QTU Privacy Policy
Introduction
The Queensland Teachers' Union (Union, we, our or us) is the union representing teachers in Queensland government schools and TAFE institutions. The Union collects personal information in order to conduct its business of representing, advocating and campaigning for the industrial, professional, social, political and economic interests of its members. The Union operates in the political, legal, industrial and social spheres. The Union is committed to protecting your privacy and providing you with information and services relevant to you. The Union complies with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). This Privacy Policy (Policy) should be read in conjunction with the Privacy Act and the APPs.
This Policy appears on our website and we will also provide a copy of this Policy to anyone who makes a request, free of charge.
Download PDF | Last updated on: 11 February, 2026
Consent
By supplying us with your personal information, you are agreeing to be bound by this Policy and consent to us collecting, using, storing and disclosing that information (within and outside Australia) in accordance with this Policy.
When you become a member of the Union, you also consent to being a member of the Australian Education Union's Queensland Branch, and to your information being used for that purpose. Information shared with the Australian Education Union may be covered by this Policy and may also be covered by the Australian Education Union's Privacy Policy. The AEU may provide member information to the Australian Council of Trade Unions (ACTU). Members may opt out of communication for marketing purposes, either at the time of joining or at any time during membership, by contacting qtu@qtu.asn.au.
What is personal information?
Under the Privacy Act, personal information is defined to mean information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether the information or opinion is recorded in a material form or not.
Personal information can include sensitive information. Sensitive information is defined as information or opinion about a person's race, ethnic origin, political opinions, membership of political associations and trade associations, religious or philosophical beliefs, sexual orientation or practices, criminal record, health information, genetic information about an individual that is not otherwise health information, or biometric information that is used for the purpose of automated biometric verification or biometric identification and biometric templates.
Personal information can also include credit information.
Personal information that the Union collects and holds
This Policy applies to personal information the Union collects from you:
- via one of our websites
- via social media
- via telephone
- via email
- via fax
- in person
- in writing.
This Policy also applies to personal information about you the Union collects from any third party.
Information collected from Union websites
The Union websites collect two types of information. The first type is anonymous information. The web server makes a record of your visit and logs the following information for statistical purposes:
- The user's server address.
- The user's top level domain name (e.g. com, .gov, .net, .au, etc.).
- The date and time of the visit to the site.
- The pages accessed and documents downloaded.
- The previous site visited.
- The type of browser used.
No attempt will be made to identify users or their browsing activities. except in the unlikely event of an investigation, where a law enforcement agency may exercise a warrant to inspect the internet service provider's logs.
Another way information may be collected is through the use of "cookies". A cookie is a small text file that the website may place on your computer. Cookies may be used, among other things, to track the pages you have visited, to remember your preferences, and to store personal information about you.
You can adjust your internet browser to disable cookies or to warn you when cookies are being used. However, if you disable cookies, you may not be able to access certain areas of the website or take advantage of the improved website experience that cookies offer.
Our websites, including campaign pages, may also contain links to other websites, social media pages such as Facebook or Twitter, or other software programmes. We are not responsible for the privacy policies of the entities responsible for those websites, and we recommend that you review the privacy policies applicable to any other websites you visit.
The Union may, however, collect information, including personal or sensitive information, from these other websites or social media pages for the purpose of conducting its business as described above.
The kinds of personal information the Union may collect
From time to time, you may voluntarily supply your personal information to the Union. The Union will record your e-mail address if you send us a message, subscribe to an email newsletter, or complete a form if this information is requested.
When you provide your personal information, it allows us, for example, to assist you with legal, industrial relations and employment queries, inform you about and enable you to participate in industrial, social and political campaigns, and accept your application for membership. You may supply personal information to the Union by, for example, responding to a survey, filling in a meeting attendance sheet, taking part in a competition, completing a membership form, discussing your issues with a delegate, or signing up to a campaign. The Union only collects personal information that is necessary for the Union to perform its functions and/or activities.
Depending upon the circumstances, you may provide to the Union, and the Union may collect, information such as, but not limited to:
- your name
- your contact details
- your social media details (e.g. blogs, X, Facebook, LinkedIn)
- your gender identity
- your marital status
- your employment details
- your educational qualifications
- your inquiry or complaint details.
Additionally, some personal information is considered sensitive, including:
- your political, religious or philosophical opinions
- your political party membership (if any)
- your union membership (if any)
- your racial or ethnic origin
- your sexual orientation
- any disabilities, illnesses or injuries you may have
- any other health information.
The Privacy Act allows the Union to collect sensitive information which relates solely to Union members or people who have regular contact with the Union, if the sensitive information relates to the Union's activities. Sensitive information you give to us will be collected, used, disclosed and stored by the Union in accordance with this Policy.
