CyberSec People Pty Ltd takes seriously its commitment to preserve the privacy of your personal information that we collect.
We will only collect information that is reasonably necessary for the proper performance of our activities or functions as a recruitment agency.
We do not collect personal information just because we think it could be useful at some future stage if we have no present need for it.
We do not collect or use personal information for the purposes of unlawful discrimination.
We may decline to collect unsolicited personal information from or about you and CyberSec People Pty Ltd may take such measures as we think appropriate to purge it from our systems.
If you have any questions, please contact us.
2. Information Collection
CyberSec People Pty Ltd manages personal information, as an APP Entity, under the Australian Privacy Principles (APPs).
We will collect personal information from you directly when you fill out and submit one of our registration forms, provide your resume document or any other information in connection with your application to us for work.
If you wish to know whether this applies to you, please contact us.
2.1 Information Flow
When CyberSec People Pty Ltd collects personal information, we will:
Check that it is reasonably necessary for our functions or activities (see section 4 – ‘Purposes’) as a recruitment agency;
Check that it is current, complete and accurate. This will sometimes mean that we have to cross check the information that we collect from you with third parties;
Record and hold your information in our Information Record System (see section 6 – ‘How your personal information is held’). Some information may be disclosed to overseas recipients but only if necessary as part of our activities as a recruitment agency (see section 7 – ‘Disclosures’);
Retrieve your information when we need to use or disclose it for our functions and activities as a recruitment agency (see section 4 – ‘Purposes’). At that time, we check that it is current, complete, accurate and relevant. This will sometimes mean that we have to cross check the information that we collect from you with third parties once again – especially if some time has passed since we last checked;
Subject to some exceptions, we permit you to access your personal information in accordance with APP:12 of the (APPs);
Correct or attach associated statements to your personal information in accordance with APP:13 of the (APPs);
Destroy or de-identify your personal information when it is no longer needed for any purpose (see section 4 – ‘Purposes’) for which it may be used or disclosed provided that it is lawful for us to do so. We do not destroy or de-identify information that is contained in a Commonwealth Record.
2.2 Future Changes
This policy may change over time in light of changes to privacy laws, technology and business practice. If you use our website regularly or conduct transactions with us that involve to collection of your personal information, it is important that you check this policy regularly to ensure that you are aware of the extent of any consent, authorisation or permission you might give.
3. Kinds of Information that we Collect and Hold
The type of personal information that we collect and hold is information that is reasonably necessary for the proper performance of our functions and activities as a recruitment agency (see section 4 – ‘Purposes’) and is likely to differ depending on whether you are:
A Candidate – i.e. someone who is looking for a placement or work through us; or whom we have identified as a person who might be receptive to an offer of a placement or work through us;
A Client – i.e. someone other than a Candidate who is looking to acquire our services as a recruitment agency;
A Referee – i.e. a person from whom we have sought facts or opinions regarding the suitability of one of our Candidates for work or positions through us; and who may be a Referee nominated by the Candidate, a Client or us.
Sensitive information is only collected with consent and where it is necessary for the performance of our functions and activities as a recruitment agency.
Sensitive information will need to be collected where it relates to a genuine occupational requirement or an inherent requirement of the job or work being considered. Our collection of some types of sensitive information is also governed by equal opportunity and anti-discrimination laws.
3.1 For Candidates
The type of information that we typically collect and hold about Candidates is information that is necessary to assess amenability to work offers and work availability; suitability for placements; or to manage the performance in work obtained through us.
Information submitted and obtained from Candidates and other sources (e.g. Referees or Clients) in connection with applications for work;
information about personality, character, skills, qualifications and experience;
Information about career path and preferences;
Information about work entitlement and ability to undertake specific types of work;
Work performance information;
Information about incidents in the workplace;
Personal information including contact details;
Information submitted and obtained in relation to absences from work due to leave, illness or other causes;
Bank details and Australian Business Number, for the purposes of invoicing Clients on a Candidate’s behalf and for direct payment during/following placement with some Clients;
Information required to undertake criminal history checks and obtain criminal history records;
Information required to ascertain a Candidate’s right to work in Australia – i.e. confirmation of citizenship, residency or visa status;
health and immunisation records.
3.2 For Clients
The type of information that we typically collect and hold about Clients is information that is necessary to help us manage the presentation and delivery of our services and includes:
Client relationship information;
Information about position, contracting and hiring authority;
Information about team structures and roles;
Information about incidents in the workplace;
Client facility addresses, key personnel and contact details;
3.3 For Referees
The type of information that we typically collect and hold about Referees is information that is necessary to help to make determinations about the suitability of one of our Candidates for particular jobs or particular types of work and may include:
Information about work position, authority to give a reference and preferred contact details;
Opinions of the Referee regarding the Candidates character and work performance or work environment;
Facts or evidence in support of those opinions, sometimes involving the Referee’s own knowledge and experience of having worked with the Candidate.
