Client Privacy Policy
Policy GRS-CPP-06 · Approved by the Board 01/07/2023 · Responsible person: GPCC
1. Introduction
Global Rehabilitation Service Pty. Ltd (GRS) has responsibility to ensure all GRS clients' privacy is well protected throughout the course of receiving our service.
Who should read this Privacy Policy?
You should read this policy if you are:
- an individual whose personal information may be given to or held by GRS;
- a GRS staff member;
- a volunteer or trainee with GRS.
The Privacy Act 1988
The Privacy Act 1988 (the Privacy Act) regulates how private sector organisations can collect, hold, use and disclose personal information, and how you can access and correct that information. Personal information is information in any form that can identify a living person.
The Privacy Act applies only to information about individuals, not to information about corporate entities such as businesses, firms or trusts. Detailed information on the Privacy Act is available on the Office of the Australian Information Commissioner (OAIC) website.
1.1 GRS and privacy
This Privacy Policy sets out how GRS complies with the Privacy Act. In performing its functions, GRS may collect, hold, use or disclose your personal information to a third party with your consent. GRS takes privacy seriously and will only collect, hold, use and disclose your personal information in accordance with the Privacy Act. If GRS does not receive personal information about you, the Privacy Act will not apply.
1.2 Remaining anonymous or using a pseudonym
GRS understands that anonymity is an important element of privacy, and some members of the public may wish to remain anonymous when interacting with GRS. GRS also understands some GRS clients may wish to use a pseudonym. Generally, GRS clients will have the right to remain anonymous or adopt a pseudonym when dealing with GRS. However, it is not always possible to remain anonymous or adopt a pseudonym, and GRS will inform you when this is the case.
1.3 Information covered under this Privacy Policy
This Privacy Policy covers how GRS collects, holds, uses and discloses your personal information, including any financial information you provide to GRS. This Policy applies to all personal information collected by GRS, including personal information collected through our website and any third party service provider (e.g. your GP or support coordinator).
1.4 Information held by GRS staff
Under the Privacy Act, GRS is required to take contractual measures to ensure GRS staff (including sub-contractors) comply with the same privacy requirements applicable to GRS.
2. GRS's personal information handling practices
2.1 Collection of personal information
GRS may collect personal information about you from you, your representative or a third party. We generally use emails, our official website and face-to-face assessment to collect this information, and store it securely on our cloud-based filing system electronically. GRS may also obtain personal information collected by other authorised service providers, such as your GP, support coordinator, and previous therapeutic support providers.
GRS collects and holds a broad range of personal information in records relating to:
- employment and personnel matters for GRS staff and contractors (including working with children/vulnerable people screening assessments)
- the performance of GRS's legislative and administrative functions
- individuals participating in the NDIS
- the management of contracts and service agreements
- the management of internal audits and external audits required by the NDIS Quality and Safeguards Commission
- correspondence from third party service providers
- complaints (including privacy complaints) made and feedback provided to GRS
- requests made to GRS under the Freedom of Information Act 1982 (Cth)
- the provision of legal advice by internal and external lawyers.
GRS will not ask you for any personal information which we do not need. The Privacy Act requires that we collect information for a purpose that is reasonably necessary for, or directly related to, a function or activity of GRS.
When GRS collects personal information, we are required by the Privacy Act to notify you of a number of matters. These include the purposes for which we collect the information, whether the collection is required or authorised by law, and any person or body to whom we usually disclose the information. GRS generally provides this notification through Privacy Notices before our interventions.
2.2 The NDIS Act also protects personal information
The secrecy provisions in the NDIS Act also protect personal information collected by GRS. These provisions set out rules for the collection, use and disclosure of this information, and operate together with the rules in the Privacy Act.
2.3 Kinds of personal information collected and held
In performing its functions, GRS collects and holds the following kinds of personal information (which will vary depending on the context of the collection):
- name, address and contact details (e.g. phone, email and fax)
- photographs, video recordings and audio recordings of you with your prior verbal/written consent
- information about your personal circumstances (e.g. marital status, age, gender, occupation, accommodation and relevant information about your partner or children)
- information about your financial affairs (e.g. your financial intermediary and NDIS plan details)
- information about your employment (e.g. work history)
- information about your background (e.g. educational qualifications, the languages you speak and your English proficiency)
- government identifiers (e.g. your NDIS reference number)
- information about assistance provided to you under the NDIS.
On occasions, GRS may collect or hold some sensitive information about you, including information about:
- your racial or ethnic origin;
- your health (including your medical history and any disability or injury you may have);
- the supports or services you receive, including under the NDIS, and information about the people who provide those supports or services to you; and
- any criminal record you may have.
2.4 How GRS collects and holds personal information
GRS collects personal information through a variety of different methods, including:
- paper-based forms
- electronic forms (including online forms)
- face to face meetings
- telephone communications
- email communications
- GRS's website and social media accounts.
GRS holds personal information in a range of paper-based and electronic records. Storage of personal information (and its disposal when no longer required) is managed in accordance with the Australian Government records management regime, including the Archives Act 1983, Records Authorities and General Disposal Authorities. This ensures that we hold your personal information securely.
2.5 Purposes for which personal information is collected, held, used and disclosed
GRS collects and holds personal information for a variety of purposes relating to its functions and activities, including:
- performing its clinical service, including delivering assessment and intervention
- performing its employment and personnel functions in relation to its staff and contractors
- performing its legislative and administrative functions
- policy development, research and evaluation
- complaints handling
- service agreement management.
