DSS source chapter · ServiceCite reference page
6. Privacy
Consent, personal information, privacy incidents and complaints.
Independent reference copy. Check the official source for current guidance.
Source details, coverage and attribution
Source record
Inclusive Employment Australia Guidelines — Part A: Administrative Requirements
Australian Government Department of Social Services
- Recorded version
- 1.1
- Effective
- 21 November 2025
- Publication location checked
- 21 September 2026
Independent web copy · not a Department publication. The recorded check is not a live check for newer Guidelines.
Check the official document and the applicable Deed, Work Orders, variations and Provider Portal instructions before acting.
How this copy is checked · changes and limitations
- Recorded file
- Automated checks compare stored source files with their recorded SHA-256 fingerprints. The fingerprint below identifies the original Word file used to prepare this copy; it does not certify the document's accuracy or currency.
- Web preparation
- Chapter pages are regenerated from the recorded conversion and checked for unexpected differences, conversion artefacts and broken section targets. This is a reproducibility check, not an independent review of every sentence against today's official document.
- What to verify with DSS
- Open the official publication to check the available version and compare the passage in its original context. ServiceCite is not endorsed by DSS and does not verify your organisation's private provider instructions.
Recorded publication details
Attribution and web changes
Source material: © Commonwealth of Australia 2025, Australian Government Department of Social Services, Inclusive Employment Australia Guidelines — Part A: Administrative Requirements, version 1.1. Used under the Creative Commons Attribution 4.0 International licence, subject to the exclusions in the DSS copyright notice.
ServiceCite split the Word document into chapter pages and reformatted it for the web. Word artefacts, source logos, duplicate navigation and internal authoring links were removed; workflow icons were replaced with text labels; and some links were moved for accessibility. ServiceCite headings, summaries, navigation and notices are independently written. This reuse does not imply Australian Government or DSS endorsement.
- Document ID
iea-guidelines-part-a- Version ID
iea-guidelines-part-a@1.1- SHA-256
1c38bae7298aedde9ae63598f24b4de2d4699417851ad7a24ced1eff3ff4ba61
Source: Australian Government Department of Social Services, Inclusive Employment Australia Guidelines — Part A: Administrative Requirements, version 1.1, © Commonwealth of Australia 2025. Used under CC BY 4.0 (creativecommons.org/licenses/by/4.0/), subject to the DSS copyright exclusions. Official source: https://www.dss.gov.au/system/files/documents/2025-12/inclusive-employment-australia-guidelines-part-a-v11-2.docx. ServiceCite reformatted the Word document for web navigation and search; this is not an official DSS publication. Authenticated provider material is excluded; check the applicable Deed and current portal instructions before operational use.
Save this chapter, or jump to a heading to work with an exact section.
My reading list 0
Keep public sources for a team discussion or your next visit. Saved on this browser only; links open the current reference, so check the version when returning.
Open a section and choose “Save source” to begin. Your list is shared between Canvas and Reader.
Supporting Documents for this Chapter
Supporting Documents (sign-in required)
-
Privacy Notification and Consent Form
-
Direct Registration Form
-
Release of Protected Information Notification Form
-
Public Interest Certificate (PIC)
6.1 Chapter Overview
This Chapter provides information for Providers, their Personnel and Third Parties on their obligations in relation to handling Personal and Protected Information about individuals, as well in relation to reporting privacy incidents.
6.2 Where to find your obligations
When a Provider enters into a Deed with the Commonwealth to deliver Services, the Provider becomes:
-
a “service organisation” with obligations about Protected Information under the Social Security (Administration) Act 1999 (Cth) (the Social Security Law), and
-
a “contract service provider” with obligations about personal information under the Privacy Act 1988 and the Australian Privacy Principles (the privacy law).
A Provider may also have other obligations about how to handle information under the laws of States or Territories where it operates as well. It is the Provider’s obligation under the Deed to make sure that it understands and complies with all its legal obligations when delivering the Services.
Privacy obligations
The privacy law sets minimum standards for handling personal information, known as the Australian Privacy Principles (APPs). The Office of the Australian Information Commissioner (OAIC) has published guidelines about the APPs and what they mean — see the OAIC website.
As the Provider is delivering work-related services to participants under the Deed with the Commonwealth, the Provider is a contract service provider and must meet the same APP requirements as a Commonwealth agency (rather than the APP requirements of an organisation).
If the Provider subcontracts any delivery of services to another organisation, then the Provider must make sure the subcontractor also meets the same APP requirements as a Commonwealth agency.
In delivering Services, Providers collect, use and disclose personal information about individuals. The APPs includes standards, rights and obligations around the:
-
management of Personal Information
-
collection, use and disclosure of Personal Information
-
the security of Personal Information, and
the rights of individuals to access and correct their Personal Information.
