Groundskeeper
Research

HPI-I and Victorian Student Number processing: privacy, legal, records and security controls

Research date / evidence cut-off: 3 October 2026 (Australia/Sydney) Status: research and specification only. No runtime behaviour is changed by this document. Implementation status: written in parallel with the experimental HPI-I and VSN detectors, which have since shipped disabled by default with structural-only validation, no egress and no logging of values (see the micro-slice record). Their hand-chosen, structurally valid fixtures predate the fixture registry in GK-HV-19 and remain subject to OD-029. Scope: Groundskeeper evaluating LLM inputs and outputs that may contain a Healthcare Provider Identifier – Individual (au.health.hpi_i) or a Victorian Student Number (au.education.vic_vsn). Related: identifier inventory, ADR 0007, threat model, persistence, open decisions

This is not legal advice. It summarises primary sources and regulator guidance so engineering can design conservative defaults. Every item marked [I] or [D] needs review by a qualified legal, privacy, or records owner before it is relied on.

1. Bottom line

  1. Both identifiers are statutorily restricted, not merely "PII". The Healthcare Identifiers Act 2010 (Cth) s 26(1)(d) prohibits any person from using or disclosing an individual healthcare provider's healthcare identifier unless an exception applies. Penalties include a criminal offence and a civil penalty. Part 5.3A of the Education and Training Reform Act 2006 (Vic) limits VSN access, use and disclosure to persons the Secretary authorises, for listed purposes. VCAA says that authorised users include third-party IT contractors.
  2. Groundskeeper is likely to "use" these identifiers when it detects or redacts them [I]. Whether an operator has authority for that depends on the deployment. For example, it may be a contracted service provider of a healthcare provider, a State contractor for a school, or an unrelated deployer that receives an identifier incidentally. That question cannot be resolved by engineering. It is decisions OD-023 and OD-024.
  3. The safe engineering default is minimise → redact → forget. Detect with local structural checks only, replace with an irreversible category placeholder before any onward disclosure, and keep identifier values out of logs, telemetry, audit records, fingerprints, caches, fixtures and external judges.
  4. Hashes of these identifiers are not de-identification. Each identifier has an effective space of about 10⁹ values: nine free digits for HPI-I and nine digits for VSN. Single-threaded Python computed 1.34 million SHA-256 hashes per second in this orb, so it could enumerate the whole space in about 12 minutes. A keyed HMAC protects values only while its key stays secret. ADR 0007's "keyed privacy-safe fingerprints" should therefore be prohibited by default for these two categories (OD-026).
  5. Synthetic fixtures can collide with real identifiers. Any 16-digit value that starts 800361 and passes Luhn may be an issued HPI-I. The VSN has no published checksum. A Victorian VET collection specification gives its value range as 000000001–999999999, so almost every nine-digit number may be a real VSN. Synthetic identifier values are therefore treated as potentially real. Section 6 defines generation rules.
  6. Never "validate" against the HI Service, the Healthcare Provider Directory or the Victorian Student Register. Those lookups are restricted to authorised parties. They would also create a new collection or disclosure and records. Validation stays structural only.
  7. Victorian deployments add obligations beyond the Commonwealth APPs. Under IPP 9, sending information outside Victoria is a transborder transfer, including interstate cloud hosting. IPP 7 restricts the use of another organisation's unique identifiers. VPDSS applies to contracted service providers. Decision records may be public records whose disposal requires an authority under the Public Records Act 1973 (Vic).
  8. Breach handling has several regimes: the Privacy Act NDB scheme for APP entities, the HI Act rule that a contravention is an interference with privacy, the OVIC incident scheme for Victorian public sector information, contractual notification to the Department or VCAA, and ransomware-payment reporting. One runbook must cover all of them (OD-028).
  9. Production trials are production processing. Observe or shadow mode still receives real identifiers. A trial needs the same authority, PIA, contract, residency and incident controls before the first real request (OD-030).

2. Method and labels

Primary sources were preferred: Commonwealth and Victorian legislation (current compilations), regulators (OAIC, OVIC, PROV), issuers and operators (VCAA, Australian Digital Health Agency, Services Australia via ADHA), the Victorian Department of Education Policy and Advisory Library, and ASD. Secondary commentary was used only to locate primary material. Section 11 lists URLs.

LabelMeaning
[B]Binding requirement: statute, regulation, legislative instrument, or a standard that is mandatory for the named class of entity, such as VPDSS for Victorian public sector bodies and their contracted service providers. Applicability still depends on the entity and deployment.
[G]Regulator, issuer or departmental guidance: authoritative and often contractually imposed, but not itself statute.
[I]Uncertain interpretation: an engineering reading of the sources that a qualified owner must confirm.
[D]Decision needed: cannot be settled without a qualified legal, privacy, records or governance owner. It is mapped to the open-decisions register.

Processing model assumed

Groundskeeper is a stateless decision service (architecture). A gateway sends prompt or response content. Groundskeeper evaluates it in memory and returns a verdict, findings (category, offsets, coverage), and optional transformations. By default, it does not retain raw payloads (ADR 0007).

