Securus Consulting Group Pty Ltd
Privacy Policy
Effective Date: 21 April 2025

1. Purpose and Requirements

This Privacy Policy sets out how Securus Consulting Group Pty Ltd (“Securus”) manages personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs). This document forms part of the Securus Quality Management System (QMS), aligned to ISO 9001 and ISO/IEC 27001.

2. Scope

This Policy applies to all personal information collected, held, and processed by Securus in relation to clients, employees, contractors, suppliers, and other stakeholders.

3. Roles and Responsibilities

The following roles have specific responsibilities under this Policy:

  • Executive Management Team (EMT): Endorse and oversee implementation of the policy/procedure and appropriate governance; allocate resources; and ensure compliance, including review of reports from the Assurance manager.
  • Chief Executive Officer (CEO): Approve the policy/procedure; ensure obligations are integrated into strategic and operational planning; provide overall leadership and accountability.
  • Assurance Manager: Monitor compliance; conduct periodic audits and privacy risk assessments; investigate and coordinate responses to privacy complaints and incidents.
  • Records Management Officer: Maintain records retention schedules, oversee secure storage, archiving, de-identification and disposal / destruction of personal information in accordance with legal and regulatory requirements.
  • Service Line Managers: Implement policy/procedure within their business areas; ensure personal information is collected, used, and disclosed only as necessary for service delivery; promote staff awareness and report any suspected privacy breaches to the Assurance Manager.
  • System Administrators: Manage access restrictions, authentication, and identity management for information systems; apply encryption, security monitoring, and incident response procedures; ensure secure backup, storage, and deletion of personal information in digital systems.
  • All Staff: Handle personal information in accordance with the Privacy Policy and training provided; report privacy concerns, suspected data breaches, or unauthorised disclosures immediately; maintain confidentiality and use personal information only for authorised purposes.

4. Collection of Personal Information

This includes information collected directly (via forms, phone, email) and indirectly (via website logs, analytics, referrals, and public sources). Sensitive information is only collected with consent or as authorised by law.

Securus collects personal information only where reasonably necessary for its functions and activities, including (but not limited to):

  • Client contact details, job titles, login credentials, billing and account information.
  • Employee and contractor records including identifiers, payroll data, superannuation, and pre-employment screening outcomes.
  • Website and systems usage data such as IP addresses, metadata, and device identifiers.

Sensitive information is collected only where authorised by law or with explicit consent.

5. Use of Personal Information

Securus uses personal information for the following purposes:

  • Delivering ICT consulting and cyber security services;
  • Account management, billing, and payments;
  • Security monitoring, threat detection, and incident response;
  • Recruitment and workforce management;
  • Compliance with contractual, statutory, and regulatory obligations.

 

6. Disclosure

Securus may disclose personal information to:

  • Service providers, contractors, and partners engaged in service delivery;
  • Professional advisors (legal, financial, insurance);
  • Government agencies, regulators, or law enforcement as required by law.

Overseas disclosure may occur, including to service providers in the United States and European Union. Securus takes reasonable steps to ensure such recipients comply with the APPs.

7. Data Security

Securus employs reasonable physical, technical, and administrative safeguards, including:

  • Access restrictions and identity management;
  • Encryption of sensitive data at rest and in transit;
  • Intrusion detection and security monitoring;
  • Secure disposal and data destruction processes.

 

8. Data Retention

Personal information is retained only for as long as required to fulfil legal, regulatory, or business purposes. Information no longer required will be securely destroyed or de-identified.

9. Access and Correction

Individuals may request access to, or correction of, personal information by contacting the Privacy Officer. Requests can be made in writing, by email, or phone. Securus will respond within 30 days in accordance with APP 12 and 13. Identification may be required.

10. Complaints

Complaints regarding a potential breach of the APPs should be submitted in writing to the Privacy Officer. Securus will investigate and respond within 30 days. Complaints must first be made to Securus. If unresolved, individuals may escalate the complaint to the Office of the Australian Information Commissioner (OAIC) via www.oaic.gov.au. The policy is available free of charge in print, electronic, or accessible format upon request.

11. Contact

Privacy Officer
Securus Consulting Group Pty Ltd
Email: legal@securus-cg.com
Phone: 02 6189 4920
Address: Unit 4, 2 Brindabella Cct, Brindabella Business Park, ACT 2609

12. Documented Information
All Securus Documented Information is named and saved as appropriate and in line with Securus Records Management and Documented Information procedures.

13. Amendments

This policy is reviewed as part of the Securus internal audit program and in response to any legislative change, significant incident, or organisational change. Amendments require EMT/CEO endorsement and approval, with changes circulated within 30 days of reissue. The current version is published on the Securus website.