top of page
DPA Brand Guideline - Master (5)_edited.png

Data Ownership and Privacy


Overview


Assessment Manager has been designed to provide organisations with complete confidence that their information remains secure, confidential and under their control. The platform stores a range of operational information including assessments, maturity ratings, benchmarking data, improvement plans, validation results, uploaded evidence and limited user account information necessary to operate the service.


Your organisation retains ownership of all information entered into Assessment Manager. Drowning Prevention Australia does not claim ownership of your organisational data, assessment content, supporting documentation or intellectual property.


Our role is to provide a secure platform that enables organisations to manage risk, compliance and continuous improvement while protecting the confidentiality, integrity and availability of customer information.


Assessment Manager has been developed to support Australian organisations in meeting their obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) through secure information management, controlled access and responsible handling of personal information.

Who Owns the Data?

All assessment information entered into Assessment Manager remains the property of your organisation.

This includes, but is not limited to:

  • Assessment results and maturity ratings.

  • Goals and improvement plans.

  • Benchmarking information.

  • Secret Swimmer and AFSA results.

  • Uploaded evidence and supporting documents.

  • Notes, comments and observations.

  • Organisation and facility information.

  • User-generated content.


Assessment Manager simply provides the secure technology platform used to store, manage and present this information.


What Information is Collected?


Assessment Manager only collects information necessary to provide and support the platform.

This may include:


Organisation Information

  • Organisation name.

  • Aquatic facilities.

  • Subscription information.

  • Organisation settings.


User Information

  • Name.

  • Work email address.

  • User role.

  • Assigned facility.

  • Account activity.


Assessment Information

  • Maturity ratings.

  • Assessment comments.

  • Goals.

  • Improvement actions.

  • Validation results.

  • Benchmarking information.

  • Uploaded evidence.


No unnecessary personal information should be entered into Assessment Manager.


Who Can Access My Information?


Access to information is controlled through multiple layers of security.

Information is protected using:

  • Individual user authentication.

  • Role-Based Access Control (RBAC).

  • Organisation-level segregation.

  • Facility-level permissions.

  • Secure encrypted communications.


Only authorised users within your organisation can access information appropriate to their assigned role and responsibilities.


Organisation Administrators control user permissions and determine who has access to organisational information.


How is My Information Used?


Information stored within Assessment Manager is used solely for the operation of the platform and the services your organisation has subscribed to.


This includes:

  • Displaying assessment dashboards.

  • Calculating maturity ratings.

  • Producing benchmarking information.

  • Supporting validation services.

  • Managing improvement plans.

  • Supporting user authentication.

  • Providing customer support where authorised.

  • Maintaining platform performance and security.


Customer information is never sold to third parties.


Confidentiality


Drowning Prevention Australia recognises that customer information may include commercially sensitive operational information, internal procedures, audit findings and strategic improvement activities.


Customer information is treated as confidential and is only accessed where necessary to:

  • Deliver subscribed services.

  • Provide customer support.

  • Conduct authorised validation activities.

  • Investigate technical issues.

  • Maintain platform security and reliability.


Access to customer information is limited to authorised personnel who require access to perform their duties.


Protection of Personal Information


Assessment Manager has been designed to minimise the collection of personal information.

Only information necessary to provide the platform and manage user accounts is collected.


Organisations remain responsible for ensuring personal information entered into Assessment Manager is accurate, appropriate and managed in accordance with their own privacy obligations.

Users should avoid uploading unnecessary personal information, medical information or confidential employee records unless required for a legitimate business purpose.

Data Security


Customer information is protected using multiple technical and administrative security controls, including:

  • TLS 1.2+ encrypted communications.

  • AES-256 encryption (or equivalent industry standard) for stored information.

  • Enterprise-grade cloud infrastructure.

  • Role-based access controls.

  • Automatic backups.

  • Continuous infrastructure monitoring.

  • Distributed Denial of Service (DDoS) protection.

  • Web Application Firewall (WAF).

  • Security event monitoring.

  • Regular security updates.


These controls help protect customer information against unauthorised access, accidental loss and cyber security threats.


Data Retention


Information remains available within Assessment Manager while your organisation maintains an active subscription.


Assessment records, uploaded evidence and improvement activities provide valuable historical information that supports continuous improvement and organisational learning.


Should your organisation cease using Assessment Manager, arrangements regarding data retention or export can be discussed with Drowning Prevention Australia in accordance with applicable contractual arrangements and organisational requirements.


Customer Responsibilities


Organisations also play an important role in protecting information.


Organisation Administrators should:

  • Review user permissions regularly.

  • Remove access for former employees.

  • Keep organisation information current.

  • Ensure only authorised documents are uploaded.

  • Protect confidential organisational information.

  • Monitor user access and activity where appropriate.


Individual users should:

  • Protect their passwords.

  • Never share accounts.

  • Only access information relevant to their role.

  • Upload appropriate evidence.

  • Report suspected security concerns immediately.


Privacy Principles


Assessment Manager has been designed to support good privacy governance by helping organisations:

  • Protect personal information.

  • Limit access to authorised users.

  • Maintain accurate records.

  • Manage information securely.

  • Reduce unnecessary collection of personal information.

  • Support responsible information management throughout the assessment lifecycle.


These principles align with recognised privacy practices and support Australian organisations in managing information responsibly.


Frequently Asked Questions


Who owns the information entered into Assessment Manager?

Your organisation retains ownership of all assessment data, uploaded evidence, improvement plans and organisational information entered into the platform.


Does Drowning Prevention Australia own my data?

No. Drowning Prevention Australia provides the Assessment Manager platform but does not claim ownership of your organisation's information or intellectual property.


Can other organisations view our information?

No. Organisations are logically separated within Assessment Manager. Users can only access information belonging to their own organisation and only where permitted by their assigned role.


Can Drowning Prevention Australia access our information?

Authorised personnel may access customer information only where necessary to provide support, deliver subscribed services, investigate technical issues or undertake authorised validation activities. Access is controlled and limited to authorised personnel.


Is my information shared with third parties?

No. Customer information is not sold or shared with third parties except where required to operate the platform, comply with legal obligations or where authorised by your organisation.


What happens to our information if we stop using Assessment Manager?

Assessment data remains your organisation's information. Data retention, export or transition arrangements can be discussed with Drowning Prevention Australia in accordance with your subscription agreement.


What information should not be uploaded?

Users should avoid uploading unnecessary personal information, confidential employee records, medical information or material that is unrelated to the assessment or improvement activity.


How can my organisation protect its information?

Regularly review user permissions, use individual user accounts, maintain strong password practices, keep user records current and ensure confidential information is only accessed by authorised personnel.

bottom of page