This policy sets out the way we handle personal information. It explains the sort of personal information we collect, hold and use and how we might disclose this information. We believe it is important we protect personal information we receive in accordance with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth).
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether the information or opinion is recorded in a material form or not. This includes but is not limited to an individual’s:
*Tax file numbers are subject to “special” rules. We comply with the relevant guidelines issued by the Australian Privacy Commissioner. These are available from the Office of the Australian Information Commissioner’s (OAIC) website: www.oaic.gov.au
Sensitive information is a class of information that is a subset of personal information and is considered as particularly private. It means personal information which is also information or an opinion about an individual’s:
In addition, sensitive information means an individual’s health information and the individual’s:
We will only collect personal information (also refer to the paragraph below for details about how we handle sensitive information) about you where the information is reasonably necessary for the activities or functions, we undertake with or for you and/or as otherwise permitted by the Privacy Act. These activities and functions usually involve the purchase of an insurance policy and/or the settlement of an insurance claim or activities associated with the issuing of an insurance policy or paying a claim, such as reinsurance, loss investigation and/or adjustment. This may require us to collect personal information such as your name, age, gender and your employment details. If you are applying for a job with us, we may need personal information such as your qualifications and past occupations. If you are providing a personal guarantee to us related to a surety bond, we may need information about your financial status.
Where the personal information to be collected is also considered sensitive information, in addition to the above criteria, the information will only be collected if you consent to it being collected or as otherwise permitted by the Privacy Act. Our activities and functions may require us to collect sensitive information such as your health information. If you are applying for a job with us or if you are providing a personal guarantee to us, we may need sensitive information such as details of any criminal record.
There may be circumstances where we may collect sensitive information without your consent, as permitted under the Privacy Act, which circumstances broadly relate to:
In any of these circumstances we will only collect, hold and disclose this sensitive information in accordance with the Privacy Act.
We would usually only collect your personal information for one or more of the following purposes:
If we want to collect information for purposes other than those named above we will advise you of the reason we are collecting the information.
We will not generally adopt government related identifiers (such as Medicare numbers, driver licence numbers) as our own identifiers. We may however, use such identifiers where permitted under the Privacy Act. For example, assisting us in identifying you where this is reasonably necessary.
Under the Privacy Act, we may only collect personal information by lawful and fair means.
We will collect your personal information directly from you unless doing so is unreasonable or impracticable or you would expect us to collect the information from a nominated third party. For example, where you authorise a representative e.g. an insurance broker, a financial planner, a legal services provider or an agent or carer providing services to you to deal with us on your behalf, we may collect your personal information from your representative.
We might collect your personal information when you or your representative:
There may also be occasions when we collect your personal information from a third party or publically available source. This will only be where it is unreasonable or impracticable for us to collect directly from you. Such sources include:
If you provide personal information to us about another person, particularly if you are acting on behalf of someone else, we proceed on the understanding that in collecting the information you have complied with Australian Privacy Principle 5 Notification of the Collection of Personal Information. Where sensitive information is involved, we proceed on the understanding that you have obtained the person’s consent to collection of the information, or you were otherwise able to collect the information under the Privacy Act. If you have not done, or will not do, either of these things, you must tell us before you provide the relevant personal information to us.
Where we have collected personal information, we may hold it:
Your personal information will only be available to members of our staff who require access for one or more of the purposes we have disclosed. For example, to our claims team when you make a claim under an insurance policy or our surety team if you are providing a personal guarantee or the appropriate managers if you are applying for a job. How we might disclose your information to a third party is outlined in section 6 of this policy.
We may use cookies which are small data files transferred onto your computer or device when you visit our website for record-keeping and to enhance the functionality on the website. Most browsers allow you to choose whether to accept cookies or not. If you do not wish to have cookies placed on your computer, you should set your browser preferences to reject all cookies before accessing our website.
In some circumstances, we will deal with you without you having to identify yourself, or where you adopt a pseudonym in your dealings with us. For example, this would apply where you access general information on our products and services through our website or making initial enquiries about a job we are advertising. However, in most cases it would be impracticable for us to provide the product, service or information you require or consider your application for a job with us unless we have identified you. For example, an insurance contract is provided in accordance with the Insurance Contracts Act 1984 which requires both parties to act in good faith and disclose facts pertinent to issuing an insurance policy or paying a claim.
In some circumstances we may also be required or authorised by law to identify you, for example anti-money laundering laws which require us to sight and record details of certain documents in order to meet the standards set under those laws.
If we receive personal information that we did not solicit (that is, we did not actively seek the information) we will, within a reasonable period after receiving the information, determine whether we could have collected the information in accordance with this privacy policy if we had actively sought the information. If we determine we could not have collected the information in accordance with this privacy policy we will, as soon as it is practicable to do so, destroy or de-identify the information if it is lawful and reasonable to do so. If we determine that we could have collected the information in accordance with this privacy policy, we will hold the information in accordance with the relevant terms of this policy.
