👉 👉 EOFY Gym Membership Offer 👈👈
💪 $0 join fee + the rest of the month FREE❗️*
While exercise is important, so is staying connected. Come for a swim or workout. Stay for a chat. That’s how we do things at the YMCA.
Hurry offer valid until 30th June 17. Offer EXTENDED until 16th July 17.
*Terms and Conditions Apply
Terms and Conditions – YMCA Managed facility $0 Joining Fee and the rest of the month free
YMCA NSW is committed to the responsible collection, handling, storage, disclosure and destruction of personal information, as specified in the Privacy Act 1988. We respect the privacy of our clients, participants, parents, staff and other visitors to our facilities and ensure that:
This document clearly outlines what is required to fulfil our commitment to privacy and confidentiality. YMCA NSW will ensure full compliance to the Australian Privacy Principles (APP), as detailed in the Privacy Act 1988 (Privacy Fact Sheet 17: Australian Privacy Principles).
This privacy & Confidentiality Policy applies to YMCA NSW and entities controlled by YMCA NSW, including the YMCA of Sydney Youth and Community Services and the Young Men's Christian Association of Sydney.
This policy may be accessed by any person who has dealings with the YMCA NSW, including clients, staff and the wider community.
1. Collection of Information
We collect personal information of our clients, including participants in our programs, parents and visitors to our facilities. When we receive personal information about you, we will handle it in accordance with the Privacy Act and the APPs. We only collect personal information if it is reasonably necessary for one or more of our functions or activities.
We will give you the option of remaining anonymous or using a pseudonym in your dealings with us, provided that it is lawful or practical to do so.
1.1 Collection of personal information
We collect the minimum personal information that is necessary to provide you with a service that you have requested, or to ensure that we comply with legislative requirements. If you do not wish to provide us with your personal information, we may not be able to provide you with a service that you have requested.
The personal information that we may collect and hold about our clients includes:
1.2 Collection of sensitive information
In performing our functions and activities we may collect sensitive information about our clients, including:
The APPs require that we only collect sensitive information from you where:
We also collect sensitive information when we are authorised to do so for the purposes of preventing or lessening a serious threat to life, health or safety; human resource management; taking appropriate action against suspected unlawful activity or serious misconduct; and responding to inquiries by courts, tribunals and other bodies.
1.3 Collection of personal information about children and young people
We collect personal information about children and young people under the age of 18 in order to deliver programs and services for children and youth. We collect personal information about children and young people only with the written consent of a parent or guardian or another authorised person.
1.4 How we collect and hold personal information
We collect personal information by fair and lawful means. We use forms, online portals, and other electronic and paper correspondence to collect personal information. We may also collect your personal information if you:
As far as practical, we collect personal information directly from you. We collect personal information from third parties only where it is unreasonable or impracticable to collect the information directly from you. In those circumstances, we may collect personal information from third parties including councils, health services, government agencies, authorised representatives and legal advisers. We may also collect personal information from publicly available sources of information.
We hold personal information in a range of paper-based and electronic records, including in cloud computing. Personal information is stored securely, and we conduct regular audits and reviews of our record keeping systems. We store personal information in Australia, except as specified at section 5.1 below.
We take all reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Only authorised staff have access to personal information for approved purposes.
If we hold personal information about you which we no longer need in order to fulfil the purpose for which it was collected, and we are not legally required to retain that information, we will take reasonable steps to destroy the information or to ensure that the information is de-identified.
1.5 Data Breaches
A data breach occurs when personal information, in any format, held by an agency or organisation is lost or subjected to unauthorised access, modification, disclosure or other misuse or interference. The primary cause of a data breach is not limited to malicious or criminal attack, such as theft or hacking, but may arise from internal errors or failure to follow information handling policies that cause accidental loss or disclosure.
The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Australia Privacy Act 1988 (Privacy Act) establishes requirements for entities in responding to data breaches. The NDB scheme applies to all agencies and organisations with existing personal information security obligations under the Privacy Act from 22 February 2018. This includes YMCA NSW.
The NDB scheme requires agencies and organisations to notify particular individuals and the OAIC about an ‘eligible data breach’. A data breach is eligible if it’s likely to result in serious harm (psychological, emotional, physical, reputational or other forms of harm) to any of the individuals to whom the information relates. The eligible data breach provision applies to the information outlined in the subsections 1.1 & 1.2 of this policy that YMCA NSW collects for both its customers and staff:
A breach may be exempt from being defined as eligible if the entity takes remedial action prior to serious harm occurring. Then the legislation provides that there never was a breach and as such, the breach cannot be eligible.
In the event of a data breach occurring whether by malicious interference or human error, YMCA NSW will control the process of responding to the breach in accordance with the Privacy Amendment (Notifiable Data Breaches) Act 2017.