Where you provide information to the Union in relation to a job application, the personal information you provide will only be collected, held, used and disclosed for the purposes of considering your potential employment with the Union. Where you provide the details of referees, you confirm that you have informed the referees that you are providing their contact information to the Union and they have consented to the Union contacting them and discussing the personal information you have provided in relation to the job application.
You can choose to interact with us anonymously or by using a pseudonym where it is lawful and practicable. For example, you may wish to participate in a blog or enquire about a particular campaign anonymously or under a pseudonym. Your decision to interact anonymously or by using a pseudonym may affect the level of services we can offer you. For example, we may not be able to assist you with a specific industrial enquiry or investigate a privacy complaint on an anonymous or pseudonymous basis.
If we receive unsolicited personal information about or relating to you and we determine that such information could have been collected in the same manner as if we had solicited the information, then we will treat it in the same way as solicited personal information and in accordance with the APPs.
The purposes for which personal information is collected, held, used and disclosed
The Union collects, holds, uses and discloses your personal information to:
- assist you with legal, industrial relations and employment queries
- inform you about, and assist the Union in, industrial, social and political campaigns
- inform you about your rights at work
- inform you about changes to legislation
- refer you to a legal practitioner, accountant or other professional
- improve our service delivery
- manage our relationship with you
- conduct surveys and research
- provide educational services and professional development
- conduct Union elections, including provision of information to you in advance of elections
- provide information to the Australian Education Union for the purpose of your membership of the Queensland Branch of the Australian Education Union
- enable a contractor engaged by the Union to provide bulk mail services, provided that the contractor may only use the information to give effect to the contract, and may not provide the information to any third party.
We will only use your information for the purposes for which it was collected (primary purposes) or a purpose related to the primary purpose, if this use is permitted by law.
We may disclose your information to necessary third parties who assist us to provide, manage and administer our services. Information provided to third parties will be dealt with in accordance with that entity’s privacy policy.
Using your personal information for direct marketing
You consent to our use and disclosure of your personal information for the purposes of direct marketing, which may include providing you with information about events, products or services which may be of interest to you.
If you do not want us to use your personal information for direct marketing purposes, you may elect not to receive direct marketing at the time of providing your personal information or at any time during your membership by contacting qtu@qtu.asn.au.
We will never use or disclose any sensitive information for marketing or advertising purposes.
Unsubscribing and opting out
If you no longer wish to receive direct marketing or other communications from the Union, you may request at any time to cancel your consent by emailing qtu@qtu.asn.au or by contacting the Union's Privacy Officer. Members can also unsubscribe from publications through the QTU member portal online.
Data integrity
The Union endeavours to ensure that all personal information that we hold is accurate, complete and up-to-date. To assist the Union with this, individuals should contact us if any of their personal information changes, or if they believe that the personal information that we have is not accurate or complete.
When personal information that we collect is no longer required by us, we will destroy or de-identify that personal information, unless we are required by a law or a court/tribunal to retain the personal information.
We may retain personal information for so long as it is required for any of our business purposes, for the prevention of fraud, for insurance, and for governance purposes and in our IT back up.
Security
While the Union takes reasonable steps to protect the personal information that we hold from misuse, loss, unauthorised access, modification or disclosure, you should be aware that no system is completely secure against a cyber attack.
In addition, the open nature of the internet is such that information exchanged may be accessed and used by people other than those for whom the data is intended. Any information sent via the internet is sent at the sender's risk.
You should contact us immediately if you believe that there has been unauthorised access or disclosure with respect to any personal information that we hold about you.
Collection of your personal information from, and disclosure to, third parties
The Union may collect from and/or disclose your personal information, in connection with or to further the purposes outlined above, to:
- the Australian Education Union
- organisations to whom we outsource functions (including information technology providers, print service providers, mail houses, lawyers)
- otherwise as you have consented
- otherwise as required by law.
All ICT services are currently located within Australia. If any of these organisations relocate to be outside Australia, you expressly consent to us disclosing your personal information to those organisations, on the understanding that if the overseas recipient’s handling of the personal information is in breach of the APPs, the entity will not be accountable under the Privacy Act, and you will not be able to seek redress.
We take reasonable steps to ensure that each organisation from which we collect or to whom we disclose your personal information is committed to protecting your privacy and complies with the APPs, or is subject to a law or scheme that is at least substantially similar to the way in which the APPs protect information.
By providing your personal information to the Union, you consent to us transferring your personal information to such other organisations.