We will normally only use personal information for the particular purpose for which it was collected. This would usually involve the purchase of an insurance policy and/or the settlement of an insurance claim, or activities associated with the issuing or administrating of an insurance policy or paying a claim, such as reinsurance, loss investigation and/or adjustment. If you apply for a job with us, the information will be used in the consideration of your application. If you are providing a personal guarantee, we will use the information to assess your financial status.
We may also use personal information for a secondary purpose, but only with your consent or as otherwise permitted under the Privacy Act. For example, where you would reasonably expect us to do so and the secondary purpose is related (or, in the case of sensitive information, directly related) to the primary purpose.
The following are examples of when we might disclose your personal information and to which business partners:
The majority of information is retained within Australia, but there may be instances where your personal information may be disclosed to and stored by related bodies corporate, business partners, reinsurers and service providers that may be located overseas. Those recipients are usually based in the USA, Canada, Bermuda, Europe (including the United Kingdom), South Africa, Singapore and Hong Kong but may be any country in the world. The overseas countries will have a different data protection regime to that of Australia. The types of personal information we may send to them would usually be associated with an insurance policy you have with us or a claim you are making on an insurance policy such as, name, address, date of birth, occupation, financial status or if a claim is for personal injury, your health details. We will always disclose and collect your personal information in accordance with privacy laws, and only to the extent it is necessary to perform our functions or activities.
We may use your information for marketing but only as permitted by the Privacy Act.
We take reasonable steps to ensure that personal information we collect, hold, use and disclose is accurate, up-to-date, complete and relevant.
We are committed to keeping secure the personal information provided to us. We take all reasonably necessary steps to protect the personal information we hold about you from misuse, interference and loss and from unauthorised access, modification or disclosure. We have a range of practices and policies in place to provide a robust security environment. We will ensure the ongoing adequacy of these measures by regularly reviewing them. Our security measures include but are not limited to:
You are generally entitled to access the personal information we hold about you. If you wish to access this information we ask that you put this in writing as this will help identify you and assist us in identifying your policy and/or claim number(s) and/or the type of information you wish to access.
We will respond to your request for access as soon as possible (we aim to do so within 30 days) and are required to do so within a reasonable period. The time we need to process your request will depend on the type of information you have requested. There may be circumstances where you are not entitled to access the personal information, such as where:
If we are not able to give you access to the personal information we hold about you we will give you reasons as to why we are unable to provide you with access.
You should address your request to, The Privacy Manager:
By post at: Enthusiast Underwriting Pty Ltd, PO Box R299, Sydney, NSW 1225, or
By email at: PrivacyIssues@enthusiast.com.au or
By phone on: 1800 10 10 44
If you believe we have made an error or breached this policy and/or the Privacy Act you may make a complaint to our Privacy Manager by:
Post at: Enthusiast Underwriting Pty Ltd, PO Box R299, Sydney, NSW 1225,
Email at: PrivacyIssues@enthusiast.com.au, or
Phone on: 1800 10 10 44
Our Privacy Manager will review your complaint, consider the facts and aim to resolve the complaint to your satisfaction as quickly as possible. This process must be completed within 30 calendar days.
If you are not satisfied with our review, you may take your complaint to the Australian Financial Complaints Authority (AFCA) which is a recognised external dispute resolution scheme. You can contact AFCA by:
Phone on: 1800 931 678 (free call)
Post at: Australian Financial Complaints Authority, GPO Box 3, Melbourne VIC 3001
Email at: info@afca.org.au.
Lastly, the Office of the Australian Information Commissioner also has the power to investigate complaints and recommend appropriate action to remedy your complaint. You can contact the Commissioner by:
Phone on: 1300 363 992,
Post at: The Privacy Commissioner at, GPO Box 5218, Sydney 2001, or
Email at: enquires@oaic.gov.au.
We do not believe that there is a time when we can safely say we no longer need to hold your personal information. Insurance claims can be made many years after a policy has expired or a claim can be reopened many years after it was originally closed. For example, for an injury occurring to a child, a claim could be made up to at least 24 years after the injury occurred. For some types of insurance the claim is made on the date it is discovered not when the injury or action occurred. This could conceivably be in 40 or 50 years-time.
The Federal Insurance Regulator, the Australian Prudential Regulation Authority and potential claimant’s expect insurers to be able to pay all valid claims whenever they are made. We could not say with certainty we could do this if we destroyed or de-identified any of the personal information we hold.
We take the precautions outlined in section 9 for all personal information we hold regardless of how old it is.
Our website may contain links to websites that are not owned or controlled by Enthusiast Underwriting Pty Limited. Whilst such links are provided for your convenience, you should be aware that the information handling practices of the linked websites might not be the same as ours.
This policy will be reviewed periodically with the current policy available on our website.
We are currently experiencing some issues with our internal systems, we are currently investigating into it. You can still do a quote online by clicking our “Get a quote” option, or for urgent matters you can email us at motor@enthusiast.com.au or use the contact form on our Contact page.