Request accessible format of this publication.
Responsibilities within DCS
The DCS Privacy Officer
The DCS Privacy Officer is responsible for the PMP and for providing governance services. They lead a dedicated DCS Privacy Team and work with privacy leads across DCS. Privacy leads are the first point of contact within a DCS business area in all matters related to privacy.
The DCS Privacy Officer role is held by the Executive Director of the Governance, Risk and Assurance division.
The DCS Privacy Team
The DCS Privacy team is responsible for managing the DCS privacy management functions. These functions include providing guidance to DCS employees and service providers on their privacy obligations, and how to manage personal and health information in their day-to-day work. The Team is responsible for:
- developing, co-ordinating and embedding the:
- Privacy Management Plan
- Privacy Management Framework
- Data Privacy Incident Response Plan
- Privacy Partners Network
- periodically reviewing and updating the DCS privacy mandatory training
- consulting with the Privacy Commissioner on high-risk privacy programs or incidents
- ensuring relevant privacy documents are consolidated and made available through the DCS website.
- providing advice and endorsement to projects or system changes that involve the use or handling of personal information
- coordinating and, where appropriate, investigating privacy incidents, breaches and complaints.
Advice and evaluation
The DCS Privacy team, in collaboration with privacy leads, undertake a range of initiatives to ensure DCS employees and members of the public are informed of our privacy practices and obligations under privacy legislation.
The team provides advice to business areas to ensure new initiatives, projects and upgrades to systems involving personal information are designed in line with privacy legislation and expectations of our customers.
The team also continuously evaluates privacy practices, policies, and procedures to ensure they remain effective and identify, evaluate, and mitigate risks of potential non-compliance with privacy legislation.
We also have a Privacy Partners Network which includes representatives from across DCS. They meet regularly to discuss privacy and to identify opportunities for improvement.
Privacy risks are managed in line with the DCS Risk Management Framework. People leaders and privacy leads are responsible for systematically assessing privacy risks and ensuring those risks are controlled.