GDPR. This officer may have other duties within our business and also be assisted
by internal and external professionals and advisors.
7.2. We will take all reasonable precautions to protect an individual’s Personal Information
from unauthorised access. This includes appropriately securing our physical facilities
and electronic networks.
7.3. Each individual that provides information to us via the internet or by post does so at
their own risk. We cannot accept responsibility for misuse or loss of, or unauthorised
access to, Personal Information where the security of information is not within our
control.
7.4. We are not responsible for the privacy or security practices of any third party
(including third parties that we are permitted to disclose an individual’s Personal
Information to in accordance with this policy or any applicable laws), unless otherwise
required by the Privacy Act and the GDPR. The collection and use of an individual’s
information by such third parties may be subject to separate privacy and security
policies.
7.5. If an individual suspects any misuse or loss of, or unauthorised access to, their
Personal Information, they should let us know immediately.
7.6. We are not liable for any loss, damage or claim arising out of another person’s use of
the Personal Information where we were authorised to provide that person with the
Personal Information.
7.7. Where there is a breach of security leading to the accidental or unlawful destruction,
loss, alteration, unauthorised disclosure of, or access to, Personal Information, then:
(a) We will immediately establish the likelihood and severity of the resulting risk
to wider rights and freedoms of natural persons;
(b) If we determine there is a risk from the security breach, then we will
immediately notify the relevant supervisory authority and provide all relevant
information on the particular breach, and by no later than 72 hours after
having first become aware of the breach;
(c) If we determine there is a high risk from the security breach (a higher
threshold than set for notifying supervisory authorities), we will immediately
notify the affected individuals and provide all relevant information on the
particular breach without undue delay.
7.8. We will document the facts relating to any security breach, its effects and the
remedial action taken, and investigate the cause of the breach and how to prevent
similar situations in the future.
8. HOW TO ACCESS, UPDATE AND/OR REMOVE INFORMATION
8.1. Subject to the Australian Privacy Principles and the GDPR, an individual has the right
to request from us the Personal Information that we have about them, and we have
an obligation to provide them with such information as soon as practicable, and by no
later than 28 days of receiving the written request. The individual is free to retain and
reuse their Personal Information for their own purposes. We may be required to
transmit the Personal Information directly to another organisation if this is technically
feasible.
8.2. If an individual cannot update their own information, we will correct any errors in the
Personal Information we hold about an individual within 28 days of receiving written
notice from them about those errors, or two months where the request for rectification
is complex.