Commonwealth Consolidated ActsAct No. 119 of 1988 as amended
This compilation was prepared on 4 October 2007
taking into account amendments up to Act No. 158 of 2007
The text of any of those amendments not in force
on that date is appended in the Notes section
The operation of amendments that have been incorporated may
be
affected by application provisions that are set out in the Notes section
Prepared by the Office of Legislative Drafting and
Publishing,
Attorney‑General's Department, Canberra
Contents
Part I--Preliminary 1
1............ Short title [see Note 1] ....................................................................... 1
2............ Commencement [see Note 1] .............................................................. 1
3............ Saving of certain State and Territory laws .......................................... 1
3A......... Application of the Criminal Code ...................................................... 2
4............ Act to bind the Crown ........................................................................ 2
5............ Interpretation of Information Privacy Principles ............................... 2
5A......... Extension to external Territories ......................................................... 2
5B......... Extra‑territorial operation of Act ........................................................ 3
Part II--Interpretation 5
6............ Interpretation ...................................................................................... 5
6A......... Breach of a National Privacy Principle ............................................. 20
6B......... Breach of an approved privacy code ................................................ 21
6C......... Organisations .................................................................................... 22
6D......... Small business and small business operators .................................... 25
6DA...... What is the annual turnover of a business? ..................................... 27
6E.......... Small business operator treated as organisation ............................... 28
6EA....... Small business operators choosing to be treated as organisations .... 29
6F.......... State instrumentalities etc. treated as organisations ......................... 30
7............ Acts and practices of agencies, organisations etc. ............................ 31
7A......... Acts of certain agencies treated as acts of organisation .................... 34
7B......... Exempt acts and exempt practices of organisations ......................... 35
7C......... Political acts and practices are exempt ............................................. 37
8............ Acts and practices of, and disclosure of information to, staff of agency, organisation etc. 39
9............ Collectors .......................................................................................... 40
10.......... Record‑keepers ................................................................................. 41
11.......... File number recipients ...................................................................... 42
11A....... Credit reporting agencies .................................................................. 43
11B....... Credit providers ................................................................................ 43
12.......... Application of Information Privacy Principles to agency in possession 46
12A....... Act not to apply in relation to State banking or insurance within that State 46
12B....... Severability: additional effect of Act in relation to organisations ..... 46
Part III--Information privacy 48
Division 1--Interferences with privacy 48
13.......... Interferences with privacy ................................................................ 48
13A....... Interferences with privacy by organisations .................................... 49
13B....... Related bodies corporate .................................................................. 50
13C....... Change in partnership because of change in partners ....................... 51
13D....... Overseas act required by foreign law ................................................ 52
13E........ Effect on section 13 of sections 13B, 13C and 13D ......................... 52
13F........ Act or practice not covered by section 13 or section 13A is not an interference with privacy 52
Division 2--Information Privacy Principles 53
14.......... Information Privacy Principles ......................................................... 53
15.......... Application of Information Privacy Principles ................................ 59
16.......... Agencies to comply with Information Privacy Principles ............... 59
Division 3--Approved privacy codes and the National Privacy Principles 60
16A....... Organisations to comply with approved privacy codes or National Privacy Principles 60
16B....... Personal information in records ........................................................ 60
16C....... Application of National Privacy Principles ..................................... 61
16D....... Delayed application of National Privacy Principles to small business 61
16E........ Personal, family or household affairs ............................................... 62
16F........ Information under Commonwealth contract not to be used for direct marketing 63
Division 4--Tax file number information 64
17.......... Guidelines relating to tax file number information ............................ 64
18.......... File number recipients to comply with guidelines ............................ 64
Division 5--Credit information 65
18A....... Code of Conduct relating to credit information files and credit reports 65
18B....... Credit reporting agencies and credit providers to comply with Code of Conduct 65
Part IIIAA--Privacy codes 66
18BA.... Application for approval of privacy code ........................................ 66
18BAA. Privacy codes may cover exempt acts or practices .......................... 66
