
Privacy Law
Australian Privacy Principles
APP 6 — Use or Disclosure of Personal Information
Use or disclosure
If an organisation has possession or control over personal information about an individual that was collected for a particular purpose (aka the ), the entity must not use or disclose the information for another purpose (aka the ).
A Primary purpose is that which is immediate or obvious or which is stated to the individual, while a secondary purpose is something on the side, or which may arise subsequently, or may be in the back of the collector's mind. This is important terminology to be aware of in the interpretation of the Act.
Exceptions to the above include where:
-
the individual has consented expressly or impliedly to the use or disclosure of the information (See section 6(1)).
-
the individual would reasonably expect the organisation to use or disclose the information for a secondary purpose which is related to the primary purpose. ( requires a direct relationship to the primary purpose)
-
use or disclosure of the information is required or authorised by law or a court order
-
a exists
-
the information is provided to the police or other government enforcement body. Under APP 6.5, the individual must be notified of such disclosure.
Reasonable Expectation
The OAIC characterises reasonable expectation as based on what a reasonable person, if properly informed, would expect in the circumstances. It exemplifies a reasonable expectation as where the individual makes a complaint in the media about the organisation, giving rise to a right for the organisation to defend itself by releasing certain personal information. Given the distance between a public battle and the basis on which most personal information would be given to most organisations, this seems more a moral imputation of a right of self defence rather than recognition of a plausible related purpose – and thus not acceptable to a court as an interpretation of this statute. Perhaps better examples would be when an employee sues an employer for an employment-related matter, or where a client who is reasonably expected to present a risk of some kind, actually causes such harm (maybe to a worker or contractor), the employer’s self defence in the midst of known contingencies is a reasonably expected secondary purpose, so it can prepare for litigation by using personal information.
Also, where an employee claims for compensation under Work Cover insurance, the information the employer holds about them can be used for the reasonably expected secondary purpose of investigating whether the claim is legitimate.
Related bodies corporate
If the organisation is a corporation and collects information from a related corporation, then the primary purpose for the original collection still applies.
APP 7 — Direct Marketing
Direct marketing
An organisation must not use or disclose personal information for the purpose of direct marketing.
Exceptions
An organisation may use or disclose personal information (other than sensitive information) about an individual for the purpose of direct marketing if:
-
the individual concerned would reasonably expect the organisation that collected it to use or disclose it for that purpose; and
-
the organisation provides a simple opt-out method and the individual has yet to opt out.
Situations are also provided for under 7.3 where the individual may not reasonably expect direct marketing and either has consented, or where it is impracticable to obtain consent.
Exception — sensitive information
An organisation may use or disclose sensitive information for purposes of direct marketing if the individual has consented to use or disclosure for that purpose.
Individual may Opt Out
-
An organisation must, on request, notify an individual of the source of the information concerned, unless this is unreasonable or impracticable to do so.
-
If an individual requests of an organisation that they not use or disclose personal information for purposes of direct marketing (either their own marketing or another entity’s marketing), then that request must be granted.
APP 8 — Cross-Border Disclosure of Personal Information
Before an organisation discloses personal information about an individual to an overseas recipient, they must ensure, as reasonable, that the overseas recipient does not breach the APPs (other than APP 1) in relation to the information. An overseas recipient is expressed to be a ‘person.’
This APP is to be read in conjunction with Section 16C. It provides, basically, that where an overseas recipient is not itself bound by the APPs then the organisation itself is liable for any act by the overseas recipient in breach of the APP’s.
‘Persons’ are usually taken in law to be individuals or incorporated bodies. ‘Disclosure’ is considered to have occurred for purposes of the Act when the organisation grants access to information and releases it from its own control. It is furthermore a positive act and distinct from unauthorised access, or usage of information such as placing it on an internet server located overseas. It has to reach the recipient themselves before disclosure is considered to have been made.
As to what reasonable steps are to be taken, the OAIC recommends that organisations enter enforceable contracts to control the recipient’s treatment and use of the information. The organisation need not take these steps if it is reasonably satisfied that the recipient is subject to laws that will protect the information in a similar way and the individual can access effective mechanisms of enforcement. These steps also do not apply if the individual consents to the overseas disclosure.
APP 9 — Adoption, Use or Disclosure of Government Related Identifiers
Definition
A Government Related Identifier (GRI) is a code which identifies a person, and is used by a government body. Eg: tax file number, licence numbers, Medicare number, Passport number and Centrelink reference number. Excluded from this are the individual’s name and ABN.
Adoption of government related identifiers
An organisation must not adopt a government related identifier of an individual as its own identifier of the individual unless specially required or authorised by law, or subject to a judicial order.
According to the OAIC, to adopt is to organise information about a person with reference to the GRI. Also according to OAIC, this is simply to prevent general use of GRI’s. Not really a privacy rule at all in that case.
Use or disclosure of government related identifiers
An organisation must not use or disclose a government related identifier of an individual unless:
-
it is reasonably necessary for the verification of the individual’s identity, for the purposes of the organisation's activities or functions; or
-
it is reasonably necessary for the organisation to fulfil its obligations to a government or a body acting on behalf of the government (an agency).
-
it is required or authorised by or under an Australian law or a court/tribunal order; or
-
a permitted general situation exists as per s 16A.
-
it is reasonably necessary for enforcement related activities conducted by an enforcement body (Eg: the police) or
-
regulations apply which prescribe the particular identifier, the organisation (or type of organisation) and the relevant circumstances.

