0%

The ADC works to protect the health and safety of the public by ensuring dental practitioners meet the high standards required of dental professionals in Australia.

We are an independent accreditation authority assigned the accreditation functions for the dental professions by the Dental Board of Australia under the National Registration and Accreditation Scheme. As part of this role, we are responsible for a range of functions which involve the collection and management of personal information. These functions include:

  • assessing the professional qualifications, knowledge, judgement, and clinical skills of overseas trained dental practitioners, excluding dental specialists, for the purposes of eligibility to apply for registration to practise in Australia.
  • Management of channels for the communication and exchange of personal information including our website enquiry forms, and bulletin subscriber forms.

1.   Purpose

This purpose of the Privacy Policy is to outline how we collect, hold, use, and disclose your personal information.

Personal information means information or an opinion about an identified individual or an individual who is reasonably identifiable.

We reserve the right, at our discretion, to change this Privacy Policy by posting a revised Privacy Policy on our website.

References to “ADC”, “we”, “us”, and “our” in this Privacy Policy are references to Australian Dental Council Ltd (ABN 70 072 269 900). ADC International is a service of the ADC.

2.   Overview

The ADC is committed to protecting your privacy and the confidentiality of any personal information we collect. We value honesty and transparency and want you to know what we will do with your personal information.

We collect, use, disclose and otherwise handle your personal information or sensitive information in accordance with the Australian Privacy Principles (APPs) which are contained in the Privacy Act 1988 (Cth) (Privacy Act). This Privacy Policy is periodically reviewed and updated to reflect current ADC information handling practice.

 

3. Scope

The policy applies to all users of the ADC website, staff members, contractors, third parties, candidates and all other stakeholders.

4.   Policy

What personal information do we collect and hold?

In the course of our business operations we are likely to collect and hold various types of personal information about you.

The types of personal information we may collect and hold include:

  1. name, age, and date of birth
  2. residential, mailing, email, and billing address
  3. telephone and mobile numbers
  4. emergency contact person and their contact details
  5. passport information, including, for example, your passport number, date of issue, and expiration date
  6. information contained in any other identification document such as birth certificates or drivers licence
  7. areas of dental practice
  8. education and qualifications, including, for example, your graduation certificate, academic history, and academic transcript
  9. employment history and information
  10. registration status as a dental practitioner; and
  11. bank account

We may also collect and hold personal information regarding:

  1. details of the services we provide to you or that you have enquired about and any additional information necessary to deliver those services or respond to your enquiries
  2. information relating to you that you provide to us directly through our website or indirectly through your use of our website or through other websites or accounts from which you permit us to collect your personal information
  3. information you provide us by mail or that you provide in person
  4. photographs, film recordings, or audio from or about you that were collected at our examination centre
  5. information about you which has been obtained from a third party with your permission; and
  6. any other information that may be required in order to facilitate your dealings with

The ADC adheres to the Payment Card Security Standards for the secure storage and transmission of credit card and banking information. We do not store any credit card information on our website or write down any credit card details. If you provide your credit card or banking information via our website, the information provided will be passed onto our bank or payment provider for processing payments.

Sensitive information

The Privacy Act defines ‘sensitive information’ as information relating to racial or ethnic origin, political opinions, membership of a political, professional or trade association, membership of a trade union, religious beliefs or affiliations, philosophical beliefs, health information, genetic information, sexual orientation or practices and criminal record.

We may collect your sensitive information when we have your consent and when the collection is reasonably necessary for us to carry out one or more of our functions or activities.

Example of when we collect sensitive information

We require candidates to undertake assessment of eligibility. This means we often need to collect copies of identity documents (such as your passport) to confirm your name, date of birth and nationality, as required by the Health Practitioner Regulation National Law Act 2009.

How do we collect and hold personal information?

We may collect personal information either directly from you or from third parties. We may also collect personal information when you:

  1. submit an enquiry or communicate with us via our website, mail, email, fax, telephone or in person
  2. register for an account and access any portal on our website
  3. make an application to us for accreditation, assessment, or other related purpose
  4. access, disclose, download, upload, or update any information or documentation to or from any portal on our website or otherwise as part of any application
  5. book and undertake examinations with us, or an examination delivery organisation delegated or contracted by us
  6. complete and submit any form via our website
  7. complete or submit an authority to act
  8. submit a complaint in relation to our services
  9. submit an application to work with or work for the ADC as a staff member, board or committee member; or
  10. attend or provide personal information at our office or at our examination centre including, for example, any information we may collect about you through the use of surveillance devices (being CCTV).

