Independent public Guidelines referenceNot an Australian Government serviceHow ServiceCite worksAbout
ServiceCite
Part A: Universal Guidelines

DEWR source chapter · ServiceCite reference page

Chapter 2. Records Management Instructions

Department wording for Chapter 2, Records Management Instructions, from Part A: Universal Guidelines version 1.16.

Version and source status

Workforce Australia Services reference · Part A v1.16

File integrity checked by ServiceCite
Program status
Current service
Published
3 June 2026
Effective
1 July 2026
Source retrieved
6 August 2026
Official record modified
14 July 2026
Official location checked by ServiceCite
6 August 2026
Attribution, presentation changes and technical record

Source material: © Commonwealth of Australia. Australian Government Department of Employment and Workplace Relations, Workforce Australia Guidelines, Part A: Universal Guidelines, version 1.16, published 3 June 2026. Used under the Creative Commons Attribution 4.0 International licence, subject to the exclusions in the DEWR copyright notice.

ServiceCite split the Word document into chapter pages and reformatted it for web navigation and search. Source logos, authoring artefacts and duplicate navigation were removed. System step, documentary evidence and work health and safety markers were converted to visible text labels. ServiceCite navigation and notices are independently written. Compare this page with the official source before operational use. This reuse does not imply Australian Government or DEWR endorsement.

The SHA-256 and file size record the official Word file verified during corpus preparation. ServiceCite does not publish the source DOCX because it contains images excluded from DEWR's default Creative Commons licence.

Document ID
dewr-workforce-australia-guidelines-part-a
Version ID
dewr-wa-part-a-v1.16-effective-2026-07-01
SHA-256
c88ac5d339842ee1ca56694d66e154d61be21ea9bbcde33f1860e0c474be0757
FOI reference
D26/3084244
Recorded file size
269,995 bytes
MIME type
application/vnd.openxmlformats-officedocument.wordprocessingml.document
Department wording, reformatted for the web · ServiceCite coverage notes are labelled

Supporting Documents for this Chapter:

2.1. Chapter Overview

This Chapter outlines Provider obligations with regards to the creation, management, retention, storage, transfer and disposal of Records created or used by Providers under the relevant Deed, and access to those Records by its Personnel and Subcontractors, in accordance with the Records management provisions in the relevant Deed. Providers must create and maintain true, complete and accurate Records in the connection with the delivery of its obligations under and in accordance with the relevant Deed and these Records Management Instructions.

General advice on the management and storage of records, information and data is available on the National Archives of Australia (NAA) website.

2.2. Records Framework

Under the relevant Deed, ‘Records’ means documents, information and data stored by any means and all copies and extracts of the same. Records includes 3 categories:

  • Commonwealth Records are Records provided by the Department to Providers for the purposes of the relevant Deed and includes Records which are copied or derived from Records so provided.

  • Deed Records are all Records:

  • developed or created or required to be developed or created as part of or for the purpose of performing the relevant Deed

  • incorporated in, supplied or required to be supplied along with the Records referred to in the point above, or

  • copied or derived from Records referred to in the above points, and

  • includes all Reports.

  • Provider Records are all Records, except Commonwealth Records, in existence prior to the relevant Deed Commencement Date:

  • incorporated in

  • supplied with, or as part of, or

  • required to be supplied with, or as part of,

the Deed Records.

To the extent that Records contain personal information for the purposes of the Privacy Act, Providers must also take reasonable steps (if any) in the circumstances to ensure that the personal information that the Provider:

  • collects is accurate, up-to-date and complete, and

  • uses or discloses is, having regard to the purpose of the use or disclosure, accurate, up-to-date, complete and relevant.

2.2.1. General Records Authority 40

The General Records Authority 40 (GRA 40) sets out the requirements for the transfer of custody of Commonwealth Records to contractors providing services under outsourcing arrangements, either on behalf of or to the Australian Government. The GRA 40 provides that, notwithstanding custody of Records that temporarily resides with the Provider, ownership of the relevant records remain with the Australian Government.

Further information on relevant application and conditions of the GRA 40 is provided on the NAA website.

