Mediix Recruitment Pty Ltd manages personal information and is an identified entity in accordance with the Privacy Act 1988. This Policy addresses our compliance with the Australian Privacy Principles (APPs) and applies to information collected by Mediix Recruitment Pty Ltd and all our operations in Australia.
As an identified entity we are also responsible for the protection of any personal information collected and comply to the best of our abilities with the Identifiable Data Breaches Scheme.
Mediix Recruitment Pty Ltd is a national On Hire Employer and collects personal information such as Tax File Numbers (TFN’s). As such we are a Lawful Tax File Number Recipient.
We only collect information that is reasonably necessary for the proper performance of our activities or functions. We do not collect personal information just because we think it could be useful at some future stage if we have no present need for it. We may decline to collect unsolicited personal information from or about you and take steps to purge it from our systems.
By following the links in this document, you will be able to find out how we manage your personal information as an APP Entity under the APP.
Mediix Recruitment falls within the Australian Privacy Principles (APP) and manages personal information, in compliance with the Australian Privacy Principles as an APP Entity, under the
Australian Privacy Principles APP. As we are a contracted service provider to a range of Commonwealth, State and Territory government agencies, it sometimes becomes necessary for us to collect and manage personal information as an Agency under different privacy arrangements. If you wish to know whether this applies to you, please contact us.
This Privacy Policy and Collection Statement explains how we collect information, including your personal information, and how we maintain, use and disclose that information. It also provides some details about your privacy rights along with our general rights and obligations in relation to the information we keep on record.
When we collect your personal information:
Personal information that we collect, and hold is information that is reasonably necessary for the proper performance of our functions and activities as a Recruitment Service Provider, and is likely to differ depending on whether you are:
The type of information that we typically collect and hold about Job Seekers is information that is necessary to assess the amenability to work offers and work availability; suitability for placements; or to manage the performance in work obtained through us and includes:
The type of information that we typically collect and hold about Clients, is information that is necessary to help us manage the presentation and delivery of our services and includes:
PRIVACY POLICY & COLLECTION STATEMENT
The type of information that we typically collect and hold about Referees, is information that is necessary to help to make determinations about the suitability of one of our Job Seekers for particular jobs, or particular types of work and includes:
The purposes, for which we collect, hold, use and disclose your personal information are likely to differ depending on whether you are:
The following sections are also relevant to our use and disclosure of your personal information:
Information that we collect, hold, use and disclose about Job Seekers is typically used for:
Personal information that we collect, hold, use and disclose about Clients is typically used for:
Personal information that we collect, hold, use, and disclose about Referees is typically used for:
PRIVACY POLICY & COLLECTION STATEMENT
We may utilise your information for direct marketing purposes. In addition:
The means by which we will generally collect your personal information is likely to differ depending on whether you are:
We sometimes collect information from third parties and publicly available sources when it is necessary for a specific purpose such as checking information that you have given us, or where you have consented, or would reasonably expect us to collect your personal information in this way.
Sometimes the technology that is used to support communications between us will provide personal information to us – see the section in this policy on Electronic Transactions. Please also see the section on Photos and Images.
Personal information will be collected from you directly when you fill out and submit one of our application forms, apply on line, email your information directly to us, or provide us with any other information in connection with your application to us for work.
Personal information is also collected when:
We may also collect personal information about you from a range of publicly available sources, including newspapers, journals, directories, the Internet and social media sites. When we collect personal information about you from publicly available sources for inclusion in our records, we will manage the information in accordance with the Australian Privacy Principles APP and our Privacy Policy.
Personal information about you may be collected when:
PRIVACY POLICY & COLLECTION STATEMENT
We may also collect personal information about you from a range of publicly available sources, including newspapers, journals, directories, the Internet and social media sites. When we collect personal information about you from publicly available sources for inclusion in our records, we will manage the information in accordance with the Australian Privacy Principles APP and our Privacy Policy.
Personal information about you may be collected when you provide it to us:
We may also collect personal information about you from a range of publicly available sources, including newspapers, journals, directories, the Internet and social media sites. When we collect personal information about you from publicly available sources for inclusion in our records, we will manage the information in accordance with the Australian Privacy Principles APP and our Privacy Policy.
We will not request that you supply photographs, scan photo ID, or capture and retain video image data of you in cases where simply sighting photographs or proof of identify documents would be sufficient in the circumstances.
Sometimes, we collect personal information that individuals choose to give us via online forms or by email, or during a telephone conversation, for example when individuals:
It is important that you understand that there are risks associated with use of the Internet and you should take all appropriate steps to protect your personal information. It might help you to look at the QAIC’s resource on Internet Communications and other Technologies.
