Protecting Your Privacy and Personal Information
Noonan Real Estate Agents is committed to protecting the privacy, confidentiality and security of the personal information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, store and protect personal information when providing our real estate services and conducting our business. It also outlines your privacy rights and our commitment to complying with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and other applicable Australian privacy laws.
Whether you are a vendor, purchaser, landlord, tenant, applicant, contractor or visitor to our website, we are committed to handling your personal information responsibly, transparently and securely.
SECTION 1
Introduction, Commitment, Scope & Definitions
1. Our Commitment to Privacy
At Noonan Real Estate Agents Pty Ltd ("Noonan", "we", "our" or "us"), we recognise that protecting the privacy and personal information of our clients, landlords, tenants, vendors, purchasers, employees, contractors and business partners is fundamental to the way we conduct business.
We are committed to handling personal information lawfully, fairly, transparently and securely. We recognise that individuals entrust us with their personal information when buying, selling, leasing, renting or managing property, and we treat that responsibility seriously.
We continually review our systems, procedures and technologies to ensure our privacy practices remain consistent with Australian privacy laws, industry best practice and our commitment to providing professional real estate services.
2. About Noonan Real Estate Agents
Noonan Real Estate Agents Pty Ltd is a licensed real estate agency providing professional services including, but not limited to:
Residential property sales
Commercial sales and leasing
Residential property management
Commercial property management
Property leasing
Auctions
Property appraisals
Buyer enquiries
Landlord services
Tenant services
Maintenance coordination
Trust account administration
Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) compliance
Recruitment and employment activities
General business administration
To deliver these services, we collect, hold, use and disclose personal information in accordance with this Privacy Policy.
3. Legislative Framework
This Privacy Policy has been developed in accordance with:
Privacy Act 1988 (Cth)
Australian Privacy Principles (APPs)
Notifiable Data Breaches Scheme
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
AML/CTF Rules
Spam Act 2003 (Cth)
Do Not Call Register Act 2006 (Cth)
Electronic Transactions Act 1999 (Cth)
Any other applicable Commonwealth or State legislation relating to privacy, real estate services or information management.
Where legislation changes, we will review and update this Privacy Policy as required.
4. Scope of this Policy
This Privacy Policy explains how we collect, use, disclose, store, protect and otherwise manage personal information.
It applies to personal information collected through:
our offices
our website
online enquiry forms
rental applications
sales enquiries
open homes
auctions
inspections
telephone conversations
emails
SMS messages
social media platforms
electronic identity verification services
customer relationship management systems (CRM)
third-party referral sources
publicly available information
government agencies
business partners
any other lawful means.
This Privacy Policy applies to all individuals whose personal information we collect, regardless of whether they ultimately become a client.
5. Who this Policy Applies To
This Privacy Policy applies to:
Vendors
Purchasers
Landlords
Tenants
Rental Applicants
Auction Bidders
Prospective Buyers
Prospective Tenants
Guarantors
Occupants
Company Directors
Trustees
Beneficial Owners
Attorneys
Authorised Representatives
Contractors
Tradespeople
Suppliers
Consultants
Strata Managers
Body Corporate Representatives
Mortgage Brokers
Conveyancers
Solicitors
Valuers
Building Inspectors
Insurance Providers
Job Applicants
Employees (except where the employee records exemption applies)
Visitors to our offices
Visitors to our website
Users of our online services
Any individual who communicates with us.
6. Our Privacy Principles
Noonan is committed to:
collecting only the personal information reasonably necessary to conduct our business and comply with our legal obligations;
being transparent about how personal information is handled;
collecting personal information by lawful and fair means;
using personal information only for legitimate business or legal purposes;
maintaining accurate, complete and up-to-date information where reasonably practicable;
protecting personal information against misuse, interference, loss, unauthorised access, modification and disclosure;
providing individuals with access to their personal information where required by law;
correcting inaccurate or outdated personal information when requested;
securely destroying or de-identifying personal information when it is no longer required and legal retention obligations have expired; and
continually reviewing and improving our privacy practices.
7. Definitions
For the purposes of this Privacy Policy:
Australian Privacy Principles (APPs) means the Australian Privacy Principles contained in Schedule 1 of the Privacy Act 1988 (Cth).
Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in material form or not.
Sensitive Information includes information such as health information, racial or ethnic origin, religious beliefs, political opinions, trade union membership, sexual orientation, criminal history, biometric information and any other information defined as sensitive information under the Privacy Act.
Processing includes collecting, recording, storing, organising, accessing, using, analysing, verifying, disclosing, transmitting, retaining, archiving, de-identifying and destroying personal information.
Disclosure means making personal information available to another person or organisation outside Noonan Real Estate Agents.
Identity Verification means any process undertaken to verify an individual’s identity, including electronic identity verification, document verification and AML/CTF customer due diligence.
AML/CTF means Anti-Money Laundering and Counter-Terrorism Financing obligations under Australian legislation.
Privacy Officer means the person appointed by Noonan Real Estate Agents to oversee privacy compliance, respond to privacy enquiries and manage privacy complaints.
Business Day means a day other than a Saturday, Sunday or public holiday in New South Wales.
8. Changes to this Privacy Policy
We may amend this Privacy Policy from time to time to reflect changes in legislation, regulatory guidance, technology, our business practices or the services we provide.
The most current version of this Privacy Policy will always be available on our website.
Where significant changes are made, we will take reasonable steps to notify individuals where appropriate.
9. What Personal Information We Collect
The type of personal information we collect depends on the nature of your relationship with us, the services you request, and our legal and regulatory obligations.
We only collect personal information that is reasonably necessary for our business activities, to provide our services, comply with our legal obligations, protect our legitimate business interests, or where you have otherwise consented.
The information we collect may include the categories described below.
Vendors and Property Owners
If you engage us to sell, lease or manage your property, we may collect:
Full name
Residential address
Postal address
Telephone numbers
Email address
Date of birth (where required)
Identification documents
Driver licence
Passport
Medicare card (where permitted)
Proof of ownership
Property ownership details
Property history
Mortgage information where relevant
Banking details for payment of sale proceeds or rental income
Taxation information where required
Trust details
Company information
Beneficial ownership information
Emergency contact details
Correspondence with us
Instructions provided to us
Records of meetings and telephone conversations
Electronic communications
Digital signatures
Audio or video recordings where permitted by law
Purchasers and Prospective Purchasers
We may collect:
Name
Address
Telephone number
Email address
Buyer preferences
Inspection history
Property enquiries
Auction registrations
Identification documents
Proof of identity
Financial capacity information voluntarily provided
Deposit payment details
Contract information
Communication history
Property search preferences
Feedback regarding inspections
Marketing preferences
Where required by law, additional information may be collected to satisfy our AML/CTF obligations.
