Organisational Policy

Ozcare ABN: 58 072 422 92 (referred to in this document as “we“, “us” or “our“) recognises that privacy is very important and we are committed to protecting the personal information we collect from our employees and from our clients (referred to in this document as “you“, or “your“). The Privacy Act 1988 (Cth) (Privacy Act), and the Australian Privacy Principles (APPs) govern the way in which we must manage your personal information and this policy sets out how we collect, use, disclose and otherwise manage personal information.

This policy appears on our website at www.ozcare.org.au, and copies of this policy will be made available free of charge to any person who requests it

By visiting our website, using any of our services or otherwise providing us with your personal information (or authorising it to be provided to us by someone else), you consent to your personal information being handled by us as set out in this policy. You understand that your consent will be ongoing for the duration of your association with us. Your consent can be revoked at any time by giving written notice to Ozcare. If you withdraw your consent, you may not be eligible for the services provided to you, by Ozcare.

What is personal information?

Personal information is defined in the Privacy Act to mean information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether the information or opinion is recorded in a material form or not.

Personal information can include sensitive information.  Sensitive information is defined in the Privacy Act as information or an opinion about a person’s race, ethnic origin, political opinions, membership of political associations and trade associations, religious or philosophical beliefs, sexual orientation or practices, criminal record, health information, genetic information about an individual that is not otherwise health information, biometric information that is used for the purpose of automated biometric verification or biometric identification and biometric templates.

Personal information can also include credit information.

Purpose of collection of personal information

The personal information that we collect and hold about you, depends on your interaction with us, either as an employee or as a client. We will take such steps as are reasonable in the circumstances, to ensure that the personal information that we collect is accurate, up‑to‑date and complete.

Generally, we will collect, use and hold your personal information (including sensitive information) for the purposes of:

  1. facilitating our internal business operations, including the fulfilment of any legal requirements;
  2. operating and facilitating your use of our website;
  3. identification and assessment of required services;
  4. providing services to you or someone else that you know;
  5. providing you with information about services that we, or our related entities and other organisations that we have affiliations with, offer (if you consent to receiving these);
  6. responding to your requests and enquiries;
  7. analysing our services and customer needs with a view to developing new or improved services;
  8. collecting money either directly by us or through an authorised payment gateway facility;
  9. security and occupational health and safety;
  10. investigating or reporting suspected unlawful activity;
  11. protecting someone’s life, health, safety or welfare; and
  12. complying with a law or regulation, or a court order or other legal process, including the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).

Types of personal information collected and recorded

Ozcare collects and holds personal information about employees and clients, including but not limited to:

  • your full name and contact details, such as email address postal address and telephone number;
  • your date of birth, age and gender;
  • your photograph;
  • your passport/driver’s licence number;
  • your job title or position;
  • your bank details;
  • your communication preferences;
  • technical and behavioural information about your activity associated with our website and services;
  • information about the IP address and device that you use to access our website;
  • CCTV images recorded at our premises;
  • marketing and relationship information, including preferences for communications, newsletter subscriptions and consent records;
  • information provided when you correspond with us; and
  • updates to information you have already provided to us.

Additionally, if you are a client, unless otherwise permitted by law, only with your consent we may also collect, store and use sensitive information that is relevant to assessing you for, or providing you with, agreed Services. Sensitive information that we collect, store and use may include, information about your:

  • physical, physiological and mental health;
  • sexual orientation;
  • medical records and history and other health information, including, but not limited to, past and present diseases, allergies, previous treatments, diagnostic reports, prescriptions and medication history;
  • biometric information;
  • racial or ethnic origin;
  • religion; and
  • (only where it is directly relevant to the service being provided or your employment) criminal record.

Method of collection of personal information

Ozcare collects personal information from:

  • individuals directly;
  • health care professionals and service providers in the course of them providing health services to clients and residents;
  • our suppliers, contractors and related entities;
  • third parties;
  • CCTV cameras located at our premises; and
  • public records and other publicly available sources.

