loader image

PRIVACY POLICY

 

1. Introduction

Chapman and Frazer Real Estate Pty Ltd, trading as Chapman and Frazer Commercial Real Estate (“we,” “us,” “our”), is committed to protecting the privacy of our clients and website visitors. This Privacy Policy outlines how we collect, use, disclose, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as well as relevant New South Wales State laws.

 

2. Collection of Personal Information

We may collect and hold the following types of personal information about you:

    • Identity Information: Legal names, profession, job title, employer name, organisation, gender, age, and date of birth.

    • Contact Information: Phone number, facsimile number, mailing or street address, and email address.

    • Payment and Transaction Information: Billing address, details about payments to and from you, bank account details, and records of products or services purchased.

    • Details of Products and Services: Information about products and services you have purchased or enquired about from us or our clients.

    • Employment-related Records: Job applications, education, employment history, salary, benefits, leave records, training, and performance evaluations.

    • General Administrative Records: Office administration records, enquiries, and complaints handling records.

    • Customer Records: Personal data collected in relation to customer membership applications, transactions, complaints, and enquiries.

  • Other Records: Administrative and program-related records containing personal data.
 

3. How We Collect Your Personal Information

We collect your personal information through various methods, including:

    • Directly from you when you access and use our website.

    • When you contact us by telephone, email, or post.

    • During conversations with our representatives.

    • When you provide us with your business card.

    • When you become our customer or enter into agreements with us.

    • When you submit payments to us.

  • When you request marketing materials or respond to marketing communications.
 

4. Purpose of Collecting, Holding, Using, and Disclosing Personal Information

We collect personal information to:

    • Provide products and services to you.

    • Send communications requested by you.

    • Update our records and keep your contact details accurate.

    • Respond to your enquiries and provide product or service information.

    • Provide access to protected areas of our website.

    • Conduct business operations, including sharing data with related corporate bodies, contractors, or third parties.

    • Comply with statutory and regulatory obligations.

    • Conduct internal and external audits.

    • Process and respond to complaints or legal obligations.

    • Conduct marketing, planning, and quality control activities.

    • Process job applications.

If we intend to use your personal information for any purpose other than those described in this policy, we will obtain your consent.

 

5. Disclosure of Personal Information

We may disclose your personal information to:

    • Our employees, contractors, service providers, and related corporate entities.

    • Clients, suppliers, and third parties with whom we have business relationships.

    • Professional advisers such as lawyers, accountants, and auditors.

    • Third-party service providers, including payment system operators, IT suppliers, marketing services, and web hosting providers.

    • Courts, law enforcement agencies, and government regulators.

  • Any authorised entities with your express consent.
 

6. Direct Marketing Materials

We may send you direct marketing communications regarding our or our clients’ products and services that may be of interest to you. These communications may be sent via mail, SMS, fax, or email, in compliance with the Spam Act 2003 (Cth).

You may opt out of receiving marketing communications at any time by contacting us or using the provided opt-out options.

 

7. Security of Personal Information

We take reasonable steps to protect your personal information from misuse, loss, unauthorised access, modification, or disclosure. Personal information is stored in electronic and/or hard copy form and is securely destroyed or de-identified when no longer needed.

 

8. Access to and Correction of Personal Information

You have the right to access and correct the personal information we hold about you. To request access, updates, or corrections, please contact us using the details provided below. We will respond within a reasonable timeframe.

 

9. Cookies and Website Analytics

Our website may use cookies and tracking technologies to enhance your browsing experience and collect data on site usage. You can manage cookie preferences through your browser settings.

 

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. The most recent version will always be available on our website.

 

11. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal information, please contact us:

Chapman and Frazer Commercial Real Estate
Level 1 / 27 Dane Drive, Gosford NSW, Australia
Phone: +61 2 4325 0208
Email: enquiries@chapmanfrazer.com.au

If you believe we have breached your privacy rights, please contact us. We will address your concerns promptly. If you are unsatisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC) or the New South Wales Information and Privacy Commission (IPC).