Why and how do we use your personal information?

We may collect, hold and use your personal information for the following purposes:

  1. carrying on our business
  2. fulfilling our functions, obligations, and responsibilities under or as provided for under the Health Practitioner Regulation National Law Act 2009 or the equivalent legislation applicable in each Australian State and Territory
  3. fulfilling our functions, obligations, and responsibilities under the Migration Regulations 1994 (Cth). This would be information about education and work experience.
  4. answering enquiries and fulfilling requests for our services
  5. making decisions in relation to an assessment
  6. maintaining a record about a candidate and communicating with a candidate for the purposes of assessment
  7. receiving payment for our services
  8. appointment to our register of assessors, item writers or examiners
  9. providing payment to our staff members and contractors including, for example, payment to our assessors, item writers or examiners employed or contracted by us
  10. improving our services including, for example, by examining and keeping track of patterns of use in the emails and social interactions we send to you
  11. optimising our website and our users’ experience, such as by performing analytics and conducting research
  12. complying with our legal obligations, resolving any disputes that we may have with you or any of our users, and enforcing our agreements with third parties; or
    • providing information to organisations in Australia involved in the education, representation, assessment, or regulation of dental practitioners including Ahpra which required name, date of birth and education.

We may also use your personal information to communicate our services to you including, for example, communicating with you by mail, email, SMS, MMS, or telephone to inform you about our services. You may request not receive direct communication however this may impact our ability to provide services.

We may also use information about individual candidates to generate reports or other documents for the following purposes:

  1. research purposes, including, for example, research relevant to studying, teaching, or practising dentistry
  2. providing information to bodies and organisations involved in the education, representation, assessment, or regulation of dental practitioners; or
  3. monitoring the performance of our assessment and accreditation

We endeavour to do our best to first de-identify the information before using the information for the purposes described above.

Direct marketing

Direct marketing is the promotion of goods and services directly to you including through social media, emails, SMS, phone calls and by mail. Due to the nature of the ADCs work, direct marketing is not undertaken.

Who do we disclose personal information to?

We may disclose personal information for the purposes described in this Privacy Policy to:

  1. our contractors, or our staff members
  2. our related bodies or staff members of our related bodies
  3. our suppliers or service providers such as:
    • contractors assisting us to provide services to you
    • mailing and distribution providers which organise delivery of services; or
    • live help service providers, maintenance, or repair services
  4. our professional advisers (including, for example, our accountants, lawyers, and auditors)
  5. our insurers
  6. payment system operators such as banks or merchants receiving credit or debit card payments
  7. anyone to whom our assets or businesses (or any part of them) are transferred
  8. specific third parties authorised by you to receive information held by us
  9. any person as may be required, authorised, or permitted by law; or
  10. government agencies, courts, law enforcement agencies, or regulatory or industry bodies including, for example, bodies and organisations involved in the education, representation, assessment, or regulation of dental practitioners such as the Dental Board of Australia, the Department of Education, the Department of Home Affairs, the Department of Employment and Workplace Relations and the Australian Health Practitioner Regulation Agency.

Do we disclose personal information outside Australia?

We may disclose personal information to entities located in countries outside of Australia for purposes such as:

  • verifying information provided by you as part of an application for assessment including, for example, corresponding with the authorities or education providers in the countries in which you qualified or practised or in any country specified in any form you provide us with (e.g. Staff of Pearson (in the USA) which conduct written examinations)
  • identifying you when sitting examinations outside Australia.

It is not practical for us to specify the countries to which we may provide personal information, given our functions to liaise with applications for assessment who may reside in any country. However, we will take reasonable steps to inform you, or seek your consent where required before corresponding with a specific outside Australia.

We may disclose or store your personal information to our contracted information technology service providers that are hosted offshore or in cloud via Amazon Web Services (AWS). We will take reasonable steps to ensure that any overseas recipients of your personal information will abide by the Australian Privacy Principles.

What security measures do we have?

