We are committed to protecting your privacy. This policy explains how we handle personal information collected through this website and our services.
01
Compliance & Risk Services Pty Ltd (Compliance & Risk Services) does not collect personal information from its clients or users of our website.
Some personal information may be collected by users of our web-based tool, CRS-Certus. Users of CRS-Certus are responsible for the collection, management, protection and destruction of any personal information they collect and hold on CRS-Certus. Compliance & Risk Services has no control of information gathered, stored, used and destroyed by users of CRS-Certus.
The types of information stored by users of CRS-Certus may possibly include personal information such as:
When recruiting employees or appointing contractors Compliance & Risk Services may collect and hold personal information such as: the individual’s name, contact details, date of birth, citizenship, employment references, civil credit and criminal records, regulatory accreditation (such as RG 146 accreditation persons who may provide general financial product advice to retail clients) driver’s licence information, education and employment history.
Once appointed we will also collect and hold TFNs, financial information relating to the appointing and banking details for payments.
02
Users of CRS-Certus may collect personal information directly from their clients and upload that into databases comprising the service.
Compliance & Risk Services may collect personal information from employees by request.
03
Users of CRS-Certus may collect hold, use and disclose personal information for the purposes of evidencing controls and practices relating to the:
04
Personal information is stored in a secure environment on CRS-Certus.
Personal information is only made available to users of CRS-Certus and, if permitted by those users, employees of Compliance & Risk Services on a need-to-know basis to perform their obligations and duties.
Compliance & Risk Services maintains information security standards and requires similar standards to be maintained by our service providers. Cybersecurity is monitored through our enterprise risk management framework and we consider both technical and organisational measures when we developed our IT systems and data controls.
05
We will implement corrective plans if our security measures are breached or your personal information is lost or inadvertently accessed by an unauthorised person. The priority of any plan would be to secure your personal information if it is lost or accessed where possible. If this is not possible, we will inform you of the loss or access and we will undertake an assessment of the potential impact on you. We will inform you and the OIAC within 30 days of discovery if we assess the data breach is likely to cause you serious harm.
06
07
If you wish to make a complaint about our handling of your personal information you should contact the Compliance & Risk Services Privacy Officer as referred to above. If we cannot resolve your complaint then you may raise your issue with the OIAC.
All privacy breaches that have resulted in or are likely to result in serious harm to any individual affected are ‘eligible data breaches‘ which must be reported by Compliance & Risk Services to the Office of the Australian Information Commissioner.
08
Compliance & Risk Services will only disclose personal information collected and held by us to a government authority if required to or compelled by law.
09
Compliance & Risk Services will not collect sensitive personal information on clients. Sensitive personal information is information about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information, genetic information, biometric information or biometric templates.
10
Compliance & Risk Services is required to notify individuals and the Office of the Australian Information Commissioner about eligible data breaches. An eligible data breach occurs when the following criteria are met:
We will conduct an assessment if it is not clear if a suspected data breach meets these criteria. The assessment will determine whether the breach is an eligible data breach that triggers notification obligations.
If your personal information is compromised by an eligible data breach we will inform you about that matter as soon as practicably possible.
11
We will not hold your personal information any longer than is required by law.
12
Further information on privacy in Australia may be obtained by visiting the website of the Office of the Australian Information Commissioner (OAIC) at: http://www.oaic.gov.au/. We regularly review the OAIC website to keep informed of issues and developments in privacy law and changing legal obligations.
13
We will provide training to our employees and relevant contractors on this policy at least annually.
14
We will review this policy at least annually or more frequently if required by law reform.
— End of Policy —