Privacy Policy

‍El Rahman Inc.

Privacy and Consent Policy

Purpose 

El Rahman Inc.  is committed to upholding the privacy and security of personal information for all clients.

This Privacy and Consent Policy (the Policy) demonstrates our commitment to protecting clients’ right to privacy. It outlines the obligations that all leaders, employees, and volunteers must uphold.

This Policy also details how El Rahman Inc.  will respond to data breaches and privacy violations. 

Scope 

This Policy applies to all El Rahman Inc.  employees and volunteers. It also applies to third-party contractors and any employees or volunteers from external organisations who engage with El Rahman.

Policy Statement

El Rahman Inc.  is committed to protecting, promoting, and ensuring the privacy and security of all personal information it collects and holds.

Collecting and Handling Personal Information

El Rahman Inc.  collects personal information from clients to deliver its core services and activities. Personal information is also collected to comply with legal obligations and to support effective service delivery.

We collect a range of personal and sensitive information, including:

  • Name, date of birth, and gender

  • Contact details (phone number, email address, residential address)

  • Identification and eligibility information (e.g. health care card details, visa status)

  • Cultural and demographic information (e.g. Aboriginal or Torres Strait Islander status, nationality, country of birth)

  • Personal circumstances (e.g. housing situation, marital status, disability and medical information)

To verify identity and eligibility, we may request:

  • Photo identification

  • A recent bank statement (within the last three months)

  • A valid health care card

  • Visa Status documentation

Clients may also be asked to provide information about their circumstances and need for services, including personal hardship information. This information is collected through intake forms and recorded in secure systems.

Additional information may be collected for specific programs. For example, medical information and allergy details are collected for youth programs.

Storage and Access

Client information is stored securely in both electronic and hard copy formats:

  • Electronic records are stored on organisational systems (e.g. spreadsheets), with access restricted to authorised administrative staff

  • Hard copy records are stored in locked cabinets within secure office areas

  • Office spaces are secured outside of operating hours

Volunteer and employee records are also stored securely in both electronic and physical formats.

Use and Disclosure of Information 

Personal information is only used for the purpose for which it was collected, or for related purposes where appropriate.

El Rahman Inc.  will only share client information with external partners where:

  • The client has provided informed consent, and

  • Only relevant information is shared

For example, where a referral is made to an organisation such as the National Zakat Foundation (NZF), client consent will be obtained prior to sharing any information.

Data breaches 

El Rahman Inc.  takes all data breaches seriously.

  • External breaches (e.g. cyber incidents or malicious activity) may be escalated to relevant authorities, including police

  • Internal breaches (e.g. unauthorised access or disclosure by staff) will be treated as a breach of this Policy and may result in disciplinary action, including termination

All breaches will be managed promptly and appropriately to minimise harm. If a data Breach occurs whether internal or external, clients will be informed.

Reporting 

All employees, volunteers, and contractors must report any actual or suspected privacy breaches to:

complaints@elrahman.org.au or their manager.

Members of the public are also encouraged to report concerns via this email address or to any El Rahman Inc.  staff member or volunteer.

Related organisational policies and procedures/supporting material 

Child Safety and Wellbeing Policy 

Working Health and Safety Policy 

Legislative context 

El Rahman Inc.  complies with the Australian Privacy Principles, which are part of the Privacy Act 1988 (Cth). El Rahman Inc.  is also bound by the Privacy and Data Protection Act 2014 (Vic) (PDPA) and the Information Privacy Principles made under the PDPA and the Health Privacy Principles made under the Health Records Act 2001 (Vic).

Review 

El Rahman Inc.  will review this Policy every two years.

This policy was created on 22 Of May 2026.‍