Privacy Policy

WCG Group Pty Ltd T/A WCG Security Electrical Data, referred to in this Privacy Policy as WCG Security, we, us or our, is committed to protecting personal information and managing privacy in an open, transparent and secure manner.

This Privacy Policy explains how we collect, use, hold, disclose and protect personal information in connection with our security services, including security system installation, maintenance, alarm monitoring, CCTV, access control, duress systems, patrol services, service works, client support and related business activities.

WCG Security is required to comply with the Privacy Act 1988 (Cth), including the Australian Privacy Principles.

1. Personal information we collect

We may collect personal information that is reasonably necessary for our business functions and activities. This may include:

  • Name, job title, company name and contact details.
  • Email address, phone number and postal address.
  • Site address, service address and access-related details.
  • Client, contractor, employee, visitor or authorised user information.
  • Emergency contact details, call-out lists and authorised contact lists.
  • Account, billing and payment-related information.
  • Alarm user names, user numbers, access permissions and system-related identifiers.
  • Alarm event records, monitoring records, call notes and incident details.
  • CCTV footage, still images or video extracts where we are authorised to access, review, retrieve, maintain or manage CCTV systems.
  • Access control records, door activity logs, swipe card records and entry/exit information.
  • Duress, panic alarm, intercom and security response records.
  • Patrol records, incident reports, key register records, visitor records and site attendance information.
  • Service requests, job notes, technician reports and correspondence.
  • Technical information relating to security devices, networks, systems, software and infrastructure.
  • Information required to verify identity, authority, access permissions or site instructions.

We may also collect sensitive information in limited circumstances and only where permitted by law. This may include information contained in incident records, emergency response records, workplace safety information, CCTV footage or other security-related records where it is reasonably necessary for security, safety, legal compliance or incident response.

2. How we collect personal information

We may collect personal information directly from you when you:

  • Contact us by phone, email, post or in person.
  • Request a quote, service, support, monitoring or maintenance arrangement.
  • Enter into a contract or service arrangement with us.
  • Provide information to our control room, administration team, technicians, management or support staff.
  • Attend or interact with a site where we provide security services.
  • Use or are recorded by a security system, access control system, alarm system, intercom, duress system or CCTV system that we are authorised to operate, monitor, support or maintain.
  • Apply for employment, subcontractor work or other business engagement with WCG Security.

We may also collect personal information from third parties, including:

  • Clients, property owners, facility managers and authorised site representatives.
  • Employers, building managers, managing agents and contractors.
  • Security, alarm, CCTV, access control, monitoring and job management platforms.
  • Emergency services, law enforcement agencies, regulators or government bodies.
  • Service providers, subcontractors, suppliers and professional advisers.
  • Publicly available sources, where appropriate and lawful.

Where a CCTV, alarm, access control, duress, intercom or monitoring system is owned or controlled by one of our clients, we may collect, access or process information as a service provider acting on behalf of that client.

Where lawful and practicable, you may deal with us anonymously or using a pseudonym. However, this will often not be practical for security services, monitoring, service works, access control, billing, incident response or legal and compliance matters.

3. Why we collect, use and disclose personal information

We collect, use and disclose personal information for purposes connected with our business, including to:

  • Provide security, monitoring, maintenance, patrol and technical support services.
  • Install, configure, repair, maintain and manage alarm, CCTV, access control, intercom, duress and related security systems.
  • Respond to alarm events, faults, incidents, duress activations and service requests.
  • Verify authorised users, site contacts, access permissions and site instructions.
  • Manage keys, access cards, credentials, user codes and authorised contacts.
  • Communicate with clients, contractors, site representatives and authorised contacts.
  • Prepare quotes, invoices, service reports, job records, compliance records and other business documents.
  • Manage client accounts, contracts and service arrangements.
  • Investigate incidents, system faults, complaints, unauthorised activity or safety concerns.
  • Support emergency response, law enforcement requests, insurance matters or legal obligations.
  • Maintain records for operational, compliance, audit, insurance, legal and accounting purposes.
  • Improve our services, systems, internal processes and operational procedures.
  • Recruit employees, engage contractors and manage workplace-related matters.
  • Protect the safety, security and integrity of people, property, assets, systems and information.

We will not use personal information for purposes unrelated to our business functions unless permitted by law or with your consent.

4. CCTV, surveillance and client-managed security systems

Due to the nature of our business, WCG Security may handle CCTV footage, alarm events, access logs, intercom records, duress activations and other security-related information.

This information may be collected, accessed, retrieved, exported or reviewed when:

  • We operate, monitor, maintain or support a system on behalf of a client.
  • We install, configure, test, repair or troubleshoot a security system.
  • We investigate a fault, alarm event, incident or service request.
  • We are authorised to retrieve or export footage, logs or event records.
  • We are required to provide information to an authorised client representative, emergency service, insurer, legal adviser, regulator or law enforcement agency.

WCG Security may access, retrieve, review or export CCTV footage, alarm records, access logs and related security information where authorised by the client, required for service delivery, required for incident response, or permitted by law.

WCG Security does not directly operate facial recognition, licence plate recognition, biometric access control or AI-assisted video analytics for its own purposes. Some clients may use these technologies on systems they own or control. Where this occurs, the client is responsible for the collection, storage, management and use of the related data, unless WCG Security is separately engaged to provide a specific service in relation to that system.

Where WCG Security handles footage, logs or security records on behalf of a client, the client may also have its own privacy obligations and privacy policy. Individuals seeking access to footage or records from a client-controlled system may need to contact the relevant site owner, occupier, employer or system owner.

WCG Security does not use CCTV footage, access control records, alarm events or security system records for marketing purposes.

5. Website privacy

At the time of publication, WCG Security does not knowingly use website analytics, tracking pixels, online enquiry forms or non-essential cookies.

