Industri is committed to maintaining the privacy and confidentiality of its personnel and student records. Industri complies with the Privacy Act 1988 (Cth) including the 13 Australian Privacy Principles (APPs) as outlined in the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth). Providing an overall framework for our privacy practices, Industri has developed and implemented this APP Privacy Policy. This policy is designed to maintain requirements with additional jurisdictional requirements including:
Industri manages personal information in an open and transparent way. This is evident in the implementation of practices, procedures and systems we outline in this policy, that ensure our compliance with the APPs and any binding registered APP code and provide suitable procedures for Industri personnel to be able to deal with related inquiries and complaints that may be received from time to time.
The following sections of this policy outline how we manage personal information.
Purposes for information collection, retention, use and disclosure Industri retains a record of personal information about all individuals with whom we undertake any form of business activity. Industri must collect, hold, use and disclose information from our clients and stakeholders for a range of purposes, including but not limited to:
Requirements of stakeholders As a government registered training organisation, regulated by the Australian Skills Quality Authority, Industri is required to collect, hold, use and disclose a wide range of personal and sensitive information on students in nationally recognised training programs. This information requirement is outlined in the National Vocational Education and Training Regulator Act 2011 and associated legislative instruments. In particular, the legislative instruments:
It is noted that Industri is also bound by various State Government Acts requiring similar information collection, use and disclosure (particularly Education Act(s), Vocational Education & Training Act(s) and Traineeship & Apprenticeships Act(s) relevant to state jurisdictions of Industri operations). It is further noted that, aligned with these legislative requirements, Industri delivers services through a range of Commonwealth and State Government funding contract agreement arrangements, which also include various information collection and disclosure requirements. Individuals are advised that due to these legal requirements, Industri discloses information held on individuals for valid purposes to a range of entities including:
Kinds of personal information collected and held The following types of personal information are generally collected, depending on the need for services delivery:
The following types of sensitive information may also be collected and held:
Where Industri collects personal information of more vulnerable segment of the community (such as children), additional practices and procedures are also followed. Please refer to Industri’s Working with Children Policy and Procedures for further information. How personal information is collected Industri’s usual approach to collecting personal information is to collect any required information directly from the individuals concerned. This may include the use of forms (such as registration forms, enrolment forms or services delivery records) and the use of web-based systems (such as online enquiry forms, web portals or internal operating systems). Industri does receive solicited and unsolicited information from Third Party sources in undertaking services delivery activities. This may include information from such entities as:
How personal information is held Industri’s usual approach to holding personal information always includes robust storage and security measures. Information on collection is:
Only authorised personnel are provided with login information to each system, with system access limited to only those relevant to their specific role. Industri ICT systems are hosted internally with robust internal security to physical server locations and server systems access. Virus protection, backup procedures and ongoing access monitoring procedures are in place. Destruction of paper-based records occurs as soon as practicable in every matter, using secure shredding and destruction services at all Industri sites. Individual information held across systems is linked through an Industri allocated identification number for each individual. Retention and Destruction of Information Industri maintains a Retention and Disposal Schedule documenting the periods for which personal information records are kept. Accessing and seeking correction of personal information Industri confirms all individuals have a right to request access to their personal information held and to request its correction at any time.
