Simulated workplaceCAQA Meridian Business Group is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
BSBCAQA MeridianSimulated workplace
Back to library
CAQA Meridian Business Group · Simulated workplace

Privacy and Information Security Policy

PolicyControlled document
MER-POL-001
v3.2
Document ownerQuality, Risk and Compliance Manager
Version3.2
Approved10 February 2026
Next review10 February 2027
StatusCurrent

Purpose. Sets out how Meridian collects, uses, stores, shares and disposes of personal and client information in accordance with the Privacy Act 1988 and the Australian Privacy Principles.

1.Policy statement

Meridian will handle personal information and confidential client information lawfully, fairly and securely. The firm will collect only the information it needs, use it only for the purpose it was collected, protect it from misuse and loss, and destroy or de-identify it when it is no longer required. Every worker is responsible for privacy in their own work.

2.Scope

This policy applies to all employees, contractors and students at both offices and when working remotely or at client sites. It covers personal information about clients, client employees, job applicants, Meridian staff and suppliers, and confidential business information entrusted to Meridian.

3.Collection and use

Personal information must be collected directly from the individual where practicable and the individual must be told why it is collected and how it will be used. Information collected for one client engagement must not be used for another purpose without consent. Sensitive information such as health, union membership or criminal history must only be collected with consent and where it is necessary for the service.

4.Access and security

Client and personnel files are held in the firm's systems with role based access. Workers must use multi-factor authentication, lock screens when away from a desk, and must not store client information on personal devices or unapproved cloud services. Paper records must be kept in locked cabinets and shredded when no longer required.

  • Role based access to client and personnel records
  • Multi-factor authentication on every system
  • No client data on personal devices
  • Clean desk and locked cabinets
  • Encrypted laptops and secure remote access

5.Disclosure

Personal information must not be disclosed to a third party unless the individual has consented, the disclosure is required by law, or it is necessary for the engagement and the client has authorised it. Requests from regulators, courts or law enforcement must be referred to the Quality, Risk and Compliance Manager before any information is released.

6.Data breaches

Any suspected loss, unauthorised access or disclosure of personal information must be reported to the Quality, Risk and Compliance Manager immediately and recorded in the risk and compliance register. The firm will assess whether the breach is likely to result in serious harm and will notify affected individuals and the Office of the Australian Information Commissioner where the law requires.

7.Retention and disposal

Records will be retained for the periods in the records retention schedule and then securely destroyed or de-identified. Client files will be returned or destroyed at the end of an engagement in accordance with the engagement terms.

MER-POL-001 v3.2 · CAQA Meridian Business GroupUncontrolled when printed. Simulated document created by CAQA for training and assessment.