1. PURPOSE

Precision Group is committed to protecting the privacy and security of Personal Information entrusted to us by our clients.

Precision Group does not generally collect Personal Information directly from individuals. Instead, we process Personal Information provided by our clients solely for the purpose of delivering contracted products and services.

This Policy outlines how Precision Group manages Personal Information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Privacy and Other Legislation Amendment Act 2024, ISO/IEC 27001 and ISO/IEC 27701.

 

2. SCOPE

This Policy applies to:

  • all employees
  • contractors
  • temporary staff
  • consultants
  • approved service providers
  • who access or process Personal Information on behalf of Precision Group
 

3. PERSONAL INFORMATION

Personal Information includes any information or opinion that identifies, or could reasonably identify, an individual.

Examples include:

  • names
  • addresses
  • telephone numbers
  • email addresses
  • customer identification numbers
  • financial information
  • health information
  • other information supplied by clients
 

3. COLLECTION AND USE

Precision Group generally does not collect Personal Information directly from individuals except where required for employment purposes.

Personal Information is supplied by clients solely for the purpose of performing agreed services. Precision Group will:

  • only use Personal Information for authorised client purposes
  • not use Personal Information for marketing
  • not sell, share or disclose Personal Information except:

     o where authorised by the client;

     o where required by law; or

     o where necessary to engage an approved service provider under appropriate contractual protections

 

5. INFORMATION SECURITY

Precision Group protects Personal Information using reasonable technical and organisational security measures including:

  • restricted access
  • user authentication
  • encryption where appropriate
  • network security controls
  • secure transmission methods
  • physical security
  • staff confidentiality obligations
  • information security awareness training
  • regular monitoring and risk management
 

6. DATA RETENTION AND DESTRUCTION

Unless otherwise agreed with the client or required by law:

  • Personal Information is retained only for the period necessary to complete contracted services.
  • Client data is permanently and securely deleted after 30 days following completion of the contracted work (or as agreed with client)
  • Secure destruction methods are used to prevent recovery of information
 

7. DATA BREACHES

Any suspected or actual privacy breach must be reported immediately.

Precision Group will investigate all incidents and, where an eligible data breach has occurred, comply with the Notifiable Data Breaches Scheme, including notification to affected clients, the Office of the Australian Information Commissioner (OAIC) and affected individuals where required by law.

 

8. ACCESS AND CORRECTION

As Precision Group generally processes Personal Information on behalf of clients, requests for access to or correction of Personal Information should be directed to the relevant client.

Where appropriate, Precision Group will assist clients in responding to such requests.

9. COMPLAINTS

Privacy complaints should be submitted to Precision Group’s Privacy Officer.

E – privacyofficer@thepg.com.au
P – (03) 9490 1500

Complaints will be investigated promptly and responded to within a reasonable period.

If a complainant is dissatisfied with the outcome, they may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).