Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryPrivacy Policy
Contents & downloads
Purpose
This policy establishes Westlink Logistics’ commitment to protecting the privacy of personal information. It sets out how the organisation collects, holds, uses, and discloses personal information in compliance with the Privacy Act 1988 (Cth), the thirteen Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) scheme.
Scope
This policy applies to all personal information collected, held, used, or disclosed by Westlink Logistics. It applies to all directors, workers, contractors, and third-party service providers who handle personal information on behalf of the organisation. Personal information includes any information or opinion about an identified or reasonably identifiable individual, whether true or not and whether recorded in material form or not.
Organisational Context
Westlink Logistics operates heavy haulage, project logistics, and maritime services across Australia, primarily supporting defence, government, resources, and infrastructure sectors. The organisation collects personal information of workers, contractors, clients, and suppliers for employment administration, security vetting, WHS obligations, payroll, and client service delivery. Sensitive information including health records, criminal history, and security clearance data is held for DISP and fitness-for-work purposes.
The organisation holds DISP membership and is subject to JOSCAR pre-qualification, both of which require demonstrated data privacy controls. The Privacy and Other Legislation Amendment Act 2024 introduced a statutory tort for serious invasion of privacy (commenced June 2025), increasing the consequence of privacy breaches.
Policy Commitments
Westlink Logistics is committed to:
-
Collecting only personal information that is reasonably necessary for business functions, directly from the individual where practicable, and providing notice of collection purposes at or before the time of collection (APP 3, APP 5).
-
Using and disclosing personal information only for the primary purpose of collection or a directly related secondary purpose the individual would reasonably expect. Westlink does not sell personal information or use it for unsolicited direct marketing (APP 6, APP 7).
-
Protecting personal information from misuse, interference, loss, unauthorised access, modification, and disclosure through physical, technical, and administrative security measures aligned with TEC-POL-001. Information no longer needed is destroyed or de-identified per APP 11.2 and GOV-SCH-001 (APP 10, APP 11).
-
Providing individuals with access to their personal information and correcting inaccurate, out-of-date, or incomplete information within 30 days of request, unless an exception under the Privacy Act applies (APP 12, APP 13).
-
Maintaining a data breach response capability per Part IIIC (NDB scheme). Where a breach is likely to result in serious harm, Westlink will notify the OAIC and affected individuals as soon as practicable. All suspected breaches must be reported immediately to the QHSE Manager.
Responsibilities
| Role | Responsibility | When |
|---|---|---|
| Chief Executive Officer | Accountable for this policy. Ensures the organisation meets its obligations under the Privacy Act 1988. | Ongoing; annual management review |
| QHSE Manager | Implements this policy. Coordinates data breach response. Maintains the data breach register. Liaises with the OAIC as required. | Ongoing; on breach notification |
| Managers and Supervisors | Ensure their teams understand and comply with privacy obligations relevant to their functions. | Ongoing; on new process/system |
| All Workers and Contractors | Protect personal information in accordance with this policy. Report any suspected data breaches immediately to the QHSE Manager. | Ongoing; on suspected breach |
Review
This policy is reviewed annually as part of the management review cycle, or following any notifiable data breach, significant legislative change, or update to OAIC guidance. This policy is communicated to all workers at induction and is available to interested parties on request.
