(1) We respect the privacy of the information of all individuals that provide their information to us or that we are otherwise required or permitted by law to collect. This Policy explains how we will manage that information and is to be read subject to any overriding provisions of law. (2) The University of Canberra is a young University anchored in the national capital and works with government, business, and industry to serve our communities and nation. The University of Canberra challenges the status quo; always pursuing better ways to teach, learn, research, and add value – locally and internationally. Our purpose is to provide education which offers high quality transformative experiences; to engage in research which makes a difference to the world around us; and to contribute to the building of just, prosperous, healthy, and sustainable communities. The University of Canberra has recently established its long-term ambitions through its Connected Decadal Strategy 2023–2032. Through its three objectives (Connected to Canberra, Connected for life and Connected UC), the University of Canberra aims to build sustainable communities through deep collaborations that are locally focused and globally relevant, partner for life with our students to shape our economic, social and cultural futures. (3) This Policy applies to the personal information the University collects from and about individuals (your personal information), including staff and students of the University, affiliates, and any other person who interacts with the University in person or online (you). (4) All members of University staff have a responsibility to carry out and abide by the principles and processes set out in this Policy. (5) Except as set out in this Policy, other companies and organisations we associate with, including organisations whose services are in some way linked to us through online content or services (such as apps, social media platforms) do not have a responsibility to carry out and abide by the principles and processes set out in this Policy. You must refer to the relevant Privacy Policy of these other companies or organisations we associate with to understand how your personal information will be managed. (6) The types of personal information we may collect and hold include: (7) The types of information we may collect and hold include: (8) The types of information we may collect and hold include: (9) For staff, students, and individuals other than staff and students, we may also collect and hold a special subset of personal information, sensitive information, such as: (10) We only collect personal information when it is reasonably necessary or directly related to one of our functions or activities. We recommend that you do not provide sensitive information to us unless specifically requested by us. We will only collect your sensitive information if: (11) When we intend to collect personal information from children (i.e. people who are under the age of 16), where possible, we take additional steps to protect their privacy, including by: (12) Parents and guardians can exercise privacy rights on their children’s behalf, but we may need to verify that you are authorised to act on their behalf and collect additional information from you to do so. (13) Parents and guardians for children who are under the age of 16 are not third parties for the purposes of this Policy. (14) When possible, we try to collect personal information directly from you, for example when you: (15) While we will generally collect personal information from you directly, sometimes we might get it from other parties (for example when we check references or pre-employment checks). The other parties we may need to obtain information from include: (16) When we collect personal information from third parties you refer to us, we will assume that you have consented to that third party disclosing that information to us. We will only use and disclose such information provided to it for the purpose for which it was given and other purposes only in accordance with this policy. (17) If you are a contracted service provider or a partner who gives us personal information about individuals such as your employees, directors or owners, we may also ask you to advise them of the purposes of our collection, use and disclosure of their information in line with this Policy or with a specific collection notice we give to you. (18) If we receive unsolicited information about you, we will retain it (and use disclose or destroy it) in line with our obligations under the law, including the privacy laws and Territory Records Act 2002. (19) We collect, use and disclose your personal information to enable us to provide the education, services, products and information you request, and when it is reasonably necessary to enable us to perform our functions and activities. We may also use or disclose your personal information for a secondary purpose which is directly related (where there is sensitive information) or related (for non-sensitive information) to the reason you provided the information in the first place, but only where you would reasonably expect us to use your information for that purpose. In particular, we may collect, use and disclose your personal information for the purposes of: (20) We can also use it for a secondary purpose where permitted by law, including the privacy laws. (21) We will not sell, trade or rent your personal information. (22) We may disclose your personal information to: (23) The above entities may in turn disclose your information to other entities as described in their respective privacy policies or notices. (24) We will only use or disclose your personal information for another purpose if: (25) From time to time, we may engage contracted service providers or partners located overseas (including, but not limited to providers or partners located in Indonesia) to perform certain functions and activities. Generally, this information is provided for the purposes of global student recruitment or under collaboration agreements for student exchanges. While they are providing services to or partnering with us, we may need to disclose your personal information to these recipients. If your personal information is sent overseas, we will take reasonable steps to ensure that our contracted service providers and partners have policies, procedures and systems in place to ensure your personal information is handled in accordance with the Privacy Act and other applicable legislation. (26) We are committed to protecting information we hold about you. We will (and we will require our contracted service providers to) take reasonable steps to protect your information (whether in physical or electronic form) from loss, misuse, unauthorised access, modification and/or disclosure. (27) We may store your information in different forms, including in physical and electronic form, including using cloud-based storage services. We take steps to ensure the security of your personal information despite its form, including through our websites and service applications, but there is always some risk when transmitting information across the internet, including a risk that information sent to or from a website or other Internet of Things application may be intercepted, corrupted or modified by third parties. (28) When your information is no longer required by law to be retained by us, we will take reasonable steps to destroy, delete or de-identify your information in a secure manner. The privacy laws and the Territory Records Act 2002 (ACT) are some examples of laws that may require us to retain certain information. (29) It is important that the personal information we hold about you is complete, accurate, current and relevant. At any time while we hold your information, we may ask you to tell us of changes