Landlords
Where we provide property management services we may collect:
Name
Residential address
Contact details
Identification documents
Banking information
Taxation information
Ownership documentation
Trust account payment instructions
Insurance details
Property information
Emergency contact details
Maintenance instructions
Authority to incur expenditure
Correspondence
Communication history
Complaint history
Records of inspections
Photographs relating to the property
Tenants and Prospective Tenants
For tenancy applications and property management purposes we may collect:
Name
Residential history
Employment information
Employer details
Income information
Identification documents
Driver licence
Passport
Visa information where applicable
Date of birth
Contact details
Rental history
Previous agent references
Landlord references
Personal references
Emergency contacts
Vehicle registration details
Pet information
Utility information where relevant
Maintenance requests
Inspection reports
Routine inspection photographs
Communications with our office
Rent payment history
Trust account transactions
Tribunal or court information where relevant
Insurance claims relating to the tenancy
Guarantors
Where a guarantor is required we may collect:
Name
Address
Contact details
Identification documents
Relationship to the applicant
Financial information reasonably necessary to assess the guarantee
Signature
Communication records
Contractors, Tradespeople and Suppliers
We may collect:
Business name
Contact details
ABN
Company details
Trade licence information
Qualifications
Insurance certificates
Banking details
Payment information
Tax invoices
Service history
Work orders
Compliance documentation
Safety certifications
Communication records
Job Applicants
If you apply for employment with Noonan, we may collect:
Name
Address
Telephone numbers
Email address
Resume
Qualifications
Employment history
Professional memberships
Licences
References
Interview notes
Right to work documentation
Police checks where required
Working with Children Checks where applicable
Background verification information where permitted by law
Superannuation details (if employed)
Banking details (if employed)
Information collected during recruitment will only be used for employment-related purposes unless otherwise permitted by law.
Employees
For employees, we collect personal information necessary to administer the employment relationship.
The handling of employee records is generally exempt from the Australian Privacy Principles where the employee records exemption under the Privacy Act applies.
Website Visitors
When you visit our website we may automatically collect information including:
IP address
Browser type
Device type
Operating system
Pages visited
Date and time of access
Time spent on our website
Referral website
Search terms
Cookies
Analytics data
Website preferences
Geographic location (approximate)
Device identifiers
Website performance information
This information helps us improve our website, analyse usage trends, maintain security and enhance the user experience.
Social Media
Where you interact with us through social media platforms such as Facebook, Instagram, LinkedIn or other platforms, we may collect information that you make publicly available or provide directly to us, including:
Name
Username
Profile information
Messages
Comments
Reviews
Photographs
Videos
Enquiries
Marketing preferences
Your use of social media platforms is also governed by the privacy policies of those platforms.
CCTV and Office Visitors
Where CCTV is installed at our offices, we may collect:
Video footage
Date and time of entry
Images of visitors
Vehicle details where visible
CCTV is used for the safety and security of our staff, visitors, contractors and property, and for the prevention and investigation of unlawful activity.
Sensitive Information
Sensitive information is afforded additional protection under Australian privacy law.
We will only collect sensitive information where:
you have given your consent;
the information is reasonably necessary for our functions or activities;
collection is required or authorised by law; or
another exception under the Privacy Act applies.
Sensitive information may include:
health information;
biometric information used for identity verification (where applicable);
criminal history information where required by law;
information relating to legal proceedings where necessary to provide our services; and
any other information classified as sensitive under the Privacy Act.
We do not seek to collect sensitive information unless it is genuinely necessary.
Information Required by Law
Certain laws require us to collect and verify personal information before providing particular services.
This includes information collected to comply with:
the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth);
taxation laws;
trust accounting requirements;
real estate licensing legislation;
court or tribunal orders;
lawful requests from government authorities; and
any other applicable legislation.
Where you choose not to provide information that we are legally required to collect, we may be unable to provide our services or continue acting on your behalf.
Our Commitment to Data Minimisation
We are committed to the principle of data minimisation. This means we only collect personal information that is reasonably necessary for our business functions, legal obligations, or the services you have requested. We do not intentionally collect excessive or irrelevant personal information.
From time to time, we review the categories of personal information we collect to ensure they remain appropriate, relevant and consistent with our legal obligations and operational requirements.
10. How We Collect Personal Information
We collect personal information by lawful, fair and transparent means and only where it is reasonably necessary for our business activities or required by law.
Where it is reasonable and practicable to do so, we collect personal information directly from you. In some circumstances, we may collect personal information from authorised third parties or publicly available sources where permitted by law.
The way we collect your personal information depends on the nature of your relationship with us and the services we provide.
Information You Provide Directly
We may collect personal information directly from you when you:
enquire about buying, selling, leasing or renting a property;
request a market appraisal;
engage us to sell, lease or manage a property;
submit a rental application;
register to attend an open home or auction;
register as an auction bidder;
complete property enquiry forms;
subscribe to property alerts or newsletters;
contact us by telephone, email, SMS or social media;
attend one of our offices;
provide instructions to us;
submit maintenance requests;
make complaints or provide feedback;
apply for employment;
participate in surveys or promotional activities; or
otherwise communicate with us.
Property Management Services
As part of our property management services, we collect personal information throughout the tenancy lifecycle, including when:
tenancy applications are submitted;
lease agreements are entered into;
rent payments are administered;
maintenance requests are lodged;
inspections are conducted;
repair work is arranged;
tenancy disputes arise;
insurance claims are managed;
tribunal proceedings occur; or
the tenancy concludes.
Sales and Auctions
When buying or selling property, we may collect personal information during:
property inspections;
private appointments;
contract negotiations;
auction registrations;
contract execution;
settlement processes;
post-settlement communications; and
customer service enquiries.
Identity Verification
Where required by law or where reasonably necessary to protect our clients and business, we may collect information to verify your identity.
This may include:
government-issued identification documents;
proof of residential address;
company documentation;
trust documentation;
beneficial ownership information;
authority to act on behalf of another person; and
information required to comply with our AML/CTF obligations.
Identity verification may be undertaken electronically using secure identity verification service providers.
Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF)
Where required by law, we collect personal information to comply with our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
This may include collecting information for:
customer identification;
customer due diligence;
enhanced customer due diligence;
ongoing customer monitoring;
beneficial ownership verification;
politically exposed person (PEP) screening;
sanctions screening;
source of funds enquiries;
source of wealth enquiries where required;
transaction monitoring;
risk assessments; and
compliance with our legal reporting obligations.
Further information regarding our AML/CTF obligations is outlined later in this Privacy Policy.
Information Collected from Third Parties
In some circumstances, we may collect personal information from third parties where authorised by you, where required by law, or where it is reasonably necessary to provide our services.
These third parties may include:
previous landlords;
previous managing agents;
referees;
employers;
mortgage brokers;
financial institutions;
solicitors;
conveyancers;
strata managers;
building managers;
insurers;
valuers;
building and pest inspectors;
utility providers;
government departments;
courts and tribunals;
regulatory authorities;
identity verification providers;
AML/CTF service providers;
credit reporting bodies where permitted by law;
publicly available registers; and
your authorised representatives.
Property Portals and Online Platforms
We may collect personal information when you interact with us through third-party platforms, including:
realestate.com.au;
Domain;
real estate comparison websites;
online rental application platforms;
inspection registration platforms;
electronic signature platforms;
property management software;
customer relationship management (CRM) systems; and
other online services used to deliver our real estate services.
