
This mark confirms that an organisation operates a privacy program aligned with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It gives customers and partners a checked assurance that personal information is handled responsibly. It is an independent alignment assessment against a public framework. It is not a determination by, or an endorsement of, the Office of the Australian Information Commissioner, and it must never be presented as government approval.
What this mark certifies
This mark confirms that an organisation operates a privacy program aligned with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It gives customers and partners a checked assurance that personal information is handled responsibly. It is an independent alignment assessment against a public framework. It is not a determination by, or an endorsement of, the Office of the Australian Information Commissioner, and it must never be presented as government approval.
The mark certifies the privacy program assessed at the point of assessment. It does not guarantee that the organisation will never experience a data breach, and it must not be presented as such a guarantee. It confirms that the program, its policies and its practices were aligned with the Australian Privacy Principles when assessed.
Certification requirements
Evidence required
How it is assessed
The privacy program is assessed against the current Australian Privacy Principles by an approved certifier with demonstrated privacy competence. The certificate records the certified privacy program as at the assessment date.
Re-verification and monitoring
Certification is valid for twelve months and is subject to annual re-verification of the privacy program.
Grounds for refusal, suspension or revocation
Certification is refused, suspended or revoked where a material lapse occurs in the privacy program, or where a notifiable data breach remains unremediated in a way that indicates the program is no longer aligned with the Australian Privacy Principles.
Contractual obligations on the badge holder
In addition to the core terms of the CAQA Certified Licence Agreement in Section 4, a holder of this mark agrees to the following obligations specific to this badge.
The holder must maintain a privacy program aligned with the current Australian Privacy Principles throughout the licence term.
The holder must notify CAQA in writing within fourteen days of any eligible data breach under the Notifiable Data Breaches scheme that indicates a material failure of the certified privacy program, without limiting the holder's separate obligations to affected individuals and to the Office of the Australian Information Commissioner.
The holder must not represent that the mark is a government approval, a regulator determination, or a guarantee against data breaches.
The holder must provide updated privacy documentation at re-verification and within ten business days of a request by CAQA.
The holder warrants that the privacy documentation and practices provided are true and current.
Service lines across every CAQA brand, one standard of quality. Scroll the wall or jump straight to a brand.
To Receive Updates And Offers