┌──────────────┐  prompt/response  ┌────────────────┐  verdict + redacted  ┌──────────────┐
│ User / app   │──────────────────▶│ Gateway (PEP)  │◀────────────────────▶│ Groundskeeper│
└──────────────┘                   └───────┬────────┘                      └──────┬───────┘
                                           │ only if allowed                      │ metadata only
                                           ▼                                      ▼
                                   ┌────────────────┐                     ┌───────────────┐
                                   │ Model provider │                     │ Audit / OTel  │
                                   └────────────────┘                     └───────────────┘

Each arrow can be a collection, use, or disclosure. Each box can be in a different jurisdiction.

Deployment roles that change the analysis

RoleExampleWhy it matters
R1 Health CSPHealthcare provider or health administration entity deploys an assistant. The Groundskeeper operator provides IT services to it.The HI Act s 36 authority can extend to a contracted or subcontracted service provider whose duties involve implementing the authorised purpose [B]. Whether guardrail inspection implements that purpose is [I/D].
R2 Victorian public sectorA Victorian government school, the Department, or VCAA uses Groundskeeper.PDP Act IPPs and Part 4 VPDSS, the Public Records Act, Department policy, and possibly VSN authorisation apply.
R3 Other education APP entityCatholic or independent school, RTO, TAFE vendor, or edtech provider.Privacy Act APPs, including APP 9 government-related identifiers; ETR Act authorisation; and possibly the Children's Online Privacy Code.
R4 Incidental receiptUnrelated deployer, such as a bank or retailer, where a user pastes an HPI-I or VSN.The deployer probably has no HI Act or ETR Act authority [I]. The only defensible behaviour is to minimise, redact, and not forward.
R5 Groundskeeper engineeringDevelopment, CI, benchmarks, fixtures.Must not contain real identifiers. ISM-1420 applies to production-derived data.

3. Identifier facts that drive controls

PropertyHPI-IVSN
Format16 digits, prefix 800361, Luhn check digit (HL7 AU Base profile)Randomly generated 9-digit number (VCAA). VET collection spec range: 000000001–999999999
Free space9 free digits → about 10⁹ structurally valid valuesAbout 10⁹ values. No checksum is published
HoldersIndividual healthcare providers (adults). Ahpra-registered practitioners and others can be assigned oneEvery student under 25 at a Victorian school, home-schooling registration, or in-scope VET provider. Most holders are children
StatuteHI Act and HI Regulations 2020; s 26 use and disclosure offence; s 27 protection; s 29 interference with privacyETR Act Part 5.3A; s 5.3A.9 authorisation; s 5.3A.10 offence (authorised users); s 5.3A.10B guidelines
Privacy-law statusGovernment related identifier for the Privacy Act (HI Act s 9(6)) [B]Assigned by the Secretary of a State department, so it is likely a government related identifier for APP 9 [I]. It is likely a "unique identifier" under PDP Act IPP 7 [I]
Public?May appear in healthcare directories with the provider's consent (HI Regs s 10E). That does not lift s 26 restrictions on other uses [B]Not public. VCAA says the Act does not permit VSNs in shared communications such as class lists [G]
Authoritative validationHI Service. Access is limited to registered or authorised participants [B]Victorian Student Register. Access requires authorisation [B]
Groundskeeper detector classValidated structural: prefix + Luhn (ADR 0010)Context-bound: requires a VSN or full-label context

4. Findings by regime

4.1 Healthcare Identifiers Act 2010 and Regulations 2020

Current compilation: Act C2026C00415 (19 September 2026). Regulations F2026C00393 (5 May 2026).

  • [B] s 26(1)(d), (3), (5), (6). A person must not use or disclose an individual healthcare provider's healthcare identifier unless the use or disclosure is required or authorised under the HI Act, another Commonwealth law, or a court order; is by the provider for personal, family or household affairs; or falls within listed permitted general situations. The offence penalty is 2 years' imprisonment or 120 penalty units, or both. The civil penalty is 600 penalty units for knowing or reckless use or disclosure. Section 26(2) also prohibits use or disclosure of information disclosed in contravention.
  • [B] Authorised purposes for provider identifiers. These include communicating or managing health information as part of providing healthcare or health administration (s 23); the My Health Record system (s 24); authentication in electronic communications (s 25); disclosure of an HPI-I to the provider (s 25C); and regulation-prescribed purposes (s 25D). Examples of prescribed purposes are health facilitation programs (HI Regs s 10A) and healthcare directory services (HI Regs s 10E, provider consent required).
  • [B] s 36 / s 36A. An authorisation extends to employees, contracted service providers and subcontracted service providers where their duties involve, or are reasonably connected with, implementing that purpose. Section 5 defines a contracted service provider to include "information technology services relating to the communication of health information".
  • [B] s 27. An entity holding healthcare identifiers must take reasonable steps to protect them from misuse, loss, and unauthorised access, modification or disclosure. It must also meet any prescribed requirements.
  • [B] s 29. A contravention in connection with an HPI-I is an interference with privacy under the Privacy Act. For Part V investigations, a State or Territory authority is treated as an organisation. OAIC therefore has jurisdiction even over Victorian public bodies for this conduct.
  • [B] HI Regs s 12. Retrievable records of individuals who access identifiers from the service operator must be kept, including for 7 years after authority ends. This applies only if Groundskeeper ever queries the HI Service. The control GK-HV-04 forbids such queries.
  • [G] OAIC. Healthcare identifiers are personal information. Use outside the HI Act attracts penalties and is an interference with privacy. OAIC recommends audit trails of individual staff access.
  • [G] ADHA HI conformance profile v5.0. For connected software, an audit trail of identifiers disclosed by the HI Service is required (008028). The ADHA security conformance profile for My Health Record connecting systems requires segregation of production from test and development environments (SEC-0520, tracing ISM-0400). This applies to Groundskeeper only by analogy unless it becomes HI-connected software.
  • [I] Detecting, redacting or forwarding an HPI-I is probably a "use", and forwarding it to a model provider is probably a "disclosure". The HI Act does not expressly address transient machine inspection.
  • [I] No data-location restriction specific to healthcare identifiers was found in the provisions reviewed. Do not confuse this with My Health Records Act 2012 obligations, which apply only if Groundskeeper touches My Health Record data.
  • [D] OD-023. For each role (R1–R4), is Groundskeeper's inspection or redaction authorised? Is allow-through of an HPI-I to a model provider ever permitted?

