Purpose
To manage personal information in compliance with the Privacy Act 2020, subsequent amendments and other relevant laws and regulations.
Application
This policy applies to all staff, programme participants, parents and caregivers who may require the collection, access, use or disclosure of personal information.
Policy
YMCA collects and processes personal information about program participants, staff members, clients, contractors, potential staff members and volunteers as necessary for the operation of the organisation and in compliance with the Privacy Act 2020 (the Act)
Procedure guidelines refer to the 13 Privacy Principles.
Disclosure of information
- No information will be shared with other agencies without the written consent of parents/guardians.
- Should the request be to support the safety of the child, i.e. from Oranga Tamariki or the Police, then information will be shared.
- Parents/ guardians and service staff will have the right to view and amend any information that is held about them or their child/children.
- Any personal information of staff will be stored in a locked cabinet accessible only by the manager or relevant administrator. HR information is kept in MyHR. A login and password are required.
Notifiable Reporting
- When a privacy breach has caused serious harm to someone (or is likely to do so), it is the responsibility of the centre to notify the Office of the Privacy Commissioner and the Ministry of Social Development – Te Manatū Whakahiato Ora as soon as possible.
- Notify all concerned parties that are affected by a privacy breach.
- It is an offence to fail to inform the Privacy Commissioner.
The Privacy Commissioner
- Has new powers to issue a Compliance Notice (directing an organisation to do or stop doing something) and Binding Access Determinations (requiring an organisation to release personal information), along with new finds for non-compliance with the Privacy Act.
- Be able to direct agencies to provide individuals with access to their personal information.
Complaints Procedure
Customers, staff, contractors or volunteers can lodge a formal complaint regarding the way personal information is collected, used or disclosed by contacting the General Manager, Education, gmeducation@ymcagisborne.nz
All complaints must be managed in accordance with the YMCA Feedback Procedure.
For self-help information and appropriate services from the Privacy Commissioner: www.privacy.org.nz/about us/contact
Key relevant documents:
- Privacy Act 2020
- MSD Accreditation Standards Level 3 and OSCAR
Collection of personal information
- All collection of personal information by staff or anyone working on behalf of YMCA Gisborne is governed by Privacy Act 2020 and any subsequent amendments.
- Staff must only collect personal information they need for a lawful purpose and the information is necessary for that purpose.
- Personal information should be collected directly from the individual concerned, unless an exception can be relied upon to collect it from a third party (exceptions are listed in Principle 2 of the Act). The usual basis on which we collect information from a third party is with the authorisation of the individual concerned.
- When collecting personal information, you will ensure the person is aware of:
• What information is being collected
• Why information is being collected
• Whether giving it is authorised/required by law, mandatory or voluntary
• Who the information will be shared with
• The rights of access and correction of information provided
• What will happen for the individual if all or part of the requested information is not provided.
The individual must be told the above information prior to collecting the information or, if this is not possible as soon as practicable after the information has been collected, unless exceptions apply (see Principle 3 of the Act). - Collection of personal information will be by lawful means, fair in the circumstances and not unreasonably intrusive, especially when collecting information from child and young people.
Personal information will not be kept longer than lawfully necessary (Principle 9).
• Staff files are held for 7 years and held in an inactive file in Myr or in the archive fault at the main YMCA
• Enrolment documents and records are held for 7 years to support audits and funding claims
• All physical documents no longer active will be shredded and inactive files and documents in MyHR will be deleted yearly after 7 years. - Before using the personal information, you must take reasonable steps to check it is accurate, complete, relevant, up to date, and not misleading.
- A unique identifier can only be assigned to individuals where it is necessary for operational functions and may not be the same identifier as used by another organisation and the risk of misuse (such as identity theft) is minimised.
Storage & security of personal information
- All staff have a responsibility to protect the personal information they handle against loss, misuse or unauthorised access, modification or disclosure.
- Staff must only access or use personal information when this is necessary for a legitimate business purpose.
- Managers who are responsible for collecting personal information as part of the organisation’s operations must ensure the personal information is protected by having reasonable security safeguards in place to prevent loss, misuse or disclosure of personal information. This includes limits on employee browsing of other people’s information.
- An individual’s personal information should not be kept longer than the YMCA Gisborne has a lawful purpose to use it.
- Staff must ensure any privacy breach they become aware of is reported promptly to the Privacy Officer YMCA CEO).
Access & correction of personal information
- Individuals have the right to request confirmation of and access to their personal information collected by YMCA Gisborne. In most cases the information will be given promptly, unless there are good reasons to refuse access (refer to Act).
- Individuals have the right to request the correction of the personal information held by YMCA Gisborne and must be advised at the time of requesting to access their personal information that they may request the correction of that information.
- Access to and correction of personal information is subject to the provisions of Part 4 of the Act. Any requests from individuals for confirmation of or access to their personal information should be referred to your manager and will be discussed with the Privacy Officer to ensure the Act is followed.
Limits on use & disclosure of personal information
- Except as provided in No. 13, personal information held by YMCA Gisborne should only be used or disclosed by staff if that use or disclosure is the purpose for which it was collected and has been made clear to the individual concerned in writing.
- Before using or disclosing personal information in new ways, or in ways that are not part of the organisation’s routine business, staff must ensure that this is necessary for a lawful purpose or is otherwise permitted or required by law. The best method to use or disclose information in new ways is for the individual to give permission. Staff must be able to rely on an exception to Principle 10 (use) or Principle 11 (disclosure) of the Act. Please check with your manager and the Privacy Officer.
- Prior to sharing personal information with a contracted service provider or disclosing personal information to someone overseas, the staff must ensure it is required, and they are able to provide adequate protection of the personal information shared (Principle 11 & 12 of the Act). Please check with the Privacy Officer if this is not clear.
- Requests for disclosure from third parties should be in writing, detailing the information required and the authority they must request disclosure. The individual concerned may be contacted to confirm release of information or informed of disclosure and included in correspondence relating to the release of information. If the request from the third party is unclear, further information should be sought in writing.
- Staff must take reasonable steps to ensure that personal information is accurate and up to date before using or disclosing it, particularly where this use or disclosure could impact on the rights or interests of the individual concerned.
Responsibilities
- Staff who need to collect, store, access or use personal information must adhere to the Information Privacy Principles contained in the Privacy Act 2020 and any subsequent amendments.
- Managers are responsible for ensuring that all systems, processes, and practices in the areas for which they are responsible conform to this policy
- Managers should support staff to understand and comply with this policy and the Privacy Act.
- New staff members will receive introductory Privacy training specific to their role.
- If staff have any questions about the interpretation of, or compliance with, the Privacy Act, they must, in the first instance, discuss them with their direct manager. If there is still uncertainty about interpretation, it must be referred to the Privacy Officer.
- Any requests for access or disclosures of personal information should be referred to the Privacy Officer or HR.
- Any privacy breaches or complaints should be reported promptly to the Privacy Officer as soon as possible.
- The Privacy Officer will support staff to understand and comply with the Privacy Framework.
- The Privacy Officer will assist with privacy breaches and issues and manage privacy complaints in compliance with the Privacy Act.
Reviewed: 7 February 2025 | Next review date: June 2028 | Approved by: Y Gisborne CEO & Senior Management
