The Privacy Act 1988 is the Australian law that sets out how government agencies and many organisations must collect, use, disclose and correct personal information, including credit reporting data.
Also known as: Privacy Act 1988, Commonwealth Privacy Act
Key points
- The Act's backbone is the 13 Australian Privacy Principles (APPs), covering collection, notice, use, direct marketing, security, access and correction.
- It applies to government agencies and to organisations above an annual turnover threshold, plus smaller ones handling credit reporting, health or other sensitive information.
- The Notifiable Data Breaches scheme requires organisations to assess breaches and notify the OAIC and affected people when serious harm is likely.
- Lenders and brokers handle identity documents, bank statements and credit files, so the Act sets duties on every application they touch.
Who the Privacy Act applies to
The Act covers two broad groups: federal government agencies, and private sector organisations that meet a threshold test. The most common test is annual turnover, but smaller organisations are also covered if they handle particular kinds of information, such as credit reporting, health records or other sensitive personal information. Credit reporting has its own dedicated provisions within the Act, so a business that engages in credit reporting is covered even if it sits under the turnover threshold.
Personal information means any information or opinion about an identified individual, or one who is reasonably identifiable: names, addresses, phone numbers, driver licence and tax file numbers, account numbers and more. Sensitive information, such as health, biometric data or political opinions, gets higher protection. The employee records exemption means personal information in employee records is generally outside the APPs while it is used in an employment context.
The Australian Privacy Principles
The 13 APPs set out what an organisation must do at each stage. It must manage personal information openly and publish a privacy policy (APP 1), collect only what is reasonably necessary and by fair means (APP 3), and tell people why it is collecting their data and who it may be shared with (APP 5). Information can only be used or disclosed for the purpose it was collected for unless an exception applies or the person consents (APP 6), and direct marketing needs a clear opt-out (APP 7).
Before sending personal information overseas, the organisation must take reasonable steps to make sure the recipient protects it (APP 8). It must keep data accurate (APP 10), secure it against misuse, loss and unauthorised access (APP 11), and give people access to their information and correct it on request (APPs 12 and 13).
Data breaches and enforcement
Under the Notifiable Data Breaches scheme, an eligible data breach occurs when personal information is accessed, disclosed or lost without authorisation and a reasonable person would conclude it is likely to cause serious harm. The organisation must contain the incident, assess it quickly and, if serious harm is likely, notify the OAIC and the affected individuals, explaining what happened and what they should do. The assessment has to be finished within 30 days of the entity becoming aware there may be an eligible breach, and notification must follow as soon as practicable.
The Office of the Australian Information Commissioner enforces the Act. It can investigate, audit, make determinations ordering remedial action or compensation, and accept enforceable undertakings, and for serious or repeated breaches it can seek civil penalties through the courts. Individuals can complain to the OAIC after first raising the issue with the organisation.
Example
A finance broker keeps copies of customers' driver licences, payslips and bank statements from past applications on a shared drive. A staff member's laptop is stolen, and the drive was synced to it without encryption. Because those files could be used for identity theft, a reasonable person would say serious harm is likely, so the broker contains the breach, works out which customers are affected, notifies them and the OAIC, and records every step. Encrypting devices and deleting files it no longer needs are the practical controls APP 11 expects.
Not to be confused with
- Data protection
- data protection is the broader practice of securing information; the Privacy Act is the specific law that sets Australian obligations
- OAIC
- the OAIC is the regulator that enforces the Privacy Act, not the law itself
- Comprehensive credit reporting (CCR)
- CCR is the credit data-sharing regime that operates under the Privacy Act's credit reporting provisions
Frequently asked questions
Does the Privacy Act apply to small businesses?
Possibly. Most small businesses under the annual turnover threshold are exempt, but the exemption falls away if the business handles health information, engages in credit reporting or meets other specified criteria. Check your turnover, the kinds of data you hold and whether you collect information from the public; the OAIC publishes detailed coverage guidance.
What are the Australian Privacy Principles?
The APPs are the 13 principles at the heart of the Privacy Act. They cover open management and privacy policies, anonymity, collecting and notifying, use and disclosure, direct marketing, cross-border disclosure, government identifiers, data quality, security, and an individual's right to access and correct their information. Each one sets a specific obligation for regulated entities.
When do I have to notify the OAIC about a data breach?
When the breach is an eligible data breach: personal information has been accessed, disclosed or lost without authorisation, and a reasonable person would conclude it is likely to cause serious harm to someone. If you suspect one, finish the assessment within 30 days of becoming aware, then notify the OAIC and the affected individuals as soon as practicable, keeping records of your assessment and response.
How do I make a privacy complaint?
Raise it with the organisation first and give them a chance to fix it. If that does not resolve the issue, lodge a complaint with the OAIC, which can investigate and make determinations requiring correction, deletion or other remedial steps. The OAIC website sets out the steps and timelines.
Can a business send my personal information overseas?
Yes, but under APP 8 it must first take reasonable steps to make sure the overseas recipient will handle the information in line with the APPs, typically through contract clauses and due diligence checks. Those steps should be documented, often in a privacy impact assessment, so the business can show what it did.
Related terms
OAIC
The OAIC is the Office of the Australian Information Commissioner, Australia's independent privacy regulator, which enforces the Privacy Act, the Australian Privacy Principles and the Notifiable Data Breaches scheme.
Read definitionData protection
Data protection is the legal duty of brokers and lenders to handle customers' personal information under the Privacy Act and the Australian Privacy Principles, from collection to secure destruction.
Read definitionComprehensive credit reporting (CCR)
Comprehensive credit reporting (CCR) is the system under which lenders share positive credit information, such as repayment history and credit limits, as well as defaults, on your credit file.
Read definitionKnow your customer (KYC)
Know your customer (KYC) is the process a reporting entity uses to identify and verify a customer, understand their business and assess the money laundering and terrorism financing risk.
Read definitionOpen banking
Open banking is the regulated framework under Australia's Consumer Data Right (CDR) that lets you authorise accredited third parties to access specific financial data held by your bank.
Read definitionEquifax
Equifax is a credit reporting body (credit bureau) that collects credit information from lenders and public records to build the credit files, reports and scores used to assess applications.
Read definitionGo deeper
Sources
This article is general information only and is not financial advice.