Privacy

1. Purpose of This Document 

This policy explains how BMW Club Queensland protects member information and outlines the responsibilities of all members, especially those serving on the committee. It ensures that personal data is handled lawfully, securely, and respectfully. 

2. Commitment to Privacy 

BMW Club Queensland is committed to safeguarding the privacy of all members. Personal information is collected only for legitimate club purposes and is never sold, shared, or disclosed outside the organisation unless required by law. 

3. What Information We Collect 

The club may collect and store the following types of information: 

  • Contact details — name, address, phone number, email 

  • Membership details — membership status, renewal dates 

  • Vehicle information — model, year, registration (optional) 

  • Event participation — attendance, volunteer roles 

  • Committee-related information — roles, responsibilities, access permissions 

This information is used solely for club administration, communication, event management, and legal compliance. 

4. How Member Data Is Stored 

Member data is stored using secure, access-controlled systems. These may include: 

  • Membership databases 

  • Email distribution systems 

  • Cloud-based document storage 

  • Financial systems for membership payments 

Access is restricted to authorised committee members only, based on their role and responsibilities. 

5. Responsibilities of Committee Members 

Committee members are entrusted with elevated access to member information. They must: 

  • Use member data only for official club purposes 

  • Keep all information confidential 

  • Ensure data is not shared with unauthorised individuals 

  • Report any suspected data breach immediately to the President or Secretary 

  • Use secure passwords and devices when accessing club systems 

  • Avoid storing member data on personal devices unless necessary and protected 

Committee members must also return or delete all club data when their term ends. 

6. Acceptable Use of Member Information 

Member information may be used for: 

  • Membership administration 

  • Event planning and communication 

  • Club newsletters and announcements 

  • Legal or insurance requirements 

  • Emergency contact purposes during events 

It must not be used for: 

  • Personal gain 

  • Marketing unrelated to the club 

  • Sharing with third parties without approval 

  • Any activity that violates privacy laws or club rules 

7. Data Security Practices 

To protect member information, the club follows these practices: 

  • Strong, unique passwords for all club accounts 

  • Two‑factor authentication where available 

  • Secure cloud storage with access logs 

  • Regular review of who has access to what data 

  • Removal of access when committee roles change 

  • Avoiding the use of unsecured public Wi‑Fi for club administration 

8. Data Breach Procedure 

If a data breach is suspected or confirmed: 

  1. The committee member must report it immediately to the President and Secretary. 

  1. Access to affected systems may be temporarily restricted. 

  1. The committee will assess the severity and take corrective action. 

  1. Members will be notified if their information is affected. 

9. Member Rights 

All members have the right to: 

  • Request access to their personal information 

  • Request correction of inaccurate information 

  • Request removal of their data when membership ends (where legally permitted) 

  • Ask how their information is stored or used 

10. Committee Acknowledgement 

All committee members must acknowledge that they: 

  • Understand this policy 

  • Agree to comply with all privacy and security requirements 

  • Accept responsibility for protecting member information 

11. Code of Conduct for Handling Member Information 

This Code of Conduct outlines the expected behaviour of all BMW Club Queensland members, with additional obligations for committee members who have elevated access to personal information. It ensures that all data is handled ethically, respectfully, and in line with legal and club standards. 

11.1 Respect for Privacy 

Members must respect the privacy of others at all times. Personal information shared within the club must remain confidential and used only for legitimate club activities. 

11.2 Appropriate Communication 

Members must not use member information to send unsolicited messages, marketing, or personal promotions. Communication must remain relevant to club activities, events, or responsibilities. 

11.3 Responsible Use of Data 

Members must not collect, store, or distribute personal information about other members unless authorised and necessary for a club function. Any data collected for an event or activity must be handled securely and deleted when no longer required. 

11.4 No Misuse of Access 

Committee members must not use their access to member information for personal benefit, influence, or any purpose outside their official duties. Access is granted strictly for operational needs. 

11.5 Professional Conduct 

Members and committee must act with integrity when handling data. This includes: 

  • Being honest about how information is used 

  • Avoiding gossip or sharing private details 

  • Treating all member information with the same care as their own 

11.6 Reporting Concerns 

Any member who becomes aware of inappropriate use of personal information must report it to the President or Secretary. Reports will be handled confidentially and investigated promptly. 

11.7 Compliance with Laws and Club Policies 

Members must comply with all relevant privacy laws, including the Australian Privacy Principles (APPs), and with all BMW Club Queensland policies relating to data protection and security. 

11.8 Consequences of Misconduct 

Breaches of this Code of Conduct may result in: 

  • Removal of access to club systems 

  • Formal warnings 

  • Suspension or termination of membership 

  • Additional action if required by law