GRS uses and discloses personal information for the primary purposes for which it is collected. We will give you information about the primary purpose of collection at the time the information is collected. GRS will only use your personal information for secondary purposes where it is able to do so in accordance with the Privacy Act.
2.6 How to seek access to and correction of personal information
You have a right under the Privacy Act to access personal information held about you, and to request corrections to any personal information GRS holds about you if you think it is inaccurate, out-of-date, incomplete, irrelevant, or misleading. However, the Privacy Act sets out circumstances in which GRS may decline access to or correction of personal information (e.g. where access is unlawful under a secrecy provision in portfolio legislation, or where the information held is an opinion rather than an objective fact).
To access or seek correction of personal information we hold about you, please contact us using the details set out in section 5.1 below. It is also possible to access and correct documents held by GRS under the Freedom of Information Act 1982 (the FOI Act).
2.7 Accidental or unauthorised disclosure of personal information
GRS will take seriously and deal promptly with any accidental or unauthorised disclosure of personal information. GRS follows the OAIC's Data Breach Notification guide when handling accidental or unauthorised disclosures of personal information. Legislative or administrative sanctions, including criminal sanctions, may apply to unauthorised disclosures of personal information.
2.8 Data security
Access to personal information held within GRS is restricted to authorised persons who are GRS staff or contractors. Electronic and paper records containing personal information are protected in accordance with suitable electronic medical record security policies. GRS regularly conducts audits to ensure we adhere to our protective and computer security policies.
2.9 Our website
This website is managed internally by GRS staff. Generally, GRS only collects personal information from its website where a person chooses to provide that information. If you visit our website to read or download information, GRS records a range of technical information that does not reveal your identity, including your IP or server address, your general locality, and the date and time of your visit. This information is used for statistical and development purposes. No attempt is made to identify you through your browsing other than in exceptional circumstances, such as an investigation into improper use of the website.
Some functionality of the GRS website is not run by GRS, and third parties may capture and store your personal information outside Australia. These third parties include (but are not limited to) Facebook, Wix, Google, Dropbox, 123 Forms, VINCI, and Powerdiary, and may not be subject to the Privacy Act. GRS is not responsible for the privacy practices of these third parties and encourages you to examine each website's privacy policy and make your own decisions regarding their reliability.
The GRS website might contain links to other websites. GRS is not responsible for the content and privacy practices of other websites and encourages you to examine each website's privacy policy and make your own decisions regarding the reliability of material and information found.
2.10 Cookies
Cookies are used to maintain contact with a user through a website session. A cookie is a small file supplied by GRS and stored by your web browser software on your computer when you access the GRS website. Cookies allow GRS to recognise an individual web user as they browse the GRS website.
2.11 Electronic communication
There are inherent risks associated with the transmission of information over the internet, including via email. You should be aware of this when sending personal information to us by email or through the GRS website. If this concerns you, you may prefer to use other methods of communication with GRS, such as post, fax, or phone (although these methods have associated risks). GRS only records email addresses when a person sends a message. Any personal information provided, including email addresses, will only be used or disclosed for the purpose for which it was provided.
2.12 Disclosure of personal information overseas
On occasions, GRS may disclose personal information to recipients who are overseas. Situations in which GRS may transfer personal information overseas include:
- the provision of personal information to overseas researchers or consultants (where consent has been given or GRS is otherwise legally able to provide this information);
- the provision of personal information to recipients using a web-based email account where data is stored on an overseas server; and
- the provision of personal information to foreign governments and law enforcement agencies (in limited circumstances and where authorised by law).
It is not practicable to list every country to which GRS may provide personal information, as this will vary depending on the circumstances. However, you may contact GRS (using the details in section 5.1) to find out which countries, if any, your information has been given to.
3. Complaints
3.1 How to make a complaint
If you think GRS may have breached your privacy rights, you may contact us using the details set out in section 5.2 below.
3.2 GRS's process for handling complaints
The relevant GRS area service manager will respond to your complaint or request promptly if you provide your contact details. We are committed to the quick and fair resolution of any complaints and will ensure your complaint is taken seriously. You will not suffer negative treatment as a result of making a complaint. Details of our complaint policy are available in the GRS Compliments and Complaints Policy.
3.3 How to complain to the Office of the Australian Information Commissioner (OAIC)
You also have the option of contacting the OAIC if you wish to make a privacy complaint against GRS, or if you are not satisfied with how we have handled a complaint made to us in the first instance. The OAIC website contains information on how to make a privacy complaint. If you make a complaint directly to the OAIC rather than to GRS, the OAIC may recommend you try to resolve the complaint directly with GRS first.
4. Privacy policy updates
We will review this Privacy Policy regularly and update it as required.
5. How to contact us
5.1 General enquiries and requests to access or correct personal information
If you wish to:
- query how your personal information is collected, held, used or disclosed
- ask questions about this Privacy Policy
- obtain access to or seek correction of your personal information
please contact the GRS administrative team using the following details:
- Email: admin@grs.health
- Telephone: 1300 066 716
5.2 Contact details for privacy complaints
If you wish to make a complaint about a breach of your privacy, please contact the GRS management team using the following details:
- Email (NSW): info.nsw@grs.health
- Email (QLD): info.qld@grs.health
- Online feedback/complaint form: grs.health/feedback-and-complaint
5.3 Availability of this Policy
If you wish to access this Policy in an alternative format (e.g. hard copy), please contact GRS using the details set out in section 5.1 above.
Global Rehabilitation Service Pty. Ltd. · ABN 51626759019
Approved by the Board on 01/07/2023 · Scheduled review 02/05/2025