EXPLANATORY STATEMENT
My Health Records Act 2012
My Health Records (Information Commissioner Enforcement Powers) Guidelines 2026
Purpose and authority
The My Health Records Act 2012 (My Health Records Act) establishes the My Health Record system. The Australian Information Commissioner (Information Commissioner) is the independent regulator of the privacy aspects of the My Health Record system. The Information Commissioner has various complaints handling, investigations and enforcement functions in respect of the My Health Record system, under both the My Health Records Act and the Privacy Act 1988 (Privacy Act).
The Information Commissioner has made the My Health Records (Information Commissioner Enforcement Powers) Guidelines 2026 (Guidelines) under subsection 111(2) of the My Health Records Act. Subsection 111(2) provides that the Information Commissioner must, by legislative instrument, make enforcement guidelines outlining how the Information Commissioner will exercise their enforcement powers conferred on the Information Commissioner under the My Health Records Act or a related power conferred on the Commissioner by another Act. The Information Commissioner must have regard to the Guidelines in exercising his or her enforcement powers in relation to the My Health Record system (subsection 111(1)).
These Guidelines replace the My Health Records (Information Commissioner Enforcement Powers) Guidelines 2016 (the previous Guidelines). They reflect legislative updates the Parliament made to the Privacy Act and My Health Records Act since the previous Guidelines were made.
These Guidelines outline the Information Commissioner's approach to handling complaints, investigations, and enforcement in respect of the My Health Record system under the Privacy Act and My Health Records Act. They summarise existing law and do not create new rights, obligations or penalties. They are not a restatement of all the privacy obligations that participants in the My Health Record system have. The Guidelines should be read alongside other laws and regulations relevant to an entity’s participation in the My Health Record System.
Consistent with modern regulatory practices these Guidelines have been streamlined, and the language simplified, to improve accessibility, reduce duplication, and facilitate regulatory compliance to enhance the privacy of Australians. These changes aim to support the integrity of, and growing participation in, the My Health Record system among consumers and healthcare providers. This will also support transparency around the Information Commissioner’s oversight approach in respect of the My Health Record system more effectively.
These Guidelines are informed by the Office of the Australian Information Commissioner’s (OAIC) Statement of Regulatory Approach, and draw upon published policies and guidance that are relevant to the exercise of functions under both the Privacy Act and the My Health Records Act.[1] Specifically, they note that the Commissioner will have regard to additional regulatory policies that are publicly available to the regulated community on the website of the Commissioner’s office.[2] These policies are reviewed and revised from time to time to ensure they are fit for purpose and meet community expectations. These guidelines also note that the Information Commissioner will have regard to internal operational processes.
Background
The My Health Record system aims to enable the secure sharing of health information between a healthcare recipient’s registered healthcare provider organisations, while enabling the healthcare recipient to control who can access their My Health Record. A healthcare recipient’s My Health Record provides a summary of his or her health information, which is held by the National Repositories Service as well as registered repository operators. Registered repositories may be operated by either private or public sector bodies that must register with the System Operator and comply with any My Health Record Rules that apply to their registration.
The My Health Records Act establishes and regulates the My Health Record system including establishing certain privacy protections. It prescribes the circumstances in which entities can collect, use and disclose health information included in a healthcare recipient’s My Health Record. It also allows for the Information Commissioner to seek a range of remedies, including civil penalties, where there is an unauthorised collection, use or disclosure of health information included in a healthcare recipient’s My Health Record, or where certain actions, events or circumstances occur that might compromise the security or integrity of the My Health Record system.
The Information Commissioner has complaints handling, investigative and enforcement powers and functions under both the My Health Records Act and the Privacy Act. Conduct that breaches the My Health Records Act may also concurrently be a contravention of the Privacy Act. In these cases, the Information Commissioner may investigate the matter under the Privacy Act and exercise regulatory powers and seek remedies under that Act. These Guidelines set out the Commissioner’s general approach to the exercise of investigative and enforcement powers and functions under both Acts in relation to the My Health Record system.
Commencement date
These Guidelines are a legislative instrument for the purposes of the Legislation Act 2003 (Legislation Act). This instrument commences on the day after it is registered on the Federal Register of Legislation.
