Privacy Policy
Jon & Jon Consulting Pty Ltd
Contact: +61 2 9174 5352 | Operations@jonandjon.com
Last Reviewed on 06 August 2026
Jon & Jon Consulting Pty Ltd (ABN 59 169 496 235) (“Jon & Jon”, “we”, “us” or “our”) respects the privacy of individuals whose personal information we collect, hold, use and disclose. We manage personal information in an open and transparent way, in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and, where relevant, the General Data Protection Regulation (GDPR). We collect only information that is reasonably necessary for our recruitment, placement, compliance, payroll, client service and business activities.
We do not collect personal information simply because it may be useful in the future. We do not use or disclose personal information for unlawful purposes, including discriminatory purposes. If we receive unsolicited personal information that we do not require for our functions or activities, we will take reasonable steps to destroy or de-identify it where lawful and practicable.
Where it is lawful and practicable to do so, you may deal with us anonymously or by using a pseudonym. However, this may not be possible in recruitment, compliance or placement processes where we need to verify identity, work rights, registration status or other information.
Commitment to Privacy
The type of personal information we collect depends on whether you are a candidate, client, referee, contractor or other person with whom we deal.
We may collect:
- identity and contact details, including name, date of birth, gender, address, phone number and email address;
- professional and employment information, including qualifications, skills, career history, work preferences, right to work, and performance-related information;
- compliance information, including police checks, Working with Children Checks, vaccination and immunisation records, health declarations, AHPRA registration, Medicare provider numbers and visa status;
- workplace information, including incidents, feedback, absence records and complaints;
- financial information, including bank account details, tax file numbers, ABNs and taxation details for payroll and related purposes;
- client information, including hiring authority details, role descriptions, team structures and relationship information; and
- referee information, including contact details, authority to provide a reference, and opinions or factual statements about a candidate’s performance.
We may also collect sensitive information, such as health information or criminal history information, only where it is reasonably necessary for our functions or activities and where you have consented, unless an exception under the Privacy Act applies.
If you do not provide us with the information we request
If you choose not to provide some or all of the personal information we ask for, we may be limited in our ability to assess your suitability for a role, verify your compliance or registration status, place you with a client, or otherwise provide our services to you. In some cases, we may be unable to proceed with your application, placement or engagement.
Information we collect
We generally collect personal information directly from you when you submit an application, CV, compliance pack or enquiry, communicate with us by phone, email or in person, register on our website or through job boards, or take part in interviews, assessments or testing.
We may also collect information from referees, clients, professional associations, regulatory and registration bodies, migration and visa systems, enquiries about you to former employers, screening agencies and publicly available sources such as LinkedIn, online directories or other public sources, where it is lawful and reasonable to do so.
Photographs and identity documents
Where it is sufficient for us to sight an original document or photograph to verify your identity, right to work, or compliance status, we will not require you to provide us with a scanned copy, photograph unless keeping a copy is necessary for the purpose — for example, where a client or regulatory body requires a copy to be held on file.
When we collect personal information from you, we will take reasonable steps to notify you of the matters required by the Australian Privacy Principles, including who we are, why we collect the information, how we may use or disclose it and how you can contact us.
How we collect personal or sensitive information
We use personal information for purposes connected with our recruitment and employment services. The purposes for which we use personal information differ depending on whether you are a candidate, client or referee.
For candidates and locums
- assessing suitability for roles and placements;
- verifying registrations, work rights, visas and credentials;
- managing recruitment operations and workforce administration;
- meeting healthcare client compliance requirements;
- payroll, accounts and payment administration;
- workplace health and safety, risk and insurance purposes;
- reporting, analytics and statutory compliance; and
- direct marketing where permitted by law or where you have consented.
For clients
- client, contractor and business relationship management;
- assessing and fulfilling your recruitment requirements;
- reporting, analytics and statutory compliance; and
- direct marketing where permitted by law or where you have consented.
For referees
- confirming your identity and authority to provide a reference;
- candidate suitability assessment; and
- confirming information provided to us by the candidate.
We will only use personal information for a secondary purpose where that purpose is related to the original purpose of collection and you would reasonably expect that use or disclosure, or where another lawful basis applies.
How we use information
The recipients to whom we disclose personal information vary depending on whether you are a candidate, client or referee, and may include:
- hospitals, health services, medical practices and other clients seeking candidates;
- referees, for verification purposes;
- professional and regulatory bodies, such as AHPRA, Medicare and state health departments;
- immigration advisers or lawyers, where authorised or consented;
- contractors and service providers, including IT, legal, screening, payroll and marketing providers;
- insurance brokers, loss assessors, underwriters and workers’ compensation bodies, for insurance and workplace injury purposes;
- superannuation fund managers, for superannuation contribution purposes; and
- other parties where required or authorised by law.
We only disclose personal information that is reasonably necessary for the relevant purpose and take reasonable steps to limit disclosure to what is needed.
Overseas disclosure
Some personal information may be disclosed to overseas recipients where necessary for recruitment, placement, migration, regulatory or service delivery purposes, including where a placement, registration, visa or service provider involves another country. We may disclose information to recipients in countries such as New Zealand, the United Kingdom, Europe, India or other jurisdictions relevant to a particular placement or service arrangement.
Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles the information in a way that is consistent with the Australian Privacy Principles, unless an exception applies.
How we disclose information
The When you visit our website, we may collect information about your device and browsing activity through cookies and similar technologies. This may include pages visited, time spent on the site, browser type and IP address. We use this information to operate and improve our website, monitor performance, protect against misuse and understand how people use our online services.
You can usually control cookies through your browser settings, but some website features may not work properly if cookies are disabled.
Cookies and website data
We store personal information in secure systems, including cloud-based recruitment databases and related business systems. Access is restricted to authorised staff on a need-to-know basis. We use reasonable security measures such as passwords, access controls, encryption, monitoring, staff training, secure document handling and secure destruction of hard-copy records.
We also use internal safeguards including privacy training, clean desk and document handling practices, restricted access procedures.
Storage and security
We retain personal information only for as long as it is reasonably necessary for our business, legal, compliance and contractual obligations. Some records, such as financial records, may need to be kept for seven years or longer where required by law or for audit, compliance or healthcare-related purposes.
When personal information is no longer required, we take reasonable steps to destroy or de-identify it securely.
Retention and destruction
You may request access to the personal information we hold about you and request that we correct information that is inaccurate, incomplete, out of date, irrelevant or misleading, subject to any lawful exceptions. This may include information relating to a referee report, where access is not prevented by law or confidentiality obligations.
Requests should be made to our Privacy Officer using the contact details below. We will take reasonable steps to verify your identity before responding. We aim to respond to access and correction requests within 30 days of receipt. If we refuse access or correction, we will provide written reasons and information about your complaint options
Access and correction
We may use your contact details to send direct marketing communications by email, SMS, phone or print where permitted by law or where you have consented. You may opt out at any time by contacting us or using the unsubscribe facility in the communication.
Testimonials or feedback provided to us may be used in marketing material only with your consent.
Direct marketing
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Where we become aware of a data breach involving personal information we hold that is likely to result in serious harm to one or more individuals, we will follow our internal data breach response process — contain, assess, notify and review — and, where required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable.
Notifiable data breaches
As a provider of payroll services to contractors and employees, we collect Tax File Numbers (TFNs) and are a lawful TFN recipient under the Privacy (Tax File Number) Rule 2015. We will not use or disclose a TFN except where required or authorised by taxation law or superannuation law, or with your written authority.
Tax file numbers
If you believe we have interfered with your privacy, you may contact our Privacy Officer using the details below. We will acknowledge your complaint, investigate it and respond within a reasonable timeframe, usually within 30 days.
If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner or, where relevant, another applicable privacy regulator.
Complaints
Where we process personal information in connection with individuals in the European Union or United Kingdom, or where GDPR otherwise applies, we will comply with applicable GDPR requirements. In those circumstances, individuals may have additional rights, including rights of access, correction, erasure, restriction, objection and data portability, subject to legal exceptions and the circumstances of the processing.
Where GDPR applies, we will also provide information about the lawful basis for processing, the categories of recipients, retention periods and any international transfers, in the applicable notice or consent form for that processing.
GDPR
We may update this Privacy Policy from time to time to reflect changes in law, technology or our business practices. The updated version will be published on our website and will take effect when posted.
Changes to this policy
If you wish to contact us about your personal information, exercise your access or correction rights, or make a complaint, please contact our Privacy Officer:
Email: operations@jonandjon.com
Phone: + 61 2 9174 5352
For privacy or security concerns that are urgent, please email us and mark your message “Urgent — Privacy.”