Information collected through these platforms is also subject to the privacy practices of the relevant provider.
Publicly Available Information
Where permitted by law, we may collect personal information from publicly available sources, including:
property ownership records;
ASIC registers;
electoral rolls where authorised;
court judgments;
government publications;
publicly available websites;
professional networking platforms;
social media platforms; and
other publicly accessible records.
We only collect such information where it is reasonably necessary for our legitimate business purposes or legal obligations.
Website Collection
When you visit our website, we may automatically collect technical information about your interaction with the site.
This may include:
IP address;
browser type and version;
operating system;
pages viewed;
referring website;
date and time of access;
session duration;
clickstream data;
approximate geographic location;
device identifiers;
website preferences; and
diagnostic information.
This information assists us in maintaining website security, improving performance, understanding visitor behaviour and enhancing the user experience.
Cookies and Similar Technologies
Our website may use cookies, pixels, tags and similar technologies to improve functionality, analyse website traffic and support marketing activities.
These technologies may:
remember your preferences;
keep you logged into secure areas;
analyse website usage;
measure marketing effectiveness;
personalise content;
improve website performance; and
assist with fraud prevention and website security.
You may configure your browser to refuse or delete cookies. However, doing so may affect the functionality of certain parts of our website.
Analytics and Online Advertising
We may use analytics and advertising services to better understand how visitors use our website and to improve our online services.
These services may collect information about your interaction with our website using cookies and similar technologies.
Where used, these services may include:
Google Analytics;
Google Ads;
Microsoft Advertising;
Meta (Facebook) advertising services;
LinkedIn advertising services; and
other reputable analytics or advertising platforms.
Information collected through these services is generally aggregated and used to improve our services, marketing and website performance.
CCTV
For the safety and security of our staff, clients, contractors and visitors, CCTV may operate at our offices and other premises under our control.
CCTV recordings may be used for:
security monitoring;
investigating incidents;
protecting people and property;
preventing unlawful activity; and
complying with legal obligations.
CCTV recordings are retained only for as long as reasonably necessary unless required for an investigation or by law.
Telephone Calls and Electronic Communications
We maintain records of communications with clients and other individuals to provide our services, maintain accurate business records and comply with legal obligations.
This may include:
telephone calls;
voicemail messages;
emails;
SMS messages;
online chat messages;
video conference communications; and
correspondence through social media platforms.
Where telephone calls are recorded, we will do so in accordance with applicable laws.
Collection from Children
Our services are generally intended for adults.
We do not knowingly collect personal information from children unless:
the information is reasonably necessary to provide our services;
a parent or legal guardian has authorised the collection; or
collection is otherwise permitted or required by law.
If You Choose Not to Provide Personal Information
You are generally not required to provide us with your personal information.
However, if you choose not to provide information that we reasonably request or are legally required to collect, we may be unable to:
provide our services;
enter into contracts with you;
verify your identity;
comply with our legal obligations;
process tenancy applications;
conduct property transactions;
administer trust account payments; or
otherwise act on your behalf.
Where possible, we will explain the consequences of not providing the requested information.
11. Why We Collect, Hold, Use and Disclose Personal Information
We collect, hold, use and disclose personal information only where it is reasonably necessary to conduct our business, provide our services, comply with our legal obligations, protect our legitimate interests, or where you have otherwise consented.
The purposes for which we collect, hold, use and disclose personal information include, but are not limited to, the following.
Providing Real Estate Services
We collect and use personal information to provide professional real estate services, including:
selling residential and commercial property;
leasing residential and commercial property;
managing rental properties;
conducting auctions;
arranging inspections;
negotiating contracts;
preparing documentation;
communicating with buyers, sellers, landlords and tenants; and
providing ongoing customer support.
Property Management
Where we manage rental properties, personal information is used to:
assess tenancy applications;
verify applicant information;
prepare tenancy agreements;
manage rental payments;
administer trust account transactions;
arrange repairs and maintenance;
conduct routine inspections;
communicate with landlords and tenants;
manage lease renewals;
administer bond matters;
coordinate insurance claims;
manage disputes;
represent landlords where authorised; and
comply with residential tenancy legislation.
Property Sales
Where we act in the sale of property, personal information is used to:
market properties;
arrange inspections;
respond to buyer enquiries;
register auction attendees;
negotiate sales;
prepare contracts;
coordinate settlement;
liaise with solicitors and conveyancers;
maintain transaction records; and
comply with legislative obligations.
Customer Service
We use personal information to:
respond to enquiries;
provide requested information;
resolve complaints;
investigate concerns;
improve customer service;
maintain communication records;
provide updates regarding transactions;
arrange appointments; and
administer customer relationships.
Identity Verification
We use personal information to verify identity where required by law or reasonably necessary to protect our clients, our business and the integrity of property transactions.
Identity verification assists us to:
confirm identity;
reduce fraud;
prevent identity theft;
protect trust account transactions;
comply with AML/CTF legislation; and
satisfy other legal requirements.
Compliance with AML/CTF Obligations
Where applicable, we collect, hold, use and disclose personal information to comply with our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and associated Rules.
This may include:
customer identification;
customer due diligence;
enhanced customer due diligence;
beneficial ownership identification;
ongoing customer monitoring;
politically exposed person (PEP) screening;
sanctions screening;
transaction monitoring;
source of funds enquiries;
source of wealth enquiries where appropriate;
suspicious matter reporting;
record keeping; and
compliance reporting to AUSTRAC.
Failure to provide information required under AML/CTF legislation may prevent us from providing particular services.
Compliance with Legal and Regulatory Obligations
We may collect, hold, use or disclose personal information to comply with:
Commonwealth legislation;
State legislation;
court orders;
tribunal proceedings;
regulatory investigations;
statutory notices;
law enforcement requests;
licensing requirements;
taxation obligations;
trust accounting requirements;
audit requirements; and
other lawful obligations.
Employment and Recruitment
Where you apply for employment with us, we use personal information to:
assess applications;
verify qualifications;
conduct interviews;
undertake reference checks;
determine suitability for employment;
comply with employment legislation; and
administer the employment relationship where applicable.
Contractors and Suppliers
Where you provide goods or services to us, we may use personal information to:
engage contractors;
verify licences and qualifications;
process payments;
manage service agreements;
administer work orders;
communicate regarding services;
monitor performance; and
comply with legal obligations.
Marketing and Communications
We may use your personal information to:
provide property updates;
advise of new listings;
notify you of inspections and auctions;
send newsletters;
provide market information;
invite you to events;
conduct customer satisfaction surveys;
provide information about our services; and
send other communications which may reasonably be expected.
Where required by law, we will obtain your consent before sending marketing communications.
You may opt out of receiving marketing communications at any time by:
clicking the unsubscribe link included in electronic communications;
contacting our Privacy Officer;
emailing us; or
updating your communication preferences.
Opting out of marketing communications will not affect service-related communications that we are required to send.
