Data Protection
Document control
Policy title: Data Protection Policy
Organisation: flowprofiler® Pty Ltd
Policy owner: Rebecca Chalmers, Executive Sponsor
Operational lead: Rebecca Chalmers, Data Protection Lead
Assurance lead for AI systems and agents: Bronwyn, AI Agent Compliance, Governance and Assurance Manager
Version: 2.0
Effective date: 16 July 2026
Review date: July 2027, or earlier following a material legal, operational or technological change
Classification: Internal policy
1. Purpose
This policy establishes how flowprofiler® Pty Ltd protects personal information and complies with applicable privacy and data-protection requirements. It sets minimum standards for the collection, use, storage, access, disclosure, transfer, retention and deletion of personal information processed through:
- flowprofiler® assessment platforms and products;
- client-sponsored assessments and surveys;
- training, coaching and professional development services;
- websites, marketing and customer communications;
- employment and contractor administration;
- business systems and supplier relationships;
- product development, testing and research; and
- artificial intelligence, automated tools and AI agents.
The policy is intended to ensure that personal information is handled lawfully, fairly, transparently, securely and only for appropriate purposes.
2. Organisational identity
The operating legal entity is: flowprofiler® Pty Ltd, Australia
Privacy and data-protection enquiries must be directed to:
Data Protection Lead
Email: hello@flowprofiler.com
3. Scope
This policy applies to:
- directors;
- employees;
- contractors;
- consultants;
- trainers and facilitators;
- authorised delivery partners;
- system administrators;
- developers and technical suppliers;
- temporary workers and interns;
- AI agents and automated systems acting for or on behalf of flowprofiler® Pty Ltd; and any other person who has access to personal information controlled or processed by flowprofiler® Pty Ltd.
It applies to personal information in any form, including information held:
- electronically;
- in cloud-based systems;
- in emails or collaboration platforms;
- on authorised devices;
- in assessment reports;
- in audio, video or image form;
- in structured databases;
- in paper records; and
- in backups, logs and archives.
Compliance with this policy is a condition of access to flowprofiler® information and systems.
4. Applicable framework
flowprofiler® Pty Ltd will comply with the privacy and data-protection laws that apply to each processing activity, including, where applicable:
- the Australian Privacy Act 1988 and Australian Privacy Principles;
- the Australian Notifiable Data Breaches scheme;
- the United Kingdom General Data Protection Regulation;
- the United Kingdom Data Protection Act 2018;
- the United Kingdom Data (Use and Access) Act 2025;
- the European Union General Data Protection Regulation;
- applicable electronic-marketing and cookie requirements; and
- relevant contractual data-protection obligations.
Where more than one legal framework applies, flowprofiler® Pty Ltd will apply the requirements relevant to the individuals, client, processing activity and jurisdictions involved.
Where this policy provides a higher level of protection than the minimum required by law, this policy will apply unless there is a documented legal or contractual reason to take a different approach.
5. Definitions
Personal information or personal data
Information relating to an identified or reasonably identifiable individual. This includes information that identifies a person directly and information that may identify a person when combined with other available information.
Assessment information
Personal information associated with a psychometric assessment, survey or development activity, including:
- participant details;
- assessment invitations;
- responses;
- scores;
- profiles;
- dimension results;
- written comments;
- rater feedback;
- reports;
- completion records; and
- interpretation or development notes.
Assessment information must be treated as confidential personal information. It is not automatically sensitive or special-category information. It may become sensitive or special-category information where it reveals or directly concerns health, disability, ethnicity, religion, political beliefs, sexual orientation, trade-union membership or another legally protected category.
Sensitive information
Information afforded additional protection under Australian privacy law, including certain information about health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, trade-union membership, criminal records and biometric information.
Special-category data
The corresponding categories of specially protected personal data under UK or European data-protection law.
Controller
The person or organisation that determines why and how personal information will be processed.
Processor
A person or organisation that processes personal information on the documented instructions of a controller.
