- LEGAL
Data Subject Rights Policy
1. Purpose
This Data Subject Rights Policy establishes the requirements and procedures used by Alphalitica Pty Ltd, trading as Five Faces (“Five Faces”), to receive, assess, authenticate, manage and respond to requests from individuals concerning their personal information.
Five Faces is committed to respecting the privacy rights of individuals and handling personal information in a lawful, transparent, secure and accountable manner. This Policy supports Five Faces’ compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) and its privacy information management framework aligned with ISO/IEC 27701 and ISO/IEC 27001.
Where Five Faces handles personal information that is subject to another applicable privacy or data protection regime, contractual obligation or customer requirement that provides additional individual rights, Five Faces will assess and facilitate those rights as required.
2. Scope
This Policy applies to personal information held or processed by Five Faces in connection with its operations, products, services, websites and business activities.
It applies to all Five Faces employees, contractors, consultants and other personnel involved in collecting, accessing, using, disclosing, storing, correcting, deleting or otherwise processing personal information.
This Policy applies both where Five Faces determines the purposes for which personal information is handled and where Five Faces processes personal information on behalf of a customer. Where Five Faces processes personal information on behalf of a customer, requests may need to be referred to or managed in conjunction with that customer in accordance with contractual arrangements and applicable law.
3. Policy Statement
Five Faces will provide individuals with reasonable and accessible mechanisms for exercising rights relating to their personal information.
Requests will be handled fairly, securely and without unreasonable delay. Five Faces will take reasonable steps to verify the identity and authority of a person making a request before disclosing, correcting, deleting or otherwise acting upon personal information.
Five Faces will not refuse a valid request except where permitted or required by applicable law or where the requested right does not apply in the circumstances.
Under Australian privacy law, APP 12 generally requires an organisation holding an individual’s personal information to provide access on request, subject to specified exceptions. APP 13 requires reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
4. Rights Managed Under This Policy
Five Faces will maintain processes for handling the following categories of requests:
- Access – a request to obtain access to personal information Five Faces holds about an individual.
- Correction or rectification – a request to correct personal information that is inaccurate, out of date, incomplete, irrelevant or misleading.
- Deletion, destruction or de-identification – a request concerning deletion or destruction of personal information. Five Faces will assess the request against applicable legal requirements, retention obligations and the purposes for which the information continues to be required.
- Restriction of processing – where a restriction right applies under applicable law, contract or customer requirements, Five Faces will assess and implement appropriate restrictions.
- Objection to processing – where an individual has an applicable right to object to particular processing, Five Faces will assess the objection and cease, modify or continue the processing as permitted by the applicable requirements.
- Data portability – where a portability right applies, Five Faces will provide or facilitate provision of relevant personal information in the form required by the applicable regime, where technically feasible and legally required.
- Withdrawal of consent – where processing relies upon consent, an individual may withdraw that consent, subject to applicable legal and contractual requirements and the consequences of withdrawal.
- Direct marketing preferences – individuals may request that Five Faces cease sending direct marketing communications in accordance with applicable law.
- Automated processing or decision-making – where applicable law provides rights relating to automated decisions or profiling, Five Faces will facilitate those rights and appropriate human review.
These rights are not absolute. The availability and extent of a particular right will depend on the applicable law, the nature of the information, the purpose for which it is held and Five Faces’ legal and contractual obligations.
5. Access to Personal Information
An individual may request access to personal information Five Faces holds about them.
Five Faces will take reasonable steps to provide access in the manner requested where it isreasonable and practicable to do so. Access may, for example, be provided electronically, inwriting or through another appropriate method.
Five Faces may refuse access where permitted by law, including circumstances whereproviding access would have an unreasonable impact on another person’s privacy oranother applicable exception applies.
Where access is refused, Five Faces will provide written notice setting out the reasons forrefusal, except where it would be unreasonable to provide those reasons, and informationabout available complaint mechanisms as required by law.
6. Correction and Rectification
Individuals may request correction of personal information held by Five Faces.
Where Five Faces is satisfied that personal information is inaccurate, out of date, incomplete, irrelevant or misleading having regard to the purpose for which it is held, Five Faces will take reasonable steps to correct the information.
Where corrected information was previously disclosed to another APP entity and theindividual requests notification of the correction, Five Faces will take reasonable steps tonotify that entity unless doing so would be impracticable or unlawful.
If Five Faces refuses a correction request, it will provide the individual with the required written notice and, where required and requested, take reasonable steps to associate a statement with the relevant information recording that the individual considers the information incorrect.
Five Faces will not charge an individual for making a correction request or for correcting personal information under APP 13.
7. Deletion, Destruction and De-identification
Five Faces will not retain personal information indefinitely.
Where personal information is no longer required for a purpose for which it may lawfully be used or disclosed, Five Faces will take reasonable steps to destroy or de-identify it unless the information must be retained under Australian law, a court or tribunal order, or another applicable obligation.
Where an individual requests deletion or erasure, Five Faces will assess whether the information can lawfully and appropriately be deleted, destroyed or de-identified.
A deletion request may not result in deletion where information must continue to be retained for reasons such as legal or regulatory obligations, contractual requirements, establishment or defence of legal claims, security and fraud prevention, audit requirements or other lawful purposes.
8. Restriction and Objection
Where an applicable privacy regime provides an individual with a right to restrict or object to processing, Five Faces will assess the request against the relevant legal requirements.
Where a valid restriction applies, Five Faces will take reasonable steps to ensure the affected personal information is not processed beyond the permitted purposes while the restriction remains in force.
Where a valid objection applies, Five Faces will cease or modify the relevant processing unless applicable law permits or requires processing to continue.
9. Data Portability
Where an applicable law, contract or customer obligation provides an individual with a right to data portability, Five Faces will take reasonable steps to provide the relevant personal information in the required structured or machine-readable form or facilitate its transfer as required.
This section does not create a general data portability right under the Australian Privacy Principles where one does not otherwise apply.
10. Submission of Requests
Individuals may make a request verbally or in writing. Five Faces may provide a preferred request form or process to assist efficient handling, but will not reject an otherwise valid Australian access or correction request merely because the individual did not use that process. OAIC guidance specifically recognises that organisations may recommend a procedure but should not make it an unnecessary barrier to exercising APP access or correction rights.
Requests may be directed to:
Privacy Officer
Alphalitica Pty Ltd ta Five Faces
Email: support@fivefaces.com.au
Postal address: Ground Level, 154 Melbourne St, South Brisbane, QLD, 4101
Phone: 1300 550 267
11. Identity and Authority Verification
Before providing access to personal information or making material changes to it, Five Faces must take reasonable steps to verify that the requester is the individual concerned or is properly authorised to act on that individual’s behalf.
Verification measures must be proportionate to the sensitivity of the information and the risks associated with unauthorised disclosure or alteration.
Five Faces must avoid collecting excessive additional personal information solely for verification purposes. Verification information must itself be handled securely.
12. Request Management Procedure
Upon receiving a data subject request, Five Faces will:
- record the request and date received;
- acknowledge receipt where appropriate;
- determine the identity and authority of the requester;
- identify the nature and scope of the request;
- determine which legal, contractual or regulatory requirements apply;
- identify relevant systems, records, suppliers or customers that may hold the information;
- retrieve and review relevant information;
- consider applicable exemptions, retention requirements and third-party privacy interests;
- obtain appropriate internal review where required;
- implement the approved action;
- communicate the outcome to the requester; and
- retain sufficient records to demonstrate how the request was handled.
Requests involving significant legal, privacy, security or contractual issues must be escalated to the Privacy Officer and, where appropriate, the CTO, CEO or external legal adviser.
13. Response Timeframes
Five Faces will respond to requests without unreasonable delay and within any timeframe required by applicable law.
For Australian APP access requests made to an organisation, Five Faces will respond within a reasonable period. Correction requests will likewise be handled within the applicable APPrequirements.
Where another applicable privacy regime establishes a specific response period, Five Faces will apply that period.
If additional information is reasonably required to identify the individual, understand the request or locate the relevant information, Five Faces may contact the requester for clarification.
14. Requests Relating to Customer-Controlled Information
Five Faces provides technology services to business customers and may process personal information under the instructions of those customers.
