Document: APS-GC-POL-001 – Privacy Policy
Version: 1.0
Date: 04/09/2026
Purpose
To establish Australasian Protective Services’ (APS) commitment to protecting personal information and managing it in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and other applicable privacy requirements.
This Policy explains how APS collects, holds, uses, discloses and protects personal information and how individuals may access or correct their information or raise a privacy concern or complaint.
Scope
This Policy applies to personal information collected, held, used or disclosed by APS in connection with its business operations and service delivery.
It applies to all APS employees, consultants and subcontractors who access or handle personal information on behalf of APS.
Personal information may relate to:
- employees and job applicants;
- clients and prospective clients;
- client personnel;
- consultants, subcontractors and suppliers;
- visitors, members of the public and other individuals whose information APS collects or handles through its operations and security services.
Certain employee records may be exempt from the Australian Privacy Principles where the employee records exemption under the Privacy Act applies. APS nevertheless applies appropriate privacy and confidentiality controls to employee information.
Policy Statement
APS is committed to respecting individual privacy and managing personal information responsibly, transparently and securely.
Personal information will only be collected, held, used and disclosed where reasonably necessary for APS's functions and activities, or where otherwise permitted or required by law.
APS will maintain appropriate practices, systems and controls to protect personal information throughout its lifecycle and support compliance with applicable privacy requirements.
Privacy Principles
APS will:
- collect personal information lawfully, fairly and only where reasonably necessary for its functions and activities;
- be transparent about the collection and handling of personal information;
- use and disclose personal information only for authorised purposes or as otherwise permitted or required by law;
- apply appropriate protections to sensitive information;
- take reasonable steps to maintain the accuracy, completeness and currency of personal information;
- protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure;
- respect an individual's rights to access and seek correction of their personal information;
- appropriately manage privacy concerns, complaints and suspected privacy breaches; and
- regularly review its privacy practices and controls to support ongoing compliance and improvement.
Collection of Personal Information
APS collects personal information reasonably necessary to conduct its business, manage its workforce and deliver security and related services.
Depending on the nature of an individual's interaction with APS, personal information collected or held may include:
- names, addresses and contact details;
- client, contractor and supplier contact information;
- employment, recruitment, qualification and employment history information;
- security licences, training and competency information;
- identification and site-access information;
- information relating to enquiries, complaints and service delivery;
- images, video and audio recordings and associated information obtained through CCTV, body-worn cameras and other security or monitoring systems;
- access control, alarm, duress and other security-system information associated with identifiable individuals;
- information relating to incidents, investigations and workplace activities;
- website, online enquiry and digital-platform information, including technical information collected through cookies or similar technologies where applicable; and
- other personal information reasonably necessary for APS's functions and activities.
APS may collect personal information directly from an individual or, where appropriate, from clients, contractors, recruitment providers, referees, publicly available sources, security and monitoring systems, APS websites and digital platforms, or other authorised third parties.
Where reasonable and practicable, APS will collect personal information directly from the individual concerned and take reasonable steps to make them aware of relevant collection and handling practices.
Individuals may interact with APS anonymously or using a pseudonym where this is lawful and practicable. Identification may be required where necessary to provide a service, meet security or site-access requirements, or comply with legal or contractual obligations.
Use and Disclosure of Personal Information
APS will generally use or disclose personal information for the purpose for which it was collected, for a related purpose reasonably expected by the individual, with consent where required, or where otherwise permitted or required by law.
Personal information may be used or disclosed for purposes including:
- providing and managing security and related services;
- managing client, contractor and supplier relationships;
- administering recruitment, employment and workforce activities;
- managing site access, security and monitoring activities;
- responding to security events, incidents and emergencies;
- investigating incidents, complaints or concerns;
- meeting contractual, insurance, licensing, legal and regulatory requirements; and
- protecting the safety and security of people, property and operations.
Information obtained through CCTV, body-worn cameras and other security or monitoring activities will only be accessed, used or disclosed for authorised purposes and in accordance with applicable privacy, surveillance, contractual and legal requirements.
APS may disclose personal information to clients, contractors, subcontractors, professional advisers, insurers, technology and service providers, government agencies, regulators, emergency services or other parties where reasonably necessary and authorised.
Where APS provides contractors, subcontractors or service providers with access to personal information, reasonable steps will be taken to ensure the information is handled in accordance with applicable privacy and confidentiality requirements.
APS does not sell personal information.
Where permitted by law, APS may use contact information to communicate about its services or other relevant business activities. Individuals may opt out of receiving direct marketing communications from APS.
Sensitive Information
APS will only collect sensitive information where reasonably necessary for its functions or activities and where the individual has consented, or where collection is otherwise permitted or required by law.
Sensitive information may include health information, criminal history and other information required for employment, licensing, safety or service-delivery purposes.
Access to sensitive information will be limited to persons who require the information for an authorised purpose, and the information will be handled with safeguards appropriate to its nature and sensitivity.
Security and Protection of Personal Information
APS will take reasonable steps to protect personal information from misuse, interference and loss and from unauthorised access, modification or disclosure.
Personal information may be held in electronic systems, physical records and systems operated by authorised service providers.
APS maintains administrative, physical and technical safeguards appropriate to the nature and sensitivity of the information held. Access to personal information is limited according to business requirements, role responsibilities and authorised purposes.
