Simulated workplaceCAQA Ledger and Lane Financial is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
FNSCAQA Ledger and LaneSimulated workplace
Back to library
CAQA Ledger and Lane Financial · Simulated workplace

Privacy and Information Security Policy

PolicyControlled document
LNL-POL-001
v3.4
Document ownerCompliance Manager
Version3.4
Approved12 February 2026
Next review12 February 2027
StatusCurrent

Purpose. This policy sets out how Ledger and Lane collects, uses, stores and protects the personal and financial information of clients, their employees and staff under the Privacy Act 1988 and the Australian Privacy Principles.

1.Scope

This policy applies to every employee, contractor and representative of the firm and to all personal information the firm holds, including tax file numbers, bank details, payroll records, identity documents, credit information and health information collected for insurance purposes. It applies to paper files, the firm's systems, cloud accounting platforms and lender and insurer portals.

2.Collection and use

The firm will only collect personal information that it needs to provide the service the client has engaged it for, and will tell the client at or before collection what it is for. Information will only be used or disclosed for that purpose, for a related purpose the client would reasonably expect, with the client's consent, or where the law requires. Tax file numbers must only be collected, used and disclosed as the tax laws permit.

3.Access controls

Staff must only access client files they are working on. Access to systems is granted by role and reviewed quarterly by the Compliance Manager. Multi-factor authentication must be used on every system that holds client information. Passwords must not be shared and screens must be locked when unattended.

  • Role-based access reviewed quarterly
  • Multi-factor authentication on all systems
  • No shared logins
  • Screens locked when unattended
  • Client information never stored on personal devices

4.Sending information

Documents containing tax file numbers, bank details or identity documents must be sent through the secure client portal, not by email. Where a client insists on email, the document must be password protected and the password sent separately. Staff must verify a change of bank account by calling the client on a known number before acting on it.

5.Retention and destruction

Client records will be retained for at least five years after the work is complete, or longer where the tax and credit laws require, and then destroyed securely. Identity documents used for verification will be retained for seven years after the relationship ends as the anti-money laundering laws require.

6.Data breaches

A suspected loss, theft or unauthorised access to personal information must be reported to the Compliance Manager immediately. The firm will contain the breach, assess whether it is likely to result in serious harm and, where it is, notify the affected people and the Office of the Australian Information Commissioner in line with the notifiable data breaches scheme.

7.Access and complaints

Clients can ask to access or correct their information and the firm will respond within 30 days. Privacy complaints will be handled under the Complaints Handling Policy and the client will be told how to contact the Office of the Australian Information Commissioner if they are not satisfied.

LNL-POL-001 v3.4 · CAQA Ledger and Lane FinancialUncontrolled when printed. Simulated document created by CAQA for training and assessment.