Contents
At Foxtel, we are committed to ensuring compliance across all relevant privacy related legislation. There are several privacy related laws which regulate how we handle customer information.
The over-arching law is the Privacy Act 1988, which contains 13 Australian Privacy Principles (APPs). These principles govern how we collect, hold, use and disclose Personal and Sensitive Information.
Personal information is defined as all information within the Foxtel Group's control about an identified individual or an individual who is reasonably identifiable. Including (but not limited to):
- an individual's name, address, telephone numbers, email address;
- account number;
- services subscribed to;
- payment history;
- any other information relating to an individual or provided by an individual to the Foxtel Group.
Sensitive information means information or an opinion about (including but not limited to):
- an individual's racial or ethnic origin;
- political opinions;
- religious beliefs;
- sexual orientation;
- medical conditions;
- difficult/traumatic experiences
2. Collecting Personal Information
Principles that govern the collection of Personal Information:
APP3 Collection of Solicited Personal Information
Employees of the Foxtel Group should 1. only collect personal information when essential for a business task, 2. for sensitive data, always get consent and 3. gather information fairly and directly from the individual, unless impossible.
APP5 Notification of the Collection of Personal Information
Individuals must be told why their personal information is being collected, either at the time of collection or soon after.
Examples of a breach:
- an employee asking a customer for their driver's license number, incorrectly claiming it is for ID verification
- an employee asking probing questions on a customers mentioned relationship break-down, claiming it is for a valid business purpose
- an employee hearing sensitive information mentioned in the background of the call, and recording this against the customer's account
3. Storing & Sharing Personal Information
Principles that govern the storage and sharing of Personal Information:
APP5 Notification of the Collection of Personal Information
Individuals must be told why their personal information is being collected, either at the time of collection or soon after.
APP6 Use & Disclosure of Personal Information
The Foxtel Group can use or share personal information if 1. the individual consents, 2. for its original collection purpose, or 3. for a related secondary purpose they would reasonably expect (directly related for sensitive data).
APP11 Security of Personal Information
The Foxtel Group must 1. reasonably protect personal information from misuse, loss, or unauthorized access, and 2. destroy or de-identify it when no longer needed, unless legally required to retain it.
APP12 Access to Personal Information
Individuals generally have the right to access their personal information held by the Foxtel Group, unless special circumstances apply.
Examples of a breach:
- an employee keeping a notepad on their desk with a customer's personal information written down
- an employee recording a customer's personal information in a saved excel spreadsheet for the purpose of call tracking
- an employee sending an email to a colleague with a screenshot of a customer's account that displays their personal information
The Foxtel Group is required to have a privacy policy setting out how it handles Personal Information.
The Foxtel Group Privacy Policy is provided to subscribers when they sign up to a service and is available on our website.
Internally, employees complete the Privacy training module during induction (with a yearly refresh). We also have the Foxtel Privacy Compliance Policy which governs how the Foxtel Group handles the Personal Information of our subscribers, potential subscribers and other individuals (as well as staff). This is available on the Foxtel Group Intranet.
Important: If any CI notes refer to information deemed sensitive, you must escalate to a Team Leader for removal. The Team Leader will edit/remove CORE notes via Kenan. For Zendesk, refer to Procedure - Redacting Sensitive Information in Zendesk.