Website Improvement and Analytics
We use information collected through our website to:
improve website functionality;
analyse visitor behaviour;
identify website performance issues;
enhance user experience;
improve security;
understand customer preferences;
develop new services;
measure marketing effectiveness; and
prevent fraud or misuse of our systems.
Where possible, we use aggregated or de-identified information for these purposes.
Business Administration
We may use personal information for legitimate business administration, including:
record keeping;
financial management;
trust account administration;
accounting;
auditing;
insurance;
risk management;
business continuity planning;
information technology support;
cybersecurity;
policy development;
legal advice;
dispute resolution;
corporate governance; and
internal reporting.
Artificial Intelligence and Technology-Assisted Services
To improve efficiency and customer service, we may use technology-assisted tools, including artificial intelligence (AI), to support administrative and operational activities.
These tools may assist with tasks such as:
drafting correspondence;
summarising documents;
preparing reports;
organising information;
identifying trends;
improving customer service; and
enhancing operational efficiency.
Where AI-assisted tools are used, we implement reasonable safeguards to protect personal information. We do not make decisions that have a legal or similarly significant effect on individuals solely through automated processing without appropriate human oversight.
Research, Planning and Business Improvement
We may use personal information to:
analyse business performance;
identify service improvements;
understand customer needs;
develop new services;
improve staff training;
enhance operational efficiency; and
support strategic planning.
Where practical, this information will be aggregated or de-identified.
Other Lawful Purposes
We may also collect, hold, use or disclose personal information:
where you have provided your consent;
where required or authorised by law;
where necessary to protect the life, health or safety of an individual;
where necessary to establish, exercise or defend legal claims;
where necessary to investigate suspected unlawful activity, fraud or misconduct; or
for any other purpose permitted under the Privacy Act 1988 (Cth).
Our Commitment to Purpose Limitation
We are committed to the principle of purpose limitation.
We will not use or disclose your personal information for a purpose that is unrelated to the reason it was collected unless:
you have provided your consent;
you would reasonably expect the use or disclosure;
the use or disclosure is required or authorised by law; or
another exception under the Privacy Act applies.
Where we intend to use personal information for a new purpose that is not reasonably expected, we will obtain your consent where required by law.
12. Disclosure of Personal Information
We recognise that personal information is entrusted to us and will only disclose personal information where it is reasonably necessary to provide our services, comply with our legal obligations, protect our legitimate business interests, or where you have otherwise consented.
We do not sell personal information to third parties.
We do not disclose personal information for unrelated commercial purposes.
Where personal information is disclosed to another organisation, we take reasonable steps to ensure that the recipient handles the information appropriately and, where required, in accordance with the Australian Privacy Principles or equivalent privacy obligations.
Disclosure Within Noonan Real Estate Agents
Personal information may be shared internally between authorised directors, managers, employees and contractors where access is reasonably necessary for the performance of their duties.
Access to personal information is limited on a need-to-know basis and is subject to appropriate access controls and confidentiality obligations.
Vendors, Purchasers, Landlords and Tenants
To facilitate property transactions and property management services, we may disclose personal information between parties involved in the same transaction where reasonably necessary.
For example:
vendors and purchasers;
landlords and tenants;
landlords and authorised contractors;
tenants and maintenance providers (where required to arrange repairs);
authorised representatives; and
legal representatives acting for any party.
Only information reasonably necessary to perform the relevant service will be disclosed.
Solicitors, Conveyancers and Settlement Agents
We may disclose personal information to legal professionals involved in a property transaction or dispute, including:
solicitors;
conveyancers;
settlement agents;
legal advisers; and
barristers where appropriate.
This enables contracts to be prepared, settlements completed, legal advice obtained and disputes resolved.
Financial Institutions
We may disclose personal information to:
banks;
financial institutions;
mortgage brokers;
lenders;
payment processors; and
trust account service providers.
This assists with financial transactions, settlements, trust accounting and payment processing.
Contractors and Maintenance Providers
Where repairs, maintenance or property services are required, we may disclose relevant personal information to contractors including:
plumbers;
electricians;
builders;
locksmiths;
cleaners;
painters;
pest control providers;
Bliższe przyjrzenie się lizaroscasino.org pokazuje, dlaczego ten adres zyskuje coraz większą rozpoznawalność. Program poleceń pozwala trwale budować pasywne środki bonusowe dzięki poleconym znajomym. Często zadawane pytania bonusowe są zebrane w osobnej sekcji pomocy. Biblioteka gier regularnie rozszerza się o nowości największych studiów deweloperskich. Spersonalizowany pasek rekomendacji sugeruje pasujące gry na podstawie dotychczasowego zachowania. Gracze mogą również mobilnie edytować i zarządzać listą ulubionych. Przegląd wszystkich transakcji jest zawsze dostępny w obszarze gracza. Zakłady poboczne rozszerzają strategiczne możliwości przy klasycznych stołach. Generatory liczb losowych są regularnie certyfikowane przez niezależne instytucje, takie jak eCOGRA. Konsekwencja w jakości serwisu przemawia za poważnym dostawcą.
gardeners;
handymen;
appliance repair technicians;
roofers;
glaziers;
carpet cleaners;
security providers; and
other appropriately qualified contractors.
Information disclosed will generally be limited to the property address, contact details, access arrangements and details necessary to complete the requested work.
Property Service Providers
We may disclose personal information to organisations assisting us in delivering our real estate services, including:
strata managers;
owners corporations;
body corporate managers;
valuers;
surveyors;
building inspectors;
pest inspectors;
insurance assessors;
utility providers;
removal companies;
property photographers;
floor plan providers;
marketing agencies;
signboard contractors; and
auction service providers.
Technology and Software Providers
To operate our business efficiently, we use a range of reputable technology providers.
Depending on the services being provided, personal information may be processed by providers of:
property management software;
real estate CRM systems;
trust accounting software;
document management systems;
cloud storage;
secure file sharing;
email hosting;
electronic signature platforms;
customer communication platforms;
website hosting;
cyber security services;
managed IT services;
backup and disaster recovery services;
accounting software; and
business productivity platforms.
These providers are contractually or otherwise required to protect personal information and use it only for authorised purposes.
Identity Verification Providers
Where identity verification is required, we may disclose personal information to trusted identity verification providers to:
verify identity documents;
verify biometric information where applicable;
confirm residential address;
detect identity fraud;
prevent financial crime; and
comply with applicable legislation.
Identity verification providers may compare information provided by you with reliable and independent data sources.
AML/CTF Compliance Providers
To comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), we may disclose personal information to specialist compliance providers, including electronic identity verification and AML screening services such as AML Smart Guard, or equivalent providers engaged by us from time to time.
These providers may assist us with:
electronic identity verification;
customer due diligence;
enhanced due diligence;
politically exposed person (PEP) screening;
sanctions screening;
beneficial ownership verification;
ongoing customer monitoring;
transaction monitoring; and
compliance reporting.
Only the information reasonably necessary to perform these services will be disclosed.
