Court Data Australia and Office of the Australian Information Commissioner [2025] ARTA 876 (28 May 2025)
Applicant:Court Data Australia
Respondent: Office of the Australian Information Commissioner
Other Party HBBM
Tribunal Number: 2024/1435
Tribunal:General Member J. Ross
Place:Canberra
Date:28 May 2025
Decision:The Tribunal affirms the decision under review.
........................................................................
General Member J. Ross
CATCHWORDS
PRIVACY ACT 1988 – collection of solicited personal information–collection by lawful and fair means–whether the collection was fair–notification of the collection of personal information–were reasonable steps taken to ensure awareness–quality of personal information–were reasonable steps taken to ensure personal information is accurate, up-to-date and complete–breach of APP 3.5, 5.1, 10.2 established
LEGISLATION
Privacy Act 1988 (Cth), ss 2A, 13, 52, sch 1 (Australian Privacy Principles)
CASES
Clearview AI Inc and Australian Information Commissioner [2023] AATA 1069 078
Commissioner initiated investigation into Clearview AI, Inc. [2021] AICmr 54 135
Drake v Minister for Immigration and Ethnic Affairs (1979) 46 FLR 409; (1979) 24 ALR 577
SZTAL v Minister for Immigration and Border Protection (2017) 262 CLR 362
White v Director of Public Prosecutions [2011] HCA 20; (2011) 243 CLR 478
SECONDARY MATERIALS
OAIC Australian Privacy Principles Guidelines (July 2019 version)
Statement of Reasons
INTRODUCTION
The Applicant in this matter JFA (Aust) Pty Ltd trading as Court Data Australia (CDA) applied to the Administrative Review Tribunal (Tribunal) for review of a determination dated 12 February 2024 made by the Respondent, the Australian Information Commissioner (Information Commissioner).
The Respondent determined (Commissioner’s Determination) under s 52(1)(b)(i)(B) of the Privacy Act 1988 (Cth) (Privacy Act) that the Applicant had interfered with the complainant’s (the Other Party) privacy by failing to:
(a)collect the Other Party’s personal information by fair means in breach of Australian Privacy Principles (APP) 3.5.
(b)take such steps as were reasonable in the circumstances to notify the Other Party of the collection of their personal information in breach of APP 5, and
(c)take such steps as were reasonable in the circumstances to ensure that personal information it disclosed about the Other Party was accurate, up-to-date, complete and relevant, having regard to the purpose for which the Respondent disclosed the Other Party’s personal information in breach of APP 10.
As a result of the breaches, the Respondent declared under s 52(1)(b)(ia) of the Privacy Act that the Respondent must:
(a)Cease to collect personal information from the Portal in breach of the Portal’s Conditions of Use and without the knowledge of the Other Party whose personal information is collected.
(b)Within 30 days of the determination, ensure that any personal information that it has collected from the Portal in breach of the Portal Conditions of Use and without the knowledge of the Other Party whose personal information is collected for the Database, is destroyed.
(c)Within 14 days of compliance with (b), report to the Office of the Australian Information Commissioner the steps that it took to ensure that the personal information referred to in [b] was destroyed.
ISSUES
This matter has a long history with the initial complaint made by the Other Party to the Respondent in June 2020. There are now three issues accepted by both Parties for determination by the Tribunal. These issues concern the question of whether CDA unlawfully interfered with the Other Party’s privacy by failing to:
(i)collect the Other Party’s personal information by fair means (APP 3.5),
(ii)take such steps as were reasonable in the circumstances to notify the Other Party of the collection of their personal information (APP 5.1), and
(iii)take such steps as were reasonable in the circumstances to ensure the personal information it disclosed about the Other Party was accurate, up-to-date, complete and relevant having regard to the purpose for which it was disclosed (APP 10.2).
The court data Australia system
There are slight differences in the way that the Applicant and Respondent describe the business of CDA.
