|
OzChild is committed to protecting the privacy of our clients, supporters, volunteers and staff by protecting the privacy of personal information that we handle. Personal information is information that directly or indirectly identifies a person.
We collect and handle a range of personal information for the purposes of carrying out our services and recognise that much of the information that we handle is particularly sensitive.
OzChild supports and is bound by the Information Privacy Act 2000 and the Health Records Act of 2001.
To demonstrate our commitment to protecting the information we hold about individuals, we have adopted a set of principles that comply with the aforementioned legislation.
In broad terms this means that we:
- collect only information which we need for a specified primary purpose;
- ensure that the person knows why we collect it and how we will handle it;
- use and disclose it only for the primary or a directly related purpose, or for another purpose with the person's consent (unless otherwise authorised by law);
- store it securely, protecting it from unauthorised access;
- retain it for the period authorised by the Public Records Act 1973;
- provide the person with access to their own information, and the right to seek its correction.
A summary of our Privacy Principles is as follows:
- Collection – we only collect information necessary for the performance of a function or activity and with consent;
- Use and Disclosure – we only use and disclose information for the primary purpose for which it was collected or a directly related secondary purpose the person would otherwise expect;
- Data Quality – we make sure personal information is accurate, complete and up-to-date;
- Data Security – we take reasonable steps to protect personal information from misuse, loss, unauthorised access, modification and disclosure;
- Retention and disposal - we retain files in accordance with the Public Records Act and ensure they are kept secure;
- Openness – we document clear policies on management of personal information and communicate our policies to those who need to know;
- Access and Correction – individuals have the right to seek access to their personal information and make corrections;
- Unique Identifiers – we assign numbers to identify persons if necessary to carry out our functions effectively – however we take steps to ensure that data matching cannot occur;
- Anonymity – where possible we give individuals the opportunity to not identify themselves;
- Trans-border data flows – if required, personal information will be transferred interstate if that state has the same level of privacy protection;
- Sensitive information - we are restricted from collecting sensitive information such as racial or ethnic origin, political views, religious beliefs, sexual preferences etc. for collection purposes only;
- Transfer or closure of health service provider – if (as a health services provider) we close or transfer our operations, we must notify all past service users.
Our Privacy Principles
We will only collect information if it is relevant and necessary to the function/activity of OzChild. The information will be collected by lawful and fair means and not in an unreasonable, intrusive way.
Where reasonable and practicable, OzChild will collect personal information about an individual directly from that individual. However, if we need to collect information from a third party we will take reasonable steps to ensure that the individual concerned is made aware of the collection, except to the extent that making the individual aware may pose a serious threat to the life or health of any individual.
When collecting the personal information from the individual, or as soon as practicable after, OzChild will take the necessary steps to ensure that the individual is aware:
- that the information has been collected
- of the fact that the individual can obtain access to the information
- of the purpose for which it was collected
- to whom (or what organisation) OzChild may disclose the information to
- of any law that requires the information to be collected
- of the consequences for the individual if the information is not provided.
|