Notes on the Guidelines can be found at Attachment A.
The Guidelines do not incorporate documents by reference. Instead, the Guidelines only note that the Information Commissioner may have regard to external policies and guidance published on their office’s website. The contents of these external materials are not legally binding and only serve to inform or guide the Information Commissioner’s discretion when exercising their regulatory powers and functions in respect of the My Health Records system.
Consultation
Before the Guidelines were made, the Information Commissioner was satisfied that consultation was undertaken to the extent appropriate and reasonably practicable, in accordance with section 17 of the Legislation Act. The OAIC took the following steps to consult with stakeholders:
On 27 January 2026 the OAIC posted on its website a draft of the Guidelines together with a Consultation Paper summarising the key proposed changes to the Guidelines.[3] The OAIC invited public comment in the form of submissions. The period allowed for public consultation was three weeks. The closing date for submissions was 17 February 2026.
The OAIC emailed relevant government entities, peak and professional bodies and health consumer groups about the public consultation. 35 organisations were invited to provide a submission.
Ten submissions were received as a result of the public consultation, and these will be published on the OAIC’s website. Four of these submitters were granted an extension of time in which to provide a submission and those final submissions were received on 20 February 2026.
The OAIC also engaged with the Attorney-General’s Department and the Department of Health, Disability and Ageing through officer-level feedback.
The OAIC made variations to the draft Guidelines as a result of the consultation process. Common matters raised by stakeholders that were not suitable to address in the Guidelines themselves are dealt with below.
Key feedback from consultation submissions
The consultation submissions generally welcomed the substantive changes made and noted that the updated Guidelines are more clear, accessible and readable than the previous Guidelines. However, stakeholders observed that the Guidelines remain regulatory in language. They emphasised the need for consumer-facing and clinician-facing resources to complement the Guidelines and improve its practical utility.
Submissions highlighted the importance of having plain language resources that explain the OAIC’s graduated complaints pathway in light of new powers (e.g. infringement and compliance notices, investigation and monitoring warrants) and enforcement considerations when responding to alleged privacy breaches, including through illustrations of how the Guidelines might apply in common operational scenarios. One submission emphasised the importance of working with the Australian Digital Health Agency to ensure the content of the Guidelines are incorporated into existing My Health Record resources related to privacy and security.
The OAIC recognises growing community expectations for widely accessible and clear guidance, which plays a key role in developing practical education and guidance materials to support compliance by regulated entities participating in the My Health Record System and empowering individual health consumers in exercising their privacy rights. Following the registration and publication of the updated Guidelines, the OAIC as part of its regular reviews will consider any updates required to existing education and guidance materials arising from the consultation and consider producing new materials where required. Some examples of past relevant materials, including those that the OAIC has produced, reviewed or contributed to for the My Health Record system include:
Consumer-facing materials such as About My Health Record[4], Privacy and the My Health Record system[5] and Make a My Health Record complaint[6]
Practitioner-facing materials such as My Health Record for healthcare providers[7] and My Health Record Training Checklist (security, privacy and access eLearning module for healthcare providers)[8]
Regulatory guidance such as the Guide to mandatory data breach notification in the My Health Record system[9] and Security and Access policies – Rule 42 guidance[10]
Various submissions sought further clarity and specific detail to address the operational complexities and nuances of clinical workflows. The purpose of the Guidelines is to articulate the general approach taken by the Information Commissioner to enforcement action. This is because any enforcement action will be assessed on a case-by-case basis through applying the Guidelines to individual circumstances. The Guidelines are not a suitable platform to provide exhaustive detail of the application of legislation or definitive answers on how the Information Commissioner may respond to an alleged breach of the Privacy Act and My Health Records Act. Instead, some of these considerations could be addressed in practical materials. Representative examples of what submissions sought further clarity on that could be addressed in future materials include:
Whether system design factors and cyber security failures (e.g. software configuration errors, poor user interface design, inadequate credential management controls) are considered when enforcement decisions are made
What factors might affect the proportionality of enforcement action (e.g. patient safety, continuity of care, practical implementation and clinical workflow realities, entities being small and resource-limited)
How compliance notices interact with mandatory data breach notifications and when they might escalate to civil penalties
What types of factors might contribute to consideration of monitoring and/or investigation warrants, and what safeguards are in place to protect unrelated clinical records when they are used
How state and territory laws interact with federal laws for the purposes of how complaints are handled
Statement of compatibility with human rights
Subsection 9(1) of the Human Rights (Parliamentary Scrutiny) Act 2011 requires the rule-maker for a legislative instrument to which section 42 (disallowance) of the Legislation Act applies to cause a statement of compatibility with human rights to be prepared in respect of that legislative instrument. A statement of compatibility set out in Attachment B has been prepared.
