LCIS Privacy and Confidentiality

Authority: Board

Responsibilities: All persons, businesses and/or organisations engaged with LCIS in any capacity. CEO and CIO (Chief Information Officer) are responsible for assessment, investigation, escalation, notification decisions and oversight of corrective actions relating to data breaches.

Purpose & Scope

  • The purpose of this document is to inform the types of information collected and why it is collected, how information is used, stored and how it is disposed of and how this may affect your privacy.
  • Laverton Community Integrated Services Inc. recognises the personal and confidential nature of staff / student / student placement / community worker / volunteer / participant / client information and records and is committed to maintaining the privacy of this information.
  • Your privacy is important, and breaches are considered serious. All complaints regarding possible privacy breaches can be made through the Office of the Victorian Privacy Commissioner.
  • LCIS is bound by the Privacy Act 1988 (Cth) and the Privacy and Data Protection Act 2014 (Vic). These laws protect the privacy of an individual’s personal information. LCIS also complies with the Health Records Act 2001 (Vic). LCIS manages personal information in accordance with the 13 Australian Privacy Principles (APPs) and relevant Victorian privacy legislation.
  • This policy also applies to the use of emerging technologies, including commercially available artificial intelligence (AI) tools, where personal or sensitive information may be processed.
  • Laverton Community Integrated Services Inc. is committed to working within current Privacy Legislation and will maintain everyone’s privacy in accordance with information privacy principles. The key elements are:
    • Collect only the information you need
    • Inform the person why you need the information and how you will use it
    • Disclose only as necessary for the purpose of the service, or by law
    • Secure information against unauthorised use/disclosure

Privacy by Design

LCIS is committed to embedding privacy considerations into the design, implementation and review of its programs, services, systems, technologies and business processes. Privacy, confidentiality and information security risks will be considered when introducing new systems, technologies, service providers or significant changes to the handling of personal information.

Use of Artificial Intelligence (AI)

LCIS recognises that Artificial Intelligence (AI) tools may provide administrative efficiencies but may also introduce privacy, confidentiality, information security and compliance risks.

LCIS will consider relevant guidance issued by the Office of the Australian Information Commissioner (OAIC) and any applicable contractual, legislative and regulatory requirements when considering the use of AI tools.

To ensure privacy and confidentiality are maintained:

  • Personal, sensitive or identifiable information relating to clients, participants, children, students, staff, volunteers or other individuals must not be entered into AI tools.
  • AI tools must not be used in connection with service delivery activities where personal or sensitive information is involved.
  • AI tools must not be used to make decisions that significantly affect individuals without appropriate human oversight.
  • Any use of AI tools must comply with applicable privacy legislation, Child Safe Standards, contractual obligations and LCIS policies and procedures.
  • LCIS recognises that AI tools may introduce risks including inaccurate information, bias, data breaches, unauthorised disclosure of information and loss of control over organisational data, and will take reasonable steps to mitigate these risks.
  • Any actual or suspected privacy, security or confidentiality incident involving an AI tool must be reported immediately and managed in accordance with the LCIS Data Breach Response Procedure and Information Security Management System (ISMS).

Personal Information

Personal Information is considered to be any information that can be used to personally identify you such as your name, address, telephone number, email address or occupation.

Many of our programs may require you be given forms to complete that request basic personal information, some of which may be considered as sensitive such as:

  • Name
  • Address (Both Street and PO Box)
  • Telephone Number
  • Email Address
  • Gender
  • Date of Birth
  • Citizenship/Residency status
  • Employment Status
  • Birth Country
  • Languages Spoken
  • Known disabilities
  • Indigenous status
  • Schooling level
  • Qualifications attained
  • Victorian Student Number (VSN)
  • Customer Reference Number (CRN)

Collection, Use and Disclosure

This information will be entered into the secure database systems maintained by LCIS, once paperwork is entered it will be securely destroyed unless otherwise required to meet regulatory or legislative compliance requirements.

When you give LCIS your personal information, we use this to:

  • Provide direct assistance to you
  • Allow you to access available programs
  • Check your eligibility for Government funding and services
  • Provide our funding bodies with statistical information to assist with future planning
  • Provide LCIS with statistical information to assist with future planning
  • Refer you to other services both internally and externally

It is important to be aware that information from enrolment / registration forms is stored on electronic systems and disclosed as statistical data for Government funding bodies. If you have enrolled for a course at the Education Centre, you may be contacted to give feedback about your experiences.

If you choose not to give personal information about yourself, it may mean:

  • You will not have access to certain services, or
  • You will be ineligible for funding or financial support
  • You will not have the ability to have certain training customised, or
  • You may not receive important related correspondence from us

Data Storage, Security and Disposal

All information collected by LCIS is stored in a secure environment and protected from unauthorised access, use, disclosure, modification or loss. Information may be stored in both electronic and physical formats.

Personal information is managed within the LCIS Information Security Management System (ISMS). Information is classified according to its sensitivity and business requirements, with access restricted to authorised personnel on a need-to-know basis and protected through appropriate administrative, physical and technical security controls.

LCIS manages the retention and secure disposal of information in accordance with the LCIS Data Retention and Disposal Policy.