If this changes, this Privacy Policy will be updated to explain what information is collected through the website and how that information is used.

Basic technical information may still be processed by website hosting, security or infrastructure providers as part of normal website operation, maintenance and security.

6. Disclosure of personal information

We may disclose personal information where reasonably necessary for our business operations, service delivery or legal obligations, including to:

  • Clients and their authorised representatives.
  • Property owners, facility managers, building managers and managing agents.
  • Our control room, monitoring personnel and response providers.
  • Technicians, contractors, subcontractors, installers and service partners.
  • Security software, alarm, CCTV, access control, telecommunications and cloud service providers.
  • IT, email, hosting, accounting, job management and payment service providers.
  • Emergency services, police, regulators, courts, tribunals or government agencies.
  • Insurers, legal advisers, auditors and professional advisers.
  • Debt collection or credit management providers, where applicable.
  • Authorised personnel, contractors, subcontractors and service providers, including personnel located outside Australia, where reasonably necessary for monitoring, administration, technical support, reporting, service delivery and client support.

We will only disclose personal information to the extent reasonably required for the relevant purpose.

7. Support personnel and service providers

WCG Security may use authorised personnel, contractors, subcontractors and service providers located in Australia or overseas to assist with security monitoring, administration, technical support, reporting, client support, service delivery and related business operations.

These personnel and providers may access personal information where reasonably necessary to perform authorised work for WCG Security. This may include client contact details, alarm event records, monitoring records, site instructions, service information, access control records, CCTV-related records and other operational information relevant to our services.

WCG Security takes reasonable steps to protect personal information accessed by authorised personnel, contractors, subcontractors and service providers. These measures may include role-based access permissions, multi-factor authentication, access logging, audit trails, confidentiality obligations, internal procedures and restrictions on unauthorised use, downloading, disclosure or copying.

WCG Security requires authorised personnel, contractors, subcontractors and service providers to handle personal information only for approved WCG Security business purposes and in accordance with applicable privacy, confidentiality and information security requirements.

The location of personnel and service providers may vary depending on operational requirements. Further information about access arrangements may be requested by contacting the WCG Security Compliance Department.

Personal information is not sold to third parties. Personal information is only accessed, used or disclosed where reasonably necessary for our business functions, service delivery, client instructions, legal obligations, emergency response, security purposes or another purpose permitted by law.

8. Security of personal information

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.

These steps may include:

  • Restricting access to systems and records.
  • Using passwords, user permissions, role-based access controls and multi-factor authentication.
  • Maintaining user access logs, audit trails and access monitoring where appropriate.
  • Storing electronic and physical records securely.
  • Limiting access to personal information on a need-to-know basis.
  • Applying confidentiality obligations to staff, contractors and service providers.
  • Restricting unauthorised downloading, copying, disclosure or secondary use.
  • Using secure systems where appropriate.
  • Maintaining operational procedures for handling security-related information.
  • Reviewing and improving information security practices where required.
  • Removing access when personnel no longer require it.
  • Securely destroying or de-identifying information when it is no longer required, where lawful and practicable.

9. Retention of personal information

We retain personal information for as long as reasonably required for the purpose for which it was collected, including for operational, legal, insurance, accounting, audit, contractual and compliance purposes.

Security-related records, such as CCTV footage, alarm events, monitoring records, access logs and service notes, may be retained for different periods depending on:

  • The relevant client agreement.
  • The system configuration.
  • Legal, regulatory, insurance or contractual requirements.
  • Incident investigation requirements.
  • Operational and technical requirements.
  • The data retention settings of client-owned or third-party systems.

Exported footage, reports, logs or records may be retained where required for service delivery, incident management, legal, insurance, client, compliance or operational purposes.

When personal information is no longer required, we will take reasonable steps to securely destroy or de-identify it, unless we are required or permitted by law to retain it.

10. Accessing and correcting your personal information

You may request access to personal information we hold about you. You may also request correction if you believe the information is inaccurate, out of date, incomplete, irrelevant or misleading.

To request access or correction, please contact us using the details below.

We may need to verify your identity before processing your request. In some circumstances, we may refuse access or correction where permitted by law, including where the information relates to security operations, legal proceedings, an investigation, another person’s privacy, or information controlled by one of our clients.

Where the information is held in a client-controlled system, we may direct you to the relevant client, site owner, employer or system owner.

We will aim to respond to access and correction requests within a reasonable timeframe.

11. Data breaches

If we become aware of a data breach involving personal information, we will take reasonable steps to contain, assess and respond to the breach.

This includes incidents involving WCG Security systems, personnel, contractors, subcontractors, service providers or authorised support personnel.

Where the Notifiable Data Breaches scheme applies and a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner where required.

12. Direct marketing

We may use your contact details to send service updates, business communications or information about our services where permitted by law.

You may opt out of direct marketing communications at any time by contacting us or using the unsubscribe option where provided.

We do not sell personal information to third parties for marketing purposes.

13. Employment and contractor information

We may collect personal information from job applicants, employees, contractors and subcontractors for recruitment, onboarding, engagement, compliance, safety, payroll, rostering, performance management and related workplace purposes.

Employee records may be handled in accordance with applicable employment, workplace and privacy laws.

14. Complaints and privacy enquiries

If you have a privacy-related question, concern or complaint, please contact us first so that we can review and respond to the matter.

We will aim to respond within a reasonable timeframe.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.

Privacy ContactWCG Security Compliance Department
OrganisationWCG Group Pty Ltd T/A WCG Security
AddressUnit 7, 289-295 Princes Highway
Unanderra NSW 2526
Emailcompliance@wcgsecurity.com.au
Phone02 4226 1966

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business, services, systems, legal obligations or privacy practices.

The updated version will be published on our website with the revised date.