Subprocessor
A third party engaged by a processor to process personal information for the controller.
Processing
Any operation performed on personal information, including collecting, recording, organising, storing, accessing, analysing, scoring, altering, retrieving, sharing, transmitting, restricting, deleting or destroying it.
Data subject or individual
The person to whom personal information relates.
Personal data breach
A security incident resulting in accidental or unlawful loss, destruction, alteration, unauthorised disclosure of, or access to personal information.
A breach may involve confidentiality, integrity or availability.
De-identified information
Information that has been processed so that an individual is no longer reasonably identifiable. De-identification must consider whether the information could be re-identified when combined with other reasonably available information.
6. Controller and processor roles
The role of flowprofiler® Pty Ltd must be determined for each processing activity. Its role must not be assumed solely from the product or contractual relationship involved.
6.1 Controller activities
flowprofiler® Pty Ltd generally acts as controller for personal information relating to:
- its websites and online enquiries;
- prospective and direct customers;
- client contacts;
- contracts, invoicing and accounts;
- marketing and event communications;
- trainers, facilitators and delivery partners;
- suppliers and professional advisers;
- job applicants, employees and contractors;
- complaints and privacy requests;
- product security and platform access records;
- internal governance and compliance;
- fraud prevention and legal claims; and
- its own product development and research activities where flowprofiler® determines the purpose and means of processing.
flowprofiler® Pty Ltd may also act as controller for security logs, authentication records and other information necessary to operate and protect its platform, even where it acts as processor for the underlying client assessment information.
6.2 Processor activities
flowprofiler® Pty Ltd generally acts as processor where a client commissions an assessment, survey or related service and determines:
- why participants are being assessed;
- who will participate;
- the lawful basis for the assessment;
- who will receive the results;
- how reports will be used; and
- how long the client requires the information to be retained.
In these circumstances, flowprofiler® Pty Ltd must:
- process personal information based on client instructions;
- comply with the applicable data-processing agreement;
- ensure authorised personnel are subject to confidentiality obligations;
- apply appropriate technical and organisational security measures;
- manage subprocessors in accordance with the client contract;
- assist the client with individual rights and regulatory obligations where required;
- notify the client of relevant personal data breaches without undue delay;
- support appropriate audits and compliance enquiries;
- inform the client where an instruction appears to breach applicable law; and
- delete or return information at the end of the service in accordance with the contract and applicable law.
6.3 Joint or separate controller arrangements
Where flowprofiler® Pty Ltd and another organisation jointly or separately determine the purposes and means of processing, the parties must document their respective responsibilities before processing begins.
The description “processor” must not be used merely because a client relationship exists.
7. Data-protection principles
flowprofiler® Pty Ltd applies the following principles to all personal information.
7.1 Lawfulness, fairness and transparency
Personal information must be processed lawfully, fairly and in a manner that is transparent to the individual.
People must not be misled about:
- what information is collected;
- why it is collected;
- who will receive it;
- how an assessment or profile will be used;
- whether the information will be transferred internationally; or
- how long it will be retained.
7.2 Purpose limitation
Personal information must be collected for specific, explicit and legitimate purposes.
It must not be used for a materially incompatible purpose without:
- assessing the proposed new use;
- identifying an appropriate legal basis;
- obtaining client authority where flowprofiler® acts as processor;
- updating the applicable privacy information; and
- obtaining consent where consent is legally required.
7.3 Data minimisation
Only information that is reasonably necessary and proportionate for the intended purpose may be collected or retained. Assessment forms, registration forms, platform fields and internal records must not request information merely because it may be useful later.
7.4 Accuracy
Reasonable steps must be taken to ensure personal information is accurate, complete and current where accuracy is necessary for the relevant purpose.
Individuals and clients must have an appropriate method for reporting inaccurate account or identity information.
Assessment responses provided by an individual are records of the responses given and must not be altered merely because the individual later disagrees with a resulting score or interpretation.