Government and Regulatory Authorities
We may disclose personal information where required or authorised by law to government agencies and regulatory authorities, including but not limited to:
AUSTRAC;
Office of the Australian Information Commissioner (OAIC);
NSW Fair Trading;
NSW Civil and Administrative Tribunal (NCAT);
courts and tribunals;
Australian Taxation Office;
Australian Securities and Investments Commission (ASIC);
law enforcement agencies;
police;
local councils;
government departments; and
other regulators with lawful authority.
Professional Advisers
We may disclose personal information to our professional advisers where reasonably necessary, including:
accountants;
auditors;
insurers;
insurance brokers;
legal advisers;
risk advisers;
compliance consultants;
external investigators; and
other professional advisers engaged by us.
Business Transfers
If all or part of our business is sold, restructured, merged or otherwise transferred, personal information may be disclosed to prospective purchasers, advisers and financiers involved in the transaction.
Any disclosure will be subject to appropriate confidentiality obligations and applicable privacy laws.
Emergencies
We may disclose personal information where reasonably necessary to:
protect the life, health or safety of an individual;
prevent serious threats;
respond to emergencies;
investigate suspected unlawful activity; or
protect our legal rights.
With Your Consent
We may disclose personal information to another person or organisation where:
you have requested us to do so;
you have authorised another person to act on your behalf;
you have otherwise consented to the disclosure; or
the disclosure is incidental to providing the services you have requested.
We Do Not Sell Personal Information
Noonan Real Estate Agents does not sell, rent, trade or otherwise commercially exploit personal information.
We do not permit third parties to use personal information for their own direct marketing purposes unless you have separately provided your consent or such use is otherwise authorised by law.
Data Sharing Principles
Whenever we disclose personal information, we seek to ensure that:
only the minimum amount of personal information reasonably necessary is disclosed;
disclosures are made securely;
recipients are subject to appropriate confidentiality or contractual obligations;
access is restricted to authorised persons;
information is disclosed only for legitimate business or legal purposes; and
disclosures comply with applicable Australian privacy laws.
Our Commitment to Responsible Disclosure
We recognise that every disclosure of personal information carries privacy obligations.
Accordingly, we regularly review our information-sharing practices, service providers and contractual arrangements to ensure they continue to meet our legal obligations, reflect industry best practice and appropriately protect the personal information entrusted to us.
13. Overseas Disclosure of Personal Information
As part of operating a modern real estate business, Noonan Real Estate Agents may engage trusted third-party service providers, cloud-based technology providers and overseas contractors to assist us in delivering our services efficiently and securely.
Where this involves the disclosure of personal information outside Australia, we take reasonable steps to ensure that the information continues to be protected in accordance with the Australian Privacy Principles and this Privacy Policy.
Overseas Contractors
From time to time, we engage suitably qualified overseas contractors to provide administrative and operational support services to our Australian business.
At the date of this Privacy Policy, our overseas contractors are primarily located in the Republic of the Philippines.
These contractors may assist with activities including:
administrative support;
property management administration;
document preparation;
data entry;
customer service support;
maintenance coordination;
marketing administration;
CRM administration;
compliance administration;
reporting;
scheduling;
file management; and
other administrative tasks authorised by Noonan.
Our overseas contractors work remotely from their own premises and access our systems using secure technology approved by Noonan.
Information Accessible by Overseas Contractors
Depending on their authorised duties, overseas contractors may have access to personal information reasonably necessary to perform their work.
This may include:
names;
contact details;
property addresses;
tenancy information;
landlord information;
purchaser and vendor information;
maintenance records;
inspection records;
communication history;
property documentation;
trust account administration information (where authorised);
compliance documentation; and
other information necessary to perform their contracted services.
Access is restricted according to each contractor’s role and responsibilities.
Security Measures
Before granting overseas contractors access to personal information, Noonan implements reasonable safeguards designed to protect the confidentiality and security of that information.
These safeguards may include:
confidentiality agreements;
contractual privacy obligations;
role-based system access;
unique user accounts;
password protection;
multi-factor authentication (where implemented);
secure cloud-based systems;
audit logging;
restricted permissions;
supervision by Australian management;
ongoing monitoring of access;
privacy and confidentiality training; and
prompt removal of system access when no longer required.
We continually review our security measures to ensure they remain appropriate having regard to the nature of the personal information we hold.
Cloud-Based Technology Providers
Many of the technology platforms used by Noonan are cloud-based.
Accordingly, personal information may be stored, processed or backed up on secure servers located in Australia or overseas by reputable technology providers.
These providers may include organisations supplying:
cloud hosting;
email services;
document management;
data backup;
cyber security;
accounting software;
customer relationship management systems;
electronic signature services;
identity verification services;
AML/CTF compliance platforms;
property management software;
trust accounting software; and
business productivity platforms.
The location of data centres used by these providers may change from time to time.
Cross-Border Disclosure
Where personal information is disclosed outside Australia, we take reasonable steps to ensure that overseas recipients:
handle personal information in a manner consistent with Australian privacy laws;
are subject to appropriate contractual confidentiality obligations;
implement appropriate security controls;
use the information only for authorised purposes;
protect the information against unauthorised access, misuse and disclosure; and
comply with any additional contractual requirements imposed by Noonan.
Where required by law, we will take additional steps before disclosing personal information overseas.
Our Responsibility
Noonan remains committed to protecting personal information regardless of where it is processed.
Although overseas contractors and technology providers may assist us in delivering our services, responsibility for the proper handling of personal information remains with Noonan.
We regularly review our overseas service arrangements to ensure they continue to meet our legal obligations, operational requirements and privacy expectations.
Changes to Overseas Arrangements
As our business evolves, we may engage additional overseas contractors or service providers located in other countries.
Where this occurs, we will take reasonable steps to ensure that any overseas disclosure of personal information complies with applicable Australian privacy laws and reflects the commitments contained in this Privacy Policy.
Transparency
By engaging our services or otherwise providing us with your personal information, you acknowledge that, where reasonably necessary for the delivery of our services or compliance with our legal obligations, your personal information may be accessed or processed by approved overseas contractors or technology providers acting on our behalf.
Such access will always be subject to appropriate security controls, contractual obligations and our ongoing oversight.
14. Protecting Personal Information
Noonan Real Estate Agents is committed to protecting the personal information entrusted to us against misuse, interference, loss, unauthorised access, modification and disclosure.
We recognise that protecting personal information is an ongoing responsibility requiring appropriate governance, technology, staff awareness and operational practices.
We maintain a privacy and information security framework designed to safeguard personal information throughout its lifecycle.
Our Security Principles
Our approach to protecting personal information is based on the following principles:
confidentiality;
integrity;
availability;
accountability;
least privilege access;
continuous improvement; and
compliance with Australian privacy laws.
These principles guide the way we collect, store, access, use and dispose of personal information.
Physical Security
We implement reasonable physical security measures to protect paper records and physical assets that contain personal information.
These measures may include:
secure office premises;
restricted office access;
visitor management procedures;
locked filing cabinets;
secure document storage;
alarm systems;
monitored premises where appropriate;
CCTV security systems;
secure destruction bins;
controlled key access; and
clean desk practices.
