EXPLANATORY MEMORANDUM
DATA - MATCHING GUIDELINES - issued under Section 12 of the DATA - MATCHING PROGRAM (ASSISTANCE and TAX) ACT 1990.
Introduction
Section 12 of the Data-matching Program (Assistance and Tax) Act 1990 (the Act) requires the matching agency and source agencies to comply with guidelines the Privacy Commissioner may issue from time to time to replace any existing guidelines.
The objective of the guidelines is to ensure that the use of the privacy-intrusive technique of data-matching is based on clear and publicly known standards, and that individuals are protected by appropriate safeguards in the design and implementation of the data-matching program.
The guidelines provide for monitoring of technical standards for data-matching programs by the Privacy Commissioner and for safeguards for individuals affected by the outcomes of data-matching. So far, monitoring by the Privacy Commissioner and an audit by the Auditor-General has indicated that agencies have complied with the privacy provisions of the Act and Guidelines.
These guidelines apply only to data-matching carried out under the Data-matching Program ("Assistance and Tax) Act 1990.
Definitions
Guideline 2 provides that definitions contained in the Act apply. Where a term is not defined in the Act but is defined in the Privacy Act, that definition applies. Terms not defined in either of these Acts are defined in the guidelines. Definitions that have been modified or added include "action", "dispute" and "matches undertaken".
"Action" limits the range of administrative actions an agency my take to those defined in section 10 of the Act.
"Dispute" would mean the situation where an individual disputes the accuracy of the data on which a match is based and will not retract.
"Matches Undertaken" would mean the total number of individual records the matching agency receives after they have been separated into maiden names, aliases, partners, children and parents. The figures for the matches undertaken will be greater than the number of client records an agency keeps. Because "matches undertaken" includes maiden names and aliases the total matches undertaken will be greater than the total number of records kept on individuals.
Safeguards for Individuals
Guidelines 5-7 lay down a series of requirements designed to minimise the possibility of unfairness to individuals in the use of results of data-matching programs.
The modifications have been made to 5.3, 5.5, 5.6, 6.1, 6.3 and 6.5 (iv).
Guideline 5.3 has been modified to remove the phrase "or the proposed action". If an individual disputes the accuracy of the data which forms the basis of a match, and the agency does not concede, it must inform the individual of the rights of complaint conferred by the Privacy Act 1988. This is consistent with Information Privacy Principle 8 of the Privacy Act. Any action the agency proposed to take has to be consistent with action allowed by section 10 and it is unlikely that such action would result in a breach of privacy.
Guideline 5.5 reinforces the requirement to retain a written note on or linked to a client's file if a client responds orally to a notice issued by an agency under section 11 of the Act.
Guideline 5.6 is a new requirement to help ensure individuals are afforded the opportunity to respond to notices issued under section 11.
The modification to guideline 6.1 is of a technical nature to ensure that files from the Health Insurance Commission and the Australian Electoral Commission used to verify identities do not have to be destroyed.
Guideline 6.3 authorises the practice of referring discrepancies from one source agency to another for further investigation.
Guideline 6.5(iv) allows the ATO to retain data on discrepancies until the taxpayer's appeal period had expired. Representatives from the ATO expressed difficulty in complying with the prior requirement to destroy data before an individual's appeal period under the Income Tax Assessment Act had expired.
Guideline 9 outlines the matters on which agencies may be required to report to the Privacy Commissioner on a periodic basis.
Guideline 12 outlines the matters on which agencies must include in their reports to both Houses of Parliament. The changes modify the statistics which agencies should maintain and report. The main change is hi the way agencies report on debts collected. They are now required to identify:
the number of cases where an overpayment was identified; the number of cases where recovery action was initiated; and the number of cases where debt was fully recovered.
Overview
The Data-Matching Program (Assistance and Tax) Act 1990 was enacted to address the need for a structured and privacy-compliant framework for the use of data-matching techniques by government agencies, particularly in the context of assistance and tax programs. This Act was introduced by the Parliament of Australia to provide a legal basis for the use of data-matching while ensuring that the privacy rights of individuals are protected. The primary policy objective of the Act is to facilitate the efficient administration of assistance and tax programs by enabling agencies to identify discrepancies and potential fraud through data-matching, while simultaneously enforcing strict privacy safeguards. These safeguards are further detailed in guidelines issued by the Privacy Commissioner to ensure compliance with privacy standards and to provide transparency and accountability in the use of data-matching programs.
Scope and Application
The Data-Matching Guidelines issued under Section 12 of the Data-Matching Program (Assistance and Tax) Act 1990 apply to all data-matching activities conducted under the Act, involving both the matching agency and source agencies. These guidelines serve to ensure that the data-matching processes, which inherently involve privacy-intrusive activities, are conducted in accordance with established standards and safeguards to protect individuals' privacy. They apply specifically to the data-matching activities conducted under this Act, which primarily concerns the matching of data between various government agencies to assist in the provision of assistance and tax-related services. The guidelines encompass the definitions relevant to the Act and the Privacy Act, with any undefined terms being clarified within the guidelines themselves. Notably, the guidelines have been updated to address various aspects of data-matching activities, including the handling of disputes regarding data accuracy, the retention of client information, and the reporting requirements for agencies to both the Privacy Commissioner and Parliament.
Key Provisions
The Data-Matching Program (Assistance and Tax) Act 1990 is administered through a set of guidelines issued by the Privacy Commissioner. Section 12 of the Act mandates compliance with these guidelines by matching agencies and source agencies, aiming to ensure that data-matching is conducted under clear standards and with appropriate safeguards to protect individuals. These guidelines are crucial for maintaining the integrity and fairness of the data-matching process. They establish the framework within which agencies must operate to avoid privacy breaches and ensure that individuals have the opportunity to contest the accuracy of data used against them.
The guidelines impose several obligations on the agencies involved. For instance, agencies must comply with the technical standards set forth in the guidelines to ensure the effectiveness and accuracy of data-matching programs. Additionally, they must implement safeguards to protect individuals from potential unfairness arising from the outcomes of data-matching. These safeguards include informing individuals of their rights under the Privacy Act if they dispute the accuracy of data used in a match and ensuring that any action proposed by the agency does not breach privacy principles. Agencies are also required to maintain records and reports as outlined in the guidelines, such as noting client responses to notices issued under section 11 of the Act and reporting specific statistics to the Privacy Commissioner and Parliament.
Failure to adhere to the guidelines can result in significant consequences. Although the document does not explicitly state penalties for non-compliance, breaches of the Privacy Act or the guidelines can lead to civil or criminal penalties. For instance, under the Privacy Act, individuals can seek remedies for breaches, including compensation. Additionally, agencies may face scrutiny and potential sanctions for not adhering to the required safeguards and reporting obligations. The seriousness of these consequences underscores the importance of strict compliance with the guidelines to maintain the trust and privacy of individuals participating in the data-matching program.
In summary, the Data-Matching Program (Assistance and Tax) Act 1990, through its guidelines, establishes a robust framework for data-matching activities that balances the need for effective program administration with the protection of individual privacy rights. Agencies are required to follow specific protocols and safeguards to ensure fairness and accuracy in their operations. Non-compliance with these guidelines can result in serious repercussions, highlighting the critical nature of adhering to the established standards.