The Applicant submits the primary function of CDA is to provide the public with a searchable database of information about historical and current criminal and civil court list records.[1] The Applicant also submits that in reproducing the information provided by each Australian court in their published daily court lists it operates identically to the Australian Legal Information Institute The Applicant further submits a CDA record is simply factual information and is no more designed to draw inferences than the daily court lists published by the courts and by extension the site.[3]
[1] Exhibit R2, T2, page 011; CDA, About, About Court Data Australia - courtdata.com.au, accessed 7 April 2025.
[2] Exhibit R2, T2, page 11.
[3] Ibid, page 8.
The Respondent submits that CDA operates ‘what is, in essence’, a ‘data scraping business’ in relation to Australia’s court listings.[4] This is because each day CDA collects information including personal information contained in published daily court and tribunal lists and places this information into its databases (CDA database) using a ‘web crawler’ or ‘data scraper’.[5]
[4] Ibid.
[5] Ibid, page 12.
The Applicant takes issue with the Respondent describing CDA as a ‘data scraping business’ and using the term ‘web crawler’ as the Applicant regards that this description is an attempt to affix some kind of negative connotations to the work of CDA.[6] The Applicant says it uses programs to extract data from websites but says the majority of the work involves processing that data into a state that can be searched on CDA’s database.[7]
[6] Exhibit R2 T6, page 59.
[7] Ibid.
A person must be a CDA account holder to search the CDA database for the name of an individual, business or government entity to see if they have been scheduled to appear before a criminal or civil court in any Australian jurisdiction.[8] Registering an account allows users to search the database for free.[9] However, fees apply to obtain full details of database records.[10]
CDA’s collection of the Other Party’s personal information from Western Australian court listings
[8] CDA, About, About Court Data Australia - courtdata.com.au, accessed 7 April 2025.
[9] CDA, Fees, CDA Database search fees - courtdata.com.au, accessed 12 May 2025.
[10] Ibid.
The Respondent’s Determination is concerned only with information collected from the court listings posted on the Western Australian Courts Portal (WA Portal). The personal information collected from the WA Portal concerning the Other Party was 52 court listings relating to six criminal charges against the Other Party.[11] The Other Party asked CDA to remove the information as the charges were dismissed.[12] Because CDA failed to remove the information the Other Party (through her mother as authorised representative) lodged a privacy complaint with the Information Commissioner.[13]
[11] Exhibit R2 T8, page 80.
[12] Exhibit R2 T6, page 036.
[13] Ibid.
The Condition of Use for the WA Portal says that ‘copyright in this Website and any Application and their respective Material is vested in the State of Western Australia’ and further ‘no part of this Website, an Application or any Material in either of them may be reproduced or re-used for any commercial purpose without the prior written permission of the Court.[14] In response to the Respondent’s preliminary views on this matter the Applicant implemented a free Western Australian search option in an attempt to appease the Respondent’s concerns regarding copyright.[15]
[14] Exhibit R2 T4, page 013.
[15] Exhibit R2 T6, page 059.
RELEVANT LEGISLATION
Section 13 of the Privacy Act provides that an act or practice of an APP entity is an interference with the privacy of an individual if the act or practice breaches an APP in relation to the personal information about the individual.
The APPs relevant to this matter are:
(a)APP 3 – collection of solicited personal information,
(b)APP 5 – notification of the collection of personal information, and
(c)APP 10 – quality of personal information.
There is no dispute that the Applicant collects information from court lists which is personal information within the meaning of the Privacy Act.
CONSIDERATION
APP 3.5 – collection by lawful and fair means
Parties’ submissions
APP 3.5 requires an APP entity to collect personal information only by lawful and fair means.
The issue is whether the collection of the Other Party’s personal information was by fair means.
The Commissioner’s Determination was that the Respondent breached APP 3.5 because the Other Party’s information was collected in a way that was not fair as it was collected contrary to the Portal’s Conditions of Use, and in circumstances where the Other Party was not aware of the collection and could not reasonably have expected the Respondent to collect their personal information.[16]
[16] Ibid.
The Applicant submits, using as an example, that it is quite well understood by the public that anything that is legally published online can be and is often republished or reproduced somewhere else.[17]
[17] Exhibit R2 T2, page 014.
