Back To Top

Confidentiality Policy

1. Purpose

The purpose of this Confidentiality Policy is to protect confidential, sensitive, and proprietary information held by the organisation and to establish clear responsibilities for accessing, using, storing, and sharing such information.

The policy is intended to promote trust, protect individuals and the organisation, and ensure that confidential information is handled responsibly and appropriately.

2. Scope

This policy applies to all individuals who have access to confidential information through their involvement with the organisation, including:

  • Board members and directors.

  • Committee members.

  • Officers and office bearers.

  • Employees.

  • Members.

  • Volunteers.

  • Consultants and contractors.

  • Temporary staff.

  • Other individuals acting on behalf of or representing the organisation.

3. Definition of Confidential Information

Confidential Information means information that is not publicly available and that should reasonably be treated as private, sensitive, or restricted.

This may include:

  • Personal information relating to members, employees, volunteers, or other individuals.

  • Membership records and applications.

  • Complaints, grievances, and disciplinary matters.

  • Conflict of interest disclosures.

  • Financial and accounting information.

  • Business plans and organisational strategies.

  • Contracts and agreements.

  • Internal communications.

  • Meeting discussions and minutes where designated as confidential.

  • Passwords, access credentials, and security information.

  • Intellectual property and proprietary information.

  • Information provided to the organisation on a confidential basis.

  • Any other information identified as confidential by the organisation.

4. Confidentiality Responsibilities

Individuals covered by this policy are responsible for protecting confidential information that they access through their involvement with the organisation.

Confidential information must only be accessed, used, copied, stored, or shared for legitimate organisational purposes and in accordance with applicable policies and procedures.

5. Access to Confidential Information

Access to confidential information should be limited to individuals who require the information to perform their authorised duties or responsibilities.

Individuals must not access confidential information merely because they have the technical ability or opportunity to do so.

Access may be restricted, monitored, or withdrawn where necessary to protect the organisation and the individuals whose information it holds.

6. Use of Confidential Information

Confidential information must not be:

  • Used for personal benefit.

  • Used to benefit another individual or organisation without authorisation.

  • Used for unauthorised commercial purposes.

  • Shared with unauthorised persons.

  • Used to cause harm, embarrassment, or disadvantage to another person.

  • Removed from organisational systems or premises without appropriate authorisation.

Individuals should only use confidential information for the purpose for which access was granted.

7. Disclosure of Confidential Information

Confidential information must not be disclosed to external individuals or organisations without appropriate authorisation.

Disclosure may be permitted where:

  • The individual concerned has provided appropriate consent.

  • The organisation has authorised the disclosure.

  • Disclosure is necessary for a legitimate organisational purpose.

  • Disclosure is required by law or a lawful authority.

  • Disclosure is necessary to protect the safety or rights of an individual.

  • Disclosure is otherwise permitted under applicable organisational policies.

Where there is uncertainty about whether information may be disclosed, individuals should seek guidance from the appropriate authorised person before sharing it.

8. Confidential Meetings and Discussions

Information discussed during confidential meetings, committee meetings, disciplinary proceedings, grievance processes, investigations, or other restricted discussions must not be disclosed outside the authorised group.

Individuals must respect any confidentiality requirements communicated before, during, or after a meeting.

9. Personal and Member Information

Personal information relating to members, employees, volunteers, or other individuals must be handled with appropriate care and only for legitimate organisational purposes.

Individuals must not disclose personal information, contact details, records, complaints, or other sensitive information without appropriate authorisation.

Personal information should be stored and processed in accordance with the organisation’s applicable privacy and data protection requirements.

10. Electronic Information and Communications

Confidential information transmitted electronically must be handled securely.

Individuals should:

  • Use authorised organisational systems where available.

  • Protect passwords and access credentials.

  • Avoid sending confidential information to incorrect or unauthorised recipients.

  • Use appropriate security measures when sharing sensitive information.

  • Avoid storing confidential information on unauthorised devices or platforms.

  • Report suspected unauthorised access or disclosure promptly.