Where Five Faces receives a request relating to information for which a customer controls the relevant processing purpose, Five Faces will determine whether the request should be referred to that customer or whether Five Faces should assist the customer in responding.
Five Faces will provide reasonable assistance in accordance with applicable contractual arrangements, privacy obligations and documented customer instructions.
Five Faces must not independently alter, disclose or delete customer-controlled personal information where doing so would be inconsistent with lawful customer instructions or applicable contractual obligations.
15. Third Parties and Service Providers
Where relevant personal information is held or processed by an authorised supplier or service provider on behalf of Five Faces, Five Faces will take reasonable steps to ensure the request is communicated to the relevant provider where necessary.
Supplier and service arrangements involving personal information should support Five Faces’ ability to meet applicable data subject rights and privacy obligations.
16. Security and Confidentiality
Data subject requests and associated records must be treated as privacy-sensitive information.
Information must only be disclosed to the verified individual or their authorised representative and must be transmitted using methods appropriate to the sensitivity of the information.
Access to request records must be limited to personnel who require access for legitimate business, privacy, legal, security or compliance purposes.
17. Refusal and Exceptions
Five Faces may refuse or limit a request where permitted or required by applicable law.
Where Five Faces refuses an access or correction request, it will provide reasons and information about available complaint mechanisms where required by the Privacy Act and APPs.
Any refusal involving uncertainty about Five Faces’ legal obligations should be escalated tothe Privacy Officer and, where appropriate, legal advice should be obtained.
18. Complaints and Escalation
An individual who is dissatisfied with the handling of a request may raise a privacy complaint with the Privacy Officer using the contact details in section 10.
Five Faces will investigate and respond to privacy complaints in accordance with its Privacy Policy and applicable privacy requirements.
Where applicable, an individual may also have the right to make a complaint to the Office of the Australian Information Commissioner or another competent privacy or data protection authority.
19. Records and Accountability
Five Faces will maintain appropriate records of data subject requests to demonstrate compliance and support audit and continual improvement.
Records may include the request, verification performed, relevant correspondence, decisions, approvals, information provided, reasons for refusal or limitation, actions taken, completion date and any complaint or escalation.
Request records must be retained in accordance with the Five Faces Record Retention Policy and protected in accordance with the Information Security Policy and Data Classification Policy.
20. Roles and Responsibilities
The CEO is the final approver of this Policy.
The Privacy Officer is the document owner and is responsible for overseeing data subject rights requests, maintaining this Policy, coordinating responses, monitoring compliance and escalating material privacy issues.
The CTO is responsible for ensuring that appropriate technical and security capabilities are available to identify, retrieve, correct, restrict, export, delete or de-identify personal information where required and technically applicable.
Managers, system owners and relevant personnel must cooperate with requests and provide relevant information within required timeframes.
All workers must promptly forward any data subject request they receive to the Privacy Officer and must not independently disclose, alter or delete information in response to are quest unless authorised to do so.
21. Training and Awareness
Personnel whose roles involve handling personal information or data subject requests must receive appropriate privacy awareness and training.
Relevant personnel must understand how to recognise a request even where the requester does not use terminology such as “data subject request”, “APP 12”, “access request” or “right to erasure”.
22. Related Documents
This Policy should be read together with the Five Faces Privacy Policy, Privacy and Consent documentation, Information Security Policy, Data Classification Policy, Record Retention Policy, Incident Management Policy and Procedure, Acceptable Use Policy, and Policy Creation and Document Control Procedure.
23. Compliance and Breaches
Failure to comply with this Policy may expose Five Faces and affected individuals to privacy, security, contractual and regulatory risks.
Suspected breaches must be reported promptly and managed in accordance with Five Faces incident management and privacy breach processes. Non-compliance by workers may result in corrective or disciplinary action, subject to applicable employment or contractual arrangements.
24. Review and Approval
This Policy must be reviewed at least annually and sooner where there is a material change to applicable privacy law, Five Faces’ processing activities, customer requirements, information systems, ISO certification requirements or findings from an audit, incident or privacy review.
Material amendments must be reviewed by the Privacy Officer and approved by the CEO before issue.