| Monash home | About Monash | Faculties | Campuses | Contact Monash |
| Staff directory | A-Z index | Site map |
|
|
Collection, Storage and Destruction of Credit Card Details PolicyFor Use by all University Staff
Policy StatementMonash University values the privacy of credit card information and is committed to protecting the credit card details it holds and uses. This policy outlines how Monash University intends to collect, store and destroy credit card details. PrinciplesThe policy is based on the following principles:
Broad OverviewMonash University may consider the following matters when adopting reasonable steps to protect the credit card information it holds:
ApplicationAll University staff. Operative DateOperative from first full pay period to commence on or after 18 May 2003 Policy AuthorisationDivisional Director, Human Resources Division Policy AdministratorDirector, Policy & Consultancy, Human Resources Division Detailed Policy1.0 Application of PolicyThis policy is designed to deal with situations where a person provides details of their credit card to the university. The policy is also designed to ensure that Monash University will store and destroy credit card details in a manner which protects the credit card details from:
2.0 Collection of Credit Card DetailsMonash University is committed to ensuring that credit card details are collected in a secure manner. Monash University will take reasonable steps to protect the credit card details it holds from misuse and loss and from unauthorised access, modifications and disclosure during collection by adopting the following practices:
3.0 Storage of Credit Card Details3.1 Monash University is committed to ensuring that credit card details are held securely. Monash University will take reasonable steps to protect the credit card details it holds from misuse and loss and from unauthorised access, modifications and disclosure by adopting the following practices:
3.2 Credit card details may be stored in hard copy documents. If credit card details are stored as electronic data appropriate security measures must be utilised in accordance with the University's IT Security Policy and IT Security Framework. Some of the ways Monash University seeks to protect credit card details include the following:
3.3 Credit Card details are required to be stored onsite or in an easily accessible location for 12 months for charge back purposes. After 12 months, credit card details may be moved offsite providing the credit card details are stored in a secure location. 3.4 Credit card details must be stored for the length of time prescribed by the Records Disposal Authority. 4.0 Destruction of Credit Card DetailsCredit card details will be destroyed in a secure manner when they are no longer needed by Monash University. Examples of destruction in a secure manner include shredding, pulping or disintegration of paper files, fire, confidential disposal in accordance with any guidelines provided by Records & Archives, encryption or scrubbing of credit card number or contracting an authorised disposal company for secure disposal. 5.0 For Further InformationFor further information about this policy please contact: Privacy Officer Or refer to the IT Security Policy and IT Security Framework Document for IT requirements. 6.0 Obligations of StaffIf a staff member collects credit card details on Monash University's behalf, the staff member must meet the relevant requirements of this policy in relation to the storage of credit card details. 7.0 Disciplinary ActionBreach of this policyIf a staff member breaches this policy, depending on the circumstances it may be regarded as misconduct or poor performance and this may result in action being taken in accordance with the provisions set out in the Monash University enterprise agreement or, where applicable, the provisions of the relevant AWA Terms and Benefits Policy. 8.0 Change of PolicyMonash University may change this policy from time to time without prior notice. Relevant Australian Legislation, Policies and Associated Documentation9.0 PrivacyLegislation
10.0 Associated Policies and Legislation (including Guidelines & Procedures)Associated Documentation
Further Information11.0 Further Information and AssistanceAdherence to this policy will generally ensure compliance with University requirements and relevant legislation. However, there may be instances where inadvertent breaches could occur. When in doubt users requiring assistance with interpretation of the policy, or who wish to report an incident, should contact:
|