When you visit the Mediix Recruitment website, we record anonymous information such as the date and time of your visit, the server/IP address, which site was visited, and the information viewed and/or downloaded. The information gathered cannot be directly matched to an individual and
PRIVACY POLICY & COLLECTION STATEMENT
Only used for administration and statistical purposes such as error logging. The information cannot tell us anything about you; it can only tell us about how you used our web site. This information can help us determine what areas of our website are most beneficial to our visitors. No attempt is made by Mediix Recruitment to identify users or their browsing activities.
If you visit the Candidate Registration website and register on-line for employment opportunities or visit the client resources site to register a vacancy, we do collect some personal information about you which you volunteer by filling in your details. The information required may include providing basic personal details such as your name, address, phone number and email address etc. You may also submit your resume or a position description. The information gathered at this point is stored in our database for retrieval and use by Mediix Recruitment staff only for the purposes for which it was intended. By submitting your personal information in this way, you acknowledge and accept our Privacy Policy and Collection Statement.
When submitting a time sheet, the information is transmitted directly to our payroll division, where it is only used for the intended purpose and is not disclosed to anyone outside the organisation. There is no collection of personal information until you have completed the time sheet and submit to Mediix Recruitment for processing.
We do not disclose any information gathered about your visit to our website, or personal information that you provide through the Candidate Registration process, such as your name, address etc. to any other organisation outside Mediix Recruitment unless you give your express consent, or if we are required to do so by law.
At times you may forward an email to us via the email link in our website. The information collected through this email will only be used for the purpose for which you have provided it.
Personal information is held in our Information Record System until it is no longer needed for any purpose for which it may be used or disclosed, at which time it will be de-identified or destroyed, provided that it is lawful for us to do so.
We take a range of measures to protect your personal information from:
We take all reasonable steps to ensure our Information Record System is compliant and secure:
We undertake several security measures in relation to Information Security, including:
PRIVACY POLICY & COLLECTION STATEMENT
We may disclose your personal information for any of the purposes for which it is primarily held or for a lawful related purpose. We may disclose your personal information where we are under a legal duty to do so.
Disclosure will usually be:
We outsource a number of services to contracted service providers (CSPs) from time to time. Our CSPs may see some of your personal information. Typically, CSP’s would include:
We take reasonable steps to ensure that terms of service with our CSPs recognise that we are bound by obligations to protect the privacy of your personal information and that they will not do anything that would cause us to breach those obligations.
Your personal information is not likely to be disclosed to overseas recipients. However, in the event that it is, we cannot guarantee that any recipient of your personal information will protect it to the standard to which it ought to be protected. The costs and difficulties of enforcement of privacy rights in foreign jurisdictions and the impracticability of attempting to enforce such rights in some jurisdictions will mean that in some instances, we will need to seek your consent to disclosure.
Subject to some exceptions set out in privacy law, you can gain access to your personal information that we hold.
PRIVACY POLICY & COLLECTION STATEMENT
Important exceptions include:
In many cases, evaluative material contained in references that we obtain will be collected under obligations of confidentiality that the person who gave us that information is entitled to expect it will be observed. We do refuse access if it would breach confidentiality.
For more information about access to your information refer to our Access Policy.
For more information about applying to correct your information refer to our Correction Policy.
If you wish to obtain access to your personal information you should contact our Privacy Co-ordinator.
You will need to be able to verify your identity.
Subject to some exceptions which are set out in the Australian Privacy Principles (APP:12) APP, you have a right to see a copy and have a copy of personal and sensitive information about you that we hold.
If you wish to exercise your rights of access and correction, you should contact our Privacy Co-ordinator, whose details are shown below. You will need to be able to verify your identity. We will make every effort to respond to your access request within 10 business days of receipt of your request.
Should you be unsatisfied with respect to the handling of your personal or sensitive information, you can make a complaint to the Office of the Australian Information Commissioner OAIC Complaint.
Subject to some exceptions, which are set out in the Australian Privacy Principles (APP:13) APP, you have a right to correct personal and sensitive information about you that we hold.
If you find that personal information that we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to correct it by contacting us. You will need to verify your identity. We will make every effort to respond to your access request within 3 business days of receipt of your request.
If you are able to establish that personal or sensitive information that we hold about you is not accurate, complete and up to date, we will take reasonable steps to correct that information, so it is accurate, complete and up to date.
If we are unable to agree that personal or sensitive information that we hold about you is accurate, complete and up to date, you may ask us to attach information by way of a statement by you, which claims that particular information is not accurate, complete and up to date.
If we have disclosed personal information about you that is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to notify the third parties to whom we have made the disclosure and we will take such steps (if any) as are reasonable in the circumstances, to give that notification, unless it is impracticable or unlawful to do so.
PRIVACY POLICY & COLLECTION STATEMENT
We will take such steps as are reasonable in the circumstances to correct that information to ensure that, having regard to the purposes for which it is held, the information is accurate, up to date, complete, relevant and not misleading.
