Privacy (International Money Transfers) Temporary Public Interest Determination 2014 (No. 2)

Administered by Attorney-General's Department

Legislation au F2014L00534 Not in force Legislative Instrument

Legislation content

Explanatory Statement

Privacy (International Money Transfers) Temporary Public Interest Determination 2014 (No. 2)

This explanatory statement has been prepared by the Privacy Commissioner, in accordance with the functions and powers conferred on him by section 12 of the Australian Information Commissioner Act 2010 (the Australian Information Commissioner Act).

It explains the purpose and intended operation of the Privacy (International Money Transfers) Temporary Public Interest Determination 2014 (No. 2) (TPID 2014-2) made under subsection 80A(2) of the Privacy Act 1988 (Privacy Act).

Authority for the temporary public interest determination

Subsection 80A(2) of the Privacy Act states:

The Commissioner may, by legislative instrument, make a determination that he or she is satisfied of the matters set out in subsection (1). The Commissioner may do so:

(a)   on request by the APP entity

(b)   on the Commissioner’s own initiative.

Subsection 80A(1) states:

This section applies if the Commissioner is satisfied that:

(a)   the act or practice of an APP entity that is the subject of an application under section 73 for a determination under section 72 breaches, or may breach:

(i)                  an Australian Privacy Principle; or

(ii)                a registered APP code that binds the entity; and

(b)   the public interest in the entity doing the act, or engaging in the practice, outweighs to a substantial degree the public interest in adhering to that principle or code; and

(c)    the application raises issues that require an urgent decision.

Subsection 6(1) of the Privacy Act defines ‘Commissioner’ to mean ‘the Information Commissioner within the meaning of the Australian Information Commissioner Act 2010.’

As a ‘privacy function’, TPID 2014-2 can be made by the Privacy Commissioner in accordance with the functions and powers conferred on the Privacy Commissioner by section 12 of the Australian Information Commissioner Act.

Purpose

The purpose of TPID 2014-2 is to permit the Reserve Bank of Australia (the RBA) to disclose the personal information of a beneficiary of an international money transfer (IMT) to an overseas financial institution when processing an IMT without breaching the Australian Privacy Principles (APPs). Specifically, TPID 2014-2 will ensure that the RBA does not breach APP 8.1 when disclosing the beneficiary’s personal information to the overseas financial institution, and is not held to breach another APP (other than APP 1) as a result of being held accountable for an act or practice of the overseas financial institution in relation to that information (in accordance with subsection 16C(2)).

In making TPID 2014-2, the Privacy Commissioner has had regard to the objects of the Privacy Act, in particular:

  • to promote the protection of the privacy of individuals (paragraph 2A(a))
  • to recognise that the protection of the privacy of individuals is balanced with the interest of entities in carrying out their functions and activities (paragraph 2A(b))
  • to promote responsible and transparent handling of personal information by entities (paragraph 2A(d)), and
  • to facilitate the free flow of information across national borders while ensuring that the privacy of individuals is respected (paragraph 2A(f)).

Application for a Public Interest Determination

On 9 May 2014, the RBA made an application under subsection 73(1) of the Privacy Act for a public interest determination under subsection 72(2) of the Privacy Act, and a temporary public interest determination under subsection 80A(2) of the Privacy Act.

The RBA, in its application, refers to the Privacy (International Money Transfers) Temporary Public Interest Determination 2014 (No. 1) (TPID 2014-1) made under subsection 80A(2) of the Privacy Act and the Privacy (International Money Transfers) Generalising Determination 2014 (No. 1) (GD 2014-1) made under subsection 80B(3) of the Privacy Act, both of which were registered on the Federal Register of Legislative Instruments on 11 March 2014. The RBA states in the application that:

As indicated in the Explanatory Statement for TPID 2014-1 and GD 2014-1 (Explanatory Statement), the purpose of TPID 2014-1 and GD 2014-1 is to permit Australia and New Zealand Banking Group Limited (ANZ) and other authorised deposit-taking institutions within the meaning of the Banking Act 1959 (ADIs) to disclose the personal information of a beneficiary of an international money transfer (IMT) to an overseas financial institution when processing an IMT without breaching the Australian Privacy Principles (APPs) following the commencement of the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Privacy Amendment Act). In particular, the purpose is to ensure that ANZ and other ADIs do not breach APP 8.1 when disclosing the beneficiary’s personal information to the overseas financial institution, and are not held to breach another APP (other than APP 1) as a result of being held accountable for an act or practice of the overseas financial institution in relation to that information (in accordance with subsection 16C(2) of the Privacy Act).

The RBA is not an ADI but is authorised under the Banking Act (section 8(1)), and under the Reserve Bank Act 1959 (sections 26 and 27), to carry on banking business. It provides payment and collection services for the Australian Government, various Australian government agencies, and a number of overseas central banks and official institutions. It also provides limited international payment services for its staff. In the course of its banking business it processes IMTs for its customers in a similar way to the way that ANZ and other ADIs process IMTs for their customers. It believes that, for the reasons given in the Explanatory Statement, the relief offered to ANZ and other ADIs in TPID 2014-1 and GD 2014-1 should be extended to the RBA. 

The RBA submits that the public interest in the RBA processing IMTs outweighs to a substantial degree the public interest in adhering to APP 8 and being held accountable for any incidents of non compliance of the APPs by an overseas recipient of the personal information.”

The RBA provided an outline of the IMT processes it is involved with in its application. These are similar in nature to the processes described in the PID application by ANZ which resulted in TPID 2014-1 and GD 2014-1 being made.  

Relevant privacy principles 

IMTs under the National Privacy Principles (NPPs)

The RBA in its application indicated that:

“[it] is an ‘agency’ for the purpose of the APPs. Its contestable transactional banking business constitutes commercial activity for the purposes of section 7A(3) of the Privacy Act. Accordingly under section 7A(1), in respect of the RBA's commercial activities, it is also an ‘organisation’ for the purpose of the APPs.

Before the Privacy Amendment Act took effect this contestable business was, through the operation of section 7A of the Privacy Act, subject to the National Privacy Principles (NPPs) in the same way as the activities of ANZ and other ADIs. Under National Privacy Principle 9 (NPP 9), the transfer of personal information of the sender or beneficiary to a foreign financial institution was treated as a trans-border data flow and permissible provided one of six criteria were met.  Similar to ANZ, the RBA primarily relied upon subsections (d) and (e) of NPP 9 to process an IMT without seeking express consent from the beneficiary given that either:

  • the transfer was necessary for the conclusion or performance of a contract concluded in the interest of the individual between the organisation and a third party (NPP 9(d)); or
  • the transfer was for the benefit of the individual; it was impracticable to obtain the consent of the individual to that transfer; and if it were practicable to obtain such consent, the individual would be likely to give it (NPP 9(e)).”

IMTs under the Australian Privacy Principles (APPs)

The Privacy Amendment Act commenced on 12 March 2014 and made changes to the Privacy Act that included a repeal of the NPPs and the commencement of a new set of principles (the APPs) that apply to most Australian and Norfolk Island Government agencies and some private section organisations (known as APP entities), including, as discussed above, some activities of the RBA. The changes to the Privacy Act included the following:

  • A new APP 8 dealing with cross-border disclosure of personal information to replace NPP 9.
    • APP 8.1 requires an APP entity that discloses personal information to an overseas recipient to take reasonable steps to ensure that the overseas recipient does not breach the APPs (other than APP 1) in relation to the information, unless an APP 8.2 exception applies.
    • The exceptions set out in APP 8.2 differ from the NPP 9 exceptions. Importantly, APP 8.2 does not cover either of the exceptions set out in NPP 9(d) or (e).
  • A new accountability approach dealing with cross-border data flows. As part of this approach, a new section 16C provides that where an APP entity discloses personal information to an overseas recipient, in circumstances where the overseas recipient is not bound by the APPs and an APP 8.2 exception does not apply to the disclosure, the APP entity will be taken to have breached the APPs in instances where the overseas recipient does an act or engages in a practice in relation to that information that would be a breach of the APPs (other than APP 1) if the APPs so applied to that act or practice.

