1. Purpose
1.1This Privacy Policy (Policy) is to help all Employees, including directors and officers of the Company and its subsidiaries (CHIA QLD) to effectively collect, hold, use, disclose and manage personal information in accordance with applicable privacy legislation and governance obligations.
1.2This Policy is intended to:
  • (a)Ensure CHIA QLD complies with its obligations under applicable privacy legislation;
  • (b)Protect the privacy and confidentiality of personal information; and
  • (c)Promote responsible information handling practices across CHIA QLD.
1.3As a peak industry body representing community housing providers, CHIA QLD collects and manages personal information primarily for membership, advocacy, governance and sector engagement purposes.
2. Defining Personal Information and Data Breaches
Personal Information
2.1Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether the information or opinion is recorded in material form or not.
2.2For the purpose of this policy, personal information may include a person’s name, address, email address, telephone number, date of birth, job title, organisation, payment or billing details, membership details, employment information, records of correspondence, digital records, and any other information CHIA QLD holds that can identify, or reasonably identify an individual.
Sensitive Information
2.3Sensitive Information is a subset of personal information and includes information or an opinion about an individual’s:
  • (a)racial or ethnic origin;
  • (b)political opinions or membership of a political association;
  • (c)religious beliefs or affiliations;
  • (d)philosophical beliefs;
  • (e)membership of a professional or trade association or trade union;
  • (f)sexual orientation or practices;
  • (g)criminal record;
  • (h)health information;
  • (i)genetic information;
  • (j)biometric information used for automated biometric verification or identification; and
  • (k)biometric templates.
2.4CHIA QLD does not ordinarily collect sensitive information unless it is reasonably necessary for its functions or activities, the individual has consented, or the collection is otherwise required or authorised by law.
Health Information
2.5Health information is a subset of personal information and includes information or an opinion about:
  • (a)the health or disability of an individual;
  • (b)an individual’s expressed wishes about the future provision of health services;
  • (c)a health service provided, or to be provided, to an individual; and
  • (d)other personal information collected in connection with the provision of a health service or relating to donated body parts, organs or body substances.
2.6CHIA QLD will only collect health information where reasonably necessary and permitted by law, including where required to support accessibility, workplace health and safety, or other legitimate organisational purposes.
Data Breaches
2.7A Data Breach occurs when personal information held by CHIA QLD is subject to unauthorised access, unauthorised disclosure, or loss.
2.8A data breach may arise from circumstances including:
  • (a)accidental or unlawful disclosure of personal information;
  • (b)unauthorised access to electronic systems, files or databases;
  • (c)loss or theft of devices, records or documents containing personal information; or
  • (d)failure to securely dispose of personal information.
2.9Not all data breaches are eligible data breaches for the purposes of the Notifiable Data Breaches scheme.
2.10An eligible data breach arises where:
  • (a)there is unauthorised access to, unauthorised disclosure of, or loss of personal information held by CHIA QLD;
  • (b)the access, disclosure or loss is likely to result in serious harm to one or more individuals; and
  • (c)CHIA QLD has not been able to prevent the likely risk of serious harm through remedial action.
2.11Where CHIA QLD becomes aware of, or suspects, a data breach, it must assess and respond to the incident promptly in accordance with this Policy and any related internal procedures.
3. Privacy Principles and Obligations
Privacy Principles
3.1CHIA QLD is committed to complying with the Privacy Act and the Australian Privacy Principles (APPs), which regulate the collection, use, disclosure, storage and access to personal information.
3.2Where CHIA QLD handles personal information on behalf of, or in connection with, Queensland Government agencies or programs, it will also have regard to the Information Privacy Act 2009 (QLD) and the Queensland Privacy Principles.
3.3CHIA QLD will take reasonable steps to ensure personal information is:
  • (a)collected lawfully and fairly;
  • (b)used only for legitimate and disclosed purposes;
  • (c)accurate, complete and up to date; and
  • (d)protected from misuse, interference, loss, unauthorised access, modification or disclosure.
Collection of Personal Information
3.4CHIA QLD collects personal information that is reasonably necessary to carry out its functions as a membership-based peak body.
3.5The types of personal information CHIA QLD may collect include:
  • (a)names, contact details and professional information;
  • (b)membership and organisational affiliation details;
  • (c)employment and governance-related information (e.g. directors, representatives);
  • (d)event, training and engagement information;
  • (e)financial and billing information;
  • (f)correspondence and stakeholder engagement records; and
  • (g)limited sensitive information where reasonably necessary and with consent.
3.6CHIA QLD will only collect sensitive information where:
  • (a)the individual consents;
  • (b)the collection is required or authorised by law; or
  • (c)it is otherwise permitted under applicable legislation.
3.7At or before the time CHIA QLD collects personal information, or as soon as practicable afterwards, CHIA QLD will take reasonable steps to notify individuals of:
  • (a)the purpose for which the information is being collected;
  • (b)the consequences (if any) of not providing the information;
  • (c)the types of organisations or persons to whom the information may be disclosed;
  • (d)whether the information is likely to be disclosed overseas; and
  • (e)the availability of this Policy.
How Personal Information is Collected
3.8CHIA QLD collects personal information directly from individuals where possible, including through:
  • (a)membership applications and renewals;
  • (b)event registrations and training participation;
  • (c)surveys, consultations and stakeholder engagement;
  • (d)employment and recruitment processes;
  • (e)correspondence via email, phone or online platforms; and
  • (f)website and digital interactions, including via cookies, analytics tools and online forms.