The Applicant also submits that there is no evidence that the collection of the Other Party’s personal information was contrary to the WA Portal’s condition of use.[18] The Applicant further submits there has been no copyright breach because copyright protects creative or artistic endeavour or expression which does not form part of the information that CDA extracts from the WA Portal and in any event WA courts have not asserted or concluded that the conditions of the WA Portal have been breached.[19] In his reply submissions the Applicant also submits that CDA prominently describes ‘research purposes’ on its website and reiterated that the material used by CDA is not something that can be the subject of copyright.[20]
[18] Ibid.
[19] Ibid.
[20] Exhibit R2 T6, page 060.
The Applicant submits that these factors combined mean that it is more than reasonable for a person who has been scheduled to appear before an Australian court to expect that their name to be on the CDA database.[21] To illustrate this point the Applicant submits that the very fact that the Other Party searched their name means that they had a reasonable expectation it would appear on the CDA database.[22] The Applicant also submits that CDA has always gone to a great deal of effort to ‘specifically encourage its users to not draw any adverse inferences from the fact a name is in the CDA database’.[23] The example the Applicant provided was that CDA makes it clear on its website that the database only contains matters scheduled to be heard before a court and not court outcomes.[24]
[21] Ibid.
[22] Exhibit R2 T4, page 015.
[23] Exhibit R2 T6, page 060.
[24] Ibid.
In relation to the temporary nature of published daily court lists, the Applicant submits that the WA Portal also has a future court listing search facility that can include matters to be heard in the future.[25]
[25] Ibid.
The Applicant further submits that the Respondent has failed to take into account the object of the Privacy Act which provides that the protection of the privacy of individuals is balanced with the interests of entities in carrying out their functions and activities.[26]
[26] Exhibit R2 T6, page 061.
The Respondent submits that because the meaning of ‘fair’ is not defined in the Privacy Act, consistent with the principles of statutory interpretation, its meaning under APP 3.5 needs to be determined having regard to a consideration of the text, context and purpose of the Privacy Act.[27] The Respondent also submits that because it is not defined it is necessary to undertake an open-textured, evaluative assessment which makes it not susceptible to precise and comprehensive defining.[28]
[27] Ibid.
[28] Exhibit R2 T4, page 041.
The Respondent further submits the objects of the Privacy Act in s 2A that inform the content of the norm of fairness in APP3.5 including:
(a) “to promote the protection of the privacy of individuals”
(b) “to recognise that the protection of the privacy of individuals is balanced with the interests of entities in carrying out their functions or activities”
(d) “to promote responsible and transparent handling of personal information by entities”
(g)“to provide a means for individuals to complain about an alleged interference with their privacy”.
The Respondent submits a long list of features that it further submits when combined support the conclusion that the collection of the personal information was unfair.[29] This is because the Other Party would not have had a reasonable expectation that her personal information would be collected and stored indefinitely on a searchable commercial database which encourages the drawing of adverse inferences about her.[30]
[29] Exhibit R2 T4, page 041 and 042.
[30] Ibid.
Was the collection ‘fair’?
‘Fair’ is not defined in the Privacy Act.[31] However the APP guidelines (APP guidelines) say:
A ‘fair means’ of collecting information is one that does not involve intimidation or deception, and is not unreasonably intrusive. Whether a collection uses unfair means will depend on the circumstances. For example, it would usually be unfair to collect personal information covertly without the knowledge of the individual. However, this may be a fair means of collection if undertaken in connection with a fraud investigation.[32]
[31] Exhibit R2 T8, page 089.
[32] Exhibit R3, page 0869.
The Tribunal will follow what is in the APP guidelines unless there are cogent reasons not to do so.[33] Although the guidance above is useful and appears in the explanatory memorandum to the Privacy Act, I agree with the Respondent’s submission that it does not purport to exhaustively define the standard of what is ‘fair’ under APP 3.5.[34] In addition, given the somewhat novel context of this matter, none of the examples provided in the APP guidelines of when a collection of personal information may not be by fair means are entirely analogical to this matter.[35] However, the example does show that the context in which the personal information is collected is important in determining whether the collection was by fair means.