The APPs are principles-based law. The Provider must consider its own situation and relevant Deed provisions and implement procedures and policies to ensure compliance with the relevant APPs, noting that their obligations may be different as a contract service provider to those as an organisation undertaking other business activities.
The Provider and its Personnel must also make sure they comply with their obligations in relation to the tort of serious invasion of privacy, in Schedule 2 of the Privacy Law.
(Deed Reference(s): Clause 45)
6.2.1 Personal information and sensitive information
The Privacy Act 1988 defines “personal information” as:
information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, or is recorded in a material form or not. What is personal information? | OAIC.
Personal Information includes an individual’s name, signature, date of birth, address, telephone number, sensitive information, bank account details, employment information, and commentary or opinion about an individual. This kind of information may be shared verbally, contained in physical or digital files or documents, such as résumés or application forms provided by the individual, or in an email or text message, or recorded.
Sensitive Information is a subset of personal information and includes information that relates to an individual’s racial or ethnic origin, health status, genetics and biometrics, religious beliefs or affiliations, philosophical beliefs, sexual orientation, criminal record or membership of a political association, professional or trade association or trade union.
Sensitive Information is subject to higher levels of protection under Privacy Law.
Information about a person’s disability is generally considered to be Sensitive Information’, because it is a kind of information about a person’s health – see What is health information?. This means Providers will be handling ‘sensitive information’ as part of delivering the Services and need to ensure their practices, procedures and systems meet the higher privacy standard required. Providers should make sure they are also meeting any obligations about the handling of ‘health information’ under State or Territory law.
6.2.2 Consent and the APPs
In complying with the Privacy Act 1988, the APPs and this Chapter, it will be important for Providers to get consent from individuals for the handling of their personal and sensitive information.
In all cases, the Provider must ensure when it asks a person for their consent for the handling of their personal and sensitive information:
-
the individual is adequately informed before giving consent
-
the individual gives consent voluntarily
-
the consent is current and specific, and
-
the individual has the capacity to understand and communicate their consent.
Consent can be given expressly, either orally or in writing, or it can be implied. In whatever way the person gives their consent to the Provider, the Provider must record the consent so that it can be found and checked easily in the day-to-day operations of the provider and if the Department requires to see it. As described at 5.3.1 Storage of Documentary Evidence in the Department’s IT Systems, the best way to do this is to record the consent and how it was obtained in the Department’s IT system, where possible.
Please see 6.3.1 Participant consent requirements for requirements about the method of obtaining and recording participant consent prior to their commencement in the program.
Providers must establish a person’s capacity to give consent on a case-by-case, decision-by-decision basis. A person’s capacity to give consent can be affected by their age or the nature of their disability (e.g. people with an intellectual disability may be unable to give consent). Further, a person’s ability to give consent may change over time. A Provider must prepare practical guidance for their Personnel, which includes options for supported decision making, so Participants can make their own decisions about their personal information. As a guide, the Department recommends Providers familiarise themselves with the NDIA Supported Decision Material, available here: National SDM Guide.
Where an individual is under 18 years old, the Provider must decide if the individual has the capacity to consent on a case-by-case basis. The OAIC advises, as a general rule, that an individual under the age of 18 has the capacity to consent if they have the maturity to understand what is being proposed. If the individual lacks maturity, it may be appropriate for a parent or guardian to consent on their behalf.
A Provider’s ability to rely on a person’s consent diminishes over time. Providers must ensure each individual’s consent is regularly reviewed on an ongoing basis (such as in relation to the collection and disclosure of sensitive information under the Privacy Statement contained in the Privacy Notification and Consent Form (sign-in required) and/or Direct Registration Form, see APP 3: Collection of solicited personal information below). This process should typically occur annually.
Further information about consent can be found on the OAIC's website.
6.3 APP 3 and 5: Collection of solicited personal information
APP 3 outlines when an APP entity may collect solicited personal information, including sensitive information.
To deliver the Services they are contracted to provide, Providers are generally required to collect personal information. APP 3 outlines when an APP entity may collect solicited personal information, including sensitive information (see 6.2.2 Consent and the APPs).
Providers may only solicit and collect personal information that is reasonably necessary for, or directly related to, one or more of the Provider’s functions or activities. A Provider’s functions or activities will vary depending on the Services being delivered and Providers should consider their obligations under their Deed(s) with the Department to deliver Services before collecting personal information.
APP 5 requires an APP entity that collects personal information about an individual to take reasonable steps to notify the individual of certain matters or to ensure the individual is aware of those matters.
