Skip to main content
Shield Data Systems

Privacy

Privacy policy

Set out as drills, because that is what this company sells. Every clause names the precondition it starts from, the procedure that runs, the outcome you should be able to observe, and the record left behind afterwards. Each is also marked with the capacity it applies in, since the obligations we carry for our own records and the obligations we carry for a customer's backup are not the same obligations.

Effective 14 August 2026Version 2.0Privacy Act 1988 (Cth)Controller and processor

01Both rolesWhich capacity you are reading

Start here, because the rest of this document is unreadable without it. Two entirely different bodies of information pass through this company, and blurring them is the standard failure of business-to-business privacy writing.

The first kind we chose to gather. Somebody emailed us, or signed an engagement, or asked to be quoted, and we decided to keep what came with that. We set the purpose, so we answer for it. This document marks those clauses Controller.

The second kind arrived because a customer handed us a backup and asked whether it restores. Inside that backup sit records about the customer's own employees, patients, students, clients, donors, whoever they are. We did not choose the purpose, we do not know most of the contents, and the people concerned have never heard of us. Those clauses are marked Processor, and there the customer, not this company, is the organisation you want.

Precondition

You want to know what happens to information about you.

Procedure

Establish which side you are on. Did you write to us, or were you simply inside a file a customer of ours nominated for a rehearsal?

Outcome

Wrote to us: read the Controller clauses and address requests to us. Sat inside a backup: read the Processor clauses, and the organisation that took the backup is the one that must answer you.

Record kept

Where you contact the wrong one of us, we identify the right one and route the request. Drill 20 gives the timing.

02Both rolesThe company and the reach of this policy

SHIELD DATA SYSTEMS PTY LTD (ACN 696 553 036, ABN 46 696 553 036) is a proprietary company limited by shares, registered in Australia and operating from New South Wales. In these clauses "we" and "us" mean that company. Shield Data Systems is the name it trades under.

Covered

  • Everything this website collects, which is close to nothing and is itemised in drill 04.
  • Correspondence sent to [email protected] and whatever follows from it.
  • Records created by running or scoping the backup verification service.
  • Personal information inside a customer's backup, for as long as a rehearsal is holding it.

Not covered

  • What a customer does with its own systems, its own backups and its own people's information outside a rehearsal.
  • Sites you reach through a link from here. Their handling is theirs.
  • Anything you post about us somewhere else, on a platform running its own policy.

Precondition

Information about a person touches this company in any way.

Procedure

Check it against the two lists above before acting on it.

Outcome

Inside the first list, this policy governs it. Inside the second, somebody else's policy does and we say so rather than implying otherwise.

Record kept

This page, versioned and dated at the head.

03Both rolesThe statute underneath

The governing statute is the Privacy Act 1988 (Cth), and within it the thirteen Australian Privacy Principles in Schedule 1. A reference below to APP 6, or any other number, means the corresponding Principle.

APP 1, which is why this document exists

APP 1 requires open and transparent management of personal information and a policy that is clearly expressed, current and free. Clearly expressed is the part most policies fail. A document nobody finishes reading satisfies the letter and defeats the point, which is the reason for the drill structure: each clause tells you what actually happens, in the order it happens.

Turnover, and why it changes nothing here

Most Australian businesses under three million dollars in annual turnover fall outside the Act. Handling other people's backups is not a business we would want to run on that footing, so the Australian Privacy Principles are applied here as though the exemption were unavailable. A customer can therefore contract with us on Privacy Act terms without first working out our revenue.

Other law in play

  • The Spam Act 2003 (Cth), covering commercial electronic messages. Drill 13.
  • The Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Drill 23.
  • The statutory tort of serious invasion of privacy in Schedule 2 to the Privacy Act. Drill 24.
  • The Corporations Act 2001 (Cth) and tax law, which set how long financial records stay. Drill 18.

Precondition

A question arises about what may be done with personal information here.

Procedure

Apply the Australian Privacy Principles in the ordinary way, without reaching for the small business exemption.

Outcome

One consistent standard, whatever the company's turnover happens to be in a given year.

Record kept

This policy, and the engagement terms that mirror it.

04ControllerWhat we gather for ourselves

Here is the complete inventory of information collected for our own purposes. A category absent from this table is a category we do not collect.

