Purpose
As an associated Provider of TriCare Aged Care, Elderly Care is required to comply with the Privacy Act, State-based privacy legislation, the Aged Care Act and Rules, and relevant retirement village legislation.
The Privacy Act sets out the manner in which organisations may collect, store, use, and disclose Personal Information and how a person can access and/or correct records containing their Personal Information.
As an organisation that delivers services on behalf of a registered provider of funded aged care services, We comply with the obligations under the Aged Care Act relating to the handling and protection of Personal Information and upholding an Individual’s right to have their privacy respected.
As an organisation that provides services within retirement villages, we comply with the obligations under the relevant State-based retirement village legislation and in accordance with residence agreements.
We are committed to protecting the privacy of those to whom we deliver services.
As part of this commitment, we:
- are transparent about the Personal Information we collect;
- only collect Personal Information that is necessary for the services we provide;
- ensure Personal Information is handled in accordance with the law;
- take reasonable steps to keep all Personal Information secure;
- build privacy considerations into our contractual and other arrangements, including where other organisations or contractors are used to deliver services on our behalf;
- monitor activities to ensure compliance and identify areas for improvement; and
- notify affected Individuals and Residents, and the Australian Information Commissioner, Queensland Information Commissioner or the Victorian Information Commissioner (as required) in the event of a data breach, when required to comply with our regulatory obligations.
This policy outlines the types of Personal Information that we usually collect, the purposes for which we collect it, to whom we disclose it, how we hold and keep it secure and your rights in relation to your Personal Information, including how to complain and how we deal with complaints.
We are committed to ensuring that this policy is accessible, understood, and embedded in everyday practice. We do this by:
- delivering privacy training to our Employees;
- taking reasonable steps to make this policy available to a person or body who requests it; and
- implementing policies, procedures and systems to ensure compliance with the APPs and deal with enquiries or complaints about compliance.
Definitions
In this policy, capitalised terms have the following meanings:
| Term | Definition |
|---|---|
| Aged Care Act | means the Aged Care Act 2024 (Cth). |
| APPs | means the Australian Privacy Principles. |
| Elderly Care | means Elderly Care Pty Ltd. In this policy, a reference to “we, our or us” also refers to Elderly Care. |
| Employees | means any employee, volunteer, aged care worker or subcontractor engaged by us, or on our behalf. |
| Individual | means individuals who receive funded aged care services from TriCare. |
| Personal Information |
means information or an opinion (including written and verbal information or an opinion forming part of a data base), whether true or not, and whether recorded in a material form or not, about an identified individual or an individual who is reasonably identifiable. It may include, for example, basic identifying information such as name and address, health information, financial information, or employment information such as job title or work schedule. Personal Information may include Sensitive Information and protected information (as that term is defined in the Aged Care Act). Personal Information may or may not apply to information of deceased people. |
| Privacy Act | means the Privacy Act 1988 (Cth). |
| Resident | means person living in a retirement village operated by TriCare. |
| Rules | means person living in a retirement village operated by TriCare. |
| Sensitive Information |
means a type of Personal Information that requires higher protection due to its sensitive nature. It may include, for example, racial or ethnic origin, religious or philosophical beliefs, health records, criminal record, or any other Personal Information that is ‘Sensitive Information’ as defined in the Privacy Act. For an Individual, this may look like:
|
| TriCare | means TriCare Aged Care Pty Ltd and Allegiance Care Pty Ltd or related entities. |
Policy
- Scope
- This policy applies to:
- Elderly Care;
- Individuals, and their relatives, supporters and authorised representatives;
- Residents, and their relatives, and authorised representatives; and
- our Employees.
- The Privacy Act and this policy do not apply to Employee records, such as salary details, performance reviews, medical records, and disciplinary actions where the collection, use, or disclosure is directly related to a current or former employment relationship with us.
- This policy applies to:
- Types of Personal Information we Collect
- We collect Personal Information from Individuals, Residents, Employees, job applicants, students on work placements, donors and other people when they choose to engage with us.