1.6 Quality of personal information
We take all reasonable steps to ensure that the personal information we collect, use and disclose is accurate, complete, up-to-date and relevant. However, the accuracy of that information depends to a large extent on the information you provide to us.
We recommend that you:
We require clients in some of our programs to update their details on a regular basis, or whenever they experience a change in circumstances. We will advise you if these requirements apply to you.
By signing or submitting paper documents or agreeing to the terms and conditions for the use of our electronic documents you are consenting to the collection of any personal information you provide to us. By acquiring or using our services, products or facilities, you consent to the reasonable collection, use and disclosure of personal information.
2. Purposes for which we collect, hold, use and disclose personal information
To the extent practicable, we will take reasonable steps to notify you of the purpose for which we are collecting personal information at the time when we collect it.
We collect personal information for the following purposes:
3. Marketing and promotion of our services
Personal information that you provide to us may be placed on our internal database to enable us to advise you of the various products, services and events which we provide.
4. Our website
If you visit our website and read or download materials, we will receive the following types of information, which will not be used to identify you personally.
4.1 Computer information
To enable communication between your computer and the server hosting our website, it is necessary for your web browser to provide your computer's network address. This allows our web server to address its replies to the correct machine. The browser type and operating systems which you use may also be recorded. We will not use this type of information to personally identify you.
4.2 Navigation and click-stream data
When you browse our website you generate a 'foot-print' or trail of the pages you have visited, the amount of data transferred and the time and duration of access. This information is recorded against the network address supplied by your web browser. We will not use this type of information to personally identify you.
4.4 Information logs
The information we collect about the use of our website is recorded in logs for use in the management of our website. We use statistics drawn from these logs to help us to improve our website and to make it more interesting and relevant to browsers. The statistics also help us to determine market preferences for the services we offer. We may use statistics about the use of our website to promote our goods and services or to research market preferences and trends. No statistical information collected about the use of our website will be linked to your name, address or other identifier.
5. Disclosure of personal information
We hold, use and disclose personal information for the primary purpose for which it was collected (see section 1 above). We may disclose personal information to the following kinds of third party organisations and individuals:
We do not disclose personal information about anyone under the age of 18 unless we have the prior written consent of a parent, career or guardian, or we are legally permitted or required to do so.
We will only use or disclose your personal information for secondary purposes where we are permitted to do so in accordance with the Privacy Act. This may include where:
5.1 Overseas disclosures of personal information
We may store your personal information in facilities supplied by our contractors that may be located outside of Australia, including our data hosting and cloud-based IT service providers in Germany and the United States of America, for some of the purposes listed at section 1 above. Those contractors do not disclose, share or on-sell your personal information and we take reasonable steps to ensure that our overseas contractors do not breach privacy obligations relating to your personal information.
6. Accessing and correcting your personal information
You have a right under the Privacy Act to access personal information we hold about you. You may also request corrections of any personal information that we hold about you if you think the information is inaccurate, out-of-date, incomplete, irrelevant or misleading.
If you request access to or correction of your personal information, we will respond to you within a reasonable period of time (usually 30 days).
The APPs do set out circumstances in which we may refuse to give you access or decline to correct your personal information. If we refuse to give you access or make corrections to your personal information, we will provide you with a written notice which sets out our reasons for refusing your request.
We are committed to prompt and fair resolution of complaints and we will ensure that your complaint is taken seriously and investigated. We will keep you informed throughout the investigation of your complaint and will provide you with a written response. We will usually provide you with a response within 30 days of receipt of your written complaint.
If you are not satisfied with the way we have handled your complaint, you may contact the Office of the Australian Information Commissioner to refer your complaint for further investigation. The Information Commissioner may not investigate if you have not first brought your complaint to our attention.
Office of the Australian Information Commissioner:
Telephone: 1300 363 992
Post: GPO Box 5218, Sydney NSW 2001
8. Contact us
If you would like to:
Please contact our Privacy Officer using the details below:
Telephone: 02 9687 9425
Post: Chief Risk Officer, YMCA NSW, P.O Box 1433, Parramatta NSW 2150
Roles and responsibilities
|YMCA NSW Board||
|Executive Leadership Team||
|Managers and Supervisors||
|Staff Members and Volunteers||
Failing to adhere to the Privacy & Confidentiality Policy is viewed as serious misconduct and may lead to disciplinary action, up to and including formal warning, demotion or termination of employment or cessation of volunteer involvement.
Other related documentation
|Confidential Information including||
|Policy owner||Lisa Giacomelli, Chief Risk Officer|
|Policy sponsor||Leisa Hart, Chief Executive Officer|
|Chief Executive Officer||Leisa Hart, Chief Executive Officer|
|Date due for review||Two years from date of approval|