|
Introduction
United Credit Union is bound by the National Privacy Principles (NPPs). It is recognised that all members have rights and that their personal and other details should be treated in the strictest confidence.
The national privacy scheme is a legislatively based framework of privacy laws for the Australian private sector. It is designed to give appropriate privacy protection to individuals when private sector organisations seek to collect, hold, use, disclose, correct or transfer their personal information.
Authority
The Policy has been approved by the Chief Executive Officer.
Review Periods
The policy statement will be reviewed by the Executive Manager, Risk not less frequently than annually.
Monitoring and Supervision
Monitoring for compliance with this policy will be the responsibility of the Executive Manager, Sales & Service. Breaches of compliance will be reported to the Operational Risk Committee.
Related Documents
- Privacy Act 1988
- Privacy Amendment (Private Sector) Act 2000
- National Privacy Principle Guidelines (2001)
- Dispute Resolution Policy & Process
Definitions
| NPP | National Privacy Principle - Benchmark for privacy to be observed by private sector organisations handling personal information |
| NPP1 | Collection of information |
| NPP2 | Use and disclosure |
| NPP3 | Data quality |
| NPP4 | Data security |
| NPP5 | Openness |
| NPP6 | Access and correction |
| NPP7 | Identifiers |
| NPP8 | Anonymity |
| NPP9 | Transborder flow of data |
| NPP10 | Sensitive information |
Roles and Responsibilities
- Every staff member at United Credit Union is responsible for upholding this policy and for ensuring that the National Privacy Principles are understood and adhered to at all times.
National Privacy Principles
- Information collected: Information is collected only when it is relevant to the specific need.
- Use and Disclosure: Personal information will only be used and disclosed:
- or the primary purpose for which it was collected
- for reasonably expected secondary purposes
- when the member has authorised it
- for direct marketing, unless specified otherwise
- where required or authorised by law
- Data Quality: United is responsible for taking reasonable steps to ensure that the information collected, used or disclosed is accurate, complete and up to date.
- Data Security: United is responsible for taking reasonable steps to protect the personal information held from misuse and loss and from unauthorised access, modification or disclosure.
- Openness: Policies about the management of personal information must be freely available.
- Access & correction: United must provide people with access to information about them on request except in certain circumstances relating to:
- Health issues
- An impact on the privacy of other people
- The request is frivolous or vexatious
- Legal matters
The Credit union must ensure that information held is accurate, complete and up to date before basing decisions on, or disclosing to others that information.
- Identifiers: United must not adopt, use or disclose identifiers assigned by other organisations or agencies.
- Anonymity: Where lawful and practical, individuals must have the option of not identifying themselves when entering transactions with an organisation
- Transborder data flows: United may transfer personal information about an individual to someone (other than the organisation or individual) in another country only if:
- The information is subject to law
- The individual consents
- It is necessary for the performance of a contract
- Sensitive information: Must not be collected unless:
- The individual has consented
- It is required by law
- The collection is necessary to prevent or lessen a serious and imminent threat to life or health of the individual who is incapable of giving consent
- If the information relates to a non-profit organisation and it relates only to the members of the organisation and the organisation undertakes not to disclose the information without the individual's consent
Policy Statement
The information collected about individuals will depend on the product or facility required by that person or organisation. United will only collect information that is relevant to the specific needs of individuals. Information is generally collected during application for membership or loan facilities and will be stored within the core banking system database which is fully secure.
United will only disclose personal information:
For the primary purpose for which it was collected
For reasonably expected secondary purposes
When there is authorisation to do so
For direct marketing where the member has satisfied specified criteria
Where required or authorised by law
United will hold information about individuals only when it is related to provision of banking and other financial services required. In some instances, United may be required to exchange personal information with external advisers, regulatory bodes, insurers and other organisations with which there are alliances or arrangements to promote or provide respective products and services.
Dispute Resolution: United has established a Dispute Resolution process which is readily accessible.
United is obliged to provide access to information held about individuals to them on request (with certain exceptions).
|
Privacy Officer United Credit Union 430 Roberts Road
Subiaco WA 6008 Telephone:
(08) 9382 0444 Facsimile: (08) 9381 4741 Email: united@unitedcredit.com.au |
|
|