Cox Ferguson Privacy Policy

Privacy Policy As a business that collects and holds personal information about our clients, we must comply with Code Standard 5 of the Code of Professional Conduct for Financial Advice Services and adhere to the Privacy Act 2020 and its principles.

We only use client information for the purposes that we collect it for, and we do not underestimate the importance of keeping personal information secure during the collection, use, or authorised disclosure when providing our services.

Our key obligations:

What is personal information?

The Privacy Commission provides the following definition on their website: Personal information is any piece of information that relates to a living, identifiable human being. People's names, contact details, financial health, purchase records: anything that you can look at and say, "this is about an identifiable person.”

It does not need to include the client name and does not need to be secret or sensitive in nature. It is any information that could be used to identify an individual.

The Process

1. Client Authorisation

When meeting a client for the first time, we discuss the services that we offer and explain the process followed when providing advice. This involves asking the client to complete a Personal Information Authority & Declaration that outlines:

We do not provide any personal information, either verbal or written, without explicit consent from the client.

2. Office Security

3. Data Security 

4. Use of Information 

We only use information for the purposes it is intended and only after the client has given authorisation to do so. Their information may be used for the following purposes: 

5. Breach of Privacy

Where a breach of privacy is suspected, it is reviewed for potential harm to determine what immediate actionneeds to be taken to prevent any further breach. 

If it is concluded that a breach of privacy has occurred, we notify the affected individuals of the breach and let them know how their privacy has been breached, what steps we are taking to limit the breach, and confirm that we will be reporting the breach to the Privacy Commissioner.

We then notify the Privacy Commissioner using the NotifyUs function on the website of the PrivacyCommission: https://www.privacy.org.nz/privacy-for-agencies/privacy-breaches/notify-us/ 

Where it is determined that there has been a breach of privacy or there was the potential for a breach to haveoccurred, it is recorded in our Incident & Breach Register and treated in line with our Material Issues andReporting Policy.

How compliance is monitored 

Ryan Li is the nominated Privacy Officer and is responsible for understanding our responsibilities under the Privacy Act 2020. We review all our advice files for accuracy and compliance with our obligations under this policy.