• Specific Year
    Any

PRIVACY AND DATA PROTECTION ACT 2014 (NO. 60 OF 2014) - SECT 78 Compliance notice

PRIVACY AND DATA PROTECTION ACT 2014 (NO. 60 OF 2014) - SECT 78

Compliance notice

    (1)     The Commissioner may serve a compliance notice on an organisation, if it appears to the Commissioner that—

        (a)     the organisation has done an act or engaged in a practice in contravention of an Information Privacy Principle (including an act or practice that is in contravention of an applicable code of practice) or an approved information usage arrangement; and

        (b)     the act or practice—

              (i)     constitutes a serious or flagrant contravention; or

              (ii)     is of a kind that has been done or engaged in by the organisation on at least 5 separate occasions within the previous 2 years.

    (2)     A compliance notice requires the organisation to take specified action within a specified period for the purpose of ensuring compliance with the Information Privacy Principle, applicable code of practice or approved information usage arrangement.

    (3)     If the Commissioner is satisfied, on the application of an organisation on which a compliance notice is served, that it is not reasonably possible to take the action specified in the notice within the period specified in the notice, the Commissioner may extend the period specified in the notice on the organisation giving the Commissioner an undertaking to take the specified action within the extended period.

    (4)     The Commissioner may only extend a period under subsection (3) if an application for the extension is made before the period specified in the notice expires.

    (5)     The Commissioner may act under subsection (1) on the Commissioner's own initiative or on an application by an individual who was a complainant under Division 8.

    (6)     In deciding whether or not to serve a compliance notice, the Commissioner may have regard to the extent to which the organisation has complied with a decision of VCAT under Subdivision 5 of Division 8.