Privacy Policy for Management of Personal Information

This section describes the privacy policy of Sure Psychology for the management of clients’ personal information. The psychological service provided is bound by the legal requirements of the Australian Privacy Principles set out in the Privacy Act 1988 (Cth).

Digital client information and client files are held in secure electronic document management systems. Identifying paper-based information is held in a secure filing cabinet which is accessible only to authorised employees. The information on each file includes personal information such as name, address, contact phone numbers, medical history, and other personal and relevant clinical information collected as part of providing the psychological service.

How client’s information is collected

A client’s personal information is collected in a number of ways during psychological consultation with Sure Psychology. These include when the client provides information directly to Sure Psychology using hard copy forms, electronic correspondence, verbal interaction with Sure Psychology administrative staff, and when third parties provide personal information to Sure Psychology, via referrals, correspondence, and medical reports.

Implications of not providing personal information

If the client does not wish for their personal information to be collected in a way outlined by this Privacy Policy, Sure Psychology may not be in a position to provide the psychological service to the client. In some circumstances, clients may request to be anonymous or to use a pseudonym, unless it is impracticable for Sure Psychology to provide a service for the client or if Sure
Psychology is required or authorised by law to do so.

Purpose of holding personal information

A client’s personal information is gathered and used for the purpose of providing psychological services, which includes assessing, formulating, diagnosing, and treating a client’s presenting issue or concerns, as well as monitoring the client’s response to treatment. The personal information is retained in order to document what happens during sessions and enables the
practitioner to provide a relevant and informed psychological service that is evidence-based.

Disclosure of personal information

Clients’ personal information will remain confidential except when:

  • It is subpoenaed by a court, or disclosure is otherwise required or authorised by law
  • Failure to disclose the information would in the reasonable belief of Sure Psychology placing a client or another person at serious risk to life, health or safety
  • The client’s prior approval has been obtained to:
    • provide a written report to another agency or professional (e.g., a GP or a lawyer)
    • discuss the material with another person (e.g., a parent, employer, health provider, or third-party funder)
    • disclose to another professional or agency (e.g., GP) and disclosure of personal information to that third party is for a purpose which is directly related to the primary purpose for which the personal information was collected
    • disclose the information in any other manner relevant to the client’s care

A client’s personal information is not disclosed to overseas recipients unless the client consents or such disclosure is otherwise required by law. Clients’ personal information will not be used, sold, rented, or disclosed for any other purpose.

In the event that unauthorised access, disclosure or loss of a client’s personal information occurs, Sure Psychology will activate its data breach plan (see Section 21 Data Breach Policy below) and use all reasonable endeavours to minimise any risk of consequential serious harm.

Requests for access and correction to client information

At any stage clients may request to see and correct the personal information about them kept on file. The psychologist may discuss the contents with them and/or give them a copy or a summary, subject to the exceptions in the Privacy Act 1988 (Cth). If satisfied that personal information is inaccurate, out of date or incomplete, reasonable steps will be taken in the circumstances to ensure that
this information is corrected. All requests by clients for access to or correction of personal information held about them should be lodged in writing with Sure Psychology. These requests will be responded to in writing within 21 days, and an appointment will be made, if necessary, for clarification purposes.

If clients have a concern about the management of their personal information, they can discuss this with an authorised representative of Sure Psychology.

Clients can obtain a copy of the Australian Privacy Principles, which describe their rights and how their personal information should be handled at: https://www.oaic.gov.au/privacy/australian-privacy-principles

If clients wish to lodge a formal complaint about the use of, disclosure of, or access to, their personal information, they may do so with the Office of the Australian Information Commissioner by phone on 1300 363 992, online at: https://www.oaic.gov.au/privacy/privacy-complaints/ or by post to:

Office of the Australian Information Commissioner
GPO Box 5218
Sydney NSW 2001

Secure Data and Record Storage

Practitioners must comply with all policies and procedures outlined in this document in relation to client record security, particularly in regard to communication of clinical information (internally or externally) via any media or digital technology. Where possible, work-related or confidential issues should be discussed online using a secure medium.

In accordance with relevant State legislation (e.g., Health Records and Information Privacy Act 2002 (NSW), NSW Health Practitioner Regulation, 2010) and codes of conduct (APS Position Statement on Client Records) client records are required to be
kept and stored securely (locked cabinets/password protected computer files), for at least 7 years from the date of the last contact, or in the case of a child (under 18), up until the age of 25 years.

Permission to transport client files outside of the Sure Psychology office location must be sought from the authorised practice representative. When confidential client records are required to be taken from the office (e.g., during home visits) or
transmitted electronically, measures must be taken to ensure they are secured (e.g., locked bag or briefcase, password protected files, secure file transfer) and are not left unattended.

