Data Protection & Privacy
Client and candidate data is handled under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), with data held onshore and access restricted to what a role actually requires.
- Data minimisation and purpose limitation for every system we build or operate
- Encryption at rest (AES-256) and in transit (TLS 1.2+) for all client and candidate data
- Australian-hosted data residency, with client data logically segregated per engagement
- Notifiable Data Breaches (NDB) scheme compliance — assessment and notification within statutory timeframes
- Defined retention schedules with secure, logged disposal at end of life