Privacy
1. The Association is committed to protecting your privacy
The NSW Nurses and Midwives’ Association (NSWNMA)/Australian Nursing and Midwifery Federation NSW Branch (hereafter referred to as “we”, “us” or “the Association”) is the union representing nurses, midwives and carers in NSW.
The Association is committed to promoting and adhering to high standards of protection and accountability in its governance to ensure the protection and privacy of your personal information.
This policy outlines how the Association will comply with privacy requirements in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). Find out more from the Office of the Australian Information Commissioner https://www.oaic.gov.au/
This policy describes how we handle personal information.
This policy provides information on what personal information is collected, how this information is used, how long it will be kept for, who it is disclosed to or shared with, and the process of how incorrect personal information amended.
This policy also applies to personal information the Association collects from any other third party.
Australian Privacy Principles (APP). These are a set of 13 legally binding principles that govern how personal information must be handled by Australian Government agencies and private sector organisations that manage personal information as part of business as usual e.g. national retailers, banks, insurers, universities and private hospitals.
NSWNMA Members are all people who’ve joined the NSWNMA. This includes nurses, midwives, assistants in nursing (AINs), assistants in midwifery, carers and nursing/midwifery students (TAFE or university) working in NSW public, private, or aged care and primary health care sectors. This includes councillors and delegates, members who are financial, unfinancial or have resigned.
NSWNMA Online means NSWNMA websites, including The Lamp, lead generation platforms, social media and Membership Central.
NSWNMA Staff means NSWNMA Elected Officers, Managers, Coordinators, Employees, Workers and Contractors.
Personal information means information/opinion about an identified person, or a person who is reasonably identifiable – whether the information or opinion is true or recorded in a material form. This may include sensitive information which means information or an opinion about such matters as a person’s membership of a trade union, identity as Aboriginal or Torres Strait Islander or racial or ethnic origin. The Privacy Act allows the Association, with your consent, to collect sensitive information where it relates to the Association’s activities.
Record Retention and Disposal Schedule (RRDS) A Record Retention and Disposal Schedule (RRDS) is a NSWNMA policy that sets how long records must be kept and how to dispose of or archive them securely. It ensures compliance with this policy and the Records Policy. Its purpose is to reduce organisational risk and only keep records for as long as they are needed.
In Scope
The Association collects personal information from members, employers and other stakeholders to support its work in advocating for and representing the interests of its members in the nursing and midwifery professions, as well as the employment of nurses, midwives and carers. We also gather information to communicate with community stakeholders and provide details about our products and services. This includes information from people who submit job applications including CVs and cover letters to the Association.
Out of Scope
The policy does not apply to staff records, current or separated. The NSWNMA Personnel Files Policy addresses staff private information.
5. Privacy principles and actions
Personal information is collected, held, used, disclosed, and shared – by the Association and authorised third parties to:
- Provide member services and support
- Administering member employment-related matters
- Fulfilling legal obligations
- Conduct research and analysis
- Communicate with members and stakeholders
- Deliver education, training, and promotional materials and products
- Facilitate operational functions through third-party service providers (e.g. IT, communications, data hosting)
- Refer individuals to legal or professional services where appropriate
Where necessary, personal information may be shared with third parties who are bound by contractual obligations to comply with the Association’s privacy and security standards. This includes service providers, affiliated organisations, and legal professionals, provided such sharing is lawful and aligned with the purpose for which the information was collected.
The Association will only collect, hold, use and disclose personal information – whether obtained directly or through a third party by express consent for these purposes. The Association does not sell personal data or share personal information with political parties or other affiliated Associations.
The Association collects personal information in several ways including via:
- NSWNMA Online;
- Photography and video at campaign events and rallies
- Social media platforms in circumstances where: o An Association rule has been breached
- A member or stakeholder initiates a request for engagement Telephone, mobile applications, email or fax;
- In person and/or in writing.
The Association only collects your personal information that is necessary to perform our functions and/or activities.
In addition, we use online tools to gather information to make it easier and more rewarding to use our sites:
- Cookies: When a person visits or uses a website of the Association, personal information may be collected automatically through cookies including IP address and/or domain name, operating system (type of browser and platform), the date, time and length of the visit to the website. This information primarily is used for the compilation of statistical information about the use of the website. Cookies may also be used to assist the Association and our third-party service providers present targeted and customised advertising to a person using our website or a third party’s website.
- Website traffic: The Association uses Google Analytics to track visits to our website. Google Analytics is a web analytics tool that helps website owners understand how visitors engage with their website. Google Analytics customers can view a variety of reports about how visitors interact with their website so they can improve it. Types of data collected include visits, viewed pages and the technical capabilities of our visitors. Google Analytics collects information anonymously, however once you have registered your membership online these statistics will identify you. For more information read Google’s Privacy Policy.
- Links to other websites: The Association’s website may contain links to third party websites and social media pages including Facebook, Instagram, X (previously Twitter) and LinkedIn. These websites and social media pages may also have links to the Association’s website. This Privacy Policy does not apply to external links or other websites. These third-party websites may collect personal information. The Association encourages people to read the privacy policies of any website you link to from the Association’s website.
The Association may disclose personal information to other organisations, in connection with, or to further its objects and purposes, provided that reasonable steps are taken to ensure that each organisation to which the personal information is disclosed is committed to protecting privacy and complies with the Australian Privacy Principles (APPs) or is subject to a law or scheme that is at least substantially similar to the way in which the APPs protect information.