- The type of Personal Information we collect and why we collect it depends on what services we are engaged to deliver to you. The Personal Information we collect or receive may include (but is not limited to):
- Individuals: name, address, date of birth, details of next of kin, emergency contacts, financial information and Sensitive Information such as health and medical information, racial or ethnic origin, religious beliefs or affiliations;
- Residents: personal and care-related information, including name, address, date of birth, next of kin details, medical information, Enduring Power of Attorney (EPOA) documents, financial records, emergency contact details, and any other information required to support their care and wellbeing;
- Employees: name, address, date of birth or emergency contact information;
- Job applicants: employment history and qualifications, information provided in resumes and cover letters, information from interviews, reference checks, and health information such as medical assessments, superannuation fund details, personal alternative contact details and criminal history record;
- Students on work placement: academic history, placement agreements, contact details, and emergency information;
- Other people: any information provided in the course of interacting with us, such as through, commission, auditors on behalf of the commission, feedback forms, surveys, or event participation.
- We collect Personal Information from you to provide services and to operate our business. We may also collect Sensitive Information from you. If we are unable to collect Personal or Sensitive Information, we may be unable to provide our services.
- Where possible, Individuals and Residents may choose to remain anonymous or use a different name when dealing with us. However, this may not be possible if:
- it is impracticable to proceed without identification; or
- identification is required by law, a court, or tribunal.
- How we collect Personal Information
- We will generally collect Personal Information directly from you, using forms and documents (including in electronic form) you submit to us, such as when you enter into a contract with us.
- Personal Information may also be shared with us by TriCare Aged Care Pty Ltd where it is necessary for the delivery of care services on your behalf.
- We also collect Personal Information through:
- you or your authorised representative;
- completion of our enquiry or application form for employment & entry to residential aged care;
- publicly available sources, including social media;
- correspondence, telephone calls, or meetings;
- online interactions through our website;
- photography or videography in the course of providing services, such as during consultations;
- Services Australia; and
- if you are an Employee via facial recognition scanning for timekeeping purposes.
- We may collect Personal Information from you without your consent in certain lawful circumstances, for example where it is necessary to prevent a serious threat to the life, health or safety of a person.
- Information from third parties
We also collect Personal Information from third parties depending on your relationship with us, including:- TriCare Aged Care Pty Ltd: where Elderly Care is engaged to deliver care services on behalf of TriCare Aged Care, TriCare Aged Care may share Personal Information with us that is necessary for the provision of those services. This may include your contact details, medical and health information, care needs and assessments, and other information relevant to the delivery of your care.
- Services Australia
- Individuals: from relatives, supporters or other authorised representatives, health service providers (such as general practitioners, hospitals or allied health professionals), or relevant government agencies (such as MyAgedCare and the Department of Health, Disability and Ageing);
- Residents: from relatives, or authorised representatives;
- Job applicants and contractors: we may collect details of any existing criminal record from police agencies or agencies completing police checks on our behalf, information from your references and previous employers.
- Unsolicited information
If we receive unsolicited information (for example, an email sent to us by mistake), we will check if we could have lawfully collected it. If not, we will destroy or anonymise the information as soon as possible, unless it’s reasonable and lawful to keep it. If we do keep it, we will handle it according to this policy. - Handling government identifiers
Tax file numbers and other government identifiers will only be handled in accordance with relevant legislation, if applicable.
- Purposes for which we collect, use and disclose Personal Information
- We collect, use and disclose your Personal Information to:
- deliver services or provide the appropriate care or support, where applicable;
- photographs taken to support care and treatment and be displayed on medication chart, clinical care and lifestyle assessments and care plans;
- Photographs taken during social events and activities for use in resident & employee newsletters or displayed on notice boards;
- manage and conduct our business;
- report data to government departments, TriCare Aged Care or other third parties, as required by law;
- comply with legal obligations, resolve any disputes and comply with our agreements and rights with TriCare Aged Care and third parties;
- to offer or promote our products and services;
- to obtain feedback;
- to help us manage, develop and enhance our services, including our websites and applications;
- assess suitability and eligibility for employment;
- improve our services, programs, and communication with stakeholders.
