Simulated workplaceCAQA Studio Aurora is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
CUACAQA Studio AuroraSimulated workplace
Back to library
CAQA Studio Aurora · Simulated workplace

Privacy and Image Consent Policy

PolicyControlled document
AUR-POL-004
v1.7
Document ownerOperations and Finance Manager
Version1.7
Approved22 January 2026
Next review22 January 2027
StatusCurrent

Purpose. This policy sets out how Studio Aurora collects, uses and protects personal information about audiences, artists, performers, clients and staff, and how it obtains consent to record and publish a person's image, voice or performance.

1.Personal information we hold

Studio Aurora collects contact details, ticketing and membership history, audience survey responses, artist and freelancer engagement records, performer and talent details and images and recordings of people in its work. The company will only collect information it needs and will tell people why it is being collected.

2.Use and disclosure

Personal information will be used for the purpose it was collected for, including ticketing, marketing to people who have opted in, payment and contract administration. Information will not be sold or given to other organisations except service providers under contract, or where the law requires. Audience data used for reporting to funders will be de-identified.

3.Image, voice and performance consent

No person's image, voice or performance will be recorded for publication or used in any work without a signed Talent and Location Release Form, except for incidental audience photography at events where signage and ticket conditions give notice. Consent must state the uses agreed and any limits. Consent for a child must be given by a guardian.

  • Signed release before publication
  • Uses and platforms stated
  • Term and territory stated
  • Right to withdraw for future uses
  • Guardian consent for children

4.Security and retention

Personal information will be stored in access-controlled systems and paper records will be locked away. Releases and consents will be filed against the job in the Media Asset Library. Ticketing data will be retained for seven years and then destroyed. Staff must not copy personal information to personal devices or accounts.

5.Access, correction and complaints

A person can ask to see or correct the information the company holds about them and the company will respond within 30 days. Complaints about privacy will be handled by the Operations and Finance Manager and, where unresolved, the person will be told how to contact the Office of the Australian Information Commissioner.

6.Data breaches

A suspected loss or unauthorised access to personal information must be reported to the Operations and Finance Manager immediately. The company will assess the breach, contain it and notify affected people and the regulator where the law requires.

AUR-POL-004 v1.7 · CAQA Studio AuroraUncontrolled when printed. Simulated document created by CAQA for training and assessment.