4.2 Privacy Act 1988 (Cth) and the APPs

  • [B] APP 3 / APP 5. Collection must be reasonably necessary for the entity's functions. Notice must be given. Content generated or inferred by AI that contains personal information is a collection [G OAIC AI guidance].
  • [B] APP 6. Use and disclosure are limited to the primary purpose unless an exception applies. Entering personal information into a third-party AI product can be a disclosure [G OAIC]. As best practice, OAIC recommends not entering personal information, especially sensitive information, into publicly available generative AI tools [G].
  • [B] APP 8 / s 16C. Overseas disclosure requires reasonable steps. The disclosing entity remains accountable for an overseas recipient's acts.
  • [B] APP 9. An organisation must not adopt a government related identifier as its own identifier. It must not use or disclose one unless an exception applies, such as when required or authorised by law (HI Act s 28 makes HI Act authorisations count). The HPI-I is a government related identifier (HI Act s 9(6)). The VSN probably is one [I]. Using either identifier as a Groundskeeper key, fingerprint key, tenant user ID or join key risks "adoption" [I].
  • [B] APP 11, including APP 11.3. From 2024, APP 11.3 states that reasonable steps include technical and organisational measures. APP 11.2 requires destruction or de-identification when information is no longer needed.
  • [B] Part IIIC NDB. APP entities must assess a suspected eligible data breach within 30 days. They must notify OAIC and affected individuals where serious harm is likely. Health service providers are APP entities regardless of turnover. State authorities are generally not APP entities, although HI Act s 29 still brings HPI-I contraventions to OAIC [B/I].
  • [B, commences 10 Dec 2026] APP 1.7–1.8 automated decisions. A privacy policy must describe computer programs that make, or substantially and directly relate to, decisions that could reasonably be expected to significantly affect an individual's rights or interests using personal information. Whether a guardrail block or redaction meets that test is [I/D] (OD-031).
  • [B pending] Children's Online Privacy Code. OAIC must register it by 10 December 2026. The exposure draft applies to APP entities providing social media, relevant electronic or designated internet services that are likely to be accessed by children or primarily concerned with children's activities. Services provided by health service providers are excluded. It may bind R3 deployers in education. Applicability depends on the final text [D OD-031].
  • [G] OAIC de-identification guidance. Hashing identifiers obscures them but is primarily a linkage technique. De-identified data can become personal information again in another environment.

4.3 Education and Training Reform Act 2006 (Vic) Part 5.3A and VCAA guidance

  • [B] s 5.3A.9. The Secretary may authorise, in writing, a person, body or class to access, use or disclose VSNs or related information for listed purposes: enrolment and attendance; resources; statistical or research purposes relating to education or training; accurate educational records; as required or authorised by law; prescribed purposes; or purposes in a Ministerial Order. Authorisations may be conditional and revocable.
  • [B] s 5.3A.10. An authorised user must not access, use or disclose a VSN or related information except in accordance with Division 3 (30 penalty units). This does not apply to statutory authorities.
  • [B] s 5.3A.10A–10C. The Secretary must issue guidelines on the manner of access, use and disclosure and on storage and destruction. Guidelines may cover reporting requirements. Authorised users must comply with them. If an authorised user is not otherwise covered by the PDP Act or the Privacy Act, the PDP Act applies to it as if it were an organisation.
  • [B] s 5.3A.13. A student may use or disclose their own VSN for any lawful purpose. A student's own VSN may therefore legitimately appear in input. That does not authorise the recipient's later handling [I].
  • [G] VCAA. Requests for identifiable data or VSN data matching require authorisation. Example applicants include third-party contractors, such as IT contractors, doing work for an authorised user that requires VSN access. VCAA considers suitability, purpose, access, use, disclosure and destruction, and privacy and human-rights implications. VSN information must not appear in shared communications such as class lists.
  • [G] Department of Education (schools). VSN use is regulated and limited to what legislation stipulates. Department guidance tells schools not to enter personal information into generative AI tools under any circumstances. Department policy applies to staff, contractors and service providers.
  • [G] VET (DJSIR-administered collection). The Victorian VET Student Statistical Collection Guidelines (2022 v1.0, issued by DET before VET functions moved to DJSIR) specify VSN as numeric, length 9, values 000000001–999999999. Confirm against the current DJSIR edition.
  • [I] In the provisions reviewed (ss 5.3A.9–5.3A.15), no general offence was found for a person who is not an authorised user. Privacy law (IPP 7, APP 9), contracts and Department policy still constrain those persons. Do not read the absence of an offence as permission.
  • Evidence gap. The current Secretary's Guidelines on the Victorian Student Number could not be retrieved. VCAA's link returned an HTML page instead of the document on 3 October 2026. Storage, destruction, reporting and contractor conditions must be taken from that document before any Victorian education deployment.
  • [D] OD-024. Does the operator, or each sub-processor, need VCAA authorisation? Under which permitted purpose is guardrail inspection of VSNs justified?