Attachment A
Notes to the My Health Records (Information Commissioner Enforcement Powers) Guidelines 2026
Part 1 Preliminary
Section 1 Name of instrument
Section 1 provides that this instrument is the My Health Records (Information Commissioner Enforcement Powers) Guidelines 2026 (the Guidelines).
Section 2 Commencement
Section 2 provides that the Guidelines commence on the day after the instrument is registered on the Federal Register of Legislation. From the date of commencement, the Information Commissioner will have regard to the Guidelines when exercising relevant enforcement and investigative powers in respect of the My Health Record system. It also states that the My Health Records (Information Commissioner Enforcement Powers) Guidelines 2016 are repealed when these Guidelines commence.
Section 3 Definitions
Section 3 defines terms used in the Guidelines. It also clarifies that, unless the contrary intention appears, terms used in the Guidelines have the same meaning as in the My Health Records Act 2012 (My Health Records Act).
Section 4 Introduction
This section deals with a number of introductory matters including by providing a brief description of the My Health Record system and the role of the Information Commissioner and the Guidelines in that context.
Sections 4.1 and 4.2 explain that the Information Commissioner is a statutory office holder appointed under subsection 14(1) of the Australian Information Commissioner Act 2010 (AIC Act). The Information Commissioner performs functions and exercises powers conferred on the position by the AIC Act and other Acts. Among other things, this includes performing functions and exercising powers in relation to the My Health Record system.
Section 4.3 explains that the My Health Record system is established under and regulated by the My Health Records Act. The My Health Record system aims to enable the secure sharing of health information between a healthcare recipient’s registered healthcare provider organisations, while enabling the healthcare recipient to control who can access his or her My Health Record. It explains that the My Health Records Act establishes the role and function of the System Operator, a registration framework for recipients and participants in the My Health Records system, and a privacy framework.
Section 4.4 explains that the System Operator is responsible for the operation of the My Health Record system. This includes, but is not limited to:
the operation of the National Repositories Service that stores key records (e.g. discharge summaries, event summaries and healthcare recipient entered information) that form part of a registered healthcare recipient’s My Health Record;
the establishment and maintenance of an index services that allows information in different repositories to be connected to registered healthcare recipients, and facilitates the retrieval of such information when required; and
the establishment and maintenance of access control mechanisms.
Section 4.5 states that the collection, use and disclosure of health information included in a healthcare recipient’s My Health Record is regulated by the My Health Records Act and regulations and rules made under that Act. It also states that these legislative instruments regulate an entity’s participation in the My Health Record system through other obligations.
Sections 4.6 and 4.7 clarify that, in addition to the requirements of the My Health Records Act, participants in the My Health Record system are subject to the Privacy Act 1988 (the Privacy Act) and relevant State and Territory privacy laws.
Section 4.8 describes the core functions of the Information Commissioner in relation to the My Health Record system. These are not an exhaustive list of powers and focus on those most relevant powers to the Commissioner’s oversight role in the My Health Record system which include:
investigating an act or practice that may be an interference with the privacy of a healthcare recipient under subsection 73(1) of the My Health Records Act, and seeking to address contraventions as appropriate through conciliation, education and enforcement action;
to do anything incidental or conducive to the performance of those functions; and
functions under the Privacy Act.
Section 4.9 states that under section 111 of the My Health Records Act the Information Commissioner must formulate, and have regard to, guidelines regarding the exercise of the Information Commissioner's powers under the My Health Records Act or a power under another Act related to such a power, such as the Privacy Act.
Section 4.10 makes it clear that, despite the general approach provided in the Guidelines, the Information Commissioner maintains a discretion to exercise the available powers that he or she considers the most appropriate in the particular circumstances of each case.
