Simulated workplaceCAQA PrintWorks Media is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
ICPCAQA PrintWorksSimulated workplace
Back to library
CAQA PrintWorks Media · Simulated workplace

Privacy and Client Artwork Security Policy

PolicyControlled document
PWK-POL-004
v1.3
Document ownerClient Services and Estimating Manager
Version1.3
Approved18 August 2025
Next review18 August 2027
StatusCurrent

Purpose. This policy protects client artwork, variable data files and personal information handled by the business.

1.Purpose

The business receives client artwork, unpublished designs, product launch material and mailing lists that contain personal information. This policy sets out how that material is protected under the Privacy Act 1988 and the Australian Privacy Principles and how client intellectual property is respected.

2.Handling of artwork and files

Client files must be received through the client portal or the approved file transfer service, never through personal email or removable media. Files are stored on the production server in the job folder and must not be copied to personal devices. Unreleased artwork must not be photographed, shared on social media or shown to other clients.

  • Portal or approved transfer service only
  • One job folder per job ticket
  • No personal devices or removable media
  • No photographs of unreleased work

3.Variable data and mailing lists

Mailing lists and personalisation data must be used only for the job they were supplied for and deleted from the production server thirty days after dispatch unless the client instructs otherwise in writing. Access to data folders is restricted to the prepress operator running the job and the Prepress Manager. Printed waste containing personal information must be placed in the secure destruction bin.

4.Responsibilities

The Client Services and Estimating Manager owns this policy and handles client privacy enquiries. The Prepress Manager controls server access. Every worker must report suspected loss or misuse of client data immediately.

5.Breach response

A suspected data breach must be reported to the General Manager on the day it is discovered. The business will contain the breach, assess whether serious harm is likely and notify affected individuals and the Office of the Australian Information Commissioner where the notifiable data breach scheme requires it. A record of the assessment will be kept.

6.Review

This policy will be reviewed every two years or when the portal, servers or legislation change.

PWK-POL-004 v1.3 · CAQA PrintWorks MediaUncontrolled when printed. Simulated document created by CAQA for training and assessment.