure with the Participant’s consent. This will be made clear in the Collection Notice at the time of enrolment.
6.7.5 Sharing with Authorised Third Parties
If an Authorised Third Party requests Participant details, we may provide program and year of participation only. We will not provide a Participant’s name, position title, or any other individually identifying information without that Participant’s explicit consent.
When responding to broader requests for information not covered above, we will either seek consent from the individual Participants before sharing identifiable information, or provide non-identifiable details only.
6.7.6 Passport and Visa Information
For some programs, we may need to collect and hold passport and visa details (including copies of passports or documents containing passport information) to facilitate international travel, visa processing, and compliance with host country requirements.
This information will only be used for the stated purpose, shared with authorised parties where necessary (e.g. travel providers, government authorities), and handled securely.
Passport and visa details will be destroyed once they are no longer required, including removal from email trails and systems, in line with ANZSOG’s Records Retention and Disposal Authority.
6.7.7 Who We May Share Information With
In addition to those parties set out above, we may disclose personal information to the following categories of recipients:
ANZSOG directors, employees, faculty members and contractors;
Authorised Third Parties;
conferring universities and academic collaborators — for participants in programs that lead to an academic credential, we share certain information with the relevant conferring university only, including admissions documents (such as birth certificates, passports, CVs, and marriage certificates in the case of name changes) and academic records (including assessment results and transcripts), solely for the purposes of administering the relevant credential;
faculty members engaged to deliver programs — where a client has provided participant information (typically full name, position title, and email address) for the purposes of arranging enrolments, ANZSOG may share that information with the relevant faculty members via email as needed for program delivery;
service providers who assist with IT, web hosting, mailing, analytics, and other operational needs; and
organisations or individuals where disclosure is required by law or authorised by you.
We do not sell, trade, or otherwise commercialise your personal information. Any disclosure is strictly for the purposes outlined in this Privacy Policy.
6.8 Secondary Purposes
We may also use or disclose your personal information for a secondary purpose where:
you have consented to the secondary use or disclosure;
you would reasonably expect us to use or disclose the information for the secondary purpose, and that purpose is related to the primary purpose of collection (or, in the case of Sensitive Information, directly related to the primary purpose);
the use or disclosure is required or authorised by or under Australian or New Zealand law; and/or
the use or disclosure is otherwise permitted under the Australian Privacy Principles.
6.9 Direct Marketing
We may use your personal information to send you updates about ANZSOG programs, events, and services that may be relevant to you. These communications may be sent by email, SMS, phone, or LinkedIn in line with applicable laws. If you have a preferred communication method, we will endeavour to accommodate it. You may opt out of marketing communications at any time by using the unsubscribe link in our messages or by contacting us. Once you opt out, we will remove you from the relevant mailing list(s). We do not share your personal information with other organisations for their marketing purposes.
6.10 Accessing and Updating Your Information
You have the right to access the personal information we hold about you and to ask for corrections if it is inaccurate or incomplete. We take reasonable steps to ensure that the personal information we collect, use, and disclose is accurate, up-to-date, complete, and relevant. If you believe any of the information we hold about you is incorrect or out of date, please contact us so we can update our records. This includes personal information held within ANZSOG systems and learning platforms, including Canvas and Cahoot Learning.
6.10.1 How to Access Your Information
You may contact us at any time to request a copy of the personal information we hold about you. We will respond to your request within 30 days of receiving it, as required by APP 12.
6.10.2 Costs
There is no charge to submit a request or to have your details corrected. In limited circumstances, a reasonable fee may apply for providing access to information, but we will advise you of any applicable charge before proceeding.
6.10.3 Corrections
If any information we hold about you is inaccurate, incomplete, or out of date, please notify us and we will take reasonable steps to correct it. If we are unable to make the requested correction, we will provide you with written reasons and inform you of the available complaint mechanisms. At your request, we can associate a statement with the record noting the correction you have sought.
6.10.4 When Access May Be Limited
In some situations, we may not be able to give access (for example, if it affects someone else’s privacy or breaches confidentiality). If this happens, we will provide you with written reasons and explain your options.
6.11 How to Make a Privacy Complaint
If you have a concern about how your personal information has been handled, or if you wish to make a complaint about a potential breach of your privacy, please contact our Privacy Officer using the details in section 7 below.
Provide as much detail as possible so we can investigate.
We may ask you to confirm the details and what outcome you expect.
We will confirm whether we will investigate, who is handling it, and an estimated timeframe.
Once the investigation is complete, we will provide you with the outcome in writing and invite your feedback.
We aim to resolve all privacy complaints within 30 days of receipt. If we need more time, we will let you know and explain the reason for the delay.
If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au. If your complaint relates to the handling of personal information under New Zealand law, you may complain to the New Zealand Privacy Commissioner at www.privacy.org.nz.