4.4 Victorian privacy, security and health records

  • [B] PDP Act IPP 4. Personal information must be protected, and destroyed or permanently de-identified when no longer needed. IPP 7 restricts adopting, using or disclosing another organisation's unique identifier. A contracted service provider cannot adopt a client's unique identifier as its own (OVIC guideline 7.2(c)) [G]. IPP 9 applies to any transfer outside Victoria, including interstate cloud processing. Permitted grounds include substantially similar law, contract or binding scheme, consent, and reasonable steps [G OVIC IPP 9 guidance].
  • [B] PDP Act s 17 / State contracts. Contracted service providers can be bound to the IPPs. Part 4 / VPDSS V2.0 (still current; implementation guidance v2.4, January 2026) requires contracted service providers with access to public sector information to adhere to the standards. Under PDP Act s 89, the agency's security risk profile assessment and protective data security plan must cover those providers.
  • [G] OVIC incident notification (VPDSS E9.010). Notify incidents affecting public sector information rated BIL 2 (limited) or above, including OFFICIAL: Sensitive, as soon as practical and within 30 days. OVIC also encourages timely notification to affected individuals.
  • [I] This review found no general statutory duty in the PDP Act for Victorian public sector bodies to notify individuals of breaches. Confirm the current position.
  • [B/I] Health Records Act 2001 (Vic). It may apply where an HPI-I appears with health information held in Victoria, including by private-sector bodies. Its identifier and transborder principles (HPP 7, HPP 9) parallel IPP 7 and IPP 9. Applicability to provider identifiers alone is uncertain.

4.5 Records: Public Records Act 1973 (Vic) and PROV

  • [B] Public offices must make and keep full and accurate records. They may destroy them only under a retention and disposal authority (RDA) or normal administrative practice (NAP).
  • [G/B for public offices] PROV AI Technologies and Recordkeeping Policy (2024). Content created by or through AI technologies is a public record. Accuracy checks and disposal must be overseen by an authorised human. Automated disposal must follow the PROV Approval Processes Policy.
  • [G] PROS 22/06 (School Records RDA) governs government school records. NAP covers duplicates and backups of records held elsewhere.
  • [I] For an R2 customer, Groundskeeper verdicts, transformations and audit metadata may be public records, even when processing is transient. That conflicts with "delete after N days" defaults and with APP 11.2 or IPP 4.2 minimisation unless the customer's records manager maps them to an RDA or NAP.
  • [D] OD-027. Are Groundskeeper decision artefacts records? Who is the record-keeper: the customer system of record or the operator? Which RDA class applies?

4.6 Breach and incident regimes

RegimeTriggerWhoTimingLabel
Privacy Act Part IIIC (NDB)Eligible data breach likely to cause serious harmAPP entities, including health service providersAssess within 30 days, then notify OAIC and individuals as soon as practicable[B]
HI Act s 29Any contravention involving an HPI-IAny person, including State authorities, for OAIC investigationNo separate notification clock. Exposure to complaints and investigation[B]
OVIC incident scheme (VPDSS E9.010)Confidentiality, integrity or availability incident on public sector information rated BIL 2 or aboveVictorian public sector bodies; contracted service providers via contractAs soon as practical and within 30 days[G/B]
ETR Act guidelines / authorisation conditionsPer the Secretary's Guidelines and conditions (not retrieved)Authorised usersUnknown until the guidelines are obtained[B/D]
Department of Education privacy incident processPrivacy incident in schoolsSchools, staff and contractorsPer Department policy[G]
Cyber Security Act 2024 Part 3Ransomware or cyber-extortion paymentBusinesses with turnover of at least $3 million, or SOCI responsible entities; not State bodies72 hours after payment[B]
SOCI Act cyber incident reportingIncident on a critical infrastructure assetResponsible entities, such as some hospitals and higher-education assets; usually customers rather than Groundskeeper12 or 72 hours by severity[B/I]
ContractAny suspected incident affecting customer dataGroundskeeper operator → customerContractual SLA (to be decided)[D]

4.7 Security guidance

  • ISM (ASD). ISM-0400 requires segregated development, test, staging and production environments. ISM-1420 prohibits production data in non-production environments unless they are secured to the same level. ISM-2030 requires commit scanning for secrets. ISM-2103 prohibits using organisational data processed by AI applications for training without informed, explicit consent. ISM-2123 requires deleting chat-session prompts and outputs with the session. ISM-1536 requires central logging of database queries and errors; log safely without values. All are [G] for non-government organisations and commonly contractual. Many Victorian controls trace to ISM through VPDSS.
  • ASD Essential Eight and Engaging with AI (2024). Restrict admin privileges, use MFA, back up, know what data the AI system receives, and plan incident response [G].
  • OAIC Guide to securing personal information gives the APP 11 reasonable-steps baseline [G].