Information collected as controller
CategoryWhere it comes fromWhyHow long
Your email address and whatever you put in the messageYou, by writing to usTo answer the thing you asked about24 months from the last exchange, then destroyed
Name, role and employer where you mention themYou, in the same messageTo understand who is asking and on whose behalf24 months from the last exchange
Scoping notes for a possible engagementThe conversation itselfTo quote accurately and to remember what was discussed24 months, or the life of the engagement plus 7 years if one starts
Engagement records: contacts, notice addresses, schedulesThe customerTo run the service and to know who to warn when a rehearsal failsEngagement plus 7 years, under Corporations Act and tax requirements
Billing details and invoicesThe customer, and our accounting softwareTo bill, to account, and to satisfy the Australian Taxation Office7 years from the end of the financial year concerned
Request logs for this websiteThe hosting provider, automaticallyTo serve pages and turn away abusive trafficUnder 30 days, on the provider's own cycle
Security reportsWhoever sends oneTo fix the fault and to reply to the reporter24 months after the fix ships

Absent from that table

No advertising profile, no behavioural data, no data purchased from a broker, no enrichment of your address against a commercial database, no scoring of you, and no sensitive information as the Act defines it. Nothing about health, race, politics, religion, union membership, sexual orientation or criminal record is sought as controller, and any that arrives unbidden is dealt with under drill 10.

Precondition

You email us, or an engagement begins, or a page is requested.

Procedure

Keep only what the table names, only for the reason beside it, only for the period in the last column.

Outcome

A small, boring holding that can be listed on one screen and checked against on request.

Record kept

The mailbox, the engagement file, the accounting ledger. Nothing else exists to be found.

05ProcessorWhat sits inside a customer's snapshot

The uncomfortable answer belongs at the front. Restoring a customer's backup means holding whatever that backup contains, and until the customer tells us what it contains, we do not know.

A production backup is not a curated extract. It is everything the system held at the moment it was taken: customer records, staff records, addresses, phone numbers, payment references, free-text notes written by people who never expected an outsider to read them, and frequently sensitive information as the Act defines the term. Health records if the customer is a clinic. Enrolment records if it is a school. Case notes if it is a charity.

What that means in practice

  • The customer decides which systems are in scope, and therefore decides what we ever touch.
  • We do not index, catalogue, browse or search a restored copy. Checks run against it; people do not read it.
  • Nothing from inside the restored copy is written into the evidence file, so the deliverable can be handed to an auditor without a redaction exercise first.
  • No content is exported, copied out, retained after teardown, or used for anything other than the checks written into the engagement.
  • No content is used for product development, for benchmarking, or for training or evaluating any model. That commitment is contractual, not aspirational.

Sensitive information

Where a customer's backup carries sensitive information, and most do, it stays inside the isolated environment for the length of the run and dies with it. We seek no consent from the individuals concerned because we have no relationship with them and no basis on which to ask; the customer holds that relationship and that obligation.

Precondition

A customer nominates a backup and a rehearsal falls due.

Procedure

Read the backup with a read-only credential, restore into an environment built for that run, execute the agreed checks, destroy the environment.

Outcome

A pass or a failure with timings attached, and no copy of anybody's records anywhere afterwards.

Record kept

A content-free evidence file naming the systems, the checks, the results, the durations, and confirmation of teardown.

06ProcessorInstruction, and nothing beyond it

As processor we act on the customer's written instruction and we do not improvise. That constraint is what keeps a verification supplier from quietly becoming a second data controller over somebody else's records.

  • Scope, schedule and checks come from the customer in writing, and change the same way.
  • An instruction that looks unlawful gets queried in writing before anything runs, and the run waits.
  • Asked to extract records from a restored copy and send them somewhere, we decline. The engagement produces findings, never exports.
  • Approached by anyone other than the customer about a customer's data, including a person who believes their records are inside it, we take no substantive action and route the approach to the customer.
  • A demand from law enforcement or a regulator is passed to the customer before anything is handed over, unless the law forbids telling them.

Precondition

Anybody asks us to do something with data inside a customer's backup.

Procedure

Check the request against the written instruction. Where it is not covered, stop and ask the customer.

Outcome

The customer keeps control of its own data and its own obligations, and no third party can get at either through us.

Record kept

The instruction, any query we raised, and the customer's answer.

07ProcessorThe second live copy this service creates

The risk this service creates

A restore brings a working copy of a production system into existence. While it stands it can leak precisely as the original could. Run verification carelessly and a dormant risk becomes a recurring one, on a schedule, by appointment. Anybody weighing this service should weigh that first.