As well as obtaining their consent to the collection of sensitive information as required by APP 3, the Privacy Notification and Consent Form and Direct Registration Form (discussed below at 6.3.2 Consent to the collection of Sensitive Information) complies with APP 5.2 by informing the individual of matters such as:
-
the identity and contact details of the Department
-
the purposes for which the Department and Provider are collecting the personal information, and
-
the main consequences for the individual if all or some of the personal information is not collected by the Department and Provider.
The provider must not alter the Privacy Notification and Consent Form and Direct Registration Form. If the Department gives the Provider a template for an APP 5 notice and/or consent form, then the Provider must adopt or adapt that form in a manner that meets its obligations under the privacy law. In any event, all privacy and consent documents presented to Participants must use simple language and formatting as much as possible.
6.3.1 Participant consent requirements
In all instances, before providing employment services to Participants (new or transferred), Providers must provide Participants with the standard Privacy Notification and Consent Form (sign-in required) or Direct Registration Form (sign-in required) as appropriate. Providers must ensure they are using the most up-to-date form.
Providers must obtain the Participant’s consent and declaration in accordance with the Privacy Notification and Consent Form or the Direct Registration Form, as appropriate, before handling the Participant’s personal and sensitive information, commencing a Direct Registration process and/or providing them with employment services. In addition, the Provider must ensure that the Participant’s consent is current and checked for currency every 12 months or in changes of circumstances.
During the first meeting or interview with the new or transferred Participant, the Provider must:
-
issue the Participant with the appropriate standard Direct Registration Form or Privacy Notification and Consent Form
-
discuss and explain the contents of the form, answering any questions the Participant may have, in a manner that meets the Participant’s communication needs
-
ensure that the Participant understands in accordance with the Privacy Statement:
-
the types of personal information collected, and how it will be used and disclosed as part of the program
-
the Provider collects this information to commence the participant in the program or otherwise determine if the person is eligible to receive the Services, and will use the information to check whether the person already has a record in the Department’s IT Systems
-
they are not required to give consent for the collection of their Sensitive Information and can withdraw their consent at any time
-
that Services provided may change depending on whether personal information is given or consent is withdrawn
-
that withdrawing their consent may ultimately affect their participation in the program, and affect any mutual obligation requirements
-
which third parties have access to information in the Department’s IT Systems, and
-
if eligible, the Provider will use the information to register the person to start receiving the Services.
-
-
ensure they are satisfied that the Participant (or their Legal Guardian or authorised nominee has provided valid consent to how their personal information will be handled in accordance with the Privacy Statement in the relevant form
-
ensure the Participant agrees to the Participant declaration in the appropriate form
-
ensure they otherwise comply with and agree to the Provider declaration in the appropriate form at the same time as the Participant, and
-
otherwise ensure the Participant provides valid consent consistent with the requirements of the Privacy Act.
Participant does not provide consent
If a Participant does not wish to provide consent at the first meeting (for example they want to seek further information about how their information will be used so they can provide informed consent) they can provide a record of their consent at a later date but should be made aware that this will delay their ability to commence in the program. Implied consent is not sufficient to commence the participant or begin providing them with employment services.
Recording the Participant’s consent
Providers must ensure that a record is made of the Participant’s valid and express consent to have their information handled in accordance with the Privacy Statement in the Direct Registration Form or Privacy Notification and Consent Form. This record of consent should then be scanned and/or uploaded to the IT system. The preference is for Participants to record their consent via a hard copy or digital form. However, the Participant’s consent can be recorded in an alternative format to meet accessibility requirements.
Provided the Participant is providing express consent on the basis of information contained in the Direct Registration Form or Privacy Notification and Consent Form, has agreed to the contents of the declaration, and the Provider has complied and agreed to the declaration at the same time, a Participant’s consent can be recorded by:
-
completing and signing a hard copy form
-
completing and signing a digital copy form
-
a detailed file note by the Provider that the Participant has provided express verbal consent to the privacy statement
-
a written statement or email from the Participant or their nominee outlining they consent to the handling of their information in accordance with the relevant form and agree to the declaration
- I [participant full name] declare I have read and understood the [Direct Registration Form/ Privacy Notification and Consent Form]. I consent to the collection and use of my personal and sensitive information in accordance with the Privacy Statement and Declaration contained in the Direct Registration Form/ Privacy Notification and Consent Form. [DD/MM/YYYY]
-
another format as agreed to by the Department to best meet any accessibility requirements.
Where a file note, written statement or email is used to record the Participant’s consent, the record should at a minimum include the date and time of consent and be accompanied with a copy of the form provided to the participant, and the Provider’s signed declaration.
See also Inclusive Employment Australia Guidelines: Part B: Chapter 3: Commencements, Transfers, Suspensions and Exits.
6.3.2 Consent to the collection of Sensitive Information
Providers must only collect sensitive information where the individual gives consent to the collection, unless another exception applies.
In all other instances after a participant has been commenced and has not otherwise consented to a particular handling of their information, Providers must provide Participants with an APP 5 compliant Privacy Collection Notice. They must obtain the consent of the Participant before handling their sensitive information. In addition, the Provider must ensure that the Participant’s consent is current and checked for currency every 12 months or in changes of circumstances. Providers should make it clear to Participants that if they withhold or withdraw their consent, this may ultimately affect their participation in the program or affect any mutual obligation requirements they may have.
Whenever obtaining consent from a Participant, the Provider needs to ensure a Participant is given the time and information they need to understand what is being asked of them, so that the Participant has a real choice. This means the Provider must ensure their Personnel understand privacy and consent documents, so they can explain these in a manner that meets the Participant’s communication needs.
The Provider must provide guidance to their Personnel about how to properly identify and manage capacity or other issues which affect a Participant’s ability to understand a privacy or consent documents, including how and when to call on a Participant’s nominee or use an interpreter.
When signing the Privacy Notification and Consent Form or Direct Registration Form, the Participant indicates consent at the time of signing. Individuals may also provide their express consent to the form verbally. Refer to Section 6.3.1 Participant consent requirements for more information.
In some circumstances, Providers may also reasonably infer from an individual’s conduct there has been implied consent to the collection of sensitive information, for example, from the voluntary disclosure of a document containing sensitive information to the Provider. The participant’s consent must be recorded in the Department’s IT system as an appropriate comment.
Where consent is not provided or is withdrawn and no APP exception applies, the Provider cannot collect the individual’s personal information. In these circumstances, Providers must explain to the individual that they may still be required to participate in the program, however the lack of consent may limit the options and employment services that a Provider can offer. For example, if an individual does not consent to the collection of sensitive information about their health status or racial or ethnic origin, they may not be referred to appropriately targeted Specific Cohort services. The Provider must ensure there is a process in place for a Participant to withdraw their consent, which includes providing information to the Participant about what that means for the Participant. This includes the Participant’s ability to continue to receive services and any impact relating to mutual obligation requirements or compulsory participation requirements. If they are a voluntary participant and decide to withdraw or withhold their consent, they can exit if they choose.
Some examples of exceptions which may permit the collection of sensitive information without consent include where:
-
the collection of personal information is required or authorised by or under an Australian law or a court/tribunal order (e.g. the Social Security Law)
-
it is unreasonable or impracticable to obtain the individual’s consent to the collection, and the Provider reasonably believes that the collection is necessary to lessen or prevent a serious threat to the life, health or safety of any individual or to public health or safety, or
-
the Provider has reason to suspect that unlawful activity, or misconduct of a serious nature, that relates to the Provider’s functions or activities has been, is being or may be engaged in and the Provider reasonably believes the collection is necessary in order for the Provider to take appropriate action in relation to the matter.
The above are examples only. Providers should seek their own independent legal advice before collecting sensitive information without consent or if the Provider is unsure whether the information is a Commonwealth record and should consider the circumstances and obligations under Use and Disclosure of Protected Information below.
Third party consent requirements
Providers must ensure that they do not collect, use or disclose sensitive information about a third party unless:
-
the collection is by lawful and fair means
-
it is unreasonable or impracticable to collect the personal information directly from the third-party individual
-
the third party’s personal information is reasonably necessary and required for the Provider to meet its obligations under the deed and these guidelines
-
the third party has provided valid consent
-
the third party is the Participant’s child and is under 15 years of age
-
the Participant is the legal guardian of the third party who is under 15 years of age
-
the Participant is the legal guardian and authorised decision maker of the third party who may not have capacity to consent, or
-
the provider reasonably believes that collection of that sensitive information is necessary to lessen or prevent a serious threat to the life, health or safety of the Participant or any other individual, or to public health or safety, and that obtaining consent from the third party to the handling of their personal information is unreasonable or impracticable in the circumstance.
Providers may be able to rely on implied consent by third parties in some circumstances where personal information (excluding sensitive information) is provided, e.g. the contact details of an Auslan interpreter.
Providers must make a record of consent by third parties. For example, Providers can upload an email or make a file note that they are satisfied the third party has provided their express consent (e.g. via a phone call) or that their consent is implied.
Before collecting or uploading materials to the IT system containing the personal or sensitive information of a third party, the Provider must be satisfied that appropriate consents have been obtained and make a record of that consent.
Providers must also ensure they redact any sensitive information about third parties which is not reasonably necessary or required, such as Tax File Numbers or Government Identifiers.
6.3.3 Manner of collection
Providers must only collect personal information directly from the individual, unless any one of the following exceptions applies:
-
the individual consents to the collection of the information from a third party
-
the Provider is required or authorised by Australian law, or court/tribunal order, to collect the information from the third party, or
-
it is unreasonable or impracticable to collect the personal information directly from the individual.
For example, it may be unreasonable or impracticable to collect personal information directly from an individual where language difficulties prevent the individual from providing their personal information. In these cases, the Provider should seek the individual’s consent to collect the information through an interpreter. Providers must also ensure the use and need for an Interpreter is recorded in the Department’s IT system. Under APP 10, Providers are required to take reasonable steps to ensure the personal information they collect is accurate, up-to-date, and complete. Providers therefore need to take steps to ensure the interpreter will be providing accurate and complete information from the individual.
The collection of personal information by a Provider must be by lawful and fair means only. A fair means of collecting information is one that does not involve intimidation or deception and is not unreasonably intrusive.
6.4 APP 4: Dealing with unsolicited personal information
APP 4 outlines when an APP entity may collect unsolicited personal information.
A Provider may receive personal information it did not ask for. APP 4 outlines when a Provider may collect unsolicited personal information. Where a Provider receives unsolicited personal information, it must determine whether it would have been permitted to collect the personal information under APP 3. If not, the Provider must destroy or de-identify the information, unless it is a Commonwealth record under the Archives Act 1988 or as per the Deed. Most records held by Providers in performing the Services will be Commonwealth records. Providers should seek their own independent legal advice prior to destroying unsolicited information.
If the Provider determines it can collect the personal information under APP 3 or retain the personal information because it is contained in a Commonwealth record, it must handle the information in accordance with the Privacy Act 1988.
6.5 APP 6: Use and Disclosure of personal information
APP 6 provides that if an APP entity holds personal information about an individual that was collected for a particular purpose (primary purpose), the entity must not use or disclose the information for another purpose (secondary purpose), unless an exception applies.
Personal information in employment services is generally collected, used and disclosed for the primary purpose, which is administering the relevant employment service program and to provide individuals with appropriate services and assistance. In this case, participant’s personal information (including sensitive information) is collected and managed for the primary purpose of administering, managing and regulating the Inclusive Employment Australia program. This includes under any future variation of the Inclusive Employment Australia program (e.g. if the name of the program is changed or if amendments are made to the legislative framework under which the program operates).
A Provider may use and disclose an individual’s personal information, including sensitive information, for the primary purpose. More information about the primary purpose can be found in the Privacy Statement in the Privacy Notification and Consent Form (sign-in required) and Direct Registration Form, and information available on the Department’s website at DSS – Participant Privacy.
A secondary purpose is any purpose that is not the primary purpose. Providers must not use or disclose personal information for a secondary purpose unless an exception applies, including where:
-
the individual consents to the use or disclosure for the secondary purpose*
-
the individual would reasonably expect the use or disclosure for the secondary purpose, and either the secondary purpose is related to the primary purpose or, in the case of sensitive information, is directly related to the primary purpose, or
-
the use or disclosure is required or authorised by or under an Australian law or a court/tribunal order (e.g. the Social Security Law, see 6.9 Use and disclosure of Protected Information).
*It should not be assumed that an individual has given consent on the basis alone that they did not object to a proposal to handle personal information in a particular way.
Access by Provider Personnel to Participant records in the Department’s ICT system is a use of personal information and is provided by the Department for the purpose of providing the Services to the Participant only. All access to Department’s ICT System by all Provider Personnel can and will be monitored for inappropriate use by the Department, and the Provider must put in place its own systems and processes to protect against this.
The APP 6 obligations apply to the use of personal information by the Provider and the disclosure of personal information to third parties, that is parties other than the Provider. The Provider may disclose personal information, other than sensitive information, to a related body corporate.
6.5.1 Information for ‘checks’
Both Provider Personnel and Participants may be involved in activities that have risks which are appropriately managed through background or other checks. These might be checks like police checks, Working with Children Checks, Working with Vulnerable People Checks, Visa Entitlement Verification Online (VEVO) checks, and health/medical checks.
The Provider should make sure that both Participants and their Personnel are notified up-front if a role is likely to involve checks, what those checks are and who the result of a check will be given to. This gives Personnel and Participants more control over whether and what personal information they share, by helping them to identify whether a role is appropriate for them early on.
For both Personnel and Participants, it is the responsibility of the Provider to arrange and pay for all relevant checks, before:
-
the person is involved in the relevant activity (in the case of Personnel), and
-
the person is involved in the relevant activity or placed in the employment (in the case of a Participant).
When referring an individual to a relevant agency for a check to be undertaken, Providers must ensure the individual is aware their personal information will be disclosed to the relevant agency for this purpose and provide relevant information, including details of what the check will involve. Where a Provider is referring an individual to an activity that requires one or more of these checks, the Provider must refer the individual to the relevant agencies which undertake the checks prior to the placement.
6.5.2 Information for assessments
Participant sensitive information may be collected, used, and disclosed to Health care professionals including the National Panel of Assessors, JobAccess Professional Advisors, Services Australia Assessment Services, or other qualified health and allied health professionals to undertake assessments or provide services as part of the Program. The National Panel of Assessors may undertake:
-
Ongoing Support Assessments
-
Supported Wage Subsidy Assessments, and/or
-
Workplace Modification Scheme Assessments as part of the Employment Assistance Fund.
Providers must ensure that participants are aware that their personal information may be handled by third parties. Providers must also ensure Provider Personnel are aware of and consent to the handling of their personal information by any third parties as required.
6.5.3 Tax File Numbers
Providers and their staff have no requirement to collect a participant’s Tax File Number (TFN). If a Participant or Employer supplies a payslip for evidence of outcome fees, payments under a Wage Subsidy Agreement, or to meet any other evidence requirements, the Provider must not share the TFN with any other party, including the Department.
A Provider must not record, collect, use or disclose TFN information unless this is permitted under taxation, personal assistance or superannuation law. Providers must make themselves aware of when they are authorised to handle TFNs under the TFN Rule and provide appropriate guidance to their Personnel. That guidance must include proper storage and destruction of TFNs, consistent with the TFN Rule.
TFN recipients must take reasonable steps to protect TFN information from misuse and loss, and from unauthorised access, use, modification or disclosure. A breach of the TFN Rule is an interference with privacy under the Privacy Act 1988.
Unauthorised disclosure of a TFN may also amount to a breach of APP 9.
6.6 APP 7: Direct marketing
Under APP 7, Providers must not use or disclose personal information for the purposes of direct marketing unless an expressed consent to a secondary collection purpose has been provided by the Participant and recorded. Without express consent, this will consist of a breach, and the Department may take actions under clause 66 of the Deed. It may in some circumstances also constitute an offence in relation to protected information.
Prior to undertaking any direct marketing in relation to functions and activities under the Deed(s), Providers must consider whether the proposed marketing is consistent with the Privacy Act 1988. Providers should obtain their own independent legal advice.
6.7 APP 9: Adoption, use or disclosure of government related identifiers
Providers routinely interact with government related identifiers, including Centrelink Reference Numbers (CRNs) and Job Seeker Identification numbers (JSIDs). APP 9 restricts the adoption, use, and disclosure of government related identifiers by organisations. Under the Deed, Providers must comply with APP 9.
APP 9 provides limited exceptions where a Provider may use or disclose a government related identifier of an individual. This means a Provider should make sure it understands its authority in relation to the identifier and provides guidance to its Personnel about how the identifier should be handled. An example is where the use or disclosure of a government related identifier is reasonably necessary for the Provider to fulfil its obligations to the Department.
Providers should note that consent is not a basis on which the adoption, use, or disclosure of a government related identifier may be permitted. Providers should obtain their own independent legal advice.
6.8 APPs 12 and 13: Access to and correction of personal information
Under APP 12, if an APP entity holds personal information about an individual, the entity must, on request by the individual, give the individual access to the information. APP 12 does not stipulate any formal requirements for making a request or require a request to access personal information be made in writing or require an individual to state it is an APP 12 request. Therefore, a verbal request for personal information may be a valid request under APP 12.
Under APP 13, if an APP entity holds personal information about an individual and the individual requests the entity to correct the information, the entity must take such steps as are reasonable in the circumstances to correct that information to ensure that, having regard to the purpose for which it is held, the information is accurate, up-to-date, complete, relevant and not misleading.
Generally, Providers must process requests for access to personal information and requests for correction of personal information. If a Provider receives such a request, they must provide a response within 30 calendar days after the request is made.
Certain requests must be referred to the Department for consideration where the Provider proposes to refuse the request or the request encompass records containing information falling within the following categories:
-
records also containing information about another person
-
medical records (other than those supplied by the individual, or where the individual has a copy or has previously sighted a copy of the records)
-
psychological records, and
-
information provided by other third parties (excluding Subcontractors, the Department and Services Australia).
Providers must not direct a request to the Department without first considering whether they are obliged to process the request.
If an individual is seeking access to personal information on behalf of another individual, Providers must obtain written authority from the individual whose personal information is being sought before releasing any documents. At a minimum, an authority should state the individual’s name, include a description of the documents they are authorising the release of, who the documents can be released to, and bear the individual’s signature.