Applicable Standards and Legislation
-
Privacy Act 1988 (Cth)
-
OAIC Guide to Securing Personal Information (2024)
-
OAIC Data Breach Preparation and Response guidance
-
ISO 9001:2015 Quality Management Systems — Requirements
Related Documents
-
TEC-POL-001 Information Security Policy
-
GOV-POL-011 Grievance Resolution Policy
-
QHSE-PRO-001 Hazard and Incident Reporting and Investigation Procedure
Compliance coverage — cited by 31 requirements across 3 frameworks
ISO 9001:2015(5)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO9001-2015-4.2-01 | 4.2 | Full | §Organisational ContextPrivacy Policy — commits to DISP/JOSCAR data privacy. | |
| ISO9001-2015-5.1.1-01 | 5.1.1 | Partial | Low | §ResponsibilitiesPrivacy Policy — commits to CEO accountable for policy. |
| ISO9001-2015-5.3-01 | 5.3 | Full | §ResponsibilitiesPrivacy Policy — commits to breach response and OAIC liaison. | |
| ISO9001-2015-7.4-01 | 7.4 | Full | §ReviewPrivacy Policy — commits to Available to interested parties. | |
| ISO9001-2015-9.3.1-01 | 9.3.1 | Full | §ReviewPrivacy Policy — commits to Annual review. |
JOSCAR-AU 2026(9)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| JOSCAR-Q1.4.7 | Q1.4.7 | Full | Privacy Policy governs personal information handling. | |
| JOSCAR-Q1.4.12 | Q1.4.12 | Full | Privacy Policy applies to personal information collected or processed on behalf of clients, per Australian Privacy Principles. | |
| JOSCAR-Q2.12.1 | Q2.12.1 | Full | Privacy Policy. | |
| JOSCAR-Q2.12.1.1 | Q2.12.1.1 | Full | Privacy Policy scope covers personal information collected from or on behalf of clients. | |
| JOSCAR-Q2.12.2.1 | Q2.12.2.1 | Full | Privacy Policy defines categories of personal information collected. | |
| JOSCAR-Q2.12.2.2 | Q2.12.2.2 | Partial | Medium | Privacy Policy addresses consent. |
| JOSCAR-Q2.12.2.3 | Q2.12.2.3 | Full | Privacy Policy addresses safeguards. | |
| JOSCAR-Q2.12.3 | Q2.12.3 | Partial | Medium | Privacy Policy addresses data accuracy and update obligations (APP 10). |
| JOSCAR-Q2.12.4 | Q2.12.4 | Partial | Medium | Privacy Policy references retention but no separate retention schedule document is in WMS. |
Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches(17)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| PRV-APP1-01 | APP 1.2 | Partial | High | §Purpose / Policy CommitmentsPolicy establishes APP compliance framework and assigns complaint-handling to Privacy Officer role. Operating procedures (PIA process, training, audit) not separately documented. |
| PRV-APP1-02 | APP 1.3 | Full | §whole documentGOV-POL-015 Privacy Policy (Rev 3) is APP-structured and covers APPs 1-13 + Part IIIC NDB. Reviewed as part of the management review cycle per Review section. | |
| PRV-APP1-03 | APP 1.4 | Partial | High | §Organisational ContextOrganisational Context section identifies types of information. APP 1.4 overseas-disclosure countries list — policy states whether disclosure occurs but country list may be general (verify). |
| PRV-APP3-01 | APP 3.1 / 3.2 | Full | §Policy CommitmentsPolicy bullet 1 commits to collection minimisation (APP 3). | |
| PRV-APP5-01 | APP 5 | Partial | High | §Policy CommitmentsPolicy bullet 1 commits to notification at or before collection (APP 3, APP 5). Operational notices at collection points (employment forms, customer onboarding forms, supplier onboarding) not verified to contain all APP 5.2 matters. |
| PRV-APP6-01 | APP 6 | Full | §Policy CommitmentsPolicy bullet 2 commits to use/disclosure for primary purpose only (APP 6). No secondary-purpose register or consent capture mechanism documented. | |
| PRV-APP7-01 | APP 7 | Full | §Policy CommitmentsPolicy bullet 2 states "Westlink does not sell personal information or use it for unsolicited direct marketing (APP 6)." Functional compliance by policy-level prohibition. | |