We will take steps that are reasonable in the circumstances to protect your personal information that we hold from loss, misuse, interference, unauthorised access, modification, or disclosure.

We hold personal information in both hard copy and electronic formats. Paper files are stored in lockable cabinets onsite. They may also be archived in boxes and stored offsite in secure facilities.

The security of your personal information is important to us and when storing and handling your personal information, we use a secure server using the latest SSL (secure sockets layer) encryption technology to process any financial transactions.

The steps we take to ensure the personal information we collect and hold is protected from misuse, interference and loss, as well as unauthorised access, modification or disclosure include:

  • website protection measures (such as encryption, firewalls and anti-virus software)
  • access restrictions to our computer systems requiring multi-factor identification (such as login and password protection)
  • restricted access to our office premises and files containing personal information,
  • adherence to the Payment Card Data Security Standards,
  • staff training and implementation of workplace policies and procedures that cover access, storage and security of information, and
  • regular cyber security awareness activities such as phishing simulations, and
  • maintaining retention and disposal policies to ensure reasonable steps are taken to destroy or de-identify personal information when it is no longer required

While we strive to protect the personal information and privacy of users of our website, no data transmission over the internet can be guaranteed to be 100% secure and any information that you disclose online is disclosed at your own risk. If you are concerned about sending your information over the internet, you can contact us by telephone or mail.

Third party websites

Links to third party websites that are not operated or controlled by us are provided for your convenience. We are not responsible for the privacy or security practices of those websites. Third party websites should have their own privacy and security policies, which we encourage you to read before supplying any personal information to them.

Do we monitor your use and access of our website and use cookies?

We may collect some information about website visitors when users access our website. We may record certain information about the use of our website, such as which pages users visit, the time and date of their visit, which country users are accessing our website from, and the internet protocol address assigned to the user’s computer.

Cookies are small data files stored in your device’s memory that do not, of themselves, identify individuals personally but do identify devices. We use cookies on our website. We use session ID cookies to make it easier for you to navigate our website. A session ID cookie expires when you close your browser. If you reject cookies, you may still use our website but your access to our website and its functionality may be limited.

Some of our business partners use cookies and web beacons on our website. We have no access to or control over these tracking technologies.

How do you access and correct your personal information?

We will take steps that are reasonable in the circumstances to ensure that the personal information we collect, hold, use or disclose is accurate, complete, and up to date. However, we rely on the accuracy of personal information provided to us by you and others to be accurate.

We encourage you to regularly review and update your personal information.

You may request in writing to access or update your personal information if it is inaccurate, incomplete, or outdated. If we do not allow you to access any part of your personal information that we hold about you, we will provide you with reasons why.

If we do not allow or update any part of the personal information that we hold about you, we will provide you with reasons and give you details about your other access and correction options under the Privacy Act.

How do you make a complaint?

If you wish to make a complaint about the way we have handled your personal information or believe that a breach of this Privacy Policy may have occurred, you may submit your complaint by email to privacy@adc.org,au. Please include your name, email address, and telephone number. Please also clearly describe your complaint.

We will acknowledge your complaint within three business days and aim to resolve your compliant within 30 business days, or if the complaint is particularly complex, with notice that a responsible will be provided within a further period of time. If you think that we have failed to resolve the complaint satisfactorily, we will provide you with information about further steps you can take.

If you are unhappy with our response, you can refer your complaint to the Office of the Australian Information Commissioner (see details below) or, in some instances, other regulatory bodies, such as:

 

Office of the Australian Information Commissioner Online:

www.oaic.gov.au/about-us/contact-us

Phone: 1300 363 992 (Australia) or +61 2 9284 9749 (International) Email: enquiries@oaic.gov.au

Fax: +61 2 9284 9666

Post: GPO Box 5218 Sydney NSW 2001

How to contact us to make an enquiry or report a concern?

You may contact the ADC Privacy Officer with any enquiries or concerns regarding the ADC’s management of personal information:

Address: Level 6, 469 La Trobe Street Melbourne Vic 3000

Email: privacy@adc.org.au

Fax: 61 3 9657 1766

The ADC also maintains specific processes to guide its timely response to suspected data breaches. If you identify a potential breach in security regarding personal information, you can report it by telephone on +613 9657 17777 or via the email address above.