What you need to notify us about
All users of the Document Verification Services (DVS) have obligations to notify us, the Attorney-General's Department, about key events, risks and changes in your use of the DVS. This page provides information about when and how to notify us. These notifications are important for the DVS's system integrity, security and help to protect individuals' personal information. You must meet these notification obligations to maintain your access to the DVS.
Privacy Impact Assessment
We commissioned a Privacy Impact Assessment (PIA) to cover standard DVS use for all users of the DVS. You should assess whether your proposed use of the DVS is consistent with the standard use covered in the PIA before you sign a participation agreement. Once you have access to the DVS, if your business model changes, you should consider whether you are still consistent with the standard use.
If you use or plan to use the DVS in a way that is inconsistent with the standard use covered in our Privacy Impact Assessment (PIA), you must:
- Promptly notify us in writing and include details about how your use is inconsistent with our PIA.
- Commission your own independent PIA about your use of the DVS.
- Provide the findings and recommendations of your independent PIA to us. Please note that under your participation agreement, we may publish your PIA.
Further information on PIAs is published by the Office of the Australian Information Commissioner (OAIC).
Where to find this obligation in your participation agreement:
- Business users – Clause 5.3
- Gateway service providers – Clause 5.3
- Identity service providers (IDSP) – Clause 5.3
- Government requesting agencies – Clause 19.7
- Document issuers – Clause 19.9
Accessing the DVS from overseas
Private sector users must provide us with written notice before any of your personnel access the DVS outside of Australia or New Zealand. This applies to any of your employees, agents, contractors, consultants and all sub-contractors who access or use the DVS overseas.
To notify us, you must send the information below to IVSComplianceReporting@ag.gov.au:
- Your legal entity name.
- Your Australian Business Number or New Zealand Business Number.
- Your Originating Access Code(s).
- The countries outside of Australia and New Zealand where DVS information will be accessed.
- The names of any overseas based entity or individual (overseas personnel) acting on your behalf.
- Your relationship with the overseas personnel or entity.
Where to find this obligation in your participation agreement:
- Business users – Clause 4.7(g)
- Identity service providers – Clause 4.12(j)
- Gateway service providers (GSP) – 4.15(j)
Security breaches
Private sector users must immediately notify us in writing if you know or suspect that:
- your access to the DVS or access to your own systems have been compromised
- an unauthorised use of the DVS or any security breach has occurred
- a security vulnerability, fault, error or problem exists in the DVS, in the match result you receive, or your organisation's own connected systems
- for GSPs, if a security vulnerability, fault, error or problem exists in your Gateway System, Gateway Service or Gateway User's systems.
If you notify us of a breach that is reasonably likely to result in serious harm to an individual whose identification information is involved, we are required to inform the OAIC. We will notify you if we take this step. You must take reasonable steps to notify affected individuals.
Fulfilling this obligation does not exempt you from any other legal obligations you may have including under the Privacy Act 1988 (Cth). If you are unsure what your legal obligations are in the event of a breach, please seek independent legal advice.
Where to find this obligation in your participation agreement:
- Business users – Clause 10
- Identity service providers – Clause 10
- Gateway service providers – Clause 10
Change in control in your organisation
Your organisation must provide us with written notice at least 45 days before you take any action or there is any arrangement resulting in a change in control in your organisation. If you wish to continue to access the DVS after there has been a change in control in your organisation, you must get our written consent.
Where to find this obligation in your participation agreement:
- Business users – Clause 17.1
- Identity service providers – Clause 18.1
- Gateway service providers – Clause 18.1
Assigning, transferring or novating your rights or obligations under the agreement
If you are an IDSP, GSP or government user, you must give us written notice at least 45 days before any proposed assignment, transfer or novation of rights or obligations under your participation agreement.
If your organisation intends to novate your agreement to another organisation, you must provide to us full details of the other organisation or entity. If you are assigning or transferring your rights and obligations to another organisation, you must provide full details of the organisation or entity.
You must seek our consent from us before any assignment, transfer or novation takes effect.
Where to find this obligation in your participation agreement:
- Identity service providers – Clause 17
- Gateway service providers – Clause 17
- Government requesting agencies – Clause 17.8
- Document issuer – Clause 17.7
For government users
Additional notification obligations for government users
Machinery of Government
If you are a government user and your duties are moved to a different agency because of a machinery of government change, your participation agreement automatically transfers to the new agency. However, if this occurs, please inform us so that we can update our records.
Where to find this obligation in your participation agreement:
- Government requesting agencies – Clause 17.9
- Document issuer – Clause 17.8
Intervening events
If an intervening event prevents you from performing an obligation, you must notify us as soon as practicable (no later than 5 business days after the event happens).
Where to find this obligation in your participation agreement:
- Government requesting agency – Clause 11, Clause 1.1
- Document issuer – Clause 11, Clause 1.1
Unauthorised access to classified information
You must immediately notify us if you become aware of any unauthorised access to information that has a security classification:
- Government requesting agency – Clause 13
- Document issuer – Clause 13
Correction of personal information
If you find that personal information held by another DVS government agency is inaccurate, out-of-date, incomplete, irrelevant or misleading, you must take reasonable steps to notify us.
Where to find this obligation in your participation agreement:
- Government requesting agency – Clause 14.2
- Document issuer – Clause 14.2(d)
Change to competitive neutrality status
Australian governments agreed to the 2025 Intergovernmental Agreement on National Competition Policy and have developed related policies. It will be your responsibility to ensure you comply with any of these policies that apply to your use of the DVS.
For government requesting agencies, Clause 17.7 requires you to notify us immediately if your agency's competitive neutrality status changes.
Security breaches
You must notify us and any other affected government agency within 48 hours if you learn about, or have reasonable grounds to suspect, a security breach. Your notification should include your view on whether the breach is likely to result in serious harm to the individual whose identification information is involved.
Where to find this obligation in your participation agreement:
- Government requesting agencies – Clause 19.3
- Document issuers – Clause 19.4
Public complaints
If you receive a complaint from a member of the public about the DVS that relates to another DVS user, you must notify that other user.
Where to find this obligation in your participation agreement:
- Government requesting agency – Clause 20
- Document issuer – Clause 20
The information on this page is not and should not be taken as legal advice.