1. Our Commitment to Privacy
This Privacy Policy sets out how the Diamond Certification Laboratory of Australia (DCLA) manages Personal Information. It explains how DCLA collects, uses, discloses, stores, and protects Personal Information, and how individuals may access and correct Personal Information held by DCLA.
This Policy has been prepared having regard to DCLA’s obligations under the Privacy Act 1988 (Cth) and the National Privacy Principles (NPPs). This Policy is a public document and is published in accordance with National Privacy Principle 5 (Openness).
2. Collection of Personal Information
2.1 General Collection Principles
DCLA will only collect Personal Information where it is necessary for DCLA to perform one or more of its functions or activities.
For the purposes of this Policy, collect means to gather, acquire, or obtain information by any means in circumstances where an individual is identifiable or reasonably identifiable.
2.2 Purposes of Collection
DCLA collects Personal Information primarily to provide services to users and clients. DCLA may also collect and use Personal Information for secondary purposes, including:
Account management
Business planning and product development
Providing information about DCLA services and affiliated organisations
Enhancing user experience by displaying retailers or services aligned with user preferences, based on prior website activity
2.3 Sensitive Information
DCLA will not collect Sensitive Information unless:
The individual has provided consent; and
The information is necessary for DCLA to perform a specific activity or function.
2.4 Fair and Lawful Collection
DCLA will not collect Personal Information secretly or in an underhanded manner.
DCLA will take reasonable steps to ensure individuals are informed of:
The purpose of collection; and
Any secondary uses or disclosures that may occur.
3. Use of Personal Information
3.1 Primary Use
DCLA uses Personal Information primarily for the purposes outlined in Section 2.2.
3.2 Secondary Use
DCLA will obtain an individual’s consent before using Personal Information for secondary purposes unless:
The secondary purpose is directly related to the primary purpose; and
The use falls within the individual’s reasonable expectations.
3.3 Direct Marketing
Where DCLA relies on a Direct Marketing exception, it will ensure that:
Individuals are clearly informed of their right to opt out
Only one initial use occurs before an opt-out is offered
Opt-out requests are honoured across all DCLA Related Bodies Corporate
Opt-out rights are provided in all future communications
DCLA does not use Sensitive Information for Direct Marketing.
3.5 Data Accuracy
DCLA will not use Personal Information without taking reasonable steps to ensure it is accurate, complete, and up to date.
4. Disclosure of Personal Information
4.1 Disclosure with Consent
DCLA may disclose Personal Information to related or unrelated third parties where consent has been obtained, including disclosures under credit reporting obligations.
4.2 Related Bodies Corporate
DCLA may disclose Personal Information to Related Bodies Corporate. Any such disclosure remains subject to the original Primary Purpose of collection.
4.3 Outsourced Services
DCLA may disclose Personal Information to third parties to support outsourced services such as:
Billing
Customer relationship management
Order fulfilment
Such disclosure will only occur where:
It is for a related Secondary Purpose; and
It falls within reasonable expectations.
4.4 Contractual Safeguards
DCLA will take reasonable steps to ensure contracts with third parties require compliance with the Privacy Act and this Policy.
4.5 Legal Disclosure
DCLA may disclose Personal Information where required or permitted by law, including disclosures to:
Courts
Law enforcement agencies
Government bodies
Professional advisers
4.6 Emergency Disclosure
Personal Information may be disclosed to prevent an imminent threat to life or public safety.
4.7 No Unauthorised Disclosure
If a disclosure is not for a Primary Purpose, a related Secondary Purpose, or covered by legal exceptions, DCLA will not disclose Personal Information.
4.8 Customer Lists
DCLA does not sell or commercially share customer lists. If this were to occur, it would only be with explicit consent, and any third-party use would be contractually limited to that consent.
5. Information Quality
5.1 Accuracy Review
DCLA regularly reviews its data collection and storage practices to improve accuracy and reliability.
5.2 Retention & De-Identification
Personal Information will be destroyed or de-identified as soon as practicable and no later than seven (7) years after the last customer interaction, unless required by law
6. Information Security
6.1 Staff Obligations
All DCLA employees and contractors must handle Personal Information in accordance with this Policy and applicable law.
6.2 Secure Storage
DCLA takes reasonable steps to ensure Personal Information is stored securely and accessible only to personnel with a legitimate need and right to know.
6.3 Ongoing Review
Information security practices are reviewed regularly to ensure ongoing compliance and effectiveness.
7. Access and Correction
7.1 Access Rights
Individuals may request access to Personal Information held by DCLA in accordance with the Privacy Act.
7.2 Correction Rights
DCLA will correct Personal Information promptly upon request where information is inaccurate, incomplete, or outdated.
7.3 Requests
Requests for access or correction should be directed to DCLA Customer Service using the contact details provided on the DCLA website.
7.4 Fees
DCLA may charge a reasonable fee for access requests, but generally only where requests are complex or resource-intensive.
8. Openness & Complaints
DCLA Customer Service is the first point of contact for:
– Privacy enquiries
– Complaints
– Requests relating to this Policy
This Privacy Policy is published on the DCLA website and available upon request.
9. Anonymous Transactions
Where lawful and practicable, individuals may interact with DCLA anonymously. Personal Information will only be required where necessary to provide a service or respond to an enquiry.
10. Glossary
Personal Information – Information or an opinion about an identifiable individual.
Sensitive Information – Includes racial origin, beliefs, health information, criminal record, and similar protected data.
Primary Purpose – The main reason information is collected.
Secondary Purpose – A related use within reasonable expectations.
Direct Marketing – Marketing communications by any means.
Opt Out – A request to cease marketing communications.
Related Body Corporate – As defined under the Corporations Act 2001 (Cth).
Use – Handling Personal Information within DCLA.
Disclosure – Release of information outside DCLA.
