1. Actevate considers privacy as freedom from intrusion and public attention.
2. Confidentiality is the assurance that written and spoken information is protected from access and use by unauthorised persons. With respect to confidentiality, Actevate staff members are to refer to the Code of Conduct for Workplace Rehabilitation Providers and are to note that the disclosure or misuse of confidential information held on official records, including client files, is illegal.
3. Actevate recognises that each person has the right, in all aspects of their lives, to privacy, confidentiality and to be treated with dignity. The organisation is committed to protecting clients’ personal and health information. Actevate will ensure that its collection, documentation, use, disclosure, storage, access, correction, retention and disposal practices comply with the Australian Privacy Principles and, in relation to health information handled in New South Wales, the Health Privacy Principles under the Health Records and Information Privacy Act 2002 (NSW). Actevate will only collect information that is necessary for the provision of services to each client and will keep records in a standardised, accurate, objective and efficient manner. All client information will be kept in accordance with legal requirements, ensuring that the privacy and confidentiality of personal information is maintained at all times. Actevate will make information kept about a client available for that individual or their substitute decision makers to access at any time.
4. In compliance with the following legislation – Privacy Act 1988 (Cth), Health Records (Privacy and Access) Act 1997 (ACT), and the NSW Health Records and Information Privacy Act 2002 – our service adheres to the privacy principles as outlined in this policy.
The Australian Privacy Principles apply to personal information handled by Actevate under the Privacy Act 1988 (Cth).
Health information handled in New South Wales is also subject to the 15 Health Privacy Principles contained in Schedule 1 of the Health Records and Information Privacy Act 2002 (NSW). Health information includes information or an opinion about an individual’s physical or mental health, disability, expressed wishes about future health services, a health service provided or to be provided, and other personal information collected in connection with providing a health service.
Where more than one privacy requirement applies, Actevate will handle the information in a manner that complies with all applicable requirements. Where the requirements differ, Actevate will apply the requirement that provides the greater protection, unless otherwise required or authorised by law.
For services delivered in the Australian Capital Territory, Actevate will also comply with the Territory Privacy Principles and applicable health record requirements under the Health Records (Privacy and Access) Act 1997 (ACT).
In addition to the Australian Privacy Principles outlined below, Actevate applies the NSW Health Privacy Principles to health information as follows:
HPP 1: Lawful collection: Actevate will only collect health information for a lawful purpose that is directly related to its functions or activities and where the collection is reasonably necessary for that purpose. Information will be collected by lawful means.
HPP 2: Relevant collection: Actevate will take reasonable steps to ensure that health information collected is relevant, accurate, up to date, complete and not excessive, and that its collection does not unreasonably intrude into the individual’s personal affairs.
HPP 3: Direct collection: Health information will be collected directly from the individual where reasonable and practicable. Where information is obtained from another person or organisation, Actevate will ensure that the collection is authorised, consented to or otherwise permitted by law.
HPP 4: Open collection: At or before collection, or as soon as practicable afterwards, Actevate will take reasonable steps to explain why the information is being collected, its intended uses and recipients, whether collection is required or voluntary, any consequences of not providing it, Actevate’s contact details, and the individual’s access and correction rights. Reasonable notification will also be provided where health information is collected from a third party.
HPP 5: Secure storage: Health information will be protected through reasonable physical, technical and organisational safeguards against loss, unauthorised access, use, modification, disclosure or other misuse. Information will not be retained for longer than required and will be securely disposed of or de-identified when lawful and appropriate.
HPP 6: Transparency: On request, Actevate will take reasonable steps to explain whether it holds health information about an individual, the nature of that information, the purposes for which it is used, and the individual’s access rights.
HPP 7: Access: Individuals may request access to their health information without unreasonable delay or expense, subject to applicable legal exceptions and identity-verification requirements.
HPP 8: Correction: Individuals may request that their health information be amended where it is inaccurate, incomplete, irrelevant, out of date or misleading. Requests will be managed in accordance with applicable legislation.
HPP 9: Accuracy before use: Before using health information, Actevate will take reasonable steps appropriate to the circumstances to ensure it is relevant, accurate, up to date, complete and not misleading.
HPP 10: Limited use: Health information will generally only be used for the purpose for which it was collected or for a directly related purpose that the individual would reasonably expect. A secondary use requires consent unless it is otherwise authorised or permitted by law.
HPP 11: Limited disclosure: Health information will generally only be disclosed for the purpose for which it was collected or for a directly related purpose that the individual would reasonably expect. Any other disclosure requires consent unless it is otherwise authorised or permitted by law.
HPP 12: Identifiers: Actevate will only assign or use a unique identifier where this is reasonably necessary to carry out its functions efficiently.
HPP 13: Anonymity: Where lawful and practicable, individuals will be given the option of interacting with Actevate anonymously. Actevate may need to verify identity where this is required to provide workplace rehabilitation, assessment or other funded services.
