The Sweet Pins Foundation Limited Policy and Procedures: Privacy, Dignity and Confidentiality
The Sweet Pins Foundation Limited(SPFL) is committed to protecting the privacy of personal information which the Association collects, holds and administers. Personal information is information which directly or indirectly identifies a person.
SPFL recognises the essential right of individuals to have their information administered in ways which they would reasonably expect – protected on one hand, and made accessible to them on the other. These privacy values are reflected in and supported by our core values and philosophies.
SPFL is bound by laws which impose specific obligations when it comes to handling information.
This policy aims to provide clear principles and guidance about how SPFL collects, stores and disposes of information.
This policy will be implemented in various processes, forms and tools that SPFL uses including online activities.
This policy will be followed by all SPFL staff and volunteers. Volunteers include Board members, parent support volunteers and all other people that assist with SPFL activities in a voluntary capacity.
The National Privacy Principles (NPPs)
SPFL will adhere to the national privacy principles.
The NPPs set minimum standards that include:
- collection, use and disclosure of personal information which could identify a person
- quality, security and storage of information
- giving a person access to their information
- handling special categories of information such as ‘sensitive’ information and ‘health’ information.
- What is personal information?
- Information or an opinion about an individual whose identity is apparent or can be ascertained from that information or opinion.
- This includes name, address, telephone number/s, age and e-mail address.
- What is sensitive information?
Under the NPP sensitive information includes information such as health, racial or ethnic background, or criminal record. Higher standards apply to the handling of sensitive information. The Association only records information that can be defined as health information.
SPFL has adopted the following principles as minimum standards in relation to handling personal information.
- collect only information which is required for its primary function
- ensure that information is available as to why we collect the information and how we administer the information gathered
- use and disclose personal information only for our primary functions or a directly related purpose, or for another purpose with the person’s consent
- store personal information securely, protecting it from unauthorised access
- provide people with access to their own information, and the right to seek its correction.
- What information does SPFL collect?
In providing our services, SPFL collects personal information. This information includes:
- Information that can identify a person (such as name, address, contact details)
- Information that could be considered health information, such as whether a person is affected by disadvantage
- When collecting information about a person SPFL will only collect information that is necessary to provide our services and for other activities that SPFL carries out.
- Where possible, SPFL will provide services to people who do not wish to provide information about themselves.
- Collection will be undertaken by a method which is fair, lawful and not unreasonably intrusive.
- Individuals from whom personal information is collected are to be made aware of
- the contact details of SPFL
- the primary purpose for which the information is collected
iii. any possible secondary purpose for which the information may be used
- the names of the organisations or types of organisations to which we disclose information of any nature (if any)
- Where reasonable, SPFL will collect information about an individual from that individual.
Using and Disclosing Information
- Information will only be used or disclosed for the primary purpose for which it was collected. Information provided by individuals may be used to keep them better informed about SPFL activities and services, by way of a newsletter or emails about research or other opportunities. Individuals have the right to opt out of receiving such additional communications at any time.
- Personal information about an individual will not be used or disclosed for a secondary purpose unless:
- the purpose is closely related to the primary purpose and the individual would reasonably expect the information to be used in that way; or
- the information is health information and its use is necessary for records or statistical analysis relevant to public health; or
iii. the individual has consented; or
- SPFL has a legal obligation to disclose personal information which overrides the provisions of the primary legislation.
- SPFL will never sell or exchange or release personal information about an individual for commercial gain.
Reasonable steps will be taken to ensure information collected and used is complete, accurate and up-to-date.
Safeguard the information we collect and store against misuse, loss, unauthorised access and modification.
- SPFL will publish this policy. This will be available on the SPFL website, and to any person who asks for it.
- On request by a person, SPFL will take reasonable steps to let the person know, generally, what sort of personal information it holds, for what purposes, and how it collects, holds, uses and discloses that information.
Access and Correction
- Ensure individuals have a right to seek access to information held about them and to correct it if it is inaccurate, incomplete, misleading or not up to date.
- SPFL will make information held on an individual accessible to them on request (except where frivolous and vexatious). This will be available free of charge. An individual may only access their own information and cannot be given access to information about another individual.
- If an individual informs SPFL that information SPFL holds is not accurate, complete or up to date, SPFL will take reasonable steps to ensure the information provided is accurate and up-todate. Requests should be sent to firstname.lastname@example.org
- Individuals have the option of not identifying themselves when dealing with SPFL. This is not practicable when registering for SPFL programs, events or in becoming a member of SPFL.
SPFL does not collect sensitive information about individuals unless:
- we have the consent of the individual; or
- the information is collected in the course of SPFL activities where the individual is in regular contact in relation to those activities and the individual understands that the information will not be disclosed without consent.
- This policy will be provided to SPFL volunteers and staff
- No volunteer or staff member will have access to personal information until they have signed that they have read and understood the policy
- Changes to forms and communications:
- There will be an option provided to one-time donors to donate anonymously
- Event registration and donation forms will include the opportunity to opt-out of future communications with a check box: “SPFL would like to send you communications about future activities that may interest you. Check this box if you do not wish to receive any further communication from SPFL.”\
- All email messages to members and donors will include an unsubscribe link.
- No opt-out from communications will be provided upfront for supporters because it is implicit in becoming a supporter that the person wishes to stay in contact with SPFL. However they will be able to opt out of email communications at any time.