The design answers it in four places, and the answers are worth checking against rather than trusting.

  • Duration. The environment exists for one rehearsal. Minutes or hours, not days, and never left standing between runs.
  • Isolation. A fresh network and storage boundary per run, with no route into the customer's network and no route to any other customer. Nothing is shared and nothing persists.
  • Read-only credentials. The credential reads the backup store and can write nowhere. Anything wider is declined at the scoping stage.
  • Unconditional teardown. The environment is destroyed whether the run passed or failed. Leaving a broken run standing for investigation is the obvious temptation and it is prohibited, so investigation happens against logs rather than against a live copy of somebody's production data.

Precondition

A rehearsal is about to create a working copy of a production system.

Procedure

Build the boundary, restore inside it, check inside it, tear it down. Never widen the credential and never extend the environment to make investigation easier.

Outcome

Exposure measured in the length of one run, rather than a standing second copy of the customer's estate.

Record kept

Teardown confirmation in the evidence file for every run, including the failed ones.

08ControllerTelling you at the point of collection

APP 5 requires notice at or around the time information is collected. Since the only route in is an email address, the notice is this page and the sentence beside that address on the contact page.

Write to us and you should take the following as told to you: the recipient is SHIELD DATA SYSTEMS PTY LTD; the purpose is answering your message; nobody is required to answer any particular question; the consequence of writing anonymously is only that a reply may be impossible; access and correction run under drill 20; complaints run under drill 26; nothing is disclosed overseas except as drill 14 sets out.

Precondition

You are about to send something to [email protected].

Procedure

Read the paragraph above. Send only what the question actually needs.

Outcome

Nothing about the handling of your message should come as a surprise afterwards.

Record kept

The message thread, under the retention period in drill 04.

09ControllerDealing with us unnamed

APP 2 gives you the option of not identifying yourself, or of using a pseudonym, wherever that is practicable. Here it usually is.

Read every page without telling us anything, since there is no form, no login and no counting of readers. Ask a question from an address that says nothing about you, and expect a real answer. Report a security fault under any name at all, or none, and the fault still gets fixed and you still get thanked.

Identification becomes unavoidable in two places only. An engagement needs a real counterparty, because a contract with a pseudonym is not a contract. And a request for access to information under drill 20 needs enough proof that we are handing your own record to you rather than to somebody claiming to be you.

Precondition

You would rather not say who you are.

Procedure

Do not say. Nothing on this site asks, and no reply will demand it unless one of the two exceptions applies.

Outcome

A normal exchange in which the only thing we hold is an address you chose to write from.

Record kept

Whatever the message itself contained, and nothing inferred around it.

10Both rolesMaterial nobody asked for

APP 4 covers personal information arriving unsolicited. It happens: an attachment carrying more than the question needed, a CV nobody advertised for, a spreadsheet forwarded to illustrate a point.

The test under APP 4 is whether we could have collected the material lawfully had we asked for it. Where the answer is no, and the information is not in a Commonwealth record and no law requires keeping it, it is destroyed or de-identified as soon as practicable.

Precondition

Something lands in the inbox that nobody requested.

Procedure

Apply the APP 4 test. Where it fails, destroy the material and tell the sender what was destroyed.

Outcome

Nothing accumulates in a mailbox simply because deleting it took effort.

Record kept

A short note of what was destroyed and when. The note holds no copy of the material.

11ControllerThe purposes we may act on

APP 6 confines use and disclosure to the purpose of collection, to a related purpose you would reasonably expect, or to something you have consented to. The purposes here are short enough to list in full.

  • Answering your message and doing whatever it asks.
  • Quoting for, negotiating and running an engagement.
  • Billing, accounting and tax.
  • Fixing a fault you reported, on this site or in the service.
  • Meeting a legal obligation, including a request from a court, a regulator or the Australian Taxation Office.
  • Establishing or defending a legal claim.

Nothing here is sold, rented, licensed, bartered or handed to a data broker. Nothing is used to build a profile of you, and nothing is disclosed for anybody else's marketing.

Precondition

A use is proposed for information collected as controller.

Procedure

Match it against the six purposes above. Absent a match, ask first or do not do it.

Outcome

Uses stay inside the reason the information arrived.

Record kept

Where consent was sought for something outside the list, the request and your answer.

