This is the Privacy Commission’s advice:
Information Privacy Principles
These principles can be summarised as:
1. Only collect personal information if you really need it
2. Get it straight from the people concerned where possible
3. Tell them what you’re going to do with it
4. Collect it legally and fairly
5.Take care of it once you’ve got it
6. People can see their personal information if they want to
7. They can correct it if it’s wrong
8. Make sure personal information is correct before you use it
9. Get rid of it when you’re done with it
10. Use it for the purpose you got it
11. Only disclose it if you have a good reason
12. Only assign unique identifiers where permitted.
Together, these principles form a ‘life-cycle’ for personal information.
Also, Section 23 of the Privacy Act states that all agencies must have at least one privacy officer. They provide free training for a privacy officer. Looks like another volunteer.
Cheers,
Kelly