1.1 From time to time Creating Students ("the Company") is required to collect, use and disclose personal information relating to its customers, contractors, suppliers and employees in the performance of its business activities.
1.2 This policy sets out guidelines to assist the Company and its employees to comply with the requirements of the Privacy Act 1998 (Cth) (“Privacy Act”) and the National Privacy Principles (“NPP”) in relation to the collection, storage, use and disclosure of records containing individuals’ Personal Information.
2.1 This policy applies to the collection, storage, use and disclosure by the Company (or a person acting on behalf of the Company) of records containing individuals' Personal Information in Australia.
2.2 This policy does not apply to the collection, storage, use and disclosure of Personal Information where:
(a) The Personal Information is an employee record; and
(b) The collection, storage, use and/or disclosure of the employee record relates to the Company's employment relationship with the employee; and
(c) The information is accessed by a third party provider in the course of systems maintenance, such as an upgrade of the company’s payroll software, or financial management system.
3.1 Employee Record means a record of Personal Information relating to the employment of a Company employee.
3.2 Personal Information means information or an opinion (including information or an opinion forming part of a database), whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion.
3.3 Sensitive Information has the meaning set out in the Privacy Act.
4. Collection of personal information
4.1 The Company is entitled to collect Personal Information by lawful and fair means. Personal Information must not be collected in an unreasonably intrusive way.
4.2 A person who collects Personal Information on behalf of the Company must comply with this Policy and the requirements of the Privacy Act.
5. Use and disclosure of personal information
5.1 The Company, or its employees, will not use or disclose personal information about an individual for a purpose (the secondary purpose) other than the primary purpose of collection unless;
(a) Both of the following apply:* The secondary purpose is related to the primary purpose of collection and, if the personal information is Sensitive Information, directly related to the primary purpose of collection; and
* The individual would reasonably expect the Company to use or disclose the information for the secondary purpose; or
(b) The individual has consented to the use or disclosure; or
(c) The Company has reason to suspect that unlawful activity has been, is being or may be engaged in, and uses or discloses the Personal Information as a necessary part of its investigation of the matter or in reporting its concerns to relevant persons or authorities; or
(d) The use or disclosure is required or authorised by or under law; or
(e) The use or disclosure is not inconsistent with the requirements of the Privacy Act.
6. Data quality
6.1 The Company will take reasonable steps to make sure that the Personal Information it collects uses or discloses is accurate, complete and up-to-date.
7. Data security
7.1 The Company will take reasonable steps to protect the Personal Information it holds from misuse and loss and from unauthorised access, modification or disclosure.
7.2 The Company will take reasonable steps to destroy or permanently de-identify Personal Information (such as a job applicant's resume or a past Student) if it is no longer needed.
8.2 On request by a person, the Company will take reasonable steps to let the person know, generally, what sort of Personal Information it holds, for what purposes, and how it collects, holds, uses and discloses that information.
9. Access and correction
9.1 If the Company holds Personal Information about an individual, it will comply with legislative obligations to provide the individual with access to the information on request by the individual.
9.2 If the Company holds Personal Information about an individual and the individual is able to establish the information is not accurate, complete and up-to-date, the Company will take reasonable steps to correct the information so that it is accurate, complete and up-to-date.
9.3 The Company will provide reasons for denial of access or a refusal to correct Personal Information.
10.1 The Company has implemented generally accepted standards of technology and operational security in order to protect Personal Information from loss, misuse, alteration or destruction.