Disputes regarding scoring, report generation or interpretation must be investigated and documented.
7.5 Storage limitation
Personal information must not be kept for longer than necessary.
Retention periods must be established by reference to:
- the processing purpose;
- the client contract;
- legal and regulatory obligations;
- applicable limitation periods;
- certification or professional record requirements;
- information-security needs; and
- the interests and rights of the individual.
7.6 Integrity and confidentiality
Personal information must be protected through appropriate technical and organisational measures against:
- unauthorised access;
- improper disclosure;
- alteration;
- misuse;
- interference;
- accidental loss;
- destruction; and
- unavailability.
7.7 Accountability
flowprofiler® Pty Ltd must be able to demonstrate how it complies with this policy and applicable law.
Evidence may include:
- processing records;
- data maps;
- privacy notices;
- lawful-basis assessments;
- data-processing agreements;
- supplier reviews;
- data-protection impact assessments;
- security controls;
- training records;
- breach records;
- retention schedules;
- approval records; and
- audit findings.
8. Governance and responsibilities
8.1 Executive Sponsor and policy owner
Rebecca Chalmers is the Executive Sponsor and owner of this policy.
The Executive Sponsor is responsible for:
- approving the policy;
- ensuring appropriate organisational support and resources;
- deciding ordinary commercial and governance matters;
- ensuring significant privacy risks are considered in business decisions; and
- approving corrective action where required.
8.2 Data Protection Lead
Rebecca Chalmers is the Data Protection Lead.
The Data Protection Lead is responsible for:
- overseeing operational compliance with this policy;
- advising on privacy and data-protection requirements;
- coordinating individual rights requests;
- coordinating privacy complaints;
- overseeing data-protection impact assessments;
- maintaining or supervising relevant processing and incident records;
- reviewing data-processing agreements and supplier protections;
- investigating suspected personal data breaches;
- determining whether specialist legal or technical advice is required;
- coordinating regulatory and client notifications;
- identifying required corrective action; and
- coordinating technical or content remediation for Flow issues identified through governance review.
The title Data Protection Lead is used unless flowprofiler® Pty Ltd separately determines and documents that a formal statutory Data Protection Officer appointment is required.
8.3 AI Agent Compliance, Governance and Assurance Manager
Bronwyn is responsible for assurance relating to the handling of personal information by AI systems and AI agents.
This includes:
- monitoring compliance with approved AI-agent permissions;
- reviewing whether agents are operating within authorised data boundaries;
- identifying unauthorised access, disclosure, reuse or retention;
- supporting assurance reviews and evidence gathering;
- escalating material privacy or governance concerns; and
- verifying that corrective action has been completed where appropriate.
8.4 Flow Product Owners
Flow Product Ownership is shared jointly by Rebecca Chalmers and Iain Chalmers.
Product decisions involving personal information must take account of:
- data-protection requirements;
- security risks;
- client commitments;
- assessment integrity;
- system architecture; and
- the rights and reasonable expectations of participants.
No product release may proceed where the Data Protection Lead has identified an unresolved security or data-protection breach until the matter has been independently reviewed and the release has been authorised through the applicable governance process.
8.5 Personnel and authorised users
Everyone within the scope of this policy must:
- access personal information only where required for an authorised purpose;
- follow confidentiality and security requirements;
- use only approved systems and tools;
- complete required training;
- report suspected breaches, errors or policy failures immediately;
- cooperate with investigations and rights requests;
- avoid sharing accounts or passwords;
- verify recipients before sending personal information; and
- seek guidance where the appropriate handling of information is uncertain.
9. Lawful processing
Where UK or European data-protection law applies, a lawful basis must be identified before flowprofiler® Pty Ltd processes personal information as controller.
Depending on the activity, this may include:
- performance of a contract;
- steps requested before entering a contract;
- compliance with a legal obligation;
- legitimate interests;
- consent;
- vital interests; or
- another basis permitted by law.
Consent must not be treated as the automatic or preferred basis for every activity.
