Privacy and Confidentiality Policy

 

At Symbol, how we handle your personal information is a direct reflection of how we care for you. Privacy is not simply a legal obligation – it is an expression of the warmth, respect and genuine connection that shape every part of how we work. This policy explains, in plain language, what information we collect, how we use it, and how we keep it safe. If you ever have questions about your information, we welcome the conversation.

Symbol is subject to Sections 154 and 168 of the Aged Care Act 2024 and will follow the guidelines of the Australian Privacy Principles, in regard to its information management practices.
Throughout this policy, “people under our care” refers to anyone receiving services from Symbol, who are referred to as “you/your”. Symbol is referred to as “we/our”. Organisational personnel refers to the total group of people employed by or working for Symbol, including volunteers, external contractors and external consultants. Team members refer to direct employees of Symbol.

Symbol will ensure that:

  • we meet legal and ethical obligations as an employer and service provider in relation to protecting your privacy and the privacy of our organisational personnel
  • people under our care and our organisational personnel are provided with information about their rights regarding privacy
  • people under our care and organisational personnel are provided with privacy when they are being interviewed or discussing matters of a personal or sensitive nature
  • all team members and Governing body members understand what is required in meeting these obligations.

This policy will apply to all records, whether hard copy or electronic, containing your personal information, and to interviews or discussions of a sensitive, personal nature.

 

1. Definitions

Privacy Act 1988 (Cth) – regulates how personal information is handled. The Act includes thirteen Australian Privacy Principles (APPs). The APPs set out standards, rights and obligations for the handling, holding, use, accessing and correction of personal information. The Act protects the privacy of a people’s information where it relates to Commonwealth agencies and private businesses with a turnover of more than $3 million. All organisations that provide a health service and hold health information (other than in a team member record) are covered by the Act.

Health Information – personal information or an opinion about:

  • the health, including an illness, disability or injury, (at any time) of the people under our care;
  • a person under our care’s expressed wishes about the future provision of health services; or
  • a health service provided, or to be provided, to the people under our care;

that is also:

  • personal Information;
  • other Personal Information collected to provide, or in providing, a health service to the person under our care;
  • other Personal Information collected from a person under our care in connection with the donation, or intended donation, of his or her body parts, organs or body substances; orgenetic information about the people under our care in a form that is, or could be, predictive of the health of that person or a genetic relative of that person.

Personal Information – information or an opinion about an identified individual, or an individual who is reasonably identifiable:

  • whether the information or opinion is true or not; and
  • whether the information or opinion is recorded in a material form or not.

Sensitive Information – personal information or an opinion about a person’s:

  • racial or ethnic origin;
  • political opinions;
  • membership of a political association;
  • religious beliefs or affiliations;
  • philosophical beliefs;
  • membership of a professional or trade association;
  • membership of a trade union;
  • sexual orientation or practices;
  • criminal record;

that is also:

  • personal Information;
  • health Information;
  • genetic information that is not otherwise health information;
  • biometric information that is to be used for the purpose of automated biometric verification or biometric identification; or
  • biometric templates.

Protected Information – information:

  • about a person that is or was held in the records of the Agency; or
  • to the effect that there is no information about a person held in the records of the Agency.

 

2. The Information We Collect

We collect two categories of information about you:

  1. Personal, safety, health and medical information; and
  2. Income information to determine if you’re experiencing personal financial hardship or will be subject to income testing.

This may include:

  • name
  • date of birth
  • gender
  • current and previous addresses
  • residency status
  • telephone numbers and e-mail addresses
  • financial information
  • bank account details
  • tax file number
  • driver’s licence number
  • Centrelink and My Aged Care information
  • photographs or videos
  • race or ethnicity
  • religion
  • Care and Service Plan
  • assessments
  • progress notes
  • medical history or information provided by a health service.

We gather personal, safety, health and medical information directly from you, your families and any other authorised people or services (e.g. Power of Attorney, General Practitioner, Aged Care Assessment Service, Hospitals), and through observations and assessments.
We use this information to:

  • assess and provide services
  • administer and manage those services
  • evaluate and improve those services
  • keep you safe
  • contact family, carers, or other third parties if required
  • meet our obligations under relevant legislation and aged care funding arrangements.

We also collect information about supporters, guardians and other contact persons, so we can:

  • share information with those you have authorised us to
  • register the person as a contact in case of emergency
  • stay in regular contact, if that’s what you would like.