2.3. Management of Records

In accordance with the "digital by default" approach set out in the Australian Government's Building trust in the public record: managing information and data for government and community policy (effective 1 January 2021), Providers must, wherever possible and consistent with the Deed and other applicable legal requirements, create and manage Records in a digital format.

Providers must ensure that any digital Record is created, stored and operated in accordance with the Deed requirements (particularly the requirements in relation to Provider IT Systems and other applicable legislative provisions, including the Electronic Transactions Act 1999 (Cth).

Digital Records containing sensitive information as defined in the Privacy Act must be kept securely. The Office of Australian Information Commissioner (OAIC) website provides information on keeping personal identifying information secure.

The Provider must ensure that its:

  • Personnel and Subcontractors do not access, copy, disclose or use any:

  • Record containing any information about any participant in any employment services program, or

  • Record in the Department's IT Systems containing any information about any individual (including individuals who are not participants in any employment services program),

    unless such access, copying, disclosure or use is for the purpose of:

  • providing Services to a participant under the relevant Deed, or

  • otherwise complying with the Deed, and

  • Third Party IT Vendors do not access, copy, disclose or use any electronic Record unless such access, copying, disclosure or use is for the purpose of assisting the Provider to comply with the relevant Deed.

    Records held by a Provider which were created under a previous Deed (e.g. under the jobactive Deed 2015-2022) must be managed in accordance with the Records management requirements of that previous Deed.

2.3.1. Storage requirements

The Provider must store all Records in accordance with these Records Management Instructions, the Department’s Security Policies, and where relevant, its Privacy Act obligations.

Providers must store Records securely either on their own premises or off-site using a records storage facility in compliance with legislation covering the management of Commonwealth/Deed Records, including the Privacy Act.

For Records that contain personal information for the purposes of the Privacy Act, in accordance with Australian Privacy Principle 11 as set out in Schedule 1 of the Privacy Act, the Provider must take such steps that are reasonable in the circumstances to protect the information from misuse, interference and loss, and from unauthorised access, modification or disclosure. The guide to securing personal information can be found on the OAIC website and provides guidance on the reasonable steps entities are required to take under the Privacy Act to protect the Personal Information they hold from misuse, interference, loss, and from unauthorised access, modification or disclosure.

Providers must ensure that the Department can access Records by retrieving the Record (including, if stored digitally, by retrieving the digital copy and if relevant printing it) and providing it to the Department upon request.

Providers are required to store digital Records in accordance with the Department’s Security Policies, including the Security Policy for External Employment Service Providers and Users available on the Provider Portal (sign-in required).

General advice on the management and storage of Records is available on the NAA website.

Providers must ensure physical Records are protected from:

  • storage environment damage (e.g. for paper Records, damp from a cement floor or fire damage)

  • unauthorised addition, alteration, removal or destruction

  • use outside the terms of the relevant Deed

  • for Records containing Personal Information, incidents of privacy, and

  • unauthorised access including inappropriate ‘browsing’ of Records

Physical Records containing sensitive information, as defined in the Privacy Act, must be kept in lockable cabinets.

2.3.2. Control of Records

Providers must be able to locate and retrieve Records about a Participant if requested. Providers must inform their Provider Lead if they become party to legal action in relation to their previous or current delivery of Services, so that arrangements for the appropriate retention of Records can be organised.

Providers must store Records in such a way that all Records relevant to a request under the Freedom of Information Act 1982 (Cth) (the FOI Act) are able to be located and retrieved efficiently. This includes being able to retrieve email Records and Records created by, or sent to, individuals who have ceased working for Providers.

Records Register

The Provider must maintain an up-to-date register of the Records (digital and physical) held by the Provider and any Third Party IT Vendor and make this register available to the Department upon request. The register should contain sufficient information to clearly identify the content and location of a Record.

The Records register must be created and managed in a digital format (ideally Microsoft Excel or equivalent or a comma or tab limited format) that the Department’s IT Systems can read. Providers may wish to identify on the Records register whether Records are:

  • Priority – pertaining to current or pending legal action, Complaint, injury or possible claim for compensation

  • Active – current Participants

  • Inactive – former Participants

  • Damaged – e.g. paper Record affected by water

  • Destroyed (whether authorised or accidental) – e.g. paper Record burnt

  • Transferred – Participant and Record transferred to another Provider

  • Returned – have been returned to the Department.

