Privacy (Market and Social Research) Code 2021

Administered by Attorney-General's Department

Legislation au F2021L00231 In force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

Issued by the authority of the Australian Information Commissioner (Commissioner) under the Privacy Act 1988 (Privacy Act). 

 

Privacy (Market and Social Research) Code 2021

This explanatory statement relates to the Privacy (Market and Social Research) Code 2021 (the Market and Social Research Privacy Code), which replaces the Privacy (Market and Social Research) Code 2014 (the Previous Code) varied under section 26J of the Privacy Act.

The Market and Social Research Privacy Code, as varied, is a registered Australian Privacy Principle (APP) code for the purposes of s 26B the Privacy Act.

 

Authority for variation of registered APP codes

Section 26J of the Privacy Act enables the Commissioner to approve a variation of a registered APP code.

On 23 November 2020, the Association of Market and Social Research Organisations ABN 20 107 667 398 (AMSRO), the Code Administrator, applied for variation of the Previous Code under paragraph 26J(1)(c).

The variation application followed a review of the Previous Code conducted by an independent reviewer appointed by the AMSRO Board and conducted in accordance with Part G (Review) of the Previous Code. The review included publication of draft amendments to the Previous Code and subsequent review by AMSRO and the independent reviewer of comments submitted by interested parties during a public consultation process. AMRSO published a report of the independent code review, including recommendations for amendments to the Previous Code that AMSRO and the independent reviewer considered necessary or desirable for the effective operation of the code. The Market and Social Research Privacy Code that is the subject of this explanatory statement addresses those recommendations for amendments to the Previous Code and accordingly replaces the Previous Code in full.

Under subsection 26J(6), if the Commissioner approves a variation of a registered APP code (the original code), the Commissioner must remove the original code from the Codes Register and register the APP code, as varied, by including it on the Register.

The Commissioner, having regard to the matters set out in subsections 26J(4) and 26J(5) of the Privacy Act and the OAIC’s Guidelines for developing codes, approved the variation of the Previous Code on 1 March 2021. The Market and Social Research Privacy Code, as varied, was included on the Codes Register on 1 March 2021.

 

Purpose

Each member of AMSRO which is an organisation covered by the Privacy Act (including because they have opted-in under s 6EA of that Act) is bound by the Market and Social Research Privacy Code. If an organisation covered by the Privacy Act ceases to be a member of AMSRO they will still be liable under the Market and Social Research Privacy Code for acts and practices that breach this Code and that occurred while they were an AMSRO member.

AMSRO is the national industry body of market and social research, data and insights organisations. AMSRO states that it considers that the market and social research sector depends upon the willing cooperation of the public and business community, which is based upon confidence that the work of the sector is carried out honestly, objectively and without unwelcome intrusion or disadvantage to participants. The Market and Social Research Privacy Code sets out standards for AMSRO members in relation to the conduct of market and social research which expand upon and supplement the operation of the APPs in the Privacy Act as applied to organisations that are AMSRO members and that conduct market and social research. AMSRO states that the provisions of the Market and Social Research Privacy Code seek to give effect to the APPs in a manner that is tailored to the market and social research context, while providing the public and business community with the assurances needed to encourage informed and willing participation in market and social research activities.

Methods of collecting information in market and social research include postal or mail surveys, e-mail surveys, internet surveys, telephone surveys, door-to-door surveys, central location (e.g. shopping centre) surveys, observational techniques, desk research, and the recruitment and conduct of group discussions (e.g. focus groups), in depth interviews and series of interviews with online panels.

Market and social research is consent-based: mandatory provision of personal information from and about survey participants, respondents or subjects is not market and social research within the scope of this code.

Market and social research differ from other forms of information gathering in that the information is not to be used or disclosed either to support measures or decisions with respect to the particular individual, without the express consent of that individual, or in a manner that could result in any serious consequence (including substantial damage or distress) for the particular individual.