- In certain circumstances, including those contemplated by the Aged Care Act, we disclose your Personal Information to third parties, including the following types of persons or entities:
- medical or healthcare professionals, health funds and those providing services to our Individuals;
- TriCare Aged Care and other necessary third parties in order to provide our services;
- relatives, authorised representatives or supporters (if applicable) where permitted;
- Employees, including contractors, consultants, associates, volunteers, students, and related entities who are subject to confidentiality obligations;
- our professional advisers, including lawyers, accountants and auditors;
- industry bodies, tribunals, courts, or others, in connection with any complaints made;
- government departments or funding agencies, police agencies and agencies (such as CrimTrac and MyAgedCare);
- a purchaser of our business, or part of our business, as a going concern; and
- other entities with the required consent or as permitted or required by law (such as where there is a coronial inquest).
- In certain circumstances, we may use or disclose your Personal Information for a purpose other than what it was collected, for example, in emergency situations or law enforcement activities.
- We may disclose the Personal Information of Employees, if required, to:
- health services providers;
- other employees in the course of conducting referee checks;
- government departments or funding agencies, police agencies and agencies;
- the Australian Tax Office;
- workplace regulators, including for workplace health and safety, and workers compensation purposes;
- superannuation and insurance bodies; or
- external auditors or regulators.
- We will not use your Personal Information without taking reasonable steps to ensure the information is relevant, accurate, up to date, complete and not misleading.
- We may aggregate or de-identify statistical information so that people cannot be identified, for use in our internal purposes or for sharing with government agencies or research organisations.
- We collect, use and disclose your Personal Information to:
- How we keep your Personal Information safe
- We will handle your Personal Information in an open and transparent way.
- Storing your Personal Information
We store Personal Information in both paper form and electronically. Electronic records may be stored on local and/or cloud-based platforms. Our cloud storage providers are contractually required to handle Personal Information securely and in accordance with privacy laws. - We may also store archived Personal Information at a secure offsite records storage and archive management facility. The Personal Information will be destroyed in line with the relevant legislative requirements.
- Images from facial recognition timekeeping software do not store images. The timeclock scans an image, which generates an individual template created from digital representations. These mathematical digital representations of the face cannot be used to re-create the original image. The original images are promptly destroyed once the template is created.
- We take all reasonable and appropriate steps (including organisational and technological measures) to protect your Personal Information from misuse, interference and loss, as well as unauthorised access, modification or disclosure.
- How we protect your Personal Information
We have strict security measures in place to protect Personal Information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include:- policies and procedures: clear security protocols for our Employees to follow;
- secure storage: physical files are stored in secured facilities both on our premises and at offsite locations;
- restricted access: only authorised Employees and contractors, who need access for their role, can view certain Personal or Sensitive Information;
- secure transmission: electronic information is transmitted using secure networks or encryption. However, despite our best endeavours, it is important to note that no internet transmission is completely secure; and
- device and network protection: security tools such as authentication controls, firewalls, virus scanning and intrusion detection help safeguard our systems.
- cloud based storage: We use third-party cloud-based software providers to store, process and manage information. These providers are subject to contractual and security controls across the services they provide.
- How we handle data breaches
We take data breaches seriously. If a data breach occurs, we will notify the affected parties, and the Australian Information Commissioner if required. - How long we keep Personal Information
We retain Personal Information only as long as necessary for the primary purpose of collection or a lawful secondary purpose. - Generally, records are kept for at least seven years from the date of the last record. When no longer needed, Personal Information is securely destroyed or de-identified.
- How we destroy Personal Information
When Personal Information is no longer required for our functions, activities, or legal obligations, we securely destroy or permanently de-identify it to protect privacy and prevent unauthorised access. - We follow all legal and regulatory requirements when destroying information, ensuring compliance with the Privacy Act and other relevant laws.