When handling personal information, our team members will always:

  • let you know what information is being collected, why we need it, who will have access to it, and your right to access, correct or raise concerns about how it is handled
  • protect your privacy, our team members and governing body members in any conversations of a personal or sensitive nature
  • only collect and store personal information that is necessary for the functioning of the organisation and its activities
  • use fair and lawful ways to collect personal information
  • make sure you can always find out what personal information we hold, why we hold it, and who can access it
  • keep personal information accurate, complete and current, and make it easy for you to review or correct your information
  • take responsible steps to protect all personal information from misuse and loss and from unauthorised access, modification or disclosure
  • securely destroy or permanently de-identify personal information once it is no longer needed or once legal retention requirements have been met

 

3. How We Manage Your Privacy

  • Every team member is responsible for handling personal information appropriately – whether in day-to-day care, research, consultation or advocacy work.
  • The Privacy Officer is responsible for content in Symbol publications, communications and website and must ensure the following:- appropriate consent is obtained for the inclusion of any personal information about any individual, including Symbol personnel – information being provided by other agencies or external individuals conforms to privacy principles
  • That the website contains a Privacy statement that makes clear the conditions of any collection of personal information from the public through their visit to the website
  • The Privacy Officer is also responsible for:- safeguarding personal information relating to Symbol team member and Governing body members, volunteers, Associated Providers, and Symbol members – ensuring that all team member are familiar with the Privacy Policy and administrative procedures for handling personal information
  • Ensuring that people under our care and other relevant individuals are provided with information about their rights regarding privacy
  • Handling any queries or complaints about a privacy issue

4. Your Privacy – What You Should Know

At your initial assessment, we will explain what information we are collecting, how your privacy will be protected, and what rights you have in relation to your information. This will also be outlined in your Support at Home Service Agreement and in the Information Handbook we provide.

Your Consent Form is provided and explained at the time of onboarding with Symbol. This form is to be:

  • signed and placed in your file; and
  • held securely with access limited to team member members in the performance of their role.

You, your families and our team members will be encouraged to provide feedback on Symbol’s privacy practices through our quarterly Sharing Your Feedback survey.

 

5. Keeping Your Information Current

Keeping your information accurate and up to date matters to us. Symbol reviews and updates personal details:

  • whenever we review your services; and
  • whenever you or someone on your behalf lets us know something has changed

There is no charge for correcting your personal information.

If we have previously shared your information with other parties and you ask us to notify them of any changes, we will take reasonable steps to do so.

 

6. How We Collect and Store Your Information

We collect information:

  • directly from you, in conversation or in writing
  • from third parties, such as medical practitioners, government agencies, people under our care’ supporters, carer/s, and other health service providers
  • through referrals; and
  • from publicly available sources of information.

When we collect sensitive information, we do so:

  • only with your consent, unless an exemption applies (for example, where required by law, court or tribunal order, or to prevent a serious and imminent threat to life or health)
  • fairly, lawfully, and non-intrusively
  • directly from you, wherever this is reasonable and practicable
  • only where deemed necessary to support

We take all reasonable steps to protect your personal information against loss, interference, misuse, unauthorised access, modification or disclosure. We will destroy or permanently de-identify personal information that is:

  • no longer needed
  • unsolicited and could not have been obtained directly
  • not required to be retained by, or under, an Australian law or a court/tribunal order.

We have appropriate security measures in place to protect all stored information – both electronic and hard copy – including locked filing systems, restricted access and password-protected records systems.

We maintain a secure archiving process to ensure your files are stored confidentially and destroyed appropriately when no longer required.

In the unlikely event of a privacy breach that could expose your information (for example, a system compromise or lost device), our Privacy Officer will act immediately in accordance with our response plan (see Section 12: If Your Information Is Ever at Risk).

 

7. Photos, Videos and Recordings

Photos, videos and other recordings are personal information. Our team members must always obtain written consent before taking any photo or video content of you. That consent must clearly state the purpose and where the content may be used. We respect your choices about being photographed or filmed, and we handle all images with care – including cultural sensitivities and any images that require particular consideration.

 

8. When We Share Your Information – and Why

We take your right to privacy seriously. We will not share your personal information unless you have given consent and the sharing is consistent with Section 168 of the Aged Care Act 2024, meaning it is:

  • for a purpose connected with the provision of aged care to the person by the approved provider; or
  • for a purpose for which the personal information was given by or on behalf of the person to the approved provider.

Without your written consent, we will not share your personal information with anyone except:

  • for a purpose connected with the provision of aged care by Symbol to yourself;
  • for a purpose connected with the provision of aged care to yourself by another registered aged care provider, so far as the disclosure relates to the transfer of services and associated payments/funds held; or
  • where required or authorised by law.

 

9. Sharing Information Overseas

Under the Privacy Act 1988 (Cth), before we share personal information with an overseas recipient, we must take reasonable steps to ensure that recipient handles your information in a way that meets the standards set out in Australian Privacy Principle 8.

Our Privacy Officer is responsible for carrying out these assessments.

This requirement does not apply if:

  • the overseas recipient is subject to a law or binding scheme that has the effect of protecting the information in a way that is substantially similar to protection given under the APPs, and
  • there are mechanisms available to enforce that protection.

 

10. Your Right to Access Your Information

You have the right to access your personal information, subject to exceptions allowed by law. Access to health information is guided by the relevant Health Privacy Principles and legislation in each state.

To request access to your information, please let us know:

  • the information to be accessed
  • the preferred means of accessing the information,
  • You can share this with our Privacy Officer verbally or in writing.

Our Privacy Officer will review your request carefully, taking into account any circumstances that may affect access under applicable law.

If access cannot be granted, our Privacy Officer will write to you within 20 business days to explain:

  • the reasons for denying access and
  • the mechanisms available to complain or appeal.

