Guide to Giving
MEDIA, JOBS & RESOURCES FOR THE COMMON GOOD
NEWS  | 

Ten Steps to Protect Other People’s Personal Information – Privacy Commission


Tuesday, 1st May 2012 at 10:51 am
Lina Caneva, Editor
The Australian Privacy Commissioner has released a 10 point guide to help Not for Profits protect other people’s personal information as part of Privacy Week 2012.

Tuesday, 1st May 2012
at 10:51 am
Lina Caneva, Editor


0 Comments


FREE SOCIAL
SECTOR NEWS

 Print
Ten Steps to Protect Other People’s Personal Information – Privacy Commission
Tuesday, 1st May 2012 at 10:51 am

The Australian Privacy Commissioner has released a 10 point guide to help Not for Profits protect other people’s personal information as part of Privacy Week 2012.

Personal information means information that identifies or could reasonably identify an individual.

The Privacy Commissioner, Tim Pilgrim says there are some obvious examples of personal information, such as a person's name and address. Personal information can also include medical records, bank account details, photos, videos, and even information about what an individual likes, their opinions and where they work.

The 10 step guide gives a snapshot of some of the:

  • privacy rights for individuals, and

  • obligations that organisations and Australian, ACT and Norfolk Island Government agencies have under the Privacy Act.

1. Only collect information you need

Make sure individuals know what personal information your organisation or agency collects and why. Also ensure that:

  • each piece of information is necessary for any of the functions or activities of the organisation or agency, and

  • the information is required in the circumstances.

Sometimes, activities can be carried out without collecting personal information. This allows individuals to interact anonymously with your organisation or agency.

2. Don't collect personal information about an individual just because you think that information may come in handy later

Only collect information that is necessary at the time of collection, not because it may become necessary or useful at a later date. If you need it later, collect the information then.

3. Tell people how you are going to handle the personal information you collect about them

Have a publicly available policy that tells people how you handle personal information.
Also, when you collect personal information, always let people know why you need to collect the information, how you plan to use it, who you are going to give it to. Make sure they know your contact details and, if they want to, how they can get access to their personal information.

4. Think about using personal information for a particular purpose

Generally, organisations should not use personal information for a secondary purpose unrelated to the main purpose for which they collected the information.\

Unless your organisation has consent from the individual concerned or authorisation under law, it should generally only use personal information if it is:

  • related to the purpose your organisation collected it for, and

  • within the reasonable expectations of the individual.

Similarly, agencies must:

  • only use personal information for a relevant purpose, and

  • take reasonable steps to ensure that personal information is accurate, up to date and complete before using it.

The OAIC website has more information on the obligations organisations and agencies have under the Privacy Act.

5. Think before disclosing personal information

The Privacy Act allows organisations and agencies to disclose personal information in some circumstances.
Sometimes, organisations and agencies disclose personal information when they don't need to, or without considering whether the disclosure is authorised under the Privacy Act.

Always think about whether a purpose can be achieved without disclosing personal information.
Good practice: Get consent from the individual if you want to disclose their personal information for a reason that is different from the reason you collected it.

6. If people ask, give them access to the personal information you hold about them

Organisations and agencies have a general duty to give individuals access to their personal information. Here are some things to consider:

  • Be as open as possible by giving individuals access to their personal information in the form they request.

  • If you deny access to personal information, give the reason — consistent with the Privacy Act — to the individual as soon as you can.

  • An individual also has an alternative path when seeking information from an agency. If an individual seeks access under the Freedom of Information Act 1982 ((Cth)) (FOI Act), the agency is obliged to consider the request under the FOI Act rather than the Privacy Act. Access under the FOI Act may be subject to specific exemptions. This alternative applies only to agencies, not organisations.

