Website information

Privacy

How CCTIDTO intends to collect, use, disclose, secure, correct and manage personal information connected with its website and public correspondence.

Status
Current website information
Effective date
3 September 2026
Policy owner
Centre for Counterterrorism Innovation and Deep Tech Operations Ltd

1. Our privacy approach

CCTIDTO intends to manage personal information openly, carefully and consistently with the Australian Privacy Principles as a governance baseline where applicable. Whether a particular statutory obligation applies depends on the circumstances; this policy does not limit any right available under law.

2. Information the website may involve

Depending on how a person contacts the Centre, this may include:

  • name, email address and other contact details;
  • organisation, professional role or academic affiliation;
  • enquiry, correspondence, correction or complaint details;
  • sources or documents voluntarily supplied in support of a concern;
  • limited technical and security information processed by hosting or email providers, such as an IP address, browser type, timestamps or access logs; and
  • sensitive information only where a person voluntarily provides it and it is reasonably necessary to address the relevant matter.

The current website has no contact form, donation facility, membership portal, newsletter sign-up, analytics tool or advertising tracker. Contact occurs through an external email application chosen by the visitor.

3. How and why information may be used

CCTIDTO may use relevant information to:

  • respond to an enquiry, correction or accessibility request;
  • assess an editorial, cultural, religious, privacy or legal concern;
  • maintain source, correspondence and governance records;
  • protect website and organisational security;
  • meet a legal, regulatory or reporting obligation; and
  • improve the accuracy, accessibility and integrity of its material.

CCTIDTO does not intend to sell personal information or use a correction, cultural concern or sensitive correspondence for direct marketing.

4. Disclosure and service providers

Information may be disclosed only where reasonably necessary to a hosting, email, information-technology or records provider; a lawyer, auditor or other professional adviser; a regulator, court or law- enforcement body where required or authorised by law; or another person with the individual's consent.

Hosting, email and data-storage arrangements—including any likely processing or disclosure outside Australia—are to be reviewed and recorded whenever those arrangements materially change.

5. Sensitive correspondence and data minimisation

Email is not a secure channel. A person reporting an article concern should provide only the information reasonably needed to identify and explain the issue. Personal accounts of trauma, religious identity, health information, identity documents and details identifying a survivor should not be supplied unless genuinely necessary and safe to do so.

6. Security and retention

CCTIDTO intends to use proportionate administrative and technical controls, restrict access to people with a legitimate need, and retain information only for as long as reasonably required for its purpose, governance, recordkeeping or legal obligations. No internet or email transmission can be guaranteed to be completely secure.

A suspected data breach should be contained, assessed and documented. Where the Notifiable Data Breaches scheme or another notification requirement applies, affected individuals and the relevant regulator will be notified as required by law.

7. Access, correction and privacy concerns

A person may ask what personal information CCTIDTO holds about them, request correction, or raise a privacy concern by emailing the Centre. The request should provide enough information to identify the relevant record without unnecessarily disclosing additional personal information. Identity may need to be reasonably verified before access or correction is provided.

A privacy complaint will be assessed and responded to within a reasonable period, having regard to its complexity. If a person is dissatisfied with the response and the Privacy Act applies, they may be able to complain to the Office of the Australian Information Commissioner.

8. Children and policy changes

The website is not designed to collect personal information from children. Additional safeguards will be required before any feature directed to, or likely to collect information from, a child is introduced. This policy will be reviewed when website functions, service providers or legal requirements change.