If access is granted, our Privacy Officer will be in touch within 10 business days to make arrangements.

If we are unable to provide the information in the format you requested, we will work with you to find another way.

In some cases, reasonable costs involved in providing your information may be passed on, but only if this has been discussed and agreed with you in advance.

 

11. If Something Doesn’t Feel Right

If you have any questions or concerns about how we handle your personal information, we want to hear from you.
We will reach out to you during the process to gather any further information we need.

You will be informed of the outcome and any actions taken, either in writing or in a conversation with us.

If your concerns remain unresolved and you wish to make a formal complaint, or if you believe Symbol has breached an Australian Privacy Principle (APP), you can write to:

Office of the Information Commissioner
Albert Facey House
469 Wellington Street
Perth, WA, 6000

Email: info@oic.wa.gov.au

 

12. If Your Information Is Ever at Risk

A data breach occurs when personal information is lost or accessed without authorisation. This can happen as a result of malicious action, human error or a failure in information management or security systems. We take this seriously and have clear processes in place to respond quickly and effectively.

The following processes are in place to prevent and respond to any breach of privacy:

 

Establish the Data Breach Response Team

The Data Breach Response Team will include:

Privacy Officer: The Privacy Officer, designated as the Quality and Compliance Officer, is responsible for overseeing the breach response, ensuring compliance with data protection regulations, coordinating with legal counsel, and assessing the potential impact on personal data. They will coordinate the response and act as liaison with senior management and legal counsel, ensuring adherence to the response plan.

IT Security Adviser: The IT Security Adviser may be the internal IT Manager, external IT Consultant or the lead security personnel of the system that has experienced the breach. They take the lead in the technical aspects of data breach detection and response, coordinate with the team to isolate and contain breaches, and assist with investigations.

Public Relations/Communications: The Public Relations/Communications officer, designated as Chief Operations Officer, manages internal and external communications during data breaches, prepares public statements and communications with people under our care, and handles media inquiries.

Legal Counsel: The Legal Counsel (which may be internal or an external advisor), provides legal guidance throughout the data breach response process and ensures compliance with relevant laws and regulations.

Implement the Incident Response Plan
Symbol maintains a comprehensive data breach response plan that defines roles and responsibilities and sets out how we respond to breaches of varying severity.

The plan will include the identification of all sensitive data handled by Symbol, such as personal health information, financial data, and personal identifiers. This plan will be followed in the event of a breach.

 

Implement Security Measures

We maintain robust security measures including encryption, access controls and regular security audits.

 

Data Breach Detection

We use intrusion detection systems and real-time monitoring to identify potential breaches promptly. Our team members are trained to recognise and report unusual activity.

Any team member who identifies a potential breach must immediately notify their line manager, who will escalate to the Quality and Compliance Officer.

Where a team member is suspected of breaching privacy, a thorough investigation will be conducted in accordance with our Disciplinary Action Policy.

Further detail about the Notifiable Data Breaches (NDB) Scheme is contained in the Data Breach Preparation and Response — A Guide to Managing Data Breaches in Accordance with the Privacy Act 1988 (Cth), published by the Office of the Australian Information Commissioner (OAIC).

 

Data Breach Classification

The Incident Response Plan defines a classification system to assess the severity of data breaches based on the type and amount of compromised data.

 

Containment and Mitigation

In case of a detected breach, Symbol will isolate affected systems and networks to prevent further damage and address the vulnerability that led to the breach.

 

Notification Requirements

The Incident Response Plan ensures understanding and compliance with obligations under the Notifiable Data Breaches (NDB) scheme. It mandates the preparation of templates for breach notification letters and public statements.

 

Legal and Regulatory Compliance

Legal counsel is consulted to ensure compliance with Australian data protection laws, and potential legal and financial consequences of data breaches are understood.

 

Public Relations and Communication

A communication plan is created to address internal and external stakeholders, and coordination with public relations experts is outlined to manage the organisation’s public image during and after a breach.

 

Data Breach Documentation

The Incident Response Plan mandates the maintenance of comprehensive records of data breaches, including timing, scope, containment efforts, and notifications sent.

 

Remediation and Prevention

A plan for remediating the effects of a breach and preventing future breaches is developed. Employee training programs on data security best practices are also implemented.

 

Reviews and Updates

Regular reviews and updates of the data breach response plan are conducted to incorporate lessons learned from previous incidents and changes in regulations.

 

Testing and Training

Regular desktop exercises are conducted to test the effectiveness of the response plan. All team member are trained on their roles and responsibilities in case of a breach.

 

Reporting to Authorities

Symbol is required to disclose a data breach to the Office of Australian Information Commissioner if the data contains personal information that is likely to result in “serious harm”, which includes any of the following: physical, psychological, financial or reputational harm. Personal information is information about an identified individual, or an individual who is reasonably identifiable.

 

Third-Party Relationships

The plan emphasises the importance of third-party service providers having robust data security measures and a breach response plan.

 

Insurance

Consideration of cyber insurance to mitigate the financial impact of a data breach is encouraged.