Policy number 202601
Version 1
Approved by Board on 20 July 2026
Scheduled review date 20 July 2027
1.1 This Privacy Policy (Policy) explains how Craft Queensland Limited trading as artisan (artisan, we, us, our) collects, holds, uses and discloses your personal information, including in connection with the artisan associates membership program, the artisan maker directory, our programs, exhibitions, grants, events and our use of third party service providers.
1.2 artisan is committed to protecting your privacy. Trust is central to our relationship with the Queensland makers, designers, First Nations Art Centres, collectors, members, donors, funders and members of the public who engage with our work.
1.3 Privacy Legislation means the Privacy Act 1988 (Cth) including the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and any amendments to that Act, together with any other applicable Commonwealth, state or territory privacy law.
1.4 artisan notes that the Privacy Act 1988 (Cth) is subject to ongoing reform under the Privacy and Other Legislation Amendment Act 2024 (Cth), with further tranches of reform anticipated.
(a) Changes commencing from December 2024 include a statutory tort for serious invasions of privacy, a Children's Online Privacy Code, expanded enforcement powers for the Office of the Australian Information Commissioner (OAIC), and new transparency requirements for automated decision-making.
(b) artisan will update this Policy as further reforms are enacted. The CEO is responsible for monitoring legislative change and recommending updates to the Board (see clause 14).
1.5 In this Policy, personal information, sensitive information and related terms have the meanings given in the Privacy Act 1988 (Cth).
1.6 This Policy applies to all individuals and entities who interact with artisan, including (but not limited to) artisan associates members, maker directory listees, employees, contractors, volunteers, Board members, donors, funders, event attendees, workshop participants and visitors to our website.
1.7 We may update this Policy from time to time in accordance with legislative or operational change. The current version is published at artisan.org.au/privacy. If you would like a copy, or have comments or questions, please contact us using the details in clause 13.
2. Purpose and Application
2.1 The purpose of this Policy is to provide a clear framework for how artisan deals with privacy considerations across all of its activities, and to meet our obligations under the Privacy Act 1988 (Cth).
2.2 This Policy applies to personal information collected through, but not limited to:
• the artisan associates membership program (membership applications, tier eligibility, renewals and member communications);
• email newsletter subscriptions, including subscribers who have no membership or directory relationship with artisan;
• the artisan maker directory (public-facing listings of makers' names, practice descriptions and contact details);
• artisan’s website, including cookies and usage data;
• programs, workshops, exhibitions, grants and events;
• donations, sponsorships and fundraising activity;
• employment, contracting and volunteering with artisan;
• artisan’s use of third party service providers, including payment processors, email and membership management platforms, and the insurer providing the optional public liability insurance add-on referred to in the artisan associates terms and conditions.
2.3 Where a specific program or activity has its own published terms (for example, the artisan associates membership terms and conditions), those terms should be read together with this Policy. Where there is any inconsistency, this Policy prevails on privacy matters.
3. Types of Information We Collect
3.1 The information we collect depends on the nature of a person's involvement with artisan. We only collect personal information that is reasonably necessary for, or directly related to, our functions and activities, or that we are required to collect by law.
3.2 Depending on the reason for collection, this may include:
• name and contact details (postal address, email address, phone number);
• membership tier and eligibility information (for example, evidence of enrolment for the Student Maker tier, or organisational details for the Industry / Group tier);
• payment information and banking details, where you make a payment to artisan (membership fees, donations, ticketing, the optional insurance add-on);
• maker directory content you choose to provide for public listing, including your practice description, images, biography and the contact details you nominate for publication;
• identification documentation, where reasonably required (for example, to verify Student Maker eligibility or to comply with grant or funding conditions);
• information contained in applications, forms, grant submissions or feedback;
• usage data from our website, including IP address, pages visited, referring websites, device information and general location, collected via cookies and log files;
• for Industry / Group members, the names and contact details of nominated individuals receiving Professional Maker benefits;
• for email newsletter subscribers who are not otherwise a member, directory listee or program participant, generally only an email address and, where voluntarily provided, a name.
