Security and Privacy
How we handle your data and maintain the security of information entrusted to us.
Version 1.0 | Updated: May 2026 | Next review: May 2027
Important Security Notice
NSP does not collect Tax File Numbers (TFNs) or banking passwords at any point. These are never requested through any NSP form, portal, or communication. If you receive a communication purportedly from NSP requesting your TFN, please contact us immediately - it is not from us.
Our approach to data security
We take the security of personal and payroll information seriously. We apply a least privilege access model - meaning that staff access only the data they need to perform their specific role. Access is reviewed regularly and revoked promptly when no longer required.
All data transmitted through our website and client portal is encrypted in transit using industry-standard TLS encryption. We work with reputable technology providers and maintain security controls appropriate to the sensitivity of the information we handle.
NSP is currently implementing ISO 27001:2022 certification across our information security management systems. This reflects our commitment to maintaining internationally recognised security standards for the protection of client data.
Secure forms
All forms on our websites - including nationalsalarypackaging.com.au and nationalsalarypackaging.com - are submitted over an encrypted connection.
NSP does not collect Tax File Numbers (TFNs) or banking passwords at any point. These are never requested through any NSP form, portal, or communication. If you receive a communication purportedly from NSP requesting your TFN, please contact us immediately - it is not from us.
If we require sensitive information as part of onboarding or administration, we will provide a secure method for its submission.
Our online forms are delivered through Base44, a third-party platform whose servers are located in the United States of America. For full details of how your information is stored and handled, please refer to our Privacy Policy.
Audit readiness
Our internal processes are designed to support employer audit readiness. We maintain records of salary packaging agreements, benefit payments, and supporting documentation in a manner that can be produced promptly if required by the ATO or an employer's auditor.
Employees are also required to retain original receipts and supporting documentation for a minimum of seven years in accordance with ATO requirements. This obligation is confirmed as part of every salary packaging declaration.
Third-party sharing
We do not sell or rent your personal information to third parties. We may share information with:
- Your employer - as necessary for payroll administration and salary packaging management
- Finance companies - in the case of novated lease applications and personal loan arrangements
- EML Payment Solutions - for the setup and administration of your EML digital card
- Credit reporting bodies - where a credit enquiry is made in connection with a finance application
- The Australian Taxation Office and other government agencies - where required by law
- Other parties - where you have given your explicit consent
We do not share your information for marketing purposes without your consent. For full details of our information sharing practices and overseas disclosure obligations, please refer to our Privacy Policy.
Data retention
We retain personal information for as long as it is necessary to provide our services and to meet our legal and regulatory obligations. Salary packaging records are retained in accordance with ATO requirements - generally a minimum of seven years.
Where personal information is submitted through Base44, deleted records are retained on Base44 servers for up to 30 days before permanent deletion, in accordance with Base44's data retention policy.
You may request access to, or deletion of, personal information we hold about you by contacting our Privacy Officer. Requests to delete information may be limited where retention is required by law.
ISO 27001:2022 certification
NSP is actively implementing an Information Security Management System (ISMS) in accordance with the ISO 27001:2022 standard. This internationally recognised framework covers:
- Risk assessment and treatment across all information assets
- Access controls and least privilege principles
- Incident response and notifiable data breach procedures
- Staff training and awareness
- Supplier and third-party security obligations
- Physical and environmental security controls
Certification is being pursued to provide our employer clients and their employees with independent assurance that NSP's information security practices meet a recognised international standard. We will publish our certification status on this page upon completion.
Notifiable data breaches
In the event of a data breach that is likely to result in serious harm to individuals, NSP will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
If you believe your personal information held by NSP may have been compromised, please contact our Privacy Officer immediately.
Contact
For security or privacy concerns, complaints, or requests to access or correct your personal information, please contact our Privacy Officer:
National Salary Packaging
Shante Pty Ltd | ABN 80 110 261 768 | ACL 409538
For more information about your privacy rights, visit the Office of the Australian Information Commissioner at www.oaic.gov.au or call 1300 363 992.
Related Information
This Security and Privacy page should be read in conjunction with NSP's Privacy Policy, Website Terms of Use, and Disclaimer.
Version 1.0 | Updated: May 2026 | Next review: May 2027
© 2026 Shante Pty Ltd trading as National Salary Packaging. All rights reserved.
