Security Risk Management Group Pty Ltd has adopted the National Privacy Principles contained in the Privacy Amendment (Private Sector) Act 2000 ("the Act"), as a basis in which it collects, uses and disposes of personal information that comes into its possession.
Collection
Security Risk Management Group will only collect personal information that is needed for it to operate its business activities effectively. Security Risk Management Group will always endeavour to obtain personal information directly from the individual concerned. When this is impracticable or not reasonable, it will collect personal information fairly and by lawful means and without being unreasonably intrusive. In collecting personal information, Security Risk Management Group will take reasonable steps to ensure the individual knows:
- That it is Security Risk Management Group that is collecting the information; and
- Why the information is being collected; and
- Who will receive the information in normal circumstances; and
- Any legal requirements governing the information; and
- How they can access the information held on them by Security Risk Management Group; and
- What the consequences would be if the individual did not provide the information sought unless precluded from doing so under the provisions of the Act or by any other law.
Use and Disclosure
Security Risk Management Group will only use or disclose personal information for the purpose originally intended when the information was collected. It may also use or disclose personal information for a related purpose that would reasonably be expected by both the individual concerned and Security Risk Management Group. If Security Risk Management Group uses personal information it holds for direct marketing of its products or services, it will always provide the individual the opportunity at the point of first contact and at any time afterwards at the individuals request to decline receipt of any further marketing information. Otherwise, Security Risk Management Group will neither use nor disclose personal information without the person's consent, unless:
- Required for health or other emergency reasons; or
- To investigate suspected fraud or unlawful activity; or
- It is required or authorised by law; or
- It is required for law enforcement.
Data Quality
Security Risk Management Group will take reasonable steps to ensure that the personal information it uses is accurate, complete and up-to-date.
Security
Security Risk Management Group will take reasonable steps to protect all personal information in its possession, to ensure integrity of the information and that it is only accessed by on the express authority of Security Risk Management Group. Personal information that is no longer needed by Security Risk Management Group nor required to be held by law will be destroyed by secure means, or identifiers removed so the data cannot be traced back to the person to whom it relates.
Transparency
Security Risk Management Group will place this policy on its website. Printed copies of this policy will be made available on request at the registered office of Security Risk Management Group.
Access and Correction
In order to view personal information held by Security Risk Management Group, application may be made in writing to the:
Privacy Officer
Security Risk Management Group
PO Box 3291
Tamarama NSW 2026
Security Risk Management Group will take reasonable steps to confirm the identity of the person making the request and will respond within 14 days of receiving the request. However, where the request is more complex or time consuming to process, Security Risk Management Group will facilitate access to the requested information within 28 days.
Security Risk Management Group reserves the right to deny access to personal information if providing access:
- Could pose a possible threat to life or health; or
- Could cause an unreasonable impact on the privacy of others; or
- Would be in response to a frivolous or vexatious request; or
- Relates to existing or anticipated legal proceedings which could be prejudiced as a result; or
- Relates to existing or anticipated commercial negotiations involving Security Risk Management Group, and the legitimate commercial interests of Security Risk Management Group could be prejudiced as a result; or
- Is in any way unlawful; or
- Could in any way prejudice law enforcement or security; or
- Could prejudice the prevention, detection or investigation of seriously improper conduct, either within or external to Security Risk Management Group operations.
Security Risk Management Group reserves the right to give the individual an explanation for any decision made rather than direct access to the relevant information if giving access to personal information involves revealing evaluative information generated within Security Risk Management Group in connection with a commercially sensitive decision making process.
Where there is disagreement about direct access or where direct access to personal information is impractical or inappropriate, Security Risk Management Group will discuss the possible use of a mutually acceptable intermediary.
If an individual advises Security Risk Management Group that personal information held on them is inaccurate, incomplete or not up to date, Security Risk Management Group will take reasonable steps to update the information accordingly.
Security Risk Management Group reserves the right to levy a reasonable charge to meet the costs of providing access to personal information, although there will be no charge for the act of making the request for access. Security Risk Management Group will endeavour to provide reason(s) for denial of access to or correction of personal information it holds unless precluded from doing so by the provisions of the Act or any other law.
Sensitive Information
Security Risk Management Group will not, without the consent of the individual, collect information concerning that individual's racial or ethnic origins; political opinions; membership of a political, professional or trade association or trade union; philosophical or religious beliefs or affiliations; sexual preferences or practices or health information unless:
- It is required by law; or
- It will reduce a threat to life, injury to a third party or damage to property and it is not possible or practical to gain the individuals consent; or
- The collection is necessary in relation to a legal claim.