[33] Re Drake and Minister for Immigration and Ethnic Affairs (No. 2) (1979) 2 ALD 634.
[34] Exhibit R2 T4, page 041. The Respondent’s Statement of Facts, Issues and Contentions makes reference to the explanatory memorandum to the Privacy Act which states that the OAIC has interpreted fair to mean without intimidation or deception or without use of means that are unreasonably intrusive.
[35] Ibid.
The Respondent directed the Tribunal to the High Court’s decision in SZTAL v Minister for Immigration and Border Protection where Kiefel CJ, Nettle and Gordon JJ said:[36]
[36] (2017) 262 CLR 362 at [14].
‘The starting point for the ascertainment of the meaning of a statutory
provision is the text of the statute whilst, at the same time, regard is
had to its context and purpose. Context should be regarded at this
first stage and not at some later stage and it should be regarded in its
widest sense. This is not to deny the importance of the natural and
ordinary meaning of a word, namely how it is ordinarily understood in
discourse, to the process of construction. Considerations of context and
purpose simply recognise that, understood in its statutory, historical or
other context, some other meaning of a word may be suggested, and so
too, if its ordinary meaning is not consistent with the statutory purpose,
that meaning must be rejected.’
In the hearing, Counsel for the Respondent took the Tribunal through a list of features that they consider when combined make the collection unfair.[37] Counsel for the Respondent also made it clear that it is not necessary for the Tribunal to conclude on all these features. The features I consider require closer examination in determining whether the collection was fair are:
(a)the publication of the personal information was not made by the Other Party who had no control of their personal information being published on the WA Portal,
(b)the Other Party was not notified so was not aware that the Applicant had collected their personal information,
(c)the transitory nature of court lists and their purpose compared to the permanent nature and purpose of the information on CDA’s database, and
(d)the collection of the personal information from the Other Party for commercial gain despite the Applicant being aware of the Conditions of Use of the WA Portal.
[37] See Exhibit R2 T4, page 042 for full list of features.
Senior Member now Deputy President O’Donovan stated in Clearview AI Inc and Australian Information Commissioner[38] (Clearview) fair becomes hard to judge in relation to information that is collected from the public internet which is open to any person to take without informing the person to whom in relates that they have done so.
[38] [2023] AATA 1069.
Deputy President O’Donovan also stated in Clearview that he was not satisfied that it was unfair to collect an image using a web crawler of an individual who had decided to place their image on the internet without any restrictions.[39] He also said the result might be different if the collection was in breach of the limitations that the person posting the image understood would apply.[40]
[39] At [133].
[40] Ibid.
I do not find the automated means of collection by CDA to be inherently unfair, that is, as opposed to manual collection.
Having said that, I consider that automated collection makes the information easier to collect and therefore less discriminating. I also consider there are significant concerns with the way the Applicant collected the Other Party’s personal information when looked at in all the circumstances. I find the fact that the Other Party was not in a position to provide consent to the publication of her personal information nor was aware that the Applicant had collected her personal information to be significant to determining whether the collection was by fair means.
There are valid reasons why the Other Party had no decision-making ability or ‘control’ in relation to their personal information being published on the WA Portal. As is stated in the Respondent’s decision, the publication of the information on the WA Portal was a result of Australia’s system of open justice.[41] Indeed, it could well be the case that if the Other Party was in the position to provide consent, they may have refused the publication. However, the context within which the information was published also makes it public information, that as the Applicant submits, is free for any member of the public to take. Given the different circumstances of this case, I find that Clearview does not help in supporting a finding that there has been no breach of APP 3.5.
[41] Exhibit R2 T8, Page 089.
I also find the difference in the nature and the purpose of daily courts lists compared to CDA’s database to be significant in that the Other Party could not have reasonably expected that her personal information would be taken from the WA Portal and used for a commercial purpose unrelated to the purpose for which it was posted.