 

12. Compliance with Privacy Laws

This Privacy Policy complies with:

    • Privacy Act 1988 (Cth) and Australian Privacy Principles: Covers collection, use, disclosure, and protection of personal information, rights to access/correct information, and website tracking.

    • New South Wales State Laws: Ensures compliance with Australian and state laws regarding information sharing, complaint handling, and regulatory obligations.P

OVERVIEW

The purpose of this policy is to ensure that CHAPMAN & FRAZER REAL ESTATE PTY LTD T/AS CHAPMAN & FRAZER COMMERCIAL REAL ESTATE (referred to throughout this document as CFCRE) handles personal and sensitive information responsibly, transparently, and in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988. The policy outlines the processes for collecting, using, disclosing, storing and protecting personal information.

SCOPE

This policy applies to all personal and sensitive information collected by CFCRE, including information relating to:

  • Clients;
  • Prospective clients;
  • Prospective vendors;
  • Prospective buyers;
  • Prospective landlords;
  • Prospective tenants;
  • Vendors;
  • Buyers;
  • Landlords;
  • Tenants;
  • Contractors;
  • Suppliers;
  • Employees;
  • And any other individuals whose information is gathered in the course of providing real estate services.

CFCRE is committed to safeguarding the privacy of individuals and ensuring the confidentiality, security and integrity of personal and sensitive information. The organisation will comply with the Australian Privacy Principles and all relevant legislation while promoting trust and transparency in every interaction.

CFCRE complies with the Privacy Act 1988 (Cth) including the 13 Australian Privacy Principles (APPs) introduced under the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth). To provide a clear framework for our privacy practices, CFCRE, has developed and implemented this APP Privacy Policy.

RATIONALE

CFCRE’s privacy processes are designed to ensure effective and compliant management of personal and sensitive information, in alignment with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). These processes promote responsible, transparent, and secure handling of information, helping build trust among stakeholders while meeting all regulatory obligations.

By establishing clear procedures for the collection, use, storage, and disclosure of information, CFCRE ensures its activities remain compliant with national and state-based privacy legislation. This includes maintaining strong data quality and security measures – such as password-protected computer systems, encrypted digital records, secure physical storage, and regular audits – to reduce the risk of unauthorised access, misuse, or loss of personal information.

The organisation ensures transparency by providing accessible privacy policies, offering detailed notifications at the point of data collection, and maintaining clear processes for individuals to request access to or correction of their personal information. Provisions for anonymity and informed consent further support and respect individual privacy. In addition, established procedures for managing complaints, including the option to escalate unresolved matters to external authorities, strengthen overall accountability.

Regular monitoring and review of privacy practices support continuous improvement, ensuring that processes remain effective and responsive to evolving legal requirements and organisational needs. Together, these comprehensive privacy measures protect individual rights and uphold the integrity of the organisation.

APPLICABLE LEGISLATION

This policy is designed to maintain requirements with additional jurisdictional requirements including:

  • Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth)
  • Privacy and Personal Information Protection Act 1988 (NSW)

Australian Privacy Principles (APP)

CFCRE manages personal information in an open and transparent manner. This commitment is reflected in the practices, procedures, and systems outlined in this policy, all of which support our compliance with the Australian Privacy Principles (APPs) and any binding registered APP code.

These measures also ensure that CFCRE personnel are equipped to respond appropriately to privacy-related inquiries and complaints as they arise.

The following sections of this policy explain how we handle and protect personal information.

APP 1 – Open and transparent management of personal information

Purposes for information collection, retention, use and disclosure

CFCRE maintains a record of personal information for all individuals with whom we engage in the course of our activities. As part of delivering our services, we collect, hold, use, and disclose personal information from our clients, customers and other stakeholders for a range of real estate related purpose, including but not limited to:

  • Providing sales, leasing and property management services
  • Managing relationships with vendors, landlords, buyers, tenants and prospective clients
  • Coordinating activities with contractors, tradespeople, and service providers engaged in property maintenance or preparation
  • Promoting properties, marketing campaigns, and related services
  • Conducting internal business operations, compliance tasks and trust accounting obligations
  • Meeting regulatory, legislative and reporting requirements imposed by industry bodies, government agencies, or stakeholders.

