Privacy Act 1988
Total Page:16
File Type:pdf, Size:1020Kb
Privacy Act 1988 No. 119, 1988 Compilation No. 81 Compilation date: 13 August 2019 Includes amendments up to: Act No. 63, 2019 Registered: 20 August 2019 Prepared by the Office of Parliamentary Counsel, Canberra Authorised Version C2019C00241 registered 20/08/2019 About this compilation This compilation This is a compilation of the Privacy Act 1988 that shows the text of the law as amended and in force on 13 August 2019 (the compilation date). The notes at the end of this compilation (the endnotes) include information about amending laws and the amendment history of provisions of the compiled law. Uncommenced amendments The effect of uncommenced amendments is not shown in the text of the compiled law. Any uncommenced amendments affecting the law are accessible on the Legislation Register (www.legislation.gov.au). The details of amendments made up to, but not commenced at, the compilation date are underlined in the endnotes. For more information on any uncommenced amendments, see the series page on the Legislation Register for the compiled law. Application, saving and transitional provisions for provisions and amendments If the operation of a provision or amendment of the compiled law is affected by an application, saving or transitional provision that is not included in this compilation, details are included in the endnotes. Editorial changes For more information about any editorial changes made in this compilation, see the endnotes. Modifications If the compiled law is modified by another law, the compiled law operates as modified but the modification does not amend the text of the law. Accordingly, this compilation does not show the text of the compiled law as modified. For more information on any modifications, see the series page on the Legislation Register for the compiled law. Self-repealing provisions If a provision of the compiled law has been repealed in accordance with a provision of the law, details are included in the endnotes. Authorised Version C2019C00241 registered 20/08/2019 Contents Part I—Preliminary 1 1 Short title ........................................................................................... 1 2 Commencement ................................................................................. 1 2A Objects of this Act ............................................................................. 1 3 Saving of certain State and Territory laws ......................................... 2 3A Application of the Criminal Code ..................................................... 2 4 Act to bind the Crown ....................................................................... 3 5A Extension to external Territories ....................................................... 3 5B Extra-territorial operation of Act ....................................................... 3 Part II—Interpretation 5 Division 1—General definitions 5 6 Interpretation ..................................................................................... 5 6AA Meaning of responsible person ....................................................... 32 6A Breach of an Australian Privacy Principle ....................................... 34 6B Breach of a registered APP code ..................................................... 35 6BA Breach of the registered CR code .................................................... 36 6C Organisations ................................................................................... 36 6D Small business and small business operators ................................... 39 6DA What is the annual turnover of a business? ..................................... 41 6E Small business operator treated as organisation .............................. 42 6EA Small business operators choosing to be treated as organisations .................................................................................... 45 6F State instrumentalities etc. treated as organisations ......................... 46 6FA Meaning of health information ........................................................ 46 6FB Meaning of health service ............................................................... 47 Division 2—Key definitions relating to credit reporting 49 Subdivision A—Credit provider 49 6G Meaning of credit provider .............................................................. 49 6H Agents of credit providers ............................................................... 50 6J Securitisation arrangements etc. ...................................................... 51 6K Acquisition of the rights of a credit provider ................................... 52 Subdivision B—Other definitions 53 6L Meaning of access seeker ................................................................ 53 6M Meaning of credit and amount of credit .......................................... 53 6N Meaning of credit information......................................................... 54 Privacy Act 1988 i Compilation No. 81 Compilation date: 13/8/19 Registered: 20/8/19 Authorised Version C2019C00241 registered 20/08/2019 6P Meaning of credit reporting business .............................................. 55 6Q Meaning of default information ....................................................... 56 6R Meaning of information request ...................................................... 57 6S Meaning of new arrangement information ...................................... 58 6T Meaning of payment information .................................................... 59 6U Meaning of personal insolvency information .................................. 59 6V Meaning of repayment history information ..................................... 60 Division 3—Other matters 62 7 Acts and practices of agencies, organisations etc. ........................... 62 7A Acts of certain agencies treated as acts of organisation ................... 65 7B Exempt acts and exempt practices of organisations ......................... 66 7C Political acts and practices are exempt ............................................ 68 8 Acts and practices of, and disclosure of information to, staff of agency, organisation etc. ............................................................. 70 10 Agencies that are taken to hold a record .......................................... 71 11 File number recipients ..................................................................... 72 12A Act not to apply in relation to State banking or insurance within that State ............................................................................... 73 12B Severability—additional effect of this Act ...................................... 73 Part III—Information privacy 76 Division 1—Interferences with privacy 76 13 Interferences with privacy ............................................................... 76 13B Related bodies corporate ................................................................. 78 13C Change in partnership because of change in partners ...................... 79 13D Overseas act required by foreign law............................................... 80 13E Effect of sections 13B, 13C and 13D .............................................. 80 13F Act or practice not covered by section 13 is not an interference with privacy ................................................................. 80 13G Serious and repeated interferences with privacy .............................. 80 Division 2—Australian Privacy Principles 81 14 Australian Privacy Principles.......................................................... 81 15 APP entities must comply with Australian Privacy Principles ........ 81 16 Personal, family or household affairs .............................................. 81 16A Permitted general situations in relation to the collection, use or disclosure of personal information .............................................. 81 16B Permitted health situations in relation to the collection, use or disclosure of health information .................................................. 84 ii Privacy Act 1988 Compilation No. 81 Compilation date: 13/8/19 Registered: 20/8/19 Authorised Version C2019C00241 registered 20/08/2019 16C Acts and practices of overseas recipients of personal information ...................................................................................... 87 Division 4—Tax file number information 88 17 Rules relating to tax file number information .................................. 88 18 File number recipients to comply with rules .................................... 88 Part IIIA—Credit reporting 89 Division 1—Introduction 89 19 Guide to this Part ............................................................................. 89 Division 2—Credit reporting bodies 90 Subdivision A—Introduction and application of this Division etc. 90 20 Guide to this Division ...................................................................... 90 20A Application of this Division and the Australian Privacy Principles to credit reporting bodies ................................................ 90 Subdivision B—Consideration of information privacy 91 20B Open and transparent management of credit reporting information ...................................................................................... 91 Subdivision C—Collection of credit information 92 20C Collection of solicited credit information ........................................ 92 20D Dealing with unsolicited credit information .................................... 94 Subdivision D—Dealing with credit reporting information etc. 95 20E Use or disclosure