Paid Parental Leave Amendment (Public Interest Certificates for Work Health and Safety Purposes) Rules 2025

Administered by Department of Social Services

Legislation au F2025L01195 Rules Not in force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

 

Issued by the authority of the Minister for Social Services

 

Paid Parental Leave Act 2010

 

Paid Parental Leave Amendment (Public Interest Certificates for Work Health and Safety Purposes) Rules 2025

Purpose

The Paid Parental Leave Amendment (Public Interest Certificates for Work Health and Safety Purposes) Rules 2025 (‘Amendment Rules’) amend Part 9 Division 2 of the Paid Parental Leave Rules 2021 (‘PPL Rules’) which prescribes guidelines that the Secretary of the Department of Social Services (‘DSS’) (or a delegate) must follow when considering whether to disclose information pursuant to a public interest certificate under paragraph 128(1)(a) of the Paid Parental Leave Act 2010 (‘PPL Act’).

 

Background

Paragraph 128(1)(a) of the PPL Act allows the Secretary to disclose information acquired by an officer in the performance of functions or duties or exercise of powers under the PPL Act or the Regulatory Powers (Standard Provisions) Act 2014 (as that Act applies in relation to the PPL Act), where the Secretary certifies that it is necessary in the public interest.

Subsection 128(4) of the PPL Act provides that the Minister for Social Services may make guidelines for the exercise of the power for the Secretary to give public interest certificates under paragraph 128(1)(a). Subsection 128(3) of the PPL Act provides that, in giving certificates for these purposes, the Secretary must act in accordance with guidelines (if any) from time to time in force under subsection 128(4).
Part 9 Division 2 of the PPL Rules is made for the purposes of subsection 128(4) of the PPL Act.

Personal information handled under the PPL Act is also protected by the
Privacy Act 1988 (‘Privacy Act’).

The Amendment Rules amend the PPL Rules by inserting a new purpose
in Part 9 Division 2 to allow for the disclosure of information in the public interest where reasonably necessary to assist a government agency to manage a work health and safety risk to that agency.

This amendment will assist Services Australia to respond to the issues identified in the Services Australia Security Risk Management Review report dated July 2023 (the Ashton Review), which the Government commissioned following the serious assault of a staff member at Services Australia’s Airport West Service Centre.

Commencement

The Amendment Rules will commence on the day after it is registered on the Federal Register of Legislation.

Consultation

The Amendment Rules have been made at the request of Services Australia to assist with its implementation of the recommendations of the Ashton Review. Services Australia has been consulted on the text of the Amendment Rules and this explanatory statement and has confirmed that the changes would assist it to better manage customer aggression risk.

Information sharing

The amendment is intended to improve Services Australia’s ability to share information about customer aggression incidents within and outside of the agency as reasonably necessary to manage a potential or actual work health and safety risk. Services Australia may share information about customer aggression incidents to entities that service premises, such as security firms and other entities co-located in premises where the agency has a presence. This includes other federal, state or local government agencies, government-funded organisations, non-government organisations and private businesses.

Application of the Privacy Act

The disclosure and management of information about customers is also governed by the Privacy Act, which requires agencies (including Services Australia) to, among other things, take reasonable steps to protect information from:

  • Misuse, interference and loss; and
  • Unauthorised access, modification or disclosure.

Most entities operating in co-located premises, including individuals employed or engaged by these entities, would be subject to the Privacy Act. Many of these entities are already governed by the Privacy Act, including Commonwealth agencies or statutory officeholders, and organisations with an annual turnover of more than $3 million. Any co-located entities that are not subject to the Privacy Act are nevertheless contractually bound through agreements with Services Australia, to handle personal information in accordance with the Privacy Act. In addition,
co-located State or Territory authorities are subject to equivalent privacy legislation in their own jurisdiction.

Safeguards under the PPL Act

Irrespective of whether a recipient of information disclosed in the public interest for this new purpose is subject to the Privacy Act, the information remains ‘protected information’ under the secrecy provisions of the PPL Act. This means that the recipient must not disclose the information to other parties unless the disclosure is for the same purpose or is otherwise authorised by the PPL Act.

The PPL Act imposes a higher level of protection for ‘protected information’ than the Privacy Act does for ‘personal information’. For instance, any person that records, uses or discloses protected information for a purpose that is not permitted by the PPL Act commits an offence punishable by up to two years’ imprisonment (see section 130 of the PPL Act).

Explanation of the provisions

 

Paid Parental Leave Amendment (Public Interest Certificates for Work Health and Safety Purposes) Rules 2025

 

PART 1 - PRELIMINARY

Section 1 – Name

Section 1 states how the instrument is to be cited, that is, as the Paid Parental Leave Amendment (Public Interest Certificates for Work Health and Safety Purposes) Rules 2025.

Section 2 – Commencement

Section 2 provides that the Amendment Rules will commence the day after it is registered on the Federal Register of Legislation.

Section 3 – Authority

Section 3 provides that the Amendment Rules are made under section 298 of the PPL Act.