Kinds of personal information collected and held

The following types of personal information are generally collected:

  • Identity Information
    • Full name
    • Business role or title
    • Company affiliation (tenant entity, landlord entity, trust, etc)
    • Residential and business address
    • Phone number & email address
    • Driver’s licence, passport or other photo ID (limited detail recorded)
    • Verification of Identity (VOI) documentation for contracts and leases
    • Biometric Information such as a facial image or a short video of you holding your ID. This information is treated as sensitive information under the Privacy Act and is only used for identity verification and related compliance purposes, and only with your consent.
  • Commercial Tenancy Application Information
    • Company registration details (ABN, ACN, business structure)
    • Director/partner personal details
    • Guarantor personal details
    • Trading history and business profile
    • References from previous commercial landlords, agents or suppliers
    • Business plans (for certain tenancies, eg retail or start-ups)
  • Financial & Credit Related Information
    • Personal financial statements (for guarantors or sole traders)
    • Proof of income or financial capacity
    • Bank account details (for payments and refunds)
    • Trust account transaction records
    • Payment history and arrears information
    • Credit checks or credit-worthiness information (where permitted and with consent)
    • Details relating to commercial bonds or bank guarantees
  • Property & Transaction Related Information
    • Details of properties owned, leased or managed
    • Information provided during inspections, negotiations or due diligence
    • Correspondence relating to offers, lease terms, or contracts
    • Fit-out or use of premises requirements
    • Access card or security access information
  • Legal, Regulatory & Compliance Information
    • Anti-money laundering / counter-terrorism financing documentation (where required)
    • Identity verification for signing leases, sale contracts, or trust transactions
    • Records related to insurance and liability coverage
    • Incident or accident reports occurring on premises
    • Dispute resolution or compliance correspondence
  • Sensitive Information (only when necessary and with consent)
    • Information unintentionally revealed via ID documents
    • Health or disability information (eg workplace accommodation requirements)
    • Criminal history (eg for certain industrial or sensitive site leases)
    • Commercially confidential or sensitive information (eg trade secrets)
  • Marketing, Enquiry & Interaction Data
    • Attendance at commercial property inspections
    • Online enquiry information
    • Preferences for property types, locations or investment categories
    • Website or email engagement data (eg for marketing campaigns)

How personal information is collected

CFCRE generally collects personal information directly from individuals we deal with. This may occur through the use of forms (such as commercial tenancy applications, enquiry forms, registration documents or service agreements), through web-based systems (including online enquiry forms, digital inspection registration tools, customer portals, and internal business platforms), or via interpersonal interaction, such as via phone calls or face to face meetings.

To verify your identity, we may use electronic identity verification services, including the Australian Government’s Document Verification Service (DVS).

Where you have consented, your name, date of birth and identity document details will be securely sent to the relevant Commonwealth or State authority that issued your document. This may include passport offices, driver licence authorities, the Department of Home Affairs, Births Deaths and Marriages, or other authorised holders. These authorities check whether the details you have provided match the records they hold.

We do not receive a copy of your government records. The authority returns a match result only, confirming whether your details match (yes or no).

This process may be carried out through accredited identity verification providers, including APLYiD (APLYiD Pty Ltd, ABN 36 632 866 794) and its sub-providers.

More information about the DVS is available at idmatch.gov.au.

In the course of delivering commercial real estate services, CFCRE may also receive both solicited and unsolicited personal information from third-party sources.

