Amara Residences Privacy Policy
1. Policy Purpose
a. | Amara Residences, its subsidiaries and affiliates in Australia (collectively referred to as “we” and “us”) are committed to managing personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and in accordance with other applicable privacy laws. | ||||||||
b. | This policy sets out how we intend to do so to ensure Amara Residence’s associated entities and all Amara Residences act in a serious and committed manner to meet obligations under the Privacy Act, ensuring personal or sensitive information is collected, held, used, and disclosed in accordance with the Australian Privacy Principles (APP) and in accordance with other applicable privacy laws. | ||||||||
c. | In this Privacy Policy, “we” and “us” refers to Amara Residences and “you” refers to any individual about whom we collect personal information. | ||||||||
d. | To ensure all legislated notifiable breaches are identified, investigated and communicated as per legislative requirements of the Privacy Amendment (Notifiable Data Breaches) Act 2017. To comply with our obligations under the Australian Privacy Principles (APP), as set out in the Privacy Act 1988 (Cth) and the Privacy Amendment (enhancing Privacy Protection) Act 2012 (Cth). | ||||||||
e. | To support the privacy and confidentiality rights of residents, staff and visitors to Amara Residences by meeting the requirements of the Surveillance Devices Act 2007 and to ensure all resident staff and visitors are informed of and understand the surveillance mechanisms in place and the requirements of the Surveillance Devices Act 2007 are met at the facility. | ||||||||
f. | The Policy applies to all persons/stakeholders involved in Amara Residences. This includes: | ||||||||
|
|||||||||
g. | Please contact us for a full list of the companies which comprise Amara Residences and which are subject to this Privacy Policy. |
2. Definitions
a. | Personal information Is defined as any ‘information or an opinion about an identified individual, or an individual who is reasonably identifiable’. |
||||||||||||||||||||
b. | Sensitive information Is a subset of personal information and is defined as information or an opinion (that is also personal information) about an individual’s:
|
||||||||||||||||||||
c. | Notifiable data breach Where there has been unauthorised access or disclosure of personal information it holds, or such information has been lost in circumstances where it is likely to lead to unauthorised access or disclosure; and a reasonable person would conclude that such access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates. |
||||||||||||||||||||
d. | Surveillance device Means a data surveillance device, a listening device, an optical surveillance device, or a tracking device. Amara Residences have video surveillance for security of the workplace. The surveillance cameras are located in general work areas, including kitchen, treatment rooms and corridors on all levels, building exit/entry access points and car park. All employees are notified during orientation and it is documented Amara Residences Privacy Policy Page 2 of 10 Last Updated: November 2023 in the employment agreement and staff handbook that Amara Residences has video surveillance in the workplace. |
||||||||||||||||||||
e. | Listening device Means any device capable of being used to overhear, record, monitor or listen to a conversation or words spoken to or by any person in conversation, but does not include a hearing aid or similar device used by a person with impaired hearing to overcome the impairment. |
||||||||||||||||||||
f. | Optical surveillance device Any device capable of being used to record visually or observe an activity, but does not include spectacles, contact lenses or a similar device used by a person with impaired sight to overcome that impairment. |
||||||||||||||||||||
g. | Tracking device Any electronic device capable of being used to determine or monitor the geographical location of a person or an object. |
||||||||||||||||||||
h. | Person responsible The term “Next of Kin” was replaced by “Person Responsible” by the Guardianship Act of 1987. There is a clear hierarchy set out by the Guardianship Act as follows;
|
3. Types Of Personal Information Collected
The organisation collects and holds the personal information of residents, employees, volunteers, and contractors. ‘Personal information’ means information we hold about the individual from which their identity is either clear or can be reasonably determined. The personal information we may hold includes the following: |
a. | Residents
|
||||||||||||||||||||||||||||||||||||
b. | Employees
|
||||||||||||||||||||||||||||||||||||
c. | Volunteers
|
||||||||||||||||||||||||||||||||||||
d. | Contractors
|
||||||||||||||||||||||||||||||||||||
e. | Other individuals
|
||||||||||||||||||||||||||||||||||||
f. | Visitors to our website The way in which we handle the personal information of visitors to our websites is discussed below. |