HPP 14: Transferrals: Health information will only be transferred outside New South Wales where the requirements of HPP 14 are satisfied, including where the individual has consented, the transfer is necessary for an agreed service and appropriate safeguards apply, or the transfer is otherwise authorised or permitted by law. This includes consideration of cloud-based and AI service providers whose systems may process information outside New South Wales.
HPP 15: Linkage: Actevate will not include health information in a health records linkage system, or disclose an identifier for that purpose, without the individual’s express consent unless the linkage is otherwise authorised or permitted by law.
These requirements are applied together with the relevant APP provisions below. Exceptions will only be relied upon where supported by applicable legislation and appropriately documented.
This principle sets out how Actevate can use and disclose personal information. Health service providers need to be open about how they handle health information.
On first meeting with the client, staff / contractors of Actevate are to provide a copy of the Consent Form and Actevate Privacy Policy. Clients are to sign the Consent Form to indicate that they have consented to the referral to our service and that they have been informed about what information will be gathered about them during the assessment process and how that information will be utilised/stored.
a. Informing the person from whom information is collected
By providing the Privacy Policy and signing the Consent Form, Actevate will clarify with the client the accuracy of information received through the referral process and will make them aware:
Artificial Intelligence (AI) Usage
Actevate may use approved Artificial Intelligence (AI) technologies to support the delivery of workplace rehabilitation services and business operations. AI may assist with administrative tasks, documentation, drafting correspondence and reports, summarising information, transcription (where applicable), and improving operational efficiency.
AI technologies are used as support tools only and do not replace the professional judgement, clinical reasoning or decision-making of Actevate staff.
Where AI technologies are used, Actevate will take reasonable steps to ensure that:
Actevate does not use client information to train publicly available AI models. Where third-party AI providers are engaged, Actevate will take reasonable steps to ensure appropriate contractual, privacy and security safeguards are in place.
For clients receiving services, Actevate is required to identify them to funding bodies (insurers). It is therefore unlawful and impractical for us to deal with clients who have not identified themselves.
Where it is lawful and practicable to do so, individuals may deal with us anonymously (e.g., when enquiring about our products and services generally).
Actevate collects personal and sensitive information from people only if this information is necessary for the provision of our service, functions and activities and only if consented to by the person.
Actevate only collects information in accordance with permitted general and health situations in relation to our service delivery. Actevate will only collect information by lawful and fair means.
a. Purpose of Collecting Information The purposes may include:
b. Type of information collected and held Includes but is not limited to:
Documentation kept on the client’s individual file includes but is not limited to:
c. Staff, Contractors and Students
Actevate collects information from you which is necessary to properly manage and operate its business. This includes collecting personal information such as your name, address and contact details, professional experience, qualifications and past employers, and any other information which may be necessary appropriately conduct its business.
d. Job applicants and Students
Actevate collects information from you which is necessary to assess and engage job applicants. This includes collecting personal information such as your name, address and contact details, professional experience, qualifications, references and past employers, and any other information which is necessary to process your job application.
Actevate will advise clients of any information obtained or collected, including unsolicited personal or sensitive information. If the information received is not relevant to the provision of Actevate services, function and activities it will either destroy or de-identify the information.
All Actevate clients will be advised during referral and assessment processes about what information we collect and for what purpose.
Actevate will not collect information from sources that the client has not consented to.
a. Sources of information
We obtain personal information from the following:
The organisation does not disclose any of the above information to others without the client’s or the client’s authorised representative’s consent.
Actevate does not disclose or release client information to any persons or entities outside of Australia.
Actevate releases or discloses personal information only as permitted by general and health situations and only as required under Australian legislation i.e., mandatory reporting, reporting as per government funding contracts.
1. Disclosure of Client Information
In certain circumstances, Actevate may obtain and release personal information from:
We may also disclose information with the consent of the person responsible where:
These disclosures and others to third parties may be for:
Actevate obtains some services from external service providers. Some clients’ information may be provided to them on a confidential basis if the client gives his or her consent.
Actevate does not collect a client’s personal information for the purposes of marketing nor provide direct marketing communications to clients.
For stakeholders utilising services other than workplace rehabilitation services (e.g., pre-employment services, OH&S Training), Actevate will seek consent to use or disclose personal information for the purposes of informing individuals about:
Actevate does provide newsletters to other scheme stakeholders (i.e. scheme agents, employers) quarterly. These do not contain client personal information and stakeholders can elect not to receive these communications.
As per APP 6 above.
Some approved AI service providers engaged by Actevate may process information using cloud-based infrastructure located outside Australia. Where this occurs, Actevate will take reasonable steps to ensure appropriate privacy protections are in place and that the provider complies with Actevate’s contractual and privacy requirements.
Actevate does not adopt, use or disclose government related identifiers.
a. Data quality
Actevate will take reasonable steps to ensure that your personal information which is collected, used or disclosed is accurate, complete and up to date.
Actevate ensures that it provides security and protection of client personal information from misuse, interference and loss and unauthorised access, modification or disclosure.
a. Storage
All personal information held by Actevate is stored securely in either hard copy or electronic form.
b. Data security
Actevate strives to ensure the security, integrity and privacy of personal information, and will take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification or disclosure. Actevate reviews and updates (where necessary) its security measures considering current technologies.