Part 2 of the Market and Social Research Privacy Code sets out how the APPs in the Privacy Act are to be applied and complied with by AMSRO members in relation to the collection, retention, use and disclosure of personal information about the subjects of and participants in market and social research (referred to in this Market and Social Research Privacy Code as identifiable research information). The subjects/participants are any individual about or from whom any information is sought, collected, retained, used and/or disclosed by a research organisation for the purposes of research (research subjects).

The Market and Social Research Privacy Code imposes some additional requirements to the requirements of the APPs. These obligations reflect the fact that participation by research subjects in market and social research as carried out by AMSRO members is always voluntary; that market and social researchers are generally not interested in making use of the identity of research participants and that they use and disclose the information collected only for research purposes.

Part 5 of the Market and Social Research Privacy Code also includes monitoring and reporting requirements.

The Market and Social Research Privacy Code differs from the Previous Code by:

  • adding references to the Notifiable Data Breach scheme including requirements that businesses covered by the Code:
  • notify AMSRO (as Code Administrator) of any notifications made to the OAIC of an ‘eligible data breach’ as defined in the Privacy Act, and
  • notify AMSRO of any serious data breach (whether or not a notifiable eligible data breach) that demonstrates a significant vulnerability of other research organisations in the handling of identifiable research information
  • clarifying that AMSRO will conduct an annual feedback review by making enquiries of research organisations in relation to issues or concerns that research organisations have experiences in relation to or within the scope of the operation the Market and Social Research Privacy Code during the year in review
  • making minor textual amendments throughout the Code to improve clarity and comprehension
  • inserting a new definition of ‘direct marketing’
  • removing references to the Australian Market and Social Research Society Code of Professional Behaviour.

 

Background on the Previous Code

An APP code may be developed by an APP code developer (either on their own initiative or following a request from the Commissioner) or by the Commissioner.

AMSRO developed the Previous Code in accordance with section 26E(1) of the Privacy Act. The Previous Code was registered on 28 November 2014.

APP codes do not replace the APPs but operate in addition to the requirements of the APPs. An APP code must set out how one or more of the APPs are to be applied or complied with. An APP code may also deal with other relevant matters and may impose additional requirements to those imposed by the APPs, so long as the additional requirements are not contrary to, or inconsistent with, the APPs. 

An APP entity that is bound by a registered APP code must not do an act, or engage in a practice, that breaches the registered APP code. A breach of a registered APP code will be an interference with privacy by the entity under section 13 of the Privacy Act and subject to investigation by the Commissioner under Part 5 of the Privacy Act.

Any APP code that is registered will be a disallowable legislative instrument.

 

Statement of compatibility with human rights

Subsection 9(1) of the Human Rights (Parliamentary Scrutiny) Act 2011 requires the rule-maker in relation to a legislative instrument to which section 42 (disallowance) of the Legislation Act applies to cause a statement of compatibility to be prepared in respect of that legislative instrument.

The statement of compatibility set out below has been prepared to meet that requirement.

 

Commencement and period in force

Under subsection 26J(7) of the Privacy Act, if the Commissioner approves a variation, the variation comes into effect on the day specified in the approval, which must not be before the day on which the APP code, as varied, is included on the Codes Register. Under s 26B of the Privacy Act, the APP code, as varied, is a legislative instrument once it is included on the Codes Register.

The Market and Social Research Privacy Code was included on the Codes Register on 1 March 2021. It commences on 22 March 2021 and will remain in force until it is repealed.

The Market and Social Research Privacy Code must be periodically reviewed as stated in Part 4 (Review) of the Code.

 

Consultation

The Commissioner has considered the consultation process undertaken by AMSRO as the Code Administrator.