To request access to personal records, individuals are to make contact with:
Industri Privacy Officer
Mr Luke O’Sullivan
Chief Executive Officer
A number of third parties, other than the individual, may request access to an individual’s personal information. Such third parties may include employers, parents or guardians, schools, Australian Apprenticeships Network Providers, Governments (Commonwealth, State or Local) and various other stakeholders. In all cases where access is requested, Industri ensures that:
Complaints about a breach of the APPs or a binding registered APP code If an individual feels that Industri may have breached one of the APPs or a binding registered APP code, please refer to the Privacy Complaints Procedure below for further information on what actions may be taken. Likely overseas disclosures Industri confirms that individuals’ personal information is not disclosed to overseas recipients, for any purpose. Making our APP Privacy Policy available Industri provides our APP Privacy Policy available free of charge, with all information being publicly available from the Privacy link on our website at www.industrieducation.com/privacy This website information is designed to be accessible as per web publishing accessibility guidelines, to ensure access is available to individuals with special needs (such as individuals with a vision impairment). In addition, this APP Privacy Policy is:
If, in the unlikely event the APP Privacy Policy is not able to be provided in a particular format requested by an individual, we will explain the circumstances around this issue with the requester and seek to ensure that another appropriate method is provided. Review and Update of this APP Privacy Policy Industri reviews this APP Privacy Policy:
Where this policy is updated, changes to the policy are widely communicated to stakeholders through internal personnel communications, meetings, training and documentation, and externally through publishing of the policy on Industri’s website and other relevant documentation (such as our Student Handbook) for clients. Australian Privacy Principle 2 Anonymity and pseudonymity Industri provides individuals with the option of not identifying themselves, or of using a pseudonym, when dealing with us in relation to a particular matter, whenever practical. This includes providing options for anonymous dealings in cases of general course enquiries or other situations in which an individuals’ information is not required to complete a request. Individuals may deal with us by using a name, term or descriptor that is different to the individual’s actual name wherever possible. This includes using generic email addresses that does not contain an individual’s actual name, or generic usernames when individuals may access a public component of our website or enquiry forms. Industri only stores and links pseudonyms to individual personal information in cases where this is required for services delivery (such as system login information) or once the individual’s consent has been received. Individuals are advised of their opportunity to deal anonymously or by pseudonym with us where these options are possible. Requiring identification Industri must require and confirm identification however in services delivery to individuals for nationally recognised course programs. We are authorised by Australian law to deal only with individuals who have appropriately identified themselves. That is, we identify individuals and their specific individual needs on commencement of services delivery and collect and disclose Australian Vocational Education and Training Management of Information Statistical Standard (AVETMISS) data on all individuals enrolled in nationally recognised training programs. Other legal requirements, as noted earlier in this policy, also require considerable identification arrangements. There are also other occasions also within our services delivery where an individual may not have the option of dealing anonymously or by pseudonym, as identification is practically required for us to effectively support an individual’s request or need. Australian Privacy Principle 3 — Collection of solicited personal information Industri only collects personal information that is reasonably necessary for our business activities. We only collect sensitive information in cases where the individual consents to the sensitive information being collected, except in cases where we are required to collect this information by law, such as outlined earlier in this policy. All information we collect is collected only by lawful and fair means. We only collect solicited information directly from the individual concerned unless it is unreasonable or impracticable for the personal information to only be collected in this manner. Australian Privacy Principle 4 Dealing with unsolicited personal information Industri may from time to time receive unsolicited personal information. Where this occurs, we promptly review the information to decide whether we could have collected the information for the purpose of our business activities. Where this is the case, we may hold, use, and disclose the information appropriately as per the practices outlined in this policy. Where we could not have collected this information (by law or for a valid business purpose) we immediately destroy or de-identify the information (unless it would be unlawful to do so). Australian Privacy Principle 5 Notification of the collection of personal information Whenever Industri collects personal information about an individual, we take reasonable steps to notify the individual of the details of the information collection or otherwise ensure the individual is aware of those matters. This notification occurs at or before the time of collection, or as soon as practicable afterwards. Our notifications to individuals on data collection include:
Where possible, we ensure that the individual confirms their understanding of these details, such as through signed declarations, website form acceptance of details or in person through questioning. Collection from third parties Where Industri collects personal information from another organisation, we:
Australian Privacy Principle 6 Use or disclosure of personal information Industri only uses or discloses personal information it holds about an individual for the primary purposes for which the information was collected, or secondary purposes in cases where:
Requirement to make a written note of use or disclosure for this secondary purpose If Industri uses or discloses personal information in accordance with an ‘enforcement related activity’ we will make a written note of the use or disclosure, including the following details:
Australian Privacy Principle 7 Direct marketing Industri does not use or disclose the personal information that it holds about an individual for the purpose of direct marketing, unless:
