Privacy

Intent

Personal information collected in the course of the ERA ’s activities will be treated respectfully and carefully.

The Privacy Act 2020 and other relevant regulatory standards will be complied with. 

Definitions

“Affected people” in relation to personal information that is the subject of a privacy breach refers to people to whom the information relates and includes people inside and outside Aotearoa/New Zealand. 

“Personal information” is information about an identifiable, living human being. It includes health information and all other types of information whether paper, digital, or electronic which identifies a person. 

Privacy Officer”- see here for role of Privacy Officer.

“Serious harm” – examples include: 

  • Physical harm or intimidation 
  • Financial fraud including unauthorised credit card transactions or credit fraud 
  • Family violence
  • Psychological, or emotional harm

Requirements

When and how we collect personal information

Personal information may be collected about people in the course of preparing and providing ERA activities/services.

The information collected must have a purpose.  If non-identifying information would suffice, we will collect and use that in preference to personal information.   

When personal information is collected, the purpose of collecting, how it will be used and kept safe will be explained. Particular care will be taken to collect information in a fair and understandable way and to avoid undue intrusion for people including young people. People will be informed of their rights to raise and complain about a breach of privacy and to access and correct personal information we hold. 

Personal information provided by third parties will, wherever practicable, be checked for accuracy with the person or whānau concerned. 

What we do with personal information

The personal information the ERA collects will be used for the purposes for which it was collected. We do not use it for any other purpose unless disclosure for another purpose is authorised by law or within the purpose agreed by the person concerned. 

Safety and security of personal information

Personal information will only be kept for as long as it’s needed for the purpose it was collected.

It will be stored securely (eg as a password-protected electronic record.) If it is held as hard copy, it will be locked securely.

Safe disposal of personal information

Personal information will be securely disposed of once the purpose for which it was collected no longer applies and if we are not obligated to keep it legally.

Reasonable care will be taken to safeguard privacy during the disposal process and where possible, the personal information (on our hardware and any third-party service used for backup or storage) will be irretrievably destroyed. If irretrievable destruction is not possible, arrangements will be made to prevent access.  

Disclosure to others 

Personal information will not be disclosed for trade or commercial purposes. It will only be disclosed to third parties with a person’s consent or in accordance with the law. 

Access to personal information

If a person wants to check and access their information, they will be given access within 20 working days of request unless there is good (lawful) reason to decline the request. They will be advised they can request a correction of their information. 

Personal information in this context does not include information relating to people other than the requestor.  The Trust will take all due care to protect the third-party information from being accessed. 

If a request is declined, the person concerned will be informed that they can complain to the Privacy Commissioner.

Generative AI

Personal information and organisationally sensitive information must not under any circumstances be input to and used with Generative AI, unless specifically agreed by the ERA  and in the case of personal information, agreed by the person whose information it is. 

If using publicly available AI (eg ChatGPT4, Goggle Baird, Bing CoPilot) for ERA  purposes, members must not:  

  • use AI-generated outputs without carefully scrutinising and vetting it for accuracy and bias
  • misrepresent AI-generated outputs as their own work
  • enter data to plagiarise the work of others or breach copyright
  • use public AI or Freemium versions for any purpose in breach of our policies, kaupapa and the law.

Recordkeeping

Trustees will ensure that a record is kept of: 

  • any request from a person to access the personal information we hold and of the date when received
  • a copy of the information that was accessed
  • authorisation to access 
  • the reasons for delay or refusal of access (may only be on lawful grounds)
  • safeguards that were implemented to action the request
  • other steps taken for the request (eg in relation to parental access).

Breach of privacy

If personal information is wrongly released or privacy is breached in another way, the ERA  will take immediate steps to contain the breach (eg change access code; shut down activity). Any affected person and the Privacy Commissioner will be notified if serious harm is caused or risked by the breach.

The Trust will investigate the privacy breach to ascertain the cause and prevent a recurrence.