We generally collect your personal information directly from you through the use of any of our standard forms, in person during a consultation, over the internet, via email, or telephone conversation. There may, however, be some instances where we collect your personal information from someone else, such as a supplier, contractor, related entity or third party, because it is unreasonable or impractical to collect it directly from you (for example, where one of our clients has obtained services from you on your behalf). In such a case, we will take reasonable steps to notify you of this in advance, or where this is not practicable, as soon as reasonably practicable after your personal information has been collected.

If you provide us with sensitive information about other individuals, such as health information, please ensure that the individual or the individual’s representative is aware of the disclosure and that he or she consents to the disclosure to us as well as to the handling of their personal information in accordance with this policy.  Otherwise you must not provide us with any sensitive information about other individuals.

Internet users

If you access our website, we may collect additional personal information about you in the form of an IP address and domain name. If you do not want information to be collected through the use of cookies or traffic measurement software, your device and/or browser may enable you to delete or “turn off” cookies or some the measurement software features.  However, some or all parts of our website may not function correctly if such features are disabled.

In addition, our website may contain links to other websites. We are not responsible for the privacy practices of linked websites and linked websites are not subject to our privacy policies and procedures.

Use and disclosure of personal information

Generally, we only use or disclose personal information about you for the purposes for which it was collected. We will take such steps as are reasonable in the circumstances to ensure that the personal information that we use or disclose is, having regard to the purpose of the use or disclosure, accurate, up‑to‑date, complete and relevant.

We may disclose personal information about you, to:

  • other service providers who assist us in delivering services to our clients;
  • our related entities and other organisations with whom we have affiliations so that those organisations may provide you with information about services and various promotions (if you consent to receiving these);
  • your nominated next of kin in an emergency involving you;
  • (in the case of a transfer to hospital or other care) any medical practitioner, hospital, or service provider involved in the provision of care;
  • your nominated family / carer;
  • Government entities as part of summaries of service provision data (personal and identifying information may be provided, where this is specifically required to identify eligibility for funding or to inform future service planning);
  • law enforcement officers, regulators, courts and government agencies, if permitted or required: by law, regulation, court order or other legal process; to assist in the prevention or detection of crime; or to prevent a threat to any person’s life, health or safety;
  • relevant Government Departments e.g. Queensland Police (as required by law) where we have a concern regarding significant harm or risk of significant harm to yourself, or somebody else, including children;
  • emergency services personnel (Police, Fire, Ambulance), where required;
  • insurers and legal entities;
  • third party service providers;
  • technology vendors;
  • our professional advisers (e.g. lawyers and accountants);
  • any purchaser or prospective purchaser of our business, including in the case of bankruptcy, a merger, acquisition, reorganisation, sale of assets or assignments, or due diligence in respect of any such transactions.

We do not disclose personal information to overseas recipients.

Marketing and advertising

We will never use or disclose any sensitive information for direct marketing purposes.

We may use and disclose your personal information (other than sensitive information) to provide you with information about products or services offered by us or other parties.  To the extent we use your personal information for direct marketing purposes, we will provide you with the ability to opt-out of such uses, if you do not wish to receive such communications.  To opt-out of being on such call, SMS, e-mail and/or other communication lists, you may e-mail us at PrivacyAndLegalRequests@ozcare.org.au and we will ensure you do not receive such communications in the future.

CCTV

Ozcare may record CCTV images both inside and outside its premises in Queensland. 

Any individuals moving through the relevant areas, including Ozcare employees, contractors and visitors to the premises, may be recorded.  Without limitation, CCTV cameras may record individuals performing both work tasks and personal activities.  However CCTV cameras will not be used in any toilets, washrooms, change rooms or lactation rooms.

CCTV cameras will be housed in domes or cases which will be clearly apparent, and will not be unduly concealed.

CCTV cameras are used by Ozcare:

  • to enhance personal safety of employees, clients and residents;
  • for security purposes, including to protect Ozcare’s premises from break-ins and to protect Ozcare’s property from theft or damage, by deterring potential offenders;
  • for occupational health and safety purposes, including to deter unsafe work practices and to provide a record of accidents or other non-crime related incidents;
  • to investigate or report suspected unlawful activity or occupational health and safety incidents;
  • to obtain and provide evidence in actual or potential criminal and/or civil proceedings; and
  • to identify witnesses.

