Government Information Handling Statement
Effective: 31 August 2026.
1. Purpose
Data-Driven AI Pty Ltd (ABN 58 635 718 455) provides data, analytics, AI, cloud and related consulting services. This Statement explains how we approach government information during Australian Government and NSW Government consulting engagements.
This is a public statement, not a contract, security plan or certification. It does not make every government framework apply to every service. The applicable agency contract, order, statement of work and privacy, security, records and data schedules set the binding requirements for an engagement.
Our Privacy Policy explains how we handle personal information for our own website, recruitment and business activities. When we handle agency-controlled personal information, both that Policy and the engagement requirements may be relevant.
2. Information covered
Government information can include information supplied by an agency and information created, changed or collected for an engagement. Depending on the work, this may include:
- official, operational or project information;
- personal information and health information;
- security-sensitive or classified information;
- agency records, working papers and evidence;
- system, identity, access, audit and incident records; and
- information held in source systems, data platforms, applications, reports or AI services.
The responsible agency determines the information’s classification and business requirements. Data-Driven AI does not treat every agency document or dataset as having the same handling rules.
3. Our role
Our role depends on why and where we handle information.
For our own corporate activities, we decide why information is used. Examples include an agency contact’s business details, a tender response, recruitment or billing records.
For agency-directed work, the agency ordinarily determines the purpose, systems and authorised use. We handle the information to deliver the agreed service and meet applicable legal and contractual duties.
The agency may retain responsibility for collection notices and access or correction decisions. It may also remain responsible for statutory records, information-access applications and notifications to affected people.
If someone asks us about agency-controlled personal information, we will explain when the responsible agency must decide the request. We will assist or refer the request where authorised and required.
4. Requirements agreed before access
Before Data-Driven AI receives access to protected project information, the engagement documents should record the requirements relevant to the work. These can include:
- the authorised purpose, scope and agency instructions;
- information ownership, custody, classification and record status;
- approved systems, environments, communication channels and data flows;
- storage, processing, backup, administrative-access and support locations;
- authorised personnel, need-to-know limits and any required clearances;
- approved subcontractors and technology providers;
- identity, access, logging, monitoring and assurance requirements;
- incident reporting, investigation, evidence preservation and notification roles;
- audit, regulator, FOI, GIPA and other lawful access requirements; and
- retention, legal hold, return, export and authorised destruction.
The agency and service determine the evidence required. This may include a privacy impact assessment, security plan, data-flow record, control mapping, risk assessment or assurance report.
5. Handling commitments
Subject to applicable law and the engagement documents, we:
- use government information only for the authorised engagement purpose;
- limit access to people who need it for their approved role;
- use the systems, channels and locations agreed for the work;
- apply the required confidentiality, privacy, security and records controls;
- maintain the records and evidence required for access, change, incidents and assurance;
- report suspected incidents through the agreed agency process;
- give subcontractors access only where the engagement permits it and apply the required obligations to them; and
- preserve, return, export or destroy information only as authorised.
We do not use agency-controlled information for unrelated marketing. We do not place it in a public AI service. We also do not use it to train a public or general-purpose AI model unless the agency expressly authorises that use and the engagement documents permit it.
6. Public enquiry channels
Our public website, booking links and general email addresses are for basic contact details and high-level enquiries. They are not approved project channels.
Do not send classified or security-sensitive government information through those channels. This includes credentials, production data, personal or health information about another person and commercial-in-confidence material. We will agree an approved channel before receiving project material.
An initial enquiry does not create a consulting relationship, security boundary or special confidentiality obligation.
7. Data locations and suppliers
We do not make a blanket claim that every service or item of government information remains in Australia. Hosting region alone does not establish where administrative access, support, backups or subprocessors are located.
For each relevant engagement, the parties should record:
- where information may be stored, processed, backed up and accessed;
- whether remote or overseas access is permitted;
- which cloud, software and support providers are approved;
- the notice or approval needed before a provider changes; and
- the contractual duties that must flow to each subcontractor.