Daily court lists serve a particular purpose. As said above, they are part of Australia’s system of open justice. Daily court lists notify the public, including those summoned to appear before a court as well as interested observers, of the schedule of court hearings. In that sense they are transitory in nature even if it is possible to retrieve them from the internet after the day has passed or, as the Applicant has pointed out in the case of the WA Portal, may be searched for future listing. They nonetheless exist in the particular context for which they were created.
The nature and purpose of the CDA database is as the Respondent has pointed out the opposite of this. It transforms past listings into a database that is accessible indefinitely.[42] One of its stated purposes is ‘pre-screening’. At the hearing Counsel for the Respondent took me through several examples of how the CDA database proports to help businesses. One does not need to look at many of the examples to see how unfairness could result from making an assumption based on the fact that a person’s name appears in CDA’s database. For example, for employers it professes that the information is particularly relevant should that employee be given a position of trust.[43] It also states that police criminal histories are insufficient as they only show details of convictions not court attendances.[44] This suggests, as the Respondent’s claim, that users are encouraged to draw adverse inferences about a person from their name appearing in the CDA database. Although there is a note to warn users that because the CDA database does not show any form of identification care should be taken to establish correct identification, this does not discourage the drawing of inferences. It is not hard to see the risk to the Other Party’s future employment opportunities from her personal information being held in the CDA database indefinitely.
[42] Exhibit R2 T4, page 045.
[43] Exhibit R2 T6, page 495.
[44] Ibid.
In the hearing and in the Applicant’s reply submissions, the Applicant made the point that the Respondent is unable to differentiate between CDA drawing attention to how its database can be of relevance to certain groups such as employers and ‘with somehow suggesting that simply naming those groups and itemizing areas of relevance means they should draw a negative view of a name being in the database’. I find it is the wording on the website that makes it difficult to differentiate these things, for example:
‘The CDA database can be of significant assistance when evaluating persons for rental properties or short/long term boarding house situations’
‘Identifying someone’s court attendance can often be quite relevant to insurance claims’.
The Applicant seeks to compare CDA’s operations to to contend that there is no difference between courts supplying with information and CDA collecting the information from court websites. That may be so. However, as the Respondent points out does not do anything different to the publications made by the courts themselves.[45] Publication on the website does not change the context within which the information exists. The only claim that makes about the legal material on its website is to ‘improve access to justice through better access to information’.[46] further explains it is part of the system of open justice that courts and tribunals publicly report their reasons for judgements and is only one mechanism by which they can do so.[47] also provides a mechanism to have information removed from its site.[48]
[45] Exhibit R2 T6.
[46] About Who We Are & What We Do, accessed 27 May 2025.
[47] FAQ, Frequently Asked Questions, accessed 27 May 2025.
[48] Ibid.
The Applicant also directs the Tribunal to Clearview to argue that because the WA Portal has never contacted CDA about their Conditions of Use policy there is no breach of that policy as the Respondent has claimed.[49] In Clearview, DP O’Donovan also stated the fact that no legal action had been instituted to prevent Clearview’s conduct suggested there is nothing Clearview is doing which breaches the conditions of service. As the Respondent points out, the Applicant’s contention appears to miss the point that given the Conditions of Use a reasonable person would not expect their personal information to be collected from the WA Portal and used for a commercial purpose to draw adverse inferences about them.[50] Therefore, I find it is not necessary to determine whether or not those conditions have in fact been breached.
[49] Exhibit R2 T6, page 060.
[50] Exhibit R2 T4, page 044.
In my view, the posting of personal information on the public internet does not make that information a free for all and allow for it to be used in whatever way the collector chooses without regard to the knowledge and reasonable expectations of the person whose information it concerns. To conclude so would be to ignore that fair needs to be interpreted within the context and purpose of the provision in which it is found[51] and its interpretation guided by the circumstances of the case.
[51] White v Director of Public Prosecutions [2011] HCA 20; (2011) 243 CLR 478 at [12] (French CJ; Crennan and Bell JJ).