3.3 Sensitive information. In limited circumstances we may collect sensitive information, such as information about cultural or racial heritage (relevant to First Nations maker partnerships and cultural protocols) or health information (for example, accessibility requirements for an event). We only collect sensitive information with consent, or where the collection is otherwise permitted by law, and we limit the amount of sensitive information we collect to what is reasonably necessary.
3.4 You are not required to provide the personal information we request. However, if you choose not to, we may not be able to process your membership application, provide a maker directory listing, process a payment, or otherwise deliver the relevant service.
4. How We Collect Information
4.1 We collect personal information only by lawful and fair means, including by telephone, email, post, through forms on our website, or through the artisan associates membership portal.
4.2 Wherever reasonable and practicable, we collect personal information directly from you.
4.3 We may also collect personal information:
• from an Industry / Group member organisation, regarding its nominated individuals;
• from a parent or guardian, where a member is under 18 and consent has been obtained in accordance with our membership terms;
• from third party service providers we engage to deliver our services (for example, a payment processor confirming a transaction);
• through cookies and log files on our website. You can block or delete cookies through your browser settings and still use most of our website, although some functions (such as the member portal) may require you to log in each time.
4.4 We generally obtain your consent to collect personal information. Consent may be given in writing, given orally, or implied through your conduct — for example, submitting a maker directory listing implies consent to the information in that listing being made public in accordance with clause 6.6.
5. Unsolicited Personal Information
5.1 If we receive personal information we did not request and determine we have no need for it, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
6. How We Use Your Personal Information
6.1 We use personal information for purposes including:
• processing membership applications, renewals and tier changes under the artisan associates program;
• administering and publishing the artisan maker directory;
• processing payments, including membership fees, the optional insurance add-on, donations and event ticketing;
• delivering programs, workshops, exhibitions, grants and events;
• communicating with you about your membership, including renewal reminders, benefit changes and policy updates;
• sending newsletters and marketing communications about artisan’s programs and Queensland craft and design more broadly, where you have consented or as otherwise permitted by clause 9;
• responding to enquiries, feedback and complaints;
• meeting funding, grant acquittal and reporting obligations to government and other funders;
• screening for and preventing fraudulent, illegal or abusive activity, including in relation to membership eligibility (for example, verifying Student Maker enrolment);
• complying with our legal obligations, including under the Australian Charities and Not-for-profits Commission Act 2012 (Cth) and the Corporations Act 2001 (Cth).
6.2 We only use or disclose personal information for the purposes set out above, for purposes you would reasonably expect, for purposes you consent to, or as otherwise required or authorised by law.
6.3 Maker directory and public listings.
(a) If you receive a listing in the artisan maker directory, the practice description, images, biography and contact details you nominate for publication will be publicly accessible on the artisan website. By submitting directory content, you consent to this public disclosure.
(b) You may request that your directory listing be updated or removed at any time by contacting us under clause 13. artisan may also edit or remove a listing that does not comply with artisan’s directory policies, consistent with the artisan associates terms and conditions.
(c) Where artisan provides promotional support for a member, including via the directory or social media, the member grants artisan a non-exclusive, royalty-free licence to use the images, descriptions and biographical information provided, for the purpose of promoting the member's work and artisan’s programs, for the duration of membership. artisan will cease use of this material within a reasonable time of cancellation or expiry, consistent with clause 10.2 of the artisan associates terms and conditions.
(d) Additional care applies to content concerning First Nations makers, designs, stories or Indigenous Cultural and Intellectual Property (ICIP). Such content will only be used, displayed or shared with the express consent of the relevant maker or Art Centre, consistent with artisan’s commitments to First Nations cultural protocols.
6.4 If you submit content to a public area of our website (for example, a public forum or comment field), it will be visible to the public and we may reuse or republish it. If you ask us to remove such content, we will do so promptly where practicable.
6.5 If you have concerns about how we are using your personal information, please contact us immediately using the details in clause 13.
7. How We Store and Protect Your Information
7.1 We hold personal information in electronic databases (including our membership management system), email systems, and, where necessary, paper files held in secure offices.