Recorded CCTV footage will be stored in a secured IT room, and will only be reviewed by a member of Ozcare’s senior management team when an incident is suspected or takes place.  Footage of criminal activity may be provided to other members of Ozcare’s senior management and the police.  Footage of personal safety incidents, including occupational health and safety incidents, may be provided to other members of Ozcare’s senior management team and Ozcare’s occupational health and safety committee.

Recorded CCTV footage will only be kept for the purposes disclosed in this policy, and will not be kept any longer than is necessary for those purposes.  Recorded material that is no longer required will be disposed of, or deleted, in a secure manner.

Data integrity

We may combine the information you give to us and information we automatically collect about you to maintain and improve the accuracy of the records we hold about you.  We may also use the combined information about you to form a view on what products we think you, or others similar to you, may want or need to target our marketing closer to your interests.

We endeavour to ensure that all personal information that we hold is accurate, complete and up-to-date.  To assist us with this, individuals should contact us if any of their personal information changes, or if they believe that the personal information that we have is not accurate or complete.

When personal information that we collect is no longer required by us, we will destroy or de-identify that personal information unless we are required by a law or a court/tribunal to retain the personal information.

We may retain personal information for so long as it is required for any of our business purposes, for the prevention of fraud, for insurance and governance purposes, for the purposes of complying with any relevant regulations or laws (including the AML/CTF Act) and in our IT back up.

Security

We store personal information in different ways, including in paper and in electronic form. The security of your personal information is important to us. We take reasonable steps (including technical and organisational measures) to ensure that your personal information is stored safely and to protect it from misuse, interference, loss, unauthorised access, modification or disclosure, including:

  • electronic and physical security measures;
  • maintaining strict access controls and endpoint security;
  • ensuring that staff access is role-based and monitored, and our IT staff oversee our Information Security Management System (ISMS);
  • ensuring that staff undergo privacy training; and
  • ensuring that we review threats and incidents, and implement policy updates.

Also, if we provide you with in-home care, we may leave a record of treatment with Ozcare, which includes personal information, at your home. In this circumstance, we require that you acknowledge that you will keep the record safe and secure and that you will inform us if any event or threatened event jeopardises the safety and security of this record.

While we take reasonable steps to protect the personal information that we hold from misuse, loss, unauthorised access, modification or disclosure, you should be aware that no system is completely secure against cyber attack.

In addition, the open nature of the internet is such that information exchanged via the internet may be accessed and used by people other than those for whom the data is intended.  Any information sent via the internet is sent at the sender’s risk.

You should contact us immediately if you believe that there has been unauthorised access or disclosure with respect to any personal information that we hold about you.

Government-related identifiers

We do not use any government related identifiers, such as Medicare, driver’s licence or passport numbers, as our own internal identifier of any individual.  We will not use or disclose any government related identifiers other than in accordance with the Privacy Act.

De-identified data

You consent to us using and disclosing your de-identified data (information that no longer identifies you) for any purpose, including, without limitation, statistical analysis, product or service development, marketing and business planning or any other commercial purpose.  We undertake technical measures to ensure that this data cannot be associated back to you.

Automated decision-making systems

We may process your personal information using semi- or fully- automated decision-making systems, being any computer program or artificial intelligence to make, or do something that is substantially and directly related to making a decision that could significantly affect the rights or interests of an individual. We have set out some examples below:

  • PainChek, for diagnosis of possible pain in non verbal clients

Access to & correction of information

You are entitled to have access to and seek correction of any personal information that we may hold about you, subject to the grounds for refusal under the Privacy Act.  We prefer that requests for access to, or to update or correct, your information be in writing outlining the details of your request.  Such requests should be addressed to our Privacy Officer via the details provided in this policy.

Requests for access to information

Ozcare does not impose a charge for making a request for access.  However, we may charge for reasonable administrative costs incurred in providing access.

We will take appropriate steps to verify your identity (or verify that you act as an authorised agent of the individual concerned) before granting access to your personal information.

We will respond to your request for access to your personal information within a reasonable time after you make the request and, if access is granted, access will be provided within 30 days from your request.  If we deny your request, we will provide you with a written notice detailing the reasons for the refusal and the process for making a complaint about the refusal to grant your request.