Section 4.11 notes that the scope of the Guidelines is to outline the Information Commissioner’s approach to handling complaints, investigations, and enforcement in respect of the My Health Record System. It emphasises that the Guidelines are not a restatement of all the privacy obligations that participants in the My Health Record system have, and that the Guidelines should be read alongside other laws and regulations relevant to an entity’s participation in the My Health Record system.
Part 2 General principles relating to complaints handling, the exercise of investigative powers, and enforcement action
Section 5 Types of investigative and enforcement powers available to the Information Commissioner
Section 5 outlines the broad categories of investigative and enforcement powers available to the Information Commissioner and the legislative basis for these powers. These powers include administrative actions, civil litigation and referrals to other bodies, including to law enforcement for serious matters.
Section 5.1 explains that there are relevant enforcement and investigative powers available to the Information Commissioner under both the My Health Records Act and the Privacy Act in relation to the My Health Record System, and reflects the broader regulatory environment in which the Information Commissioner operates. It also notes the information sharing powers of the Information Commissioner in exercising the powers outlined in Section 5.
General approach to complaints
Section 5.2 states that Australian Privacy Principle (APP) 1 outlines the requirements for an APP entity to manage personal information in an open and transparent way, and imposes obligations upon an APP entity to take reasonable steps to implement practices, procedures and systems that will ensure the entity complies with the APPs and is able to deal with related inquiries and complaints (APP 1.2).
Section 5.3 sets out the Information Commissioner’s general approach to complaints relating to the My Health Record system. A complaint will generally be treated as a complaint made under section 36 of the Privacy Act, unless there is a reason to accept the complaint and act under the My Health Records Act.
Section 5.4 explains that the Information Commissioner may seek efficient and early dispute resolution by requesting that the complainant lodge their complaint with the participant in the My Health Record system, and requesting that the participant take reasonable steps to resolve the complaint.
Section 5.5 clarifies that in the event that early resolution or conciliation is not possible, or if it is not reasonable for an individual to lodge a complaint with the participant in the My Health Record system, the Information Commissioner may decide to investigate the complaint and may decide to take enforcement action under the My Health Records Act or the Privacy Act.
Investigative powers
Section 5.6 states that the Information Commissioner has power under subsection 73(4) of the My Health Records Act to do all things necessary or convenient to investigate an alleged contravention of the My Health Records Act in relation to the My Health Record system, either in connection with health information in a healthcare recipient’s My Health Record or as a result of a breach of a civil penalty provision.
Section 5.7 clarifies that because a contravention of the My Health Records Act in connection with health information included in a healthcare recipient’s My Health Record or a provision of Part 4 or 5 is an interference with privacy for the purposes of the Privacy Act, the Information Commissioner may investigate the act or practice under the Privacy Act.
Section 5.8 clarifies that Part V of the Privacy Act sets out the investigative powers and processes available when the Information Commissioner conducts an investigation under the Privacy Act into an alleged interference with privacy.
Section 5.9 outlines a range of powers available to the Information Commissioner under Part V of the Privacy Act in relation to the conduct of investigations.
Section 5.10 states that the Information Commissioner also has entry, search and seizure powers when investigating an offence provision or civil penalty provision in the Privacy Act, or a civil penalty provision enforceable by the Commissioner under the My Health Records Act. This section also notes that these powers are contained in Part VIB of the Privacy Act, and outlines the conditions placed upon the Information Commissioner in exercising these powers.
Enforcement powers
Section 5.11 notes that the Information Commissioner has enforcement powers under the My Health Records Act and Privacy Act, which are enforceable under specified parts of the Regulatory Powers (Standard Provisions) Act 2014 (Regulatory Powers Act). These powers are outlined in this section, along with references to sections contained in Part 3 with further information about these powers.
Section 5.12 clarifies that the Information Commissioner may refer matters to other bodies, including law enforcement bodies. The section also references a section in Part 3 with further information about referrals.
Section 6 Consistent regulatory approach
This section sets out the general principles that the Information Commissioner will apply when investigating an alleged contravention to promote a consistent regulatory approach.
