Privacy and Consent

Privacy
Data Protection
User Consent
Internal policy on how Tessera collects, notifies, uses, secures and handles personal information under the Australian Privacy Principles, and the relationship to the external Privacy Policy and the NDB scheme.
Title Privacy and Consent
Doc# POL-DATA-023
Version 1.0
Date 04-03-2025
Owner Chief Information Security Officer (I. Ferreira)
Approved By Head of Compliance (M. Dubois)
ISO/IEC 27001:2022 A.5.34 — Privacy and protection of personal information

1. Purpose and scope

This internal policy sets out how Tessera collects, uses, discloses, secures and disposes of personal information about individuals, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It applies to all Tessera workforce members, contractors and subprocessors who handle personal information in the course of providing or supporting the Services. It is the internal counterpart to Tessera’s external Privacy Policy (POL-DATA-022), which is what we publish to customers and the public.

2. Collection and notification (APP 3 and APP 5)

  1. We collect personal information only where it is reasonably necessary for, or directly related to, our functions and activities — primarily to provide the Services to business customers, to administer accounts, and to run the business (APP 3).

  2. Sensitive information within the meaning of APP 3.3 is collected only with consent, or where another exception in APP 3.4 applies. The Services are not configured to require sensitive information about individuals, and workforce members must not collect it without a clear basis.

  3. At or before the time we collect personal information, we take reasonable steps to ensure the individual is aware of the matters set out in APP 5 — who we are, how to contact us, the purposes of collection, the usual disclosures, and that the external Privacy Policy (POL-DATA-022) explains how to access and correct information. For platform end-users this notice is delivered through the collection-notice template held in the Customer Onboarding pack.

3. Use and disclosure (APP 6)

Personal information is used and disclosed only for the purpose for which it was collected, or a directly related purpose, unless the individual consents or we are required or authorised to use or disclose it otherwise (APP 6). Workforce members handle personal information on a need-to-know basis, and tenant data held by Tessera as a processor is used solely to provide the Services to that tenant and never for Tessera’s own purposes.

5. Security of personal information (APP 11)

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure (APP 11), through the controls described in the Acceptable Use Policy (POL-SEC-022), the Data Protection Policy, and the information security management system aligned to ISO/IEC 27001:2022. Personal information is retained only as long as needed (APP 11.2), in line with the Data Lifecycle and Classification Policy.

6. Data breaches and the NDB scheme

A suspected or actual data breach involving personal information is handled under the NDB Playbook (SOP-PRIV-001), which is the authoritative procedure for assessment and notification to the Office of the Australian Information Commissioner (OAIC) under Part IIIC of the Act. The Playbook supersedes the legacy notification framing in POL-COMP-006. Workforce members who become aware of a suspected breach must report it immediately to security@tessera.locoensayo.org.

7. Where the published notices live

  • External Privacy Policy (POL-DATA-022): https://tessera.locoensayo.org/privacy
  • Platform Terms of Use: https://tessera.locoensayo.org/terms
  • Collection notices for platform end-users are presented in-product at the point of collection, using the template held in the Customer Onboarding pack.

8. Review

This policy is reviewed at least annually and after any material change to the Services, the law, or the OAIC’s guidance. The next scheduled review is 04-03-2026. Questions go to privacy@tessera.locoensayo.org.