If the Provider is unable to obtain written authority, they should inform the individual they may wish to make a request under the Freedom of Information Act 1982 (Cth). Requests under the Freedom of Information Act 1982 should be directed to the Department via FOI@dss.gov.au.
(Deed Reference(s): Clause 50)
6.8.1 Freedom of Information requests
Under the Deed, Providers are required to assist the Department in processing requests under the Freedom of Information Act 1982 by providing Records (digital or physical) in their possession that are relevant to a request. An individual seeking to access documents containing their personal information may submit a request for access under either the Privacy Act 1988 or the Freedom of Information Act 1982. However, where the document being sought does not contain their personal information, access is not available under the Privacy Act 1988. The Privacy Act 1988 only applies to personal information.
Requests under the Freedom of Information Act 1982 should be directed to the Department via FOI@dss.gov.au.
(Deed Reference(s): Clause 51.3)
6.9 Use and disclosure of Protected Information
“Protected Information” is defined under the Disability Services and Inclusion Act 2023 as either:
-
personal information within the meaning of the Privacy Act 1988*, or
-
information about the affairs of a person the disclosure of which could reasonably be expected to find an action by a person (other than the Commonwealth) for breach of a duty.
* See 6.2.1 Personal information and sensitive information (above).
Both protected information and personal information may be collected, used, and disclosed with the consent of the individual concerned. Compliance with the consent framework for Inclusive Employment Australia is a key part of a Provider ensuring they have authority to deal with information about Participants.
Under Social Security Law, a Provider’s Personnel may obtain, record, use and disclose protected information as part of the efficient and effective delivery of work-related services to Service Recipients. Work-related services include:
-
assessment of a Service Recipient’s capacity to work
-
helping a Service Recipient prepare to seek or undertake work, and
-
placement of a Service Recipient in a position of employment.
Information provided by the Commonwealth through Workforce Australia Online for Providers about a Participant who has mutual obligations will be protected information, that can be handled for the purpose of delivering work-related services being provided under the Deed with the Commonwealth.
6.9.1 Offences related to Protected Information
It is an offence under Social Security Law for a person to intentionally obtain, make a record of, disclose to any other person, or otherwise use, protected information if the person:
-
is not authorised by or under the Social Security Law to do so, and
-
the person knows, or ought reasonably to know, that the information is Protected Information.
This means the Provider’s Personnel may commit a criminal offence if they:
-
search for, or access, Protected Information not required for their duties
-
make copies of Protected Information where not authorised
-
disclose Protected Information to other staff or third parties who do not need to know that information, or
-
otherwise use Protected Information where not permitted.
6.9.2 Permitted uses of Protected Information
Providers are permitted to obtain, make records of, use and disclose Protected Information where this is authorised or required by the Social Security Law, such as:
-
for the purposes of the Social Security Law, such as ensuring that an individual enters into, and complies with their Job Plan, or
-
to deliver the Services.
Providers may also make a record, use, and disclose an individual’s Protected Information where that individual provides express or implied consent to that use or disclosure. This may be helpful where a Provider wishes to assist or support an individual by providing their information with their consent to a third party.
6.9.3 Public Interest Certificates
In addition to the permitted uses discussed above, Providers may disclose Protected Information to certain persons where this is authorised by a Public Interest Certificate (PIC). A PIC identifies the Protected Information that can be disclosed, the purposes for which the information can be disclosed, and to whom the information can be disclosed. A PIC may also specify who can disclose the information.
Protected Information collected prior to 30 June 2025 remains subject to the Disability Services Act 1986 (Cth). A class PIC, which was issued under the Social Security (Administration) Act 1999 and paragraph 28(5)(a) of the Disability Services Act 1986 (Cth), enables disclosure of this information in specified circumstances. For other circumstances, a specific PIC will need to be requested from the Department.
Protected Information collected from 1 July 2025 is subject to the Disability Services and Inclusion Act 2023. The Department will issue further instructions in due course regarding the handling of information collected from 1 July 2025.
For detailed information regarding PICs, refer to the PIC Guidelines.
6.10 Privacy Incidents and the Notifiable Data Breaches Scheme
Acts or practices by a Provider which breach an APP are an interference with the privacy of the individual. The OAIC has powers to investigate possible interferences with privacy, either following a complaint by an individual or on the OAIC’s own initiative. The OAIC also has a range of enforcement powers and other remedies.
Providers are required under the Notifiable Data Breaches scheme to notify affected individuals and the OAIC about eligible data breaches. An eligible data breach occurs when there is unauthorised access to, or disclosure of, personal information held by an entity, or information is lost in circumstances where unauthorised access or disclosure is likely to occur.
