Atlantis Recruitment Brisbane Pty Ltd (“we”, “us”, “our”) processes personal information as part of providing recruitment and related services. This Data Processing Policy sets out how we process personal data responsibly and securely, the principles and controls we apply, and the rights available to individuals.
We process personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Policy supports, and should be read together with, our Privacy Policy.
1. Purpose and Scope
This Policy applies to all personal information we process about candidates, clients, referees, suppliers, our personnel and website users, in any format (electronic or physical), throughout its lifecycle.
“Processing” means any operation performed on personal data, including collecting, recording, organising, storing, accessing, using, disclosing, transferring, retaining, archiving, de-identifying and destroying it. This Policy applies to all our staff, contractors and service providers who process personal data on our behalf.
2. Definitions
- Personal information (personal data) — information or an opinion about an identified individual, or an individual who is reasonably identifiable.
- Sensitive information — a subset of personal information, including health, criminal record, racial or ethnic origin, and similar information, which attracts a higher level of protection.
- Processing — any operation performed on personal data, from collection through to destruction.
- Candidate — an individual seeking work or registered with us.
- Client — an organisation or person that engages our recruitment services.
- Service provider — a third party that processes personal data on our behalf and on our instructions.
- Data breach — unauthorised access to, unauthorised disclosure of, or loss of, personal information that we hold.
3. Our Data Processing Principles
We are committed to processing personal data in line with the following principles:
- Lawfulness, fairness and transparency — we process personal data lawfully and fairly, and are open about how we handle it.
- Purpose limitation — we collect personal data for specified purposes and do not use it in ways that are incompatible with those purposes.
- Data minimisation — we collect and process only the personal data we reasonably need.
- Accuracy — we take reasonable steps to keep personal data accurate, complete and up to date.
- Storage limitation — we keep personal data only for as long as it is needed.
- Integrity and confidentiality — we protect personal data with appropriate security measures.
- Accountability — we take responsibility for the personal data we process and can demonstrate our compliance.
4. Grounds for Processing
We process personal data where one or more of the following applies:
- It is reasonably necessary to provide recruitment and related services
- The individual has given consent, including consent to collect sensitive information
- We are required or authorised to do so by law
- It is necessary for another purpose the individual would reasonably expect
Where we rely on consent, the individual may withdraw that consent at any time by contacting us, although this may affect our ability to provide services.
5. Categories of Personal Data We Process
- Identification and contact details
- Employment and education history, qualifications, skills and licences
- Resume/CV, interview notes and the results of skills assessments
- Right-to-work, visa, residency and citizenship status
- Referee details and the results of reference and background checks (where applicable, with consent)
- Tax file number, superannuation, payroll and bank account details, for candidates we place
- Client and supplier business contact and billing information
- Website usage and technical data collected through cookies and analytics tools
- Sensitive information, only where reasonably necessary and with consent
6. Purposes of Processing
We process personal data to:
- Assess candidate suitability and present candidates to potential employers
- Verify identity, qualifications and right to work, and conduct relevant checks
- Manage client relationships and deliver recruitment and related services
- Manage payroll, contractor and employment arrangements
- Operate, maintain and improve our systems, website and business
- Communicate with candidates, clients and other contacts
- Meet our legal, regulatory and contractual obligations
7. Data Collection and Minimisation
We collect personal data by fair and lawful means and, where it is reasonable and practicable, directly from the individual concerned. We collect only the personal data we reasonably need for the relevant purpose and take care to avoid collecting excessive or irrelevant information. If we receive personal data we did not request and could not lawfully have collected, we will, where lawful and reasonable, destroy or de-identify it.
8. Data Quality
We take reasonable steps to ensure that the personal data we collect, use and disclose is accurate, complete, up to date and relevant. We encourage candidates, clients and other individuals to keep us informed of any changes to their personal information so our records remain current.
9. Data Storage and Security
We implement appropriate technical and organisational measures to protect personal data from misuse, interference and loss, and from unauthorised access, modification or disclosure. These measures include:
- Secure, access-controlled IT systems and databases
- Encryption of data in transit and, where appropriate, at rest
- Strong authentication and role-based access controls
- Firewalls, anti-malware protection and regular software updates
- Secure backups and business continuity arrangements
- Physical security measures for devices and any paper records
- Secure destruction or de-identification of data that is no longer required
10. Access Controls and Confidentiality
Access to personal data is limited to personnel who need it to perform their role. Our staff and contractors are subject to confidentiality obligations and are provided with guidance on their data protection responsibilities. We monitor and review access arrangements to help ensure they remain appropriate.
11. Data Sharing, Third Parties and Service Providers
We may share personal data with:
- Clients and prospective employers, for the purpose of presenting candidates for roles, with consent
- Service providers and contractors, such as IT and cloud-hosting providers, background-checking providers, payroll providers and professional advisers
- Government agencies, regulators and law enforcement, where required or authorised by law
Where we engage service providers to process personal data on our behalf, we take reasonable steps to ensure they are bound by appropriate confidentiality and data-protection obligations and process personal data only on our instructions and consistently with this Policy. We do not sell personal data.
12. Overseas Data Processing
Some of our service providers — for example, cloud-hosting and software providers — may store or process personal data on servers located outside Australia. Where we transfer personal data to an overseas recipient, we take reasonable steps to ensure the recipient handles it in accordance with the Australian Privacy Principles. We store and process personal data in Australia and New Zealand, with New Zealand being the only country outside Australia in which such recipients are likely to be located.
13. Data Retention and Disposal
We retain personal data only for as long as it is reasonably necessary for the purposes for which it was collected, or for as long as we are required to retain it by law. We periodically review the personal data we hold and securely destroy or de-identify data that is no longer required. Candidates may request removal of their information from our database at any time by contacting us.
14. Individual Rights
Individuals may, subject to any applicable legal limitations:
- Request access to the personal data we hold about them
- Request correction of personal data that is inaccurate, out of date, incomplete, irrelevant or misleading
- Withdraw consent, where our processing is based on consent
- Make a privacy complaint
Requests can be made using the contact details below, and we will respond within a reasonable period. If a complaint cannot be resolved with us, it may be escalated to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by phoning 1300 363 992.
15. Data Breach Management
We maintain procedures to identify, contain, assess and respond to actual or suspected data breaches. Our staff and contractors must report any actual or suspected data breach to management immediately so that it can be assessed and managed without delay.
If a data breach is likely to result in serious harm to any affected individual, we will notify the affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
16. Roles and Responsibilities
Everyone who processes personal data on our behalf is responsible for complying with this Policy. Responsibility for overseeing data protection and for handling privacy enquiries and complaints rests with our management. We provide our staff and contractors with appropriate guidance and training to support compliance with this Policy and our legal obligations.
17. Review and Compliance
We review this Policy from time to time and update it to reflect changes in our practices, technology or legal obligations. The current version is published on our website and shows the date it was last updated. Failure by our staff or contractors to comply with this Policy may result in disciplinary or contractual action.
18. Contact Details
If you have any questions about this Policy or about how we process personal data, please contact us: