Find Your Collection Date
Privacy Policy

Privacy Policy 3.0

3.1 Purpose and structure of this policy

Hunter Resource Recovery (HRR) is committed to protecting the privacy of the personal information it holds. We are bound by the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth).

This policy is in two parts, because it serves two audiences:

  • Part A – Your privacy. Written for members of the public, residents, customers, contractors and job applicants. It explains what personal information we collect about you, why we collect it, who we share it with, and how you can access it, correct it or complain.
  • Part B – Staff handling requirements. Written for HRR employees and members of the Board of Directors. It sets out what staff must do when handling personal information belonging to anyone else.

If you are a member of the public, Part A is the part that applies to you.

PART A – YOUR PRIVACY

For residents, customers, contractors, consultants, job applicants and event participants

3.2 Who we are

Hunter Resource Recovery is a not-for-profit organisation that delivers waste and recycling education and services across the Cessnock, Lake Macquarie, Maitland and Singleton local government areas. We can be contacted using the details in section 3.12.

3.3 What personal information we collect 

The kinds of personal information we collect and hold include:

  • Your name, postal address, email address and telephone number.
  • Information about your waste and recycling service, including your service address and service history.
  • Enquiries, complaints and feedback you make to us, and our responses.
  • Records of your participation in our education programs, school visits, community events, competitions and surveys.
  • Images captured by security cameras at our premises.
  • Photographs and video taken at community events, where you have agreed to it.
  • For employees, contractors, consultants and job applicants: employment records, qualifications, referee information, financial information and payroll details.

We do not generally collect sensitive information. Where we do — for example health information relevant to a workplace matter — we collect it only with consent or where the law requires or permits it, and we apply higher security standards to it.

3.4 How we collect personal information 

Wherever it is reasonable and practicable, we collect personal information directly from you. We may collect it:

  • In person, by telephone, by email or by post.
  • Through forms on our website, and through online entry forms, surveys and competitions.
  • At community events, school visits and other education activities.
  • From your local council, where we deliver a service or an education program on its behalf.
  • From our contractors, in the course of them performing services for us.
  • Automatically, through security cameras located in the front office, the garage, and at the front and rear of our building.

You are not obliged to give us your personal information. However, if you do not provide it, we may not be able to provide the service, respond to your enquiry, or complete the transaction.

3.5 Why we collect, hold, use and disclose personal information 

We collect, hold, use and disclose personal information for the following purposes:

  • To deliver waste and recycling services and education programs, including on behalf of local councils under contract.
  • To respond to your enquiry, complaint or feedback.
  • To run community education programs, events, school and preschool programs, competitions and surveys.
  • To send you recycling information and updates, where you have asked to receive them.
  • To supply products or services, process payment and collect debts.
  • To meet our obligations under a contract, including domestic garbage contracts with local authorities.
  • To perform payroll and personnel functions.
  • To keep our premises, staff and visitors safe.
  • To meet our legal, regulatory and insurance obligations.

3.6 Who we disclose personal information to  

We may disclose your personal information to:

  • Your local council, where it relates to a service or program we deliver on its behalf.
  • Our contractors and service providers, including waste collection contractors, IT and data storage providers, and email, survey and event platforms.
  • Our insurers.
  • Any person or body where disclosure is required or authorised by law.

We do not sell, rent or trade your personal information, and we do not disclose it to any third party for that party’s own marketing purposes.

3.7 Overseas disclosure 

We do not send personal information to overseas recipients for those recipients’ own purposes.

Some of the technology services we use — including email, file storage, website hosting and online forms — are supplied by companies that may store or process data outside Australia, including in the United States. Providers and their storage locations vary and change over time, so it is not practicable to specify every country in this policy.

If you would like to know where the information we hold about you is stored, please contact us using the details in section 3.12 and we will tell you.

Before we adopt a new service that would involve personal information being held or processed overseas — for example an email marketing platform — we take reasonable steps to satisfy ourselves that the provider handles that information in a way consistent with the Australian Privacy Principles.

3.8 Direct marketing and how to opt out 

We will only send you recycling information, newsletters or event updates if you have asked to receive them. Consent to receive this material is always optional and is never a condition of entering a competition, attending an event or receiving a service.

You can opt out at any time using the unsubscribe link in any email we send, or by emailing [email protected]. We will action your request promptly and at no cost to you.

3.9 How we keep personal information secure

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. This includes appropriate measures to protect both electronic data and hard copy records, and controls on who within HRR can access what.

We are committed to ensuring that the personal information we hold remains accurate, complete and up to date. Records that are no longer required are securely destroyed or de-identified in accordance with our record-keeping obligations.

Where we contract out data storage or processing, we take steps to protect the information, including satisfying ourselves that the contracted organisation has an appropriate privacy policy and has signed a privacy undertaking.

3.10 Accessing and correcting your personal information

You can ask us at any time for access to the personal information we hold about you, and you can ask us to correct it if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading. This right applies to anyone whose information we hold — not only to our employees.

To make a request, contact the Privacy Officer using the details in section 3.12. We will need to verify your identity before releasing any information. We will respond within 30 days, and there is no charge for making a request. If we refuse access or refuse to make a correction, we will tell you why in writing and explain how you can complain.