I am satisfied that a breach of APP 3.5 has been established as the collection of the Other Party’s personal information was not by fair means.
APP 5 – notification of the collection of personal information
APP 5.1 requires an APP entity at or before the time of collecting the personal information or, if that is not reasonably practicable, as soon as practicable after, to ‘take such steps as are reasonable in the circumstances’ (reasonable steps) to either notify an individual of certain matters in APP 5.2 (APP 5.2 matters) or ensure the individual is made aware of those matters.[52]
[52] APP 5.
Were reasonable steps taken to ensure awareness?
The issue is whether CDA took reasonable steps to ensure that the Other Party was aware of certain matters in APP 5.2 because it is appreciated that individual notification of APP 5.2 matters is not reasonable in the circumstances.[53] The Respondent submits that where individual notification is not practicable, that providing notification of APP 5.2 matters on CDA’s website to those individuals who check the website is consistent with APP 5.1.[54]
[53] Exhibit R2 T4, page 045.
[54] Ibid.
The Commissioner’s Determination was that the Applicant had made some of the APP 5.2 matters available on its website which means it would be reasonable to expect that steps could be taken to ensure full compliance with APP 5.2 by making the information on its website accurate and complete.[55]
[55] Ibid.
The Respondent now accepts that all relevant APP 5.2 matters are covered on CDA’s website and considers the Applicant to be compliant with APP 5.1.[56]
[56] Ibid, page 046.
The Applicant partially concedes this point while at the same time maintaining the view that the APP 5.2 matters were contained on the CDA website albeit in a range of locations and that they may not have used ‘the correct terminology in the correct locations on its website in the past’.[57]
[57] Exhibit 2, T6, page 063.
The evidence before the Tribunal of CDA’s website does not allow for a page-by-page comparison. However, there does appear to be a significant improvement in the Applicant’s privacy policy.
The fact that the Applicant has now taken such steps to comply fully with APP 5.1 shows that it was reasonable to take steps to ensure the Other Party was made aware of the APP 5.2 matters (by making the information available on its website) at or before the time of collecting the personal information or as soon as practicable after. Further, I consider that part of ensuring the individual is aware of those matters includes, as pointed out in the APP Guidelines, ensuring that the matters are expressed clearly and easily accessible.[58]
[58] Exhibit 3, page 0883.
I am satisfied that a breach of APP 5.1 has been established due to a failure to ensure that individuals were made aware of the relevant APP 5.2 matters at the time of the complaint.
APP10 – quality of personal information
AAP 10.1 requires an APP entity to take reasonable steps (if any) to ensure that personal information it collects is accurate, up-to-date and complete. AAP 10.2 requires an APP entity to ensure that the personal information it uses or discloses is, having regard to the purpose of the use or disclosure, accurate, up-to-date and complete.
Were reasonable steps taken to ensure the personal information CDA disclosed was accurate, up-to-date and complete having regard to the purposes of disclosure?
The issue is whether CDA took reasonable steps to ensure that the Other Party’s personal information it disclosed was accurate, up-to-date and complete having regard to the purpose for which CDA disclosed the Other Party’s personal information. It is not in dispute that the personal information was accurate, up-to-date and complete at the time of collection.
An example of a reasonable step in the APP Guidelines is providing individuals with a simple means to review and update their personal information.[59] An example in APP Guidelines of when it might be reasonable for an APP to take no steps is where the entity collects the information from a source known to be reliable such as the individual concerned.[60]
[59] Ibid, page 0946.
[60] Ibid.
It was the rejection of the request by the Other Party’s advocate to remove the Other Party’s personal information from CDA’s database because the charges against the Other Party had been dropped and therefore the information was no longer ‘accurate, up-to-date and complete’ that triggered the complaint to the Respondent.
The Respondent submits that the reasonable steps the Applicant is required to take is to correct or remove information where it becomes aware it is not accurate or complete.[61] The Respondent further submits it is reasonable in the circumstances that the information CDA discloses is accurate and complete given the intention and encouraged purposes of the disclosure is to permit certain inferences to be drawn.[62]
[61] Exhibit R2 T4, page 047.