Where consent is used, it must be:
- freely given;
- specific;
- informed;
- unambiguous;
- evidenced;
- capable of being withdrawn; and
- separate from unnecessary contractual conditions.
Additional legal conditions must be identified before sensitive information, special-category data or criminal-offence information is processed.
Where flowprofiler® Pty Ltd acts as processor, the client controller is responsible for identifying the lawful basis and providing participants with the required privacy information. flowprofiler® Pty Ltd must provide reasonable assistance and must not knowingly process information where the client’s instructions are manifestly unlawful.
10. Collection and privacy information
Personal information must be collected by lawful and fair means. At or before collection, or as soon as reasonably practicable afterwards, individuals must receive appropriate privacy information explaining relevant matters such as:
- the identity and contact details of the controller;
- the purposes of processing;
- the categories of information collected;
- the lawful basis where required;
- intended recipients;
- international processing or disclosure;
- retention periods or criteria;
- applicable rights;
- complaint mechanisms;
- whether information is required;
- the source of information where it was obtained indirectly; and
- relevant profiling or automated processing.
Where information is collected through a client, flowprofiler® Pty Ltd must contractually require the client to provide an appropriate participant notice.
Privacy notices must use clear language and must not conceal material processing within lengthy contractual wording.
11. Assessment, profiling and behavioural information
Assessment information must be treated as confidential and handled with particular care because it may affect a person’s professional development, reputation, employment experience or workplace relationships.
11.1 Permitted processing
Assessment information may be processed only for authorised purposes such as:
- administering an assessment or survey;
- calculating scores;
- producing reports;
- providing interpretation, coaching or development;
- supporting authorised client reporting;
- maintaining assessment integrity;
- providing technical support;
- conducting authorised psychometric validation; or
- producing properly de-identified and aggregated research or benchmark information.
11.2 Access to reports
Assessment reports may be provided only to:
- the individual concerned;
- authorised client recipients;
- authorised trainers, coaches or interpreters;
- approved technical personnel where access is necessary; or
- another person where there is a lawful and documented basis.
The commissioning organisation must establish who is authorised to receive participant, team and organisational reports.
Rater identities and confidential comments must not be disclosed contrary to the design of the assessment, participant notice, client agreement or applicable law.
11.3 Employment and significant decisions
flowprofiler® assessment outputs are intended to support informed human judgement. flowprofiler® Pty Ltd does not authorise its platform or AI agents to make final decisions concerning:
- recruitment;
- promotion;
- dismissal;
- disciplinary action;
- remuneration;
- access to employment;
- access to essential services; or
- another decision producing a legal or similarly significant effect,
without meaningful human involvement, an appropriate legal basis, clear notice and the safeguards required by applicable law.
Clients remain responsible for how they interpret and use assessment outputs.
11.4 Research, validation and benchmarking
Identifiable assessment information must not be used for a new research, validation, norming or benchmarking purpose unless:
- the use is compatible with the original purpose or separately authorised;
- flowprofiler® has an appropriate legal basis;
- the relevant client instructions permit the use where flowprofiler® acts as processor;
- appropriate privacy information has been provided;
- the data is minimised;
- de-identification or aggregation is used wherever practicable; and
- the activity has been approved through the appropriate governance process.
12. Privacy by design and impact assessment
Privacy and data protection must be considered from the beginning of any new or materially changed:
- product;
- assessment;
- platform feature;
- integration;
- AI capability;
- automated process;
- supplier arrangement;
- data-sharing activity;
- research project; or
- business process involving personal information.
The project owner must document:
- what personal information is involved;
- the purpose of processing;
- the legal and contractual basis;
- the source of the information;
- who will have access;
- where it will be stored and processed;
- proposed retention;
- security controls;
- international transfers;
- effects on individuals; and
- measures to reduce identified risks.
A Data Protection Impact Assessment must be completed before processing begins where the activity may create a high risk to individuals.