While the changes to the Privacy Act made by the Privacy Amendment Act do not prohibit the processing of IMTs by the RBA, they will:

  • require that before processing an IMT, the RBA take reasonable steps to ensure that the overseas financial institution to which a beneficiary’s personal information is to be disclosed, does not breach the APPs (other than APP 1) in relation to that information
  • in some circumstances, make the RBA accountable for any acts or practices of the overseas financial institution that breach the APPs (other than APP 1) in relation to that information.

Additional information

The RBA’s application that led to the making of TPID 2014-2 and the Privacy Commissioner's notice of receipt of the application (required by subsection 74(1) of the Privacy Act) are available at: http://www.oaic.gov.au/privacy/applying-privacy-law/privacy-registers/public-interest-determinations/#applications  

Reasons for the decision

Might the processing of IMTs breach an APP?

APP 8

APP 8.1 requires the an APP entity to take such steps as are reasonable in the circumstances to ensure that an overseas recipient of a beneficiary’s personal information does not breach the APPs in relation to that information.

The Office of the Australian Information Commissioner has issued the APP guidelines. Chapter 8 (APP 8) of the APP guidelines states that it is generally expected that to comply with APP 8.1, the relevant APP entity will enter into an enforceable contractual arrangement with an overseas recipient that requires the overseas recipient to handle personal information in accordance with the APPs. However, the APP guidelines acknowledge that whether a contract is required, and the terms of the contract, will depend on the circumstances, including the practicability of taking that step.

The RBA states in its application that:

“It is impracticable for the RBA to obtain contractual arrangements with every potential overseas recipient to ensure their compliance with the APPs. In the majority of IMTs, the RBA relies on the relationships created by the SWIFT network and it is not practical for the RBA to alter, or attempt to alter, SWIFT to impose contractual obligations on other SWIFT users to comply with the APPs in relation to the personal information of IMT beneficiaries.”

and further:

“… the RBA uses an agent to process many IMTs … [who] is unlikely (for the reasons given in this Application) to accept an obligation to ensure that all organisations in the payment chain agree to comply with the APPs.

In addition, in the application, the RBA submitted that the RBA would be unable to rely on any of the relevant exceptions to APP 8.1 found in APP 8.2. The RBA stated:

“Specifically, under APP 8.2(a) it would be impractical for the RBA to obtain current and ongoing legal advice in relation to the privacy regimes of all [redacted] jurisdictions to which IMTs initiated by RBA customers are sent. Even if such legal advice was obtained, those jurisdictions with inferior privacy schemes would fall outside the APP 8.2(a) exception.

Under APP 8.2(b) the RBA would not be able to obtain consent from the beneficiary as its role is limited to collecting the information on the beneficiary from the sender. It has no contract with, and no opportunity to communicate with, the beneficiary. Transaction volumes would make obtaining consent impracticable even if there was a way for the RBA to communicate with beneficiaries.

Although the RBA takes steps to protect the beneficiary’s information that is sent overseas during the processing of an IMT, (for example, whether the transfer occurs as part of the SWIFT network or outside of this network, there are mechanisms in place to ensure the security and confidentiality of that information), there is uncertainty about whether these steps would satisfy the reasonable steps test in APP 8.1.

For this reason, the Privacy Commissioner was satisfied that the RBA may breach APP 8.1 when disclosing a beneficiary’s personal information to an overseas financial institution during the processing of IMTs.

Other APPs

Under subsection 16C(2) of the Privacy Act, when an overseas financial institution, to which the RBA discloses a beneficiary’s personal information, does an act or engages in a practice that would breach an APP (other than APP 1) in relation to that information, the RBA will be taken to breach that APP if the overseas financial institution is not bound by the APPs.