[62] Ibid.
The Applicant submits that it was being requested to alter its records based on unverified information from an unverified source.[63] The Applicant also submits that the position it takes to verification is in ‘stark contrast’ to that of the Respondent who has insisted that the Other Party was in the best position to know the outcome of the relevant matters and that their say so should be sufficient.
[63] Ibid, page 064.
Due to its nature, at the time of the collection of the personal information from the daily courts list it is ‘accurate, up-to-date and complete’. However, due to a range of factors including, the dropping of charges or that a person may be found not guilty of a charge, it becomes inaccurate having regard to the circumstances in which the disclosure takes place – that is, to draw inferences about a person’s character which could be adverse. It is clear from CDA’s website that the purpose of the disclosure is not to merely indicate whether a person’s name has appeared on a daily court list. As stated above, I agree with the Respondent that the value proposition of CDA’s database is that it enables the drawing of adverse inferences.[64]
[64] Ibid, page 046.
Requiring CDA to check the outcome of every court listing to ensure the personal information it discloses is accurate is not practicable because in some cases contact details would be required in order to perform the task. It is also not reasonable because embarking on such a task would render its business model unworkable. It would as the Applicant contends be a failure to recognise the object of the Privacy Act that ‘the protection of the privacy of individuals is balanced with the interests of entities in carrying out their functions or activities’.[65] Having said this, this does not excuse the taking of no steps to ensure the accuracy etc. of the personal information it holds.
[65] Exhibit R2 T6, page 061.
The steps identified by the Information Commissioner are both reasonable and practicable taking into account the business activities of CDA. These include instituting a process by which a person may seek to have personal information removed or correcting and revising its website content to clearly articulate the limits and reliability of the personal information it holds. In this matter, the bar CDA set for the Other Party to be able to correct the personal information it holds and discloses about them was unreasonably and frustratingly high. It displays a belief that once CDA collected the personal information it then had complete control over that information and was the arbitrator of its correctness.
All records for the name of the Other Party have now been removed from the CDA database and were not on the database when the Commissioner’s Determination was made.
However, I am satisfied that a breach of APP 10 has been established due to the Applicant’s failure to ensure the personal information they disclosed was ‘accurate, up-to-date and complete’ at the time of the disclosure upon becoming aware that the information was not ‘accurate, up-to-date and complete’.
CONCLUSION
I have concluded that the mere publication of personal information on the public internet does not make that information free for anyone to take and use in any way they please without regard to the consequences for the person to whom the personal information pertains. To conclude otherwise, in the context of contemporary information collection methods, would render the Privacy Act ineffective in protecting the reasonable expectations people have about how their personal information that appears on the internet will be collected, disclosed and used. Although I have found that the Applicant has breached APP 3.5, this does not mean that there are not fair means available to the Applicant to collect personal information from daily court lists. The Applicant has already implemented measures to comply with APP 5.1 and APP 10 to enhance awareness and ensure the accuracy of the personal information it discloses. While these measures also assist with complying with APP 3.5, there are other reasonable steps available to the Applicant to protect the privacy of individuals. Most notably to change the way it promotes the use of the CDA database to manage the risk of adverse inferences being drawn by its users.
Date(s) of hearing: 25 March 2025 Applicant: In person Counsel for the Respondent: Samuel Walpole Solicitors for the Respondent: Australian Government Solicitor
Exhibit R1 – T documents
Exhibit R2 – Application Book
Exhibit R3 – Book of authorities
- AGLC
- Court Data Australia and Office of the Australian Information Commissioner [2025] ARTA 876
- Case
- [2025] ARTA 876
- Decision Date
CaseChat Overview and Summary
The primary legal issues before the court were whether CDA's collection of personal information from court lists was by lawful and fair means, whether reasonable steps were taken to ensure that the personal information was accurate and up-to-date, and whether individuals were adequately notified about the collection and use of their personal information. The court had to consider the nature of the information collected, the manner in which it was collected, and the measures taken by CDA to ensure compliance with the Privacy Act. CDA argued that the collection was lawful and fair because the information was publicly available and the public reasonably expected such information to be collected and used for research purposes. However, the OAIC contended that the collection was not fair as it was done without the knowledge or reasonable expectation of the individuals involved.