On each of our direct marketing communications, Industri provides a prominent statement that the individual may request to opt out of future communications, and how to do so. An individual may also request us at any stage not to use or disclose their personal information for the purpose of direct marketing, or to facilitate direct marketing by other organisations. We comply with any request by an individual promptly and undertake any required actions for free. We also, on request, notify an individual of our source of their personal information used or disclosed for the purpose of direct marketing unless it is unreasonable or impracticable to do so. Australian Privacy Principle 8 Cross-border disclosure of personal information Before Industri discloses personal information about an individual to any overseas recipient, we take reasonable steps to ensure that Industri does not breach any privacy matters in relation to that information. Australian Privacy Principle 9 Adoption, use or disclosure of government related identifiers Industri does not adopt, use or disclose a government related identifier related to an individual except:
Australian Privacy Principle 10 Quality of personal information Industri takes reasonable steps to ensure that the personal information it collects is accurate, up-to-date and complete. We also take reasonable steps to ensure that the personal information we use or disclose is, having regard to the purpose of the use or disclosure, accurate, up-to-date, complete and relevant. This is particularly important:
We take steps to ensure personal information is factually correct. In cases of an opinion, we ensure information considers competing facts and views and makes an informed assessment, providing it is clear this is an opinion. Information is confirmed up to date at the point in time to which the personal information relates. Quality measures in place supporting these requirements include:
Australian Privacy Principle 11 — Security of personal information Industri takes active measures to consider whether we can retain personal information we hold, and also to ensure the security of personal information we hold. This includes reasonable steps to protect the information from misuse, interference and loss, as well as unauthorised access, modification or disclosure. We destroy or de-identify personal information held once the information is no longer needed for any purpose for which the information may be legally used or disclosed. Access to Industri offices and work areas is limited to our personnel only visitors to our premises must be authorised by relevant personnel and are always accompanied. About any information in a paper-based form, we maintain storage of records in an appropriately secure place to which only authorised individuals have access. Regular personnel training and information bulletins are conducted with Industri personnel on privacy issues, and how the APPs apply to our practices, procedures and systems. Training is also included in our personnel induction practices. We conduct ongoing internal audits (at least annually and as needed) of the adequacy and currency of security and access practices, procedures and systems implemented. Australian Privacy Principle 12 — Access to personal information Where Industri holds personal information about an individual, we provide that individual access to the information on their request. In processing requests, we:
In cases where we refuse to update personal information, we:
Correcting at Industri’s initiative We take reasonable steps to correct personal information we hold in cases where we are satisfied that the personal information held is inaccurate, out-of-date, incomplete, irrelevant or misleading (that is, the information is faulty). This awareness may occur through collection of updated information, in notification from third parties or through other means.
Individuals or third parties may at any stage request access to records held by Industri relating to their personal information. The following procedure is followed on each individual request for access:
Confirming identity
Industri personnel must be satisfied that a request for personal information is made by the individual concerned, or by another person who is authorised to make a request on their behalf. The minimum amount of personal information needed to establish an individual’s identity is sought, which is generally an individual’s name, date of birth, last known address and signature.
When meeting the requesting party in person, identification may be sighted.
If confirming details over a telephone conversation, questions regarding the individual’s name, date of birth, last known address or service details must be confirmed before information is provided.
Once identity and access authorisation is confirmed, and personal information is collated, access is provided to the requester within 30 calendar days of receipt of the original request. We will provide access to personal information in the specific manner or format requested by the individual, wherever it is reasonable and practicable to do so, free of charge.
Where the requested format is not practical, we consult with the requester to ensure a format is provided that meets the requester’s needs.
Individuals or third parties may at any stage request that their records held by Industri relating to their personal information be updated. The following procedure is followed on each individual request for records updates:
This request may be in any form, or preferably using Industri’s Records Access or Update Request Form.
Assessing Update
Industri personnel assess the relevant personal information we hold, and the requested updated information, to determine which version of the information is considered accurate, up-to-date, complete, relevant and not misleading, having regard to the purpose for which it is held.
This may include checking information against other records held by us, or within government databases, in order to complete an assessment of the correct version of the information to be used.
Once identity and information assessment is confirmed, personal information is:
Our notification will include the reasons for the refusal and the complaint mechanisms available to the individual:
If an individual feels that Industri has breached its obligations in the handling, use or disclosure of their personal information, they may raise a complaint. We encourage individuals to discuss the situation with their Industri representative in the first instance, before making a complaint. The complaints handling process is as follows: The individual should make the complaint including as much detail about the issue as possible, in writing to Industri:
Industri Privacy Officer
Mr Luke O’Sullivan
Chief Executive Officer
Office of the Australian Information Commissioner
www.oaic.gov.au
Phone: 1300 363 992
When investigating a complaint, the OAIC will initially attempt to conciliate the complaint, before considering the exercise of other complaint resolution powers.
Feel free to drop us a line with any question, query or quandary.
We can offer obligation free advice on what is the right choice for you.