to your information. Alternatively, if you believe that any of the personal information we hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading and needs to be corrected or updated, please contact us (see the ‘Contact Us’ section below). (30) We will respond to a request to access or correct your personal information within: (31) You may request to access or correct your personal information at any time by contacting us. We will give you access to the personal information unless an exception in the law, including the privacy laws, applies (or it is otherwise unlawful). Sometimes we may not be required to correct your personal information (for example, where it would be unlawful). Also, sometimes we may not be able to require our contracted service providers, partners or other third parties to give you access to the personal information they hold about you. (32) If we do not give you access to your personal information and/or allow you to correct it, you can ask us to include with the information a statement that the information is inaccurate, out-of-date, incomplete, irrelevant or misleading. (33) If we do not correct your personal information, we will give you our reasons for our decision. (34) While the first step to ask us to give you access to or correct information we hold about you is described in Clauses 29–33 above, an alternative way is to lodge a formal application under the Freedom of Information Act 2016. For more information on how to lodge a FOI application please visit our FOI webpage. There may be fees associated with FOI requests. (35) If you have a complaint or otherwise wish to contact us about our handling of your information or any of the matter covered by this Policy, please contact: (36) We welcome your questions and any suggestions you may have about our Policy. If you would like to lodge a formal complaint, we: (37) If you are not satisfied with how we have handled your complaint, then you may escalate the complaint to the Office of the Australian Information Commissioner (OAIC) at: (38) This Policy applies to your use of the University website – www.canberra.edu.au – and any personal information that you may provide to us via our website including our staff and student portals and any other subsites as part of the University of Canberra domain. (39) We believe it is important for you to know how we treat this personal information and how we carry out data processing practices with the Internet and any other electronic communications networks. (40) When you visit our website, we and/or our contracted service providers and partners may collect certain information about your visit. Examples of such information may include: (41) Our website may contain links to other websites which are outside our control and are not covered by this Policy. Though we scrutinise the links that are included on the UC website, we do not endorse, approve or recommend the information, services or products provided on other websites. If you access other websites using the links provided, the operators of these websites may collect information from you which will be used by them in accordance with their policy framework which may differ from ours. (42) By using our website, or giving us information, you consent to us managing your information in the way described in this Policy. (43) We compile and categorise a list of our followers on social media platforms. We may also receive information from you on Social Media where you give it to us. Additionally we may also receive aggregate, non-personalised statistics on the University’s coverage in social media. (44) The law deals with personal information, including sensitive information, differently from personal health information (see definitions below). Generally, the way we manage your personal including sensitive information is governed by: (45) We also manage your personal information including sensitive information in compliance with other relevant legislation, including: (46) The way we manage your personal health information is governed by, and we will act in accordance with: (47) We may revise or supplement this Policy from time to time. Any updated version of this Policy will be posted on the University’s Policy Library and will be effective from the date of posting. You should bookmark and periodically review this page to ensure that you are familiar with the most current version of this Policy and so you are aware of the way we handle your information.Privacy Policy
Section 1 - Purpose
Section 2 - Scope
Section 3 - Principles
What kind of personal information do we collect?
Personal information – students
Personal information – staff
Personal information – individuals other that staff and students
When we will collect personal information
Children’s privacy
How do we collect personal information?
Directly from you
From third parties
Unsolicited information
Why do we collect, hold, use and disclose your information?
Purposes for which we may collect, hold, use and disclose your personal information
To whom we may disclose your personal information
Why we disclose your personal information for another purpose
Overseas disclosure of information
Data storage, retention, security and location of your information
How to access and correct your personal information
Generally
FOI Act
Contact us
Dealing with us online
University website
Social media
Legislation
Changes to this policy
Section 4 - Responsibilities
Top of Page
WHO
RESPONSIBILITIES
Vice-Chancellor
Chief Operating Officer and Vice-President Operations
Chief Operating Officer and Vice-President Operations
Privacy Officer
Staff and Affiliates
Individuals who provide personal information to us
Section 5 - Definitions
TERM
DEFINITION
contracted service provider
means an entity or person engaged by us to provide services to the Australian Capital Territory or us, and includes their subcontractors.
our partners
means our wholly or partly owned companies, including for example UCX Ltd, other universities and other organisations that we partner with, including software and hosting service providers.
personal health information
means information or an opinion about a consumer (or from which their identity is apparent) whether true or not, and whether recorded or otherwise, which relates to their health or an illness or disability of theirs. You are a consumer when you use, or have used, a ‘health service’ or a ‘health record’ about you has been created (as those terms are defined in the Health Records (Privacy and Access) Act 1997).
privacy laws
mean the Information Privacy Act 2014 and the TPPs contained in the Act, the Health Records (Privacy and Access) Act 1997 and the HPPs contained in the Act, and the Privacy Act 1988 in respect of Tax File Numbers (TFN) and as applicable under the Higher Education Support Act 2003.
reasonably necessary
means that the personal information is collected because it is required to perform a function or activity and the University could not properly undertake the function or activity without collecting the personal information.
we, our or us
means the University of Canberra, including the Medical and Counselling Centre, Wiradjuri Preschool and Child Care Centre and Health Clinics, our controlled entities, Council members, employees (and those of controlled entities), volunteers, students on a placement facilitated by the University of Canberra, officers and agents and contracted service providers
your personal information
means your personal information, including sensitive information, but excluding any personal health information. When we use ‘personal information’ and ‘sensitive information’, we use them in the same sense as the Privacy Act – in short:
View Current
This is the current version of this document. To view historic versions, click the link in the document's navigation bar.