Where your request for access is accepted, we will provide you with access to your personal information in a manner, as requested by you, providing it is reasonable to do so.

Requests for correction of information

Ozcare does not impose any charges with respect to requests to update or correct your personal information.

Your request for correction will be dealt with within 30 days, or such longer period as agreed by you.  If we deny your request, we will provide you with a written notice detailing reasons for the refusal and the process for making a complaint about the refusal to grant your request.

We will accept your request for correction of your personal information where we are satisfied that it is inaccurate, out-of-date, incomplete, irrelevant or misleading.  Upon accepting a request for correction of your personal information, we will take all steps that are reasonable in the circumstances, having regard to the purpose for which your information is held, to correct your personal information.

If we refuse to correct your personal information, you have the right to associate with the information a statement that the information is inaccurate, out-of-date, incomplete, irrelevant or misleading.  We will take such steps as are reasonable in the circumstances to associate that statement with all records we hold that contain the relevant information.

Incomplete or inaccurate information

If the personal or sensitive information that we require, in order to provide services to you, is not provided, or is incomplete, or is inaccurate, we may be unable to provide you, or someone else that you know, with the services that you, or they, are seeking.

Notifiable data breaches

A notifiable data breach scheme is currently in place in Australia. We are committed to adhering to this scheme as an important step in preventing and managing serious privacy breaches.

We, including all our people, take breaches of privacy very seriously. If we suspect a data breach has occurred, our priority is to contain and assess the suspected breach. In doing so, we will:

  • take any necessary immediate action to contain the breach and reduce the risk of harm;
  • determine the cause and extent of the breach;
  • consider the types of information involved, including whether the personal information is sensitive in nature;
  • analyse the nature of the harm that may be caused to affected individuals;
  • consider the person or body that has obtained or may obtain personal information as a result of the breach (if known); and
  • determine whether the personal information is protected by a security measure.

If we believe an eligible data breach has occurred we will, as soon as practicable, notify the Office of the Australian Information Commissioner (OAIC) and all affected individuals or, if it is not possible to notify affected individuals, provide public notice of the breach (in a manner that protects the identity of affected individuals).

Feedback & complaints

If you have any queries or concerns about our privacy policy or the way we handle your personal information, you can contact our Privacy Officer by telephone at: 1800692 273, by e‑mail to: info@ozcare.org.au, or by writing a letter to: Ozcare, PO Box 912, Fortitude Valley, Brisbane, Qld 4006.

If you believe that we have breached a term of this policy, the APPs or the Privacy Act, you may make a complaint.  A written complaint can be emailed or posted to our Privacy Officer using the contact details set out above.  Please include contact details for us to contact you regarding your complaint.

Ozcare will not impose any charge for making a complaint, or for dealing with the complaint.  Once a complaint has been lodged, our Privacy Officer will consider your complaint and respond as soon as reasonably possible, but not more than 30 days from receiving the complaint.

All complaints and the outcomes are recorded into an electronic recording system that provides traceability of our communication with you. Our internal business processes prescribe responsibility and timeframes for timely complaint resolution. All documentary records of a complaint are kept confidential, and the information securely filed by the person closing out the complaint.

If you are unsatisfied with the outcome of your complaint, you may refer your complaint to the OAIC.

Office of the Australian Information Commissioner

The contact details for the OAIC are:

Postal address:               
GPO Box 5218
Sydney  NSW  2001
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au

For more information on privacy see the OAIC’s website at: http://www.oaic.gov.au.

Effect of policy

We may update this policy from time to time ,so please review it periodically for changes. If we make material changes to this policy, we will notify you by email or by updating the policy as it appears on the “Home” page of our website www.ozcare.org.au. Your continued use of our website or services or the provision of further personal information to us once you have been notified of the revisions constitutes your acceptance of the revised privacy policy.

This policy does not create any rights or obligations that you can legally enforce against us beyond the rights and obligations provided under the Privacy Act.

Relevant Legislation / Standards

Privacy Act 1988 (Cth)

Information Privacy Act 2009 (Qld)