These may include:

  • Government agencies and local councils
  • Legal representatives and conveyancers
  • Employers, business owners, directors, or authorised company representatives
  • Contractors, facilities managers, and service providers engaged at the property
  • Credit reporting agencies and background check providers
  • Referring agents, brokers, valuer, or financial institutions
  • Real estate listing platforms and advertising sites (such as Real Commercial, Commercial Real Estate etc)
  • Marketing platforms that capture enquiry data for listed properties
  • Business directories

How personal information is held

CFCRE’s usual approach to holding personal information includes maintaining secure storage and security measures at all times. Upon collection, personal information is:

  • Converted to electronic format as soon as possible
  • Stored in secure, password protected business systems, such as customer relationship management (CRM) platforms, property management systems, financial systems and document management platforms
  • Monitored to ensure that access and use are restricted to authorised personnel only

Access to each system is granted solely to authorised team members, with permissions limited to what is necessary for their specific role. CFCRE’s digital systems are securely hosted, across secure cloud storage, supported by strict access controls, physical security protections, encryption measures and system-level permissions. Security safeguards include virus and malware protection, routine data backups (cloud based) and continuous monitoring of access activity.

Paper based records are destroyed as soon as practicable through in office shredding and certified destruction services at CFCRE.

Retention and Destruction of Information

CFCRE retains personal information for as long as necessary to fulfil the purposes for which it was collected, to meet legal and regulatory requirements, and to support legitimate business functions related to commercial real estate activities. This includes information collected during sales, leasing, property management services, due diligence processes, financial transactions and compliance requirements.

  • Information Retention

    Personal information may be retained for the following reasons:

    • Commercial leasing and sales records: retained for the duration of the transaction and for the legally required period following completion (eg contract retention and trust account requirements)
    • Property Management: retained for the length of the management agreement and any additional statutory period
    • Financial and transactions records: stored in accordance with taxation, audit, trust account and corporate record-keeping laws
    • Compliance and regulatory documentation: retained to meet obligations under real estate, workplace safety and privacy legislation
  • Destruction and De-Identification of Information

    Once information is no longer required, and there is no legal or legitimate business reason to retain the information, CFCRE securely destroys or de-identifies the information. This includes:

    • Paper records: destroyed through in office shredding or certified destruction services
    • Electronic records: permanently deleted from cloud storage, local servers and system backups in accordance with secure deletion procedures
    • Access credentials and system links: revoked or removed to prevent further access
    • Archived data: review periodically to ensure unnecessary or expired information is securely disposed of.
  • Secure Handling

    Destruction processes are performed in a manner that prevents:

    • Unintended access
    • Misuse, loss or theft
    • Reconstruction or recovery of the information

CFCRE follows industry standard security and privacy practices to ensure information is safely managed throughout its lifecycle.

Automated decisions

CFCRE does not rely solely on automated decision making systems to make decisions that could have a significant impact on individuals or businesses in connection with our services. All decisions related to leasing, sales, tenant selection, applications, negotiations, and property management activities involve human review and professional judgement.

Accessing and seeking correction of personal information

CFCRE confirms all individuals have a right to request access to their personal information held. You also have the right to request the correction of any personal information which relates to you that is inaccurate, incomplete, irrelevant, misleading or out-of-date.

If you require any further information about the management of personal information or have any queries or complaints, you should contact:

The Privacy Officer
CHAPMAN & FRAZER COMMERCIAL REAL ESTATE
Level 1, 27 Dane Drive, GOSFORD NSW 2250
PO Box 18, GOSFORD NSW 2250
E: enquiries@chapmanfrazer.com.au
P: 02 4325 0208

A range of third parties, other than the individual concerned, may request access to personal information. These parties may include Government agencies (Commonwealth, State or local), contractors and service providers engaged at a property, legal representatives, strata agents.

Whenever such a request is made, CFCRE ensures that:

  • All parties requesting access to personal information are thoroughly identified and verified;
  • Where legally permissible, the individual to whom the information relates to will be contacted to confirm consent (if consent not already been provided for the matter); and
  • Access is granted only to appropriately authorised parties and solely for legitimate and valid purposes.

Complaints about a breach of the APPS or a binding registered APP code

Should an individual consider that CFCRE has potentially breached an APP or a binding registered APP code, they are encouraged to consult the Privacy Complaints Procedure outlined below for guidance on the steps they may take.