Section 6.1 states that there are discretionary factors that the Information Commissioner will generally consider in the exercise of his or her enforcement powers in accordance with the My Health Records Act, Privacy Act and other relevant legislation. Consideration will be given to relevant policies set out by the Information Commissioner’s office.[11] Consideration will also be given to factors (e.g. risk, proportionality and the public interest) outlined in relevant published regulatory policies.[12]
Section 6.1 also includes a note that the Information Commissioner will act consistently with general principles of good decision making, which may involve having regard to the Best Practice Guides published by the Administrative Review Council, and that the Information Commissioner will act fairly, transparently, and in accordance with principles of natural justice (or procedural fairness).
General approach to Commissioner initiated investigations
Sections 6.2 to 6.4 describe the Information Commissioner’s approach to Commissioner initiated investigations, which may be undertaken following a complaint or data breach notification or independently of any complaint or notification. Such investigations will be conducted under Part V of the Privacy Act, unless there is a reason to conduct the investigation under the My Health Records Act. Following an investigation, enforcement action may be taken under either the Privacy Act or the My Health Records Act.
Under subsection 33E of the Privacy Act, the Information Commissioner has the power to conduct public inquiries into specified matters relating to privacy as directed by or subject to Ministerial approval. To avoid doubt, a public inquiry into a specified matter or specified matters relating to privacy that concern the My Health Record system at the direction or approval of the Minister is not an investigation under section 40 of the Privacy Act nor a preliminary inquiry to determine whether to open an investigation under section 42 of the Privacy Act.
General approach to conducting investigations under section 73 of the My Health Records Act
Sections 6.5 and 6.6 set out the Information Commissioner’s general approach to conducting investigations under section 73 of the My Health Records Act. Section 6.5 states that the process will follow, as far as practicable, the investigative processes established in Part V of the Privacy Act.
Section 6.6 states that, following an investigation under section 73, the Information Commissioner may take enforcement action under the My Health Records Act. Section 6.6 also notes that the Commissioner may consider the suitability of attempting by conciliation to effect the settlement of a matter before deciding to take enforcement action.
Section 7 Enforcement action – general principles
Section 7.1 outlines the factors the Information Commissioner may consider in deciding whether to take enforcement action in relation to the My Health Record system and what action to take. Enforcement action may be directed towards healthcare provider organisations or individual healthcare professionals. This section highlights the Information Commissioner’s discretion in how they apply enforcement powers within the prescriptions set out in the My Health Records Act and Privacy Act. The prescriptions of each Act define what conduct may be subject to enforcement action and set the parameters of what regulatory responses can be pursued under each Act and when they are read together in their current form. Under the present form of the Privacy Act and My Health Records Act, this means:
Any enforcement action taken under the Privacy Act must be done according to the prescription of the Privacy Act rather than the My Health Records Act (and vice-versa). This applies when conduct that breaches the My Health Records Act is also a breach of the Privacy Act and that conduct is subject to enforcement action under the Privacy Act.
Civil penalties, enforceable undertakings and injunctions under an Act can only be pursued in respect of conduct regulated under that Act.
Compliance and infringement notices can only be issued under the Privacy Act for conduct regulated under that Act. The Information Commissioner is currently not empowered to issue these notices for conduct regulated under the My Health Records Act.
Determinations can only be made by the Information Commissioner under the Privacy Act for conduct regulated under that Act. Determinations are currently not a power conferred under the My Health Records Act.
Section 7.1 also notes that in applying these powers, the Information Commissioner may take into account relevant policies on regulatory action set out by his or her office, as updated from time to time.[13]
Section 7.2 states it is open to the Information Commissioner to use a combination of enforcement powers to address a particular contravention.
Administrative action of the System Operator
Section 7.3 explains that section 73A of the My Health Records Act authorises the Information Commissioner to disclose to the System Operator any information or documents that relate to an investigation that the Information Commissioner conducts because of the operation of section 73 of that Act, if the Information Commissioner is satisfied that to do so will enable the System Operator to monitor or improve the operation or security of the My Health Record system.
Section 7.4 states that disclosure under section 73A of the My Health Records Act may also assist the System Operator in exercising the power to cancel, suspend or vary an entity’s registration with the My Health Record system in certain circumstances in accordance with the My Health Records Act.
