RIVIRhouse Pty Ltd complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. When engaged as a contracted service provider to a Queensland Government agency, we also comply with the Information Privacy Act 2009 (Qld), the Queensland Privacy Principles, and the applicable Queensland Government Enterprise Architecture (QGEA) policies.
01Compliance
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
When engaged as a contracted service provider to a Queensland Government agency, we also comply with:
- The Information Privacy Act 2009 (Qld) and the Queensland Privacy Principles.
- Applicable QGEA policies, including the information security policy (IS18) and the records governance policy.
- The privacy, security, and recordkeeping terms of the engagement contract.
In those engagements the agency remains the custodian of the information. We handle it on the agency's behalf and under its direction.
03How we protect it
We store information securely, restrict access to those who require it, and apply encryption in transit and at rest, access controls, and multi-factor authentication.
Queensland Government client information is managed to the applicable QGEA information security and records governance policies, and retained only as long as the contract and public records legislation require. Other information is retained only as long as required, then destroyed or de-identified.
Where a data breach is likely to cause serious harm, we notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Where the breach involves Queensland Government information, we notify the agency immediately so it can meet its obligations under the Queensland mandatory notification of data breach scheme.
04Review
We review this policy annually and when our obligations change. It sits alongside our Human Rights Policy and Modern Slavery Statement.