The Alliance Française de Canberra (AFC) is committed to protecting the privacy of personal information which the organisation handles, uses and manages. Personal information is information which directly or indirectly identifies a person.
The purpose of this document is to provide a framework for the AFC in dealing with privacy considerations.
The AFC seeks to comply with the Australian Privacy Principles (APPs), which are contained in schedule 1 of the Privacy Act and apply from 12 March 2014. These outline how most Australian and Norfolk Island Government agencies, all private sector and not-for-profit organisations with an annual turnover of more than $3 million, all private health service providers and some small businesses (collectively called ‘APP entities’) must handle, use and manage personal information.
The AFC is incorporated in the ACT. There are Territory Privacy Principles in the Information Privacy Act 2014 (ACT) but these apply to ACT public sector agencies. They are substantially similar to the APPs and so the AFC, being a not-for-profit organisation, seeks to comply with the APPs.
The AFC has an annual turnover of less than $3 million and its compliance with the APPs is a policy but not a legal requirement.
The summary of AFC compliance with the APPs, set out below, is based on "Privacy Fact Sheet 17: Australian Privacy Principles" published by the Office of the Australian Information Commissioner" on its website. Further information is available from that source.
AFC COMPLIANCE WITH THE AUSTRALIAN PRIVACY PRINCIPLES (APPs)
APP 1. Open and transparent management of personal information
The AFC will take such steps as are reasonable in the circumstances to implement practices, procedures and systems relating to its functions or activities that will ensure that it complies with the APPs, and which will enable it to deal with inquiries or complaints from individuals about its compliance with the APPs.
The AFC will have a clearly expressed and up to date policy about the management of personal information.
APP 2. Anonymity and pseudonymity
Individuals have the option of not identifying themselves, or of using a pseudonym, when dealing with the AFC in relation to a particular matter.
This option does not apply if, in relation to that matter, the AFC is required or authorised by or under an Australian law, or a court/tribunal order, to deal with individuals who have identified themselves, or it is impracticable for the AFC to deal with individuals who have not identified themselves or who have used a pseudonym.
APP 3. Collection of solicited personal information
The AFC collects personal information from customers when they register on its site or place an order. When ordering or registering on the site, as appropriate, customers may be asked to enter name, email address, mailing address, phone number or credit card information. Customers may, however, visit the site anonymously in accordance with APP 2.
The AFC will not collect personal information (other than sensitive information) unless the information is reasonably necessary for one or more of the AFC's functions or activities.
The AFC will not collect sensitive information about an individual unless the individual consents to the collection of the information and the information is reasonably necessary for one or more of the AFC's functions or activities.
Sensitive information includes information about an individual's:
APP 4. Dealing with unsolicited personal information
If the AFC receives unsolicited personal information it will determine whether or not it could have collected the information under APP 3 if it had solicited it.
If the AFC determines that it could not have collected the personal information, and if the information is not contained in a Commonwealth record, the AFC will destroy the information or ensure that the information is de-identified.
APP 5. Notification of the collection of personal information
When the AFC collects personal information about an individual, the AFC will advise the individual of relevant matters including:
APP 6. Use or disclosure of personal information
Any of the information the AFC collects from customers may be used in one of the following ways:
If at any time a customer would like to unsubscribe from receiving future emails, detailed unsubscribe instructions are included at the bottom of each email.
If the AFC holds personal information about an individual that was collected for a particular purpose (the primary purpose), the AFC will not use or disclose the information for another purpose (the secondary purpose) unless:
This principle does not apply to the use or disclosure by an organisation of personal information for the purpose of direct marketing.
APP 7. Direct marketing
If the AFC holds personal information about an individual, the AFC will not use or disclose the information for the purpose of direct marketing except if:
The AFC may use or disclose sensitive information about an individual for the purpose of direct marketing if the individual has consented to the use or disclosure of the information for that purpose.
If the AFC uses or discloses personal information about an individual for the purpose of direct marketing by the AFC or the purpose of facilitating direct marketing by other organisations, the individual may request not to receive direct marketing communications from the AFC or request the AFC not to use or disclose the information for the purpose of direct marketing.
To the extent that it does not breach the APPs, the AFC does not sell, trade, or otherwise transfer to outside parties personally identifiable information. This does not include trusted third parties who assist the AFC in operating its website, conducting its business, or servicing customers, so long as those parties agree to keep this information confidential. The AFC may also release information when it believes release is appropriate to comply with the law, enforce its site policies, or protect its or others rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.
APP 8. Cross-border disclosure of personal information
Before the AFC discloses personal information about an individual to a person (the overseas recipient):
the AFC will take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the APPs (other than APP 1) in relation to the information.
At the request of individuals, the AFC may organise a linguistic stay through the Alliance Française network in France. The AFC will need to disclose relevant personal information to the Alliance Française of choice.
All customer data is stored and backed up to servers residing in Australia.
APP 9. Adoption, use or disclosure of government related identifiers
The AFC will not adopt a government related identifier of an individual as its own identifier of the individual unless:
The AFC will not use or disclose a government related identifier of an individual unless the use or disclosure of the identifier is reasonably necessary for the AFC to verify the identity of the individual for the purposes of the AFC's activities or functions.
APP 10. Quality of personal information
The AFC will take such steps as are reasonable in the circumstances to ensure that the personal information that it collects is accurate, up-to-date and complete.
The AFC will take such steps as are reasonable in the circumstances to ensure that the personal information that it uses or discloses is, having regard to the purpose of the use or disclosure, accurate, up-to-date, complete and relevant.
APP 11. Security of personal information
If the AFC holds personal information, it will take such steps as are reasonable in the circumstances to protect the information from misuse, interference and loss; and from unauthorised access, modification or disclosure.
If the AFC holds personal information about an individual; and
The AFC uses Secure Socket Layer (SSL) for capture and to administer customer data.
APP 12. Access to personal information
If the AFC holds personal information about an individual, the AFC will, on request by the individual, give the individual access to the information except if:
APP 13. Correction of personal information
If personal details, such as address, name or email address, change, customers are asked to tell the AFC straight away.
If the AFC holds personal information about an individual and the AFC is satisfied that, having regard to a purpose for which the information is held, the information is inaccurate, out of date, incomplete, irrelevant or misleading; or if the individual requests the entity to correct the information, the AFC must take such steps as are reasonable in the circumstances to correct that information.
If the AFC refuses to correct the personal information as requested by the individual, the AFC will give the individual a written notice that sets out:
We encourage you to check our website regularly for any updates to the Policy.
How to contact us
If you wish to access your personal information or have any complaints
You can contact us at:
PO Box 6125, O’Connor ACT 2602
and we will respond appropriately.