Likely overseas disclosures:

In certain circumstances, CFCRE may disclose personal information to overseas recipients. Additional information regarding such disclosures is detailed in the following sections of this policy, eg assisting clients in a transaction, placing insurance, obtaining finance etc.

Making our APP Privacy Policy Available

CFCRE makes its APP Privacy Policy available free of charge. The policy can be accessed at any time via the Privacy link on our website at www.chapmanfrazer.com.au.

In addition, the APP Privacy Policy is:

  • Prominently displayed at CFCRE premises;
  • Referenced at all points where personal information is collected, such as during telephone calls, where individuals are informed how the policy can be accessed;
  • Available free of charge upon request, and, where reasonably practicable, provided in any specific format requested by the individual;

If, in the unlikely event, the APP Privacy Policy cannot be provided in the format requested, CFCRE will explain the reasons to the requesting individual and work with them to provide access through an alternative suitable method.

Review and Update of this APP Privacy Policy

CFCRE reviews this APP Privacy Policy:

  • Continuously, as suggestions, issues, or government mandated changes arise.
  • At least annually, through our internal audit processes.
  • During any external audits undertaken by government agencies as part of our real estate registration or general business compliance activities.
  • As part of every complaint investigation where the matter relates to privacy.

When this policy is updated, CFCRE, ensures changes are clearly and widely communicated. Updates are shared internally through staff communications, meetings, training and documentation and externally through publication on the CFCRE website.

APP 2 – Anonymity and pseudonymity

CFCRE acknowledges the importance of allowing individuals to remain anonymous where practical. However, there are circumstances in which we are unable to interact with individuals who choose not to identify themselves. This is particularly the case when we are acting for a vendor or landlord in relation to the sale, rental, or lease of a property, or when we are dealing with actual or prospective tenants for any rental property under our management.

In addition, we are not able to allow people through any property inspections who do not wish to identify themselves. This requirement exists to protect the security and privacy of the property owner, as well as for other safety and operational reasons.

Where anonymity is feasible, CFCRE can provide general information, such as responding to broad telephone enquiries about a property available for sale or lease, without requiring the individual to identify themselves. However, individuals should be aware that certain modes of communication, including email or other written or electronic correspondence, may inherently disclose identifying information.

Requiring identification

While CFCRE supports the use of anonymity and pseudonyms wherever practical, there are situations in which identification is required. Certain activities, particularly those involving property access, property transactions, tenancy matters, or the verification of an individual’s authority to act, cannot be completed without confirming a person’s identity. In these circumstances, CFCRE must request sufficient identification to meet legal, contractual, and safety obligations, and to ensure the proper delivery of our services.

APP 3 – Collection of solicited personal information

CFCRE only collects personal information that is reasonably necessary for our business functions and activities.

We collect sensitive information only where the individual has provided explicit consent, unless we are legally required to collect such information, as outlined earlier in this policy.

All personal information is collected by lawful and fair means. Wherever it is reasonable and practicable to do so, CFCRE collects solicited information directly from the individual. Personal information is collected from other sources only where it would be unreasonable or impracticable to obtain it directly from the individual.

APP 4 – Dealing with unsolicited personal information

CFCRE may, from time to time, receive unsolicited personal information. When this occurs, we promptly access the information to determine whether it is the type of personal information we could have lawfully collected for the purposes of our business activities.

If the information could have been collected under APP 3 for a valid business purpose, we may retain, use and disclose it in accordance with this Privacy Policy.

If we determine that the information could not have been collected, whether due to legal restrictions or because it is not reasonably necessary for our functions, we will immediately destroy or de-identify the information, unless it would be unlawful to do so.

APP 5 – Notification of the collection of personal information

CFCRE takes reasonable steps to ensure individuals are made aware of important matters relating to the collection of their personal information at or before the time of collection, or as soon as practicable afterwards.