5. Implications by engineering topic

TopicImplicationBasis
Collection / use / disclosureTreat any request containing these identifiers as receiving restricted information. Use only for the guardrail decision. Disclose onward only when the deployment's authority covers it. Otherwise redact before the gateway forwards. Echoing the identifier to users is also disclosure.[B] HI s 26; ETR 5.3A.9–10; APP 6/9; IPP 7. [I] inspection = use
Purpose limitationBind every deployment to a declared purpose code and authority reference. Restricted-category findings must not feed analytics, model training, benchmarking or product metrics beyond coarse aggregates.[B] HI ss 23–25D; ETR 5.3A.9(2); APP 6. [G] ISM-2103
LoggingNo value, partial value, normalised value, offset-with-context snippet or hash in logs or errors. Error types and panics must not include request bodies.[B] APP 11, HI s 27, IPP 4. [G] ADR 0007
TelemetryMetrics may record category counts only at coarse tenant and time granularity. No identifier-derived labels. Third-party APM or OTel SaaS is a disclosure and possibly an overseas or interstate transfer.[B] APP 8 / IPP 9. [I]
Test dataSynthetic data only; Section 6 rules apply. No production-derived corpora. No LLM-generated identifier values, because models may reproduce memorised real ones.[G] ISM-1420. [I]
RetentionRaw payloads are not retained. Audit metadata retention follows the customer RDA (R2) or an approved schedule (OD-009). Legal hold is supported.[B] APP 11.2 / IPP 4.2 / PRA. [D]
DeletionDeletion covers replicas, caches, search indices and backup expiry. Disposal of public records needs human authorisation and a disposal record.[B] PRA. [G] PROV AI policy
Access controlsNo standing human read path to payloads. Use least-privilege RBAC with author/approver/operator separation, MFA, privileged access logs and periodic review.[B] HI s 27 / APP 11. [G] ISM, E8, VPDSS Std 4
AuditUse tamper-evident, metadata-only decision audit with policy digest, verdict, category counts, purpose code, authority reference, actor and time. Never store the identifier.[G] OAIC audit-trail tip; ADHA 008028 (analogy); PROV
Redaction / tokenisationUse an irreversible placeholder such as [HPI-I] or [VSN]. No partial masking: with a fixed prefix, the last four HPI-I digits leave about 10⁵ candidates. No format-preserving or deterministic tokens, because they may equal a real identifier and enable linkage. A reversible vault becomes a store of restricted identifiers.[I]; OD-010
Cross-border / cloudProcess and store all sinks in an approved Australian region. For R2, document an IPP 9 ground even for interstate regions. Maintain a sub-processor register. External judges never receive restricted identifiers.[B] APP 8/16C, IPP 9. [G] Department and OAIC AI guidance. [D] OD-008, OD-025
Incident responseOne runbook maps detection → containment → regime matrix (Section 4.6) → customer notice. Treat a fixture collision with a real identifier, or a canary in a sink, as an incident.[B/G]. [D] OD-028
Production trialsShadow or observe mode still processes real data. Before the first live request, complete authority, PIA, contract, residency, kill switch, time box, and metadata-only evaluation. Do not harvest examples from the trial.[B] all regimes apply. [D] OD-030

6. Synthetic fixtures: collision risk and safe generation

6.1 Can a synthetic value map to a real identifier?

Yes, for any structurally valid value.

  • HPI-I. The structurally valid space is 800361 + 9 free digits + Luhn check digit, giving (10^{9}) values. If (N) identifiers are issued uniformly at random across that space, a uniformly random fixture collides with probability (p \approx N/10^{9}). The expected number of collisions in (k) fixtures is (k \cdot N/10^{9}). Issuance is unlikely to be uniform. Sequential or blocked allocation can make small or clustered values more likely to collide. Neither (N) nor the allocation scheme is published. HL7 AU Base publishes an example HPI-I in the profile documentation, but it is not designated as non-issued.
  • VSN. VCAA describes VSNs as random. The VET collection range covers every nine-digit value except 000000000. Every nine-digit fixture is therefore a candidate real VSN. With several cohorts allocated since the register began, (p) is material and cannot be made negligible by generation strategy.
  • Pairing raises harm. A bare number that coincides with an issued identifier is not obviously "about" that person. A fixture that pairs the number with a realistic name, date of birth, school, suburb, clinic or profession may create a plausible record about a real person [I].
  • Checking a fixture against the HI Service or VSR is prohibited. It would itself be an unauthorised access, use or disclosure, and it would create access records [B].