General litigation principle
Section 7.5 outlines the general litigation principle that the Information Commissioner act in accordance with the Commonwealth’s model litigant obligations within the meaning under Division 2 of the Legal Services Directions 2025.
Publication of use of enforcement powers
Sections 7.6 and 7.7 discuss the Information Commissioner’s publication of his or her use of enforcement powers. They explain that the Information Commissioner may communicate publicly about the use of enforcement powers and will generally publish enforceable undertakings. Exceptions to this may apply when a matter is referred to a law enforcement body (e.g. the Commonwealth Director of Public Prosecutions) for criminal investigation, or is otherwise prohibited by law.
Part 3 Use of enforcement powers
Part 3 of the Guidelines explains, in more detail, the range of enforcement mechanisms available to the Information Commissioner under the My Health Records Act and the Privacy Act.
Section 8 Enforceable undertakings
This section outlines the Information Commissioner’s general approach to enforceable undertakings relating to the My Health Record system.
Section 8.1 explains that under section 80 of the My Health Records Act the Information Commissioner is an authorised person that may accept a written undertaking by an entity, in relation to the My Health Records Act, given by a person that the person will comply with the My Health Records Act or to avoid contravening the My Health Records Act.
Section 8.2 states that under section 80V of the Privacy Act, the Information Commissioner is an authorised person that may accept a written undertaking given by an entity to comply with the Privacy Act or avoid contravening the Privacy Act.
Section 8.3 clarifies that both section 80 of the My Health Records Act and section 80V of the Privacy Act are enforceable under the provisions of Part 6 of the Regulatory Powers Act which deals with the acceptance and enforcement of undertakings relating to compliance with legislative provisions. Section 8.4 adds that the individual giving and executing the undertaking must have the authority to negotiate on behalf of, and bind, the respondent person.
Section 8.5 states that there is no particular structure an enforceable undertaking must take, but that it must be written and must be expressed to be an undertaking under s 114 of the Regulatory Powers Act.
Section 9 Determinations
This section outlines the Information Commissioner’s general approach to determinations relating to the My Health Record system.
Section 9.1 states that after investigating a complaint under section 36 of the Privacy Act, the Information Commissioner may make a determination under section 52 of the Privacy Act which dismisses the complaint or finds that the complaint is substantiated.
Section 9.2 clarifies that the Information Commissioner can also make a determination after conducting an investigation on his or her own initiative.
Section 9.3 explains that under Part V of the Privacy Act, the Information Commissioner may apply to a Court for an order to enforce a determination against a person or an entity, or against an agency.
Section 9.4 explains that following an investigation of a complaint or an investigation on the Commissioner’s own initiative, the Information Commissioner has a discretion to make a determination within the prescriptions set out in the Privacy Act.
Section 9.5 states that where a respondent has failed to comply with the terms of a determination made under section 52 of the Privacy Act, the Information Commissioner will consider whether to commence proceedings in a Court to enforce the determination.
Section 9.6 outlines considerations that the Information Commissioner may take into account when deciding whether to commence proceedings to enforce a determination.
Section 10 Injunctions
This section outlines the Information Commissioner’s general approach to injunctions relating to the My Health Record system. An injunction requires a person to do, or restrains a person from doing, specified actions.
Sections 10.1 and 10.2 states that under section 81 of the My Health Records Act and section 80W of the Privacy Act, the Information Commissioner may apply to a Court for an injunction. Both sections are enforceable under provisions of Part 7 of the Regulatory Powers Act.
Section 10.3 outlines considerations that the Information Commissioner may take into account when deciding whether to seek an injunction.
Section 11 Civil penalties
This section outlines the Information Commissioner’s general approach to civil penalties relating to the My Health Record system.
Section 11.1 states that civil penalty provisions in the My Health Records Act that are within the remit of the Information Commissioner (as opposed to the Secretary of the Department of Health) are provided in section 79 of the My Health Records Act. The Information Commissioner must make the application within four years of the alleged contravention.
Section 11.2 clarifies that section 79 of the My Health Records Act and section 80U of the Privacy Act are enforceable under the provisions of Part 4 of the Regulatory Powers Act which deals with seeking and obtaining a civil penalty order for contraventions of civil penalty provisions.