12Both rolesRecipients and sub-processors

Suppliers touch some of this, as they do for every company that does not build its own accounting package. The categories are these, and each is contractually bound to confidentiality and to acting only on our instructions.

  • Email and productivity hosting, which necessarily holds correspondence.
  • Website hosting and content delivery, which handles requests and writes the logs in drill 04.
  • Cloud infrastructure, which supplies the isolated environments where restores run.
  • Accounting and invoicing software, which holds billing records.
  • Professional advisers, where a specific matter requires one.

No advertising network, no analytics vendor, no data broker, no lead-generation product and no marketing platform appears on that list, and none will be added quietly. A sub-processor whose systems would touch customer data is named to affected customers before it starts, with a reasonable window to object.

Precondition

A supplier is proposed whose systems would hold information covered by this policy.

Procedure

Assess it, bind it in writing, name it to affected customers ahead of time, then connect it.

Outcome

No supplier arrives underneath a customer without that customer knowing.

Record kept

The supplier list, its contracts, and the notice sent to customers.

13ControllerMarketing and the Spam Act

APP 7 restricts using personal information for direct marketing. The Spam Act 2003 (Cth) adds its own requirements to commercial electronic messages: consent, accurate sender identification, and a working unsubscribe.

There is no mailing list here, no newsletter, no drip sequence and no automated follow-up. Write to us and you get a reply about the thing you wrote about. Enquire about the service and you may get a follow-up about that enquiry, which stops permanently the moment you say so.

Should a mailing list ever exist, it will be built by people asking to join it. Nobody's address gets moved onto it from correspondence, every message will identify the sender and carry an unsubscribe that works on the first attempt, and unsubscribing will take effect immediately rather than within the five business days the Spam Act permits.

Precondition

A commercial message is contemplated to somebody who wrote to us.

Procedure

Send it only where it answers or follows their own enquiry. Stop on request, without asking for a reason.

Outcome

Writing to a supplier does not cost you your inbox.

Record kept

A suppression note against the address, kept precisely so nothing is ever sent to it again.

14Both rolesOverseas disclosure

APP 8 makes an Australian entity accountable for what an overseas recipient does with personal information it discloses, so a cross-border arrangement is a decision to be stated rather than a footnote.

As controller

Correspondence sits with an email provider whose infrastructure may place data outside Australia, most likely in the United States. Website request logs sit with a content delivery network operating globally by design. Both are ordinary for a company this size, both are contractually bound, and both are disclosed here rather than glossed over.

As processor

Isolated environments for restores are provisioned in Australian regions by default, because a customer's backup should not cross a border merely to be tested. Where a customer wants a different region, it becomes a written term of that engagement rather than a decision we take on their behalf.

Precondition

Information is about to reach infrastructure outside Australia.

Procedure

For correspondence and logs, rely on bound suppliers and disclose the arrangement here. For restores, default to Australian regions and change only on written instruction.

Outcome

Nothing crosses a border by accident, and we stay accountable for what a recipient does under APP 8.

Record kept

Supplier contracts, and the region written into each engagement.

15Both rolesGovernment related identifiers

APP 9 blocks an organisation from adopting a government related identifier as its own, and restricts using or disclosing one. Tax file numbers, Medicare numbers, driver licence numbers, passport numbers and the rest sit under it.

As controller we adopt none, use none and hold none, beyond the ABN of a business customer, which identifies a company rather than a person.

As processor the position needs stating carefully. A customer's backup may well contain identifiers of that kind, because customer systems legitimately hold them. We neither adopt them nor use them: they are data inside a file being restored, checks never key on them, and they are destroyed with the environment. Where a check would need such an identifier as an input, we ask the customer to design the check differently.

Precondition

A government related identifier appears in something we hold or restore.

Procedure

Never adopt it as our own identifier for anybody. Never key a check on it. Let it die with the environment.

Outcome

No cross-system linkage is created through this company that did not exist before.

Record kept

The check definitions in the engagement, which show what each check keys on.

16Both rolesKeeping the record accurate

APP 10 requires personal information to be accurate, up to date and complete, judged against the use being made of it.

As controller, most of what we hold is whatever you wrote, and the best correction mechanism is that you tell us. Drill 20 covers the route.