||||||||||||||||||||||||||||||||||||
4. How And Why Does Amara Residences Collect And Use Your Personal Information?
a. | Amara Residences collects personal information reasonably necessary to carry out our business, to assess and manage our residents’ needs, and provide services for independent living. We may also collect information to fulfil administrative functions associated with these services, for example billing, entering into contracts with you or third parties and managing resident or representative relationships or external service providers (medical officers, allied health practitioners/personnel, suppliers and contractors). | ||||||||||||||||
b. | The purposes for which Amara Residences usually collects and uses personal information depends on the
nature of your interaction with us, but may include:
|
||||||||||||||||
c. | Amara Residences generally collects personal information directly from you. We may collect and update
your personal information over the phone, by email, over the internet or social media, or in person. We may
also collect personal information about you from other sources, for example:
|
||||||||||||||||
d. | Amara Residences also collects and uses personal information for market research purposes and to innovate our delivery of products and services. | ||||||||||||||||
e. | Generally, only personal information is collected if it is necessary to provide health services and to comply with our obligations under Australian law (e.g. tax office obligations, immigration legislation, industrial instruments, etc.) or a court/tribunal order. | ||||||||||||||||
f. | Where information is collected from other sources, Amara Residences will inform the individual that we will hold their personal information. | ||||||||||||||||
g. | In some circumstances Amara Residences may be provided with personal information about an individual from a third party, for example a report provided by a medical professional, hospital or an employee reference from another person. | ||||||||||||||||
h. | Unsolicited information such as personal information that is not relevant to the functions of the organisation will be ‘de-identified’ or destroyed as soon as practicable. | ||||||||||||||||
i. | The potential consequences of not allowing us to collect and hold the required personal information may
be that we are unable to:
|
5. How Does Amara Residences Interact With You Via The Internet?
a. | You may visit our website (www.amararesidences.com.au) without identifying yourself. If you identify yourself (for example, by providing your contact details in an enquiry), any personal information you provide to Amara Residences will be managed in accordance with this Privacy Policy. |
b. | Amara Residences website uses cookies. A “cookie” is a small file stored on your computer’s browser, which assists in managing customised settings of the website and delivering content. We collect certain information such as your device type, browser type, IP address, pages you have accessed on our websites and on third-party websites. You are not identifiable from such information. |
c. | You can use the settings in your browser to control how your browser deals with cookies. However, in doing so, you may be unable to access certain pages or content on our website. |
d. | Amara Residences’ website may contain links to third-party websites. Amara Residences is not responsible for the content or privacy practices of websites that are linked to our website. |
6. Can You Deal With Amara Residences Anonymously?
Amara Residences will provide individuals with the opportunity to remain anonymous or use a pseudonym in their dealings with us where it is lawful and practicable (for example, when making a general enquiry). Generally, it is not practicable for Amara Residences to deal with individuals anonymously or pseudonymously on an ongoing basis. If we do not collect personal information about you, you may be unable to utilise our services or participate in our events, programs or activities we manage or deliver. |
7. Consent
a. | A Privacy and Confidentiality Agreement for staff and volunteers is made upon employment and engagement, respectively. A Privacy Exceptions Log that records the wishes of residents where they do not agree with any of the privacy options on the Resident Privacy Consent Form is communicated to relevant staff. | ||||||
b. | Consent is reviewed every 12 months in line with the annual case conference process. Where the resident is unable to provide written consent but has capacity to consent, the Privacy Agreement will be completed in accordance with the resident’s wishes. | ||||||
c. | A Resident has the right to withdraw or alter their privacy consent at any time. | ||||||
d. | Consent Can be:
|
||||||
e. | Consent can be obtained in writing or verbally. |
8. How Does Amara Residences Hold Information?
a. | Amara Residences stores information in paper-based files or other electronic record keeping methods in secure databases (including trusted third party storage providers based in Australia or overseas). Amara Residences Privacy Policy Page 5 of 10 Last Updated: November 2023 Personal information may be collected in paper-based documents and converted to electronic form for use or storage (with the original paper-based documents either archived or securely destroyed). We take reasonable steps to protect your personal information from misuse, interference and loss and from unauthorised access, modification or disclosure. |
b. | Amara Residences maintains physical security over paper and electronic data stores, such as through locks and security systems at our premises. We also maintain computer and network security, for example, we use firewalls (security measures for the internet) and other security systems such as user identifiers and passwords to control access to our computer systems. |
c. | Our websites do not necessarily use encryption or other technologies to ensure the secure transmission of information via the internet. Users of our websites are encouraged to exercise care in sending personal information via the internet. |
d. | We take steps to destroy or de-identify information that we no longer require. |