6.2 Safe generation practices

  1. Prefer impossible values for negative and robustness cases. For HPI-I, use the wrong prefix (for example 800362…, which is HPI-O space and must itself be handled), a Luhn failure, or the wrong length. For VSN, use wrong lengths, 000000000, or non-digit look-alikes. These can never be a real identifier of the target class.
  2. Use a minimal, registered set of structurally valid positives. Store them in a single reviewed fixture registry with provenance: generator version, seed, rule, date and reviewer. Each record carries may_match_issued_identifier: true. Keep the set small, for example fewer than 20 per category, and reuse it everywhere.
  3. Generate deterministically and algorithmically. Use a seeded CSPRNG to draw the nine free digits, then compute Luhn for HPI-I. Never ad hoc-generate in CI. Never ask an LLM for identifier values. Never perturb a real identifier: a one-digit change to a real number is derived from personal information and may itself be issued.
  4. Use only obviously fictional context. Never pair positives with realistic person names, dates of birth, schools, clinics or suburbs. Use labelled placeholders such as Example Clinician A or Example School. Do not combine an HPI-I and a VSN in one fixture unless the test requires it.
  5. Keep fixtures out of production. Production snapshots must not contain fixture allowlists or fixture-specific bypasses. Test policies and test tenants are separate. Leak canaries in production use only registered values and only through a dedicated test tenant.
  6. Fail CI on unregistered candidates. Add a pre-commit or CI scan that fails on any 800361-prefixed Luhn-valid 16-digit sequence, or any nine-digit sequence within about 30 code points of a VSN label, that is not in the registry. Scan built artefacts, logs and benchmark outputs too.
  7. Rotate on collision. If anyone reports that a fixture value belongs to a real person, remove it from the registry, purge it from history where practicable, rotate it, and handle the event under the incident runbook.
  8. Do not use vendor test environment identifiers. HI Service or ADHA conformance test data obtained under developer registration is licensed for that purpose. Do not commit it to this repository [I].

7. Engineering control matrix

Applicability: H = HPI-I, V = VSN, All = both. Gates: P0 before any real data or trial; P1 before general production enforcement; P2 before optional features.