2.4. Movement of Records

The Provider must not, and must ensure that its Personnel do not:

  • remove any Records relating to the Services, or allow any Records relating to the Services to be removed, from the Provider's premises, except to the extent necessary to enable the delivery of the Services, or

  • take, transfer, transmit or disclose any Records relating to the Services, or allow any Records relating to the Services to be taken, transferred, transmitted, accessed or disclosed, outside of Australia

without the Department's prior written consent.

Further, the obligation set out above applies in respect of taking, transferring, transmitting, accessing or otherwise disclosing any Records relating to the Services outside of Australia by the Provider:

  • within the Provider's own organisation, and

  • to any third party, including to any Subcontractor.

Providers must only transfer the Records in accordance with these Records Management Instructions or as otherwise directed by the Department.

2.5. Transfer of Records

2.5.1. Transfers between Providers

Records (digital or physical) must only be transferred between Providers in accordance with the relevant Deed and these Records Management Instructions, and where it is required to continue providing Services to Participants. Records must be transferred securely by Providers, as soon as possible or within 28 Business Days of a request to transfer Records. A list of all Records being transferred should be provided to the receiving Provider.

The transfer of Records containing personal information and Protected Information must be in accordance with the Privacy Act and the Social Security (Administration) Act 1999 (Cth).

When a Provider is transferring Records between its Sites, to another Provider, for storage or secure destruction or to the Department, it remains the Provider’s responsibility to ensure the Records are secure during the transfer process.

2.6. Return of Records

Records must be returned to the Department within 28 Business Days if requested by the Department, unless specified otherwise or the retention period has lapsed.

The Records Management Supporting Document (sign-in required) has been developed to provide information to Providers on:

  • the nature of the return process, including the steps required for the return of both digital and physical Records (where permitted),

  • how to determine the Records in scope for any return process and list these in the Records Register for Provider Returns Spreadsheet (sign-in required),

  • how to prepare Records to ensure they are successfully returned, including relevant naming conventions, and file organisation, and

  • other matters relevant to the returns process.

2.7. Data Migration

Data migration is the process of transferring data from one application or format to another. It may be required when implementing of a new application, which may require data to be moved from an incompatible proprietary data format to a format that is futureproof and can be integrated with new applications.

Providers must ensure that any migration activities include validation of the migrated data quality to ensure that no data is lost, and the data continues to be fit for the intended purpose.

When migrating information Providers must ensure:

  • the migration is planned, documented and managed

  • pre and post migration testing proves that authentic, complete, accessible and useable records can and have been migrated

  • source records are kept for an appropriate length of time after the migration to enable confirmation that the migration has been successful. Determination of the specific retention period must be based on an organisational risk assessment

This advice is in line with the Archives Act and Archives Regulations. However, if future processes include destroying source records, it is recommended that consultation with legal counsel be conducted to ensure that there is no legal requirement to maintain them.

A successful migration demonstrates that the migrated business information is at least functionally equivalent to the source record for business, legal and archival purposes. General Records Authority 31 permits the destruction of information and records after they have been successfully migrated from one system to another.

Providers must note that the information transferred to the Department will be imported into the Department’s official recordkeeping system and appropriate classification will be applied at the time of import.

2.7.1. Data Security Considerations

Providers should be conscious of the following security considerations:

  • ensure that those who access sensitive or security classified information have an appropriate security clearance if information is classified, and a need to know that information

  • access to (including remote access) to supporting ICT systems, networks, infrastructure and applications is controlled

  • information in systems should be continuously safeguarded from cyber threats

  • administrative privileges such as logon and administrator privileges should be restricted.

Providers should refer to the digital Information Assurance / IT Security Compliance guide on the Department's website for more information.

2.7.2. Decommissioning of Systems

When decommissioning any systems Providers should ensure that they have considered the value of the business information and any ongoing need to access it. If the information is no longer required, the Provider will need authorisation to legally destroy that information.

The NAA provides authorisation to destroy Australian Government business information in the form of records authorities.

