The University of Sydney is committed to protecting the privacy and personal information of our students, staff, alumni, research participants, and community members. We collect, use, disclose, and store personal information in accordance with the following:
Mishandling of personal and health information including unauthorised access, use and disclosure of personal data or misuse of health information can lead to a breach of applicable privacy principles and our compliance with applicable laws. Non-compliance with privacy, health and data protection laws may lead to serious consequences. The University of Sydney is committed to managing privacy risks proactively and encourages all staff and affiliates to handle personal information in accordance with legal obligations and University policies.
The University collects and retains personal and health information as part of carrying out its statutory functions under the University of Sydney Act 1989 (NSW).
Examples of the types of personal and health information collected include:
The University collects personal information for lawfully authorised purposes that are necessary or directly related to our functions and activities under the University of Sydney Act 1989 (NSW) or for other applicable legislations and regulations. Broadly, we collect your personal information for the following purposes:
The University's primary privacy obligations are set out in the Privacy and Personal Information Protection Act 1998 (NSW) and the Health Records and Information Privacy Act 2002 (NSW). Our Privacy Policy 2017 (pdf, 365KB) – incorporating the privacy management plan – sets out the privacy responsibilities of the University, and its staff and students. Our Privacy Procedures 2018 (pdf, 291KB) describes how the University discloses personal information and how we will manage a notifiable breach of personal information held by the University.
The University has several clinics, services and entities that are subject to the same overarching privacy obligations and governance frameworks as the University itself. These may collect, use, disclose, and store personal and health information in connection with their operational, educational, research, or commercial functions. Individuals interacting with these organisations should be aware that the personal information collected may be shared with the University for legitimate and authorised purposes, and such handling will be conducted in accordance with the University’s privacy policies and applicable legal obligations.
The University has security measures in place to safeguard personal information from misuse, and unauthorised access, use, modification or disclosure, including those in the University’s Cyber Security Policy 2019 and Acceptable Use of ICT Resources Policy 2019 . We retain your personal information in accordance with our Recordkeeping Policy 2017.
We use reasonable safeguards to protect your personal information from unauthorised access, use or disclosure. We will retain your personal information for as long as required to meet the purposes for which it was collected, stored and in accordance with the State Records Act 1998 (NSW).
More details about the personal information collected by the University can be found in our Privacy Notices.
Under NSW privacy laws, you have the right to request access to and correct any personal information concerning you held by the University. Retention of your personal information is subject to the requirements of the State Records Act 1998 (NSW).
Enquiries for access should be directed to Privacy Team, if you live or are located outside Australia you may have additional rights for information contact, privacy.enquiries@sydney.edu.au.
You have the right to complain if you think the University has breached your privacy in the way it has handled your personal information. Complaints, also known as applications for internal review, should be made in writing within six months from when you first become aware of the breach. You can use the privacy complaint form (pdf, 109KB) to make your complaint. Email your completed complaint form to privacy.enquiries@sydney.edu.au
We will advise the NSW Privacy Commissioner of your name and the details of your complaint and keep the Commissioner up to date with the progress of the internal review.
Privacy complaints are considered by the University’s Chief Governance Officer who will advise you of the results of the internal review and any action that we propose to take in respect of that complaint. The report and any proposed actions are sent to the NSW Privacy Commissioner within 60 days of the date of the privacy complaint.