As processor, accuracy inside a customer's backup belongs to the customer. Correcting a record inside a restored copy would be pointless as well as improper: the environment is destroyed at the end of the run, and the authoritative record lives in the customer's production system. Requests to correct something inside a customer's data are routed to that customer.

Precondition

Something recorded about a person turns out to be wrong.

Procedure

Ours to fix: correct it. The customer's to fix: route the request and tell you it has been routed.

Outcome

Corrections land where the authoritative copy actually lives.

Record kept

The corrected record, or the routing note naming the organisation the request went to.

17Both rolesSecurity

APP 11 requires reasonable steps against misuse, interference, loss, unauthorised access, modification and disclosure. Reasonable is measured against the sensitivity of the material, and a company handling other people's backups is at the sharp end of that measurement.

  • Credentials to a customer's backup store read and cannot write, are scoped to that store, are held in a secrets manager, and are rotated on the customer's schedule or ours, whichever is shorter.
  • Access to those credentials and to running environments is limited to people who need it for the run in front of them, with multi-factor authentication throughout.
  • Environments are per rehearsal and per customer, network-isolated, and destroyed at the end of the run without exception.
  • Data in transit is encrypted. Data at rest inside an environment is encrypted with keys that do not outlive the environment.
  • Correspondence and business records sit behind multi-factor authentication on managed devices.
  • Operational logs record which environment ran, when, and under whose account, and carry no content from any restored copy.

No arrangement of controls makes a company unbreachable, and any supplier telling you otherwise is selling something. What follows a breach is set out in drill 23.

Precondition

Any information covered by this policy is being held or moved.

Procedure

Apply the six controls above. Where a control cannot be applied to a piece of work, the work does not proceed.

Outcome

Exposure bounded by the length of a run and the width of a read-only credential.

Record kept

Content-free operational logs, plus the teardown confirmation inside each evidence file.

18Both rolesRetention

APP 11.2 requires destruction or de-identification once information is no longer needed for any permitted purpose and no law requires keeping it. Retention periods are therefore stated as periods, not as intentions.

  • Correspondence: 24 months from the last message in the thread.
  • Scoping notes where no engagement followed: 24 months.
  • Engagement records: the engagement plus 7 years, which is what the Corporations Act and tax law require.
  • Invoices and financial records: 7 years from the end of the relevant financial year.
  • Evidence files: the engagement plus 12 months, so a period report can be reconciled against the runs behind it.
  • Operational logs: 12 months.
  • Website request logs: under 30 days, held by the provider on its own cycle.
  • Restored copies of customer data: the length of one rehearsal. There is no retention period, because there is no retention.

Precondition

A retention period runs out on something.

Procedure

Destroy it or de-identify it, unless a law or a live legal claim requires holding it longer.

Outcome

The holding shrinks on a clock rather than growing by default.

Record kept

A note that destruction occurred, holding no copy of what was destroyed.

19Both rolesReturn and deletion of data at exit

Ending an engagement should not require an argument about what happens next, so the exit procedure is fixed in advance and the same for everyone.

  1. Every outstanding evidence file is delivered, in the open format it was written in.
  2. Credentials to the customer's backup store are revoked on our side, and the customer is told to revoke them at theirs.
  3. Any environment still standing is destroyed. Typically none is, since teardown follows each run.
  4. Copies of evidence files are retained for 12 months and then destroyed, unless the customer asks in writing for them to go sooner.
  5. Engagement and financial records stay for the statutory periods in drill 18. Deletion of data cannot override a law requiring its retention, and pretending otherwise would be a promise nobody could keep.
  6. Written confirmation of steps one to four is issued within 10 business days of the engagement ending.

Individuals who are not customers have a shorter route: ask us to delete your correspondence and it goes, along with any scoping notes attached to it, inside 30 days.

Precondition

An engagement ends, or somebody asks us to delete your data where "your" means their own correspondence.

Procedure

Run steps one to six above. For an individual request, locate the thread, destroy it, and confirm.

Outcome

Nothing of the customer's is held hostage, and nothing lingers for want of a process.

Record kept

The written confirmation, plus the statutory records that law requires us to keep.

20Both rolesAccess and correction

APP 12 gives you access to personal information an organisation holds about you. APP 13 obliges it to correct information that is wrong, out of date, incomplete, irrelevant or misleading. Both run through one address.

Where we are the controller

Send "Privacy request" in the subject line to [email protected], from the address the information is likely filed under, saying whether you want access, correction, or deletion of data. A response follows within 30 days. Verifying you are who you say happens inside that window rather than extending it. Access is free; there is no charge for making the request and none for the answer.