The purposes for which we collect, hold, use and disclose your personal information are those purposes that are reasonably necessary for the proper performance of our functions and activities as a recruitment agency and are likely to differ depending on whether you are:
The following sections are also relevant to our use and disclosure of your personal information:
Our Policy on Direct Marketing;
4.1 For Candidates
Information that we collect, hold, use and disclose about Candidates is typically used for:
Work placement operations;
Training needs assessments;
Workplace health and safety operations;
Marketing services to you; but only where this is permitted and whilst you are registered with us;
Statistical purposes and statutory compliance requirements.
4.2 For Clients
Personal information that we collect, hold, use and disclose about Clients is typically used for:
Client and business relationship management;
Work placement operations;
Training needs assessments;
Workplace health and safety operations;
Marketing services to you;
Statistical purposes and statutory compliance requirements.
4.3 For Referees
Personal information that we collect, hold, use and disclose about Referees is typically used for:
To confirm identity and authority to provide references;
Candidate suitability assessment;
4.4 Our Policy on Direct Marketing
We may use your personal information for the purposes of direct marketing except where you have specifically requested we don’t. We market to Candidates and Clients using a variety of methods including email, phone and print.
We provide Candidates and Clients the option to opt out of receiving marketing material from CyberSec People Pty Ltd. Upon receipt of this request their marketing preferences are updated on our systems.
If you do not wish to have your personal information used for direct marketing purposes, you may contact your Consultant or our Privacy Coordinator and request not to receive direct marketing communications from us, at which time your marketing preferences will be updated on our systems.
5. How your personal information is collected
The means by which we will generally collect your personal information are likely to differ depending on whether you are:
Sometimes the technology that is used to support communications between us will provide personal information to us. See section 5.5 – ‘Electronic Transactions’.
5.1 For Candidates
Personal information will be collected from you directly when you fill out and submit one of our application forms or any other information in connection with your application to us for work.
Personal information is also collected when:
We receive or give any reference about you;
We receive results of inquiries that we might make of your former employers, work colleagues, professional associations or registration body;
We receive the results of any competency, psychometric, or medical test;
We receive performance feedback (whether positive or negative);
We receive any complaint from or about you in the workplace;
We receive any information about a workplace accident in which you are involved;
We receive any information about any insurance investigation, litigation, registration or professional disciplinary matter, criminal matter, inquest or inquiry in which you are involved;
You provide us with any additional information about you.
5.2 For Clients
Personal information about you may be collected:
When you provide it to us for business or business related social purposes;
electronically through our telecommunications and technology systems. See section 5.5 – ‘Electronic Transactions’.
5.3 For Referees
Personal information about you may be collected when you provide it to us:
In the course of our checking Candidate references with you and when we are checking information that we obtain from you about Candidates;
for business or business related social purposes;
Electronically through our telecommunications and technology systems. See section 5.5 – ‘Electronic Transactions’.
5.4 Photos & Images
We may request proof of identification from you including copies of your passport, visa and or driver’s license and will only do so for the performance of our functions and activities as a recruitment agency.
You should also read the section about Electronic Transactions because sometimes your communications with us may attach profile images of yourself that you have uploaded to the Internet.
5.5 Electronic Transactions
This section explains how we handle personal information collected from our website and by other technology in the course of electronic transactions.
It is important that you understand that there are risks associated with use of the internet and you should take all appropriate steps to protect your personal information. It might help you to look at the OAIC’s resource on Internet Communications and other Technologies:
It is important that you:
Be careful what information you share on the Internet;
use privacy tools on the site – control access to your search listing and profile;
Make sure your anti-virus and data protection software is up-to-date.
Please contact us by phone or mail if you have concerns about making contact via the Internet.
Sometimes, we collect personal information that individuals choose to give us via online forms or by email. For example, when individuals:
Ask to be on an email list such as an opportunity notification list;
Make a written online enquiry or email us through our website;
Submit a resume by email or through our website;
Make a job application to us through an external job board or website;
Follow and communicate with us via social media such as LinkedIn and Twitter.
5.5.1 Social Networks and Web Searches
In order to assess your suitability for positions and to assist you to find work, we conduct internet searches using search engines and regulatory or government agency sites by entering your name and relevant identifying details.
5.5.2 Web Browsing
When you look at our website, our website host makes a record of the visit and logs (in server logs) the following information for statistical purposes:
Your server address;
Your top level domain name (for example .com, .gov .au, .net.au etc);
The pages you accessed and documents downloaded;
The previous site you visited and;
The type of browser being used.
We do not identify users or their browsing activities except, in the event of an investigation, where a law enforcement agency may exercise a warrant to inspect the internet service provider’s server logs.