9. Does Amara Residences Use Or Disclose Your Personal Information For Direct Marketing?
a. | Amara Residences may use or disclose your personal information for the purpose of informing you about our services, upcoming promotions and events, or other opportunities that may interest you. If you do not want to receive direct marketing communications, you can opt-out at any time by contacting us using the contact details below. |
b. | If you opt-out of receiving marketing material from us, Amara Residences may still contact you in relation to its ongoing relationship with you. |
10. How Does Amara Residences Use And Disclose Personal Information?
a. | For Residents
|
||||||||||||||||||
b. | For consumers and participants
|
||||||||||||||||||
c. | Disclosure to contractors and other service providers
|
||||||||||||||||||
d. | Use and disclosure for administration and management Amara Residences will also use and disclose personal information for a range of administrative, management and operational purposes. This includes:
|
||||||||||||||||||
e. | Other uses and disclosures We may use and disclose your personal information for other purposes explained at the time of collection or otherwise as set out in this Privacy Policy. However:
|
||||||||||||||||||
f. | Personal information may be disclosed if we:
|
||||||||||||||||||
g. | Personal information may be disclosed to other persons as part of the provision of health services,
including:
|
11. Security And Storage Of Personal Information
a. | The APPs require us to take reasonable steps to protect the security of the personal information that we hold from misuse, loose, unauthorised access, modifications or disclosure. This includes appropriate measures to protect electronic materials and materials stored and generated in hard copy. |
b. | Amara Residences personnel are required to respect the confidentiality of personal information and the privacy of individuals. |
c. | We will hold all personal information in a secure and confidential manner and take all reasonable steps to ensure personal information is secure (e.g. all computers have password access, and personal information is kept in secure areas). |
d. | All of our electronic systems that hold personal information have up-to-date security protection systems. These are reviewed on a regular basis and tested to ensure they are efficient and able to meet any potential “interference” that might occur. |
e. | Staff who have access to personal information are provided with education and information about their obligations concerning confidentiality of personal information and the privacy of individuals. AmaraResidences will ensure secure disposal of electronic and paper-based records. |
f. | Where we no longer require your personal information for a permitted purpose under the APPs, we will take reasonable steps to destroy it. |
12. Access To Information
a. | Subject to the exceptions set out in the Privacy Act, Amara Residences will take all reasonable steps to provide access to the personal information that we hold within a reasonable period of time in accordance with the Australian Privacy Principles. | ||||||||||||
b. | Subject to the exceptions set out in the Privacy Act, an individual may request to gain access to their personal information held by Amara Residences by applying in writing to the Executive Manager of the facility you are associated with. Prior to disclosing any information, the Executive Manager is to refer to Amara Residences Privacy Policy Page 7 of 10 Last Updated: November 2023 the Chief Operating Officer and Village Manager. | ||||||||||||
c. | Information will not be disclosed to any outside bodies or individuals unless we are legally bound to do so. | ||||||||||||
d. | We may not provide access to the personal information we hold about an individual when:
|
||||||||||||
e. | Amara Residences will provide reasons for denying or refusing access to personal information in writing. This correspondence will include information concerning the mechanisms for lodging a complaint. |
Please note: If the resident is currently alive and staying in Amara Residences, we can provide the information to the person with Enduring Power of Attorney (EPOA). Once the resident is deceased, the EPOA is no longer valid and the request of information must be made by the Executor. Please make sure to escalate any request of information subjected to legal proceedings to the Head Office, as indicated. |
13. Surveillance
a. | Any devices in use will be supplied by Amara Residences. Staff are advised and supported to not use personal devices for surveillance. Staff are encouraged to report any matters of concern relating to the delivery of care and services to the Village Manager. | ||||
b. | Any surveillance material stored electronically will be archived and destroyed as per policy. | ||||
c. | Listening devices Listening devices will not be used at our service other than to record a conversation or meeting to which all parties consent, expressly or impliedly, to the listening device being used. Permission to use the device must be documented at the commencement of the meeting and stored with minutes of the meeting. |
||||
d. | Optical surveillance devices Cameras will only be used with the consent of resident or staff member. The camera will be a device supplied by Amara Residences. Personal cameras are not to be used under any circumstances. Examples of approved camera use may include:
|
||||
c. | CCTV is installed at the facility and signage is installed to advise all visitors to the service of the use of this device. | ||||
d. | CCTV is installed in common areas only excluding bathrooms and change rooms. | ||||
e. | Safety tracking devices Safety tracking devices such as alert bands or anklets will only be used with the consent of the resident or their legal representative. Management will discuss the use of this device with the resident or representative and will record this conversation in progress notes and in the care plan. |
14. Quality And Correction Of Personal Information
a. | How can you access or seek correction of your personal information?