7.2 We take reasonable steps to:
• keep personal information accurate, up to date, complete and relevant;
• protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure;
• destroy or de-identify personal information that is no longer needed, except where we are required to retain it for legal, regulatory, contractual or grant-acquittal purposes (see artisan’s Records Management Policy).
7.3 Any personal information accessible through your artisan associates member account is password-protected. You must not share your password, and artisan will never ask for your password by phone or email.
8. Accessing and Correcting Your Personal Information
8.1 You may ask us to confirm what personal information we hold about you, to access it, or to correct it, by contacting us under clause 13.
8.2 We will respond within a reasonable period and within any timeframe required by the Privacy Act. Urgent requests should state the reason for urgency.
8.3 We may ask you to verify your identity before providing access.
8.4 We will provide access unless there is a sound reason not to — for example, where access would unreasonably impact another person's privacy, where a request is frivolous or vexatious, or where access is not permitted under the Privacy Act. If we refuse access, we will explain why.
8.5 If you believe information we hold about you is incorrect or out of date, we will take reasonable steps to correct it on request.
9.1 We will only contact you about artisan’s products, programs or services where you have consented, or as otherwise permitted by law. This may be by email, SMS, post or telephone, consistent with clause 11 of the artisan associates terms and conditions.
9.2 We do not sell or rent your personal information to any third party for direct marketing purposes.
9.3 You can opt out of marketing communications at any time by using the unsubscribe link in our emails, or by contacting us under clause 13. Your consent to marketing remains current until you opt out.
9.4 We do not use sensitive information for direct marketing purposes.
9.5 Email subscribers. Some individuals subscribe to artisan’s email updates without otherwise being an artisan associates member, maker directory listee, donor or program participant.
(a) Where you subscribe only to receive our updates, we collect and hold the minimum information necessary for that purpose, generally limited to your email address and, where you choose to provide it, your name.
(b) When you subscribe, we explain that you will receive regular news, event invites, details of opportunities for Queensland craftspeople and designers, and profiles of practitioners artisan represents. Inviting you to become an artisan associates member falls within this scope, as membership is itself an opportunity relevant to Queensland craftspeople and designers. We will not use subscriber-only data for purposes outside this scope (for example, unrelated commercial offers, or sharing your details with a third party for their own marketing) unless you separately consent.
(c) You can unsubscribe at any time using the unsubscribe link in any email update, or by contacting us under clause 13. We will action unsubscribe requests promptly and will not send further marketing communications once you have opted out, other than a confirmation of your unsubscribe request where reasonably necessary.
(d) If our subscriber list is held or managed by a third party email platform provider, that arrangement is covered by clause 10 (Third Party Service Providers) of this Policy.
10. Third Party Service Providers
10.1 artisan engages third party service providers (sub-processors) to support our website, membership management, payment processing, email communications and the optional public liability insurance add-on available to eligible artisan associates members.
10.2 Current categories of third party service providers include:
• payment processors, for membership fees, donations, ticketing and the insurance add-on;
• membership management and email platform providers, used to administer the artisan associates program and member communications;
• the insurer providing the optional public liability insurance add-on under a group policy arranged by artisan (see clause 5.7–5.10 of the artisan associates terms and conditions). artisan is not the insurer; the insurer separately collects and handles information relevant to that policy under its own privacy terms;
• IT hosting and cloud storage providers.
10.3 We select service providers on the basis of their published privacy policies and put in place appropriate data-handling arrangements. We do not sell or rent your personal information to service providers; we share only what is reasonably necessary for them to perform their function.
10.4 Some service providers may be located overseas, or may use overseas infrastructure (for example, cloud hosting). Where personal information is disclosed to an overseas recipient:
• we will take reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles in relation to that information, except where an exception under APP 8.2 applies (for example, you have consented to the disclosure, or the recipient is subject to a law or binding scheme that has the effect of protecting the information in a way that, overall, is at least substantially similar to the APPs);
• by using artisan’s services, you acknowledge that overseas service providers may not be required to protect your personal information to the same standard as the Privacy Act, and that artisan will take reasonable steps, but cannot guarantee, equivalent protection;
• we will disclose in this Policy, and update as it changes, the general location of any overseas recipients where reasonably practicable: <<insert details once confirmed — for example, cloud hosting location, payment processor jurisdiction>>.
