Intent
Lifeskills is committed to ensuring full compliance with the Privacy Act 2020 and its amendments, Privacy Codes of Practice and any other relevant Standards, Guidelines or Legislation. The organisation values the importance of privacy and principles to protect the privacy of individuals. To meet this commitment, Lifeskills will ensure that the way it collects, uses, secures, and discloses personal information meets the requirements of the Privacy Act 2020.
Company
This is to be achieved by ensuring:
Applicability
This Policy is operationally applicable to the Lifeskills Board, Chief Executive, Senior Managers and in particular members of the Human Resources team, privacy officers, administrators, and the Operations Manager. The contents have a bearing on all employed staff, whether a party to an employment agreement, an independent contractor or otherwise in a relationship of employment with Lifeskills. Lifeskills recognises that any entity that holds personal information including private businesses must comply with the Privacy Act 2020, and mandatory compliance with legislation and organisational policies and procedures to ensure protection of personal information is required.
Criteria
Lifeskills operational policies and procedures are to be read in conjunction with each other. This policy relates to the achievement of a robust administration system, supported by appropriately qualified and trained staff satisfying the needs of the stakeholders. The intention is to achieve procedural fairness and clarity and no policy is intended to contravene another or have an adverse effect on the person to whom it is applicable.
Appointment of Privacy Officers
The organisation appoints three distinct Privacy Officers.
The Privacy Principles (Privacy Act 2020)
The policy is designed to comply with the 13 Privacy Principles as outlined by the Privacy Act 2020:
Policy Principles
Application
The Privacy Act applies to ‘personal information’ - information which is about an identifiable individual. Individual is defined as meaning any living natural person (so doesn’t include ‘legal persons’ like companies).
Material Form
Information is defined broadly and includes physical documents (like written records or photos), electronic documents (emails, audio, and video recordings, etc.), and can include information held in the mind of the employees if that information is readily retrievable.
Personal Information
Information or an opinion about an identifiable individual or information that could lead to identification of an individual:
Sensitive Personal Information
“Information or an opinion about individuals” that also has personal information such as:
Training and Development
Lifeskills will ensure all staff and contractors are inducted to the organisation privacy policies and procedures.
Lifeskills will ensure all staff are provided training to meet the organisation’s obligations under the Privacy Act 2020.
The Privacy Officer (Approvals) is responsible to ensure that the induction and training is fit for purpose to provide education and guidance on meeting the requirements of the Privacy Act 2020.
The Privacy Officer (Operations) is responsible to ensure all staff and contractors receive induction and training on meeting the requirements of the Privacy Act 2020.
Collection of Information
The Privacy Officer (Information) is responsible to ensure that:
The Privacy Officer (Information) can set guidelines for information to be collected, disclosed and the manner in which it is collected. The Privacy Officer (Information) can stop, limit, or destroy information collected based on its non-compliance with the Privacy Act 2020.
Storage and Security
Access, Correction and Accuracy
The Privacy Officer (Approval) is responsible to set an accessible process for individuals to request access and correction of personal information held by the organisation.
The Privacy Officer (Approval) is responsible to approve such requests and provide requested information or correction as soon as practicable and no later than 20 working days of receipt of such request. In case of a disagreement to the correction of personal information, the Privacy Officer (Approval) is required to attach a statement of correction to the information to show the person’s view.
The Privacy Officer (Approval) is responsible to consider, approve or decline any requests for access, including any urgent requests within the parameters of the Privacy Act 2020.
The Privacy Officer (Approval) is responsible to ensure any disclosure of personal information is accurate, up to date, complete, relevant, and not misleading.
Retention and Use
The Privacy Officer (Information) is responsible to ensure that all information collected is only used for the lawful purpose it is collected.
The Privacy Officer (Information) is responsible to ensure that all information collected is only retained no longer than it is required for lawful purpose.
The Privacy Officer (Information) is responsible to set process for disposal of personal information in a way that complies with the requirements of the Privacy Act 2020.
The Privacy Officer (Information) is responsible to ensure that reasonable steps are in place to protect unique identifiers.
Disclosure
The Privacy Officer (Approval) is responsible to consider any requests of disclosure of personal information from any party.
The Privacy Officer (Approval) may only approve such requests in limited circumstances that meet legal obligations after considering relevant legal opinion.
The Privacy Officer (Approval) shall not approve any requests of disclosures to entities that are not subjected to the Privacy Act 2020.
The Privacy Officer (Approval) shall be responsible to ensure that disclosure does not include any unique identifiers unless expressly required by law.
Policy Access
The Privacy Policy and associated documentation are accessible to all employees and contractors.
Privacy policy disclosures and statements are accessible to individuals both in public forums such as the website and brochures and at time of collection of data.
A record of acknowledgment of the Privacy Policy should accompany all personal information collected.
Privacy Breaches
The Privacy Officer (Approvals) is responsible to report any notifiable privacy breaches to the Privacy Commissioner as soon as practicable and no later than 72 hours of being aware of such breach.
A privacy breach occurs when an organisation or individual either intentionally or accidentally:
The Privacy Officer (Operations) is responsible to take reasonable steps to prevent privacy breaches by taking steps such as:
Records Management
All personal information and records are maintained in accordance with Records Management Policy.
Related Key Documents
Legislation
Other policies that may impact on this policy
Guidelines
Standards and Procedures
Forms
Other Useful Resources
Accountability, Management and Control
Owner
Chief Executive
Content Manager
Chief Executive, Operations Manager, Group Registrar
Prepared by
Administration Project Contractors
Approval
7th October, 2022
Review date
7th October, 2023