Privacy & Data Security
Protecting patient privacy is central to how ASPREN operates. We follow strict legal, ethical, and data security standards to ensure that all information collected through the network is handled responsibly and securely. ASPREN primarily uses de-identified data, meaning information cannot reasonably be used to identify you.
ASPREN is bound by several pieces of legislation as well as human ethics approval, as follows:
Human Research Ethics
ASPREN operates under approval from the Royal Australian College of General Practitioners (RACGP) National Research and Evaluation Ethics Committee (NREEC) (Approval No. NREEC 18-003 – Surveillance of influenza and influenza-like illness through the Australian Sentinel Practices Research Network (ASPREN).
This means that:
- All ASPREN activities are independently reviewed to ensure they meet national human research ethics standards
- The rights, safety, and wellbeing of patients are protected
- Participation is voluntary, and patients can choose not to take part in surveillance activities and this will not affect their usual standard of care
Ethics approval ensures that ASPREN’s work is conducted in a way that is respectful, transparent, and in the public interest.
National Health Security Act
ASPREN contributes to Australia’s national public health influenza surveillance system and operates in alignment with the National Health Security Act 2007.
This legislation allows for the sharing of health information to:
- Monitor and respond to communicable diseases
- Detect and manage public health threats
- Support coordinated responses across states and territories
For patients, this means:
- In rare cases of significant public health concern (such as serious infectious disease outbreaks), health authorities may be able to link laboratory results back to a healthcare provider
- This process is tightly controlled and only occurs when necessary to protect public health
Australian Centre for Disease Control Act 2025
ASPREN supports national surveillance efforts aligned with the Australian CDC under the Australian Centre for Disease Control Act 2025.
This legislation strengthens Australia’s ability to:
- Detect emerging health threats earlier
- Coordinate national responses to infectious diseases
- Use high-quality surveillance data to inform public health decisions
For patients, this means:
- Data collected through ASPREN contributes to a broader national system designed to keep communities safe
- Information is used in a secure and controlled way to guide responses such as vaccination programs, outbreak management, and health policy
Privacy Act 1988
ASPREN complies with the Australian Privacy Principles, which are part of the Privacy Act 1988. These principles regulate how personal and sensitive information is collected, used, stored, and shared.
For patients, this means:
- Your personal information is only collected when necessary for public health surveillance
- Sensitive health information (such as symptoms, vaccination history, and test results) is handled with strict confidentiality
- Wherever possible, identifying details are removed before data are shared with ASPREN
- Data are stored securely and protected against misuse, loss, or unauthorised access.
How Your Data Is Protected
ASPREN applies multiple layers of protection to ensure data security:
- Removal of identifying details before data are analysed
- Secure data transfer systems between GP practices, laboratories, and ASPREN
- Restricted access to authorised personnel only
- Compliance with national data security standards
Your Choice
Participation in ASPREN surveillance is voluntary. If you are invited to take part (by completing a survey and providing a swab), you can choose whether or not to participate.
Because data are de-identified once provided to ASPREN, it may not be possible to withdraw your data at a later date.