Refusal is possible on the grounds APP 12 sets out, such as a request that would unreasonably affect somebody else's privacy. A refusal arrives in writing, names the ground it rests on, and tells you how to complain. Where we decline to correct something, you may ask for a statement of your view to be attached to the record, and it will be.

Where we are the processor

Information inside a customer's backup is the customer's to answer for, and giving you access to it would mean disclosing a customer's data to somebody the customer never authorised. So we identify the customer, pass your request to it within 5 business days, tell you we have done so, and help that customer answer.

Precondition

You want to see, fix or remove information about yourself.

Procedure

Email the address above with "Privacy request" in the subject. Say which of the three you want and give enough detail to find the record.

Outcome

Ours: an answer inside 30 days, free. The customer's: routed inside 5 business days, with confirmation to you.

Record kept

The request, the response, and any refusal with its stated ground.

21Both rolesChildren and young people

This is a business-to-business service. Nothing here is aimed at a child, nothing is marketed to one, and we do not knowingly gather information about children as controller. A child writing to us would be treated exactly as anybody else writing to us, which means an email address and a message and nothing further.

As processor the honest position is different, and it matters. A customer running a school, a paediatric clinic, a sports club or a children's charity holds records about children, and its backups contain those records. Restoring such a backup means holding a child's information for the length of the run.

Nothing about that is treated as ordinary. Checks never single out records concerning children, no such record is read by a person, none is written into an evidence file, and all of it is destroyed with the environment. Where a customer's scope covers systems holding children's data, the isolation and teardown obligations in drill 07 are the ones doing the work, and a customer in that position should read drill 07 before signing anything.

Precondition

A backup in scope holds records about children, which many customer systems do.

Procedure

Run the ordinary drill: isolated environment, checks that return counts rather than records, unconditional teardown.

Outcome

A child's record is never read, never exported, and never outlives the rehearsal.

Record kept

The content-free evidence file, identical in form to every other run.

22Both rolesDecisions taken by machine

No decision affecting a person is made automatically here. There is no scoring, no profiling, no eligibility engine and no model deciding anything about anybody.

Automation exists, and it is the boring kind: a scheduler starts a rehearsal, checks return pass or fail, a notice goes out when a run fails. Those are decisions about a backup, not about a person, and a failed check says something about a restore rather than about anyone in the data.

Precondition

Software here reaches a conclusion.

Procedure

Confirm the conclusion is about a restore. Conclusions about people are made by people, in writing.

Outcome

Nobody is ranked, rated or refused anything by a process running here.

Record kept

The check results in the evidence file, which describe a backup and nothing else.

23Both rolesBreaches and the notification scheme

Part IIIC of the Privacy Act creates the Notifiable Data Breaches scheme. An eligible data breach is unauthorised access to, unauthorised disclosure of, or loss of personal information that a reasonable person would conclude is likely to cause serious harm. It obliges notice to the Office of the Australian Information Commissioner and to the individuals at risk.

Where the breach is ours

Suspicion starts a 30-day assessment under section 26WH, and in practice that assessment starts the same day. Where the test is met, the OAIC is notified as soon as practicable with a statement under section 26WK, and affected individuals are told directly what happened, what information was involved, and what they can do about it. Where the test is not met, the reasoning is written down anyway, so the decision can be reviewed rather than remembered.

Where the breach touches a customer's data

The customer is notified without delay, at the addresses in the engagement and by telephone where one is on file, and never later than 24 hours after we become aware. The customer is the entity that decides on and makes any notification about its own data; our job is to give it everything it needs to make that decision fast, including what we know, when we knew it, and what has been done to contain it. We do not sit on it while forming a view.

Precondition

Anybody here suspects unauthorised access, unauthorised disclosure or loss of personal information.

Procedure

Contain it, assess it, tell the affected customer within 24 hours, and notify the OAIC and affected individuals where the serious harm test is met.

Outcome

Customers hear from us before they hear from anybody else, and nobody at risk is left uninformed.

Record kept

The assessment, its reasoning either way, the notifications sent, and the remediation that followed.

24Both rolesThe statutory tort

Schedule 2 to the Privacy Act creates a statutory tort of serious invasion of privacy, actionable by an individual for intrusion upon seclusion or misuse of information, where the invasion was serious and intentional or reckless.