The Privacy Commissioner was satisfied that the RBA may be taken to breach an APP (other than APP 1) as a result of subsection 16C(2).

Does the public interest in processing IMTs substantially outweigh the public interest in complying with the APPs?

In issuing TPID 2014-2, the Privacy Commissioner took account of the matters raised in the RBA’s application. Based on the available evidence presented in the application, the Privacy Commissioner considered on balance, that the public interest in permitting the relevant acts or practices engaged in during IMT processing substantially outweighs the public interest in adherence to the APPs that might be breached. The RBA submitted that:

“… the analysis in the Explanatory Statement [for TPID2014-1 and GD2014-1] under the heading ‘Does the public interest in processing IMTs substantially outweigh the public interest in complying with the APPS?’ applies equally to the RBA and that the public interest in the RBA processing IMTs substantially outweighs the public interest in adherence to the APPs that might be breached.”

Public interest benefits associated with adhering to the IMT process in its current form

The RBA put forward a number of public interest benefits associated with making IMTs available to Australian customers of the RBA:

  • IMTs allow the government to meet its obligations to overseas beneficiaries [redacted] in a timely and secure manner.
  • IMTs provide payment security and transaction certainty. This assists government to better enforce anti-money laundering and counter-terrorism financing requirements.
  • The IMT processes in their current form is one component of the global financial system, and Australia is a significant contributor to that system. Maintaining the certainty, reliability and efficiency of the IMT processing serves an important public interest within the context of Australia’s role within the global community.

Public benefits associated with adhering to APP 8 during IMT processing

The RBA submitted that:

“The public benefit associated with adhering to APP 8 when processing IMTs is to ensure the security and confidentiality of personal information of beneficiaries. As noted above, in line with the practices of other Australian banks, the RBA is currently protecting the security and confidentiality of any personal information that needs to be sent overseas in order to process an IMT.”

Compliance with APP 8.1 not practicable

It is not practical for the RBA to take additional steps to ensure compliance with APP 8.1 and impose contractual obligations on all overseas financial institutions receiving the personal information of IMT beneficiaries in order to comply with the APPs:

  • The RBA already takes steps to ensure the security and confidentiality of information that needs to be sent overseas during IMT processing.
  • Obtaining agreement from foreign banks to a separate set of privacy standards to process IMTs would be not only inconvenient, but time-consuming and costly.
  • It is unlikely that foreign financial institutions, already operating under their own privacy regimes, would agree to enter into such arrangements.  
  • Moreover, it would not be practicable for the RBA to attempt to alter SWIFT to impose these contractual obligations with all overseas SWIFT members. The RBA has pointed out that the ‘interconnectedness of the global financial system’ means that any change to SWIFT would have significant consequences for the whole financial system.

Without those additional steps there is uncertainty about whether or not the RBA complies with APP 8.1 because it is not clear that the steps that it does take would be considered ‘reasonable in the circumstances. This exposes the RBA to the risk of being held accountable for a breach of the APPs by overseas financial institutions whose acts or practices would breach the APPs if the APPs applied to those acts or practices.

There is a public benefit in providing certainty to the RBA and its customers that it will not be held to breach the APPs during IMT processing.

In addition the RBA notes that:

“If the RBA were not granted a PID for IMTs in the same terms as that granted to ANZ and other ADIs any additional compliance costs to the RBA resulting from the operation of APP 8 would represent a competitive disadvantage for the RBA’s transactional banking business in relation to which it competes with private sector banks.”

 

APP 8.2 exceptions not available

Presently, the IMT processes provide a simple, secure, cost-effective and reliable means for the global transfer of money, providing benefit to RBA customers and beneficiaries alike. The APP 8.2 exceptions will not generally be available to the RBA in the context of the IMT processes.