Digital preservation requires a proactive program to identify records at risk and take necessary action to ensure their ongoing viability. To achieve this, the Providers must consider the lifecycle of the information versus the lifecycle of the system and have plans in place to preserve information as needed. Regular and planned migration helps avoid obsolescence and ensures information continues to be accessible and useable.

2.8. Breaches and Inappropriate Handling of Records

2.8.1. Reporting Requirements

Providers must report all incidents involving unauthorised access, damaged, destroyed, lost or stolen Records to the Department. Where the Records contain or possibly contain personal information of participants, Providers must follow the Privacy incident reporting process set out in the Privacy Chapter.

2.8.2. Rectification Requirements

For all incidents involving the misuse, interference, loss, unauthorised access, unauthorised use, unauthorised disclosure, damage, destruction, loss or stealing of Records (digital or physical), Providers must:

  • immediately make every effort to recover lost or damaged Records (e.g. retrieving or photocopying Records), including if required, arranging and paying for the services of expert contractors (e.g. disaster recovery or professional drying services)

  • not destroy damaged Records without prior authorisation from the Department

  • inform Participants if any Personal Information has been lost or is at risk of being publicly available

  • where relevant and, if necessary, reinterview Participants to recollect information review relevant policies and procedures to ensure their adequacy in future

The Department may make recommendations to the Provider to mitigate the risk of recurrence of the incident.

2.8.3. Notifiable Data Breaches Scheme

All Providers, and the organisations or agencies they share information with, must comply with the requirements of the Notifiable Data Breaches (NDB) scheme in the event of an ‘eligible data breach’ involving Personal Information.

Information about the NDB scheme and guidance for undertaking an assessment of a privacy incident are available on the OAIC website.

The Department must also be informed of the incident in accordance with the Privacy Incident reporting process set out in the Privacy Chapter and provided with copies of any notifications submitted by the Provider to the OAIC.

2.9. Retention of Records

All Records must be retained by the Provider for a period of no less than 6 years after the creation of the Record, unless otherwise specified in these Records Management Instructions or advised by the Department. For certain Records, specific retention periods are applicable in accordance with Employment Services Records Disposal Authority 2003/00330307, Employment Services Records Authority 2009/00179260 (RA) and the General Records Authority GRA 33 Accredited Training 2012/00579704 (GRA 33). Details of these specific Records and corresponding retention periods are set out in the Records Retention Periods supporting document.

Records with a longer retention period should be maintained by the Provider until they no longer require them and then be returned to the Department for ongoing management. Records in storage arrangements that are retrieved should be converted to digital format and the source record destroyed.

Providers have the discretion to retain Records longer than the minimum periods outlined but must not destroy Records prior to the expiration of the relevant retention periods. In addition, the Department may direct some Records be retained for longer periods, for example, in the case of Records required in any legal action.

The Department may impose special conditions on a Provider in relation to retention of Records at the Department’s absolute discretion. This may include imposing extended record retention periods on Providers.

Providers must review Records that have reached the minimum retention period before destroying them in accordance with these Records Management Instructions.

If a relevant Record has reached the required minimum retention period but, for example, the Provider has knowledge of a legal action or potential legal action, the Provider must re‑sentence the Record and inform the Provider Lead. Sentencing is the process for identifying the minimum retention period for a Record by assessing them against the classes specified in the relevant Records Authority.

At the Completion Date, the Provider must manage all Records in accordance with these Records Management Instructions or as otherwise directed by the Department.

Retention periods are determined with reference to NAA accredited records authorities.

2.9.1. Digital Records

Where a Third Party IT Vendor is in possession of Records as a result of assisting a Provider to provide Services under the relevant Deed, the Third Party IT Vendor may only dispose of those Records in accordance with Records Retention Periods with prior agreement of the Provider.

For purposes of determining the applicable retention period, a scanned version of a paper Record would have the same creation date as the original source document.

Information in the Department’s IT Systems will be retained by the Department for the appropriate retention periods.

2.9.2. Physical Records

Providers must retain relevant paper Records according to the minimum retention periods outlined in the Deed and, where relevant, the Records Retention Periods (sign-in required) supporting document.

2.10. Disposal of Records

The Provider must:

  • not destroy or otherwise dispose of Records, except in accordance with the Deed, these Records Management Instructions, or as otherwise directed by the Department, and

  • provide a list to the Department of any Records that have been destroyed, as directed by the Department.

