Australian Privacy Act 1988
Total Page:16
File Type:pdf, Size:1020Kb
Privacy Act 1988 No. 119, 1988 as amended Compilation start date: 30 October 2014 Includes amendments up to: Act No. 108, 2014 Prepared by the Office of Parliamentary Counsel, Canberra ComLaw Authoritative Act C2014C00757 About this compilation This compilation This is a compilation of the Privacy Act 1988 as in force on 30 October 2014. It includes any commenced amendment affecting the legislation to that date. This compilation was prepared on 30 October 2014. The notes at the end of this compilation (the endnotes) include information about amending laws and the amendment history of each amended provision. Uncommenced amendments The effect of uncommenced amendments is not reflected in the text of the compiled law but the text of the amendments is included in the endnotes. Application, saving and transitional provisions for provisions and amendments If the operation of a provision or amendment is affected by an application, saving or transitional provision that is not included in this compilation, details are included in the endnotes. Modifications If a provision of the compiled law is affected by a modification that is in force, details are included in the endnotes. Provisions ceasing to have effect If a provision of the compiled law has expired or otherwise ceased to have effect in accordance with a provision of the law, details are included in the endnotes. ComLaw Authoritative Act C2014C00757 Contents Part I—Preliminary 1 1 Short title ........................................................................................... 1 2 Commencement ................................................................................. 1 2A Objects of this Act ............................................................................. 1 3 Saving of certain State and Territory laws ......................................... 2 3A Application of the Criminal Code ..................................................... 2 4 Act to bind the Crown ....................................................................... 3 5A Extension to external Territories ....................................................... 3 5B Extra-territorial operation of Act ....................................................... 3 Part II—Interpretation 5 Division 1—General definitions 5 6 Interpretation ..................................................................................... 5 6AA Meaning of responsible person ....................................................... 32 6A Breach of an Australian Privacy Principle ....................................... 33 6B Breach of a registered APP code ..................................................... 35 6BA Breach of the registered CR code .................................................... 36 6C Organisations ................................................................................... 36 6D Small business and small business operators ................................... 38 6DA What is the annual turnover of a business? ..................................... 41 6E Small business operator treated as organisation .............................. 41 6EA Small business operators choosing to be treated as organisations .................................................................................... 44 6F State instrumentalities etc. treated as organisations ......................... 45 Division 2—Key definitions relating to credit reporting 46 Subdivision A—Credit provider 46 6G Meaning of credit provider .............................................................. 46 6H Agents of credit providers ............................................................... 47 6J Securitisation arrangements etc. ...................................................... 48 6K Acquisition of the rights of a credit provider ................................... 49 Subdivision B—Other definitions 50 6L Meaning of access seeker ................................................................ 50 6M Meaning of credit and amount of credit .......................................... 50 6N Meaning of credit information......................................................... 51 6P Meaning of credit reporting business .............................................. 52 6Q Meaning of default information ....................................................... 52 6R Meaning of information request ...................................................... 54 6S Meaning of new arrangement information ...................................... 55 Privacy Act 1988 i ComLaw Authoritative Act C2014C00757 6T Meaning of payment information .................................................... 56 6U Meaning of personal insolvency information .................................. 56 6V Meaning of repayment history information ..................................... 57 Division 3—Other matters 58 7 Acts and practices of agencies, organisations etc. ........................... 58 7A Acts of certain agencies treated as acts of organisation ................... 61 7B Exempt acts and exempt practices of organisations ......................... 62 7C Political acts and practices are exempt ............................................ 63 8 Acts and practices of, and disclosure of information to, staff of agency, organisation etc. ............................................................. 65 10 Agencies that are taken to hold a record .......................................... 67 11 File number recipients ..................................................................... 68 12A Act not to apply in relation to State banking or insurance within that State ............................................................................... 68 12B Severability—additional effect of this Act ...................................... 69 Part III—Information privacy 71 Division 1—Interferences with privacy 71 13 Interferences with privacy ............................................................... 71 13B Related bodies corporate ................................................................. 73 13C Change in partnership because of change in partners ...................... 74 13D Overseas act required by foreign law............................................... 75 13E Effect of sections 13B, 13C and 13D .............................................. 75 13F Act or practice not covered by section 13 is not an interference with privacy ................................................................. 75 13G Serious and repeated interferences with privacy .............................. 75 Division 2—Australian Privacy Principles 76 14 Australian Privacy Principles.......................................................... 76 15 APP entities must comply with Australian Privacy Principles ........ 76 16 Personal, family or household affairs .............................................. 76 16A Permitted general situations in relation to the collection, use or disclosure of personal information .............................................. 76 16B Permitted health situations in relation to the collection, use or disclosure of health information .................................................. 78 16C Acts and practices of overseas recipients of personal information ...................................................................................... 81 Division 4—Tax file number information 83 17 Rules relating to tax file number information .................................. 83 18 File number recipients to comply with rules .................................... 83 ii Privacy Act 1988 ComLaw Authoritative Act C2014C00757 Part IIIA—Credit reporting 84 Division 1—Introduction 84 19 Guide to this Part ............................................................................. 84 Division 2—Credit reporting bodies 85 Subdivision A—Introduction and application of this Division etc. 85 20 Guide to this Division ...................................................................... 85 20A Application of this Division and the Australian Privacy Principles to credit reporting bodies ................................................ 85 Subdivision B—Consideration of information privacy 86 20B Open and transparent management of credit reporting information ...................................................................................... 86 Subdivision C—Collection of credit information 87 20C Collection of solicited credit information ........................................ 87 20D Dealing with unsolicited credit information .................................... 89 Subdivision D—Dealing with credit reporting information etc. 90 20E Use or disclosure of credit reporting information ............................ 90 20F Permitted CRB disclosures in relation to individuals ...................... 92 20G Use or disclosure of credit reporting information for the purposes of direct marketing ........................................................... 93 20H Use or disclosure of pre-screening assessments .............................. 95 20J Destruction of pre-screening assessment ......................................... 96 20K No use or disclosure of credit reporting information during a ban period ........................................................................................ 96 20L Adoption of government related identifiers ..................................... 98 20M Use or disclosure of credit reporting information that is de-identified..................................................................................... 98 Subdivision E—Integrity of credit reporting information