AMSRO published a review draft of the Market and Social Research Privacy Code for public consultation on 11 December 2019, together with an explanatory statement prepared by the independent reviewer. The explanatory statement summarised the purpose and scope of the review of the Previous Code and the changes that were proposed to be made to that code. The public consultation period remained open until 17 January 2020. Submissions received by AMSRO were then taken into account by the independent reviewer in making recommendations for further revision of the review draft and by AMSRO in considering the independent reviewer’s report and proposed revisions to the review draft. A further review draft and the independent reviewer’s report were then provided to the Office of the Australian Information Commissioner (OAIC). Revisions to that further review draft were made to address comments made by the OAIC and produce the Market and Social Research Privacy as now included on the Codes Register.

The Commissioner is satisfied, for the reasons set out above, that adequate consultation has occurred.

 

Reasons for decision to approve the variation of the Previous Code and register the Market and Social Research Privacy Code (as varied)

In approving AMSRO’s application for variation of the Previous Code, the Commissioner has had regard to subsections 26J(4) and 26J(5) of the Privacy Act and the OAIC’s Guidelines for developing codes.

Under subsection 26J(4), before deciding whether to approve a variation, the Commissioner must:

(a)   make a draft of the variation publicly available (paragraph 26J(4)(a))

(b)   consult any person the Commissioner considers appropriate about the variation (paragraph 26J(4)(b)), and

(c)   consider the extent to which members of the public have been given an opportunity to comment on the variation (paragraph 26J(4)(c)).

In making the decision, the Commissioner considered that:

  • the requirement set out in paragraph 26J(4)(a) of the Privacy Act had been met as a draft of the Market and Social Research Privacy Code was published on the OAIC’s website from 22 December 2021.
  • the requirements set out in paragraph 26J(4)(b) of the Privacy Act, the Guidelines for developing codes and section 17 of the Legislation Act 2003 (Legislation Act) have been met as sufficient consultation on the Market and Social Research Privacy Code had taken place (as outlined above).
  • the requirement set out in paragraph 26J(4)(c) of the Privacy Act had been met as AMSRO and the independent reviewer conducted a public consultation process from 11 December 2019 to 17 January 2019.  

Under s 26J(5), the Commissioner may consider the matters specified in any relevant guidelines made under s 26V of the Privacy Act in deciding whether to approve a variation. The Commissioner is satisfied that the Market and Social Research Privacy Code adequately addresses those criteria.

 

Explanation of sections

Section 3 (Preamble) of the code provides background as to the Market and Social Research Privacy Code’s intended operation.

Section 3 notes that AMSRO’s primary objective is to protect and promote the research, data and insights sector and that in AMSRO’s view, the long-term success of the sector depends upon the willing cooperation of the public and business community, which is based upon confidence that the work of the sector is carried out honestly, objectively and without unwelcome intrusion or disadvantage to participants.

Section 3 also notes that provisions of this code seek to give effect to the APPs in a manner that is tailored to the research context, while providing the public and business community with the assurances needed to encourage informed and willing participation in market and social research activities. Section 3 further states that the code imposes some additional requirements to the requirements of the APPs. These obligations reflect the fact that participation by research subjects in market and social research as carried out by AMSRO members is always voluntary; that market and social researchers are generally not interested in making use of the identity of research participants and that they use and disclose the information collected only for research purposes.

Section 5 (Definitions) defines certain terms used in the code.

The objectives of the code are set out in section 6 are:

  • to set out how the APPs in the Privacy Act are to be applied and complied with by AMSRO members in the conduct of market and social research;
  • to facilitate the protection of research information about identifiable individuals being the participants or subjects of market and social research as provided by, or held in relation to, those participants or those subjects; and
  • to enable quality research to be carried out, so as to provide accurate information to government, commercial and not for profit organisations to support their decision-making processes.

Section 8 (Eligibility and Coverage) of the Market and Social Research Privacy Code states that subscription to this code is a requirement of AMSRO membership, regardless of a research organisation’s size or annual turnover. Organisations that are not members of AMSRO are not eligible to subscribe to this code. This is because AMSRO is only empowered to carry out the monitoring, reporting and compliance functions, as set out in Part 5 of the code, in respect of AMSRO members.

