eCompliance

Category

Privacy & Cyber Security

7 courses

Any organisation covered by the Privacy Act has to handle personal information in line with the Australian Privacy Principles and report eligible data breaches to the OAIC and to affected people. Most breaches start with a person, not a firewall: a misdirected email, a reused password, a convincing phone call. Training has to change what staff do in those exact moments.

Which one do you need?

Privacy is the general Australian Privacy Principles course for all staff. Victorian Privacy Principles covers the separate state regime for Victorian public sector bodies and their contractors. Privacy Credit Reporting Code is for organisations handling credit reporting information. On security, Hungry Minds pairs Cyber Security Awareness (threat recognition) with Cyber Responsibility (individual accountability), plus PCI DSS for anyone touching cardholder data and Working from Home - Cyber Security for remote setups.

Courses in Privacy & Cyber Security

Common questions

Who has to comply with the Privacy Act?

Australian Government agencies and most private sector organisations with an annual turnover above the small business threshold, plus some smaller organisations regardless of turnover, including health service providers and businesses that trade in personal information. If you are unsure, check the OAIC's guidance rather than assuming you are exempt.

What is a notifiable data breach?

Under the Notifiable Data Breaches scheme, an eligible data breach is unauthorised access, disclosure or loss of personal information that is likely to result in serious harm. Entities must assess suspected breaches promptly and notify the OAIC and affected individuals where the threshold is met.

Do Victorian public sector staff need a different course?

Yes. Victorian public sector bodies are governed by the Information Privacy Principles under the Privacy and Data Protection Act 2014 (Vic), not the Australian Privacy Principles. Victorian Privacy Principles covers that regime.

Is annual cyber training enough?

As a baseline record, yes. In practice, phishing simulations and short refreshers between annual sessions work better, because recognition fades and the lures change. Pair Cyber Security Awareness with your own simulation program.

Need this tailored to your organisation?

  • Your policies, your scenarios

    We rebuild compliance training around how your organisation actually works, so the training changes behaviour instead of recording completions.

    Build a custom version
  • Ready to run as it is

    Deploy the course off the shelf, with light branding if you want it. Delivered with our partner Safetrac, who will contact you directly.

    Deploy off the shelf