Only authorised personnel are permitted access to areas containing confidential information.
Electronic Security
We use reasonable technical safeguards to protect electronic information systems.
Depending on the systems being used, these safeguards may include:
password protection;
multi-factor authentication (MFA);
encryption of data in transit and, where appropriate, at rest;
secure cloud platforms;
role-based access controls;
unique user accounts;
automatic session time-outs;
audit logging;
activity monitoring;
anti-virus software;
anti-malware software;
firewalls;
endpoint protection;
email filtering;
spam protection;
vulnerability management;
software updates and security patching;
secure backups;
disaster recovery arrangements; and
cybersecurity monitoring.
We regularly review our technical safeguards to ensure they remain appropriate having regard to the nature and sensitivity of the personal information we hold.
Access Controls
Access to personal information is restricted to individuals who require that access to perform their duties.
We apply the principle of least privilege, meaning individuals are provided with access only to the systems and information reasonably necessary for their role.
Access permissions are reviewed periodically and removed promptly where access is no longer required.
Password Management
Personnel with access to our systems are expected to:
maintain secure passwords;
protect login credentials;
avoid sharing passwords;
use multi-factor authentication where implemented;
report suspected credential compromise immediately; and
comply with our information security requirements.
Staff Awareness and Training
Protecting personal information is a shared responsibility.
Our employees and contractors receive guidance appropriate to their roles regarding:
privacy obligations;
confidentiality;
cyber security awareness;
phishing and social engineering risks;
secure handling of personal information;
reporting security incidents; and
compliance with our internal policies and procedures.
Privacy and information security training is reviewed periodically to ensure it remains current and relevant.
Confidentiality Obligations
Employees, contractors, consultants and other authorised persons with access to personal information are expected to maintain the confidentiality of that information.
Appropriate confidentiality obligations may be imposed through:
employment contracts;
contractor agreements;
confidentiality agreements;
professional obligations;
internal policies; and
other legally enforceable arrangements.
Unauthorised access, use or disclosure of personal information may result in disciplinary action, termination of engagement or other legal action where appropriate.
Information Security Monitoring
To maintain the security of our systems, we may monitor:
user access;
login activity;
system events;
network traffic;
security alerts;
audit logs;
failed login attempts;
software performance; and
other information reasonably necessary to detect, investigate or prevent security incidents.
Monitoring is undertaken for legitimate security and operational purposes.
Remote Access
Where employees or contractors access our systems remotely, including approved overseas contractors, reasonable security controls are implemented to reduce the risk of unauthorised access.
These controls may include:
secure internet connections;
encrypted communications;
authentication controls;
role-based permissions;
approved devices where applicable;
endpoint security;
access monitoring; and
prompt revocation of access when no longer required.
Third-Party Service Providers
Where third-party service providers process personal information on our behalf, we take reasonable steps to ensure they maintain appropriate privacy and information security practices.
This may include:
contractual privacy obligations;
confidentiality provisions;
information security requirements;
due diligence assessments;
periodic reviews; and
other appropriate safeguards.
Cyber Security Incidents
Despite our security measures, no method of transmitting or storing information electronically can be guaranteed to be completely secure.
If we become aware of a cyber security incident or suspected unauthorised access involving personal information, we will promptly investigate the matter and take reasonable steps to contain, assess and respond to the incident.
Where required by law, we will comply with the Notifiable Data Breaches Scheme, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC).
Business Continuity
We maintain reasonable business continuity and disaster recovery arrangements designed to support the continued availability and recovery of critical business systems following unexpected events.
These arrangements assist us in protecting information and maintaining the delivery of essential services.
Continuous Improvement
Information security risks continually evolve.
Accordingly, we regularly review and improve our privacy, cyber security and information management practices to reflect:
changes in legislation;
emerging cyber threats;
technological developments;
industry best practice;
regulatory guidance; and
operational experience.
Our Commitment
Protecting personal information is fundamental to maintaining the confidence of our clients and the integrity of our business.
We are committed to maintaining a culture in which privacy, confidentiality and information security form part of everyday business operations and decision-making.
15. Data Retention, Record Keeping and Secure Destruction
Noonan Real Estate Agents is committed to retaining personal information only for as long as it is reasonably necessary to fulfil the purposes for which it was collected, to comply with legal and regulatory obligations, to resolve disputes, enforce our legal rights, or as otherwise permitted or required by law.
When personal information is no longer required, we will take reasonable steps to securely destroy or permanently de-identify the information unless we are required to retain it by law.
Our Record Keeping Principles
We manage personal information in accordance with the following principles:
records are retained only for legitimate business or legal purposes;
information is protected throughout its lifecycle;
records are securely stored;
access is restricted to authorised persons;
retention periods are regularly reviewed; and
information that is no longer required is securely destroyed or permanently de-identified where lawful and practicable.
Why We Retain Information
We may retain personal information to:
provide ongoing services;
comply with legal obligations;
comply with taxation requirements;
comply with trust accounting obligations;
comply with AML/CTF obligations;
respond to complaints;
defend legal claims;
maintain accurate business records;
support audits;
investigate incidents;
protect our legal rights; and
meet regulatory requirements.
Retention Periods
The exact period for which personal information is retained will depend on the nature of the information, the purpose for which it was collected and applicable legal requirements.
Examples include:
Record Type
Typical Retention
AML/CTF customer due diligence records
At least the minimum period required by applicable AML/CTF legislation
Trust account records
At least the minimum period required under applicable legislation
Property transaction records
As required by law or where reasonably necessary to protect legal rights
Property management records
As required by law or where reasonably necessary for business purposes
Financial and taxation records
In accordance with applicable taxation legislation
Employment records
As required by employment and workplace legislation
Recruitment records (unsuccessful applicants)
For a reasonable period unless otherwise required by law or consented to
CCTV recordings
Generally retained only for as long as reasonably necessary unless required for an investigation or legal proceedings
Website analytics
In accordance with the settings of the relevant analytics platform and our business needs
Marketing information
Until you unsubscribe or the information is no longer required
Where different legal obligations apply, we will retain records for the longer applicable period.
Archiving
Where appropriate, older records may be archived in secure electronic or physical storage.
Archived records remain subject to the same privacy, confidentiality and security requirements as active records.
Access to archived information is restricted to authorised personnel.
Secure Disposal
When personal information is no longer required and no legal obligation exists to retain it, we take reasonable steps to securely dispose of the information.
Depending on the type of information, secure disposal may include:
secure shredding of paper records;
certified destruction of confidential documents;
secure deletion of electronic records;
permanent de-identification;
secure destruction of storage media; or
secure disposal by approved destruction providers.
De-identification
Where appropriate, personal information may be permanently de-identified rather than destroyed.
De-identified information no longer identifies an individual and may be retained for legitimate business purposes, statistical analysis, service improvement or reporting.