A risk screening or full impact assessment should also be considered for:
- large-scale assessment processing;
- new profiling methods;
- sensitive information;
- systematic monitoring;
- automated or AI-assisted decision support;
- employee monitoring;
- combining previously separate datasets;
- use of production information in development;
- new international transfers; and
- new technologies whose effects are not yet well understood.
Unresolved high privacy risks must be escalated to the Data Protection Lead and Executive Sponsor.
13. AI systems and AI agents
Personal information must not be entered into a public or unapproved AI tool.
AI systems and AI agents may process personal information only where:
- the system has been formally approved;
- the purpose is authorised;
- access is limited to the minimum information required;
- supplier terms and data use have been reviewed;
- retention and model-training settings are understood;
- client instructions permit the processing where relevant;
- appropriate human oversight is maintained; and
- the activity is recorded in the relevant system or processing documentation.
Unless a human explicitly directs otherwise through an authorised governance process, no AI agent may independently:
- merge code into a protected production branch;
- deploy to production;
- modify production personal information;
- change Flow’s system instructions;
- alter access permissions;
- create new data exports;
- approve a subprocessor;
- alter retention rules; or
- disclose personal information externally.
AI-generated outputs containing or derived from personal information must be reviewed by an authorised person before they are used or disclosed.
14. Access control and confidentiality
Access to personal information must be based on the principles of least privilege and need to know.
Access permissions must:
- be approved;
- reflect the user’s role;
- be reviewed periodically and following role changes;
- be removed promptly when no longer required; and
- be recorded where technically practicable.
Users must not:
- share login details;
- access information out of curiosity;
- download information to unauthorised devices;
- send assessment reports through unapproved channels;
- use personal accounts to store business information;
- retain local copies longer than necessary; or
- disclose personal information during training or demonstrations without authorisation.
Training, demonstrations and testing should use fictional, synthetic or properly de-identified information wherever practicable.
15. Information security
flowprofiler® Pty Ltd will implement technical and organisational safeguards proportionate to the nature of the information, processing context and potential harm.
Controls may include:
- multi-factor authentication;
- strong authentication and password management;
- role-based access;
- encryption in transit and at rest;
- secure hosting;
- system and access logging;
- vulnerability and patch management;
- malware protection;
- backup and recovery controls;
- network and environment separation;
- secure software-development practices;
- change management;
- supplier-security review;
- confidentiality agreements;
- physical security;
- secure disposal; and
- incident-response procedures.
Personal information must not be copied into development or testing environments unless:
- there is a documented need;
- the Data Protection Lead or authorised delegate has approved the use;
- client instructions permit it;
- appropriate safeguards are applied; and
- de-identification or masking is used wherever practicable.
16. Suppliers and subprocessors
Before a supplier is permitted to process personal information, flowprofiler® Pty Ltd must conduct due diligence proportionate to the risk.
The review should consider:
- the information involved;
- processing purpose;
- system access;
- hosting and processing locations;
- security controls;
- breach history;
- confidentiality;
- data retention;
- deletion capability;
- subcontracting;
- international-transfer protections;
- audit evidence; and
- termination arrangements.
A written agreement must be in place where required.
Controller-to-processor agreements must address, as applicable:
- the subject matter and duration of processing;
- nature and purpose;
- categories of personal information;
- categories of individuals;
- documented instructions;
- confidentiality;
- security;
- subprocessors;
- assistance with individual rights;
- assistance with breaches and impact assessments;
- deletion or return at the end of the service;
- audit and compliance information; and
- international transfers.
A current register of material processors and subprocessors must be maintained.
17. International processing and transfers
Personal information may be transferred or made accessible internationally only after the legal, contractual and security requirements have been assessed.
The assessment must consider:
- the exporting and receiving countries;
- whether the activity is a transfer, disclosure or remote access;
- the role of each party;
- applicable client restrictions;
- the laws and practices of the destination;
- available safeguards;
- onward transfers;
- data minimisation;
- encryption;
- contractual protections; and
- the rights and remedies available to individuals.