IDControlAppliesBasisGroundskeeper implementationVerificationGate
GK-HV-01Restricted-identifier classes are deny-by-default for onward flowAll[B] HI s 26; ETR 5.3A.9–10; APP 9; IPP 7. [D] OD-023/024Mark au.health.hpi_i and au.education.vic_vsn as restricted. The compiler rejects any policy that forwards them unredacted unless the deployment binding carries an approved identifier_authority reference and purpose codeCompiler negative tests; binding reviewP0
GK-HV-02Redact before onward disclosureAll[B] APP 6/8; HI s 26. [I]Input-stage transformation replaces values with category placeholders before gateway forwarding. Output stage applies the same ruleGolden fixtures; Portkey replacement testsP0
GK-HV-03Block VSN in broadcast or multi-recipient outputsV[G] VCAA shared-communications guidanceOutput-stage rule: block or redact VSNs where the request marks the destination as shared or broadcastConformance casesP1
GK-HV-04No registry lookupsAll[B] HI Act access regime; ETR authorisation. TM-11 analogueDetectors have no network egress. Coverage state is structural. Never call the HI Service, HPD or VSREgress policy test; code reviewP0
GK-HV-05Value-free logs, traces, errors and metricsAll[B] APP 11, HI s 27, IPP 4. [G] ADR 0007Typed log fields only; no body capture in OTel or HTTP middleware; panic recovery strips bodies; category counts onlySink canary scan (TM-05); lint for %v of request structsP0
GK-HV-06No per-value fingerprints by defaultAll[I] about 10⁹ space is enumerable. [D] OD-026Disable fingerprint emission for restricted classes. If later approved: HMAC-SHA-256, per-tenant and per-purpose non-exportable KMS key, rotation, TTL, treated as personal informationConfig test; key-policy auditP0
GK-HV-07No value-level allowlistsAll[I] APP 9 adoption riskAllowlisting by context rule or field only, never by identifier value or hashCompiler rejects value allowlists for restricted classesP1
GK-HV-08Irreversible, non-colliding placeholdersAll[I]. OD-010Fixed category placeholder; no partial masking; transformations must not emit strings in the identifier's valid spaceProperty test: output never matches detectorP0
GK-HV-09No reversible tokenisation or vaultAll[D] OD-010Feature absent. Any proposal requires a PIA, key management design, legal sign-off and authority covering storageArchitecture reviewP2
GK-HV-10External judges and models never receive restricted identifiersAll[G] Department GenAI guidance, OAIC AI guidance. [B] APP 8 / IPP 9. [D] OD-008Routing layer redacts restricted spans before any remote or model-based detector, or skips that detector with unjudged coverageIntegration test with a mock remote detectorP0
GK-HV-11Approved residency for all processing and sinksAll[B] APP 8/16C, IPP 9. [D] OD-025Region-pinned deployment, logs, APM, backups and support tooling. Sub-processor register. IPP 9 ground recorded for R2Infrastructure-as-code policy check; vendor register reviewP0
GK-HV-12No payload persistence or memory spillAll[B] APP 11. [G] ISMNo core dumps; encrypted or disabled swap; no request bodies in crash reporters; bounded buffers zeroed where practicalHost hardening checklist; crash drillP0
GK-HV-13Records-aware retention for audit metadataAll[B] PRA; APP 11.2/IPP 4.2. [G] PROV AI policy. [D] OD-009, OD-027Per-tenant retention class, legal hold, human-authorised disposal job with a disposal record (no values)Retention test; records manager sign-offP1
GK-HV-14Complete deletionAll[B] APP 11.2 / IPP 4.2Deletion propagates to replicas, caches and indices; backups expire within a documented period; deletion evidence recordedDeletion drillP1
GK-HV-15Least-privilege access, no human payload accessAll[B] HI s 27 / APP 11. [G] ISM, E8, VPDSS Std 4RBAC with author, approver and operator separation; MFA; privileged session logging; quarterly review; break-glass only for metadataAccess review evidenceP0
GK-HV-16Change control for restricted-class policyAll[G] VPDSS; TM-16/17Two-person approval; signed snapshots; tenant overrides cannot weaken restricted rulesActivation testsP1
GK-HV-17Tamper-evident metadata auditAll[G] OAIC; ADHA 008028 (analogy); PROVAppend-only audit with policy digest, verdict, category counts, purpose and authority references, actor, time; no identifiersAudit integrity testP1
GK-HV-18Purpose bindingAll[B] HI ss 23–25D; ETR 5.3A.9(2); APP 6Server-side deployment binding with a purpose code and authority reference that the request body cannot setTM-01 negative testsP0
GK-HV-19Fixture registry and generation rulesAll[I]; Section 6; [D] OD-029test/fixtures/identifiers/ registry with provenance; seeded generator; context rulesCI scan (GK-HV-20)P0 before any such fixture
GK-HV-20Repository and artefact identifier scanAll[G] ISM-2030 analogue; ISM-1420CI fails on unregistered 800361 + Luhn sequences and label-adjacent nine-digit sequences in source, artefacts and benchmark outputsCI jobP0
GK-HV-21No production-derived data outside productionAll[G] ISM-1420; conformance docCorpora come from the registry or synthetic generation only; incident-derived corpus requires a separate approvalCorpus register auditP0
GK-HV-22Multi-regime incident runbookAll[B/G] Section 4.6. [D] OD-028Runbook with a regime matrix, customer-notice SLA, evidence preservation without values, and a tabletop exerciseTabletop recordP0
GK-HV-23Production leak canariesAll[I]Registered fixture values sent through a dedicated test tenant on a schedule; all sinks scanned; alert on any hitScheduled job evidenceP1
GK-HV-24No echo in user-facing messagesAll[I] disclosureBlock reasons name the category, never the valueConformance casesP0
GK-HV-25Child-safe defaults for VSN contextsV[B pending] Children's code; [G] Department policyHighest-privacy defaults; no age or identity inference; no profiling from findingsPolicy reviewP1
GK-HV-26ADM transparency packAll[B from 10 Dec 2026] APP 1.7–1.8 for APP entities. [D] OD-031Document which decisions Groundskeeper automates (block, redact) and which inputs it uses, so deployers can assess privacy-policy disclosureDoc reviewP1
GK-HV-27Contract flow-downAll[B] PDP s 17, VPDSS, HI s 36. [D] OD-024/025/028Template clauses: IPP/APP compliance, VPDSS, HI Act contracted-service-provider duties, VSN authorisation conditions, breach SLA, sub-processors, residency, return or destruction, audit rights, no trainingLegal reviewP0
GK-HV-28No training on customer dataAll[G] ISM-2103Contract and configuration: provider training disabled; Groundskeeper does not learn from payloadsVendor attestationP0
GK-HV-29Transport and storage encryptionAll[G] ISM; VPDSS Std 11 (ICT security)TLS 1.2+ (1.3 preferred) and mTLS gateway↔Groundskeeper; encrypted metadata storesConfiguration scanP0
GK-HV-30Trial guardrailsAll[B] all regimes apply. [D] OD-030Time-boxed, tenant-scoped, kill switch, metadata-only evaluation, documented stop criteria, no corpus harvestingTrial readiness reviewP0

8. Pre-production checklist

A required owner or decision is noted where one applies. Every box must be ticked, with evidence linked, before the first real request.

Authority and legal

  • Deployment role (R1–R5) recorded for each tenant, with customer confirmation.
  • OD-023 decided for HPI-I processing in each role, including whether allow-through is ever permitted.
  • OD-024 decided. VCAA authorisation obtained or confirmed not required. Current Secretary's Guidelines obtained and their conditions mapped to controls.
  • Purpose code and authority reference configured in each server-side binding (GK-HV-18).
  • Contract executed with flow-down clauses (GK-HV-27), including a breach-notice SLA and sub-processor list.