6.12 Data Breaches
ANZSOG maintains security measures to reduce the risk of data breaches. If a breach occurs, we will:
notify you promptly by email; and
comply with all legal obligations under Australian and New Zealand data breach laws.
Under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act (Cth), ANZSOG is required to notify affected individuals and the OAIC when a data breach is likely to result in serious harm to any individual to whom the information relates. ANZSOG maintains a Data Breach Response Plan that sets out the steps for identifying, containing, assessing, and responding to data breaches, including the assessment of whether a breach is an eligible data breach under the NDB scheme.
6.13 Cross-Border Transfers
Some of our IT and cloud service providers store personal information in Australia and in certain overseas locations. Where information is stored or processed overseas, we take reasonable steps to ensure that service providers handle personal information in accordance with Australian and New Zealand privacy laws and apply appropriate technical, security, and contractual safeguards.
Before disclosing personal information to an overseas recipient, ANZSOG will take reasonable steps to ensure that the overseas recipient does not breach the Australian Privacy Principles in relation to that information (APP 8). This may include one or more of the following measures: (a) entering into contractual arrangements that require the recipient to handle personal information in accordance with the APPs; (b) satisfying itself that the recipient is subject to a law or binding scheme that is substantially similar to the APPs and that includes mechanisms for enforcement; or (c) obtaining your informed consent to the overseas disclosure after advising you that APP 8.1 will not apply.
For certain international program deliveries, ANZSOG may be required to share personal information (including identification documents) with overseas government bodies, host institutions, or travel service providers. In these cases, ANZSOG cannot guarantee the security standards of all overseas parties involved. Participants in international programs will be informed of this limitation in their Collection Notice prior to the relevant activity.
6.14 Security
We take reasonable steps to protect your personal information from misuse, loss, or unauthorised access. Our security measures include:
access controls based on Single Sign-On (SSO via Microsoft Azure AD with Multi-Factor Authentication (MFA)), licence assignment, and Access Control List (ACL) management;
secure storage of electronic and hard copy records;
periodic internal IT audits and General IT Controls (GITC) reviews of user access to business applications;
documented Information Security Management System (ISMS) processes for access control;
audit trails for access to and modification of personal information in key systems; and
secure destruction or de-identification of personal information when it is no longer needed for any purpose permitted under the APPs.
While we take reasonable steps to protect information transmitted electronically, no data transmission over the internet can be guaranteed to be completely secure.
6.15 Data Retention
ANZSOG retains personal information only for as long as it is needed for the purposes described in this policy, or as required by law. When personal information is no longer needed, it is securely destroyed or de-identified. Key retention periods include:
Course and enrolment records: 7 years after the student’s last year of enrolment (see ANZSOG RDA);
Summary records of final results and graduation records: 75 years after completion;
Learning platform data (including Cahoot Learning and Canvas): retained only as long as required to support program delivery, learning records, and certification, after which it is securely deleted or de-identified;
Financial records: as required by applicable tax and accounting legislation and in accordance with MYOB’s data retention practices. MYOB may retain individual registration and invoicing records for longer than 7 years and that data may be processed overseas by MYOB’s sub-processors (including in New Zealand, the Philippines, and the United States);
Alumni records: retained for the duration of alumni engagement, unless the individual requests deletion;
Passport and visa information: destroyed once no longer required for the relevant program, including removal from email trails; and
Website analytics and registration page analytics data (including Google Analytics and Zoho PageSense): retained in accordance with the applicable platform settings.
Further detail is set out in ANZSOG’s Records Retention and Disposal Authority.
6.16 Privacy Impact Assessments
ANZSOG may conduct a Privacy Impact Assessment before commencing any significant new project, system, or process that involves the collection, use, or disclosure of personal information, particularly where the project involves new technology, large-scale data processing, or new data-sharing arrangements with third parties.
6.17 Training
ANZSOG provides privacy awareness training to staff to support compliance with this policy and applicable privacy laws. Privacy awareness training is incorporated into staff onboarding and into ANZSOG’s periodic mandatory compliance refreshers.
6.18 Links to Other Websites
Our website may link to third-party sites. We are not responsible for their privacy practices or content. We recommend reviewing the privacy policies of those sites before providing any personal information.
6.19 Changes to Our Privacy Policy
ANZSOG may update this policy from time to time to reflect changes in our practices or legal requirements. The latest version of this policy will always be available on our website. Where we make material changes, we will publish an updated version on our website. We encourage you to review this policy periodically.
7. CONTACT US
If you have questions about this policy, or wish to raise a concern or complaint about how your personal information has been handled, please contact us using the details below or by using our Contact page at https://anzsog.edu.au/contact.
Privacy Officer
ANZSOG
PO Box 230, Carlton South, Victoria 3053
Email: engage@anzsog.edu.au
We treat all enquiries and complaints confidentially and will respond promptly to discuss your concerns and work towards a resolution.
This privacy policy is effective as of 27 August 2026.

