(1) QUT's functions require the collection, storage, use and disclosure of personal information about students, staff, alumni, donors, partners and other clients. QUT is committed to protecting personal privacy and recognises that individuals have a reasonable expectation that the university will protect and appropriately manage the personal information it holds about them. (2) QUT must comply with the requirements of the Information Privacy Act 2009(Qld) which provides for the fair collection and handling of personal information by Queensland public agencies. QUT may be required to comply with other privacy regulations in other jurisdictions to the extent that they apply to its activities, including circumstances where: (3) This Policy applies to the collection, use, disclosure, storage, transfer, handling, right of access, and amendment of personal information at QUT. (4) It does not apply to: (5) Personal information must be collected only where necessary and relevant to QUT's functions and activities and in a reasonable and transparent way. Personal information should not be collected unless there is a specific and immediate use for it. An appropriate privacy notice must be provided when collecting information directly from an individual. (6) Privacy collection notices must include the following information: (7) Where a privacy law other than the Information Privacy Act 2009 applies to the personal information collected, a privacy notice may need to include some or all of the following information: (8) Before using personal information, staff have a responsibility to take reasonable steps to ensure that information is accurate, up-to-date and complete. Personal information must be used only when it is relevant and only for the purpose for which it has been collected or a directly related purpose. (9) Further guidance on use of personal information is detailed in the Privacy Protocols (QUT staff access only). (10) Access and security safeguards are important ways of protecting personal privacy. Access to personal information is granted to staff only where this is necessary for work purposes and staff must only access personal information if there is a work-related reason for this. Personal information must be protected against loss, unauthorised access or modification, disclosure or misuse. The University's Information Security Policy provides further details on how to classify and protect personal information. (11) Staff must not disclose personal information to individuals or organisations outside the university. Disclosure refers to release of personal information to another entity (e.g. a body, agency or person separate from the university) where QUT will cease to have effective control of the information once it is released. (12) There are some limited circumstances in which personal information may be disclosed without breaching personal privacy. These circumstances include the following: (13) Privacy Protocols (QUT staff access only) which set out the considerations and procedures for disclosure of personal information in these circumstances are available and must be followed. Disclosing personal information in other situations must only occur following confirmation from the Privacy Officer that disclosure is necessary and acceptable under other limited provisions in the Information Privacy Act 2009. (14) QUT, including its predecessor institutions, maintains a public register of graduates. Information concerning a person's status as a graduate is a matter of public record and available to any member of the public, through the Verification of Qualifications service. The only details confirmed through this service are the graduate's name (as recorded in QUT systems), the degree conferred or to be conferred and the date of conferral. QUT may charge a fee for this service. (15) The Information Privacy Act 2009 also provides a right of access to, and amendment of, personal information. Details on how an individual can request access to or to amend their personal information in accordance with the Information Privacy Act 2009 can be found in the university's Information Access Policy webpage Requesting Access to and Amendment of your Personal Information under Information Privacy. (16) If an individual believes that QUT has not dealt with their personal information in accordance with the Information Privacy Act 2009 or this Policy, they may make a Privacy Complaint to QUT. A complaint must be made in writing or by email to the Privacy Officer or referred to that officer if received by another area of the university. (17) Primary responsibility for investigating and responding to the complaint will rest with the head of the organisational unit concerned, with advice from the Privacy Officer as required. The university's main objective in responding to privacy complaints is to conciliate an outcome which is acceptable to the complainant and which addresses any broader or systemic privacy issues which may arise. (18) If a complainant does not agree with the university's response, an internal review process is available, or a complainant may refer the matter for independent mediation by the Office of the Information Commissioner. (19) The head of the relevant organisational unit must report any breaches of this Policy to the Privacy Officer as soon as practicable after the breach has been identified. Where the matter involves a breach of information security, the Privacy Officer will liaise with the Manager, Information Security to assist with responding to and reporting on the complaint. (20) Management of a privacy breach will include steps to: (21) The Vice-President (Administration) and