- Cookies and websites
- Cookies are small data files stored on a person’s computer, mobile phone or other device when visiting a website. They help track pages visited and improve website functionality and may remember your preferences.
- Our website uses cookies. Browser settings can be adjusted to block cookies; however, this may limit website functionality.
- Whilst we do not use browsing information to identify you personally, we can record certain information about your use of our website, such as which pages you visit, the time and date of your visit, search engine referrals and the internet protocol address assigned to your computer.
- Our web pages can contain electronic images, known as web pixels. These electronic images enable us to count users who have visited certain pages on our website. Web beacons are not used by us to access your Personal Information, they are simply a tool we use to analyse which web pages are viewed, in an aggregate number.
- We are not responsible for third-party websites, platforms, or applications linked to, or associated with our services. Their privacy policies should be reviewed before use. Some third-party platforms may offer tools to manage privacy settings and opt out of personalised ads.
- Direct Marketing
- We can use your Personal Information to identify a product or service that we believe you may be interested in or to contact you about. We can, with your consent, use the Personal Information we have collected about you to contact you from time to time whether by email or phone etc to tell you about new products or services and special offers that we believe is of interest to you.
- You can withdraw your consent to receiving direct marketing communications from us at any time by unsubscribing from the mailing list by contacting the Privacy Officer.
- Accessing and Correcting your Personal Information
- You can request access to or correction of the Personal Information we hold about you, by contacting us using our details in the “contact us” section below.
- We will address such requests as soon as practicable, and usually within 28 days.
- Where the Personal Information you are seeking to access or correct is held by TriCare Aged Care rather than us, we will direct your request to TriCare Aged Care for actioning. We will notify you if this is the case and provide you with relevant contact details or assistance to facilitate your request being dealt with promptly.
- Before granting access to Personal Information, we may require you to verify your identity or the authority you have, to request Personal Information if the information relates to someone other than yourself.
- Access may be denied in certain circumstances, such as where releasing the information would impact another person’s privacy or where legal restrictions apply. If we decide to refuse your request, we will tell you why in writing and how to complain.
- Where a request is made for access to Personal Information of a deceased Individual or Resident, we will handle the request in accordance with its obligations under applicable Commonwealth and State legislation. Access will be granted to a legal representative of the deceased (being an executor or administrator of the estate) upon receipt of a written request and satisfactory evidence of identity and authority.
- We may require you to pay a fee to access your Personal Information.
- We will take reasonable steps to correct any Personal Information we consider to be inaccurate, incomplete, misleading or out of date.
- Making a complaint
- If there are concerns about a possible breach of the Privacy Act, APPs, or any related privacy code, a complaint can be made:
- in writing to the Privacy Officer using the contact details below.
- If you have concerns about a possible breach of the Aged Care Act, a whistleblower disclosure can be made through Elderly Care’s Whistle Blower Policy.
- Upon receiving a complaint, we will confirm how we intend to address the issue as soon as reasonably practicable.
- If the response is unsatisfactory, complaints can be escalated to the Office of the Australian Information Commissioner (OAIC). More information on lodging a complaint is available at www.oaic.gov.au/privacy/privacy-complaints.
- If there are concerns about a possible breach of the Privacy Act, APPs, or any related privacy code, a complaint can be made:
- Contact us
- For any privacy-related queries, please contact:
Elderly Care Privacy Officer
Address: 10 Bendena Terrace, Carina Heights, QLD 4152.
Telephone: 07 3569 1014
Email: privacy@elderlycare.au
- For any privacy-related queries, please contact:
- Variation
- We may update this policy, from time to time, to take account of changes to law or regulations and changes to our services or business operations.
- Related documents
- This policy should be read in conjunction with the following documents, legislation and other instruments:
- EC HR POL 06 – Whistleblower Policy;
- the Privacy Act;
- the Aged Care Act and Rules.
- This policy should be read in conjunction with the following documents, legislation and other instruments:
