7. Use of Employer Portal
Your use of the Employer Portal is at your own risk. All information made available through the Employer Portal is believed to be accurate at the time of compilation and provided in good faith. The Trustee does not warrant the accuracy or completeness of any information available on the Employer Portal. The Trustee will take commercially reasonable precautions to protect the confidentiality of the information in the Employer Portal. You must comply with this clause 7 and any additional security control obligations notified to you by the Trustee from time to time.
7.1 Access and Security
7.1 a The primary contact provided when a Registered Employer requests access to the Employer Portal will be responsible for managing Authorised user access to the Employer Portal for the Registered Employer, including adding, managing and removing access to the Employer Portal for the Registered Employer.
7.1 b The Employer Portal allows an Employer and Authorised user (incl any 3rd party that you provide access for) to access information regarding Members of Aware Super. By accessing the Employer Portal, you agree that you will:
- only access Member information you are properly authorised to access; and,
- notify the Trustee immediately if you, or any Authorised user granted access by you, have been provided access to any Member information that you should not have access to.
7.1 c For the online Employer Portal, the Trustee will provide Registered Employers and Authorised Users with a link to access the portal where a password must be set to gain access to the Employer portal. To maximise the security of Member information, you must change your Employer Portal password no less frequently than every 14 months.
7.1 d You must ensure at all times that:
- your password is kept secure and not disclosed to anyone; and,
- you do not by any other action or omission allow any person other than yourself to access a Member’s information or effect any transactions relating to the online Employer Portal.
You must:
- protect your password from being lost, stolen or disclosed;
- og off immediately after you have finished accessing the online Employer Portal.
You must not:
- keep a written record of your password;
- give, show or tell your password to anyone;
- allow any person to read or hear your password, or watch you enter your password;
- share any Multi Factor Authentication (MFA) codes with other users or share a common MFA device.
7.1 e You acknowledge that:
- you understand that your password allows anybody access to personal information contained in the online Employer Portal. Leaving your computer unattended while logged into the online Employer Portal may lead to these consequences;
- you authorise the Trustee, when access to the online Employer Portal has been gained following the successful entry of your password, to treat any operations involving your Employer Portal as having been personally authorised in writing by you;
- the Trustee is under no duty whatsoever to enquire or establish if a person accessing the Employer Portal is a person actually authorised;
- you understand that no data transmission over the internet can be guaranteed as totally secure and that, while the Trustee will take all reasonable measures to protect the security of such information, the Trustee cannot ensure or warrant the security of any information transmitted using the Employer Portal;
- and you understand that any Authorised user granted access to the Employer Portal on behalf of a Registered Employer has been provided access to employee/Member data made available via the Employer Portal and reporting available on the Employer Portal and this information will be appropriately protected when transferred to your local systems.
7.1 f If you suspect that your password may have become known to any other person, or that for any reason another person may have been in a position to access Employer Portal on your behalf, you must ensure that:
- your password is changed immediately; and,
- you inform us immediately on 1300 878 737.
7.2 Currency and Accessibility
You acknowledge that:
- all information available through the Employer Portal may not always be current; and
- the services and functions offered through the Employer Portal may not all be available at all times.
7.3 Liability
7.3 a You agree that you are solely responsible for all use of your Employer Portal Access, including all information accessed.
You agree that all use of the Employer Portal will be for lawful purposes only, and that you are liable for any use for unlawful purposes.
You accept full responsibility and indemnify us for any claims arising from expenses, loss or liability that is incurred by any person as a result of your use of the Employer Portal and your Employer Portal Access, other than as provided in clause 7.3d.
7.3 b Without limiting clause 7.3a, you are liable in respect of access to all information:
- when access to the Employer Portal has been gained following the successful entry of your password;
- if you disclose your password to another person or fail to keep it properly secure; or,
- if by your action or omission, an unauthorised third party has gained access to the Employer Portal following the successful entry of your password.
7.3 c For the purpose of clause 7.3a and 7.3b and any other misuse of your Employer Portal Access, you will continue to be liable in relation to all information accessed up until the time you notify the Trustee on 1300 878 737 that:
- the password may have become known to someone not entitled to know it, or;
- unauthorised Employer Portal Access may have been gained in some other way, and;
- the Trustee has had a reasonable opportunity to take appropriate security measures.
7.3 d You will not be liable for unauthorised access to the Employer Portal following correct entry of your password if all of the following apply:
- you were in no way responsible for the password becoming known to, or the Employer Portal being used by, an unauthorised user;
- you were not otherwise in breach of these Terms and Conditions;
- you have otherwise acted honestly and reasonably and taken all due and proper care in the use of the Employer Portal and your Employer Portal Access; and
- you fully co-operate with us and assist in investigating the circumstances that may have resulted in the unauthorised access.
Nothing in this clause 7.3d is to be taken as imposing a duty or obligation on the Trustee that would not otherwise apply.
7.3 e the Trustee is not liable for:
- reliance by anyone on information obtained through the use of the Employer Portal and your Employer Portal Access;
- any failure by the Employer Portal to provide information or perform operations requested, or any delays as a result of any circumstances beyond the Trustee’s reasonable control;
- any amount of loss or damage, except in the event of our negligence, fraud or deliberate misconduct;
- indirect, consequential or special loss or damage however caused, including as a result of negligence, whether or not the loss or damage was foreseeable;
- unavailability of the Employer Portal as a result of any circumstances beyond the Trustee’s reasonable control; or,
- any other events whatsoever beyond the Trustee's reasonable control.
7.4 Australian Residency and Data Sovereignty
By accessing and using this portal, you acknowledge and agree to the following:
7.4 a Australian Residency Requirement: You confirm that you are located within Australia and are authorised to access this portal solely for business purposes related to Australian operations.
7.4 b Data Sovereignty and Sharing Restrictions: You agree that all data accessed, processed, or stored through this portal—including employee/Member-related information—must remain within Australia and must not be disclosed, transferred, or made accessible to any party outside of Australia, unless explicitly permitted under Australian law and in compliance with the Australian Privacy Principles (APPs).
7.4 c Third-Party Compliance: You must ensure that any third-party service providers or systems you use in conjunction with this portal also comply with Australian privacy laws and do not facilitate the transfer or access of data outside Australia unless the receiving jurisdiction is recognised as having substantially similar privacy protections under the current 'whitelist' mechanism introduced by the Privacy and Other Legislation Amendment Act 2024.
7.4 d Breach Consequences: Any breach of these obligations may result in suspension or termination of access to the portal and may be subject to investigation.
7.5 Authorised Access to Employer Bank Account Information
By using this portal, you acknowledge and agree to the following:
7.5 a Bank Account Visibility: In order to facilitate Employer-requested refund transactions, Authorised Users of the portal—those authorised to act on behalf of the Employer—may be able to view bank account details associated with the Employer as recorded in Aware’s registry systems.
7.5 b Consent to Disclosure: The Employer consents to the exposure of its bank account information to:
- Authorised Users acting on its behalf within the portal, and
- Aware staff who may access the portal to assist those users in completing refund requests.
7.5 c Purpose Limitation: Bank account information will be displayed solely for the purpose of enabling accurate and secure processing of refund requests initiated by the Employer. It will not be used for any other purpose or disclosed to unauthorised parties except as described above from within the portal.
7.5 d Security and Compliance: Aware will take reasonable steps to ensure that access to bank account information is restricted to Authorised Users and complies with applicable Australian privacy laws and data protection standards.
7.6 Obligation to Report Data Breaches
By using this portal, Employers acknowledge and agree to the following:
- Notification Requirement:
Employers must promptly notify Aware of any actual or suspected data breach involving personal information accessed, stored, or transmitted via the portal, including any breach occurring within the Employer’s own systems that may impact data held or processed through the portal. - Compliance with the Privacy Act and APPs:
This obligation supports Aware Super to protect your employees (Members) as well as meets our obligations with the Privacy Act 1988 and the Australian Privacy Principles. - Timeliness and Cooperation:
Employers must notify Aware without undue delay and provide sufficient detail to enable Aware to assess the impact and take appropriate remedial action. This includes:- The nature and scope of the breach,
- The types of personal information involved,
- Steps taken or planned to contain and mitigate the breach.
- Shared Responsibility:
Employers acknowledge that data protection is a shared responsibility. Timely reporting enables Aware to meet its own legal obligations under the Privacy Act and to support affected individuals appropriately. - Consequences of Non-Disclosure:
Failure to report a data breach may result in regulatory action under the Privacy Act, including investigations, fines, and reputational damage.
Aware reserves the right to suspend, restrict or terminate portal access if an Employer fails to comply with this obligation, or if Aware determines in its sole discretion that suspension, restriction or termination of access is necessary to protect the relevant interests of Aware or its Members.
9 Privacy
9.1 Obligations
(a) Without limiting any other provision of this document, a party will comply with the requirements of the Privacy Act 1988 (Cth) and all other relevant laws and regulations in relation to any personal information collected by the party from the other party or disclosed to the party by the other party or reasonably accessible by the party under this document.
(b) Without limiting any other provision of this document, the Employer represents and warrants to the Trustee that the Employer has made all necessary disclosures (including at the time of collection of any personal information of Members) and has obtained all the necessary consents or permissions to enable the Employer to provide the Trustee with information and documentation in relation to a Member (including personal information) under the control or in the possession of the Employer in accordance with this document.
(c) Notwithstanding clause 9.1(a), any personal information collected by the Employer or Authorised Users under this document must be handled in accordance with Aware Super’s Privacy Policy.
9.2 Employer Information
The purpose for which the Trustee is collecting your information is to administer Employer Portal Access. If the information requested is not provided, the Trustee will not be able to register you as an Employer Portal user.
By using the Employer Portal, you consent to the collection, use and retention of your personal information within the Employer Portal in accordance with Aware’s Privacy Policy, Privacy Act 1988 and the Australian Privacy Principles.
The Trustee may also use this information to notify you about Aware Super and other products.
For further information about how Aware Super collects, uses and discloses information, please refer to our privacy policy.
You can locate Aware Super’s Privacy Policy at http://aware.com.au/conditions-of-use/privacy-and-governance or call 1300 878 373 for a copy.
10 Further information
You can contact Aware Super by:
Telephone (Employer Services): 1300 878 373