Where personal information may be accessed, processed or stored by authorised contractors, consultants or service providers, including those located outside Australia, LCIS will take reasonable steps to ensure appropriate privacy, confidentiality and information security safeguards are in place, including contractual obligations, access controls and oversight arrangements.

LCIS will respond to any actual or suspected data breaches in accordance with applicable legislation, including the Notifiable Data Breaches (NDB) Scheme under the Privacy Act 1988 (Cth), the LCIS Data Breach Response Procedure and the LCIS Information Security Management System (ISMS).

In the event LCIS receives unsolicited personal information, reasonable steps will be taken to securely destroy or de-identify the information unless its retention is required by law.

Overseas Access and Disclosure of Information

LCIS may engage authorised contractors, consultants or service providers who are located outside Australia or who access LCIS systems from overseas locations.

Where personal information may be accessed, processed or stored outside Australia, LCIS will take reasonable steps to ensure appropriate privacy, confidentiality and information security safeguards are in place, including contractual obligations, access controls and oversight arrangements.

Staff/Volunteer Access to Personal Information

Access to personal, sensitive and confidential information will be restricted to authorised personnel who require access to perform their duties.

Authorised personnel are defined as approved Board members, the Chief Executive Officer (CEO), Chief Information Officer (CIO), Managers and other staff whose roles require access to information for operational, service delivery, compliance or governance purposes.

Access to physical and electronic records will be granted on a need-to-know basis and managed in accordance with LCIS privacy, confidentiality and information security requirements.

Board access to personal information will only be facilitated through the CEO or delegated authority where there is a legitimate governance, legal or organisational requirement.

Volunteer personal files will be securely maintained and access restricted to the Volunteer, Volunteer Coordinator, relevant Manager, CEO and other authorised personnel as required.

All Board members, staff, volunteers, students, contractors and service providers must respect the confidentiality of information obtained through their involvement with LCIS. Personal, sensitive or confidential information must not be disclosed to unauthorised persons or entered into unauthorised third-party systems, platforms or AI tools.

The LCIS Privacy & Confidentiality Policy is available to staff, volunteers, students, participants and clients.

Process

The LCIS Privacy & Confidentiality Policy will be made available to staff, volunteers, students, participants, clients and other relevant stakeholders through appropriate organisational channels.

The key elements of this policy will be included in relevant staff, volunteer, student and participant handbooks. The Privacy Statement (Appendix 2) will be displayed and made available throughout the organisation.

Access to personal, sensitive and confidential information is restricted to authorised personnel whose role requires access to perform their duties.

The following positions are authorised to access personal information as required:

  • CEO and CIO – Access to records as required for organisational management, governance, compliance and information security purposes.
  • Community Services Manager, Education Manager and Child Care Centre Manager – Access to records relevant to their area of responsibility.
  • Finance Officers – Access to staff personnel records and limited personal information required for financial and payroll administration.
  • VET and EAL Coordinators – Access to enrolment information and anonymous survey data.
  • Education Officer – Access to student and participant records and relevant management systems.
  • Administration Officers – Access to enrolment information and relevant management systems.
  • Crisis Intervention Workers – Access to client records relevant to service delivery.
  • L2P Staff – Access to participant records relevant to service delivery.
  • Volunteer Coordinator – Access to volunteer records and Emergency Relief client records.
  • Tutors – Access to relevant student and participant records.
  • Emergency Relief Volunteer Workers – Access to Emergency Relief client records as required.
  • Board Treasurer – Access to financial records.
  • Board Chair – Access to personnel records relevant to governance, critical incidents, industrial matters and other records in conjunction with the CEO.

Sources and Related Policies

Legislation

  • Privacy Act 1988 (Cth)
  • Privacy and Data Protection Act 2014 (Vic)
  • Health Records Act 2001 (Vic)
  • Notifiable Data Breaches (NDB) Scheme
  • Australian Privacy Principles (APPs)

Regulatory Guidance

  • Guidance on Privacy and the Use of Commercially Available AI Products – Office of the Australian Information Commissioner (OAIC)
  • General privacy guidance issued by the Office of the Australian Information Commissioner (OAIC)

Related LCIS Policies and Documents

  • LCIS Data Retention and Disposal Policy
  • LCIS Child Safety and Wellbeing Policy
  • LCIS Code of Conduct
  • LCIS Data Breach Response Procedure
  • LCIS Information Security Management System (ISMS)
  • ISMS-DOC-A05-12-1 Information Classification Procedure
  • ISMS-DOC-A05 15-1 Access Control Policy

Course Category

OUR CHILD SAFETY AND WELLBEING STATEMENT

  • We want children to be safe, happy, and empowered. We support and respect all children.
  • We are committed to the safety, participation, and empowerment of all children.
  • We have risk management strategies that focus on preventing, identifying, and mitigating risks to children and young people.
  • We have zero tolerance of child abuse. All allegations and safety concerns will be treated seriously and consistently with legislative requirements and our Policies and Procedures  .
  • Our staff and volunteers have a legal and moral obligation to contact authorities when we are worried about a child’s safety which we always follow.
  • We are committed to regularly training and educating our staff and volunteers on child abuse risks.