Privacy and governance

  • PIA completed using the template the customer requires (OAIC, OVIC, or Victorian Department of Education), covering both identifiers, children, and AI.
  • APP 8 / IPP 9 basis recorded for every processing location, including interstate (OD-025).
  • Children's code and APP 1.7 assessment done for APP entity deployers (OD-031).
  • Indigenous Data Governance gate confirmed not triggered, or approved (IDG).

Architecture and configuration

  • Restricted classes enforced by the compiler (GK-HV-01). Default transformation is redaction (GK-HV-02, GK-HV-08).
  • No detector egress; validation is structural only (GK-HV-04).
  • Remote or model detectors cannot receive restricted spans (GK-HV-10).
  • Fingerprints disabled for restricted classes (GK-HV-06). No value allowlists (GK-HV-07).
  • Logs, traces, metrics, error reporting and crash tooling verified value-free with canaries (GK-HV-05, GK-HV-12, GK-HV-23).
  • Region pinning verified for compute, logs, APM, backups and support tooling (GK-HV-11).
  • Encryption in transit and at rest verified (GK-HV-29).

Data and fixtures

  • OD-029 approved. Fixture registry in place with provenance (GK-HV-19).
  • CI identifier scan enabled and passing (GK-HV-20).
  • No production-derived data in any non-production environment (GK-HV-21).

Access and audit

  • RBAC roles, MFA and privileged access logging in place. First access review done (GK-HV-15).
  • Metadata audit is append-only and tamper-evident, and contains no identifier values (GK-HV-17).
  • Two-person approval for restricted-class policy changes (GK-HV-16).

Records, retention and deletion

  • OD-027 decided. Retention class and RDA or NAP mapping recorded for R2 tenants. OD-009 durations set.
  • Legal hold and human-authorised disposal tested (GK-HV-13). Deletion drill passed (GK-HV-14).

Incident readiness

  • OD-028 decided. Runbook covers NDB, HI s 29/OAIC, OVIC, VCAA or Department, ransomware and contract (GK-HV-22).
  • Tabletop exercise completed, including "fixture matches a real person" and "identifier found in a log sink".

Trial operations

  • OD-030 approved: scope, duration, tenants, success and stop criteria, kill switch tested (GK-HV-30).
  • Observe-mode evaluation uses metadata only. No example harvesting.
  • Named privacy, security, records and customer sign-offs recorded.

9. Decisions needed

These are proposed additions to the open-decisions register. Engineering must not settle them.

IDDecisionOwnerRequired before
OD-023Whether inspection, redaction and any allow-through of HPI-Is is an authorised use or disclosure under HI Act s 26 for each deployment role, and the evidence requiredHealth-law counsel + privacyany health deployment or trial
OD-024Whether the operator and sub-processors need VCAA authorisation under ETR Act s 5.3A.9, which permitted purpose applies, and which Secretary's Guidelines conditions bind GroundskeeperLegal + privacy + customer (Department, VCAA, school)any Victorian education deployment or trial
OD-025Approved processing and storage jurisdictions and the APP 8 / IPP 9 basis, including interstate hosting and telemetry sub-processorsPrivacy + legal + securityproduction trial
OD-026Whether any per-value fingerprint of restricted identifiers is allowed, and if so the key management, rotation and retentionPrivacy + securityproduction telemetry
OD-027Records status of Groundskeeper decision artefacts for public-office customers, the record-keeper, and the RDA classRecords manager + legalVictorian public sector production
OD-028Breach notification allocation and SLAs across NDB, OAIC (HI), OVIC, VCAA or Department, ransomware reporting and contractsPrivacy + legal + securityproduction trial
OD-029Acceptance of the residual risk that structurally valid synthetic fixtures may equal issued identifiers, and approval of the registry and generation rulesPrivacy + engineering leadadding any structurally valid HPI-I or VSN fixture
OD-030Production trial authorisation: PIA outcome, scope, duration, stop criteria, and whether HREC or research approval appliesPrivacy + product + customerproduction trial
OD-031Whether Groundskeeper decisions fall within APP 1.7 automated decisions and whether the Children's Online Privacy Code affects deployers, and which documentation to providePrivacy + product10 December 2026 for APP entity customers

10. Evidence gaps and caveats

  • Secretary's Guidelines on the Victorian Student Number were not retrievable from the VCAA link on 3 October 2026. They are mandatory for authorised users and may impose storage, destruction and reporting conditions.
  • The current DJSIR edition of the VET collection guidelines was not reviewed. The VSN range was taken from the 2022 DET edition.
  • Issued-identifier counts and allocation schemes are unpublished. Collision probabilities are therefore given as formulas.
  • No HPI-I-specific data-location rule was identified. A full review of the HI Act, the regulations and any applicable HI Service terms is still needed.
  • The finding that the PDP Act imposes no statutory duty to notify individuals should be confirmed for Victorian public bodies.
  • The penalty-unit values, the final Children's Online Privacy Code text, and OAIC ADM guidance were not final or not checked at the cut-off.
  • AustLII section pages may lag the authorised compilations. Key HI Act findings were checked against legislation.gov.au compilation C2026C00415.

11. Sources (accessed 3 October 2026)

Legislation

Regulators, issuers and departments

On this page