Short answer first: which privacy law protects you depends on your university. Sydney, UNSW and UOW name the Privacy and Personal Information Protection Act 1998 (NSW), Melbourne and Monash the Privacy and Data Protection Act 2014 (Vic), and UQ the Information Privacy Act 2009 (Qld). ANU works under the federal Privacy Act 1988. Each law lets you see and correct what is held about you and complain, first to the university and then outside it: to the Civil and Administrative Tribunal in NSW, OVIC in Victoria, the Office of the Information Commissioner in Queensland, or the OAIC.
This article covers the personal information a university holds about you, how to get at it, and what happens when data leaves the state or the country, including when you choose the app. Each rule links to the Act or the university page it comes from. None of it is legal advice.
Which privacy law covers your university?
The Privacy Act 1988 is federal, and the OAIC's page on state and territory privacy legislation says it does not cover state or territory government agencies, while most states have their own laws for their public sectors. The fastest way to find your university's law is its own privacy statement, because it names the Act.
- NSW universities name the PPIP Act. The University of Sydney's page on privacy at the University sets its primary obligations under the Privacy and Personal Information Protection Act 1998 and the Health Records and Information Privacy Act 2002. UNSW's student privacy statement and UOW's student privacy and disclosure statement name the PPIP Act too.
- Victorian universities name the PDP Act. Melbourne's student privacy statement says the University is governed by the Privacy and Data Protection Act 2014 and the Health Records Act 2001. Monash's page on its collection statements says providing them is a requirement of the PDP Act.
- UQ names the Information Privacy Act. UQ's Privacy Policy says its obligations arise primarily under the Information Privacy Act 2009, including the Queensland Privacy Principles.
- ANU works under the federal Act. ANU's privacy policy says the Privacy Act 1988 requires it to have one, and that its obligations are set out in the Act and the Australian Privacy Principles.
| University | Law its privacy documents name | Who that law covers | Regulator or review body |
|---|---|---|---|
| Sydney, UNSW, UOW | Privacy and Personal Information Protection Act 1998 (NSW) | NSW public sector agencies | NSW Information and Privacy Commission; the Civil and Administrative Tribunal reviews internal review outcomes |
| Melbourne, Monash | Privacy and Data Protection Act 2014 (Vic) | Victorian public sector agencies | Office of the Victorian Information Commissioner (OVIC) |
| University of Queensland | Information Privacy Act 2009 (Qld) | The Queensland public sector | Office of the Information Commissioner, Queensland |
| ANU | Privacy Act 1988 (Cth) and the Australian Privacy Principles | Agencies and organisations under the federal Act, other than small business operators | Office of the Australian Information Commissioner (OAIC); ANU's policy says the Privacy Commissioner |
When a university names more than one law
Several do. Sydney also lists the Privacy Act 1988 and overseas laws such as the GDPR where they apply. Melbourne says federal and international privacy law applies in certain circumstances, and UQ has Privacy Act obligations for tax file numbers. For your student record, name the Act the university calls primary: the NSW Acts at Sydney, the Queensland Act at UQ.
What does your university hold about you?
More than your results. The privacy statements now list the systems you use every day.
- Your record and your use of systems. Sydney's student privacy collection notice lists enrolment details, academic progress and results, participation records, financial aid, data from your use of University facilities and systems, conduct and academic integrity matters, and sensitive information such as disability adjustments.
- Learning platform logs. Melbourne's LMS privacy collection notice lists login history, timestamps, IP address, session duration and submission times, plus usage analytics and engagement metrics, and names Instructure Inc as the learning management system provider.
- Exam supervision. UNSW says online assessments may involve session recording or live supervision by the University or a contracted provider, collecting data that can include biometric data and images, video and audio recordings. Melbourne collects data about your presence and activity in University-controlled exam environments, digital ones included.
- Recorded exams. Monash's recorded eExams page says your desktop and webcam activity is recorded from the online check-in, and that video and audio recordings of you may be taken and analysed.
- Checks on your work. Sydney may review and analyse submitted work in academic integrity investigations, including suspected unauthorised use of AI tools. Melbourne says assessment content, metadata and activity records may be reviewed to verify authorship.
- Lecture recordings. UOW's Lecture Recording Procedures say recordings may contain incidentally collected personal information, such as the likenesses, voices, names and opinions of students present.