18BB..... Commissioner may approve privacy code ....................................... 66
18BC..... When approval takes effect .............................................................. 69
18BD.... Varying an approved privacy code ................................................... 69
18BE..... Revoking the approval of an approved privacy code ....................... 70
18BF..... Guidelines about privacy codes ........................................................ 70
18BG.... Register of approved privacy codes ................................................. 71
18BH.... Review of operation of approved privacy code ............................... 71
18BI...... Review of adjudicator's decision under approved privacy code ...... 72
Part IIIA--Credit reporting 73
18C....... Certain credit reporting only to be undertaken by corporations ...... 73
18D....... Personal information not to be given to certain persons carrying on credit reporting 73
18E........ Permitted contents of credit information files .................................. 74
18F........ Deletion of information from credit information files ...................... 77
18G....... Accuracy and security of credit information files and credit reports 79
18H....... Access to credit information files and credit reports ........................ 80
18J........ Alteration of credit information files and credit reports ................... 80
18K....... Limits on disclosure of personal information by credit reporting agencies 81
18L........ Limits on use by credit providers of personal information contained in credit reports etc. 85
18M...... Information to be given if an individual's application for credit is refused 88
18N....... Limits on disclosure by credit providers of personal information contained in reports relating to credit worthiness etc. .......................................................................................................... 89
18NA.... Disclosure by credit providers to certain persons who gave indemnities 97
18P........ Limits on use or disclosure by mortgage insurers or trade insurers of personal information contained in credit reports .......................................................................................................... 97
18Q....... Limits on use by certain persons of personal information obtained from credit providers 99
18R....... False or misleading credit reports ................................................... 101
18S........ Unauthorised access to credit information files or credit reports ... 102
18T....... Obtaining access to credit information files or credit reports by false pretences 102
18U....... Application of section 4B of Crimes Act ....................................... 102
18V....... Application of this Part .................................................................. 103
Part IV--Office of the Privacy Commissioner 104
Division 1--Office of the Privacy Commissioner 104
19.......... Establishment of the Office of the Privacy Commissioner ............ 104
19A....... Privacy Commissioner .................................................................... 104
20.......... Terms and conditions of appointment ........................................... 104
21.......... Remuneration of Commissioner ..................................................... 104
22.......... Leave of absence ............................................................................. 105
23.......... Outside employment ...................................................................... 105
24.......... Resignation ..................................................................................... 105
25.......... Termination of appointment .......................................................... 105
26.......... Acting Commissioner ..................................................................... 106
26A....... Staff and consultants ...................................................................... 106
Division 2--Functions of Commissioner 107
27.......... Functions of Commissioner in relation to interferences with privacy 107
28.......... Functions of Commissioner in relation to tax file numbers ............ 110
28A....... Functions of Commissioner in relation to credit reporting ............. 111
29.......... Commissioner to have regard to certain matters ............................. 112
Division 3--Reports by Commissioner 114
30.......... Reports following investigation of act or practice .......................... 114
31.......... Report following examination of proposed enactment ................... 116
32.......... Report following monitoring of certain activities ........................... 116
33.......... Exclusion of certain matters from reports ...................................... 117
Division 4--Miscellaneous 119
34.......... Provisions relating to documents exempt under the Freedom of Information Act 1982 119
35.......... Direction where refusal or failure to amend exempt document ...... 119
Part V--Investigations 121
Division 1--Investigation of complaints and investigations on the Commissioner's initiative 121
36.......... Complaints ..................................................................................... 121
37.......... Principal executive of agency .......................................................... 122
38.......... Conditions for making a representative complaint ......................... 123
38A....... Commissioner may determine that a complaint is not to continue as a representative complaint 124
38B....... Additional rules applying to the determination of representative complaints 125
38C....... Amendment of representative complaints ...................................... 125
39.......... Class member for representative complaint not entitled to lodge individual complaint 125
40.......... Investigations .................................................................................. 125
40A....... Referring complaint about act under Commonwealth contract ...... 126
41.......... Circumstances in which Commissioner may decide not to investigate or may defer investigation 127
42.......... Preliminary inquiries ....................................................................... 128
43.......... Conduct of investigations ............................................................... 128
44.......... Power to obtain information and documents .................................. 130
45.......... Power to examine witnesses ........................................................... 131
46.......... Directions to persons to attend compulsory conference ................ 131
47.......... Conduct of compulsory conference ................................................ 132
48.......... Complainant and certain other persons to be informed of various matters 133
49.......... Investigation under section 40 to cease if certain offences may have been committed 133
50.......... Reference of matters to other authorities [see Note 2] ................... 134
50A....... Substitution of respondent to complaint ........................................ 136
51.......... Effect of investigation by Auditor‑General .................................... 137
Division 2--Determinations following investigation of complaints 138
52.......... Determination of the Commissioner ............................................... 138
53.......... Determination must identify the class members who are to be affected by the determination 140
53A....... Notice to be given to outsourcing agency ....................................... 140
53B....... Substituting respondent to determination ...................................... 141
Division 3--Enforcement 142
54.......... Application of Division .................................................................. 142
55.......... Obligations of respondent organisation .......................................... 142
55A....... Proceedings in the Federal Court or Federal Magistrates Court to enforce a determination 143
55B....... Evidentiary certificate ..................................................................... 144
Division 4--Review and enforcement of determinations involving Commonwealth agencies 146
57.......... Application of Division .................................................................. 146
58.......... Obligations of respondent agency .................................................. 146
59.......... Obligations of principal executive of agency .................................. 146
60.......... Compensation and expenses ........................................................... 147
61.......... Review of determinations regarding compensation and expenses .. 147
62.......... Enforcement of determination against an agency ............................ 147
Division 5--Miscellaneous 149
63.......... Legal assistance ............................................................................... 149
64.......... Commissioner etc. not to be sued ................................................... 150
65.......... Failure to attend etc. before Commissioner .................................... 150
66.......... Failure to give information etc. ....................................................... 151
67.......... Protection from civil actions ........................................................... 154
68.......... Power to enter premises ................................................................. 154
68A....... Identity cards .................................................................................. 155
69.......... Restrictions on Commissioner obtaining personal information and documents 156
70.......... Certain documents and information not required to be disclosed ... 158
70A....... Application of Part to organisations that are not legal persons ..... 159
70B....... Application of this Part to former organisations ............................ 159
Part VI--Public interest determinations and temporary public interest determinations 161
Division 1--Public interest determinations 161
71.......... Interpretation .................................................................................. 161
72.......... Power to make, and effect of, determinations ................................ 161
73.......... Application by agency or organisation ........................................... 162
74.......... Publication of application ............................................................... 163
75.......... Draft determination ........................................................................ 163
76.......... Conference ...................................................................................... 164
77.......... Conduct of conference .................................................................... 164
78.......... Determination of application .......................................................... 165
79.......... Making of determination ................................................................ 165
80.......... Determinations disallowable ........................................................... 165
Division 2--Temporary public interest determinations 166
80A....... Temporary public interest determinations ..................................... 166
80B....... Effect of temporary public interest determination ......................... 166
80C....... Determinations disallowable ........................................................... 167
80D....... Commissioner may continue to consider application ..................... 167
Division 3--Register of determinations 168
80E........ Register of determinations .............................................................. 168
Part VIA--Dealing with personal information in emergencies and disasters 169
Division 1--Object and interpretation 169
80F........ Object ............................................................................................. 169
80G....... Interpretation .................................................................................. 169
