DataLab user privacy notice
The Australian Bureau of Statistics (ABS), as the administrator of the DataLab, collects personal information that is necessary to provide you with use of the DataLab and properly administer the service.
Application and approval services for users of DataLab are managed using Microsoft Dynamics 365, Okta and Azure Active Directory services.
ABS provides this service as My Data Approvals To Access (myDATA).
Purpose for which personal information is collected
To administer and provide access to DataLab, we will collect any personal information you provide when registered to ABS systems, including your name, email address, job title and details of your organisation. We may also collect any other personal information you provide in using the service, including information you provide by email.
We collect your personal information so that we can identify and distinguish who you are for the purposes of administering and providing access to DataLab. This will ensure you are connected to the right projects and data in DataLab.
Any personal information collected will be retained until it is no longer needed for these purposes and will be protected in accordance with the Privacy Act 1988.
Domestic cloud based service
The myDATA and DataLab platforms use cloud based services. Personal information collected from these data services is used to identify you while logged in and will be stored in cloud data centres that are physically located in Australia.
The exception to this is Okta back ups that are located offshore, this is acceptable given the usage scenario and type of data involved and has been considered as part of ABS security assessment process.
ABS uses Okta Australia as the trusted third party identity and access management provider. Okta is cloud hosted software that implements a multi-factor authentication. Okta stores identity information within user profiles, for authentication and subsequent access to the myDATA user portal.
The ABS manages the Okta tenancy that hosts these profiles and the service provides appropriate administrative, physical and technical safeguards to protect the security and integrity of it’s service. Okta does not share customer data with other organisations.
Use and disclosures of personal information
We may use and disclose the collected personal information for the purpose of administering access to data in the DataLab, including seeking approvals on your behalf with the data custodians responsible for the data, system logging and disclosing user details to other users for the purpose of enabling collaboration.
We may also use your personal information for undertaking analysis to support the development of new products and services; informing you of recent developments, changes or upcoming product releases; or otherwise in accordance with a permitted exception under the Privacy Act 1988.
Storage and security
Microdata and personal information is stored securely in certified secure cloud services hosted in Australia in accordance with the Privacy Act 1988 and the requirements of the ABS' legislative framework.
All our information is secured in accordance with the Protective Security Policy Framework. Assessments are made against security requirements documented in the Australian Government Information Security Manual (ISM) issued by the Australian Signals Directorate (ASD).
- How personal information is managed in the DataLab cloud environment: Cloud DataLab Privacy Impact Assessment