Privacy Policy

Introduction

We believe safe, caring environments honour the dignity and privacy of every person. Upholding confidentiality and handling personal information with care are part of our Christian witness and our duty of care to children, young people, families, volunteers and staff.

This Privacy Policy explains how we collect, use, disclose, store and protect personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and how you can access or correct your information or raise a privacy concern with us.

Scope & Who We Are

This policy applies to AGC National Office and to local churches and ministries registered with AGC across Australia. AGC is progressively centralising records in our authorised church management system (ARC). During transition, some locations may also use other local systems such as Elvanto and Planning Centre. This policy governs all such handling of personal information.

Policy

Acts Global Churches Limited (AGC) is committed to respecting the privacy of every person in our community. We handle personal information so we can provide ministry, care, programs, events and services, and we take our responsibility to protect that information seriously.

We aim to be open and transparent about what we collect, why we collect it, how we use it, and the choices and rights you have. We manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We make this Privacy Policy available on our website: [[https://actsglobal.church/](https://actsglobal.church/)](https://actsglobal.church/](https://actsglobal.church/))

We work to ensure that:
  • We meet our legal and ethical obligations to protect the privacy of members, adherents, staff and volunteers.
  • People are informed about their privacy rights and how to contact us.
  • We provide appropriate privacy when people share personal or sensitive matters.
  • Staff, leaders and key volunteers are supported to understand and meet these responsibilities.
  • This policy is available free of charge and, on request, in accessible formats.

How to Contact Us

For privacy enquiries or complaints, please contact: National Compliance Officer (Privacy Lead), 28/20 Enterprise Drive, Bundoora VIC 3083, or privacy@actsglobal.church, or +61 3 9466 7999.

What Information Is Collected

We collect only the personal information we reasonably need to carry out our ministry and operations. The kinds of information we collect depend on how you connect with us—for example, attending services, joining a group, volunteering, registering for a program, receiving pastoral care, or making a donation. We take reasonable steps to ensure the information we hold is accurate, up to date and complete.

The types of personal information we may handle include contact details; membership and attendance records; small group participation; employment-related information; volunteer applications and screening (such as WWCC status and expiry); children’s and youth program registrations; camp and event registrations (including relevant health or dietary information); donations and payments; communications preferences; pastoral care notes (with consent); and, where applicable, photography, media, online streaming and social media engagement (also see out Media Policy ITC002).

From time to time our activities may include taking photos or videos for ministry and promotional purposes. We will always seek your permission to take your photo or video and we will ensure that you are notified via public notice when areas are subject to public video recording or capture of imagines (e.g. during a service or event etc). See the Appendix B for an example of a public notice>Sensitive information (such as health or disability information) is collected only where reasonably necessary for our ministry and duty of care, and usually with consent, unless an exception under the Australian Privacy Principles (APPs) applies.

How Information Is Collected

We usually collect personal information directly from you—for example, when you complete a form, sign up for a program or event, make a donation, contact us, or engage with our website or online services. In some circumstances, we may collect information from a parent or guardian (for a child), a nominated emergency contact, or another third party where you have authorised this or where collection is required or permitted by law.

We collect personal information only where it is reasonably necessary for purposes related to AGC’s functions and activities. At or before the time of collection, we aim to inform you who we are, why we are collecting your information, how it will be used and disclosed (including any overseas disclosures), how you can access or correct it, how to raise a concern, and how to contact us.

We require our staff and volunteers to clearly inform individuals when collecting personal information, obtain consent where required, and explain the purpose of collection. Where information is collected by telephone, this notification will be provided before any details are recorded.

We take reasonable steps to ensure that personal information and any associated consent are recorded securely, including in password-protected systems or files. If we become aware that information is inaccurate or out of date, we will take reasonable steps to correct it as soon as practicable by contacting the individual concerned or their authorised representative.

If we receive unsolicited personal information, we will promptly assess whether it is information we would be permitted to collect and retain. If not, and where lawful and reasonable, we will destroy or de identify the information as soon as practicable.

Storage and Security of Information

AGC will ensure that personal information is protected by reasonable safeguards against loss, unauthorised access, use, modification, disclosure or any other misuse.