10.5 Questions about our use of third party service providers can be directed to us under clause 13.
11. Notification of a Data Breach
11.1 If we become aware of unauthorised access to, or loss of, your personal information that is likely to result in serious harm, we will:
• assess the breach in accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth);
• notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where required;
• investigate the cause and take reasonable steps to remedy the consequences;
• advise the steps taken to prevent recurrence.
11.2 This is consistent with artisan’s broader incident response arrangements, including the Critical Incident Response Procedure and the AI Acceptable Use Policy (which addresses data handling risks specific to AI tools).
11.3 Further information on the NDB scheme is available at oaic.gov.au/privacy/notifiable-data-breaches.
12.1 If you have a complaint about how we collect or handle your personal information, contact us using the details in clause 13. We take privacy complaints seriously and aim to respond within seven days of receiving a complaint.
12.2 If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner at oaic.gov.au.
13.1 For any queries about how we handle your personal information, please contact our Privacy Officer:
• Phone: 07 3215 0800
• Email: coordinator@artisan.org.au
14. Governance and Review
14.1 This Policy is approved by, and may only be amended by, the Board of artisan.
14.2 The CEO is responsible for implementing this Policy, monitoring changes in Privacy Legislation (including the ongoing Privacy Act 1988 (Cth) reforms), and recommending review or revision to the Board as needed.
14.3 This Policy will be reviewed at least every 12 months, or earlier if there is a material change to Privacy Legislation, artisan’s operations, or the third party service providers relied on under clause 10.
14.4 Related artisan policies. This Policy should be read together with:
• the artisan associates membership terms and conditions, particularly clause 11 (Privacy);
• the Acceptable Use of Artificial Intelligence policy, particularly its data handling and privacy provisions;
• the Records Management and Document Retention Policy;
• the Critical Incident Response Procedure.
Appendix: Sources Referenced
|
Source
|
Relevance
|
Reference
|
|
Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs)
|
Primary Commonwealth legislation governing collection, use, disclosure, storage, access and correction of personal information by APP entities, including not-for-profit organisations meeting the relevant threshold or otherwise opting in.
|
legislation.gov.au
|
|
Privacy and Other Legislation Amendment Act 2024 (Cth)
|
First tranche of Privacy Act reform, including a statutory tort for serious invasions of privacy, a Children's Online Privacy Code, and expanded OAIC enforcement powers. Commenced progressively from December 2024. Further reform tranches were anticipated at time of drafting and should be checked.
|
oaic.gov.au
|
|
Notifiable Data Breaches (NDB) scheme — Part IIIC, Privacy Act 1988 (Cth)
|
Mandatory notification obligations for eligible data breaches likely to result in serious harm.
|
oaic.gov.au/privacy/notifiable-data-breaches
|
|
Australian Privacy Principle 8 (Cross-border disclosure)
|
Governs disclosure of personal information to overseas recipients, including the artisan third party service providers and group insurer referred to in this Policy.
|
oaic.gov.au/privacy/australian-privacy-principles
|
|
artisan associates membership terms and conditions (draft v1.0)
|
Source for membership tier structure, maker directory consent provisions (clause 11), third party service provider categories (payment processor, insurer, membership/email platforms), and IP/promotional licence terms (clause 10) reflected in this Policy.
|
Internal document
|
|
Office of the Australian Information Commissioner (OAIC) — Privacy guidance for not-for-profit and community organisations
|
General guidance on privacy obligations for the not-for-profit sector, including small business and NFP-specific exemptions and their limits.
|
oaic.gov.au
|
|
ICDA (Institute of Community Directors Australia) — Editable Policy Bank
|
Reference framework used to structure artisan’s broader policy suite. The Privacy Policy template structure (Policy / Procedures split, Board vs CEO authorisation) used in this draft is adapted from the Our Community / ICDA template.
|
communitydirectors.com.au/tools-resources/policy-bank
|