Section 4 – Schedules

Section 4 provides that the PPL Rules are amended as set out in items in the Schedule to the Amendment Rules.

 

SCHEDULE 1 - AMENDMENTS

Paid Parental Leave Rules 2021

Item 1: After section 56

Item 1 inserts a new section 56A after existing section 56 of the PPL Rules. New section 56A covers a disclosure of information that is reasonably necessary to assist a government agency to manage a work health and safety risk to that agency, where Services Australia is present.

Agencies, such as Services Australia, have obligations including under the Work Health and Safety Act 2011 to ensure that the health and safety of workers and other persons, are not put at risk by the conduct of the agency’s operations. Information held by Services Australia about aggressive customers is often critical to identifying and assessing the risk posed to workers and others. The agency needs to be able to share this information across its master programs (Centrelink, Medicare and Child Support) and externally to individuals working within a co-located premises (such as security guards and other workers in shared office environments).

Among other things, section 56A is intended to improve the arrangements for ensuring worker safety for frontline staff at Services Australia, particularly where there have been instances of customer aggression.

 

 

This amendment will assist Services Australia to implement recommendation 35 of the Ashton Review to integrate:

Customer aggression incident information… across systems that record customer interactions to provide an agency enterprise view of customer aggression information.

The principal service delivery model for dealing with customer aggression at Services Australia is known as a Managed Service Plan (‘MSP’). A MSP may be put in place when a person poses a risk to staff safety. Currently, MSPs are generally confined to each master program.

For example, a person might be placed on an MSP for the Centrelink program because they have used violence or threatened to physically harm staff or others when visiting a service centre. Information about the Centrelink MSP is unlikely to be available to Medicare and Child Support staff. This is because the details of the aggressive behaviour would be considered protected information under Centrelink program legislation, such as the PPL Act. Such information can only be disclosed with an individual’s consent, or where there is an authority or requirement under law.

Services Australia currently discloses information relating to customer aggression incidents under section 56 of the PPL Rules, where the disclosure is necessary for the purposes of preventing or lessening a serious threat to the life, health or safety of a person. However, under this provision a disclosure can generally only be made if there is a threat against a specific individual. As the individual in this example has not made a threat against a particular person, safety-related information is not able to be shared with Medicare and Child Support programs before the person might interact with staff in a different service centre.

The Amendment Rules would facilitate routine disclosures of protected information where there is an identified risk of generalised harm, meaning that Services Australia could develop an ICT solution that enables an enterprise-wide view of customer aggression information and is able to respond consistently across the master programs when interacting with individuals.

 

 

Statement of Compatibility with Human Rights

 

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

 

Paid Parental Leave Rules 2010

 

Paid Parental Leave Amendment (Public Interest Certificates for Work Health and Safety Purposes) Rules 2025

The Paid Parental Leave Amendment (Public Interest Certificates for Work Health and Safety Purposes) Rules 2025 (‘Amendment Rules’) amend Part 9 Division 2 of the Paid Parental Leave Rules 2021 (‘PPL Rules’) which prescribes guidelines that the Secretary of the Department of Social Services (‘DSS’) (or a delegate) must follow when considering whether to disclose information pursuant to a public interest certificate under paragraph 128(1)(a) of the Paid Parental Leave Act 2010 (‘PPL Act’).

 

The Amendment Rules are compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

Overview of the legislative instrument

Paragraph 128(1)(a) of the PPL Act allows the Secretary to disclose information acquired by an officer in the performance of functions or duties or exercise of powers under the PPL Act or the Regulatory Powers (Standard Provisions) Act 2014 (as that Act applies in relation to the PPL Act), where the Secretary certifies that it is necessary in the public interest.

Subsection 128(4) of the PPL Act provides that the Minister for Social Services may make guidelines for the exercise of the power for the Secretary to give public interest certificates under paragraph 128(1)(a). Subsection 128(3) of the PPL Act provides that, in giving certificates for these purposes, the Secretary must act in accordance with guidelines (if any) from time to time in force under subsection 128(4).
Part 9 Division 2 of the PPL Rules is made for the purposes of subsection 128(4) of the PPL Act.

The Amendment Rules amend the PPL Rules by inserting a new purpose in Part 9 Division 2 to allow for the disclosure of information in the public interest where reasonably necessary to assist a government agency to manage a work health and safety risk to that agency.

Agencies, such as Services Australia, have obligations including under the Work Health and Safety Act 2011 (Cth) to ensure that the health and safety of workers and other persons, are not put at risk by the conduct of an agency’s operations (section 19). Information held by the agency about aggressive customers is often critical to identifying and assessing the risk posed to workers and others. The agency needs to be able to share this information across its master programs (Centrelink, Medicare and Child Support) and externally to individuals working within a co-located premises (such as security guards and other workers in shared office environments).

This amendment will assist Services Australia to implement recommendation 35 of the Services Australia Security Risk Management Review report dated July 2023 (the Ashton Review) to integrate:

Customer aggression incident information… across systems that record customer interactions to provide an agency enterprise view of customer aggression information.

