How Global Registrar of Systems collects, uses, discloses and protects personal information — and the choices you have about it.
This policy applies to Global Registrar of Systems Pty Ltd (ABN 42 619 007 477) and its offices in Australia, New Zealand, Bangladesh and the Pacific — referred to in this document as “GRS”, “we” or “us”.
It covers personal information we handle about website visitors, enquirers, quote requesters, certified clients and their personnel, course participants, job applicants and other interested parties. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and with equivalent obligations in the other jurisdictions where we operate.
We collect only the information we need to deliver certification, inspection and training services and to run our business. Depending on how you deal with us, that may include:
Most information is collected directly from you — through our website forms, email, phone calls, applications for certification, audits and training sessions.
We may also collect information from third parties where it is reasonable to do so: from your employer or nominated representative, from accreditation bodies, from publicly available registers, and from referees you have nominated. Where we collect information about you from someone else, we take reasonable steps to make sure you are made aware of this policy.
We use personal information to:
We do not sell personal information, and we do not use it for automated decision-making that produces a legal effect for you.
As an accredited certification body we are required to allow our accreditation body — JAS-ANZ — and, where relevant, scheme owners and regulators to witness audits and to review our certification files. Audit records containing personal information may therefore be disclosed to assessors, who are bound by their own confidentiality obligations.
Certificate details necessary for public verification — organisation name, certificate number, standard, scope, status and validity dates — are published on our public register and may be shared with accreditation and IAF register services. This is a condition of accredited certification.
We may also disclose information where required by law, by court order, or to protect the safety of any person.
We use trusted third-party providers to operate our business — including cloud hosting, email delivery, document storage and payment processing. Some are located outside Australia. We disclose only what a provider needs to perform its function, we require them to protect it, and we take reasonable steps to ensure any overseas recipient handles it consistently with the Australian Privacy Principles.
All information obtained during an audit, inspection or certification activity is treated as confidential. Our personnel — employees, contract auditors, technical experts and committee members — sign confidentiality undertakings as a condition of engagement.
Where we are required by law or by our accreditation arrangements to release confidential information, we notify the client of the information provided unless we are prohibited from doing so.
Personal information is held in access-controlled systems with encryption in transit, role-based permissions and audit logging. Physical records are stored securely and destroyed once they are no longer required.
No transmission over the internet can be guaranteed to be completely secure. If we become aware of a data breach that is likely to result in serious harm, we will assess and notify it in accordance with the Notifiable Data Breaches scheme.
We retain certification records for at least one full certification cycle beyond expiry, or longer where our accreditation requirements or the law demand it. Quote and enquiry records are retained while there is an active commercial relationship and for a reasonable period afterwards. Unsuccessful job applications are retained for twelve months unless you ask us to remove them sooner.
When information is no longer needed for any purpose for which it may lawfully be used, we destroy or de-identify it.
You can ask for access to the personal information we hold about you, and ask us to correct anything inaccurate, out of date or incomplete. Write to certification@grscertification.com with enough detail for us to locate the record.
We respond to access requests within 30 days. There is no charge for making a request, though we may charge a reasonable fee for the cost of providing access. If we refuse access or a correction, we will tell you why in writing and explain how to have that decision reviewed.
If you believe we have breached the Australian Privacy Principles, contact us first at certification@grscertification.com or on 1300 007 477. Privacy complaints are handled by personnel independent of the activity concerned. We acknowledge every complaint within two business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you can refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au.
We review this policy periodically and will publish any updated version on this page with a revised effective date. Material changes affecting certified clients are also communicated directly.