3.9This information is generally used for administrative, statistical and service purposes and is not used to identify individuals unless required or consented to.
3.10CHIA QLD may also collect personal information from third parties or publicly available sources where permitted by law.
3.11If unsolicited personal information is received, CHIA QLD will determine whether it could have lawfully collected the information and, if not, will destroy or de-identify it where lawful and reasonable.
Use and Disclosure of Personal Information
3.12CHIA QLD uses personal information for purposes including:
  • (a)managing membership and stakeholder relationships;
  • (b)delivering services, programs and sector support;
  • (c)advocacy, research and policy development;
  • (d)governance and compliance activities;
  • (e)communication, engagement and marketing; and
  • (f)responding to enquiries and feedback.
3.13CHIA QLD may disclose personal information:
  • (a)to contractors and service providers engaged by CHIA QLD;
  • (b)to government agencies, regulators or funding bodies where required;
  • (c)to professional advisers (e.g. legal, financial, human resources, audit); and
  • (d)where required or authorised by law.
3.14As a peak body, CHIA QLD may use personal information of members and their representatives to:
  • (a)communicate with members and facilitate engagement;
  • (b)represent the interests of members in advocacy, policy development and sector activities;
  • (c)develop submissions, reports and research (including de-identified or aggregated form);
  • (d)support collaboration and information sharing within the community housing sector.
3.15Where appropriate, CHIA QLD will de-identify personal information used for advocacy, reporting or research purposes.
Overseas Disclosure
3.16CHIA QLD may disclose personal information to overseas recipients, including through the use of cloud-based service providers or data storage systems.
3.17Where CHIA QLD discloses personal information overseas, it will take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, unless an exception under the Privacy Act applies.
Access and Correction
3.18Individuals may request access to personal information held by CHIA QLD.
3.19Requests must be made in writing and identity verification may be required.
3.20CHIA QLD will respond within a reasonable timeframe and may refuse access where permitted by law.
3.21Individuals may request correction of inaccurate, incomplete or outdated personal information.
Data Protection and Security
3.22CHIA QLD takes reasonable steps to protect personal information, including:
  • (a)secure IT systems and access controls;
  • (b)confidentiality obligations for Employees;
  • (c)physical security measures; and
  • (d)staff training and awareness.
3.23CHIA QLD will retain personal information only for as long as necessary to fulfil its functions, meet legal and regulatory obligations and comply with record keeping requirements.
3.24When personal information is no longer required, CHIA QLD will take reasonable steps to destroy or de-identify the information.
Notifiable Data Breaches
3.25CHIA QLD will comply with the Notifiable Data Breaches scheme under the Privacy Act.
3.26In the event of an eligible data breach, CHIA QLD will:
  • (a)assess the breach;
  • (b)notify affected individuals where required; and
  • (c)notify the Office of the Australian Information Commissioner (OAIC).
Dealing with CHIA QLD Anonymously or by Pseudonym
3.27Where lawful and practical, individuals may deal with CHIA QLD anonymously or by using a pseudonym.
3.28However, because CHIA QLD is a membership-based peak body and company limited by guarantee, it will often be necessary for CHIA QLD to collect identifying information in order to carry out its functions and activities, including to:
  • (a)assess and administer membership applications and renewals;
  • (b)maintain member and stakeholder records;
  • (c)provide services, communications, events, training and sector engagement activities;
  • (d)process payments, invoices and related financial transactions;
  • (e)respond to enquiries, complaints or requests;
  • (f)administer employment, recruitment and contractor arrangements; and
  • (g)meet legal, regulatory and governance obligations.
3.29If an individual chooses not to provide personal information requested by CHIA QLD, CHIA QLD may be unable to:
  • (a)provide the requested service or assistance;
  • (b)process or maintain membership;
  • (c)register the individual for an event, consultation or training activity;
  • (d)communicate with the individual effectively;
  • (e)process payments or issue invoices or receipts; or
  • (f)otherwise carry out the relevant function or activity.
4. Complaints
4.1Individuals may make a complaint about CHIA QLD’s handling of personal information.
4.2Complaints must be made in writing to the Chief Executive Officer (CEO):
518 Brunswick St
Fortitude Valley
Brisbane QLD 4006
ceo@chiaqld.org.au
0400 141 507
4.3The CEO will acknowledge receipt of the complaint within five business days and will aim to investigate and respond within 30 days.
4.4If unresolved, complaints may be referred to the Office of the Australian Information Commissioner (OAIC).
5. Communication
5.1This Policy will be:
  • (a)communicated and promoted across CHIA QLD; and
  • (b)made available to members and stakeholders via CHIA QLD’s website or upon request.
5.2The Chief Executive Officer, with the support of the Board, is responsible for ensuring that this Policy is effectively implemented, communicated and maintained across CHIA QLD.
5.3All Employees are responsible for:
  • (a)Complying with this policy and applicable privacy legislation;
  • (b)Handling personal information in a lawful, ethical and secure manner;
  • (c)Reporting any actual or suspected privacy breaches in accordance with this policy and any related procedures.
6. Relevant Standards and Laws
6.1This Policy aligns with the following laws and regulations:
  • (a)ACNC Governance Standards and reporting requirements;
  • (b)The Privacy Act 1988 (Cth);
  • (c)The Information Privacy Act 2009 (Qld); and
  • (d)The Notifiable Data Breaches Act 2017 (Cth)