Legal Holds
Where information may be relevant to:
legal proceedings;
tribunal matters;
regulatory investigations;
insurance claims;
audits; or
law enforcement requests,
we may retain the information for longer than our usual retention periods until the relevant matter has concluded.
Backups
To support business continuity and disaster recovery, personal information may be included in secure system backups managed by Noonan or our authorised information technology service providers.
Backup data is protected using appropriate security measures and retained in accordance with our business continuity requirements.
Where information has been deleted from active systems, residual copies may remain within secure backup systems for a limited period before being overwritten through normal backup cycles.
Ongoing Review
We periodically review the personal information we hold to ensure it remains:
relevant;
accurate;
necessary;
appropriately protected; and
retained only for as long as required.
Where information is no longer required, we will securely destroy or de-identify it where lawful and practicable.
Our Commitment
Responsible management of personal information includes not only collecting and protecting information but also ensuring it is retained only for appropriate periods and securely disposed of when no longer required.
Noonan is committed to maintaining responsible record management practices that support privacy, security, legal compliance and good corporate governance.
SECTION 16
Access to Personal Information, Correction, Privacy Rights and Complaints
This section addresses Australian Privacy Principles 12 and 13, together with your internal complaint handling process.
16. Your Privacy Rights
Noonan Real Estate Agents recognises that individuals have important rights regarding their personal information.
Subject to applicable law, you have the right to:
know what personal information we collect;
understand why we collect it;
request access to your personal information;
request correction of inaccurate or incomplete information;
withdraw consent where processing is based on consent;
request that we update your information;
make a privacy complaint;
receive information about how we handle your complaint; and
contact our Privacy Officer regarding any privacy concern.
We are committed to responding to privacy requests in a fair, transparent and timely manner.
Access to Your Personal Information
You may request access to personal information that we hold about you.
Requests should be made in writing to our Privacy Officer using the contact details provided at the end of this Privacy Policy.
To protect your privacy, we may require reasonable evidence of your identity before providing access.
Responding to Access Requests
We will acknowledge your request as soon as reasonably practicable and aim to respond within 30 calendar days.
Where additional time is reasonably required due to the complexity of the request, we will advise you accordingly.
Where possible, access will be provided in the form requested by you.
Circumstances Where Access May Be Refused
In certain circumstances, the Privacy Act permits us to refuse access to personal information.
Examples include where:
giving access would unreasonably affect another person’s privacy;
legal professional privilege applies;
the request is frivolous or vexatious;
access would prejudice legal proceedings;
access would prejudice enforcement activities;
disclosure would reveal commercially sensitive information;
another law requires or authorises refusal; or
another exception under the Privacy Act applies.
If access is refused, we will provide written reasons unless we are prohibited by law from doing so.
We will also advise you of any available complaint or review mechanisms.
Charges
We do not charge a fee for making a request to access your personal information.
However, where permitted by law, we may charge a reasonable administrative fee for providing access where substantial resources are required to locate, retrieve or reproduce information.
If a fee is applicable, we will advise you before proceeding.
Correction of Personal Information
We take reasonable steps to ensure the personal information we hold is accurate, complete, relevant and up to date.
If you believe any personal information we hold is inaccurate, incomplete, out of date, irrelevant or misleading, you may request that it be corrected.
Requests should be made to our Privacy Officer.
Responding to Correction Requests
Where we are satisfied that information should be corrected, we will take reasonable steps to:
update our records;
correct inaccurate information;
notify relevant third parties where appropriate and reasonably practicable, if requested by you; and
ensure future use of the corrected information.
If we refuse a correction request, we will provide written reasons together with information about available complaint mechanisms.
Keeping Your Information Current
We encourage you to notify us promptly if your:
name changes;
address changes;
telephone number changes;
email address changes;
ownership details change;
company or trust details change; or
any other relevant personal information changes.
Maintaining accurate information helps us provide efficient services and comply with our legal obligations.
Making a Privacy Complaint
If you believe that we have mishandled your personal information or breached the Privacy Act, you may lodge a privacy complaint with us.
Complaints should be submitted in writing to our Privacy Officer.
To assist us in investigating your complaint, please provide:
your name and contact details;
details of your complaint;
any relevant dates;
copies of supporting documents (if available); and
the outcome you are seeking.
How We Handle Complaints
Upon receiving a privacy complaint, we will:
acknowledge receipt as soon as reasonably practicable;
investigate the issues raised;
request additional information where required;
consider relevant legislation;
review available evidence;
consult relevant staff where appropriate;
determine an appropriate outcome; and
provide a written response.
We aim to respond to privacy complaints within 30 calendar days.
Where additional time is reasonably required, we will keep you informed of our progress.
Complaints to the OAIC
If you are not satisfied with our response, you may refer your complaint to the:
Office of the Australian Information Commissioner (OAIC)
Website:
https://www.oaic.gov.au
Telephone:
1300 363 992
We encourage individuals to first give us the opportunity to investigate and resolve privacy concerns before referring the matter to the OAIC.
No Disadvantage
We will not treat you unfairly because you have:
requested access to your personal information;
requested correction of your information;
made a privacy complaint; or
exercised any rights available under Australian privacy law.
Continuous Improvement
Privacy complaints provide valuable opportunities to improve our services and governance.
Where appropriate, we review complaints to identify:
opportunities for improvement;
staff training requirements;
policy enhancements;
technology improvements;
operational changes; and
risk management initiatives.
Lessons learned from privacy complaints may be incorporated into our ongoing privacy management programme.
Our Commitment
We are committed to treating every privacy enquiry and complaint professionally, respectfully and fairly.
Our objective is to resolve concerns promptly while maintaining transparency, accountability and compliance with Australian privacy laws.
SECTION 17
Notifiable Data Breaches, Privacy Incidents and Data Breach Response
17.1 Our Commitment
Noonan Real Estate Agents is committed to responding promptly, responsibly and transparently to any actual or suspected privacy incident or data breach.
While we implement reasonable measures to protect personal information, no organisation can eliminate all information security risks.
Accordingly, we maintain procedures for identifying, assessing, containing, investigating and responding to privacy incidents and eligible data breaches.
Our objective is to minimise harm to affected individuals, restore the security of our systems and comply with our legal obligations under Australian privacy law.
17.2 What is a Data Breach?
A data breach occurs where personal information held by Noonan is:
lost;
accessed without authorisation;
disclosed without authorisation;
altered without authorisation; or
otherwise compromised.
A data breach may occur accidentally or deliberately and may involve electronic records, paper records or verbal disclosures.
Examples include:
emails sent to the wrong recipient;
lost laptops;
lost mobile phones;
stolen devices;
phishing attacks;
ransomware attacks;
hacked email accounts;
unauthorised access by employees or contractors;
confidential documents being misplaced;
unauthorised disclosure during conversations;
cyber attacks;
compromised cloud accounts; or
any other incident affecting the confidentiality, integrity or availability of personal information.
17.3 Privacy Incidents
Not every privacy incident will amount to an eligible data breach under the Privacy Act.
However, all suspected privacy incidents are treated seriously.