If an engagement requires Australian-only or other location controls, those requirements must be stated, implemented and verified for that engagement.
8. Security, personnel and assurance
We apply the security requirements agreed for the information, system and service. Detailed architecture, control mappings, incident contacts and evidence belong in the engagement’s security and assurance documents rather than this public Statement.
The Australian Government Protective Security Policy Framework, the Information Security Manual and hosting requirements do not automatically apply to every private-sector consulting service. The same is true of the NSW Cyber Security Policy. An agency can require relevant controls through its procurement and engagement documents.
Security clearances belong to named individuals. A person’s clearance does not mean that Data-Driven AI, every member of its workforce or every service is cleared or accredited.
The agency should verify the people, service boundary and current evidence relevant to the proposed work.
We do not make blanket PSPF, ISM, IRAP, hosting or accreditation claims. We make a specific claim only when current evidence supports the exact service scope.
9. Incidents and data breaches
The engagement documents should define what must be reported, who receives the report, the required time, how evidence is preserved and who controls communications and notifications.
We report suspected incidents involving agency-controlled information through the agreed process and assist the agency as required. The agency will often decide whether to notify affected people or its regulator. We will notify directly where a law independently requires us to do so.
The statutory assessment period under a privacy law is not a substitute for a shorter contractual reporting time.
10. Records, access and disposal
An engagement should identify which records belong to the agency and which records Data-Driven AI must retain for its own lawful purposes. It should also explain how the agency can obtain information held by us or an approved subcontractor.
We do not destroy government information only because an engagement has ended. Legal holds, disposal authorities, agency directions and contract requirements continue to apply. Where return or export is required, the engagement should define the format, timing and verification process.
Commonwealth FOI and Archives requirements, and NSW GIPA and State Records requirements, do not apply in the same way to every consultancy. Their effect depends on the service, record, agency control and contract. When they apply, the engagement must give the agency the access and control it needs.
11. Commonwealth engagements
When Data-Driven AI provides services under a Commonwealth contract, it may be a contracted service provider under the Privacy Act 1988 (Cth). Section 95B requires the agency to address privacy obligations in the contract. Relevant obligations must also flow to subcontractors.
The contract is therefore a primary source of our duties for that work. See the OAIC’s guidance for contracted service providers.
The agency’s procurement, classification and system authorisation determine whether additional PSPF, ISM, hosting, FOI, audit or Commonwealth records requirements apply. Data-Driven AI does not claim those agency-wide obligations apply to all of its corporate activities.
12. NSW engagements
A NSW Government contract does not by itself make Data-Driven AI a NSW public-sector agency. The Privacy and Personal Information Protection Act 1998 and the NSW Mandatory Notification of Data Breach scheme principally regulate the agency. Contracts commonly set the relevant supplier duties. The agency may still hold information that is in a provider’s possession or control.
The Health Records and Information Privacy Act 2002 may apply directly to Data-Driven AI when the statutory conditions for handling health information are met. The applicable engagement should identify this before access is granted.
NSW agencies should also address incident reporting, GIPA access, State Records requirements, cyber-security controls and subcontractor duties in the engagement. The Information and Privacy Commission NSW guidance for contracted providers explains the agency-provider breach boundary.
13. Products and consulting work
Using Data-Driven AI for consulting does not automatically include a Data-Driven AI product. If an agency chooses CloudMonitor or another product, the product’s agreement, privacy notice and security documents apply to that product. The consulting engagement documents still govern any separate consulting work.
14. Contact and review
For an initial question about this Statement, use our contact page with basic contact details only. You can also write to Data-Driven AI Pty Ltd, 111 Harrington Street, The Rocks NSW 2000, Australia. We will arrange an approved channel if the discussion needs protected material.
We review this Statement when our government services, handling practices or legal obligations change. A published update does not amend an existing agency agreement.