How the Union holds personal information
Wherever reasonably practicable, the Union holds electronic personal information on data servers that are owned and controlled by the Union in Australia. The data servers are password protected and login secured. However, by providing personal information to the Union, you consent to your information being stored and processed on a data server or data servers (e.g. cloud services) owned by a third party or third parties that may be located outside of Australia. The Union will take reasonable steps to ensure that any third party providers comply with the APPs. If personal information is only routed through servers located outside of Australia – this is not regarded as a disclosure.
Wherever reasonably practicable, the Union holds physical personal information in access controlled premises.
When the Union no longer requires your personal information for a specific purpose and we are not required to keep it to comply with any laws, we will take such steps as are reasonable in the circumstances to destroy your personal information or to ensure that the information is de-identified.
Government identifiers
We will not adopt as our own identifier a government-related identifier of an individual, such as a tax file number or Medicare card number, and will only use or disclose a government related identifier where the use or disclosure:
- is reasonably necessary for the Union to verify your identity for the purposes of our activities or functions
- is reasonably necessary for the Union to fulfil its obligations to an agency or a state or territory authority
- is required or authorised by or under an Australian law
- is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body.
De-identified data
You consent to us using and disclosing your de-identified data (information that no longer identifies you) for any purpose, including, without limitation, statistical analysis, product or service development, marketing and business planning or any other commercial purpose. We undertake technical measures to ensure that this data cannot be traced back to you.
Automated decision-making processes
The Union does not use automated decision-making processes.
Data breaches
A data breach occurs when personal information held by an organisation is lost or subjected to unauthorised access or disclosure.
The Notifiable Data Breaches Scheme introduced an obligation to notify individuals whose personal information is involved in a data breach that is likely to result in serious harm. The notification must include recommendations about the steps taken in response to the breach. The Australian Information Commissioner must also be notified of an eligible data breach.
An eligible data breach arises when the following three criteria are satisfied:
- There is unauthorised access to, or unauthorised disclosure of, personal information, or a loss of personal information, that an entity holds.
- This is likely to result in serious harm to one or more individuals.
- The entity has not been able to prevent the likely risk of serious harm with remedial action.
Where Union staff believe a data breach may have occurred, they must immediately report the breach to the General Secretary or a Deputy General Secretary, who will determine the next steps, guided by Appendix A – Data Breach Procedure.
How you may seek access and/or correction to personal information held by the Union
You have the right to request access to your personal information and/or to request that it be updated or corrected. In most cases you can gain access to your personal information that the Union holds. To request access to, correction of, or updating of any personal information held about you, please write to the Union at the following address:
Email: qtu@qtu.asn.au
Post: PO Box 1750, Milton LPO, QLD, 4064
Visit: 21 Graham Street, Milton, QLD, 4064
Phone: (07) 3512 9000
The Union requires that you provide proof of identity when you seek access to your personal information. We do not impose any charge for requesting access to personal information, but we may, at our discretion, impose a reasonable charge to cover staff and copying costs.
The Union will seek to provide you with access to your personal information within 30 days of receipt of a valid request. The Union may refuse to provide access if permitted to do so by law or under the APPs. If we deny your request, we will provide you with a written notice detailing the reasons for the refusal and the process for making a complaint about the refusal to grant your request. Where your request for access is accepted, the Union will provide you with access to your personal information in the manner requested by you, providing it is reasonable to do so.
We do not impose any charges with respect to requests to update or correct your personal information. Your request for correction will be dealt with within 30 days, or any longer period as agreed by you. If we deny your request, we will provide you with a written notice detailing reasons for the refusal and the process for making a complaint about the refusal to grant your request.
We will accept your request for correction of your personal information where we are satisfied that the information is inaccurate, out-of-date, incomplete, irrelevant or misleading. Upon accepting a request for correction of your personal information, we will take all steps that are reasonable in the circumstances, having regard to the purpose for which your information is held, to correct your personal information.
If your request for correction of credit information is accepted, we will provide written notice of this correction to any entity to which we have disclosed this information previously, to the extent that this is practicable.
If we refuse to correct your personal information, you have the right to associate with the information a statement that the information is inaccurate, out-of-date, incomplete, irrelevant or misleading. We will take such steps as are reasonable in the circumstances to associate that statement with all records we hold that contain the relevant information
You should contact the Union when your personal information details change. It is important that we keep our membership details up to date. Please contact the QTU Records or Membership sections to update any personal information. The Union may also take steps to update your personal information by reference to publicly available sources.
How you may complain about a breach of the Privacy Act or the APPs
To make a complaint about an alleged breach of the Privacy Act or the APPs please write to or email:
Attention: Privacy Officer, Leah Mertens, Deputy General Secretary
Email: qtu@qtu.asn.au
Post: PO Box 1750, Milton LPO, QLD, 4064
Visit: 21 Graham Street, Milton, QLD, 4064
All complaints must be written and must include details enabling us to contact you regarding your complaint. Please provide all details about your complaint, as well as any supporting documentation.
