Privacy and Information Management Policy
v2.0
Purpose. This policy sets out how the shire collects, uses, stores and discloses personal information and how it manages public records under the Privacy and Data Protection Act 2014 and the Public Records Act 1973.
1.Purpose
The shire holds personal information about ratepayers, residents, applicants, animal owners, staff and councillors. This policy ensures that information is handled lawfully and that residents can trust the shire with their details.
2.Collection
Staff must collect only the personal information needed for a lawful council function and must tell the person why it is being collected and who it will be shared with. Forms must carry a collection notice.
3.Use and disclosure
Personal information must only be used for the purpose it was collected for or a directly related purpose the person would reasonably expect. Information must not be disclosed to third parties, including councillors, except where the law requires or permits it. Property ownership details must not be released over the counter.
4.Storage and security
Personal information must be stored in the approved council systems and not in personal drives, notebooks or email folders. Access must be limited to staff who need it for their role. Paper records must be locked away when unattended and disposed of by secure destruction.
5.Records management
Every business decision must be captured as a record in the electronic document and records management system. Records must be retained and disposed of in accordance with the retention and disposal authority for local government records.
6.Access and correction
A person can ask to see the personal information the shire holds about them and to have it corrected. Requests must be referred to the privacy officer and answered within 30 days.
7.Breaches
A suspected privacy breach must be reported to the privacy officer on the day it is discovered. The privacy officer will contain the breach, assess the harm, notify affected people where required and record the breach in the breach register.