Cookies are uniquely numbered identification numbers like tags which are placed on your browser. By themselves cookies do not identify you personally, but they may link back to a database record about you.
If you do not wish us to retain any information about your visit to our site you might consider deleting the cookies on your browser and changing the settings on your web browser program.
5.5.4 Cloud Computing Services
In cases where we use cloud computing services we will take reasonable steps to ensure that:
Disclosure of your personal information to the cloud service provider is consistent with our disclosure obligations under the APPs. This may include ensuring that we have obtained your consent, or that the disclosure is for purposes within your reasonable expectations;
Disclosure is consistent with any other legal obligations, such as the restrictions on the disclosure of tax file number information or the disclosure by private employment agencies of Candidate details;
Our Cloud computing services provider’s terms of service recognise that we are bound by obligations to protect the privacy of your personal information and that they will not do anything that would cause us to breach those obligations.
5.5.5 Uploading Photographs
Please make sure that you do not upload photographs of any individuals who have not given consent to the display of their photograph. Displaying photographs without that person’s consent may breach privacy laws, and you may be responsible for any legal consequences.
Our technology systems log emails received and sent and may include read and delivery receipt notifications to enable tracking.
When your email address is received by us because you send us a message, the email address will only be used or disclosed for the purpose for which you have provided it and it will not be added to a mailing list or used or disclosed for any other purpose without your consent other than as may be permitted or required by law.
5.5.7 Call & Message Logs
Our telephone technology (systems and mobile phones) logs telephone calls, messages received and sent and enables call number display, which may include your profile picture if you have provided it.
When your call number is received by us because you phone us or send us a message, the number (and profile picture) will only be used or disclosed for the purpose for which you have provided it and it will not be added to a phone list or used or disclosed for any other purpose without your consent other than as may be permitted or required by law.
5.5.8 Teleconferences & Video Conferences
Teleconferences and video conferences may be recorded with your consent. In cases where it is proposed that they be recorded, we will tell you first the purpose for which they are to be used and retained.
We may use a cloud-based database to log and record recruitment operations. This database contains the information and documentation you have provided us. This database operates from servers that permit disclosure to cross-border recipients.
Your information will only be used or disclosed as reasonably necessary for the performance of our functions and activities as a recruitment agency.
5.5.10 Mobile Access
Our staff use laptops, tablets, phones and other portable electronic devices that allow them to access, retrieve and store your personal information.
6. How your Personal Information is Held
When your personal information is collected it will be held in our Information Record System until it is no longer needed for any purpose for which it may be used or disclosed, at which time it will be de-identified or destroyed provided that it is lawful for us to do so.
We take a range of measures to protect your personal information and these are outlined further in section 6.2 – ‘Information Security’.
There are some inherent risks in the use of the Internet Communications and other Technologies. For more information, go to:
It is important that you read the section on Electronic Transactions and Cross-Border Disclosure if you are using internet communications or other technologies to communicate with us.
6.1 Our Information Record System
Information you provide to us is stored in our secure cloud-based database, which is restricted and accessible by staff through the use of individual log-in credentials.
Information may also be securely stored in hard copy in a lockable filing system until such time as it is digitised and that information filed in our cloud-based document storage system. When this occurs, the hard copy document/s are subsequently destroyed. Your information is also securely retained as part of our backup and Disaster Recovery processes.
Where we utilise Cloud computing services, please also refer to section ‘5.5 – Electronic Communications – Cloud Computing Services’ to understand our obligations.
6.2 Information Security
We will take all reasonable steps to ensure the information you provide us remains secure and confidential and is only used for the performance of our activities or functions as a recruitment agency.
We take a range of measures to protect your personal information from misuse, interference and loss, unauthorised access, modification or disclosure. These
Password-protection of cloud-based database and messaging systems;
“Clean desk” procedures;
Secure premises with restricted access;
Need-to-know and authorisation policies;
Policies on laptop, mobile phone and portable storage device security;
Document culling procedures including shredding and secure disposal.
This section deals with our disclosure policies. Personal Information that we hold about you is only disclosed for the primary and related purposes for which it was collected. In this section you will find out about our policies dealing with:
Related Purpose Disclosures;
Cross Border Disclosures.
7.1 General Disclosures
We may disclose your personal information for any of the purposes for which it is primarily held or for a related purpose where lawfully permitted.
We may disclose your personal information where we are under a legal duty to do so, including circumstances where we are under a contractual duty to disclose information.
Disclosure will usually be:
Internally and to our related entities;
To our Clients;
To Referees for suitability and screening purposes.
In addition to disclosures for general purposes, we may also disclose your personal information for a range of related purposes.