80H....... Meaning of permitted purpose ........................................................ 170
Division 2--Declaration of emergency 171
80J........ Declaration of emergency--events of national significance ............ 171
80K....... Declaration of emergency--events outside Australia ..................... 171
80L........ Form of declarations ....................................................................... 172
80M...... When declarations take effect ......................................................... 172
80N....... When declarations cease to have effect ........................................... 172
Division 3--Provisions dealing with the use and disclosure of personal information 173
80P........ Authorisation of collection, use and disclosure of personal information 173
Division 4--Other matters 176
80Q....... Disclosure of information--offence ............................................... 176
80R....... Operation of Part ............................................................................ 177
80S........ Severability--additional effect of Part ........................................... 177
80T....... Compensation for acquisition of property--constitutional safety net 178
Part VII--Privacy Advisory Committee 180
81.......... Interpretation .................................................................................. 180
82.......... Establishment and membership ...................................................... 180
83.......... Functions ........................................................................................ 181
84.......... Leave of absence ............................................................................. 181
85.......... Removal and resignation of members ............................................. 182
86.......... Disclosure of interests of members ................................................ 182
87.......... Meetings of Advisory Committee .................................................. 182
88.......... Travel allowance ............................................................................. 183
Part VIII--Obligations of confidence 184
89.......... Obligations of confidence to which Part applies ............................ 184
90.......... Application of Part ......................................................................... 184
91.......... Effect of Part on other laws ............................................................ 184
92.......... Extension of certain obligations of confidence ................................ 185
93.......... Relief for breach etc. of certain obligations of confidence .............. 185
94.......... Jurisdiction of courts ...................................................................... 185
Part IX--Miscellaneous 186
95.......... Medical research guidelines ............................................................ 186
95A....... Guidelines for National Privacy Principles about health information 186
95AA.... Guidelines for National Privacy Principles about genetic information 188
95B....... Requirements for Commonwealth contracts .................................. 188
95C....... Disclosure of certain provisions of Commonwealth contracts ....... 189
96.......... Non‑disclosure of private information ........................................... 189
97.......... Annual report ................................................................................. 191
98.......... Injunctions ...................................................................................... 191
99.......... Delegation ....................................................................................... 193
99A....... Conduct of directors, employees and agents .................................. 193
100........ Regulations ..................................................................................... 195
Part X--Amendments of other Acts 197
101........ Amendments of other Acts ............................................................ 197
Schedule 1--Amendments of other Acts 198
Schedule 2--Interim guidelines concerning the collection, storage, use and security of tax file number information 199
Introduction ................................................................................................... 199
1............ General ............................................................................................ 199
2............ Collection of tax file number information ....................................... 200
3............ Storage and security of tax file number information ....................... 200
4............ Use and disclosure of tax file number information ......................... 201
5............ Publicity ......................................................................................... 201
6............ Cessation of employment and investment ..................................... 201
7............ Meaning of terms in interim guidelines ........................................... 202
Schedule 3--National Privacy Principles 203
1............ Collection ........................................................................................ 203
2............ Use and disclosure .......................................................................... 204
3............ Data quality .................................................................................... 208
4............ Data security .................................................................................. 208
5............ Openness ........................................................................................ 208
6............ Access and correction ..................................................................... 208
7............ Identifiers ........................................................................................ 210
8............ Anonymity ..................................................................................... 211
9............ Transborder data flows ................................................................... 211
