Privacy and Information Handling Policy
v2.4
Purpose. This policy sets out how the department collects, uses, stores, shares and releases personal, health and sensitive information under the Privacy and Data Protection Act 2014, the Health Records Act 2001 and the Freedom of Information Act 1982.
1.Purpose and scope
The department holds personal information about grant applicants, service users, complainants, provider staff and its own employees. This policy applies to every record in every format, including emails, portal data, paper files, photographs and notes. It must be read with the records management policy and the security classification procedure.
2.Collection and use
Personal information must be collected only where it is necessary for a function of the department, by lawful and fair means, and with a collection notice that explains the purpose. Information must be used only for the purpose it was collected for or a directly related purpose the person would reasonably expect. Sensitive and health information must not be collected without consent unless the law requires it.
3.Security and access
Records containing personal information must be stored in the approved records system, classified under the protective security framework and accessed only by staff who need it for their duties. Staff must not email personal information to private accounts, store it on unapproved devices or leave it visible at front counters. Access to grant, compliance and complaint records is logged and audited.
- Store personal information only in approved systems
- Apply the correct security classification to every document
- Lock screens and clear desks when away
- Do not discuss individual matters in public areas or lifts
- Report any suspected breach on the day it is found
4.Disclosure and information sharing
Personal information must not be disclosed outside the department unless the person has consented, the disclosure is required or authorised by law, or it is necessary to lessen a serious threat to life, health or safety. Sharing with other agencies must be documented under an information sharing agreement approved by the Manager, Corporate Services.
5.Access, correction and freedom of information
People have the right to request access to their own information and to ask for corrections. Requests must be registered in the correspondence tracker and referred to the freedom of information officer, who will process them under the Freedom of Information Act 1982 within the statutory timeframe. Staff must not release documents outside this process.
6.Data breaches
Any loss, unauthorised access or disclosure of personal information is a data breach. Staff must report it immediately to their manager and the privacy officer, who will contain the breach, assess the harm, notify affected people and the regulator where required, and record the breach in the risk register.