Privacy statement
This privacy statement describes how Curtin University (the University) collects, handles, uses and shares personal information in its possession or control and explains your obligations and rights. The University’s privacy statement is regularly reviewed, it is therefore your responsibility to monitor this statement for changes which may be implemented from time to time.
For information about the collection of information via our website and other digital channels, please refer to the Curtin University cookies statement.
Privacy and personal information
Privacy
At Curtin, the privacy of students, staff and other people who the university deals with is taken very seriously. Much of the information that the university collects in connection with its normal functions and activities is personal information, and this information should be handled in accordance with the privacy policy and privacy procedures and with community expectations.
What is personal information?
Personal information is –
(a) any information or opinion which, whether true or not, and whether recorded in a material form or not, relates to an individual, whether living or dead, whose identity is apparent or can reasonably be ascertained from the information or opinion; and
(b) includes information of the following kinds to which paragraph (a) applies —
- a name, date of birth or address
- a unique identifier, online identifier or pseudonym
- contact information
- information that relates to an individual’s location
- technical or behavioural information in relation to an individual’s activities, preferences or identity
- inferred information that relates to an individual including predictions in relation to behaviour, preferences or profiles generated from aggregated information
- information that relates to 1 or more features specific to the physical, physiological, genetic, mental, behavioural, economic, cultural or social identity of an individual
Personal information may also include specific information referred to as sensitive personal information which is information that relates to racial or ethnic origin; gender identity (where this does not correspond to the designated sex at birth); sexual orientation or practices; political opinion; membership of a political association; religious beliefs or affiliations; philosophical beliefs; membership of a professional or trade association or trade union; criminal record as well as health information, genetic or genomic information (other than health information); biometric information or any information from which such information can be inferred.
Raising a privacy concern
Raising a privacy complaint can be difficult and we encourage students, employees and the university community to review our advice on managing a privacy complaint at Curtin to better understand the process.
For further information and advice on making a privacy complaint, refer to advice from the Office of the Information Commissioner.
Privacy Complaints at Curtin can be made using this incident form (your identity will be collected). You can make an anonymous complaint by contacting the Privacy Officer on 08 9266 3965 or by post to Curtin University, Privacy Officer, GPO Box U1987, Perth, WA 6845
Advice and resources

Advice and resources
Student can locate details about what information we collect about them, how it is used, and who to talk to if they have any concerns by referring to the student privacy collection notice.

Privacy impact assessments
A privacy impact assessment is a process used to find out whether a project, function or activity may have an impact on the privacy of individuals. If you are starting a project, function or activity which will involve personal information of individuals or which changes the way we already use personal information, then you might need to conduct a privacy impact assessment before you start.
To consider whether a privacy impact assessment is needed, please complete our privacy impact assessment checklist and forward a copy to privacy@curtin.edu.au

Managing an information breach
An information breach can be any unauthorised access to or disclosure of personal and sensitive information. It can also be the loss of a Curtin device which holds or has access to personal information or sensitive personal information.
In the event of an actual or suspected information breach, even if it is not deliberate or malicious, refer to the information management procedure and email privacy@curtin.edu.au

Privacy and artificial intelligence
Curtin has adopted the definition of an artificial intelligence (AI) system from the International Organization for Standardization ISO/IEC 22989 as ‘an engineered system that generates outputs such as content, forecasts, recommendations or decisions for a given set of human-defined objectives’. Some examples of AI systems are chatbots, digital assistants, analytics tools, document editing or customer profiling.
Curtin encourages the safe, responsible and ethical use of AI systems in accordance with the AI policy and S.E.C.U.R.E. framework.
The Office of the Information Commissioner provides advice on privacy and accountability in automated decision-making, which should be referred to in any selection of AI systems.

Curtin’s privacy framework
At Curtin, we publish our privacy Statement, privacy values and privacy management framework to ensure all members of the Curtin community are aware of their rights and obligations.

Other external resources
Further information can be found from the West Australian Office of the Information Commissioner, or by referring to the Privacy and Responsible Information Sharing Act (WA (2024).
Contact: The Privacy Officer on 08 9266 3965 or privacy@curtin.edu.au