Platinum Certification AQA Pty Ltd is an entity under section 6(1) of the Australian Privacy Act 1988 (Privacy Act). As an entity under the Privacy Act, Platinum Certification AQA ensures that all personal information is managed according to the Australian Privacy Principals (APPs). Platinum Certification AQA fosters a culture of privacy, and treats all personal information gathered as part of audit and other activities as a valuable business asset to be respected, managed and protected. With this in mind Platinum Certification AQA takes all reasonable steps to manage personal information in an open, secure and transparent manner. The CEO will be the designated privacy officer who manages all privacy matters. This Privacy Policy is available on the Platinum Certification AQA website and is on public display. We will make available to all clients and prospective clients of Platinum Certification AQA a copy of our Privacy Policy, upon request.

Personal and sensitive information collected by Platinum Certification AQA includes:

  • Contact details, such as name, address, phone numbers and email address;
  • Personal details, such as date of birth, gender, employment history, educational qualifications;
  • Photos, videos and other reasonably identifiable electronic media;
  • Commonwealth, State or organisational generated personal identifiers and codes;
  • Credentialing and probity information required by Commonwealth or State Child Protection or
  • Disability regulation (e.g. Working with Children Check, National Police Check, Drivers’ License,
  • Working with Vulnerable Persons check);
  • Memberships and registrations with professional bodies;
  • Any current conflicts of interest including information about an individual’s membership or leadership of an association or company;
  • Bank account, credit card and other financial details; and
  • Details of complaints or requests to access information.

Collection of solicited sensitive personal information

Sensitive personal information includes:

  • Medical or health information;
  • Ethnic origin; and
  • Religious affiliation.

Platinum Certification AQA collects information from an individual or company by way of:

  • Required company forms and e-forms, for example personal onboarding information, audit certification registration, audit schedules and client lists, contractor tax details and invoices etc.
  • Meetings, interviews or telephone calls recorded with an individual or company representative;
  • Business cards received from an individual or company representative;
  • Registration details for online information or e-newsletters provided by an individual or company representative;
  • Website access where this privacy policy is located or linked; and
  • Publicly available records.

Platinum Certification AQA’s also collects personal information:

  • Through Auditor contractors who perform audit services, such as – during the delivery of an audit activity, gathering and viewing relevant information to complete reports, interviewing participants, families, advocates and staff of organisations to verify compliance;
  • To meet the requirements of specific standards and regulatory frameworks; and
  • Through Commonwealth and state government departments and agencies, and through Platinum Certification external and internal Business partners.

Collection of solicited information for children or vulnerable individuals

  • Personal and sensitive information is only collected for some certifications audit activities;
  • All information collected uses client generated codes to preserve individual anonymity;
  • All information collected, in electronic or hard copy, is kept in password protected files; and
  • All employees and contractors have current Working with Children Checks and National Police Checks and sign a Code of Conduct and strict Confidentiality and Fit and Proper Personas declarations at induction.

Consent to collect, hold, use, disclose and dispose of personal information

Platinum Certification AQA uses all reasonable means to seek consent from individuals or companies involved in audit or business activities to collect, hold, use, disclose and dispose of personal and sensitive information that is reasonably identifiable under the Privacy Act. Consent will be sought in writing wherever possible, or verbally where the individual may be witnessed by an identified advocate or person responsible.

Use and of personal information

Platinum Certification AQA takes all reasonable steps to ensure that all personal information held in electronic or hard copy is only used for the following circumstances:

  • Workforce management and planning;
  • Contract management;
  • Audit activities;
  • Reporting activities;
  • Emergency and crisis management;
  • Mandatory reporting and other regulatory or legislative requirements;
  • Risk management;
  • Gathering research data for internal measurement and sector development; and
  • Quality control activities.

Disclosure of personal information

Platinum Certification AQA has a process available for an individual or a regulatory agency to make an access request.

Platinum Certification AQA discloses personal information in the following circumstances:

  • Identity of the individual who requests to access own information is verified using APP guidelines;
  • Request from a verified officer of a government agency for the purposes of mandatory reporting, other illegal conduct or fraud; and
  • Court subpoena.

Platinum Certification AQA will not adopt a government related identifier of an individual as an internal identifier for business or audit activities, or use or disclose a government related identifier at any time.

Security and protection of personal information

Platinum Certification AQA takes all reasonable steps to protect and secure the personal information held from misuse, interference, loss and from unauthorised access, modification and disclosure.

Platinum Certification AQA will also destroy and de-identify personal information held once it is no longer required for business and audit purposes.

All personal information collected by Platinum Certification AQA is held electronically on Platinum Certification AQA secure information systems of Secured personal information can only be accessed by authorised employees with password controls. Contractors who require personal information access for client audit activities will have time limited access only.

All employees ,contractors and committee members undertake induction and continual training in the Platinum Certification AQA Privacy Policy and procedures to promote a culture of privacy and maximise the protection of individual and sensitive information.

De-identification and destruction of personal information

Personal or sensitive information gathered about client’s participants (including children and vulnerable persons) and employees as part of audit activities, will be de-identified at all times and will be destroyed or deleted within 30 days of NDIS Commission granting certification to a client. Some personal information may be held for business purposes only including employee and contractor information.

Anonymity and pseudonymity

Platinum Certification AQA, in order to verify evidence for certification frameworks, will make available options for anonymity to clients’ participants (customers), employees, volunteers and other parties who will be required to supply personal and some sensitive data during audit activities.

Unsolicited information

Platinum Certification AQA does not use direct marketing processes or disclose personal or sensitive information to any overseas parties or organisations. From time-to-time unsolicited information can be received by employees and contractors in the course of audit activities. Unsolicited information is maintained securely in the same manner as all other information and follows our strict digital and document processes.

Quality of personal information

Platinum Certification AQA will take reasonable steps to ensure that all personal information collected during business or audit activities is accurate, current and complete.

In any exceptional circumstances requiring disclosure of personal or sensitive information, Platinum Certification AQA will ensure that all reasonable steps are taken to disclose the most current information that is available. This includes contacting the client or individual to obtain current information, as required.

Requests for access to personal information

  • Platinum Certification AQA is committed to open and transparent information management. As such we support any individual who requests access to any personal information held by our company.
  • Platinum Certification AQA has a process in place that ensures:
  • Requests can be made in person, by phone or in writing including email;
  • Each individual identity is verified by the CEO using current identity documents or persons responsible in specific cases;
  • The CEO will be responsible to maintain information confidentiality and security,
  • All requests will be responded to and responses will be in writing and signed by the CEO;
  • Any information contained in documents held that identify other persons or other non-relevant information will have that information deleted;
  • The process will take no more than 30 days;
  • Where a person requests that their information be changed in any way the same process will be followed;
  • The requesting individual will be given information on making an internal and external complaint about any decision made at the time of the request and in the formal response letter; and
  • In any case of complaint an external mediator will be appointed to maintain impartiality.

Reviews and revisions

Platinum Certification AQA reviews its Privacy Policy annually or as required by regulatory changes.
Platinum Certification AQA also reserves the right to change its Privacy Policy at any time. Notifications about changes to this Privacy Policy will be communicated to all relevant stakeholders and an updated version posted prominently on our website.