Software reads some of this as well as people. Sydney's notice says the University may use generative AI and other machine learning tools for teaching and learning, research, administration and quality assurance, with your information handled under its Privacy Policy and privacy law. If a decision about you rests on data like this, the access rights below are how you see it.
How do you see or correct what the university holds?
Every one of these laws gives you access and correction, in different words.
- NSW. Section 14 of the PPIP Act requires a public sector agency to give you access to your personal information without excessive delay or expense. Section 15 requires it to make appropriate amendments on request, by corrections, deletions or additions, so the information is accurate and not misleading.
- Victoria. IPP 6 in Schedule 1 of the Privacy and Data Protection Act 2014 requires an organisation to give you access to your personal information on request, subject to listed exceptions such as an unreasonable impact on other people's privacy.
- Queensland. UQ's Privacy Policy lists three routes: the organisational unit that holds the information, an administrative access scheme, or a formal application under the Right to Information Act 2009 (Qld) to access or amend documents containing your personal information.
- The federal principles. Under APP 12 and APP 13 an agency must respond within 30 days and cannot charge for access. An organisation must respond within a reasonable period and may charge a fee for giving access that is not excessive, but nothing for making the request or for a correction.
- ANU. Its privacy policy says you can ask the Privacy Officer for access or correction, and the Privacy Officer will respond within 30 days.
A request that gets answered
- Check the student system first. UNSW says much of your information can be viewed and updated in myUNSW.
- Write to the privacy contact on your university's privacy page, and name the Act the university names.
- Say exactly what you want: your student record, LMS activity logs, an exam recording, or a specific correction.
- Keep a dated copy. The complaint clocks below run from the day your complaint arrives.
- If you are refused, ask for the reasons in writing. Under the federal principles, APP 12.9 and APP 13.3 require a written notice with the reasons and the ways to complain.
How do you complain, and where does it go next?
Start with the university in every state. The regulators expect it, and each sets a period the university gets before an outside body steps in.
| Law | First step | Time the university has | Next step |
|---|---|---|---|
| PPIP Act (NSW) | Written application for internal review, within 6 months of becoming aware of the conduct | 60 days before you may go to the Tribunal | Civil and Administrative Tribunal |
| PDP Act (Vic) | Complaint to the organisation | OVIC says allow 28 days | Complaint to OVIC |
| IP Act (Qld) | Written complaint to the university | 45 business days | Office of the Information Commissioner |
| Privacy Act (Cth) | Complaint to the organisation or agency | The OAIC says 30 days | Complaint to the OAIC |
- NSW keeps the Privacy Commissioner informed. Section 54 of the PPIP Act requires the university to notify the Privacy Commissioner of an internal review and report its findings. Sydney says its Chief Governance Officer considers complaints and sends the report to the NSW Privacy Commissioner within 60 days. Under section 55 the Tribunal can order damages of up to 40,000 Australian dollars.
- Queensland counts business days. Section 164A of the Information Privacy Act 2009 sets a response period of 45 business days after the complaint is received, which the university can ask you to extend. UQ's policy says you may then refer the complaint to the Office of the Information Commissioner.
- Victoria asks for 28 days. OVIC's guidance to complain to the organisation first says to allow 28 days, and that OVIC may refuse a complaint if you have not.
- The OAIC asks for 30 days. Its page on how to lodge a privacy complaint says to complain to the organisation or agency first, then to the OAIC if there is no response within 30 days or you are unhappy with it. ANU says it will tell you its proposed response within 30 days, and that you can ask for a senior officer's review or complain to the Privacy Commissioner.
Can your data be sent overseas?
Yes, under conditions, and each law writes its own. None of them bans it, so the questions are where it goes, to whom, and under what safeguards.
- APP 8 makes the sender responsible. Before an APP entity discloses personal information to someone overseas, APP 8.1 requires reasonable steps so the recipient does not breach the APPs. Under section 16C of the Privacy Act 1988, a breach by that recipient can be treated as a breach by the entity itself.
- NSW sets a list of tests. Section 19(2) of the PPIP Act lets an agency disclose personal information outside NSW only in listed cases, for example where the recipient is bound by a law, binding scheme or contract with substantially similar principles, or where you expressly consent.