3.10 Making a privacy complaint

If you believe we have mishandled your personal information or breached the Australian Privacy Principles, please contact our Privacy Officer using the details in section 3.12. We will acknowledge your complaint within five business days and respond within 30 days.

If you are not satisfied with our response, you can refer your complaint to the Office of the Australian Information Commissioner at oaic.gov.au, or by telephone on 1300 363 992.

3.12 How to contact us

Privacy Officer Chief Executive Officer, Hunter Resource Recovery
Post 43–47 Bulwer Street, Maitland NSW 2320
Email [email protected]
Telephone +61 2 4934 4674

 

PART B – STAFF HANDLING REQUIREMENTS

For HRR employees and members of the Board of Directors

3.13 Scope

Part B applies to all HRR employees and members of the Board of Directors in their handling of personal information relating to residents, customers, contractors, consultants, employees and job applicants. It sits alongside Part A: Part A is what we promise individuals, and Part B is how staff deliver on it. 

3.14 Collecting personal information

Collect personal information directly from the individual wherever it is reasonable and practicable to do so.

  • Collect only what is reasonably necessary for the task at hand. Do not collect extra fields because they might be useful later.
  • At or before the point of collection, tell the individual who we are, why we are collecting it, who we may disclose it to, and how they can access it or complain. A short written collection notice on the form satisfies this.
  • Where consent is required — including consent to marketing, or to photographing a child — obtain it separately and record it. Consent must never be bundled into an unrelated agreement or made a condition of service.

3.15 CCTV and photographic images

Security cameras operate in the front office, the garage, and at the front and rear of the building for security and monitoring purposes.

  • Footage is accessed only for a security, safety or investigation purpose, and only by staff authorised by the Privacy Officer. Do not view or share footage for any other reason.
  • Photographs and video taken at community events may only be used publicly where the individual has agreed. Where a child is identifiable, written consent from a parent or guardian is required before any public use.

3.16 Use, disclosure and contractors

Use personal information only for the purpose it was collected for, or a directly related purpose the individual would reasonably expect.

  • Disclose to a contractor only what that contractor needs to perform their function.
  • Before engaging a contractor who will handle personal information, confirm they have an appropriate privacy policy and have signed a privacy undertaking.
  • Where a supplier stores or processes data outside Australia, notify the Privacy Officer so that section 3.7 stays accurate.

3.17 Data quality, storage and destruction

Take reasonable steps to keep personal information accurate, complete and up to date.

  • Store electronic records in approved systems only. Do not hold personal information in personal email accounts, on personal devices, or in unmanaged spreadsheets.
  • Keep hard copy records secure and out of public view.
  • Securely destroy or de-identify records that are no longer required, in accordance with our record-keeping obligations.

3.18 Sensitive information

Sensitive information — including health information, racial or ethnic background, and criminal record — may only be collected with consent or where the law requires or permits it. Higher standards of storage, access control and destruction apply. If in doubt, ask the Privacy Officer before collecting it.

3.19 Responding to access and correction requests

Any individual may request access to their own personal information, or ask for it to be corrected. This is not limited to employees.

  • Refer all requests to the Privacy Officer. Do not release personal information directly.
  • Verify the requester’s identity before any information is released, and release information only to the person it concerns.
  • The Privacy Officer will respond within 30 days. There is no charge for making a request. Any refusal must be given in writing with reasons and information about how to complain.

3.20 Handling a privacy complaint

  • Refer every privacy complaint to the Privacy Officer immediately. Do not attempt to resolve it yourself.
  • The Privacy Officer acknowledges within five business days and responds within 30 days.
  • Record the complaint, the investigation and the outcome.
  • Advise the complainant that they may refer the matter to the Office of the Australian Information Commissioner if they are not satisfied.

3.21 Suspected data breach 

Any staff member who becomes aware of a suspected or actual data breach must notify the Privacy Officer immediately and must not attempt to resolve it alone. This includes a lost or stolen device, an email containing personal information sent to the wrong recipient, a lost hard copy file, or any unauthorised access to our systems.

The Privacy Officer will assess whether the breach is likely to result in serious harm and, if so, will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).

3.22 Training and awareness

All staff are briefed on this policy at induction and whenever it is materially updated. Staff who handle personal information regularly — including those running events, competitions, school programs and email communications — should re-read Part B before each campaign.

3.23 References

  • Privacy Act 1988 (Cth), including the Australian Privacy Principles and the Notifiable Data Breaches scheme.
  • Office of the Australian Information Commissioner — Australian Privacy Principles guidelines, oaic.gov.au.
  • HRR Policy 1.0 — Code of Conduct.
  • HRR Policy 2.0 — Business Ethics.
  • HRR Policy 8.0 — Employment Policy Statement.

3.24 Review

This policy is reviewed every two years, or sooner in the event of a change in legislation, a change to HRR’s policies, or a change to the systems or suppliers we use to hold personal information.

3.25 Status and Details

Status Ver 3.0
Effective Date August 2026
Review Date August 2028
Approval Authority    Chief Executive Officer
Approval Date August 2026
Enquiries Chief Executive Officer · [email protected] · +61 2 4934 4674