The Privacy Policy provided to individuals includes information about:

  • how we collect personal information;
  • the purposes for which personal information is collected;
  • the types of entities to whom we typically disclose personal information;
  • the consequences of not providing requested personal information;
  • direct marketing that may be undertaken by CFCRE, related companies, preferred suppliers, or sponsors;
  • circumstances where we are legally required to collect personal information under Australian or State law (e.g., the Property, Stock and Business Agents Act 2002 (NSW) and associated regulations);
  • where our full Privacy Policy can be accessed; and
  • whether personal information may be disclosed to overseas recipients.

Where we know that, as part of our relationship with the individual, their personal information will be disclosed to another identifiable organisation, we will notify the individual at the time of first collection (or as soon as reasonably practicable) of:

  • the identity and contact details of that organisation; and
  • the purpose for which their personal information may be disclosed to that organisation (eg solicitors to prepare contracts, leases or Insurance companies to provide required details for risk assessments; or Strata Managers etc.).

APP 6 – Use or disclosure of personal information

CFCRE only uses or discloses personal information for the purpose for which it was collected (the primary purpose), unless:

  • the individual has provided consent to the use or disclosure for another purpose;
  • the individual would reasonably expect us to use or disclose their information for a related purpose (or, in the case of sensitive information, a directly related purpose);
  • the use or disclosure is required or authorised by law

CFCRE ensures that all uses and disclosures of personal information are appropriate, lawful and consistent with this Privacy Policy and the expectations of the individuals concerned.

Where personal information is disclosed to third parties, including contractors, service providers, government agencies, or related entities, we take reasonable steps to ensure those parties handle the information in accordance with the Australian Privacy Principles and maintain appropriate confidentiality and security standards.

Personal information is not used or disclosed for secondary purposes that an individual would not reasonably expect, unless consent has been obtained or the disclosure is otherwise permitted under the Privacy Act.

Requirements to make a written notice of use or disclosure for this secondary purpose

CFCRE will make a written record of any disclosure of personal information in accordance with an ‘enforcement related activity’, including the following details:

  • the date of the disclosure;
  • the information disclosed;
  • the identity of the organisation or individual to whom the information was disclosed; and
  • the legal or operational reason for the disclosure.

A written notice is not required for disclosures made for the primary purpose of collection, for a reasonably expected related purpose, or where the individual has provided consent.

APP 7 – Direct Marketing

CFCRE does not use or disclose the personal information it holds about an individual for the purpose of direct marking unless one of the following conditions applies:

  • the personal information was collected directly from the individual;
  • the individual would reasonably expect their personal information to be used for direct marketing purposes; and
  • the information was collected directly or from a third party without that expectation, and we provide a simple opt-out method.

All direct marketing communications from CFCRE clearly explains how to opt out, and we act on any opt-out requests promptly and free of charge.

On request, we will also tell an individual of the source of their personal information used for direct marketing unless it is unreasonable or impracticable to do so.

APP 8 – Cross-border disclosure of personal information

CFCRE do not disclose personal information overseas, unless specifically instructed to do so by you.

Where possible, we endeavour to use onshore Australian based cloud storage. However, we may use cloud storage services or IT servers located overseas to store personal information. Because electronic and networked storage can be accessed from various countries via the internet, it is not always possible to know the exact country in which an individual’s information may be held.

Where it is practicable, we will identify the countries in which personal information is likely to be stored or transferred.

CFCRE does not adopt, use or disclose a government related identifier of an individual unless one of the following permitted circumstances applies:

  • the use or disclosure is required or authorised by Australian law or another legal instrument;
  • the use or disclosure is reasonably necessary to verify the individual’s identity
  • the use or disclosure is reasonably necessary to fulfil obligations to a government agency, or a State or Territory authority; and
  • as prescribed by regulations.

APP 10 – Quality of personal information

CFCRE takes reasonable steps to ensure that the personal information we collect is accurate, up-to-date and complete. We also take reasonable steps to ensure that any personal information we use or disclose is, having regard to the purpose of use or disclosure, accurate, up-to-date, complete and relevant.