7. Keep personal information secure

It is important that you keep personal information safe and secure from unauthorised access, modification or disclosure and also against misuse and loss.
How you do this depends on the sensitivity of the information you hold, and the circumstances of your organisation or agency.
Methods could include:

  • considering the adequacy of existing security measures and procedures, including whether any relevant standards are met

  • training staff in privacy procedures

  • ensuring adequate IT security, such as installing firewalls, cookie removers and anti-virus scanners on work IT systems

  • checking that all personal information has been removed from electronic devices before you sell or destroy them

  • keeping hard copy files in properly secured cabinets

  • allowing staff to access personal information on a ‘need to know' basis only

  • regularly monitoring your information handling practices to ensure they are secure.

Depending on the size of your organisation and the information it collects, it may be prudent to have an external privacy audit done.

8. Don't keep information you no longer need or that you no longer have to retain

If you no longer need personal information and there is no law that says you have to retain the information, then destroy it.

  • Shred, pulp or destroy the personal information paper records.

  • Dispose of files in security bins.

  • Delete electronic records or files securely so that they can't be retrieved.

9. Keep personal information accurate and up to date

The accuracy and currency of personal information you hold can change. Your organisation or agency needs to take reasonable steps to keep the personal information it holds current. Amend your records to reflect changes and make sure both hard copy and electronic files are updated.
If you know that some personal information is likely to change regularly, go through the files periodically to ensure that your records are accurate and up to date.

10. Consider making someone in your organisation or agency responsible for privacy

This could be a designated person (often called a Privacy Contact Officer or Chief Privacy Officer) who:

  • knows your organisation or agency's responsibilities under the Privacy Act, and

  • is willing and able to handle complaints and enquiries about the personal information handling practices of your organisation or agency.This person could also be responsible for implementing a complaint handling process, staff training programs and promoting Privacy Act compliance.

The OAIC website has more information for organisations and agencies. Call the Enquiries Line on 1300 363 992.


Lina Caneva  |  Editor |  @ProBonoNews

Lina Caneva has been a journalist for more than 35 years, and Editor of Pro Bono Australia News since it was founded in 2000.

Guide to Giving

FEATURED SUPPLIERS


Yes we’re lawyers, but we do a lot more....

Moores

Helping the helpers fund their mission…...

FrontStream Pty Ltd (FrontStream AsiaPacific)

Brennan IT helps not-for-profit (NFP) organisations drive gr...

Brennan IT

HLB Mann Judd is a specialist Accounting and Advisory firm t...

HLB Mann Judd

More Suppliers

Get more stories like this

FREE SOCIAL
SECTOR NEWS

YOU MAY ALSO LIKE

Susan Pascoe Appointed Head of Newly Formed Community Directors Council

Luke Michael

Friday, 22nd September 2017 at 5:21 pm

Recruitment Expert Says NFPs Need Thorough Process to Hire Honest Candidates

Luke Michael

Friday, 22nd September 2017 at 4:50 pm

Thinkers Look to Melbourne to Grow SA Purpose Economy

Wendy Williams

Thursday, 21st September 2017 at 4:44 pm

Mental Health Groups Call for Same-Sex Marriage to Prevent Suicide

Luke Michael

Thursday, 21st September 2017 at 4:24 pm

POPULAR

Moves to Stop Volunteering at Overseas Orphanages

Luke Michael

Wednesday, 13th September 2017 at 1:54 pm

Future Uncertain for Disability Organisations Following Funding Cuts

Wendy Williams

Tuesday, 19th September 2017 at 8:29 am

Majority of NFPs Are Not Believed to be Well-Run, According to New Survey

Luke Michael

Tuesday, 12th September 2017 at 4:14 pm

More Australians Are Giving Time Not Money

Wendy Williams

Monday, 11th September 2017 at 5:07 pm

Write a Reply or Comment

Your email address will not be published. Required fields are marked *


Guide to Giving
pba inverse logo
Subscribe Twitter Facebook

The social sector's most essential news coverage. Delivered free to your inbox every Tuesday and Thursday morning.

You have Successfully Subscribed!