Non-Disclosure and Acceptable Use Agreement
Who signs the district's Non-Disclosure and Acceptable Use Agreement, what each access type covers, how to sign it online, and where signed copies are kept.
On this page
What the Agreement is
The Non-Disclosure and Acceptable Use Agreement is signed by anyone given administrative access to the district's Microsoft 365 environment, or access to sensitive information within it, before that access begins.
It is an agreement between two parties: you, and Rotary International District 9660 Incorporated (ABN 47 258 228 592). It records the trust that comes with your access: that you will keep the district's information confidential, only look at what your role needs, protect the accounts and devices you use, and report anything that goes wrong.
It is the district's counterpart to the protections described on the Security, Auditing, and Confidentiality page. That page explains how the system protects your data; this Agreement is how the people with access commit to doing their part.
A policy is adopted by the Board and sets a standard. This Agreement is signed by you as an individual and binds you personally, which is what makes it the right instrument for volunteers and external contractors receiving access.
The Child Safe Code of Conduct is signed per youth event and is about behaviour around young people. This Agreement is about handling the district's information and systems, and is signed when you take on access.
Who has to sign it
You sign the Agreement if you are given any of the access types listed below. In practice that means:
- Microsoft 365 administrators. Anyone holding Global Administrator or a service-administrator role.
- Office holders with district-wide access. The District Governor, District Governor Elect, and District Governor Nominee.
- Committee chairs and members who reach their committee's mailbox, SharePoint site, or the membership and program data their committee handles.
- Anyone using the compliance lookup portal for WWCC and RYVID clearance checks.
- External contractors and providers engaged to build, host, maintain, audit, or support any part of the environment.
If you only use a standard member account (your own mailbox, calendar, and OneDrive), you do not need to sign it.
The access types
The Agreement lists seven access types, from broadest to narrowest. You tick the one or ones that apply to you. The specific systems, sites, and data you are actually granted are recorded against you in the district's access register, not on the signed form, so your access can change without you having to sign a new Agreement.
| Access type | What it covers |
|---|---|
| Global Admin | Full administrative control of the entire Microsoft 365 tenant: all accounts, every mailbox and SharePoint site, Teams, security and audit logs, and tenant configuration. |
| District Governor | Their role mailbox (districtgovernor@rotary9660.org.au), plus district-wide access for the current Rotary year: all shared, role, and committee mailboxes (not members' personal mailboxes), all committee sites and Teams, the member analytics dashboard, DACdb, Board and governance records, and the Youth Protection Compliance Register in full detail. |
| District Governor Elect (DGE) | Their role mailbox (districtgovernorelect@rotary9660.org.au), governance and committee sites relevant to planning, DACdb, and district planning materials. |
| District Governor Nominee (DGN) | Their role mailbox (districtgovernornominee@rotary9660.org.au), DACdb, and the planning and committee sites relevant to their preparation. |
| District Committee Chair | Their own committee only: its SharePoint site (as owner), its shared or role mailbox, its Teams, and the membership and program data the committee handles. |
| District Committee Member | Their own committee's SharePoint site and Teams, with no administrative rights. |
| Compliance Portal Only | The compliance lookup portal alone (clearance type, status, and expiry). No mailbox, no SharePoint, no OneDrive, no other system access. |
When you sign, and when you sign again
- Before access starts. You sign before administrative or sensitive-data access is granted, or as soon as practical if a role changes mid-year.
- When your role changes. If you take on a new role carrying broader access, you sign again for that role.
- You do not need to re-sign every year simply to keep the same access, but the IT team may ask you to re-acknowledge it during periodic access reviews.
- When your access ends, including at the 1 July changeover, your confidentiality obligations continue for as long as the information remains confidential.
What you are committing to
- Protect information about children and young people. This carries the highest priority in the Agreement. Do not access records about young people, including WWCC and RYVID data, unless your role genuinely requires it.
- Keep it confidential. Do not disclose district information that is not public, unless you are authorised or the law requires it.
- Only look at what you need. Holding access does not entitle you to browse. You access only what your current task requires.
- Leave restricted material alone. Do not open, forward, or store material intended for someone else, even where your access would technically allow it. If you encounter it by accident, stop reading and report it.
- Protect your access. Never share credentials, keep multi-factor authentication on, use a dedicated admin account for admin work, and keep your devices secure.
- Report problems fast. Tell the IT team straight away about any suspected breach, lost device, or compromised account. Honest, prompt reporting is always treated more favourably than concealment.
- Hand it back. When your role ends, return or delete district information and cooperate with removing your access.
The safety and best interests of a young person come before confidentiality. If you have a reasonable suspicion that a young person is at risk of harm, report it in accordance with the District Youth Protection Policy and the law.
How to sign
You sign the Agreement online. There is no paper form and nothing to print or post.
flowchart TD
A["You are offered a role with
administrative or
sensitive-data access"] --> B["You open the online form at
support.rotary9660.org.au/nda"]
B --> C["You read the full Agreement
and tick the access types
that apply to you"]
C --> D["You acknowledge it and
draw or upload your signature"]
D --> E["You submit. A signed PDF is
emailed to you and filed
in the access register"]
E --> F["IT provisions your access
and records what was granted"]
Working through it:
- Your details. Your full name, Rotary club or committee, district role, and email address.
- Read the Agreement. The full text is shown in a scrolling panel. You must scroll to the end before you can acknowledge it. This is deliberate: you are confirming you have actually read it.
- Tick your access type or types. At least one is required. If you are unsure which applies, ask before you sign rather than guessing.
- Acknowledge. Tick the box confirming you have read and understood the Agreement and agree to be bound by it.
- Sign. Draw your signature with a mouse, finger, or stylus, or upload an image of it.
- Submit.
You consent to signing by electronic means, and a signature you draw or upload through the form satisfies any requirement for your signature, in accordance with the Electronic Transactions Act 1999 (Cth) and the Electronic Transactions Act 2000 (NSW).
What happens after you submit
- A signed PDF containing the full Agreement text, your ticked access types, and your signature is generated. The signed copy is self-contained, so it evidences exactly what you agreed to.
- That PDF is emailed to you and to the district.
- It is filed with the district's access records and logged in the access register.
- Your access is then provisioned separately. Signing does not by itself switch anything on.
Alongside your signature, the district records the submission time, the IP address, and the browser used, as an audit record of your signing.
Where signed copies are kept
Signed Agreements and the access register are held on the District Board SharePoint site. The register records who signed, which access types they recorded, what was actually granted to them, and whether that access has since been revoked.
It is kept with the Board because it is a governance record of who has been trusted with district data, rather than an operational record of the team that administers the systems.
Email support@rotary9660.org.au. If anything in the Agreement is unclear, ask before you sign.