Surveillance Policy

Introduction

The University has introduced a new Surveillance Policy. This policy:

  1. Increases transparency and clarity on the University’s current surveillance activities
  2. Outlines the steps governing the approval of any new or changed surveillance activity, or the use or disclosure of surveillance information
  3. Introduces a Register of Approved Surveillance Activities.

The Register of Approved Surveillance Activities:

  1. Is publicly accessible
  2. Documents approved University surveillance activities
  3. Identifies the personnel approved to carry out the surveillance activity
  4. Describes the approved uses and disclosures of the collected information.

Policy and Register

The Surveillance Policy and the Register of Approved Surveillance Activities can be accessed here:

Additional information on these documents is provided below in the Frequently Asked Questions section.

The Policy is maintained in accordance with the University’s Policy Framework and will be reviewed periodically, with appropriate consultation taking place as a part of the review process.

The University is introducing a Surveillance Policy to promote transparency and clearer governance for the University’s surveillance activities and the use of surveillance information. The Surveillance Policy does not introduce any new surveillance activities and does not replace the University’s existing privacy policies and processes, which continue to apply. The Surveillance Policy explains current practices more clearly and sets out approval steps for decisions about new or changed surveillance activities. These approval pathways are designed to provide oversight for surveillance and protect against ‘scope creep’. The introduction of the Surveillance Policy is a requirement of the Victorian Privacy and Data Protection Deputy Commissioner following their investigation into certain uses of surveillance by the University.

This policy aims to:

  1. Ensure transparency in the University's surveillance activities.
  2. Establish clear protocols for any new or material changes to surveillance activities.
  3. Establish clear approval requirements for using or disclosing surveillance information.

The policy applies to anyone visiting University premises, using University assets or IT systems, or engaging in University activities. This includes University staff, contractors, students, honorary appointees, volunteers and visitors.

The policy also makes clear:

  • Which activities are in scope, and require approval in accordance with the policy.
  • That standing approvals may be included in the Register of Approved Surveillance Activities.
  • Which activities are out of scope, through the exclusions in section 2.2 of the policy.

No. The policy does not introduce new types of surveillance or extend surveillance into new areas by default.

The policy has been developed to minimise the risk of surveillance expanding beyond its intended use or becoming a default tool over time. It does this by:

  • Documenting existing surveillance activities and their approved uses in the Register.
  • Requiring explicit approval for any new surveillance activity or material change to an existing activity.
  • Requiring explicit approval for ad hoc uses of surveillance information in connection with an investigation of potential misconduct, including uses of specified kinds of personal information that was not originally collected for a surveillance purpose.
  • Requiring that surveillance information may only be used or disclosed for a legitimate University purpose.

Any proposal to introduce or change a surveillance activity must go through a formal approval process and be assessed as appropriate, reasonably proportionate, and in line with legal and policy requirements.

The University currently carries out various surveillance activities for specific purposes, which can include:

  • Optical surveillance (eg security cameras to protect people and property).
  • Data surveillance (eg if appropriate approvals are obtained, reviewing IT system or facilities access, emails, or websites visited when required to investigate potential misconduct, including data matching for identification purposes. Common situations for data matching include determining a person’s location to investigate unauthorised access to University facilities).
  • Audio surveillance (eg using recordings of calls made to the University’s Security Control Room or help phones on campus as part of an investigation).
  • Tracking surveillance (eg using a GPS or location tracker to locate University equipment).

Current approved surveillance activities, including when the University can use surveillance information or share it with others, are in the Register of Approved Surveillance Activities, available here. Any new or changed surveillance activity or proposed use or disclosure of surveillance information that is not included in the Register must be approved on a ‘case by case’ basis in accordance with the Surveillance Policy.

Surveillance activities are generally undertaken to maintain security, ensure research integrity, comply with legal and regulatory requirements, investigate staff or student misconduct and support the overall safety and wellbeing of the University community.

The University does not undertake any form of surveillance in toilets, washrooms, change rooms or lactation rooms.

Activities are excluded from the Surveillance Policy where they:

  • Are required or authorised by law (for example, managing workplace injury claims or assisting law enforcement where reasonably necessary).
  • Are covered by other comprehensive governance frameworks (for example, internal audits, approved research projects, or activities protecting financial integrity of University transactions).
  • Do not involve targeted surveillance of individuals (for example, maintaining IT security and system availability, or analysing anonymous data for space management purposes – however if this information is later used to investigate a suspected breach of University rules, regulations or policies, the Surveillance Policy will apply, which ensures appropriate oversight and governance where surveillance‑type activities are involved).

In addition, following consultation feedback, the policy scope was amended to exclude activities undertaken to protect and uphold academic integrity, including activities to discipline academic misconduct, as these activities are adequately governed by existing academic policies and privacy and data collection practices. Maintaining student academic integrity is fundamental to the University’s mission and core functions. As such, the deployment of technology to detect academic misconduct is both an operational requirement and reasonable for our students to expect.