7.2 Related Purpose Disclosures
We outsource a number of services to service providers (SPs) from time to time. Our SPs may see some of your personal information. Typically, our SPs would include:
Software solutions providers;
Legal and other professional advisors;
Insurance brokers, loss assessors and underwriters;
Background checking and screening agents.
We take reasonable steps to ensure that terms of service with our SPs recognise that we are bound by obligations to protect the privacy of your personal information and that they will not do anything that would cause us to breach those obligations.
7.3 Cross-Border Disclosures
Some of your personal information is likely to be disclosed to overseas recipients. The likely countries, type of information disclosed and likely recipients are indicated, so far as is practicable, in the following table:
United States of America, United Kingdom, Ireland, Singapore;
Type of Information:
Any information held on our cloud-based messaging systems or database;
Some of our technology service providers hold data on their servers in a range of countries to provide back-up contingencies in the event of significant outages in one or more server locations.
We will take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles.
However, we cannot guarantee that any recipient of your personal information will protect it to the standard to which it ought to be protected. The costs and difficulties of enforcement of privacy rights in foreign jurisdictions and the impracticability of attempting to enforce such rights in some jurisdictions will mean that in some instances, we will need to seek your consent to disclosure.
8. Access & Correction
You have a right to access and correct personal information under the Australian Privacy Principles (APPs).
9. Road Map
This section sets out our policy dealing with:
See also: section 10 – ‘Complaints’.
Subject to some exceptions that are set out in privacy law, you can gain access to the personal information that we hold about you.
Important exceptions include:
Evaluative opinion material obtained confidentially in the course of our performing reference checks and access that would impact on the privacy rights of other people. We do refuse access if it would breach any confidentiality that attaches to that information or if it would interfere with the privacy rights of other people. In many cases evaluative material contained in references that we obtain will be collected under obligations of confidentiality that we make and which the communicator of that information is entitled to expect will be observed.
If you wish to obtain access to your personal information you should contact our Privacy Co-ordinator on 0413 244757. You will need to be in a position to verify your identity. We might impose a moderate charge in providing access. Our Privacy Co-ordinator would discuss this with you.
You should also anticipate that it may take a little time to process your application for access as there may be a need to retrieve information from storage and review information in order to determine what information may be provided. We will generally respond to your request for access within five (5) working days.
If we refuse to give access to the personal information or to give access in the manner requested by you, we will give you a written notice that sets out:
The reasons for the refusal except to the extent that, having regard to the grounds for the refusal, it would be unreasonable to do so; and
The mechanisms available to complain about the refusal.
If you find that personal information that we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to correct it by contacting us.
We will take such steps as re reasonable in the circumstances to correct that information to ensure that, having regard to the purpose for which it is held, the information is accurate, up to date, complete, relevant and not misleading.
If we have disclosed personal information about you that is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to notify the third parties to whom we made the disclosure and we will take such steps (if any) as are reasonable in the circumstances to give that notification unless it is impracticable or unlawful to do so.
You should also anticipate that it may take a little time to process your application for correction as there may be a need to retrieve information from storage and review information in order to determine what information may be corrected. We will generally respond to your request for access within five (5) working days.
There is no charge to correct information.
In some cases we may not agree that the information should be changed.
If we refuse to correct your personal information as requested by you, we will give you a written notice that sets out:
The reasons for the refusal except to the extent that it would be unreasonable to do so; and
The mechanisms available to complain about the refusal.
You may also ask us to associate a statement that the information is contested as being inaccurate, out of date, incomplete, irrelevant or misleading and we will take such steps as are reasonable to do so.
You have a right to complain about our handling of your personal information if you believe that we have interfered with your privacy.
In this section you can learn:
How to complain;
How your complaint will be handled.
See also section 8 – ‘Access & Correction’.
9.1 How to complain
If you are making a complaint about our handling of your personal information, it should first be made to us in writing.
You can make complaints about our handling of your personal information to our Privacy Co-ordinator on +61 413 244575 or email firstname.lastname@example.org.
You can also make complaints to the Office of the Australian Information Commissioner.
9.2 How your complaint will be handled
When we receive your complaint:
We will take steps to confirm the authenticity of the complaint and the contact details provided to us to ensure that we are responding to you or to a person whom you have authorised to receive information about your complaint;
Upon confirmation we will write to you to acknowledge receipt and to confirm that we are handling your complaint in accordance with our policy.
We may ask for clarification of certain aspects of the complaint and for further detail;
We will consider the complaint and may make inquiries of people who can assist us to established what has happened and why;
We will require a reasonable time (usually 30 days) to respond;
If the complaint can be resolved by procedures for access and correction we will suggest these to you as possible solutions;
If we believe that your complaint may be capable of some other solution we will suggest that solution to you, on a confidential and without prejudice basis in our response;
Complaints may also be referred to the Office of the Australian Information Commissioner.