Personnel must only access, use or disclose personal information where required for their authorised duties.
Retention and Disposal
APS will retain personal information for as long as reasonably required for the purpose for which it was collected or to meet applicable legal, contractual, regulatory and business requirements.
Where personal information is no longer required to be retained, APS will take reasonable steps to securely destroy or de-identify the information in accordance with applicable records management and information security requirements.
Overseas Disclosure
APS may use technology and service providers in connection with the storage, processing and management of personal information.
APS is not generally likely to disclose personal information to recipients located outside Australia.
Where circumstances require personal information to be disclosed overseas, APS will manage the disclosure in accordance with the Privacy Act 1988 (Cth) and applicable Australian Privacy Principles.
Access and Correction
Individuals may request access to personal information APS holds about them or request correction where they believe the information is inaccurate, out of date, incomplete, irrelevant or misleading.
Requests for access or correction may be made using the contact details provided in this Policy. APS may take reasonable steps to verify the identity of the person making the request before providing access or making a correction.
APS will respond within a reasonable period and in accordance with the Privacy Act and Australian Privacy Principles.
Where APS is permitted to refuse access or correction, the individual will be advised of the decision and the reasons for it where required by law.
Privacy Breaches
Suspected or actual loss, unauthorised access, disclosure, misuse or other unauthorised handling of personal information shall be promptly reported through the applicable APS reporting and escalation process.
APS will assess suspected privacy breaches and take appropriate action to contain the breach, minimise potential harm and address identified risks.
Where a breach meets the requirements of an eligible data breach under the Notifiable Data Breaches scheme, APS will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Privacy Act.
Privacy Concerns and Complaints
Individuals who have concerns about APS's handling of their personal information or believe APS may have breached applicable privacy requirements may lodge a complaint using the contact details provided in this Policy.
APS will acknowledge and review privacy complaints, obtain relevant information where required and provide an appropriate response within a reasonable period.
Privacy complaints will be handled fairly and with appropriate regard for confidentiality.
Where an individual is not satisfied with APS's response, they may be entitled to refer their complaint to the Office of the Australian Information Commissioner or another applicable regulatory body.
Responsibilities
Personnel
- handling personal information in accordance with this Policy and applicable APS requirements;
- accessing personal information only where required for authorised duties;
- protecting personal information from inappropriate access, use or disclosure;
- maintaining the confidentiality of personal information obtained through their work; and
- promptly reporting suspected privacy breaches or concerns.
For the purposes of these responsibilities, personnel includes employees, contractors and subcontractors handling personal information on behalf of APS.
Managers and Supervisors
- implementing applicable privacy requirements within their areas of responsibility;
- limiting access to personal information to personnel with a legitimate business requirement;
- ensuring contractors and subcontractors under their management are provided access to personal information only where required for authorised activities and subject to applicable privacy and confidentiality requirements; and
- escalating privacy breaches, complaints and other privacy matters where required.
Privacy Officer
- overseeing APS's privacy management practices and implementation of this Policy;
- coordinating privacy enquiries, access and correction requests and complaints;
- overseeing the assessment and management of suspected privacy breaches;
- providing guidance on applicable privacy requirements; and
- monitoring changes to privacy requirements and recommending improvements where required.
Senior Management
Senior Management is responsible for providing appropriate governance and resources to support APS's privacy obligations and the effective implementation of this Policy.
Breaches of this Policy may be addressed through applicable APS performance, disciplinary or contractual processes, having regard to the nature and circumstances of the breach.
Monitoring
APS will monitor the effectiveness of this Policy and its privacy management practices through relevant reviews, audits, privacy incidents and complaints, identified risks and changes to legal, regulatory or operational requirements.
Outcomes will inform corrective action and continual improvement where required.
Availability and Contact Details
APS will make this Privacy Policy publicly available free of charge, including through the APS website. A copy will also be provided in an appropriate form upon reasonable request.
Questions about this Policy, or requests relating to access, correction, privacy concerns or complaints, may be directed to:
Attention: Privacy Officer – Australasian Protective Services
Email: [email protected]
Telephone: 0487 277 277
Postal Address: PO Box 296, Melton VIC 3337
Definitions
Personal Information – Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information or opinion is true or recorded in a material form.
Sensitive Information – Personal information afforded a higher level of protection under the Privacy Act, including information or an opinion about an individual's racial or ethnic origin, political opinions or associations, religious or philosophical beliefs, professional or trade association or union membership, sexual orientation or practices, criminal record, health information and certain genetic or biometric information.
Privacy Breach – Loss, unauthorised access, disclosure, misuse or other unauthorised handling of personal information held by APS.
Legislation and Standards
- Privacy Act 1988 (Cth);
- Australian Privacy Principles – Schedule 1 to the Privacy Act 1988 (Cth);
- Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth);
- applicable State and Territory privacy, health records, surveillance and workplace surveillance legislation; and
- applicable contractual privacy and confidentiality requirements.
Related Documents
- Information Security Policy
- Data Protection Policy
- Records Management Policy
- Records Management Procedure
- applicable Data Breach / Cyber Incident Response Procedure
- applicable CCTV and Body-Worn Camera Procedures
- Code of Conduct
Version History
| Version | Date | Description of Changes | Approved By |
|---|---|---|---|
| 1.0 | 04/09/2026 | Initial Release | Managing Director |