To protect personal information, Actevate’s electronic safeguards include:
The organisation’s procedural safeguards include:
Artificial Intelligence and Information Security
Where Actevate uses approved AI-enabled systems provided by third-party suppliers, Actevate will take reasonable steps to ensure appropriate privacy, confidentiality and information security safeguards are in place to protect personal information from unauthorised access, misuse, interference, loss, modification or disclosure.
This includes considering, where appropriate:
c. Online transfer of information
While Actevate does all it can to protect the privacy of your personal information, no data transfer over the internet is 100% secure. When you share your personal information with Actevate via an online process, it is at your own risk.
There are ways you can help maintain the privacy of your personal information, including:
(d) Use of cookies
A ‘cookie’ is a small data file placed on your machine or device which lets Actevate identify and interact more effectively with your computer.
Cookies which are industry standard and are used by most web sites, including those operated by Actevate, can facilitate a user’s ongoing access to and use of a site. They allow Actevate to customise our website to the needs of our users. If you do not want information collected through the use of cookies, there is a simple procedure in most browsers that allows you to deny or accept the cookie feature. However, cookies may be necessary to provide you with some features of our on-line services via the Actevate website.
(e) Links to other sites
Actevate may provide links to third party websites. These linked sites may not be under our control and Actevate is not responsible for the content or privacy practices employed by those websites. Before disclosing your personal information on any other website, we recommend that you carefully read the terms and conditions of use and privacy statement of the relevant website.
(f) Data breaches and the Notifiable Data Breaches scheme
A data breach occurs where personal or health information is subject to unauthorised access or disclosure, is lost in circumstances where unauthorised access or disclosure is likely, or is otherwise compromised. This includes actual and suspected data breaches involving Actevate staff, contractors, systems, third-party service providers and approved AI technologies.
Actevate will respond to actual and suspected data breaches in accordance with its Data Breach Response Plan and the four-step approach recommended by the Office of the Australian Information Commissioner (OAIC):
An eligible data breach arises under the Privacy Act 1988 where:
Where Actevate has reasonable grounds to suspect that an eligible data breach may have occurred, it will conduct a reasonable and expeditious assessment. Actevate will take all reasonable steps to complete the assessment within 30 calendar days after becoming aware of the grounds for suspicion and, wherever practicable, will complete it sooner.
Where Actevate has reasonable grounds to believe that an eligible data breach has occurred, it will prepare and submit a statement to the Australian Information Commissioner and notify affected individuals, or individuals at risk of serious harm, as soon as practicable, unless an exception applies.
Notifications will include Actevate’s identity and contact details, a description of the breach, the kinds of information involved, and recommended steps individuals should take in response.
Actevate will also consider whether notification is required to another regulator, scheme authority, insurer, contracting organisation, law-enforcement body, cyber-security authority or other affected entity.
a). Access to own information
Clients have the right to access their own information held by Actevate. If a request to access personal information is made, Actevate will validate the identity of anyone making a request to access client information. This is to ensure that information is not passed to a person who is not authorised to receive it.
While Actevate aims to meet all requests for access to personal information, in a small number of cases and where permitted to do so by law, Actevate may not give access or may do so only under conditions.
Subject to applicable laws, Actevate may destroy records containing personal information when the record is no longer required by Actevate.
If clients find that the personal information held is not correct, complete or up to date, Actevate will correct their records accordingly.
a). Length of Time Records Are Held
All information regarding clients will be destroyed seven years after clients cease to receive services or in the case of children when the client reaches 25 years of age, whichever is the latest
A data breach occurs when personal or health information is lost, accessed or disclosed without authorisation, or otherwise compromised. This includes actual or suspected breaches involving Actevate staff, contractors, systems or third-party service providers.
All staff and contractors must immediately report an actual or suspected data breach to their direct manager and the Actevate General Manager. The General Manager, or their delegate, is responsible for coordinating and documenting the response and engaging relevant internal or external expertise where required.
Actevate will respond using the following four-step process, based on the Office of the Australian Information Commissioner’s (OAIC) Data Breach Action Plan for Health Service Providers:
Reporting and activation
| Data Breach Response Plan | |
|---|---|
| Containment |
|
| Assessment |
|
| Notification |
|
| Prevention |
|
Individuals who wish to access their records, who believe that Actevate may have breached their privacy rights or to update personal information held by Actevate should contact us via:
All correspondence to be addressed to - The Director: Actevate
By phone: 1300 663 155 (Head office)
Email: admin@actevate.com.au
In writing: GPO Box 3408, Sydney NSW 2001
Web link: https://www.actevate.com.au/page/contact-us
If we do not satisfactorily answer concerns, clients have the right to make a complaint to the Privacy Commissioner:
In writing: Office of Privacy Commissioner GPO Box 5218, Sydney NSW 1042
By phone: 1300 363 992