Last updated May 2022
Select a section
- 1. Personal information we collect
- 2. How we collect and manage personal information
- 3. Direct marketing
- 4. Privacy on our websites
- 5. Children
- 6. Gaining access to personal information we hold
- 7. Keeping personal information current
- 8. Complaints
- 9. How to contact us
1. PERSONAL INFORMATION WE COLLECT
The types of personal information we collect depends on the nature of our engagement with you. Examples of personal information we may collect include:
- names, job titles, contact and address details
- information in identification documents (for example: passport or driver’s licence)
- tax file numbers and other government-issued identification numbers
- date of birth and gender
- bank account details, shareholdings and details of investments
- details of superannuation and insurance arrangements
- educational qualifications, employment history, salary and referee reports
- visa or work permit status
- your Internet Protocol (IP) address
- payment details and
- personal information about your spouse and dependants.
It may be necessary in some circumstances for KPMG to collect sensitive information about you in order to provide specific services or for recruiting purposes. Examples of the types of sensitive information that may be collected in such circumstances include professional memberships, ethnic origin, criminal record and health information.
It is generally not practical to remain anonymous or to use a pseudonym when dealing with KPMG as usually we need to use your personal information to provide specific services to you, or which relate to or involve you.
2. HOW WE COLLECT AND MANAGE PERSONAL INFORMATION
2.1 How we collect personal information
Generally we collect your personal information from you directly (for example, when we deal with you in person or over the phone, when you send us correspondence (including via email), when you complete a questionnaire, form or survey, when you subscribe to our publications or when you use our website or our social media).
Sometimes it may be necessary for us to collect your personal information from a third party. For example, we may collect your personal information from your employer where they are our client, from your personal representative, another KPMG member firm or a publicly available record.
We may also collect personal information about you from your use of our websites and information you provide to us through contact mailboxes or through the registration process on our websites.
2.2 Where you provide us with personal information about someone else
2.3 Holding personal information
KPMG holds personal information in hard copy and electronic formats. We take security measures to protect the personal information we hold including physical (for example, security passes to enter our offices and storage of files in lockable cabinets) and technological (for example, restriction of access, firewalls, the use of encryption, passwords and digital certificates).
We also have policies and processes which govern document retention and data breach incidents. In some cases, KPMG engages third parties to host electronic data (including data in relation to the services we provide) on our behalf.
2.4 Purpose for collecting, holding, using and disclosing personal information
KPMG collects, holds and uses personal information for a number of purposes including:
- to provide and enhance our services and those of other KPMG member firms
- to respond to requests or queries
- to maintain contact with our clients and other contacts (including alumni), and keep them informed of our services, industry developments, seminars and other events
- to verify your identity
- for administrative purposes, including processing payment transactions
- for recruitment purposes
- for purposes relating to the employment of our personnel, providing internal services or benefits to our partners and staff and for matters relating to the partnership
- when engaging service providers, other KPMG member firms, contractors or suppliers relating to the operation of our business
- to manage any conflict of interest or independence (including auditor independence) obligations or situations
- to conduct surveys
- for seeking your feedback
- to meet any regulatory obligations
- as part of an actual (or proposed) acquisition, disposition, merger or de-merger of a business (including KPMG’s business) or entering into an alliance, joint venture or referral arrangement or
- to develop our expertise and know how, for benchmarking purposes, analytics, quality assurance and thought leadership, and other purposes related to our business.
As part of an engagement, if you are a customer, an employee, a contractor or supplier of services to one of our clients, then we may disclose your personal information as part of providing services to that client.
The types of third parties to whom we may disclose your personal information include:
- experts or other third parties contracted as part of an engagement
- our agents, third party contractors and suppliers
- our professional advisers
- other KPMG member firms (which includes entities they wholly or dominantly own and control), or KPMG International Co-operative
- third parties as part of an actual (or proposed) acquisition, disposition, merger or de-merger of a business (including KPMG’s business) or to enter into an alliance, joint venture or referral arrangement or
- government or regulatory bodies or agencies, as part of an engagement or otherwise.
We do not disclose personal information to third parties for the purpose of allowing them to send marketing material to you. However, we may share non-personal, de-identified or aggregated information with select third parties for research or promotional purposes other than direct marketing.
2.5 Disclosure of personal information overseas and sharing personal information amongst and within the KPMG member firm network
KPMG is a member firm of the KPMG network, which has over 150 independent member firms globally that are affiliated with the KPMG International Co-operative.
Depending on the nature of the engagement or the circumstances of collecting your personal information, we may disclose your personal information to other KPMG member firms or entities overseas to fulfil the purpose for which the personal information was collected, or a related or ancillary purpose or otherwise in accordance with the Privacy Act.
The countries to which such disclosures are made, and types of personal information disclosed depend on the specific circumstances of the engagement. For a list of where our member firms are located, see KPMG's global locations.
We may also store, process or back-up your personal information on servers that are located overseas (including through third party service providers). These servers are commonly located in the United States of America, the United Kingdom, the Netherlands, Ireland, Germany and Singapore.
In some circumstances, KPMG also uses third party contractors and suppliers to carry out its functions and provide services. These contractors and suppliers are typically located in India, the Philippines and Finland.
KPMG may use your personal information for the purpose of marketing its services to you.
If you do not want to receive marketing material from us, you can contact us as detailed below:
- for electronic communications, you can click on the unsubscribe function in communications; or
- for hard copy communications, you can email firstname.lastname@example.org or
- through our contact details in 'How to contact us'.
