top of page

Privacy Law

Australian Privacy Principles

APP 3 — Collection of Solicited Personal Information

Collecting information, for purposes of the Act, is when information is gathered, acquired or obtained for inclusion in a record or publication. The information can come from any source, by any means. Soliciting of information is, for purposes of the Act, when an organisation requests information from an individual or a third party about the individual. The individual may or may not be involved at all. It can then be collected – that is, acquired and placed on record.

Personal information other than sensitive information

 An organisation must not collect personal information (other than sensitive information) unless it is reasonably necessary for, or directly related to, one or more organisation functions or activities. Therefore collecting information  that will not be used is disallowed.

Sensitive Information

If the information sought is sensitive information, an organisation must not solicit it from any source unless the individual consents to the collection of the information and the information is reasonably necessary for one or more organisation functions or activities; or if any of a few special situations apply, such as:

  • If the information is required or authorised by law or a court order;

  • If he collection of the information is reasonably necessary for, or directly related to, one or more of the organisation’s functions or activities; or

  • a applies, such as where it is reasonably necessary for the establishment, exercise or defence of a legal or equitable claim, or confidential alternative dispute resolution.

 

Means of collection

An organisation can only collect personal information by lawful and fair means. A fair means is defined as ‘one that does not involve intimidation or deception, and is not unreasonably intrusive.’ The OAIC stated, by way of example, that obtaining information covertly is unfair, unless it is done for purposes of fraud detection.

An organisation must collect personal information about an individual only from the individual unless it is unreasonable or impracticable to do so. There is no law giving further detail, but the OAIC’s policy is that what is reasonable and practicable depends on:

  • whether the individual would reasonably expect personal information about them to be collected directly from them

  • the sensitivity of the information

  • whether direct collection would jeopardise the purpose of collection or the integrity of the information

  • any privacy risk

  • excessive time, cost and inconvenience involved in collecting directly from the individual, as judged from all the circumstances.

 

APP 4 — Dealing with Unsolicited Personal Information

If an organisation receives personal information which it did not solicit, it must determine whether it is information that it could have collected under APP 3. See APP 3, above, for further details.

The organisation can use or disclose the information for purposes of making this determination.

If the answer to the above is ‘no’, then the organisation must destroy or de-identify that information as long it is lawful and reasonable to do so. If the answer is ‘yes’ then the organisation need not destroy or de-identify it, but must handle it in accordance with the Act.

Destruction or de-identification is unlawful in some circumstances. The Act does not define what is unlawful, but it is a reference to obligations such as:

  • Reporting a crime;

  • Not interfering with evidence of a crime;

  • ISP’s obligation to keep meta data for two years.

 

Examples of unsolicited personal information include misdirected mail, petitions containing contact details, and information given in addition to what is requested, or information given casually by private individuals such as customers or friends of employees.

APP 5 — Notification of the Collection of Personal Information

An organisation that collects personal information is to take reasonable steps either to notify the individual of certain matters or to ensure the individual is aware of those matters. Reasonable steps must be taken at or before the time of collection, or as soon as practicable afterwards. This applies whether the information was acquired through solicitation or not (unless the information is destroyed or de-identified).

An organisation must take reasonable steps to give the notification. The OAIC’s policy is that what steps are reasonable must be determined on the circumstances. This includes the sensitivity of the information, the possible adverse consequences for an individual of the collection, special needs of the individual and, excessive impracticability, including the time and expense involved. Mere inconvenience is not an excuse.

 

By implication it may sometimes be unreasonable to require notification. The organisation must justify any inaction. One example provided by the OAIC is where notification may jeopardise the purpose of collection or the integrity of the personal information collected and there is a clear public interest in the purpose of collection. Another is if notification would somehow breach another law.

 

The matters that an individual must be notified of include those which in the following list are reasonable to expect:

  • The organisation’s identity and contact details

  • Unless the individual should know, the fact that the organisation collects, or has collected, the information, and the circumstances of that collection.

  • Any law requiring the collection of the information.

  • The purpose of collection.

  • The main consequences for the individual of not collecting the information.

  • Any other party to which the organisation usually discloses personal information of the relevant kind.

  • That the organisation’s privacy policy states how the individual may access the information, and how they may complain about any breach of privacy law.

 

 

Explanatory Memorandum, Privacy Amendment (Enhancing Privacy Protection) Bill 2012, p 77 , as stated in Australian Privacy Principles Guidelines, Privacy Act 1988, Office of the Australian Information Commissioner, Canberra, 2015, p14.

Australian Privacy Principles Guidelines, op cit 2.

bottom of page