The court found that while CDA had implemented measures to comply with some of the APPs, it had breached APP 3.5, 5.1, and 10.2 by collecting personal information in a way that was not fair and by failing to ensure that the information was accurate, up-to-date, and complete. The court concluded that simply publishing personal information on the internet does not justify its collection and use without regard for the privacy rights of individuals. The court also noted that although CDA had taken steps to enhance awareness and ensure accuracy, there were additional measures that could be taken to protect the privacy of individuals, such as changing the way it promotes its database to mitigate the risk of adverse inferences being drawn by users. Consequently, the court established that a breach of APP 10 had been confirmed due to CDA’s failure to ensure the accuracy of the personal information disclosed.
In summary, the court ruled that CDA had breached several APPs by not collecting personal information by lawful and fair means, failing to ensure the accuracy of the information, and not taking reasonable steps to notify individuals about the collection and use of their personal information. The court's decision underscores the importance of balancing privacy rights with the legitimate needs of entities in collecting and using personal information.
Orders
Orders of the court
Full text does not contain this section.
Background
Background to the litigation
Full text does not contain this section.
Evidence
Evidence Before The Court
Full text does not contain this section.
Decision
Reasons for decision
Ratio Decidendi
Legal Principle Established
There is no dispute that the Applicant collects information from court lists which is personal information within the meaning of the Privacy Act. CONSIDERATION APP 3.5 – collection by lawful and fair means Parties’ submissions APP 3.5 requires an APP entity to collect personal information only by lawful and fair means. The issue is whether the collection of the Other Party’s personal information was by fair means. The Commissioner’s Determination was that the Respondent breached APP 3.5 because the Other Party’s information was collected in a way that was not fair as it was collected contrary to the Portal’s Conditions of Use, and in circumstances where the Other Party was not aware of the collection and could not reasonably have expected the Respondent to collect their personal information.[16] [16] Ibid. The Applicant submits, using as an example, that it is quite well understood by the public that anything that is legally published online can be and is often republished or reproduced somewhere else.[17][17] Exhibit R2 T2, page 014. The Applicant also submits that there is no evidence that the collection of the Other Party’s personal information was contrary to the WA Portal’s condition of use.[18] The Applicant further submits there has been no copyright breach because copyright protects creative or artistic endeavour or expression which does not form part of the information that CDA extracts from the WA Portal and in any event WA courts have not asserted or concluded that the conditions of the WA Portal have been breached.[19] In his reply submissions the Applicant also submits that CDA prominently describes ‘research purposes’ on its website and reiterated that the material used by CDA is not something that can be the subject of copyright.[20] [18] Ibid.[19] Ibid. [20] Exhibit R2 T6, page 060. The Applicant submits that these factors combined mean that it is more than reasonable for a person who has been scheduled to appear before an Australian court to expect that their name to be on the CDA database.[21] To illustrate this point the Applicant submits that the very fact that the Other Party searched their name means that they had a reasonable expectation it would appear on the CDA database.[22] The Applicant also submits that CDA has always gone to a great deal of effort to ‘specifically encourage its users to not draw any adverse inferences from the fact a name is in the CDA database’.[23] The example the Applicant provided was that CDA makes it clear on its website that the database only contains matters scheduled to be heard before a court and not court outcomes.[24][21] Ibid. [22] Exhibit R2 T4, page 015.[23] Exhibit R2 T6, page 060.[24] Ibid. In relation to the temporary nature of published daily court lists, the Applicant submits that the WA Portal also has a future court listing search facility that can include matters to be heard in the future.[25] [25] Ibid. The Applicant further submits that the Respondent has failed to take into account the object of the Privacy Act which provides that the protection of the privacy of individuals is balanced with the interests of entities in carrying out their functions and activities.[26][26] Exhibit R2 T6, page 061.