4.1 Automatic collection of personal information
Cookies, web beacons and other technologies are used by KPMG and its service providers on some KPMG websites and through email to automatically collect certain types of information. The collection of this information allows us to customise your online experience (including tailored KPMG marketing), to improve the performance, usability and effectiveness of KPMG’s online presence and to measure the effectiveness of our marketing activities.
An IP address is a number assigned to your computer whenever you access the internet. It allows computers and servers to recognise and communicate with one another.
Public IP addresses from which visitors appear to originate may be recorded for IT security and system diagnostic purposes. This information may also be used in aggregate form to conduct web site trend and performance analysis, and to enhance user experiences.
Cookies may be placed on your computer or internet-enabled device whenever you visit us online. This allows the site to remember your computer or device and serves a number of purposes.
Although most browsers automatically accept cookies, you can choose whether or not to accept cookies via your browser's settings (often found in your browser's Tools or Preferences menu).
You may also delete cookies from your device at any time. However, please be aware that if you do not accept cookies, you may not be able to fully experience some of our websites' features.
Cookies by themselves do not tell us your email address or otherwise identify you personally. In our analytical reports, we may obtain other identifiers including public IP addresses, but this is for the purpose of identifying the number of unique visitors to our web sites and geographic origin of visitor trends, and is not used to identify individual visitors.
KPMG uses analytics tools, such as Google Analytics and Adobe Analytics. To provide website visitors with more choice on how their data is collected by Google Analytics, Google have developed the Google Analytics Opt-out Browser Add-on.
The Google Analytics Opt-out Browser Add-on does not prevent information from being sent to the website itself or to other web analytics services.
More information about how Google Analytics is used by KPMG can be found here:
Adobe also provides a range of opt-out options for Adobe Analytics.
A web beacon is a small image file on a web page that can be used to collect certain information from your computer such as an IP address, the time that content was viewed, a browser type, and the existence of cookies previously set by the same server.
KPMG or its service providers may use web beacons to track the effectiveness of third party websites that provide us with recruiting or marketing services or to gather aggregate visitor statistics and manage cookies.
You have the option to render some web beacons unusable by rejecting their associated cookies. The web beacon may still record an anonymous visit from your IP address but cookie information will not be recorded.
In some of our newsletters and other communications, we may monitor recipient actions such as email open rates through embedded links within the messages. We collect this information to gauge user interest and to enhance future user experiences.
KPMG may collect and use the geographical location of your computer or mobile device. This location data is collected for the purpose of providing you with information regarding services which we believe may be of interest to you based on your geographic location, and to improve our location-based products and services.
4.1.6 Social media widgets and applications
Some KPMG websites and services may include functionality to enable information sharing via third party social media applications, such as the Facebook Like button and Twitter widget.
These social media applications may collect and use information regarding your use of KPMG websites. Any personal information that you provide via such social media applications may be collected and used by members of that social media application separate to KPMG.
Such interactions that are monitored by social media applications are governed by the privacy policies of the relevant companies that provide the applications. We do not have control over, or responsibility for, those companies or their use of your information.
In addition, KPMG websites or affiliate websites may host blogs, forums, crowd-sourcing and other applications or services (collectively “social media features”). The purpose of social media features is to facilitate the sharing of knowledge and content.
Any personal information that you provide on any KPMG social media feature may be shared with other users of that social media feature (unless otherwise stated at the point of collection), over whom we may have limited or no control.
4.2 Links to third party websites
Unless expressly advised, KPMG does not endorse, approve or recommend the services or products provided on third party websites.
You have several choices regarding your use of KPMG websites. In general, you are not required to provide personal information when you visit our websites. However, if you make an enquiry or subscribe to receive information about our services, events and industry updates or wish to apply for a job, provision of certain personal information will generally be required to facilitate such requests.
We understand the importance of protecting the privacy of children, especially in an online environment. In particular, our websites are not intentionally designed for, or directed at, children under the age of 13.
It is our policy to never knowingly collect or maintain information about any person under the age of 13, except as part of a specific engagement to provide services which necessitates such personal information be collected, for the purposes of ensuring compliance with our auditor independence policies, or as otherwise required by law.
6. GAINING ACCESS TO PERSONAL INFORMATION WE HOLD
You can request access to your personal information, subject to some limited exceptions as permitted or required by law. Such request must be made in writing to KPMG Australia’s Privacy Liaison. Please see 'How to contact us' for details.
KPMG may charge reasonable costs for providing you access to your personal information.
7. KEEPING PERSONAL INFORMATION CURRENT
If you believe that any personal information KPMG has collected about you is inaccurate, not up-to-date, incomplete, irrelevant or misleading, you may request correction. To do so, please contact KPMG Australia’s Privacy Liaison and we will take reasonable steps to correct it in accordance with the requirements of the Privacy Act. Please see 'How to contact us' for details.
If you wish to make a complaint to KPMG about our handling of your personal information, you can contact KPMG Australia’s Privacy Liaison as set out in 'How to contact us'. Following your initial contact, you will be asked to set out the details of your complaint in writing in a form provided.
KPMG will endeavour to reply to you within 30 days of receipt of the completed complaint form and, where appropriate, will advise you of the general reasons for the outcome of the complaint.
In some circumstances, KPMG may decline to investigate the complaint (for example if the complaint relates to an act or practice that is not an interference with the privacy of the person making the complaint).