Should you be unsatisfied with respect to the handling of your personal or sensitive information, you can make a complaint to the Office of the Australian Information Commissioner OAIC Complaint.
We are committed to abiding by the terms set out in this document. However, if something does go wrong and you have a privacy related complaint, please let us know as it gives us the opportunity to address the problem.
You have a right to complain about our handling of your personal information if you believe that we have interfered with your privacy.
For more information about our Complaints Procedure, see below.
If you are making a complaint about our handling of your personal information, it should first be made to us in writing.
You can make complaints about our handling of your personal information to our Privacy Co-ordinator, [email protected].
You can also make complaints to the Office of the Australian Information Commissioner, OAIC Complaint.
NOTE: The Associate Code and Dispute Resolution Rules do NOT constitute a recognised external dispute resolution scheme for the purposes of the APPs; but are primarily designed to regulate the good conduct of the Association’s members.
PRIVACY POLICY & COLLECTION STATEMENT
If the complaint cannot be resolved by means that we propose in our response, we will suggest that you take your complaint to any recognised external dispute resolution scheme to which we belong, or to the OAIC Complaints.
If at any time our policy changes, the updated details will be available on our website for your perusal. If at any time you have a question or concern regarding Mediix Recruitment and privacy, please contact us.
Mediix Recruitment Pty Ltd takes reasonable steps to handle personal information in accordance with the APPs. This includes protecting personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
A data breach is unauthorised access to or unauthorised disclosure of your personal information, or a loss of your personal information, that Mediix Recruitment Pty Ltd holds.
Please refer to Appendix A which outlines our Policy in the event of a breach.
Mediix Recruitment Pty Ltd is a National On Hire Employer and as such collects personal information such as Tax File Numbers (TFN’s). As a result of this we are considered under the Privacy Act 1988 to be a ‘lawful Tax File Number Recipient’ and as such comply with the TFN Rule.
Please refer to Appendix B.
If you wish to contact us about your personal information you should contact Mediix Recruitment, on +61427181818, during normal office hours, which are Monday to Friday 8.00am – 5.00pm.
If you need to contact us about your personal or sensitive information urgently outside normal office hours, you should email us on [email protected].
PRIVACY POLICY & COLLECTION STATEMENT
A Data breach occurs when personal information held by Mediix Recruitment Pty Ltd is subject to unauthorised access or disclosure or is lost.
We collect personal information in relation to candidates and employees. We are aware that this information can become personal information when it is combined with other information if this combination of information results in an individual becoming ‘reasonably identifiable’ as a result of the combination.
Personal Information is information about an identified individual, or an individual who is reasonably identified. Personal Information is defined by the Privacy Act 1988 as:
Information or an opinion about an identified individual, or an individual who is reasonably identifiable:
A data breach may be caused by malicious action (by an external or insider party), human error, or a failure in information handling or security systems.
Example of a data breach:
We minimises the risk of harm to an individual as a result of a data breach by following and upholding the thirteen Australian Privacy Principles (APPs) as per the Privacy Act 1988.
A Data Breach will have occurred when the following are met:
To reduce the risk of harm we will notify the individual of the data breach if it has been assessed that serious harm is likely, to enable the individual to take steps to reduce their risk of harm. For example, changing their passwords or being aware of the scam or identity fraud.
If a suspected or known data breach has occurred our response plan will be actioned. The Data Breach Response Plan consists of four (4) sections being Contain, Assess, Notify and Review as detailed below.
PRIVACY POLICY & COLLECTION STATEMENT
1: Contain
We will take immediate steps to contain the suspected or known breach where possible. Immediate shutdown of further access to the affected personal information will be actioned as soon as the breach is recognised.
2: Assess
We will assess whether the data breach is likely to result in serious harm to any individuals whose information was involved in the breach. If there are reasonable grounds the breach could cause harm we will notify the individual. If we suspect harm could be caused, we will undertake an assessment to consider if remedial action is required.
3: Notify
We are required to notify individuals and the Commissioner about data breaches that are likely to result in serious harm.
We will notify individuals in the event of a data breach after an assessment has been undertaken by the Director or other authorised representative of Mediix Recruitment Pty Ltd.
Notification will ONLY be made after it has been assessed that serious harm is likely.
4: Review
We will undertake a review which will involve:
A review of service delivery partners that were involved in the breach.
Mediix Recruitment Pty Ltd, is a Tax File Number (TFN) Recipient. As such, we collect TFN information and are in possession of these records and control the related information.
We apply our Notifiable Data Breach Scheme Policy and Data Breach Response Plan to any suspected or known data breaches relating to TFN information.
To further protect our employee’s information we have implemented the following: