2003Defense Counsel JournalRequires access

Protection of Personal Data: The Australian Perspective; New Legislation Has Applied the Information Privacy Principles of 1988 to the Private Sector through National Privacy Principles

Steven Klimt, Narelle Symthe, S. Stuart Clark, Jason Shailer

Open publisher page 1 citations

Abstract

The Privacy Project New legislation has applied information privacy principles of 1988 to private sector through national privacy principles THE MAIN data protection law in Australia in relation to privacy is Privacy Act 1988 (Cth). It has been amended by Privacy Amendment (Private Sector) Act 2000 (Private Sector Act), which came into operation in December 2001 and effectively extends operation of 1988 act to private sector. The regime introduced by Private Sector Act has far-reaching consequences for both business community and consumers in Australia. The stated aim is to reduce obstacles to development, takeup and use of electronic commerce and other new technologies resulting from concerns about possible mishandling of personal information by private sector, while at same time avoiding excessive red tape and minimising cost of compliance on business. The 2000 Act creates a co-regulatory legislative framework through development of self-regulatory codes of practice by organisations that must achieve certain minimum standards of privacy protection set out in 10 National Privacy Principles (NPPs) in act. The NPPs are core of private sector regime and establish minimum standards in relation to collection, holding, use, disclosure, management, access, correction and disposal of personal information about natural persons. The NPPs also include special measures with regard to certain types of personal information defined as sensitive. In absence of a relevant self-regulatory code, NPPs themselves will apply. The requirements of Private Sector Act have affected, directly or indirectly, all businesses in Australia. Organisations subject to regulation under act have been required to implement changes to transactional documents, internal and external information handling and security procedures, information technology requirements, customer communications and training of staff in order to comply with new regime. Maintaining compliant information-handling practices is a continuing challenge. It is important to note that Private Sector Act does not stand alone. Regulation of information-handling practices in Australia intended to protect individuals' privacy has existed in a number of forms prior to Private Sector Act, although these existing regimes will not be considered in any detail in this article. A number of state and territory governments have enacted legislation affecting their governments' dealings with individuals' personal information-for example, Privacy and Personal Information Act 1998 in New South Wales. Other existing forms of regulation of informationhandling practices affecting private sector include (1) common law obligations of confidentiality; (2) a number of statutory mechanisms affecting specific industry sectors; and (3) voluntary codes of conduct adopted by industry groups-for example, Insurance Council of Australia, Australian Direct Marketing Association, and Australian Bankers Association. The 1988 Act required federal government agencies to act in accordance with 11 Information Privacy Principles (IPPs), which are broadly similar to NPPs. The Privacy Act applies these to private sector organizations (1) in relation to collection, storage, use and security of tax file number information; and (2) in relation to information-handling practices of credit reporting agencies, credit providers and associated persons. SCOPE OF PRIVATE SECTOR REGIME The Private Sector Act introduced a new termed the private sector regime, which operates within existing structure of 1988 Privacy Act. References in this paper to sections are, unless otherwise stated, references to sections of Privacy Act 1988, as amended by Private Sector Act. The 2000 act extends regulation of handling of all forms of personal information across private sector, and it introduces new provisions and modifies a number of existing provisions, while leaving preexisting obligations on private sector organisations regarding tax file number information and credit reporting practices in place. …

About this research paper

What this paper is about

The Privacy Project New legislation has applied information privacy principles of 1988 to private sector through national privacy principles THE MAIN data protection law in Australia in relation to privacy is Privacy Act 1988 (Cth). It has been amended by Privacy Amendment (Private Sector) Act 2000 (Private Sector Act), which came into operation in December 2001 and effectively extends operation of 1988 act to private sector. The regime introduced by Private Sector Act has far-reaching consequences for both business community and consumers in Australia. The stated aim is to reduce obstacles to development, takeup and use of electronic commerce and other new technologies resulting from concerns about possible mishandling of personal information by private sector, while at same time avoiding excessive red tape and minimising cost of compliance on business. The 2000 Act creates a co-regulatory legislative framework through development of self-regulatory codes of practice by organisations that must achieve certain minimum standards of privacy protection set out in 10 National Privacy Principles (NPPs) in act. The NPPs are core of private sector regime and establish minimum standards in relation to collection, holding, use, disclosure, management, access, correction and disposal of personal information about natural persons. The NPPs also include special measures with regard to certain types of personal information defined as sensitive. In absence of a relevant self-regulatory code, NPPs themselves will apply. The requirements of Private Sector Act have affected, directly or indirectly, all businesses in Australia. Organisations subject to regulation under act have been required to implement changes to transactional documents, internal and external information handling and security procedures, information technology requirements, customer communications and training of staff in order to comply with new regime. Maintaining compliant information-handling practices is a continuing challenge. It is important to note that Private Sector Act does not stand alone. Regulation of information-handling practices in Australia intended to protect individuals' privacy has existed in a number of forms prior to Private Sector Act, although these existing regimes will not be considered in any detail in this article. A number of state and territory governments have enacted legislation affecting their governments' dealings with individuals' personal information-for example, Privacy and Personal Information Act 1998 in New South Wales. Other existing forms of regulation of informationhandling practices affecting private sector include (1) common law obligations of confidentiality; (2) a number of statutory mechanisms affecting specific industry sectors; and (3) voluntary codes of conduct adopted by industry groups-for example, Insurance Council of Australia, Australian Direct Marketing Association, and Australian Bankers Association. The 1988 Act required federal government agencies to act in accordance with 11 Information Privacy Principles (IPPs), which are broadly similar to NPPs. The Privacy Act applies these to private sector organizations (1) in relation to collection, storage, use and security of tax file number information; and (2) in relation to information-handling practices of credit reporting agencies, credit providers and associated persons. SCOPE OF PRIVATE SECTOR REGIME The Private Sector Act introduced a new termed the private sector regime, which operates within existing structure of 1988 Privacy Act. References in this paper to sections are, unless otherwise stated, references to sections of Privacy Act 1988, as amended by Private Sector Act. The 2000 act extends regulation of handling of all forms of personal information across private sector, and it introduces new provisions and modifies a number of existing provisions, while leaving preexisting obligations on private sector organisations regarding tax file number information and credit reporting practices in place. …

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The Privacy Project New legislation has applied information privacy principles of 1988 to private sector through national privacy principles THE MAIN data protection law in Australia in relation to privacy is Privacy Act 1988 (Cth). It has been amended by Privacy Amendment (Private Sector) Act 2000 (Private Sector Act), which came into operation in December 2001 and effectively extends operation of 1988 act to private sector. The regime introduced by Private Sector Act has far-reaching consequences for both business community and consumers in Australia. The stated aim is to reduce obstacles to development, takeup and use of electronic commerce and other new technologies resulting from concerns about possible mishandling of personal information by private sector, while at same time avoiding excessive red tape and minimising cost of compliance on business. The 2000 Act creates a co-regulatory legislative framework through development of self-regulatory codes of practice by organisations that must achieve certain minimum standards of privacy protection set out in 10 National Privacy Principles (NPPs) in act. The NPPs are core of private sector regime and establish minimum standards in relation to collection, holding, use, disclosure, management, access, correction and disposal of personal information about natural persons. The NPPs also include special measures with regard to certain types of personal information defined as sensitive. In absence of a relevant self-regulatory code, NPPs themselves will apply. The requirements of Private Sector Act have affected, directly or indirectly, all businesses in Australia. Organisations subject to regulation under act have been required to implement changes to transactional documents, internal and external information handling and security procedures, information technology requirements, customer communications and training of staff in order to comply with new regime. Maintaining compliant information-handling practices is a continuing challenge. It is important to note that Private Sector Act does not stand alone. Regulation of information-handling practices in Australia intended to protect individuals' privacy has existed in a number of forms prior to Private Sector Act, although these existing regimes will not be considered in any detail in this article. A number of state and territory governments have enacted legislation affecting their governments' dealings with individuals' personal information-for example, Privacy and Personal Information Act 1998 in New South Wales. Other existing forms of regulation of informationhandling practices affecting private sector include (1) common law obligations of confidentiality; (2) a number of statutory mechanisms affecting specific industry sectors; and (3) voluntary codes of conduct adopted by industry groups-for example, Insurance Council of Australia, Australian Direct Marketing Association, and Australian Bankers Association. The 1988 Act required federal government agencies to act in accordance with 11 Information Privacy Principles (IPPs), which are broadly similar to NPPs. The Privacy Act applies these to private sector organizations (1) in relation to collection, storage, use and security of tax file number information; and (2) in relation to information-handling practices of credit reporting agencies, credit providers and associated persons. SCOPE OF PRIVATE SECTOR REGIME The Private Sector Act introduced a new termed the private sector regime, which operates within existing structure of 1988 Privacy Act. References in this paper to sections are, unless otherwise stated, references to sections of Privacy Act 1988, as amended by Private Sector Act. The 2000 act extends regulation of handling of all forms of personal information across private sector, and it introduces new provisions and modifies a number of existing provisions, while leaving preexisting obligations on private sector organisations regarding tax file number information and credit reporting practices in place. …

Key concepts: Information privacy law, Private sector, Privacy law, Business, Legislation, Information privacy, Privacy policy, Data Protection Act 1998

Related papers

Back to paper searchBrowse research topicsOriginal source
Protection of Personal Data: The Australian Perspective; New Legislation Has Applied the Information Privacy Principles of 1988 to the Private Sector through National Privacy Principles — Research Paper | ScholarLens