(1) To provide a consolidated statement of VU's approach to and expectations regarding privacy. (2) HESF: Standard 7.3 Information Management. (3) Standards for Registered Training Organisations (RTOs) 2015: Standard 8. (4) This Policy covers the management of all information at VU. (5) This Policy applies to all VU staff, students and agents and individuals with whom VU interacts. (6) In this Policy: (7) VU values the privacy of all individuals and is committed to handling their information in a lawful and responsible manner. VU is committed to ensuring that it is compliant with the Information Privacy Principles (IPPs) in the Privacy and Data Protection Act 2014 (Vic), the Health Privacy Principles (HPPs) in the Health Records Act 2001 (Vic), and to the related legal obligations by which it is bound. Where legally required VU will comply with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Clth). (8) VU will collect information only where it is necessary in order to carry out its functions and activities. (9) As part of running the business of the university, VU collects information for various purposes, including for: (10) Overarching privacy collection statements for staff and students are attached to this Policy. (11) When collecting information, it will only be collected by lawful and fair means and not in an unreasonably intrusive way. When collecting information, the individual to whom the request relates should be advised of: (12) VU will only collect sensitive information in limited circumstances (e.g. with the individual's informed consent, or if required by law). (13) Where lawful and practicable, individuals may choose not to identify themselves when transacting with VU. However, VU may be unable to provide services in these circumstances. (14) In most cases, VU will only use or disclose an individual's information for the primary purpose for which it was collected. (15) However, VU may use and disclose information for a secondary purpose if the secondary purpose is: (16) In all other cases, VU may use and disclose the information if: (17) For further guidance regarding use and disclosure of information, including responding to requests for access to information, please see the privacy statements for staff and students attached to this Policy. (18) Staff and agents sending information outside of Victoria as part of VU's functions and activities must only do so: (19) VU will only assign identifiers to individuals, or use or disclose identifiers assigned by other organisations, in accordance with Information Privacy Principles (IPPs) or other applicable legislation. (20) VU will provide individuals with access to information it holds about them, subject to legal requirements. (21) Requests for access to information will be considered in accordance with the applicable legislation, the Privacy Procedure and the Records Management - Access to Records Procedure. (22) In some cases, requests for access to information will need to be made through VU's Freedom of Information process. (23) Where there is a concern, staff should contact the VU Privacy Officer for advice. (24) If an individual establishes and notifies VU that their information is inaccurate, incomplete or not up to date, VU will take reasonable steps to correct the information or to record that the individual disagrees with the information held by VU. (25) VU expects its staff, students and agents to take reasonable steps to ensure that any information is collected, used or disclosed is accurate, complete and up to date. (26) VU will take reasonable steps to ensure that the information it handles is protected from misuse, loss, unauthorised access, modification and disclosure. (27) VU's requirements in relation to information security are set out in the Information Security Policy, the Records Management Policy and relevant associated Procedures. (28) VU will take reasonable steps to destroy or permanently de-identify personal or sensitive information if it is no longer legally required to be held. VU's requirements in relation to the destruction of documents are governed by the Records Management Policy and related Procedures. (29) VU will only destroy or permanently de-identify health information in accordance with the Health Records Act 2001 (Vic). (30) In addition to the above, there are specific obligations with respect to health information collected by VU and health records transferred to other health service providers. Refer to the Privacy Procedure for further information. (31) Health records may be created in many circumstances at VU. Examples include: through VU's health clinics; through research or teaching and learning activities; through work performed by People & Culture; through student counselling; through the work of Accessibility Services etc. These must be managed in accordance with the Health Records Act 2001 (Vic). Further guidance on this is provided in the Privacy Procedure and the Records Management Policy and associated procedures. (32) VU has a Privacy Officer who carries out the functions listed in the Privacy Procedure. Any queries or concerns regarding Privacy should be directed to the Privacy Officer at privacy.officer@vu.edu.au. (33) Privacy Procedure (34) Privacy Security Breach Procedure (35) Operational areas within VU may develop guidelines tailoring the requirements under this Policy and the Privacy Procedure to suit their business needs. (36) Privacy Appendix 1 to this Policy is the Privacy Statement for the collection of student information. (37) Privacy Appendix 2 to this Policy is the Privacy Statement for the collection of staff information.Privacy Policy
Section 1 - Summary
Section 2 - HESF/ASQA/ESOS Alignment
Section 3 - Scope
Section 4 - Definitions
Top of PageSection 5 - Policy Statement
Collecting information
Providing information to VU anonymously
Using and disclosing information
Sending information outside of Victoria
How VU assigns identifiers
Accessing and correcting information
Maintaining data quality
Securing, storing and retaining data
Disposing of and destroying information
Health information
Privacy Support
Section 6 - Procedures
Section 7 - Supporting Documents and Information
View Document
This is the current version of this document. To view historic versions, click on the 'Historic Versions' tab above.