|
||||||||||
b. | Amara Residences will take all reasonable steps to ensure that the personal information we collect, use, hold, or disclose is accurate, complete and up to date. Individuals may request that personal information we hold is corrected if it is inaccurate, out of date, incomplete, irrelevant or misleading. | ||||||||||
c. | Amara Residences will take all reasonable steps to correct the personal information we hold. Amara Residences will provide reasons for not complying with requests to correct personal information in writing. |
15. Notifiable Data Breach And Loss Of Personal Information
a. | If Amara Residences becomes aware of reasonable grounds to believe that:
|
||||||||||||||||||
b. | Then Amara Residences will respond following these key steps:
|
||||||||||||||||||
c. | You can obtain further general information about your privacy rights and privacy law from the Chief
Operating Officer or the Office of the Australian Information Commissioner by:
|
||||||||||||||||||
d. | In the event of loss of personal information, we will:
|
16. Privacy Breaches And Reviews
a. | Where a person believes that a breach of this policy or the Privacy Act has occurred, it should be referred to the Chief Operating Officer in writing. | ||||||||||
b. | If you have any complaints about our privacy practices or wish to make a complaint about how your personal information is managed, please contact the Chief Operating Officer to request an internal review. | ||||||||||
c. | This application should be made within six months from the time the applicant became aware of the alleged breach or inappropriate disclosure. | ||||||||||
d. | All complaints will be dealt with confidentially and promptly. Residents, families, friends or staff who have complaints about how Amara Residences have dealt with personal information may apply for an internal review. | ||||||||||
e. | Applications for an internal review may concern conduct a person believes is:
|
||||||||||
f. | Application for the internal review should be made in writing to the Chief Operating Officer. This application should be made within six months from the time the applicant became aware of the alleged breach or inappropriate disclosure. | ||||||||||
g. | Nomination of internal review team In receiving an application and conducting an internal review under the Privacy Act, we will nominate an investigation team within two weeks of receiving the compliant by the Chief Operating Officer (Privacy Officer). |
||||||||||
h. | IT Security and data breaches Apek provides Amara Residences with IT support and security. Under the Privacy Act 1988 (Cth), as amended by the Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth) (Privacy Act) an “Eligible Data Breach” happens if:
|
||||||||||
i. | Apek shall, at all times, comply with its obligations under the Privacy Act. | ||||||||||
j. | If Apek, at any time, has reasonable grounds to suspect that there may have been an unauthorised access
to, disclosure of, or loss of, information of Amara Residences that could potentially result in an Eligible
Data Breach, Apek shall:
|
17. Conducting A Privacy Review
a. | The internal review team will take the following steps in conducting the review:
|
||||||||||||||
b. | Completion of Internal review Once an application for an internal review is received, the review will be completed as soon as reasonably Amara Residences Privacy Policy Page 10 of 10 Last Updated: November 2023 practicable. Once the review is completed the Chief Operating Officer, in consultation with the Managing Director, may decide to:
|
||||||||||||||
c. | You can obtain further general information about your privacy rights and privacy law from the Office of the
Australian Information Commissioner by:
|
18. Refusal To Provide Information
You are not obliged to give us your personal information. However, if you choose not to provide Amara Residences with personal details we may not be able to provide accommodation for a resident, a position of employment or service agreement in our residences. It may also restrict our ability to assist you in accessing some other services. |
19. References
• | Retirement Villages Act 1999 No 81 |
• | Australian Privacy Principles 2014 |
• | Privacy Act 1988 (Cth) |
• | Privacy Amendment (enhancing Privacy Protection) Act 2012 (Cth) |
• | Relevant State & Territory Privacy Acts |
• | The Privacy Amendment (Notifiable Data Breaches) Act 2017 |
• | Surveillance Devices Act 2007 (NSW) |
Privacy Officer's Name:
Esperanza Arias Calli
Chief Operating Officer
Privacy Officer's Phone Number:
(02) 8437 1707
Privacy Officer's Email Address:
EAriasCalli@pathways.com.au
Approval Date:
28/07/2023
Effective Date:
28/07/2023
Review Year:
2024
Policy Advisor:
Policy and Document Control Review
Committee
Approving Authority:
Policy Review Committee