By consenting to share personal information with the Association, individuals acknowledge that their information, may be disclosed to third-party organisations:
- For the purpose for which you provided it;
- As otherwise outlined in this policy; or
- As otherwise permitted by the APPs.
By consenting to share personal information with the Association, individuals acknowledge that their information may be stored and processed on data servers, including cloud-based services operated by third-party providers, which may be located outside of Australia.
The Association is committed to complying with the Spam Act 2003 (Cth) in relation to the sending of electronic communications. When sending commercial electronic messages, the Association will ensure that it:
- Obtains consent from recipients, whether express or implied in accordance with applicable laws;
- Clearly identifies the Association as the sender; and
- Includes unsubscribe option where applicable.
Payments made to the Association online are processed in real time using a secure payment gateway. Once the payment has been processed, payment information such as credit card details are tokenised.
Individuals may request to deal with the Association anonymously or through a pseudonym. We will accommodate your request if it is lawful, possible and practical to do so; however, this may not always possible.
The Association takes all reasonable steps to ensure that personal information collected, held, used, disclosed, stored and handled is complete, accurate, relevant and up to date.
People have the right to request access to their personal information without unreasonable delay or expense and either update it online or request that it be updated or corrected by visiting Member Central or contacting the NSWNMA Membership Services team at:
NSWNMA
50 O’Dea Avenue,
Waterloo, 2017
or gensec@nswnma.asn.au
Identity verification will be sought before disclosing any personal information.
Members may unsubscribe or opt out of communications at any time by contacting the Association by phone, mail or email at gensec@nswnma.asn.au, directed to Membership Services. Members can also opt out of receiving the print version of The Lamp through Member Central.
All reasonable steps are taken to ensure the security of personal information by storing it in a secure environment. Personal information kept electronically is handled with care and secured by multi-factor authentication, user identifiers, and passwords accessed only by authorised personnel. The Association’s internal databases are secured by a firewall and anti-virus software to ensure, so far as practicable, that they are not accessed by unauthorised parties.
If third party providers are used in connection with the storage of personal information it is standard practice to require these third-party providers, through agreements with them, to comply with the Association’s security guidelines and this Privacy Policy. The Association requires our employees, contractors and third-party service providers to respect and protect the confidentiality of personal information held.
NSWNMA Online has security measures designed to protect against the loss, misuse and/or alteration of personal information under the Association’s control. Secure pages on the Association’s website are protected by a 256-bit SSL certificate. We implement appropriate technical and organisational safeguards to protect data transmitted via internet connectivity with our services. However, due to the nature of the internet, no method of transmission can be guaranteed as completely secure. Internet access may be compromised by third-party malicious actors using sophisticated cyber security techniques, including credential theft and data harvesting attacks. For this reason, it is important that users access our systems from a trusted and secure internet connection to help minimise risk.
The Association’s security arrangements are monitored and reviewed regularly and all staff made aware of organisational systems for the processing, storing and transmitting of personal information and the protective security policies associated with this.
We retain personal information only for as long as it is reasonably necessary to fulfil the purposes for which it was collected, including to meet legal, regulatory, contractual, financial, audit, and operational obligations.
Where personal information is no longer required for a permitted purpose and we are not legally required to retain it, we will take reasonable steps to securely destroy or permanently de-identify the information in accordance with our information security policies and applicable laws.
Further details regarding the processes for creating, managing, and disposing of organisational records are outlined in the Records Management Policy. Staff may access this policy through the intranet, and members may request a copy if needed.
Separate from this policy, NSWNMA’s Cyber Security Policy provides guidance on how NSWNMA responds to data breaches of held information. It sets out the procedures for outlines the procedures for identifying, managing, and responding to substantiated data breaches in accordance with the Privacy Act 1988 and the Notifiable Data Breaches (NDB) scheme.
Queries or notices about data breaches should be made to the NSWNMA Privacy Officer at: gensec@nswnma.asn.au
The Association will seek to deal with any privacy complaints confidentially, seriously and promptly. To make a complaint about an alleged breach of the APPs please email the NSWNMA Privacy Officer at: gensec@nswnma.asn.au
The Association will acknowledge receipt of a valid complaint within one business day and will provide progress updates within 14 business days until the matter is resolved. If the Privacy Officer or Chief Operating Officer is unavailable, responsibility will be delegated to the Chief Technology Officer, followed by an Elected Officer if necessary. Where appropriate, the Association may also refer the concern or complaint to an independent mediator or to the Office of the Australian Information Commissioner.
Amendments to the Privacy and Other Legislation Amendment Act 2024 are now in effect. Key changes and requirements include:
- Enhanced Data Security Measures (APP 11): The Association has implemented technical and organisational measures to protect personal information. These include encryption, access controls, secure backups, audit logging, and staff training. These measures are designed to ensure compliance with the clarified obligations under APP 11 effective from 11 December 2024.
- OAIC Enforcement Powers: The Office of the Australian Information Commissioner (OAIC) now has expanded powers to issue infringement notices and compliance notices. The Association has updated its internal procedures to ensure readiness for these enforcement mechanisms.
- Children’s Privacy Protections: The Association supports the development of the Children’s Online Privacy Code and will comply with its provisions once registered by 10 December 2026. Measures will be taken to ensure the protection of children’s personal information online.
- Overseas Data Transfer Provisions: The Association will comply with the new whitelist mechanism for overseas data transfers. Personal information will only be transferred to jurisdictions approved by the Minister as having equivalent privacy protections, effective 11 December 2024.
This Policy will be reviewed every three years or earlier where changes are required. The next review date is June 2029.
The information contained on this page may be amended from time to time.





