The purpose of this policy is to provide clear principles on action to be taken by the (CITB) to ensure
that:
- personal information collected or held will be securely stored; and only collected, transmitted, published, used, shared, disclosed and accessed in accordance with Australian Privacy Principles set out in the Privacy Act 1988 (Cth).
- CITB employees and other Stakeholders who possess or control personal information collected or held by CITB make appropriate amendments to that information are reasonable, for ensuring that information assets are accurate, relevant, up-to-date, complete and not misleading.
- Employees and Stakeholders are entitled to have access to and request reasonable amendments to an individual’s personal information in accordance with the provisions of the Privacy Act 1988.
This policy applies to all personal information that is collected or held by CITB.
DEFINITIONS
Cookies: Cookies are small text files that are transferred to a user’s hard drive by a website for the purpose of collecting information about a user’s identity, browser type or website visiting patterns.
Personal information: The Privacy Act defines ‘personal information’ as:
‘Information or an opinion about an identified individual, or an individual who is reasonably identifiable:
- whether the information or opinion is true or not; and
- whether the information or opinion is recorded in a material form or not.’
Stakeholders: Stakeholders may include:
- project owners
- employers
- employer/employee Unions
- Registered Training Organisation (RTO)
- Group Training Organisation (GTO)
- teachers
- trainers/assessors
- students/participants
- apprentices/trainees
- government departments
- volunteers
This policy sets out how the Construction Industry Training Board ABN 39 817 133 546 (we) collect, hold and disclose personal information. We take privacy seriously and are committed to complying with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
Personal information
Personal information refers to information that relates to an identified, or identifiable person. (refer to Definitions).
Why does CITB collect and hold personal information?
We collect personal information to:
- provide services
- communicate with our Stakeholders, suppliers and other contacts
- manage and account for our services
- inform our Stakeholders and other contacts about industry developments
- market our services and send invitations to our events
- manage our employees and contractors
- undertake research related activities
- generally carry on our business
What personal information does CITB collect and hold?
We collect an individual’s name and contact details, and information about the individual’s occupation, employer and relationship with us or our Stakeholders and potential Stakeholders, and about the individual’s relationship with our other contacts.
We also collect the information necessary to provide the specific services our clients require, as well as credit card and payment information.
How does CITB collect personal information?
We collect personal information direct from an individual when that individual meets with us, communicates with us by letter, telephone or email, gives us a business card, subscribes to our publications, registers for, or attends, our events or submits information through our websites, blogs or other social media outlets.
We may also collect information about an individual from our Stakeholders, potential Stakeholders and their contacts, from the individual’s employer and from publicly available records or a third party e.g. a provider of an employment or other reference.
Cookies
We may ask other people to analyse traffic on our websites, blogs and other social media outlets and they may use cookies to do so.
Sensitive Information
Sensitive information is defined in the Privacy Act to include information or opinion about such things as an individual’s racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
Sensitive information will be used by us only:
- For the primary purpose for which it was obtained
- For a secondary purpose that is directly related to the primary purpose
- With your consent; or where required or authorised by law.
Third Parties
Where reasonable and practicable to do so, we will collect your Personal Information only from you. However, in some circumstances we may be provided with information by third parties. In such a case we will take reasonable steps to ensure that you are made aware of the information provided to us by the third party.
Accessing and Updating Your Personal Information
Integrity of personal information
We take all reasonable steps to ensure that the personal information we collect is accurate, up to date and complete and that the personal information we use or disclose is relevant in regard to the purpose of such use or disclosure.
To that end, we encourage individuals to contact us to update or correct any personal information we may hold about them.
Accessing / Correcting of personal information
Individuals may request access to personal information that we hold about them. We may require verification of identity and we may require them to specify the information they require.
CITB take reasonable steps to ensure all personal information we hold is accurate, up to date, complete, relevant and not misleading. As such we will correct information where necessary.
We deal with all requests for access to, and for correction of, personal information as required by the Privacy Act.
General use and disclosure
Securing personal information
CITB take all reasonable steps to protect the personal information we hold from misuse and loss, and from unauthorised access, modification or disclosure.
We store hard copies of this information in access-controlled premises, and digital versions on secure servers. We require all persons authorised to access digital information to use logins and passwords to access this information.
CITB require all contractors and others to whom we disclose personal information or for whom may have access to personal information we collect, to keep this personal information private and to protect it from misuse and loss and from unauthorised access, modification or disclosure.
CITB uses proprietary commercial banking software that complies with Payment Card Industry Data Security Standards (PCI-DSS). We safeguard customers’ data by employing up-to-date and reliable security protection. Credit card details are not retained by CITB.
Unless we are prevented from doing so by the law, we de-identify or destroy securely all personal information we hold when it is no longer reasonably required by us.
Use and disclosure for direct marketing
CITB will only market our services to individuals using their personal information where we give that individual an opportunity to request us not to utilise their information for this purpose. We will not use an individual’s personal information for this purpose if the individual requests us not to do so.
Information we share
CITB will only disclose personal information for the purpose for which it is collected, and for related purposes and for purposes permitted by the Privacy Act. We will only otherwise disclose personal information with the consent of the relevant individual. Stakeholders may have access to some personal information due to the nature of their relationship with CITB.
Our auditors, insurers, legal and other professional advisers may also access personal information to protect our interests and to ensure that we comply with our obligations.
Disclosure to overseas recipients
We will generally not disclose personal information to overseas persons or parties. Where we are required to provide specific services our Stakeholders, we may disclose personal information to overseas entities however, only to the extent required for such purposes. Otherwise, we will only disclose personal information to overseas recipients with the consent of the relevant individual or when required or authorised by law together with the Australian Privacy Principles Guidelines concerning cross-border disclosure of personal information.
Dealing with us anonymously
Individuals have the right not to identify themselves, or to use a pseudonym when dealing with us.
However, if we request personal information and it is not provided, we may not be able to provide
services to or otherwise assist the relevant individual.
Protection of children, young people and their families
CITB will adhere to Department for Education and other relevant agency policies, in relation to the
protection of children, young people and their families where applicable.
Security Breaches
In the event that we become aware of any actual or potential unauthorised access to or disclosure of personal information about an individual, or any loss of such information which may lead to unauthorised access or disclosure, we will promptly investigate. Where appropriate, we will take remedial action and notify the individual affected in accordance with the Privacy Act.
Complaints
If an individual wishes to make a complaint about this Privacy Policy or our collection, use or disclosure of personal information, we ask them to contact us in the first instance. CITB will investigate the complaint and try to promptly resolve it directly with the individual.
If the individual is not satisfied with the outcome, then they may make a complaint to the Office of the Australian Information Commissioner (OAIC). For information about how to make such a complaint, please refer to the OAIC website http://www.oaic.gov.au/.
If an individual wishes to access or correct personal information, to request not to receive marketing material or invitations from us, or to make a privacy complaint, they should contact us at citb@citb.org.au.
Changes to privacy policy
CITB reserves the right to make changes to this Privacy Policy from time to time and without notice
by publication on our website.
CITB recommend that individuals regularly review our Privacy Policy to ensure they are aware of
any changes.