The Provider must Notify the Department as soon as possible following becoming aware of any unauthorised access to, use or disclosure of, personal information, or a loss of personal information the Provider holds using the Provider Privacy Incident Report (sign-in required) (PPIR). This applies to all privacy incidents, whether or not they are an eligible data breach.
Providers must promptly assess all potential privacy incidents to determine whether an eligible data breach has occurred and, if required, notification is to be provided to affected individuals and to the OAIC. Providers must take all reasonable steps to ensure this assessment is completed within 30 calendar days of becoming reasonably aware of an eligible data breach.
By responding quickly, a Provider can substantially decrease the impact on affected individuals and reduce the costs associated with dealing with the privacy incident, including reputational costs.
The Provider must also provide the Department with a copy of any notification of an eligible data breach made to OAIC and any subsequent correspondence with OAIC.
Providers should refer to the OAIC website for information on the Notifiable Data Breach scheme.
The Provider must also immediately Notify the Department if it becomes aware:
-
of a breach or possible breach of any of the obligations contained in, or referred to in the Deed(s) by any Personnel or Subcontractor
-
that a disclosure of personal information may be required by law, or
-
of an approach to the Provider by the Information Commissioner or by an individual claiming their privacy has been interfered with.
Providers should be aware the Department monitors Personnel access to Records in the Department’s IT Systems. Where a clear business reason for access to a Record or Records is not identified, the Department may require further information or investigation by a Provider and may take action against individuals.
6.11 Privacy Complaints
An individual who considers their privacy has been interfered with can contact the Department and/or the OAIC to make a complaint. Where possible, complaints under the Privacy Act 1988 should be directed to an individual’s Provider in the first instance.
Providers are required to respond to any privacy complaints within 10 Business Days and in accordance with the PPIR where a privacy incident has been identified. Providers should follow OAIC’s advice on handling privacy complaints.
6.12 Referring individuals to the Department in relation to privacy matters
After first directing their query to their Provider, an individual can contact the Department to query how their personal information is handled, request access to or correction of their personal information, or make a privacy complaint in relation to the Department or a Provider.
Participants can submit a Privacy complaint to the Department by:
-
completing an online complaint form
-
sending an email to complaints@dss.gov.au, or
-
sending a letter to DSS Feedback, GPO Box 9820, Canberra ACT 2601.
For further details on the complaint process, please refer to 3.6 Complaint processes in Chapter 3 of these Guidelines.
6.13 Awareness and Training Expectations
Providers must adopt practices to ensure its Personnel are aware of their obligations under the privacy law, the Deed and this Chapter. Providers who have access to the Department’s IT Systems must ensure that Personnel who handle or will handle personal information in the course of delivering services under the Deed complete the Department’s Information Exchange and Privacy Training Module, available on the Learning Centre:
-
prior to accessing the IT system,
-
prior to delivering the Services, and
-
at least once every 12 months.
Providers must also make sure that they provide appropriate notice to their Personnel about how their information will be shared with the Department and other agencies as part delivering Services to Participants, both as part of the Provider fulfilling its obligations under the Deed and as part of Personnel accessing the Department’s ICT system.
Providers should note that the Department’s privacy training module has been developed to cater for the delivery of Inclusive Employment Australia. It is not a substitute for any tailored internal privacy training Providers make available to their Personnel. Where required, the Provider must supplement the Department’s privacy training module with its own additional privacy training.
6.13.1 Privacy Training Module
The Department’s Information Exchange and Privacy Training Module explains the key concepts under the Privacy Act 1988 and the APPs which govern how personal information is collected, used, disclosed, and stored.
The training module is mandatory and is essential to ensure that Personnel have a common understanding of this Chapter, the APPs, and the Social Security Law, including key processes that help manage potential risks. The completion of mandatory training assists Providers to meet legislative and regulatory requirements but is not sufficient to meet those requirements.
Privacy resources are also published on the Provider Portal for Personnel to access.
Providers should ensure their internal privacy practices, policies and procedures are proactively reviewed, compliant with new laws or updated information handling practices and responsive to new privacy risks.
6.13.2 Staff Compliance
Providers must monitor and annually self-audit Staff completion of privacy training, including the Department’s mandatory Privacy training module. The Department may request details of a Provider’s self-audit at any time or may conduct its own audit of a Provider’s compliance with the requirements in this Chapter.
Where privacy training is undertaken outside of the Department’s Learning Centre, the Provider must retain Records of privacy training undertaken by their Staff and must make this available to the Department on request.
It is also recommended that Providers put in place their own processes to audit the compliance of their Staff with privacy obligations more generally.