These steps are particularly important:

  • When we initially collect the personal information; and
  • Before we use or disclose personal information.

We take reasonable steps to ensure personal information is factually correct, and where information reflects an opinion, we ensure it is based on appropriate facts, competing views are considered, and it is clearly identified as an opinion. Personal information is confirmed as up-to-date at the point in time to which it relates.

To support these requirements, we maintain the following quality measures:

  • Internal practices, procedures and systems to audit, monitor and correct poor-quality personal information, including staff training.
  • Consistent data collection protocols, ensuring information is obtained in a standard format and from primary sources where possible.
  • Prompt updating of new or corrected personal information in relevant records.
  • Verification steps, where appropriate, before using or disclosing personal information, particularly if a long time has passed since collection.
  • Checking that third party sources have appropriate data quality processes in place.

APP 11 – Security of personal information

CFCRE takes reasonable steps to protect the personal information we hold from misuse, interference, loss and unauthorised access, modification or disclosure.

We regularly review our security measures and use appropriate technical and organisational safeguards to maintain data security.

When personal information is no longer required for any lawful purpose, we take reasonable steps to destroy or ensure it is de-identified, unless we are legally required to retain it.

Access to our offices and work areas are restricted to authorised personnel only. Visitors must be approved by relevant staff and are accompanied at all times to protect the security of our work environment. Paper-based records are stored in secure locations accessible only to authorised individuals.

We provide regular training and updates to all personnel to ensure a strong understanding of privacy obligations and how to apply the APPS to our practices and systems. Privacy training is also included in our induction process for new personnel.

To maintain robust security standards, we conduct ongoing internal audits, at least annually and additionally as required, to assess the adequacy and effectiveness of our security and access controls.

APP 12 – Access to personal information

Where CFCRE holds personal information about an individual, we provide that individual with access to their information upon request. In processing access requests, we:

  • Verify identity to ensure the request is made by the individual or an authorised representative.
  • Respond within the required timeframes:
    • Within 7 calendar days by providing access in the manner requested, where practicable
    • Within 14 calendar days if we refuse access, including written reasons for refusal and information about complaint options.
  • Provide access free of charge.

These practices reflect our commitment to meeting the access requirements under APP 12, which requires organisations to give individuals access to personal information they hold, subject to limited grounds for refusal.

APP 13 – Correction of personal information

CFCRE takes reasonable steps to ensure that the personal information we hold is accurate, up-to-date, complete, relevant and not misleading. If we identify that information requires correction, or if an individual requests a correction, we will take appropriate steps to update the information.

If we refuse to correct personal information, we will provide the individual with a written explanation including the reasons for refusal and information about available complaint mechanisms. We will also, where requested, associate a statement with the information noting the individual’s correction request.

Where appropriate, we will take reasonable steps to notify other organisations to whom the information has previously been disclosed of any corrections. We do not charge fees for making a correction request or for correcting personal information.

Privacy Complaints

If an individual believes that CFCRE has breached its obligations in the handling, use or disclosure of their personal information, they may make a complaint. We encourage individuals to first raise the matter with their CFCRE representative so we can attempt to resolve the issue promptly.

Our complaints process is as follows:

  1. Submit the complaint including as much detail about the issue as possible, in writing to
    The Privacy Officer
    CHAPMAN & FRAZER COMMERCIAL REAL ESTATE
    Level 1 / 27 Dane Drive, Gosford NSW 2250
    PO Box 18, Gosford NSW 2250
    e: enquiries@chapmanfrazer.com.au
    P: 02 4325 0208
  2. CFCRE will investigate the complaint and provide a response to the individual as soon as possible, and within 14 business days, outlining our findings and any actions taken.
  3. If the individual is not satisfied with our response, they may escalate the complaint to the Office of the Australian Information Commissioner (OAIC):
    • Website: www.oaic.gov.au
    • Phone: 1300 363 992

When the OAIC investigates a complaint, it will generally attempt to conciliate the matter before considering the use of other complaint-resolution powers.

Compare listings

Compare