Part 2 sets out how the APPs apply to conduct by research organisations of market and social research. To facilitate cross-comparison by research organisations bound by this code with provisions of the APPs (which continue to apply to those research organisations), the order of sections in Part 2 matches the APPs. Additional requirements to those stated in the APPs are identified as such and include:

  • the additional matters that a research organisation bound by the Market and Social Research Privacy Code must notify an individual participating in market research about, and the timeframe for providing that notice (section 13A)
  • the circumstances under which a research organisation bound by the Market and Social Research Privacy Code can use and disclose certain personal information (section 14A)
  • the specific purposes which a research organisation bound by the Market and Social Research Privacy Code can rely upon to permit the retention of personal information (subsection 19A(1))
  • the steps that a research organisation bound by the Market and Social Research Privacy Code must take to de-identify certain personal information (subsection 19A(2))
  • when a research organisation bound by the Market and Social Research Privacy Code is permitted to retain certain personal information (subsection 19A(3))
  • the reasonable steps a research organisation bound by the Market and Social Research Privacy Code must take to ensure that certain personal information that it discloses is protected (paragraphs 19A(4)(a) – (c))
  • a requirement to destroy or de-identify identifiable research information on request (section 21A)
  • limiting circumstances when a research organisation bound by the Market and Social Research Privacy Code is not required to comply with a request to destroy or de-identify identifiable research information (subsection 19A(1)).

Part 3 of the Market and Social Research Privacy Code addresses governance. The Code Administrator for this code is AMSRO, through the AMSRO Secretariat and under direction of the AMSRO Board. AMSRO has also established a Privacy Compliance Committee, comprising an independent chair, at least two industry representatives and one consumer representative, which meets at least twice a year. The Privacy Compliance Committee advises the Code Administrator about the timing and conduct of the periodic independent review of this code under Part G of the code.

Part 4 of the Market and Social Research Privacy Code addresses the requirement for a periodic code review to be conducted by an independent code reviewer and the process for that review. Pursuant to subsection 24(3) of Part 4, there must be a review of this code at least every five years, but the Code Administrator may commission a review at any time: for example, if regular monitoring indicates a lack of compliance with this code, or if the Code Administrator becomes aware of systemic issues that would justify a review.

Part 5 of the code provides for transparency, monitoring, oversight and reporting as to compliance with the code. 

Pursuant to subsection 28(1) of Part 5, research organisations must report annually, by 31 August, to the Code Administrator, on the number, nature and outcomes of any complaints received about breaches of the code.

Pursuant to subsection 28(2) of Part 5, research organisations must report systemic issues in relation to their compliance with this code, or serious and repeated breaches of the code, to the Commissioner as soon as they become aware of them.

Pursuant to subsection 28(5) of Part 5, the Code Administrator must monitor compliance by research organisations with the code and will investigate serious and repeated breaches and systemic issues about code compliance.

Pursuant to subsection 28(6) of Part 5, the Code Administrator must publish an Annual Report on the operation of this Code and make it available to the Commissioner and publicly, including online.

Pursuant to subsection 28(7) of Part 5, the Code Administrator must report systemic issues or serious and repeated breaches of this Code to the Commissioner as soon as the Code Administrator becomes aware of them.

Section 29 of Part 5 address handling by the Code Administrator of conduct by a research organisation that, in the AMSRO Board’s opinion, constitutes seriously improper conduct in relation to the code. The AMSRO Board must direct the Code Administrator to notify the research organisation of the conduct. Within seven business days of receipt of notification by the Code Administrator of an opinion by the AMSRO Board concerning seriously improper conduct by the research organisation, the research organisation must take all reasonable steps to rectify the seriously improper conduct, and notify the Code Administrator of the steps taken to rectify the seriously improper conduct. If a final notice in relation to that conduct is not complied with, AMSRO may take further remedial action against the research organisation, including suspension or expulsion from membership of AMSRO. These misconduct provisions operate independently of the complaint provisions of the Privacy Act and the enforcement role of the Commissioner, and do not limit the Code Administrator’s obligation, pursuant to subsection 28(7) of Part 5 of the code, to report systemic issues or serious and repeated breaches of this code to the Commissioner as soon as the Code Administrator becomes aware of them.