10.......... Sensitive information ...................................................................... 212
Notes 215
An Act to make provision to protect the privacy of individuals, and for related purposes
WHEREAS Australia is a party to the International Covenant on Civil and Political Rights, the English text of which is set out in Schedule 2 to the Human Rights and Equal Opportunity Commission Act 1986:
AND WHEREAS, by that Covenant, Australia has undertaken to adopt such legislative measures as may be necessary to give effect to the right of persons not to be subjected to arbitrary or unlawful interference with their privacy, family, home or correspondence:
AND WHEREAS Australia is a member of the Organisation for Economic Co‑operation and Development:
AND WHEREAS the Council of that Organisation has recommended that member countries take into account in their domestic legislation the principles concerning the protection of privacy and individual liberties set forth in Guidelines annexed to the recommendation:
AND WHEREAS Australia has informed that Organisation that it will participate in the recommendation concerning those Guidelines:
BE IT THEREFORE ENACTED by the Queen, and the Senate and the House of Representatives of the Commonwealth of Australia, as follows:
Note 1 The Privacy Act 1988 as shown in this compilation
comprises Act No. 119, 1988 amended as indicated in the Tables below. The Privacy Act 1988 was modified by the Australian
Capital Territory Government Service (Consequential Provisions) Act 1994
For application, saving or transitional provisions made by the Corporations (Repeals, Consequentials and Transitionals) Act 2001, see Act No. 55, 2001.
All relevant information pertaining to application, saving or transitional provisions prior to 18 June 1997 is not included in this compilation. For subsequent information see Table A.
The Privacy Act 1988 was modified by the Banking (State Bank of South Australia and Other Matters) Act 1994 (No. 69, 1994) see Table B.
Table of Acts
|
Act |
Number |
Date |
Date of commencement |
Application, saving or transitional provisions |
||
|
119, 1988 |
14 Dec 1988 |
1 Jan 1989 (see Gazette 1988, |
|
|
||
|
11, 1990 |
17 Jan 1990 |
Part 1 (ss. 1, 2) and Part 3 (ss. 6, 7):
Royal Assent |
-- |
|
||
|
75, 1990 |
22 Oct 1990 |
S. 5: Royal Assent (a) |
-- |
|
||
|
116, 1990 |
24 Dec 1990 |
24 Sept 1991 |
S. 25 (ad. by 136, 1991, |
|
||
|
as amended by |
|
|
|
|
|
|
|
136, 1991 |
12 Sept 1991 |
Part 4 (s. 21): |
-- |
|
||
|
165, 1992 |
11 Dec 1992 |
S. 4: (c) |
-- |
|
||
|
Data‑matching Program (Assistance and Tax) Act 1990 |
20, 1991 |
23 Jan 1991 |
23 Jan 1991 |
-- |
|
|
|
28, 1991 |
4 Mar 1991 |
S. 74(1): Royal Assent (d) |
-- |
|
||
|
122, 1991 |
27 June 1991 |
Ss. 4(1), 10(b) and 15--20: 1 Dec 1988 |
S. 31(2) |
|
||
|
136, 1991 |
12 Sept 1991 |
Part 3 (ss. 10--20): (e) |
-- |
|
||
|
194, 1991 |
13 Dec 1991 |
Schedule 5 (Part 2): (f) |
-- |
|
||
|
143, 1992 |
7 Dec 1992 |
7 Dec 1992 |
-- |
|
||
|
28, 1993 |
9 June 1993 |
9 June 1993 |
-- |
|
||
|
13, 1994 |
18 Jan 1994 |
S. 22: 13 Jan 1993 |
S. 16 |
|
||
|
84, 1994 |
23 June 1994 |
S. 71: Royal Assent (g) |
-- |
|
||
|
Australian Capital Territory Government Service (Consequential Provisions) Act 1994 |
92, 1994 |
29 June 1994 |
1 July 1994 (see Gazette 1994, |
-- |
|
|
|
177, 1994 |
19 Dec 1994 |
Ss. 1, 2(1), (3) and Part 2 (ss. 3--8): 19 Dec 1994 (see |
S. 19 |
|
||
|
59, 1995 |
28 June 1995 |
Schedule (item 25): 30 Oct 1992 |
Ss. 4 and 5 |
|
||
|
43, 1996 |
25 Oct 1996 |
Schedule 4 (item 122): Royal Assent (h) |
-- |
|
||
|
34, 1997 |
17 Apr 1997 |
Schedule 13: Royal Assent (i) |
-- |
|
||
|
82, 1997 |
18 June 1997 |
Schedule 4 (items 1, 2, 4--12): Royal Assent (j) |
Sch. 4 (item 12) [see Table A] |
|
||
|
as amended by |
|
|
|
|
|
|
|
100, 2005 |
6 July 2005 |
Schedule 2 (item 20): (ja) |
-- |
|
||
|
9, 2006 |
23 Mar 2006 |
Schedule 2 (item 19): (r) |
-- |
|
||
|
48, 1998 |
29 June 1998 |
Schedule 1 (item 133): 1 July 1998 ( see Gazette 1998, No. S316) (k) |
-- |
|
||
|
Financial Sector Reform (Amendments and Transitional Provisions) Act (No. 1) 1999 |
44, 1999 |
17 June 1999 |
Schedule 7 (items 126--128): (l) |
-- |
|
|
|
Public Employment (Consequential and Transitional) Amendment Act 1999 |
146, 1999 |
11 Nov 1999 |
Schedule 1 (items 738--747): |
-- |
|
|
|
Australian Security Intelligence Organisation Legislation Amendment Act 1999 |
161, 1999 |
10 Dec 1999 |
Schedule 3 (items 1, 49): (n) |
-- |
|
|
|
Privacy Amendment (Office of the Privacy Commissioner) Act 2000 |
2, 2000 |
29 Feb 2000 |
1 July 2000 (see Gazette 2000, |
Sch. 1 (item 15) [see Table A] |
|
|
|
9, 2000 |
7 Mar 2000 |
2 July 2000 (see Gazette 2000, |
Sch. 3 (items 20, 29, 34, 35) [see Table A] |
|
||
|
155, 2000 |
21 Dec 2000 |
Schedule 3: Royal Assent |
Sch. 1 (items 37, 53, 57, 76, 100, 124, 130) and Sch. 3 (item 4) [see Table A] |
|
||
|
Law and Justice Legislation Amendment (Application of Criminal Code) Act 2001 |
24, 2001 |
6 Apr 2001 |
S. 4(1), (2) and Schedule 40 (items 1--9, |
S. 4(1) and (2) [see Table A] |
|
|
|
Corporations (Repeals, Consequentials and Transitionals) Act 2001 |
55, 2001 |
28 June 2001 |
Ss. 4--14 and Schedule 3 (item 437): 15 July 2001 (see Gazette 2001, No. S285) (p) |
S. 2(8) (am. by 116, 2003, |
|
|
|
as amended by |
|
|
|
|
|
|
|
116, 2003 |
27 Nov 2003 |
Schedule 4 (item 1): (q) |
-- |
|
||
|
135, 2001 |
1 Oct 2001 |
Schedules 1--7 and 9--12: 12 Oct 2001 (see
Gazette 2001, No. S428) |
-- |
|
||
|
Abolition of Compulsory Age Retirement (Statutory Officeholders) Act 2001 |
159, 2001 |
1 Oct 2001 |
29 Oct 2001 |
Sch. 1 (item 97) [see Table A] |
|
|
|
125, 2002 |
10 Dec 2002 |
Schedule 2 (items 99--106): 1 Jan 2003 |
-- |
|
||
|
135, 2003 |
17 Dec 2003 |
Schedule 2 (item 39): 17 June 2004 |
-- |
|
||
|
49, 2004 |
21 Apr 2004 |
21 Apr 2004 |
Sch. 1 (items 3, 5) [see Table A] |
|
||
|
as amended by |
|
|
|
|
|
|
|
9, 2006 |
23 Mar 2006 |
Schedule 2 (item 21): (r) |
||||