There would, in this context, be very little public benefit associated with requiring the RBA to take additional steps to ensure the overseas recipient does not breach the APPs or to rely on any of the APP 8.2 exceptions when processing IMTs.

Does the application raise issues that require an urgent decision?

The RBA sought a temporary PID under section 80A of the Privacy Act in order to continue to be able to offer IMTs to its customers without breaching the Privacy Act, while the PID application was under consideration.

The Privacy Commissioner was satisfied that an urgent decision is required because:

  • the RBA may breach APP 8, or be taken to breach the other APPs (except of APP 1) if it continues to process IMTs
  • due consideration of the RBA’s application, including compliance with the required processes in Division 1, Part VI of the Privacy Act and the Legislative Instruments Act 2003 (Legislative Instruments Act), will require a significant period of time, and
  • a TPID would allow the RBA to continue to offer, and the IMT beneficiaries to continue to enjoy the benefits of, IMTs while the application is under further  consideration.

Operation

TPID 2014-2 will be effective for a period of 12 months from the date of commencement, as permitted by subsection 80A(3) unless ceased earlier (see s 80D(2)).

Consultation

The Privacy Act does not require consultation to occur prior to the making of a TPID. The Privacy Commissioner was satisfied that consultation required under section 17 of the Legislative Instruments Act is unnecessary or inappropriate because the TPID is required as a matter of urgency (paragraph 18(2)(b)).

Public consultation on the issues raised in the RBA’s public interest determination application will occur as the application is progressed to consider whether a further determination under subsections 72(2) of the Privacy Act should be made. This consultation will be undertaken in conjunction with the consultation on the ANZ’s IMT public interest determination application and should begin in late May or June 2014.


Statement of Compatibility with Human Rights

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

Privacy (International Money Transfers) Temporary Public Interest Determination 2014 (No. 2) (TPID 2014-2)

This legislative instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

Overview of the Legislative Instruments

The purpose of TPID 2014-2 is to permit the Reserve Bank of Australia to disclose the personal information of a beneficiary of an international money transfer (IMT) to an overseas financial institution when processing an IMT without breaching the Australian Privacy Principles (APPs) in Schedule 1 of the Privacy Act 1988.

The central public interest objective served by TPID 2014-2 is to permit the RBA to continue to process IMTs, which has benefits for individuals who might send or receive money using IMTs, Australia and its reputation as a participant in the global financial system and the stability of the global financial system.

Human rights implications

TPID 2014-2 engages Article 17 of the International Covenant on Civil and Political Rights (ICCPR), which provides that no one shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home or correspondence, nor to unlawful attacks on his or her honour and reputation, and that everyone has the right to the protection of the law against such interference and attacks. The Preamble to the Privacy Act makes clear that the legislation was intended to implement, at least in part, Australia’s obligations relating to privacy under the ICCPR.

TPID 2014-2 limits the right against the arbitrary interference with privacy and the right to the protection of the law against such interference by limiting the application of protections in the Privacy Act in relation to the cross-border disclosure of personal information.

 

However, the right to privacy is not absolute and there may be circumstances in which the guarantees in article 17 can be outweighed by other considerations. Importantly, the Commissioner must have regard to the objects of the Privacy Act when exercising his functions and powers. These objects include:

  • to promote the protection of the privacy of individuals (paragraph 2A(a))
  • to recognise that the protection of the privacy of individuals is balanced with the interest of entities in carrying out their functions and activities (paragraph 2A(b))
  • to promote responsible and transparent handling of personal information by entities (paragraph 2A(d))
  • to facilitate the free flow of information across national borders while ensuring that the privacy of individuals is respected (paragraph 2A(f)).

The Privacy Commissioner was satisfied that the public interest in permitting the acts or practices the subject of TPID 2014-2 substantially outweigh the public interest in adhering to the APPs.

Conclusion

It is considered that to the extent that the acts or practices authorised by TPID 2014-2 limit human rights, those limitations are reasonable and proportionate.

 

Timothy Pilgrim,

Privacy Commissioner

 

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.