Social Media Policy

Sure Psychology has developed the following social media policy in order to safeguard client privacy, confidentiality, and to maintain boundaries of the therapeutic relationship. This policy is compliant with the Australian Health Practitioners Registration Authority (AHPRA) Social Media Policy (2014), the Australian Psychological Society (APS) Code of Ethics, and Section 133 of the National Law concerning Advertising of Registered Healthcare Services.

Purpose of Social Media Communication

Sure Psychology may use social media (e.g., Facebook, Instagram) to inform clients, health professionals and the public about new services, changes to existing services, provide health-related resources or other relevant information.

All social media channels managed by Sure Psychology are for professional, not personal use.

Staff should be aware of the public nature of social media and that their privacy and confidentiality often are not protected on social media. Therefore, they should take steps to ensure the privacy of their personal social media accounts. Staff should avoid contact with their current or past clients on social media, recognising that it may blur boundaries of the professional relationship, and remain mindful of ethical and legal obligations to maintain client privacy and confidentiality at all times. Staff should consider the risks and implications of using social media and online searches to obtain information about clients, students, trainees, consultees, and others with whom they work on a professional basis.

Social Media Channels – Likes, Follows and Comments, Friend Requests

If social media is utilised by Sure Psychology, clients will be informed of the following:

  • It is possible to view Sure Psychology social media content without liking, following or commenting on content.
  • If a client chooses to ‘like’ or ‘follow’ Sure Psychology on social media using their name, they may be publicly disclosing a relationship with this practice.
  • Feedback on news feeds, research, and current projects is welcomed, however testimonials or reviews about their experience of treatment will be removed due to National Laws that prohibit registered health professionals to publish testimonials.
  • Friend requests will not be accepted by Sure Psychology due to privacy concerns and the upholding of professional boundaries.
  • Clients will be requested not to use social media channels to communicate with individuals at Sure Psychology or send any personal or clinical communication via social media channels

Electronic Communication (Email, Text, eFax) Policy

For sending clinical reports it is preferable to use a secure email platform, unless prior consent is obtained from the client.

Where possible, Sure Psychology only uses non-secure email and text to discuss administrative matters such as booking appointments or sending links to online resources.

All clinically relevant email and text correspondence will be recorded in the client’s clinical record. For some practice management systems this occurs automatically.

As needed, clients are informed that electronic communication is only responded to during business hours. Where Sure Psychology is closed for holidays/annual leave, an out of office email auto-response will be set up advising when the practice will re-open.

Data Breach Policy

The below data breach plan is in accordance with the requirements of the Notifiable Data Breach Scheme. From 22 February 2018, new amendments to Australia’s Privacy Act established the Notifiable Data Breaches (NDB).

The NDB Scheme introduced an obligation to notify individuals whose personal information is involved in a data breach that is likely to result in serious harm. This is termed an ‘eligible data breach’ under the Scheme.

Step 1: Containment of Data Breach

In the event of a data breach Sure Psychology will take steps to limit any further access to or distribution of the affected information – or the possible compromise of other information.

Step 2: Assessment of Data Breach

Sure Psychology will notify the Office of the Australian Information Commissioner (OAIC) if there are reasonable grounds to believe that the data breach is likely to result in serious harm to any of the individuals whose information was involved.

In order to assess the risk of serious harm an assessment process will be undertaken including the following:

  • Identification – identifying the person(s) responsible for containing an assessing the breach (or suspected breach).
  • Investigation – an investigation will be conducted to determine the details of what information was breached and to whom it has been released.
  • Evaluation – the practice manager/director will then make a decision based on the operational evidence resulting from the investigation about necessary action.

Step 3: Remedial Action

Steps will be taken to reduce any potential harm to individuals. If actions are successful in making serious harm no longer likely, then notification will not be required.

Step 4: Formal Notification of Data Breaches

If serious harm remains likely the OAIC will be notified of an eligible data breach. The OAIC will be notified, using the OAIC data breach form. The notification will include recommendations about the steps individuals should take in response to the breach.

Depending on the nature of the data breach, other relevant agencies may be notified. These could include the police or law enforcement, the practice professional indemnity insurer (under any obligation of disclosure), or AHPRA if applicable under the mandatory notifications guidelines.

Following notification, Sure Psychology will notify affected individuals and tell them about the content of the statement to the Commissioner.

Only individuals at risk of serious harm will be notified at this stage.

Step 5: Review of Data Breach

A review of the incident will be conducted in order to learn from the incident and take ‘preventative action’ for the future. The review process aims to fully understand why the breach occurred in the first place and will consider changes to the relevant policies and procedures of the practice and revise staff education and training procedures.

Date Modified: 21 October 2025