The policy is designed to support compliance with the University’s key governance and regulatory obligations, including under the following laws:

  • Charter of Human Rights and Responsibilities Act 2006 (Vic)
  • Privacy and Data Protection Act 2014 (Vic)
  • Health Records Act 2001 (Vic)
  • Surveillance Devices Act 1999 (Vic)
  • Public Records Act 1973 (Vic)

Before approving a new surveillance activity, or a material change to an existing surveillance activity, the University must:

  • Consider how the activity might affect health, safety and human rights, such as privacy, freedom of expression or freedom of association.
  • Ensure the activity will not discriminate against anyone based on protected characteristics like gender, race, or religious or political beliefs.
  • Ensure that the activity is for a legitimate purpose and is reasonably proportionate – this means the University must balance the need for surveillance against its impact on people’s privacy or sense of safety.
  • Before using or sharing surveillance information, check that doing so is reasonable and considers relevant human rights.

The Surveillance Policy does not apply where the University is using purely anonymous data that cannot identify an individual. However, the policy will apply if that anonymous data is later matched with other data for a surveillance activity – for example, matching desk sensor data with video surveillance footage to identify whether a person was in a particular location, to investigate potential misconduct.

The University developed this Surveillance Policy in response to the Victorian Privacy and Data Protection Deputy Commissioner’s investigation into certain uses of surveillance by the University. This investigation prompted the University to consider its surveillance activities and develop a dedicated policy to promote transparency and clearer governance for surveillance activities and the use of surveillance information. We are not aware of any other Victorian universities with dedicated surveillance policies. However, workplace surveillance policies are more common for universities in some other jurisdictions where legislation in that jurisdiction requires that certain types of surveillance may only be carried out with notice or in accordance with employer policies.

Surveillance information can only be used for approved purposes, including:

  • Protecting health, safety, and welfare of individuals.
  • Ensuring the safety and security of University premises and property.
  • Investigating potential staff, student general misconduct, or research misconduct.
  • Complying with legal or regulatory obligations.

Use of surveillance information must be in accordance with the Surveillance Policy, the Register of Approved Surveillance Activities, and other applicable University policies and procedures. Access to surveillance information is controlled and any use must be for an approved purpose. An approver may also impose conditions or limitations on that use as a safeguard against function creep.

Surveillance information can only be used by:

  • The people or roles specified in the Register of Approved Surveillance Activities and for the stated purposes.
  • Those who are approved by senior University staff to use surveillance information, in line with the process in section 5 of the policy.
  • Third parties, such as law enforcement agencies, when permitted or required by law.

The policy and supporting procedures will set out expectations for authorisation, logging and audit of access, to ensure compliant handling of surveillance information and to support accountability and transparency.

The University has several safeguards to prevent surveillance information from being misused, including:

  • Approval requirements – surveillance activities may only be carried out if they are approved, and must follow any conditions or limits set by the approver, and any operational procedures.
  • Clear access and purpose limits – only authorised personnel are allowed to use or disclose surveillance information, and only for approved purposes, following any conditions or limits set by the approver, and any operational procedures.
  • Scope creep protections – material changes to existing surveillance activities must follow the approval process in the policy.
  • Privacy and human rights considerations – the University must consider how surveillance may impact people’s rights, including by conducting Privacy Impact Assessments in line with the Privacy Policy.
  • Senior oversight – this policy is overseen by senior University staff, including the Chief Information Officer.

Any new surveillance activity or material change to an existing activity must be approved under this Surveillance Policy. This involves submitting a detailed request, conducting a Privacy Impact Assessment, and obtaining approval from senior University staff. Approvers must be satisfied that the proposed activity is appropriate and proportionate, and that relevant human rights have been properly considered.

Surveillance information is stored and retained in accordance with the University's Retention and Disposal Authority and applicable laws.

Yes. The Surveillance Policy supports compliance with various privacy and related laws, including the:

  • Privacy and Data Protection Act 2014 (Vic)
  • Health Records Act 2001 (Vic)
  • Surveillance Devices Act 1999 (Vic)
  • Charter of Human Rights and Responsibilities Act 2006 (Vic).

The policy operates alongside the University’s Privacy Policy (MPF1104) and other information governance policies. Together, these frameworks require that surveillance activities and use of surveillance information are designed and implemented in a way that protects privacy, data security and human rights.

The policy, together with related policies such as the Privacy Policy (MPF1104), requires that data protection and sovereignty considerations are built into surveillance activities.

In practice, this means:

  • Assessing data security, storage and cross-border data transfer risks for any surveillance activity, particularly where third-party platforms or cloud services are used.
  • Ensuring surveillance information is stored securely, with appropriate technical and procedural controls.
  • Undertaking due diligence on third-party tools and platforms that may be used in support of surveillance activities.
  • Ensuring any cross-border transfer of personal information complies with Victorian and other applicable privacy and information security obligations.