Independent public Guidelines referenceNot an Australian Government serviceHow ServiceCite worksAbout
ServiceCite
Part A: Universal Guidelines

DEWR source chapter · ServiceCite reference page

Chapter 3. Privacy

Department wording for Chapter 3, Privacy, from Part A: Universal Guidelines version 1.16.

Version and source status

Workforce Australia Services reference · Part A v1.16

File integrity checked by ServiceCite
Program status
Current service
Published
3 June 2026
Effective
1 July 2026
Source retrieved
6 August 2026
Official record modified
14 July 2026
Official location checked by ServiceCite
6 August 2026
Attribution, presentation changes and technical record

Source material: © Commonwealth of Australia. Australian Government Department of Employment and Workplace Relations, Workforce Australia Guidelines, Part A: Universal Guidelines, version 1.16, published 3 June 2026. Used under the Creative Commons Attribution 4.0 International licence, subject to the exclusions in the DEWR copyright notice.

ServiceCite split the Word document into chapter pages and reformatted it for web navigation and search. Source logos, authoring artefacts and duplicate navigation were removed. System step, documentary evidence and work health and safety markers were converted to visible text labels. ServiceCite navigation and notices are independently written. Compare this page with the official source before operational use. This reuse does not imply Australian Government or DEWR endorsement.

The SHA-256 and file size record the official Word file verified during corpus preparation. ServiceCite does not publish the source DOCX because it contains images excluded from DEWR's default Creative Commons licence.

Document ID
dewr-workforce-australia-guidelines-part-a
Version ID
dewr-wa-part-a-v1.16-effective-2026-07-01
SHA-256
c88ac5d339842ee1ca56694d66e154d61be21ea9bbcde33f1860e0c474be0757
FOI reference
D26/3084244
Recorded file size
269,995 bytes
MIME type
application/vnd.openxmlformats-officedocument.wordprocessingml.document
Department wording, reformatted for the web · ServiceCite coverage notes are labelled

Supporting Documents for this Chapter:

3.1. Chapter Overview

This Chapter provides information for Providers and their Personnel on their obligations in relation to handling personal and protected information about individuals, as well in relation to reporting privacy incidents.

3.2. The Australian Privacy Principles

The Privacy Act 1988 (Cth) (Privacy Act) regulates the collection and handling of personal information through minimum privacy standards, known as the Australian Privacy Principles (APPs).

In delivering Services, Providers collect, use and disclose personal information about individuals. In handling this personal information, Providers are required under their Deed(s) to comply with the Privacy Act and the APPs as if they were agencies. The APPs govern the standards, rights and obligations around:

  • the collectionuse and disclosure of personal information

  • an organisation or agency’s governance and accountability

  • integrity of personal information

  • protection of personal information; and

  • the rights of individuals to access and correct their personal information.

The APPs are principles-based law. The Provider must consider its own situation and relevant Deed provisions and implement procedures and policies to ensure compliance with the relevant APPs.

3.2.1. Personal information and sensitive information

‘Personal information’ means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, or is recorded in a material form or not.

Personal information includes an individual’s name, signature, date of birth, address, telephone number, sensitive information, bank account details, employment information, and commentary or opinion about an individual. This kind of information may be shared verbally, contained in physical or digital files or documents, such as résumés or application forms provided by the individual, or in an email or text message, or recorded.

‘Sensitive information’ is a subset of personal information and includes information that relates to an individual’s racial or ethnic origin, health status, genetics and biometrics, religious beliefs or affiliations, philosophical beliefs, sexual orientation, criminal record or membership of a political association, professional or trade association or trade union.

When handling personal information, Providers must ensure they are assessing whether the information is also sensitive information, as there are higher standards and additional requirements for collecting, using and disclosing sensitive information. For example, an individual’s consent is not required for a Provider (as an APP entity) to collect personal information but will be required for a Provider to collect sensitive information. Inappropriate handling of sensitive information is particularly serious and can result in, amongst other things a requirement to pay compensation or to enter into enforceable undertaking.

3.2.2. Consent and the APPs

In complying with the Privacy Act, the APPs and this Chapter, Providers may be required to seek consent from individuals to permit the handling of their personal and sensitive information. Consent can be given expressly, either orally or in writing, or it can be implied.

  • Documentary evidence — In situations of verbal or implied consent, Providers must record the nature of the individual’s consent in the Department’s IT Systems (where the Provider has access) or in another appropriate format (where the Provider does not have access and which must be made available to the Department on request).

For an individual's consent to be valid, Providers must ensure:

  • the individual is adequately informed before giving consent,

  • the individual gives consent voluntarily,

  • the consent is current and specific, and

  • the individual has the capacity to understand and communicate their consent.

Providers must ensure that each individual’s consent is regularly reviewed on an ongoing basis (such as in relation to the collection and disclosure of sensitive information under the Privacy Notification and Consent Form (sign-in required), see APP 3: Collection of solicited personal information below).

Where an individual is under 18 years old, the Provider must decide if the individual has the capacity to consent on a case-by-case basis. The OAIC advises, as a general rule, that an individual under the age of 18 has the capacity to consent if they have the maturity to understand what is being proposed. If the individual lacks maturity it may be appropriate for a parent or guardian to consent on their behalf.

Further information about consent can be found on the OAIC's website.

3.3. APP 3: Collection of solicited personal information

APP 3 outlines when an APP entity may collect solicited personal information, including sensitive information.

To deliver the Services they are contracted to provide, Providers are generally required to collect personal information. APP 3 outlines when an APP entity may collect solicited personal information, including sensitive information (see Consent and the APPs).

Providers may only solicit and collect personal information that is reasonably necessary for, or directly related to, one or more of the Provider’s functions or activities. A Provider’s functions or activities will vary depending on the Services being delivered and Providers should consider their obligations under their Deed(s) with the Department to deliver Services before collecting personal information.

3.3.1. Consent to the collection of sensitive information

In addition to the above, Providers must only collect sensitive information where the individual gives consent to the collection, unless another exception applies.

For Providers delivering Services to Participants, during the first meeting with the individual, the Provider must:

While signing the Privacy Notification and Consent Form (sign-in required) may indicate express consent at the time of signing, individuals may also provide their express consent to the form verbally. In some circumstances, Providers may also reasonably infer from an individual’s conduct that there has been implied consent to the collection of sensitive information, for example, from the voluntary disclosure of a document containing sensitive information to the Provider.

Where consent is not provided or is withdrawn, and no APP exception applies, the Provider cannot collect the individual’s sensitive information. In these circumstances, Providers must explain to the individual that they will still be required to participate in the relevant program, however, the lack of consent may limit the options and employment services that a Provider can offer. For example, if an individual does not consent to the collection of sensitive information about their health status or racial or ethnic origin, they may not be referred to any possible appropriate targeted services.

  • Documentary evidence — Where an individual withdraws consent to the collection of their sensitive information, the Provider must not destroy the Privacy Notification and Consent Form, except in accordance with the Archives Act, and the Provider must record the withdrawal of the individual’s consent to the collection of their sensitive information on the individual’s record in the Department’s IT Systems (where the Provider has access), or in another appropriate format (where the Provider does not have access and which must be made available to the Department on request).

Some examples of exceptions which may permit the collection of sensitive information without consent include:

  • the collection of the information is required or authorised by or under an Australian law or a court/tribunal order (e.g. the Social Security Law);

  • it is unreasonable or impracticable to obtain the individual’s consent to the collection and the Provider reasonably believes that the collection is necessary to lessen or prevent a serious threat to the life, health or safety of any individual or to public health or safety; or

  • the Provider has reason to suspect that unlawful activity, or misconduct of a serious nature, that relates to the Provider’s functions or activities has been, is being or may be engaged in and the Provider reasonably believes that the collection is necessary in order for the Provider to take appropriate action in relation to the matter.

The above are examples only. Providers should seek their own independent legal advice before collecting sensitive information without consent or if the Provider is unsure whether the information is a Commonwealth record and should consider the circumstances and obligations under Use and Disclosure of Protected Information below.

3.3.2. Manner of collection

Providers must only collect personal information directly from the individual, unless any one of the following exceptions applies:

  • the individual consents to the collection of the information from a third party; or

  • the Provider is required or authorised by Australian law, or court/tribunal order, to collect the information from the third party; or

  • it is unreasonable or impracticable to collect the personal information directly from the individual.

For example, it may be unreasonable or impracticable to collect personal information directly from an individual where language difficulties prevent the individual from providing their personal information. In these cases, the Provider should seek the individual’s consent to collect the information through an interpreter or translator. Under APP 10, Providers are required to take reasonable steps to ensure that the personal information they collect is accurate, up-to-date and complete. Providers therefore need to take steps to ensure that the interpreter or translator that is used will be providing accurate and complete information from the individual.

The collection of personal information by a Provider must be by lawful and fair means only. A fair means of collecting information is one that does not involve intimidation or deception and is not unreasonably intrusive.

3.4. APP 4: Dealing with unsolicited personal information

APP 4 outlines when an APP entity may collect unsolicited personal information.

A Provider may receive personal information it did not ask for. APP 4 outlines when a Provider may collect unsolicited personal information. Where a Provider receives unsolicited personal information, it must determine whether it would have been permitted to collect the personal information under APP 3. If not, the Provider must, destroy or de-identify the information unless it is a Commonwealth record under the Archives Act. Most records held by Providers in performing the Services will be Commonwealth records. Providers should seek their own independent legal advice prior to destroying unsolicited information.

If the Provider determines that it could have collected the personal information under APP 3, or retains the personal information because it is contained in a Commonwealth record, it must handle the information in accordance with the Privacy Act.

3.5. APP 5: Notification of the collection of personal information

APP 5 requires an APP entity that collects personal information about an individual, to take reasonable steps to notify the individual of certain matters or to ensure the individual is aware of those matters.

As well as obtaining their consent to the collection of sensitive information as required by APP 3, the Privacy Notification and Consent Form complies with APP 5.2 by informing the individual of matters such as:

  • the identity and contact details of the Department

  • the purposes for which the Department and Provider are collecting the personal information, and

  • the main consequences for the individual if all or some of the personal information is not collected by the Department and Provider.

3.6. APP 6: Use and Disclosure of personal information

APP 6 provides that if an APP entity holds personal information about an individual that was collected for a particular purpose (primary purpose), the entity must not use or disclose the information for another purpose (secondary purpose) unless an exception applies.

Personal information in employment services is generally collected, used and disclosed for the primary purpose, which is administering the relevant employment service program and to provide individuals with appropriate services and assistance. A Provider may use and disclose an individual’s personal information, including sensitive information, for the primary purpose. More information about the primary purpose can be found in the Privacy Notification and Consent Form (sign-in required).

A secondary purpose is any purpose that is not the primary purpose. Providers must not use or disclose personal information for a secondary purpose unless an exception applies, including where:

  • the individual consents to the use or disclosure for the secondary purpose*

  • the individual would reasonably expect the use or disclosure for the secondary purpose, and either the secondary purpose is related to the primary purpose or, in the case of sensitive information, is directly related to the primary purpose, or

  • the use or disclosure is required or authorised by or under an Australian law or a court/tribunal order (e.g. the Social Security Law, see Use and Disclosure of Protected Information).

The APP 6 obligations apply to the use of personal information by the Provider and the disclosure of personal information to third parties, that is parties other than the Provider. The Provider may disclose personal information, other than sensitive information, to a related body corporate.

*It should not be assumed that an individual has given consent on the basis alone that they did not object to a proposal to handle personal information in a particular way.

3.6.1. Information for ‘checks’

Subject to APP 6, Providers must not disclose personal information for the purpose of checks, including police checks, Working with Children Checks, Working with Vulnerable People Checks, Visa Entitlement Verification Online (VEVO) checks and health/medical checks.

If an individual is offered paid work and the Employer seeks one or more of these checks, the Employer should source the information directly from the individual.

When referring an individual to a relevant agency for a check to be undertaken, Providers must ensure that the individual is aware that their personal information will be disclosed to the relevant agency for this purpose, and provide relevant information, including details of what the check will involve. Where a Provider is referring an individual to an activity that requires one or more of these checks, the Provider must refer the individual to the relevant agencies which undertake the checks prior to the placement. See deed clauses on ‘Checks and reasonable care’ for further information.

3.6.2. Tax File Numbers

Providers should also note that the Privacy (Tax File Number) Rule 2015 (TFN Rule) only allows certain people, agencies, organisations and other entities that are authorised by taxation, personal assistance or superannuation law to ask for and receive TFNs (‘authorised or lawful TFN recipients’). A TFN recipient also must not record, collect, use or disclose TFN information unless this is permitted under taxation, personal assistance or superannuation law.

TFN recipients must take reasonable steps to protect TFN information from misuse and loss, and from unauthorised access, use, modification or disclosure. A breach of the TFN Rule is an interference with privacy under the Privacy Act.

Due to the particular sensitivities attached to TFNs, their use and disclosure are governed by secrecy provisions in applicable legislation. Relevantly, subsection 8WB(1) of the Taxation Administration Act 1953 (Cth) (TAA) provides that, unless an exception applies, a person must not divulge or communicate another person’s TFN to a third person. A breach of subsection 8WB(1) of the TAA may lead to criminal liability.

If TFNs are not authorised to be handled under the TFN Rule or TAA then Providers must redact TFNs from documents before they are stored, used or disclosed.

  • System step — TFN information must be redacted correctly to ensure the information is permanently removed before uploading documents to the Department’s IT Systems. This can be done using one of the following methods:

  • Electronic redaction using appropriate software: 

  • Use a dedicated redaction tool available through software such Adobe Acrobat, KOFAX Power PDF, or a similar software you may already have.

  • These tools permanently remove the information and sanitise hidden content or metadata.

  • Do not use methods such as placing black boxes, white boxes, or shapes over text, as the underlying information can still be recovered (for example, by deleting or moving the overlay), even after saving as a PDF.

  • Manual redaction on hard‑copy documents: 

  • Redact TFNs using an opaque black marker or similar, ensuring the information is fully obscured and cannot be read or reconstructed.

  • The redacted document must then be scanned to create a new electronic copy before being stored, shared, or processed.

  • The original hard copy must be disposed of in line with records management requirements (See the Records Management Instructions Chapter).

Unauthorised disclosure of a TFN may also amount to a breach of APP 9 including, but not limited to, where a Provider:

  • uploads a payslip onto the Department's IT Systems containing a Participant's TFN;

  • emails an unintended recipient another Participant's TFN Declaration Form or documentation containing a TFN; or

  • uploads a TFN Declaration form onto the Department's IT Systems where the Department has directed such forms be only emailed to the Department.

3.7. APP 7: Direct marketing

APP 7 provides that a Provider must not use or disclose personal information for the purposes of direct marketing unless an exception applies. Prior to undertaking any direct marketing in relation to functions and activities under the Deed(s), Providers must consider whether the proposed marketing is consistent with the Privacy Act. Providers should obtain their own independent legal advice.

3.8. APP 9: Adoption, use or disclosure of government related identifiers

Providers routinely interact with government related identifiers, including Centrelink Reference Numbers (CRNs), Job Seeker Identification numbers (JSIDs) and TFNs. APP 9 restricts the adoption, use and disclosure of government related identifiers by organisations. Under the Deed, Providers must comply with APP 9.

APP 9 provides limited exceptions where a Provider may:

  • adopt a government related identifier of an individual as its own identifier of the individual, or

  • use or disclose a government related identifier of an individual.

An example is where the use or disclosure of a government related identifier is reasonably necessary for the Provider to fulfil its obligations to the Department.

Providers should note that consent is not a basis on which the adoption, use or disclosure of a government related identifier may be permitted and should also consider the additional requirements regarding the use and disclosure of Tax File Numbers. Providers should obtain their own independent legal advice.

3.9. APPs 12 and 13: Access to and correction of personal information

Under APP 12, if an APP entity holds personal information about an individual, the entity must, on request by the individual, give the individual access to the information. APP 12 does not stipulate any formal requirements for making a request, or require that a request to access personal information be made in writing or require an individual to state that it is an APP 12 request. Therefore, a verbal request for personal information may be a valid request under APP 12.

Under APP 13, if an APP entity holds personal information about an individual and the individual requests the entity to correct the information, the entity must take such steps as are reasonable in the circumstances to correct that information to ensure that, having regard to the purpose for which it is held, the information is accurate, up-to-date, complete, relevant and not misleading.

Generally, Providers must process requests for access to personal information and requests for correction of personal information. If a Provider receives such a request, they must provide a response within 30 calendar days after the request is made.

Certain requests must be directed to the Department for consideration where they encompass records containing information falling within the following categories:

  • records also containing information about another person

  • medical/psychiatric records (other than those actually supplied by the individual, or where it is clear that the individual has a copy or has previously sighted a copy of the records)

  • psychological records, and

  • information provided by other third parties.

Providers must not direct a request to the Department without first considering whether they are obliged to process the request.

If an individual is seeking access to personal information on behalf of another individual, Providers must obtain written authority from the individual whose personal information is being sought before releasing any documents. At a minimum, an authority should state the individual’s name, include a description of the documents that they are authorising the release of, who the documents can be released to and bear the individual’s signature.

If the Provider is unable to obtain written authority, they should inform the individual that they may wish to make a request under the Freedom of Information Act 1982 (FOI Act). Requests under the FOI Act should be directed to the Department via FOI@dewr.gov.au.

3.9.1. Freedom of Information requests

Under the Deeds, Providers are required to assist the Department in processing requests under the FOI Act by providing Records (digital or physical) in their possession that are relevant to a request. An individual seeking to access documents containing their personal information may submit a request for access under either the Privacy Act or the FOI Act. However, where the document being sought does not contain their personal information, access is not available under the Privacy Act as the Privacy Act only applies to personal information.

Requests under the FOI Act should be directed to the Department via FOI@dewr.gov.au.

3.10. Use and disclosure of Protected Information

Protected Information is information about a person that was obtained by an officer under the Social Security Law and is held or was held in the records of the Department or Services Australia. Protected information may also be personal information under the Privacy Act.

For example, if an individual receives a social security benefit or payment, that individual’s information (including their name, date of birth and contact details) will likely be both personal and Protected Information.

Protected information does not include information about a person voluntarily participating in an employment services program. For the purpose of this section, a person is voluntarily participating where they have not applied to receive a social security payment from Services Australia and chooses to participate in an employment program. Information about those individuals will not be protected information, but will still be personal information under the Privacy Act.

3.10.1. Offences related to Protected Information

It is an offence under the Social Security (Administration) Act 1999 (Administration Act) for a person to intentionally obtain, make a record of, disclose to any other person, or otherwise use, Protected Information if the person:

  • is not authorised by or under the Social Security Law to do so, and

  • the person knows, or ought reasonably to know, that the information is Protected Information.

This means the Provider’s Personnel may commit a criminal offence if they:

  • search for, or access, Protected Information not required for their duties

  • make copies of Protected Information where not authorised

  • disclose Protected Information to other staff or third parties who do not need to know that information

  • otherwise use Protected Information where not permitted.

3.10.2. Permitted uses of Protected Information

Providers are permitted to obtain, make records of, use and disclose Protected Information where this is authorised or required by the Social Security Law, such as:

  • for the purposes of the Social Security Law, such as ensuring that an individual enters into, and complies with their Job Plan, or

  • to deliver the Services.

Providers may also make a record, use and disclose an individual’s Protected Information where that individual provides express or implied consent to that use or disclosure. This may be helpful where a Provider wishes to assist or support an individual by providing their information with their consent to a third party.

3.10.3. Public Interest Certificates

In addition to the permitted uses discussed above, Providers may disclose Protected Information to certain persons where this is authorised by a Public Interest Certificate (PIC). A PIC identifies the information that can be disclosed, the purposes for which the Protected Information can be disclosed and to whom the information can be disclosed. The PIC may also specify who can disclose the information.

Class PICs

The Department’s Secretary has issued Social Security (Administration) (Class of Cases) Public Interest Certificate 2022 (sign-in required) (the Class PIC). Under the Instrument of Delegation (sign-in required), the Secretary has delegated the power to disclose information in accordance with the Class PIC, to all persons engaged by an organisation contracted by the Department to deliver employment services for the Commonwealth (i.e. a Provider) who have completed the Department’s Information Exchange and Privacy training (sign-in required) (available on the Learning Centre). Provider Personnel should be up to date with this training (i.e. completed within the previous 12 months). Each person who meets these criteria is referred to as a ‘delegate’ for the purposes of the Class PIC.

Under the Social Security Law and as relevant to the delivery of employment services by Providers, an ‘officer’ for the purposes of the Class PIC and Instrument of Delegation includes:

  • a person performing duties, or exercising powers or functions, under or in relation to the Social Security Law, or

  • a person who, although not appointed or employed by the Commonwealth, performs or did perform services for the Commonwealth and who, as a result of performing those services, may acquire or has acquired information concerning a person under the social security law

As such, an ‘officer’ can include Personnel who are both directly and indirectly involved in the delivery of services to a Participant or other person under the Social Security Law. For example, Personnel in administration or governance roles, or Personnel delivering non-vocational assistance (such as allied health professionals), may be ‘officers’ for the purposes of the Class PIC and Instrument of Delegation.

Preventing or lessening a threat

A delegate may disclose Protected Information about an individual under the Class PIC to police, emergency services, an emergency call service “Triple Zero”, health service providers, or child protection agencies:

  • where the person making the request cannot reasonably obtain the information from another source, and

  • the individual to whom the information relates is unable, refuses, or is likely to refuse to provide information to those specific persons, and

  • disclosure of the information is necessary to prevent or lessen a threat to the life, health or welfare of a person.

Offences against the Commonwealth, Commonwealth officers, or offences in Provider premises

A delegate may also disclose Protected Information about an individual to the police under the Class PIC:

  • where the police cannot reasonably obtain the information from another source, and

  • the individual to whom the information relates is unable, refuses, or is likely to refuse to provide information to the police, and

  • the disclosure of the information is necessary because an offence or threatened offence has occurred against an officer, or against Commonwealth property, or in premises occupied by an organisation contracted by the Department to provide employment services for the Commonwealth.

Process for disclosure under the Class PIC

The delegate must consider the facts of the case and determine if the Class PIC applies. A delegate may consult with others (to the extent Social Security Law allows) to determine if the Class PIC applies and, if so, who may be best placed to disclose the information.

Where a delegate has determined that the Class PIC applies to a situation, the delegate should only disclose the Protected Information about an individual that is relevant to the purpose. The Protected Information that may be disclosed where relevant is:

  • the full name, any previous names and any other names the person is known by

  • any contact details (including postal or residential addresses) and telephone numbers; and

  • any other information necessary to the purpose for which the information is needed. For example, it is unlikely that providing a Participant’s JSID or Tax File Number will be necessary for any of the purposes specified in the Class PIC. Delegates must ensure that disclosures of information under the Class PIC do not incidentally or otherwise release unnecessary information, including the information of unrelated individuals.

Once the delegate has disclosed the information, they must complete the Release of Protected Information Notification Form. Once completed, the Provider must send the completed form to their Provider Lead as soon as possible and within 48 hours of the disclosure of information.

Process for disclosure of CCTV footage

Providers may be asked by police or other third party requestors for copies of CCTV footage to assist in the investigation of the types of offences referred to in the Class PIC. Where the CCTV footage contains personal information or Protected Information of multiple individuals, Provider staff should not disclose the CCTV footage to police or third party requestors under the Class PIC. If a Provider receives a request for CCTV footage containing Protected Information, or otherwise wishes to disclose such footage to a third party, the request should be sent to their Provider Lead for consideration by the Department of whether a Specific PIC can be issued. See Specific PICs below for information on what to include in this request. CCTV footage obtained broadly for security and safety purposes, and not associated with the servicing of Participants, is unlikely to be Protected Information.

Specific PICs

Providers are required to obtain a specific PIC to release Protected Information in situations that are not covered by the Class PIC and disclosure is not otherwise authorised, such as lack of consent of the individual or individuals. Examples include:

  • releasing Protected Information to Police or other authorities where the Class PIC does not apply, such as when there is no threat to anyone’s life, health or welfare; and

  • responding to a subpoena or other notice requiring production of documents.

Providers will need to approach the Department through their Provider Lead (in writing) to request consideration of issuing a specific PIC. Providers should make the request as soon as they become aware of circumstances where they wish to, or are being asked to, disclose Protected Information to ensure the Department has sufficient time to review and respond to the request.

As part of any request to the Department, Providers must provide a copy of any request from a third party they have received, and as many details as possible about why the specific PIC is being sought, including the following:

  • who the request was made by, their contact person and phone number

  • why the information is required by the person making the request

  • why the information could not be obtained from another source (e.g. what other steps they have taken to try to obtain the information and the outcome of those steps)

  • if the request relates to a breach or an alleged breach of a law (criminal or otherwise):

    • what the breach or alleged breach is, including the legislation involved

    • the details of imprisonment and/or pecuniary penalties; and

    • the details surrounding the breach.

  • if the request may require the disclosure of CCTV footage:

    • a summary of what the footage shows, including the relevant individuals visible in the footage and whether they are Participants, Personnel or other third parties (such as bystanders or witnesses)

    • a copy of the footage, where reasonably available to be extracted and provided to the Department

    • reason for the existence of the CCTV footage; and

    • confirmation as to whether the Provider is holding footage in the records of the Department, or whether footage is taken on the Department’s behalf (and if this footage is made available to the Department).

  • the information that is to be released

  • the due date of the request, if applicable. For example, a deadline specified by a subpoena; and

  • the Provider's assessment of the request, including its assessment of the appropriateness under the Class PIC and why it may not be appropriate to seek the relevant Participant’s consent to the disclosure.

The Department will not issue a specific PIC in every case and the Provider should obtain their own independent legal advice before responding to the request for, or otherwise disclosing, Protected Information. Please note, the Department will endeavour to respond to each request before any specified due date or deadline that is reasonable, however, this may not always be possible, and Providers should ensure that they obtain their own independent legal advice.

Subpoenas or notices to produce

If a Provider receives a subpoena or a notice to produce from a court which requires disclosure of Protected Information, the Provider must ensure that they comply with all relevant laws, as well as the requirements of the Deed and Guidelines, in responding to that subpoena or notice to produce.

In particular, Providers should have regard to section 207 of the Administration Act in determining whether a Participant’s Protected Information can be disclosed. Providers should obtain their own legal advice, where relevant.

Providers do not need to contact the Department if the Participant has consented to the release of the information to a nominated recipient for a specified purpose as requested under a subpoena or notice to produce, irrespective of whether it is related to employment services. For example, if a Participant is in an unrelated motor vehicle incident, they might claim compensation and the relevant insurer might want access to Protected Information about a Participant held by the Provider to help assess the Participant’s claim. The Department takes the position that the Protected Information could be disclosed to the court if the Participant consents and that it would be acceptable for the Provider to seek the Participant’s consent if the insurer has not already supplied the Provider with evidence of their consent.

3.11. Privacy Incidents and the Notifiable Data Breaches Scheme

Acts or practices by a Provider which breach an APP are an interference with the privacy of the individual. The OAIC has powers to investigate possible interferences with privacy, either following a complaint by an individual or on the OAIC’s own initiative. The OAIC also has a range of enforcement powers and other remedies.

Providers are required under the Notifiable Data Breaches scheme to notify affected individuals and the OAIC about eligible data breaches. An eligible data breach occurs when:

  • there is unauthorised access to, or disclosure of, personal information held by an entity, or information is lost in circumstances where unauthorised access or disclosure is likely to occur

  • this is likely to result in serious harm to any of the individuals to whom the information relates, and

  • the entity has been unable to prevent the likely risk of serious harm with remedial action.

The Provider must Notify the Department as soon as possible following becoming aware of any unauthorised access to, use or disclosure of, personal information, or a loss of personal information the Provider holds using the Provider Privacy Incident Report (PPIR) (sign-in required). This applies to all privacy incidents, whether or not they are an eligible data breach.

Providers must promptly assess all potential privacy incidents to determine whether an eligible data breach has occurred and, if required, notification is to be provided to affected individuals and to the OAIC. Providers must take all reasonable steps to ensure that this assessment is completed within 30 calendar days of becoming reasonably aware of an eligible data breach.

By responding quickly, a Provider can substantially decrease the impact on affected individuals, and reduce the costs associated with dealing with the privacy incident, including reputational costs.

The Provider must also provide the Department with a copy of any notification of an eligible data breach made to OAIC and any subsequent correspondence with OAIC.

Providers should refer to the OAIC website for information on the Notifiable Data Breach scheme.

The Provider must also immediately Notify the Department if it becomes aware:

  • of a breach or possible breach of any of the obligations contained in, or referred to in the Deed(s) by any Personnel or Subcontractor

  • that a disclosure of personal information may be required by law, or

  • of an approach to the Provider by the Information Commissioner or by an individual claiming that their privacy has been interfered with.

Providers should be aware that the Department monitors Personnel access to Records in the Department’s IT Systems. Where a clear business reason for access to a Record or Records is not identified, the Department may require further information or investigation by a Provider and may take action against individuals.

3.12. Privacy complaints

An individual who considers that their privacy has been interfered with can contact the Department and/or the OAIC to make a complaint. Where possible, complaints under the Privacy Act should be directed to an individual’s Provider in the first instance.

Providers are required to respond to any privacy complaints within 10 Business Days and in accordance with the PPIR where a privacy incident has been identified. Providers should follow OAIC’s advice on handling privacy complaints.

3.13. Referring individuals to the Department in relation to privacy matters

After first directing their query to their Provider, an individual can contact the Department to query how their personal information is handled, request access to or correction of their personal information, or make a privacy complaint in relation to the Department or a Provider.

Individuals may contact the Department via privacy@dewr.gov.au.

For further information and alternative contact details, please refer to the Department of Employment and Workplace Relations' Privacy Policy.

3.14. Awareness and Training Expectations

Providers must adopt practices to ensure its Personnel are aware of their obligations under the Privacy Act, the Deed and this Chapter. Providers who have access to the Department’s IT Systems must ensure that all Personnel who handle or will handle personal information in the course of delivering services under the Deed complete the Department’s Information Exchange and Privacy module (training module), available on the Learning Centre:

Providers should note that the Department’s privacy training module has been developed to cater for the delivery of all employment services. It is not a substitute for any tailored internal privacy training Providers make available to their Personnel. Providers must consider the nature of the employment services they are delivering and Personnel interaction with personal information for those employment services. Where required, the Provider must supplement the Department’s privacy training module with its own additional privacy training, within the timeframes above.

3.14.1. Information Exchange and Privacy Module

The Department’s Information Exchange and Privacy module (sign-in required) explains the key concepts under the Privacy Act and the APPs which govern how personal information is collected, used, disclosed, and stored.

The training module is mandatory and is essential to ensure that all Personnel handling personal information have a common understanding of this Chapter, the APPs, and the Social Security Law, including key processes that help manage potential risks. The completion of mandatory training assists Providers to meet legislative and regulatory requirements, but is not sufficient to meet those requirements.

Privacy resources are also published on the Provider Portal for Personnel to access.

Providers should ensure their internal privacy practices, policies and procedures are proactively reviewed, taking into account compliance with new laws or updated information handling practices, and ensuring that they are responsive to new privacy risks.

3.14.2. Personnel Compliance

Providers must monitor and annually self-audit Personnel completion of privacy training, including the Department’s mandatory privacy training module. The Department may request details of a Provider’s self-audit at any time, or may conduct its own audit of a Provider’s compliance with the requirements in this Chapter.

Where privacy training is undertaken outside of the Department’s Learning Centre, the Provider must retain Records of privacy training undertaken by their Personnel and must make this available to the Department on request.

It is also suggested that Providers put in place their own processes to audit the compliance of their Personnel with privacy obligations more generally.

On this page