Privacy Policy

Purpose

The purpose of this policy is to ensure that all staff, contractors, and volunteers of Career Employment Group Inc (CEG) understand their responsibilities regarding the collection, use, storage, and disclosure of confidential and personal information.

This policy aims to protect the privacy of employees, clients, and stakeholders while ensuring compliance with relevant South Australian and Commonwealth legislation, including the Privacy Act 1988 (Cth) and associated Australian Privacy Principles (APPs).

Scope

This policy applies to:

  • All employees, contractors, and volunteers of CEG.
  • All personal, sensitive, and confidential information obtained in the course of CEG’s operations, including employee, client, and business information.
  • All CEG systems, platforms, and communications where confidential information is stored, transmitted, or processed.

Definitions

Confidential Information: Any information which is not publicly available and which, if disclosed without authorisation, could cause harm to CEG, its employees, clients, or stakeholders. Examples include financial data, employee records, client details, business strategies, and intellectual property.

Personal Information: Information or an opinion about an identified or reasonably identifiable individual, including name, address, contact details, medical records, or employment history.

Sensitive Information: A subset of personal information that includes health records, racial or ethnic origin, religious beliefs, sexual orientation, criminal records, or other information considered sensitive under the Privacy Act 1988 (Cth).

Privacy Breach: Any unauthorised access, use, disclosure, or loss of personal or confidential information.

General Principles

  1. Confidentiality
    • All employees, contractors, and volunteers must treat all CEG information as confidential unless expressly authorised for disclosure.
    • Confidential information must only be accessed for legitimate business purposes.
    • Discussion of confidential information in public or unsecured areas is strictly prohibited.
  2. Privacy and Compliance
    • CEG collects, stores, and processes personal information in accordance with the Privacy Act 1988 (Cth) and Australian Privacy Principles.
    • Individuals’ personal information will only be used for the purpose for which it was collected, unless consent is obtained for other uses.
    • Access to personal information is limited to authorised personnel and will be maintained in secure systems.
  3. Information Security
    • Confidential and personal information must be securely stored, whether in digital or physical form.
    • Passwords, access credentials, and secure systems must be used to prevent unauthorised access.
    • Any suspected or actual breach must be reported immediately to the Human Resources Manager or Privacy Officer.
  4. Third-Party Disclosure
    • Personal or confidential information may only be disclosed to third parties where required by law, for legitimate business purposes, or with the individual’s consent.
    • Contracts with third parties must include confidentiality obligations consistent with this policy.

Roles and Responsibilities

Employee Responsibilities

  • Protect confidential and personal information in accordance with this policy.
  • Only access information necessary for your role.
  • Report any suspected breaches immediately to management.
  • Do not discuss confidential matters outside of authorised contexts.

Collection of Data

How CEG collects sensitive information

Personal or sensitive information may be collected through the following methods:

  • Directly from an individual (form, email, phone call or in-person)
  • Through CEG’s website or other online platforms such as service portals
  • From third parties where authorised or permitted by law

Purpose of Collection

CEG collects and uses personal and sensitive information for the purposes of:

  • Providing and managing our services
  • Communicating with clients and stakeholders
  • Processing payments and transactions
  • Meeting legal and regulatory obligations
  • Managing employment and contractual obligations

Legal Basis for use of personal information

Where required by law, or contractual obligation we process personal information based on one or more of the following:

  • Your consent
  • Requirement of contract
  • Compliance with legal obligation

Disclosure of Personal Information

We may disclose personal information to:

  • Employees and authorised representatives for business purposes only
  • Service provides and contractors who are required to know the information for the purpose of meeting contractual obligations
  • Regulatory authorities where required by law

Confidentiality

Termination of Employment

All staff and contractors must continue to maintain confidentiality of information obtained during their engagement with CEG, even after termination of employment or contract.

Access and Correction of Personal Information

Individuals may request access to, or correction of, their personal information held by CEG. Requests should be made in writing to the Human Resources Manager or Privacy Officer and will be managed in accordance with the Privacy Act 1988 (Cth). CEG may require verification of identity before releasing information.

Guidelines and Limitations

CEG recognises that the collection and use of personal and confidential information is necessary to conduct its operations effectively. Information must be collected lawfully, fairly, and only where it is reasonably necessary for CEG’s functions or activities.

Wherever practicable, individuals will be informed about why information is being collected and how it will be used.

Confidential and personal information must not be accessed, used, copied, altered, or disclosed for personal interest, curiosity, or unauthorised purposes. Employees and contractors must take reasonable steps to ensure information is accurate, up to date, and protected from misuse, interference, loss, unauthorised access, modification, or disclosure.

This policy does not limit lawful disclosures required by legislation, court orders, regulatory authorities, or emergency situations where there is a serious threat to life, health, or safety. Any such disclosure must be limited to the minimum information necessary and reported to the Human Resources Manager or Privacy Officer as soon as practicable.

Timeframes

Personal and confidential information will be retained only for as long as it is required to fulfil its intended purpose or to meet legal, contractual, or regulatory obligations. Retention periods will align with applicable legislation, funding agreements, and organisational recordkeeping requirements.

Once information is no longer required, it will be securely destroyed or de-identified in accordance with CEG’s relevant policy.. Requests by individuals to access or correct their personal information will be acknowledged promptly and responded to within a reasonable timeframe, consistent with the Australian Privacy Principles.

Privacy breaches will be assessed immediately upon identification. Where required under the Notifiable Data Breaches scheme, affected individuals and the Office of the Australian Information Commissioner (OAIC) will be notified as soon as practicable.

Breach of Policy

  • Any breach of this policy may result in disciplinary action, up to and including termination of employment or contract.
  • Breaches may also result in civil or criminal penalties under privacy legislation.
  • All breaches will be investigated promptly, confidentially, and fairly.

Escalation

  • Minor concerns regarding confidentiality should be addressed with Branch or Department Managers.
  • Significant issues, including potential privacy breaches, must be escalated to the Human Resources Manager or Privacy Officer.

Matters involving senior management or the CEO will be escalated to the Board of Directors.

Legislation

This policy is designed to comply with:

  • Privacy Act 1988 (Cth)
  • Australian Privacy Principles (APPs)
  • Relevant South Australian laws regarding privacy, recordkeeping, and workplace confidentiality

Policy Review

This policy will be reviewed every two (2) years, or earlier where there are changes to relevant legislation, organisational structure, or operational requirements. Reviews will be conducted by the Human Resources Manager and approved by the Chief Executive Officer.

Related Documents