Examples include:
accidental disclosure;
incorrect mail or email recipients;
inappropriate access to client files;
unauthorised downloading of information;
suspicious system activity;
loss of confidential documents;
attempted cyber attacks;
malware infections;
suspected phishing; or
any event that may place personal information at risk.
All suspected incidents should be reported promptly through our internal reporting processes.
17.4 Our Response
Where we become aware of an actual or suspected privacy incident, we will take reasonable steps to:
contain the incident;
prevent further unauthorised access or disclosure;
preserve evidence;
investigate the circumstances;
assess the nature and extent of the incident;
determine whether personal information has been affected;
identify affected individuals;
assess the likelihood of serious harm;
determine whether notification is required by law;
implement corrective actions; and
review our systems and procedures to reduce the likelihood of recurrence.
17.5 Assessment
Where required by law, we will undertake a reasonable and expeditious assessment to determine whether a suspected data breach is an eligible data breach under the Privacy Act.
This assessment will consider factors including:
the nature of the information involved;
whether the information was encrypted or otherwise protected;
who obtained access;
whether the information is likely to be misused;
the sensitivity of the information;
whether the information has been recovered;
the likelihood of serious harm; and
any other relevant circumstances.
17.6 Notification
Where required under the Notifiable Data Breaches Scheme, we will notify:
affected individuals; and
the Office of the Australian Information Commissioner (OAIC),
as soon as practicable after becoming aware of an eligible data breach.
Notifications will generally include:
a description of the incident;
the kinds of information affected;
recommendations regarding steps individuals should take; and
contact details for further information.
17.7 Containment
Where reasonably practicable, we will take immediate steps to reduce the impact of a privacy incident.
Depending on the nature of the incident, this may include:
disabling user accounts;
resetting passwords;
revoking system access;
recovering documents;
isolating affected systems;
engaging our external IT provider;
notifying relevant service providers;
restoring systems from backups;
engaging cyber security specialists;
notifying insurers; and
implementing additional security controls.
17.8 Learning From Incidents
Following every significant privacy incident, we will review:
what occurred;
why it occurred;
whether policies were followed;
opportunities for improvement;
technology improvements;
staff training requirements;
contractor management;
cyber security controls; and
governance improvements.
Lessons learned will be incorporated into our privacy management programme.
17.9 Continuous Improvement
Privacy and cyber threats continually evolve.
Accordingly, we regularly review our privacy governance, cyber security controls, incident response procedures and staff awareness programmes to strengthen our ability to prevent, detect and respond to privacy incidents.
17.10 Our Commitment
If a privacy incident occurs, our priority will always be to:
protect affected individuals;
minimise harm;
restore the security of our systems;
comply with Australian law; and
continually improve our privacy and cyber security framework.
18. Privacy Governance, Accountability and Continuous Improvement
Noonan Real Estate Agents recognises that protecting personal information requires more than policies alone. Effective privacy management depends on strong governance, clearly defined responsibilities, ongoing education and continuous improvement.
Privacy forms an integral part of our broader corporate governance framework and is embedded within our business processes, risk management practices and organisational culture.
Governance Commitment
We are committed to maintaining a privacy management programme that promotes:
accountability;
transparency;
lawful handling of personal information;
responsible decision-making;
continual improvement;
staff awareness;
cyber resilience; and
compliance with applicable Australian privacy laws.
Privacy considerations are incorporated into the planning, delivery and review of our business activities wherever reasonably practicable.
Privacy Officer
Noonan has appointed a Privacy Officer responsible for overseeing our privacy management programme.
The Privacy Officer’s responsibilities include:
monitoring compliance with this Privacy Policy;
responding to privacy enquiries;
managing privacy complaints;
coordinating privacy incident responses;
overseeing access and correction requests;
monitoring legislative developments;
supporting staff awareness and training;
reviewing privacy risks;
recommending improvements to privacy practices; and
reporting significant privacy matters to senior management where appropriate.
The Privacy Officer may work with other members of management and our external advisers to ensure effective privacy governance.
Privacy by Design
Where reasonably practicable, privacy considerations will be incorporated into the design, development and implementation of new systems, technologies, business processes and services.
Before introducing significant changes that may affect the handling of personal information, we will consider:
the necessity of collecting personal information;
opportunities to minimise the information collected;
appropriate security controls;
privacy risks;
legal obligations;
access requirements; and
the potential impact on individuals.
Risk Management
Privacy risks are considered as part of our broader business risk management framework.
Where appropriate, we assess risks associated with:
new technologies;
software providers;
overseas contractors;
cyber security;
third-party service providers;
legislative change;
information sharing;
business continuity; and
operational processes.
Where privacy risks are identified, we take reasonable steps to reduce those risks through appropriate controls and governance measures.
Training and Awareness
We recognise that effective privacy protection depends upon informed and responsible personnel.
Accordingly, we promote privacy awareness among our employees and contractors through guidance appropriate to their roles and responsibilities.
Training may include:
privacy obligations;
confidentiality;
cyber security awareness;
phishing prevention;
secure handling of personal information;
recognising and reporting privacy incidents;
AML/CTF privacy obligations; and
updates regarding changes to legislation or internal procedures.
Contractor Management
Where contractors have access to personal information, we take reasonable steps to ensure they understand and comply with applicable privacy obligations.
This may include:
confidentiality agreements;
contractual privacy obligations;
role-based access controls;
privacy guidance;
ongoing supervision;
periodic review of access; and
prompt removal of access when engagement ends.
These requirements apply equally to Australian-based and overseas contractors.
Policy Review
This Privacy Policy will be reviewed:
at least annually;
following significant legislative change;
following material changes to our business;
following significant privacy incidents;
following major technology changes; or
whenever otherwise considered appropriate.
Where amendments are made, the updated version will be published on our website.
Contacting Us
If you have any questions regarding this Privacy Policy or our privacy practices, please contact our Privacy Officer.
Privacy Officer
General Manager
Noonan Real Estate Agents Pty Ltd
Telephone: 0477 225 511
Email: mgr@noonan.com.au
Postal Address:
31 Morts Road
Mortdale NSW 2223
Australia
Office of the Australian Information Commissioner
If you are not satisfied with our response to your privacy concern, you may contact:
Office of the Australian Information Commissioner (OAIC)
Website: https://www.oaic.gov.au
Telephone: 1300 363 992
Postal Address: GPO Box 5288, Sydney NSW 2001 (or the current address published by the OAIC).
Policy Availability
The current version of this Privacy Policy is available:
on our website;
upon request from our office; and
in any other format reasonably required to assist individuals in understanding our privacy practices.
Final Commitment
Protecting personal information is fundamental to the trust our clients, landlords, tenants, vendors, purchasers, employees, contractors and business partners place in us.
Noonan Real Estate Agents is committed to maintaining responsible privacy practices that support compliance with Australian law, protect personal information and promote confidence in the services we provide.
We recognise that privacy is an ongoing responsibility. We will continue to review and strengthen our privacy practices, governance arrangements and information security measures to ensure they remain effective, proportionate and aligned with evolving legal and community expectations.