- Queensland and Victoria do the same. Section 33 of the Queensland Act allows disclosure outside Australia only in listed cases, such as your agreement. IPP 9 allows a transfer outside Victoria where, among other grounds, the recipient is bound by substantially similar principles or you consent.
- Universities say it happens. Melbourne says information may go outside Victoria or Australia where providers are located internationally or use cloud servers in other jurisdictions. UNSW says some contracted providers are outside NSW or Australia, and ANU says some of its cloud and hosting providers are overseas.
- Some data stays in Australia. Monash says all eVigilation recordings from recorded eExams are stored within Australia only.
The federal principles also make the answer public. APP 1.4 requires an APP entity's privacy policy to say whether it is likely to disclose personal information overseas and, where practicable, in which countries. A policy that names its overseas processors and their countries is doing what the principle asks.
What changes when you choose the app yourself?
When you upload your own recording to an app you picked, the university is not the one sending the data, so its privacy statement does not describe what happens next. The app's privacy policy does.
- Your own study use. Section 16 of the Privacy Act says nothing in the APPs applies to personal information an individual collects, holds, uses or discloses only for personal, family or household affairs. The Act does not say where study sits, and this article does not guess.
- The company is a separate question. The Act's definition of an organisation leaves out small business operators, and section 6D draws the small business line at an annual turnover of 3,000,000 Australian dollars or less, with exceptions. Whether a given app company is an APP entity depends on facts like that, which its policy may state.
- Storage and processing are different. A tool can keep your files in one place and send audio to a processor in another. APP 1.4 is the reason a careful policy says both.
What to check before you upload
- The company's legal name and a privacy contact.
- Whether it sends personal information overseas, and to which countries.
- The named processors that receive the audio and generate the text.
- How long audio and transcripts are kept, and how to delete them.
- How to ask for access or correction, and where to complain.
The main apps are compared on points like these in the best note-taking app for Australian students.
What about other people's voices in your recording?
A recording of a class holds other people's personal information, not just yours. UOW's procedures say so directly, and ANU's page on privacy and lecture recordings tells students worried about their voice or image being recorded to talk to the course convener first. The university's own recordings are covered in lecture capture at Australian universities.
The university rules on your own recordings are stricter than privacy law. UQ's Recording of Teaching Procedure says recordings and transcripts cannot be shared or published without permission. Melbourne's guidance on AI transcription tools treats them as a type of recording and warns that recorded data may be kept, shared or used for other purposes without people knowing. Get the permission first, and keep other students' voices out where you can. The rules by university are in can you record a lecture at an Australian university.
What has changed in privacy law recently?
Two federal changes matter for students.
- A statutory tort since 10 June 2025. The OAIC's page on the statutory tort for serious invasions of privacy says the changes introducing it commenced on 10 June 2025. It reaches further than the Privacy Act, to individuals and entities that may not be APP entities, and a court can grant damages, an injunction or an order requiring an apology. Proceedings must start in time: a plaintiff who was under 18 when it happened must start before their 21st birthday, and anyone else by the earlier of one year after they became aware of the invasion and three years after it occurred.
- Automated decisions from 10 December 2026. The OAIC's consultation on automated decision-making guidance says the Privacy and Other Legislation Amendment Act 2024 introduced an automated decision-making obligation. From 10 December 2026, APP entities that use personal information in automated decisions that could affect rights or interests must say in their privacy policies what kinds of information and decisions are involved.
The second applies to APP entities, so it reaches ANU and app companies covered by the federal Act, not the state Acts named by the other universities here.
Where Notibo fits
Notibo is one of the apps the checklist above is for, so here are its answers. Files are stored in the EU, on Supabase in Frankfurt. Transcription and the AI notes run on US processors under standard contractual clauses. Audio files are deleted from storage as soon as the transcript and notes are generated, and if processing fails the audio is kept for a short while so the recording can be tried again. The privacy policy lists the processors by name.
It records a lecture or takes an audio file you upload and returns a transcript, structured notes and flashcards with spaced repetition, in 89 languages, with export to PDF or Word. The first 14 days of Pro are free, with 240 minutes of recording and no card. When the trial ends, the free plan includes 30 minutes of recording a month, and Pro is 9.99 euro a month or 88.99 euro a year. Get permission before you record anyone.