11. Physical Documents and Records

Confidential documents must be stored securely and protected from unauthorised access.

Individuals should take reasonable precautions when:

  • Printing confidential documents.

  • Transporting physical records.

  • Storing files.

  • Disposing of confidential information.

  • Working in shared or public environments.

Confidential records should be securely destroyed or disposed of when they are no longer required, in accordance with the organisation’s records management requirements.

12. Confidentiality During Investigations and Complaints

Information relating to grievances, complaints, disciplinary proceedings, investigations, and other sensitive matters must be treated as confidential.

Individuals involved in such processes must not discuss the matter with unauthorised persons or attempt to influence witnesses, complainants, respondents, or decision-makers.

Confidentiality does not prevent individuals from obtaining appropriate support or advice where permitted by the organisation’s procedures.

13. Disclosure Required by Law

Nothing in this policy prevents an individual or the organisation from making a disclosure that is required by law, regulation, court order, or other lawful authority.

Where reasonably possible and legally permitted, the organisation should be informed before confidential information is disclosed under such circumstances.

14. Conflict of Interest and Confidential Information

Individuals must not use confidential information obtained through their organisational role to advance a personal, financial, professional, or other interest.

Where a conflict of interest exists, the individual must comply with the organisation’s Conflict of Interest & Disclosure Policy and any applicable confidentiality requirements.

15. Confidentiality After Leaving the Organisation

The responsibility to protect confidential information may continue after an individual leaves the organisation, ends their membership, or ceases to hold a position or role.

Former members, employees, volunteers, directors, officers, and representatives must not use or disclose confidential information obtained during their involvement with the organisation unless authorised or legally permitted to do so.

16. Unauthorised Disclosure

An unauthorised disclosure occurs when confidential information is accessed, used, copied, transmitted, discussed, or released without appropriate permission.

Examples may include:

  • Sending confidential documents to the wrong recipient.

  • Sharing private member information without authorisation.

  • Discussing confidential matters publicly.

  • Posting confidential information on social media.

  • Providing internal documents to unauthorised third parties.

  • Accessing records without a legitimate organisational reason.

17. Reporting a Confidentiality Breach

Any suspected or actual loss, unauthorised access, disclosure, or misuse of confidential information should be reported to the organisation as soon as reasonably possible.

The organisation may investigate the incident and take appropriate steps to limit potential harm, secure affected information, and prevent recurrence.

18. Consequences of Breach

A breach of this policy may result in appropriate action under the organisation’s applicable policies and procedures.

Depending on the circumstances, action may include:

  • Guidance or corrective measures.

  • Restriction or removal of access to confidential information.

  • Formal disciplinary action.

  • Suspension or termination of membership or involvement.

  • Termination of employment or engagement where applicable.

  • Referral to an appropriate authority where required.

19. Responsibilities of the Organisation

The organisation is responsible for taking reasonable steps to:

  • Identify and protect confidential information.

  • Establish appropriate access controls.

  • Provide relevant confidentiality guidance and training.

  • Maintain appropriate records and security measures.

  • Investigate reported confidentiality breaches.

  • Take appropriate corrective action where necessary.

  • Review confidentiality practices periodically.

20. Responsibilities of Individuals

Individuals covered by this policy are expected to:

  • Protect confidential information entrusted to them.

  • Only access information required for their authorised role.

  • Use confidential information appropriately.

  • Avoid unauthorised disclosure.

  • Follow applicable information-security procedures.

  • Report suspected breaches promptly.

  • Return or securely dispose of confidential information when required.

  • Continue to respect confidentiality after leaving the organisation.

21. Related Policies

This policy should be read together with the organisation’s:

  • Constitution and/or Bylaws

  • Member in Good Standing Policy

  • Grievance Policy

  • Conflict of Interest & Disclosure Policy

  • Code of Conduct

  • Ethics Policy

  • Disciplinary Policy

  • Privacy and Data Protection Policy

  • Records Management Policy

  • Information Security Policy

  • Whistleblower Policy, where applicable