
Privacy Law
Australian Privacy Principles
APP1 – Open and Transparent Management of Personal Information
Organisations are to manage personal information in an open and transparent way. This requires accountability with the public in information handling practices. Even if an organisation is accustomed to maintaining secrecy over commercial-in-confidence information, its processes for handling personal information are not secret.
Compliance with the Australian Privacy Principles etc.
An organisation must adopt procedures to permit compliance with all privacy principles or any relevant code, and the due handling of all inquiries and complaints regarding compliance. The steps taken need only be what is reasonable considering the nature of the information, the nature of the organisation and the risk of a breach of privacy and cost or practicality of measures.
APP Privacy policy
Organisations must have a clearly expressed and up-to-date privacy policy which delineates how they manage personal information. Avoid jargon and make it concise.
The privacy policy must include:
-
How an organisation manages personal information
-
How an organisation collects and hold personal information
-
The purposes for which information is collected, held, used and disclosed
-
How an individual may access personal information about themselves and seek correction of such
-
How an individual may complain about a breach of the Australian Privacy Principles, or a relevant code and how such complaints will be dealt with
-
Whether an organisation is likely to disclose personal information to overseas recipients;
-
If yes to f) -- the countries in which such recipients are likely to be located
Availability of APP privacy policy etc.
All reasonable steps must be taken to make the privacy policy available free of charge in an appropriate form. Eg: on an organisation's website, in a retail premises, by post.
It must be provided upon request in the requested form. The organisation needs to take whatever steps as are reasonable. The OAIC views this law as excusing organisations from declining to provide their privacy policies in a form that is unreasonable to expect it in.
APP 2 — Anonymity and Pseudonymity
An organisation must give individuals the option of not identifying themselves, or using a pseudonym, when dealing with an organisation in relation to a particular matter. This means:
-
An organisation cannot demand correct identity or proof of identity and,
-
People must be made aware of their opportunity to do this.
This does not apply to an organisation if:
-
It is required or authorised under an Australian law, or a court order, to deal with individuals who have identified themselves, or
-
It is impracticable for an organisation to deal with individuals who have changed or withheld their correct name. An example is when goods are to be delivered, especially if a recipient signature is required.
Note: Anonymity by rights involves giving no details by which a person can be identified by the recipient(s) of the information. Pseudonymity involves giving a false name, it but can allow some identifying details to be given.