Records must not be destroyed where the Provider is aware of current or potential legal action or where the records are subject to a Disposal Freeze or Retention Notice issued by the NAA, even if the minimum retention period has been reached. These Records are priority Records and must be retained in accordance with requirements set out for priority Records in Control of Records section. A Provider must also comply with any direction from the Department not to destroy Records. Providers must only destroy Records that have reached the minimum retention period and following the review process outlined in Retention of Records section.

Providers must maintain a list of destroyed Records which must be supplied to the Department upon request. This list must also be retained by the Provider in accordance with the applicable retention period or as directed by the Department.

Refer to Retention of Records section for information on retention periods.

2.10.1. Methods of destroying Records

When Providers destroy Records, they must use a method that ensures the information is no longer readable and cannot be retrieved.

Digital Records

It is the Provider’s responsibility to ensure all digital Records are identified and removed from their systems and destroyed. Methods of destroying digital Records include:

  • file shredding

  • degaussing – the process of demagnetising magnetic media to erase recorded data

  • physical Destruction of storage media – such as pulverisation, incineration or shredding

  • reformatting – if it can be guaranteed the process cannot be reversed.

To ensure the complete Destruction of a digital Record, all copies should be found and destroyed. This includes removing and destroying copies contained in system backups and off-site storage.

Deletion is not destruction and does not meet the requirements for Destruction of Australian Government Records. When digital Records are deleted, it is only the pointer to the Record (such as the file name and directory path) that is deleted. The actual data objects are gradually overwritten in time by new data. However, until the data is completely overwritten, there remains a possibility that the information can be retrieved.

Physical Records

Providers must ensure physical Records are destroyed using one of the following methods:

  • pulping – transforming used paper into a moist, slightly cohering mass

  • burning – in accordance with relevant environmental protection restrictions and

  • shredding – using crosscut shredders (using either A or B class shredders).

If Destruction of physical Records is undertaken at an off‑site facility, then a certificate of destruction including details of the Records destroyed and appropriate authorisation must be obtained and retained by the Provider.

2.10.2. General Records Authority 30

Records may be damaged beyond repair because of a disaster, emergency, or other unforeseen circumstance, as defined in GRA 30.

If a Provider considers that a Record or Records have been damaged in line with GRA 30, it must not destroy the Record(s) unless and until the Department provides written authority for the destruction of the Record(s). Providers must notify the Department as soon as possible following the Record(s) being damaged, providing at a minimum:

  • photographic evidence of the damaged Record(s)

  • do any of the damaged Record(s) need to be retained permanently

  • information about the circumstances causing the damage, including whether:

  • the Record(s) in their damaged state pose a health hazard, and

  • any Record(s) were able to be retrieved following the circumstances causing the damage and if so, how this retrieval will be managed

  • information about the Record(s), including:

  • the number affected, and if approximated, how this number was determined

  • their content

  • their classification, and

  • whether they had been digitised

  • information about how the damaged Record(s) are proposed to be destroyed, and

  • any other information the Provider considers relevant to a request to destroy the Record(s).

2.10.3. General Records Authority 31

Records as defined in the Deed are Commonwealth records for the purposes of the Archives Act.

Subject to certain exclusions and conditions, the NAA provides permission for the destruction of Commonwealth Records created on or after 1 January 1980 under General Records Authority 31 -Destruction of source or original records after digitisation, conversion or Migration (GRA 31) where those Records have been converted from hard copy to digital form.

Providers, as ‘authorised agents’ of the Department, must comply with the requirements of GRA 31.

Providers must retain the original copy of a paper Record for the relevant retention period and return it to the Department in accordance with this Chapter, regardless of whether it has also been converted to digital form, if required to do so under relevant Deed/s, Guidelines or if directed by the Department.

Further explanation of the relevant conditions and exclusions for GRA 31 is available on NAA website.

2.10.4. Destruction of Duplicate Records

Digital Records

Duplicate digital records are to be destroyed in accordance with Methods of Destroying digital Records.

Physical Records

Providers must only destroy duplicate paper records in accordance with NAA guidelines.

On this page