Where Australian privacy law applies, reasonable steps must be taken before disclosing personal information to an overseas recipient to ensure the information is handled consistently with applicable Australian requirements, subject to any lawful exception.
Where UK or European transfer restrictions apply, an approved transfer mechanism must be used where required. This may include:
- an adequacy arrangement;
- approved standard contractual clauses;
- the UK International Data Transfer Agreement;
- the UK Addendum;
- binding corporate rules; or
- another legally permitted safeguard.
No person may introduce a new overseas hosting, processing or support arrangement without approval.
18. Retention and disposal
Personal information must be retained in accordance with an approved Data Retention and Destruction Schedule.
The schedule must identify, where relevant:
- the record category;
- purpose;
- controller;
- system or location;
- retention trigger;
- retention period;
- legal or contractual basis;
- deletion method;
- responsible owner; and
- applicable exceptions or legal holds.
At the end of the retention period, personal information must be:
- securely deleted;
- destroyed;
- returned to the controller;
- permanently de-identified; or
- retained under a documented legal hold.
Deleting an active record does not necessarily remove it immediately from system backups. Backup retention and restoration controls must be documented and must prevent deleted information from being returned to active use without appropriate handling.
19. Individual rights and requests
flowprofiler® Pty Ltd will maintain procedures for receiving, verifying, recording and responding to applicable privacy-rights requests.
Depending on the law and circumstances, rights may include:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability;
- withdrawal of consent;
- objection to direct marketing;
- information about processing;
- safeguards relating to automated decisions; and
- complaint to a regulator.
- Requests must be forwarded immediately to the Data Protection Lead.
No person may delete, alter or conceal information because a rights request or complaint has been received or is anticipated.
Where flowprofiler® Pty Ltd acts solely as processor, it must not independently determine the outcome of a request unless legally required. It must promptly notify and assist the relevant client controller.
Identity verification must be proportionate. Additional personal information must not be requested where it is unnecessary to verify the requester or locate the information.
Applicable statutory timeframes must be observed. UK and European rights requests will normally be answered within one month, subject to lawful extensions or exceptions.
20. Data-protection complaints
flowprofiler® Pty Ltd will provide a clear and accessible method for individuals to make a data-protection complaint.
Complaints may be sent to:
Data Protection Lead
Email: hello@flowprofiler.com
A data-protection complaint must:
- be recorded;
- be acknowledged within 30 days where UK requirements apply;
- be investigated appropriately and without undue delay;
- be handled impartially;
- consider relevant evidence and affected processing;
- be escalated where material risk is identified;
- keep the complainant reasonably informed; and
- result in a communicated outcome.
Complaint records must include:
the date received;
- nature of the concern;
- processing and systems involved;
- investigation undertaken;
- findings;
- corrective action;
- response date; and
- any regulatory correspondence.
21. Personal data breaches
All actual or suspected personal data breaches must be reported immediately to the Data Protection Lead.
A person must not delay reporting while attempting to:
- determine the cause;
- assess seriousness;
- confirm whether information was accessed;
- correct the issue; or
- decide whether notification is required.
The Data Protection Lead will coordinate:
- containment;
- preservation of evidence;
- initial assessment;
- identification of affected systems and individuals;
- assessment of likely harm;
- technical and organisational remediation;
- client notification;
- regulatory assessment and notification;
- communication with affected individuals where required;
- documentation; and
- post-incident review.
Where flowprofiler® Pty Ltd acts as processor, the relevant controller must be notified without undue delay in accordance with the contract.
Where UK data-protection law applies and a breach is likely to create a risk to people’s rights and freedoms, the relevant supervisory authority must be notified without undue delay and, where feasible, within 72 hours of flowprofiler® Pty Ltd becoming aware of the breach.
Where the risk to affected individuals is high, those individuals must also be informed without undue delay unless a lawful exception applies.