Human rights implications

The Amendment Rules engage the following rights:

  • Right to privacy – Article 17 of the International Covenant on Civil and Political Rights (‘ICCPR’)
  • Right to safe and healthy working conditions – Article 7(b) of the International Covenant on Economic, Social and Cultural Rights (‘ICESCR’)

Right to privacy

Article 17 of the ICCPR relevantly provides that no one shall be subject to arbitrary or unlawful interference with their privacy and that everyone has the right to the protection of law against such interference or attacks. The right to privacy encompasses respect for information privacy, including the right to respect for private and confidential information, particularly the use and sharing of such information and the right to control dissemination of such information.

The use of the term “arbitrary” in Article 17 means that any interference with privacy must be in accordance with the provisions, aims and objectives of the ICCPR and should be reasonable in all the circumstances. It recognises that limitations may be imposed on the general prohibition on interference with privacy, provided that such limitations are reasonable, necessary and proportionate.

Application of the Privacy Act 1988

The disclosure and management of information about customers is also governed by the Privacy Act 1988 (‘Privacy Act’), which requires agencies (including Services Australia) to, among other things, take reasonable steps to protect information from:

  • Misuse, interference and loss; and
  • Unauthorised access, modification or disclosure.

Most entities operating in co-located premises, including individuals employed or engaged by these entities, would be subject to the Privacy Act. Many of these entities are already governed by the Privacy Act, including Commonwealth agencies or statutory officeholders, and organisations with an annual turnover of more than $3 million. Any co-located entities that are not subject to the Privacy Act are nevertheless contractually bound through agreements with Services Australia, to handle personal information in accordance with the Privacy Act. In addition,
co-located State or Territory authorities are subject to equivalent privacy legislation in their own jurisdiction.

 

 

 

 

Safeguards under the PPL Act

Irrespective of whether a recipient of information disclosed in the public interest for this new purpose is subject to the Privacy Act, the information remains ‘protected information’ under the secrecy provisions of the PPL Act. This means that the recipient must not disclose the information to other parties unless the disclosure is for the same purpose or is otherwise authorised by the PPL Act.

The PPL Act imposes a higher level of protection for ‘protected information’ than the Privacy Act does for ‘personal information’. For instance, any person that records, uses or discloses protected information for a purpose that is not permitted by the PPL Act commits an offence punishable by up to two years’ imprisonment (see section 130 of the PPL Act).

In addition to the above statutory frameworks, Services Australia takes reasonable steps to ensure that any personal information it holds is protected from misuse, interference, loss, and unauthorised access, modification, or disclosure. This includes operationalising internal safeguards through a multi-layered approach encompassing governance, training, access control and compliance frameworks. This includes tailored training and frameworks on privacy, including compliance with the Australian Privacy Principles, data collection and cyber security.

Right to safe and healthy working conditions

To the extent that the Amendment Rules limit a person’s right to privacy, the limitations pursue a legitimate objective and are a reasonable and proportionate means of achieving that objective. Article 7 of the ICESCR recognises the right of everyone to the enjoyment of just and favourable working conditions. Paragraph (b) in particular provides for the right to safe and healthy working conditions. The new section 56A promotes this legitimate objective as it is intended to improve the arrangements for ensuring worker safety for frontline staff at Services Australia, particularly where there have been instances of customer aggression.

The PPL Rules and its legislative context further contain the following safeguards to ensure any interference with a person’s privacy is reasonable, necessary and proportionate:

  • The PPL Act imposes a higher level of protection to PPL information than is  imposed on personal information under the Privacy Act 1988. For example, criminal sanctions apply for the unauthorised use or disclosure of information (see section 130 of the PPL Act);
  • Paragraph 128(1)(a) of the PPL Act only enables the disclosure of information where a decision-maker certifies that the disclosure is necessary in the public interest;
  • A decision to disclose information under paragraph 128(1)(a) of the PPL Act can only be made by the Secretary or a delegate. The delegates are Commonwealth officers (predominantly in Services Australia) that are required to undertake relevant training;
  • Recipients of information disclosed on the basis of a public interest certificate cannot disclose the information to other parties unless the disclosure is for the same purpose or the disclosure is otherwise authorised by law;
  • Paragraph 55(1)(a) of the PPL Rules, which requires the decision-maker to be satisfied that the information cannot reasonably be obtained from a source other than DSS or Services Australia, helps to stop them being regarded as an automatic or even ready source of the information and to ensure the decision-maker considers whether there are other avenues for the recipient to obtain information about a person; and 
  • Paragraph 55(1)(c) of the PPL Rules, which requires that the decision-maker disclose de-identified information about a person unless doing so would not achieve the purpose for which the information is being disclosed, safeguards against unnecessary disclosures of personal information.

Conclusion

The Amendment Rules are compatible with human rights. To the extent that the right to privacy is limited, those limitations are reasonable, necessary and proportionate, and appropriate safeguards are in place.

 

The Hon Tanya Plibersek MP, Minister for Social Services

 

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.