University Registrar must be informed of serious breaches of this Policy or related protocols and any actions arising out of any investigations. (22) A breach which involves misuse or inappropriate access to personal information by a staff member may be a breach of the Code of Conduct - Staff and managed under disciplinary or unsatisfactory performance processes. (23) Protection of personal information must be addressed as part of many university activities. These activities include: (24) Privacy Impact Assessments (PIA) (QUT staff access only) assist Project Managers, data custodians and heads of organisational areas to appropriately consider and manage privacy. A PIA should be undertaken throughout the development and implementation of a project or new business process that collects, uses, or discloses personal information, or when making significant changes to existing systems or processes. (25) Refer to Register of Authorities and Delegations (VC004, VC005) (QUT staff access only).Information Privacy Policy
Section 1 - Purpose
Top of PageSection 2 - Application
Top of PageSection 3 - Roles and Responsibilities
Top of Page
Section 4 - Collection and Use of Personal Information
Collection
Use
Section 5 - Access and Security of Personal Information
Section 6 - Prohibition on Disclosure of Personal Information
Section 7 - Register of Graduates
Section 8 - Requests for Access to and Amendment of Personal Information under Information Privacy Act 2009
Section 9 - Privacy Complaints
Section 10 - Privacy Breach Management
Section 11 - Implementation of Privacy Obligations
Top of PageSection 12 - Privacy Impact Assessment
Section 13 - Definitions
Top of Page
Term
Definition
Australian Privacy Principles
Means the set of 13 principles in the Privacy Act 1988 (Cth) governing the collection, quality, use, disclosure, management and transfer of personal information.
General Data Protection Regulation (GDPR)
Means the legal framework governing the collection and processing of personal information of individuals located in the European Union (EU).
Information Privacy Principles
Means the set of 11 principles in the Information Privacy Act 2009 governing the collection, use, disclosure, management and transfer of personal information by organisations such as the university.
Personal Data
Has the meaning given to it in Article 4 of the GDPR.
Personal Information
Is as defined by the Information Privacy Policy as information or an opinion, including information or an opinion forming part of a database, whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion. Personal information includes usernames, passwords and unique identifiers such as staff and student numbers. It can be recorded in any format including hard copy documents, electronic documents, databases, administrative systems, photographs and other images, and staff/student identity cards.
A Privacy Breach
A privacy breach occurs when there is a failure to comply with the information privacy policy or the Information Privacy Act 2009 11 privacy principles. Usually this will result in unauthorised disclosure of or unauthorised access to personal information.
A Privacy Complaint
Is a complaint about an act or practice of QUT in relation to an individual’s personal information that is a breach of this Policy or the Information Privacy Act 2009.
Unique Identifiers
Unique identifiers including student and staff numbers are used as the basis for recording a large amount of personal information. Other unique identifiers include payroll numbers, tax file numbers, credit card numbers and bank account details.
Routine Employment Information
Routine employment information of staff is any information which does not relate to the personal aspects of a staff member's employment at the university. This includes information such as a staff member's position title, QUT email address, work phone number or any information which is publicly available on the QUT website.
Section 14 - Delegations
View Document
This is the current version of this document. You can provide feedback on this document to the document author - refer to the Status and Details on the document's navigation bar.
Position
Responsibility
Vice-Chancellor and President
As the 'principal officer' under the Information Privacy Act 2009, is responsible for QUT's obligations under the Act.
Vice-President (Administration) and University Registrar
As chief administrative officer, oversees implementation of privacy management across the university, and approves privacy protocols, guidelines and mandatory training arrangements.
Manager, Compliance, Policy and Records (QUT Governance)
Acts as QUT Privacy Officer, and administers the Information Privacy Act 2009 on behalf of the Vice-President (Administration) and University Registrar, including:
Heads of Organisational Units
Manage privacy risk in the organisational unit and implement business processes consistent with the Information Privacy Act 2009.
Data custodians
Implement adequate security measures to protect privacy of personal information in information systems.
Determine user access levels which must be consistent with privacy requirements.
Implement appropriate mechanisms to revoke access to systems containing personal information, when access is no longer appropriate, for instance, in the case of a change in position or formal responsibilities, or termination of employment.
(The Corporate Information Asset Management Policy provides further details.)
All staff
Undertake required privacy training.
Comply with the requirements of the Information Privacy Act 2009, this Policy and all procedures and Privacy Protocols issued under the policy.