Section 11.3 states that a contravention of the My Health Records Act in connection with health information included in a healthcare recipient’s My Health Record or a provision of Part 4 or 5 is an interference with privacy for the purposes of the Privacy Act. Sections 13G and 13H of the Privacy Act, relating to serious interferences with privacy and interferences with privacy respectively, are civil penalty provisions.
Section 11.4 clarifies that, as such, particular conduct may contravene both a civil penalty provision in the My Health Records Act and the ‘serious interference with privacy’ or ‘interference with privacy’ civil penalty provisions in the Privacy Act. In these circumstances, the Information Commissioner may decide to seek a civil penalty under the Privacy Act for an interference with privacy arising from a contravention of the My Health Records Act.
Section 11.5 states that the Information Commissioner cannot seek civil penalty orders in relation to contraventions of ‘serious interference with privacy’, ‘interference with privacy’, and compliance notice civil penalty provisions if the entity has already been issued with a compliance notice in relation to the same conduct and the notice has not been withdrawn and the entity has complied with the notice, or the entity applied to the Court for review of the notice and the application has not been completely dealt with.
Section 12 Compliance notices
This section sets out circumstances when the Information Commissioner may consider issuing a compliance notice.
Section 12.1 states that under section 80UC of the Privacy Act, a compliance notice may be issued by the Information Commissioner, or a Senior Executive Service member of the staff of the Commissioner, if there is a reasonable belief that an entity has contravened a compliance notice provision. The section also explains that a compliance notice is a discretionary notice which may be issued to an entity before an infringement notice is issued. It is intended to provide an entity with practical and measurable steps it can take to comply with obligations outlined in compliance notice provisions.
Section 12.2 states that section 80UC of the Privacy Act prescribes the requirements for issuing a valid compliance notice, the matters that must be outlined, requirements for entities to comply with a compliance notice, and the relationship and interaction of compliance notices with other enforcement powers.
Section 13 Infringement notices
This section sets out circumstances when the Information Commissioner may consider issuing an infringement notice.
Section 13.1 states that under section 80UB of the Privacy Act, an infringement notice may be issued by the Information Commissioner, or a Senior Executive Service member of the staff of the Commissioner, where there is a reasonable belief that infringement notice provisions have been contravened. An infringement notice sets out the particulars of an alleged contravention of an offence or civil penalty provision and an amount to be paid. An entity that is issued with an infringement notice can choose to pay the penalty amount specified in the notice as an alternative to court proceedings.
Section 13.2 states that section 80UB of the Privacy Act with Part 5 of the Regulatory Powers Act prescribes the requirements for a valid infringement notice, including when an infringement notice may be given, the matters to be included in an infringement notice, how an extension of time to pay may be sought, and how a withdrawal of an infringement notice may be sought.
Section 13.3 states that subsection 80UC(10) of the Privacy Act and subsection 103(2) of the Regulatory Powers Act prescribe circumstances in which the Information Commissioner may not issue an infringement notice.
Section 14 Referrals
This section sets out the approach of the Information Commissioner to referring matters to other bodies.
Section 14.1 notes that the Privacy Act confers on the Information Commissioner a range of privacy regulatory powers, including powers that allow the Information Commissioner to work with entities to facilitate legal compliance and best privacy practice, as well as investigative and enforcement powers to use in cases where a privacy breach has occurred.
Section 14.2 advises that when the Information Commissioner receives a complaint, it may not always be the most appropriate body to investigate and resolve that complaint. The Information Commissioner has various powers to decline to investigate where there is an alternative applicable law or complaint handling body, or to refer complaints to other complaint bodies in certain circumstances.
Section 14.3 notes that the Information Commissioner can refer criminal matters under the My Health Records Act and Privacy Act to the Commonwealth Department of Public Prosecutions. For example, it is a criminal offence under subsection 66(1AA) of the Privacy Act for a body corporate to engage in conduct which constitutes a system of conduct or pattern of behaviour by repeatedly failing to give information as required under the Privacy Act. This enables the Information Commissioner to refer matters that involve more serious, systemic non-compliance.