Naming it here is deliberate. A company that restores other people's production systems on a schedule is exactly the sort of company that could commit one, and a reader ought to know the remedy exists without being told about it by a lawyer. The controls in drills 05, 07 and 17 exist to keep that possibility remote, and they are written to be checked rather than admired.

Precondition

A person believes their privacy has been seriously invaded by something done here.

Procedure

The statutory tort is available to them directly, alongside a complaint under drill 26. Neither route requires our cooperation.

Outcome

A remedy exists that does not depend on this company agreeing that something went wrong.

Record kept

Whatever a court requires. On our side, the operational logs and evidence files described above.

25ControllerStorage in your browser

Nothing on this site counts you, profiles you or recognises you. A security cookie may arrive from the provider that serves the files, and two font files are fetched from Google. Both are described in full, with names and lifetimes, in the cookies and storage notice.

Request logs are covered in drill 04 rather than in that notice, because a log is not storage on your device even though it is still personal information.

Precondition

A page here loads in your browser.

Procedure

Read the separate notice, then verify it in your browser's developer tools.

Outcome

At most two strictly necessary entries, neither of which identifies you to us.

Record kept

The request log described in drill 04, held under 30 days.

26Both rolesComplaints and the OAIC

Complain to us first, because it is faster and because the regulator will want to see that you did.

Put "Privacy complaint" in the subject line to [email protected], describe what happened and say what would resolve it. It is logged inside 5 business days and answered inside 30, and the answer says what was found and what was done rather than thanking you for the feedback.

Taking it further

Unsatisfied, take it to the Office of the Australian Information Commissioner:

Telephone

1300 363 992

Post

GPO Box 5218, Sydney NSW 2001

Lodging a complaint there costs nothing, needs no solicitor and needs no agreement from us. Complaints generally reach the Commissioner after the organisation has had a month with them, which is the practical reason for writing to us first even where you expect little from it. Where your complaint concerns data inside a customer's system, that customer is the respondent and we will tell you who it is.

Precondition

Something was handled badly and you want it addressed.

Procedure

Write to us with "Privacy complaint" in the subject. Escalate to the OAIC if the answer does not satisfy you.

Outcome

A finding inside 30 days from us, and an independent route that does not depend on us at all.

Record kept

The complaint, the finding, the remedy, and any change made as a result.

27Both rolesReading this outside Australia

The company is Australian and this policy is written to Australian law. Reading from elsewhere does not change which law governs us, and claiming to comply with every regime on earth would be a claim nobody could stand behind.

In practice several things the General Data Protection Regulation requires are already how this works: purposes stated rather than implied, retention expressed as periods, access and correction available free, breach notification on a clock. Where you hold rights under your own law that go further than the Australian Privacy Principles, write to us and we will do what we reasonably can, and say plainly where an obligation is not one we carry.

Precondition

You are outside Australia and your own law gives you rights.

Procedure

Write to [email protected] naming the right you are exercising.

Outcome

The request is met where it reasonably can be, and declined in writing with reasons where it cannot.

Record kept

The request and the answer, under the correspondence retention period in drill 18.

28Both rolesAmending this policy

The document changes when the company does, and the version and effective date at the head of the page are how you tell. A change that materially affects how personal information is handled is emailed to current customers 30 days before it takes effect.

Superseded versions are retained without being published as separate pages. Ask what a clause said on a given date and you will be sent that wording.

Precondition

Something in how information is handled here is about to change.

Procedure

Amend the affected drill, raise the version, stamp the date, notify customers where the change is material, then make the change.

Outcome

The policy never describes a past version of the company.

Record kept

Every superseded version, available on request.

29Both rolesReaching a person

Privacy questions, access requests, corrections, deletion of data and complaints all go to [email protected]. It is the only route in, it is read by a person, and the contact page lists the subject lines that get a message to the right place fastest.

Legal name

SHIELD DATA SYSTEMS PTY LTD

ACN

696 553 036

ABN

46 696 553 036

Jurisdiction

New South Wales, Australia

Formal service

The registered office ASIC currently records for ACN 696 553 036

Precondition

You have a privacy matter of any kind.

Procedure

Email the address above with a subject line from the contact page.

Outcome

General questions inside 5 business days, statutory requests inside 30.

Record kept

The thread, under the retention period in drill 18, and then destroyed.