How the Union will deal with complaints
The Union's Privacy Officer will seek to deal with privacy complaints as follows:
- Complaints will be treated seriously.
- Complaints will be dealt with promptly.
- Complaints will be dealt with confidentially.
- Complaints will be investigated.
- The outcome of an investigation will be provided to the complainant if they have provided proof of identity. The Union will seek to respond within 30 days of receipt of a valid complaint.
If you are dissatisfied with the outcome of your complaint, you may refer your complaint to the Office of the Australian Information Commissioner.
Office of the Australian Information Commissioner
The contact details for the Office of the Australian Information Commissioner are:
Postal address: GPO Box 5218, Sydney NSW 2001
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au
For more information on privacy see the Office of the Australian Information Commissioner's website at: http://www.oaic.gov.au
Variations to the Policy
This Policy may be varied from time to time, and an updated version will be posted on the Union's websites. Please check our websites regularly to ensure that you have the most recent version of the Policy.
Appendix A – Data Breach Procedure
Step 1: Contain the data breach
The Union’s first step is to contain a suspected or known breach, where possible. This means taking immediate steps to limit any further access or distribution of the affected personal information, or the possible compromise of other information.
Where possible, the Union will take steps to reduce any potential harm to individuals. This might involve taking action to recover lost information before it is accessed or changing access controls on compromised customer accounts before unauthorised activity can occur. If remedial action is successful in making serious harm no longer likely, then notification is not required.
Step 2: Assess the data breach
The Union’s second step is to assess the data breach by gathering the facts and evaluating the risks, including potential harm to affected individuals and, where possible, taking action to remediate any risk of harm.
The following factors should be considered as part of the assessment:
- The type or types of personal information involved in the data breach.
- The circumstances of the data breach, including its cause and extent.
- The nature of the harm to affected individuals, and if this harm can be removed through remedial action.
Deciding whether “serious harm is likely”
If the Union has grounds to suspect that the data breach will result in serious harm, then it must conduct an assessment process. As part of the assessment, the Union will consider whether remedial action is possible.
If an assessment is required, the Union will follow a four-stage process for assessment as follows:
- Initiate - plan the assessment and assign a team or person.
- Investigate - gather relevant information about the incident to determine what has occurred.
- Evaluate - make an evidence-based decision about whether serious harm is likely.
- Document the evidence and decision.
The Union will conduct this assessment expeditiously and, where possible, within 30 days. If it can’t be done within 30 days, the Union will explain in the documentation why this is the case.
Step 3: Notify individuals and the Commissioner if required
If the breach is an “eligible data breach” under the Notifiable Data Breaches Scheme, it may be mandatory for the Union to notify.
Notifiable/eligible data breach
A notifiable/eligible data breach occurs when the following criteria are satisfied:
- There is unauthorised access to, or unauthorised disclosure of, personal information, or a loss of personal information, that the Union holds.
- This is likely to result in serious harm to one or more individuals.
- The Union has not been able to prevent the likely risk of serious harm with remedial action.
Where serious harm is likely, the Union will prepare a statement for the Australian Information Commissioner that contains:
- the Union’s identity and contact details
- a description of the breach
- the kind(s) of information concerned
- recommended steps for individuals.
This can be done using the OAIC’s Notifiable Data Breach form.
The Union will notify affected individuals and inform them of the contents of the statement via one of three options:
- Option 1: notify all individuals
- Option 2: notify only those individuals at risk of serious harm.
- Option 3: If neither of these options are practicable, publish the statement on the Union website.
The Union may also consider reporting the incident to other relevant bodies, such as:
- police or law enforcement
- various professional bodies;
- the Australian Tax Office
- the Australian Cyber Security Centre
- the Union’s financial services provider.
Step 4: Review the incident
Notifiable/eligible data breach
When a breach requiring notification has occurred, the Union will undertake a review and take action to prevent future breaches. This may include:
- fully investigating the cause of the breach
- developing a prevention plan
- conducting audits to ensure the plan is implemented
- updating the security/response plan
- considering changes to policies and procedures
- revising/providing staff training.
Other data breaches – review
When a breach does not require notification, the Union will undertake a review and take action where reasonable to prevent future breaches. This process may include:
- fully investigating the cause of the breach
- developing a prevention plan
- conducting audits to ensure the plan is implemented
- updating the security/response plan
- considering changes to policies and procedures
- revising/providing staff training.