Where the Australian Notifiable Data Breaches scheme applies, a suspected eligible breach must be assessed expeditiously. Reasonable steps must be taken to complete the assessment within 30 days. The Office of the Australian Information Commissioner and affected individuals must be notified where the breach is an eligible data breach and no applicable exception applies.
All breaches must be recorded, including breaches that are not externally reportable.
22. Direct marketing
Personal information may be used for direct marketing only where permitted by applicable privacy and electronic-marketing laws.
Marketing records must include sufficient information to demonstrate:
- the source of the contact details;
- the intended audience;
- the applicable consent or other legal basis;
- communication preferences; and
- opt-out status.
Every applicable direct-marketing communication must provide a clear method of opting out.
Opt-out requests must be actioned promptly and must not be overridden by uploading or importing an older contact list. Service, contractual, security and administrative communications must be distinguished from promotional marketing.
23. Records and evidence of compliance
flowprofiler® Pty Ltd will maintain records proportionate to its processing activities and risks.
These may include:
a record of processing activities;
data and system inventories;
controller and processor role assessments;
lawful-basis records;
consent records;
privacy notices;
data-processing agreements;
subprocessor records;
international-transfer assessments;
impact assessments;
individual rights requests;
complaints;
data breaches;
security and access reviews;
retention and deletion records;
governance approvals; and
staff training.
Records must be accurate enough to demonstrate what was actually done. Templates or policies that do not reflect operational practice must not be treated as evidence of compliance.
24. Training and awareness
People with access to personal information must receive appropriate data-protection and information-security instruction:
- during induction or onboarding;
- when their role materially changes;
- when new systems or risks are introduced; and
- periodically thereafter.
Additional role-specific instruction must be provided to people involved in:
- system administration;
- assessment interpretation;
- client administration;
- development and testing;
- marketing;
- recruitment and employment;
- privacy requests;
- complaint handling;
- incident response; and
- AI-agent supervision.
25. Monitoring and audit
Compliance with this policy may be monitored through:
- access reviews;
- supplier reviews;
- system logs;
- project assurance;
- internal audits;
- incident analysis;
- record sampling;
- control testing; and
- review of complaints and rights requests.
Monitoring must itself comply with applicable privacy requirements and must be proportionate to the risk and purpose.
Findings must be assigned an owner, risk rating and completion date.
Material or repeated failures must be reported to the Executive Sponsor and Data Protection Lead.
26. Non-compliance
Failure to comply with this policy may expose individuals, clients and flowprofiler® Pty Ltd to harm, contractual claims, regulatory action and reputational damage.
Depending on the circumstances, non-compliance may result in:
withdrawal of system access;
additional training;
corrective action;
disciplinary action;
termination of employment or contract;
supplier remediation or termination;
notification to a client or regulator; or
legal action.
Actions will be proportionate and consistent with applicable employment, contractual and legal requirements.
No person will be penalised for raising a genuine data-protection concern in good faith.
27. Related policies and records
This policy should be read with the following documents:
- Privacy Policy;
- Subject Access Request and Individual Rights Procedure;
- Data Protection Complaints Procedure;
- Personal Data Breach Response Plan;
- Data Retention and Destruction Schedule;
- Information Security Policy;
- Password and Authentication Standard;
- Acceptable Use Policy;
- Data Processing Agreement template;
- Supplier and Subprocessor Register;
- International Data Transfer Procedure;
- Data Protection Impact Assessment template;
- AI Governance Policy;
- AI Agent Permissions Register;
- Secure Development and Change Management Policy;
- Cookies Policy; and
- Employee and Contractor Privacy Notice.
Where a related document conflicts with this policy, the matter must be referred to the Data Protection Lead.
28. Policy review
This policy will be reviewed:
- at least annually;
- following a material change in applicable law;
- following a significant data breach or complaint;
- when introducing a material new product, system or AI capability;
- when entering a new jurisdiction;
- when there is a material change to hosting or subprocessors; or
- where monitoring identifies that the policy no longer reflects actual operations.