| PRV-APP10-01 | APP 10 | Partial | Medium | §Policy CommitmentsPolicy bullet 3 addresses quality/retention. Operational mechanisms (periodic data quality review, record correction workflows) not documented separately. |
| PRV-APP11-01 | APP 11.1 | Full | §Policy CommitmentsPolicy bullet 3 references APP 11. | |
| PRV-APP11-02 | APP 11.2 | Full | §Policy CommitmentsPolicy bullet 3 commits to destruction per APP 11.2 and GOV-SCH-001. | |
| PRV-APP11-03 | APP 11 / OAIC Guide | Partial | High | §Policy CommitmentsBreach response referenced; detailed plan absent. |
| PRV-APP12-01 | APP 12 | Partial | High | §Policy Commitments / ResponsibilitiesPolicy establishes access right and assigns Privacy Officer to process requests. No documented access-request handling procedure (intake form, verification, response template, exceptions register). |
| PRV-APP13-01 | APP 13 | Partial | Medium | §Policy CommitmentsPolicy bullet 4 addresses access and correction together. Operational mechanism not documented. |
| PRV-NDB-01 | s.26WE — eligible data breach | Full | §Policy CommitmentsPolicy commits to NDB compliance. | |
| PRV-NDB-02 | s.26WH, s.26WK, s.26WL — assessment, statement and notification | Full | §Policy CommitmentsPrivacy Policy — commits to NDB scheme compliance; breach response and OAIC liaison. | |
| PRV-NDB-03 | s.26WK(3), OAIC guidance — data breach response plan | Full | §Policy CommitmentsPrivacy Policy — commits to NDB scheme compliance. | |
| PRV-REFORM-01 | Privacy and Other Legislation Amendment Act 2024 + pending tranches | Referenced-only | §Organisational ContextPrivacy Policy — commits to POLA Act 2024 statutory tort. |
Declared compliance references (31)
ISO9001-2015-4.2-01ISO9001-2015-5.1.1-01ISO9001-2015-5.3-01ISO9001-2015-7.4-01ISO9001-2015-9.3.1-01JOSCAR-Q1.4.12JOSCAR-Q1.4.7JOSCAR-Q2.12.1JOSCAR-Q2.12.1.1JOSCAR-Q2.12.2.1JOSCAR-Q2.12.2.2JOSCAR-Q2.12.2.3JOSCAR-Q2.12.3JOSCAR-Q2.12.4PRV-APP1-01PRV-APP1-02PRV-APP1-03PRV-APP10-01PRV-APP11-01PRV-APP11-02PRV-APP11-03PRV-APP12-01PRV-APP13-01PRV-APP3-01PRV-APP5-01PRV-APP6-01PRV-APP7-01PRV-NDB-01PRV-NDB-02PRV-NDB-03PRV-REFORM-01
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 24/05/2021 | WLK-GBL-GOV-POL-015 | Privacy Policy | CEO (JDG) | CEO (JDG) |
| 2 | 09/03/2026 | GOV-POL-015 | Privacy Policy | FTM (CF) | CEO (JDG) |
| 3 | 16/03/2026 | GOV-POL-015 | Privacy Policy | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 3 | Added Organisational Context section — identifies types of personal and sensitive information held (health, criminal history, security clearance), DISP/JOSCAR requirements, and POLA Act 2024 statutory tort liability (commenced June 2025).• Consolidated 16 APP-specific bullets into 5 focused policy commitments grouped by APP function (collection, use/disclosure, security/retention, access/correction, NDB). Detailed APP compliance belongs in a privacy management plan.• Added TEC-POL-001 cross-reference in security commitment — privacy security measures must align with the information security framework.• Added GOV-SCH-001 cross-reference in retention commitment — destruction/de-identification per the retention schedule.• Added GOV-POL-011 (Grievance) to related documents — privacy complaints pathway.• Responsibilities converted from paragraphs to 3-column table.• Removed JOSCAR as standalone applicable standard reference — JOSCAR requirements are contextual, not a standard Westlink is certified against. Retained in org context.• Updated terminology: 'employee' to 'worker' throughout.• Added requirements traceability matrix mapping commitments to specific APPs, Part IIIC, and ISO 9001 clauses. |