Attachment B
Statement of Compatibility with Human Rights
Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011
My Health Records (Information Commissioner Enforcement Powers) Guidelines 2026
Overview of legislative instrument
This legislative instrument is made under section 111 of the My Health Records Act 2012 (My Health Records Act). It describes the Australian Information Commissioner’s investigative and enforcement powers under both the My Health Records Act and the Privacy Act 1988 (Privacy Act) and sets out the Information Commissioner's general approach to the exercise of these powers in relation to the My Health Record system.
The Guidelines fulfill the Information Commissioner’s legislative obligation to formulate guidelines (and have regard to guidelines) about enforcement powers conferred on the Information Commission under the My Health Records Act, or a power under another Act, that is related to such a power.
The Guidelines seek to provide guidance to the regulated community, while preserving the discretion of the Information Commissioner to take enforcement action that the Information Commissioner considers appropriate in light of the particular circumstances of a given case. The Guidelines necessarily deal with a variety of factual scenarios and so are framed to give broad guidance and transparency without unduly restricting the Information Commissioner’s capacity to take appropriate action tailored to those facts and circumstances.
The Guidelines do not create new rights, obligations or penalties.
Human rights implications
The legislative instrument engages the following human rights:
Right to protection of privacy and reputation
Article 17 of the International Covenant on Civil and Political Rights guarantees protection from, among other things, arbitrary or unlawful interference with a person’s privacy.
This legislative instrument engages with Article 17 by supporting the enforcement and compliance aspects of the My Health Record system, which include a specific privacy regime for the handling of a registered healthcare recipient’s health information which will generally operate concurrently with Commonwealth, state and territory privacy laws.
In particular, this legislative instrument sets out the Information Commissioner’s general approach when using the available investigatory and enforcement powers. It makes it clear that the Information Commissioner will investigate unlawful interferences with privacy consistently, whether under the Privacy Act or the My Health Records Act. The Information Commissioner will, where appropriate, pursue available enforcement mechanisms against persons who have contravened privacy laws in relation to the My Health Record system.
Right to enjoyment of highest attainable standard of health
This legislative instrument also engages Articles 2 and 12 of the International Covenant on Economic, Social and Cultural Rights by assisting with the progressive realisation by all appropriate means of the right of everyone to the enjoyment of the highest attainable standard of physical and mental health.
This legislative instrument supports the administration of the My Health Record system, the intention of which is to enable a safer, higher quality, more equitable and sustainable health system for all Australians by transforming the way information is used to plan, manage and deliver healthcare services. The My Health Record system arose out of the National E-Health Strategy and National Health and Hospitals Reform Commission report of June 2009, which both identified an electronic health records system as being central to enabling the realisation of many health reform objectives including improved quality, safety, efficiency and equity in healthcare and the long-term sustainability of the health system.
Conclusion
The legislative instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011. This is because it advances the protection of the above human rights.
Elizabeth Tydd, Australian Information Commissioner
[1] https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/statement-of-regulatory-approach
[2] Such as https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/privacy-regulatory-action-policy and https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/guide-to-privacy-regulatory-action
[3] https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-remaking-the-my-health-records-information-commissioner-enforcement-powers-guidelines
[4] https://www.oaic.gov.au/privacy/your-privacy-rights/health-information/my-health-record/about-my-health-record
[5] https://www.oaic.gov.au/engage-with-us/research-and-training-resources/videos/privacy-and-the-my-
health-record-system
[6] https://www.oaic.gov.au/privacy/your-privacy-rights/health-information/my-health-record/make-a-my-health-record-complaint
[7] https://www.digitalhealth.gov.au/healthcare-providers/initiatives-and-programs/my-health-record
[8] https://www.digitalhealth.gov.au/sites/default/files/documents/my-health-record-recommended-training.pdf
[9] https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/my-health-record/guide-to-mandatory-data-breach-notification-in-the-my-health-record-system
[10] https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/my-health-record/Security-and-Access-policies-Rule-42-guidance
[11] Such as https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/privacy-regulatory-action-policy and https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/guide-to-privacy-regulatory-action
[12] Such as https://www.finance.gov.au/sites/default/files/2025-10/Regulatory-Policy-Practice-and-Performance-Framework.pdf and https://www.finance.gov.au/government/managing-commonwealth-resources/regulator-performance-rmg-128
[13] Such as https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/privacy-regulatory-action-policy and https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/guide-to-privacy-regulatory-action