  • Physical files are kept in a locked cabinet within secure premises. Staff and volunteers who do not have a genuine reason to access personal information will not be able to do so without permission.
  • Senior leaders will at least annually issue a reminder to maintain security consciousness.
  • Personal information in electronic form about members and adherents is stored in password-protected systems and is not stored on unprotected hard drives or portable storage devices.
  • Files containing personal information of members and adherents will not be forwarded to private email addresses or mobile phones. AGC will ensure that personal information is protected by reasonable safeguards against loss, unauthorised access, use, modification, disclosure or any other misuse.

AGC will ensure that personal information is kept for no longer than is necessary for the purposes for which it has been collected and for which it may lawfully be used. Records will be disposed of securely and in accordance with reasonable requirements for the disposal of personal information.

Information on computers and photocopiers will be removed prior to disposal.

For staff and volunteer information, we prefer records to be stored in ARC as AGC’s recognised secure system. Where local church databases are used, appropriate safeguards should be applied, including password protection, encryption where available, role-based access controls, regular access reviews, and multi-factor authentication where the system supports it (for example, in platforms such as Elvanto and Planning Centre).

Our Recordkeeping Policies (COM004 – Local Churches and National Office) set out system specific custody and storage requirements (e.g., Xero, payroll drives, locked cabinets) which form part of these security measures.

Use of Personal Information

Personal information collected and held by AGC will only be accessed and used by AGC staff and volunteers who legitimately need the information for a purpose related to their role. Staff and volunteers are required to use the information only for the purpose for which it was provided at the time of collection (or for a related purpose where permitted by law).

Information may be disclosed in the following instances:

  • with the individual’s written consent, or
  • to reduce or avoid a threat to an individual’s life, health or safety or a serious threat to public health and safety, or
  • when the use or disclosure is required or is specifically authorised by law, or
  • if the individual is reasonably suspected of being engaged in current or past unlawful activity, and the personal information is disclosed as a necessary part of the investigation or reporting the matter.

We may send ministry updates, event invitations and fundraising communications. We always provide a simple unsubscribe/opt-out in each message "Let us know if you do not wish to receive these notifications/emails/messages".

We do not adopt government-related identifiers (for example, WWCC numbers, TFNs, Medicare, driver licence or passport numbers) as our own identifiers. We use or disclose such identifiers only were permitted by law (for example, to verify a WWCC clearance or to meet tax reporting requirements) and otherwise minimise storage (for example, recording status/expiry instead of full numbers where feasible).

Access to Records

AGC will take reasonable steps to allow an individual to access the personal information it holds about them and to correct inaccurate information as appropriate. The individual will need to provide identification and be accompanied when personally viewing files.

We aim to respond to access or correction requests within 30 days. We will provide access in the requested form where reasonable or explain an alternative if not. There is no fee to request a correction. If we refuse access or correction (in whole or part), we will provide written reasons and information on how to raise a complaint. If you ask us to, we can also attach a statement to the record noting your view.

Complaint of Breach

If you have a concern about how we have handled your personal information, please contact us using the details above. We will acknowledge your complaint promptly and investigate. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

Children, Media & Online Engagement

We handle children’s information with particular care. We seek parental/guardian and the child’s consent for image/video use and follow our Child Safety & Wellbeing Policy and Code of Conduct. You may withdraw consent at any time, and we will act promptly (refer to AGC Media Policy ITC002 for further guidance).

Data Retention & Disposal

We retain personal information only for as long as needed for ministry, legal, or operational purposes. Finance/payroll records are generally retained for at least seven years. Other categories follow our Record-Keeping Policies (COM004 – Local Churches and National Office). We also apply secure disposal to backups and removable media, consistent with these policies.

Governance, Oversight and Review

The Acts Global Churches Board oversees this Policy to ensure it remains effective and accessible. The Policy will be reviewed every two years, or earlier if needed.

Related Policies and Documents

  • AGC Grievances and Complaints Policy (COM001)
  • AGC Record Keeping Policy (COM004)
  • AGC Cyber Policy (ITC001)
  • AGC Child Safety and Wellbeing Policy (GOV003)
  • AGC Media Policy (ITC002)
  • AGC Volunteer Management Policy (HR008)
  • AGC Recruitment & Selection Policy (HR011)
  • AGC Staff Management Policy (HR007)

Further Information

If you would like more information about how we handle privacy, please see our website at [[https://actsglobal.church/](https://actsglobal.church/)](https://actsglobal.church/](https://actsglobal.church/)) or contact us using the details in the “How to Contact Us” section.