STATEMENT OF COMPATIBILITY FOR A DISALLOWABLE LEGISLATIVE INSTRUMENT THAT RAISES HUMAN RIGHTS ISSUES

 

Statement of Compatibility with Human Rights

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

 

Privacy (Market and Social Research) Code 2021

Issued by the authority of the Australian Information Commissioner (Commissioner) under the Privacy Act 1988 (Privacy Act). 

This Disallowable Legislative Instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

 

Overview of the Privacy (Market and Social Research) Code 2021

The Privacy (Market and Social Research) Code 2021 (the Market and Social Research Privacy Code), as varied, is a registered Australian Privacy Principle (APP) code for the purposes of the Privacy Act. The Market and Social Research Privacy Code repeals and replaces the Privacy (Market and Social Research) Code 2014 (the Previous Code) varied under subsection 26J(6) of the Privacy Act.

The Association of Market and Social Research Organisations ABN 20 107 667 398 (AMSRO) is the Code Administrator under the Market and Social Research Privacy Code.  

APP codes do not replace the Australian Privacy Principles (APPs), but operate in addition to the requirements of the APPs. An APP code must set out how one or more of the APPs are to be applied or complied with. An APP code may also deal with other relevant matters, and may impose additional requirements to those imposed by the APPs, so long as the additional requirements are not contrary to, or inconsistent with, the APPs. 

An APP entity that is bound by a registered APP code must not do an act, or engage in a practice, that breaches the registered APP code. A breach of a registered APP code will be an interference with privacy by the entity under section 13 of the Privacy Act and subject to investigation by the Commissioner under Part 5 of the Privacy Act.

The Market and Social Research Privacy Code sets out how APP entities that are AMSRO members are to apply and comply with the APPs and sets out the period during which the code is in force.

The policy objectives of the Market and Social Research Privacy Code are set out in section 6. They include:

  • To set out how the APPs in the Privacy Act are to be applied and complied with by AMSRO members in the conduct of market and social research
  • To facilitate the protection of research information about identifiable individuals being the participants or subjects of market and social research as provided by, or held in relation to, those participants or those subjects; and
  • To enable quality research to be carried out, so as to provide accurate information to government, commercial and not for profit organisations to support their decision-making processes.

The Market and Social Research Privacy Code differs from the Previous Code by:

  • adding references to the Notifiable Data Breach scheme including requirements that businesses covered by the Code:
  • notify AMSRO (as Code Administrator) of any notifications made to the OAIC of an ‘eligible data breach’ as defined in the Privacy Act, and
  • notify AMSRO of any serious data breach (whether or not a notifiable eligible data breach) that demonstrates a significant vulnerability of other research organisations in the handling of identifiable research information
  • clarifying that AMSRO will conduct an annual feedback review by making enquiries of research organisations in relation to issues or concerns that research organisations have experiences in relation to or within the scope of the operation the Market and Social Research Privacy Code during the year in review
  • making minor textual amendments throughout the Code to improve clarity and comprehension
  • inserting a new definition of ‘direct marketing’
  • removing references to the Australian Market and Social Research Society Code of Professional Behaviour.

 

Human rights implications

The Market and Social Research Privacy Code, as varied, engages the right to privacy in Article 17 of the International Covenant on Civil and Political Rights. Article 17 provides that no one shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home or correspondence, nor to unlawful attacks on his or her honour and reputation, and that everyone has the right to the protection of the law against such interference or attacks. 

The right to privacy is positively affected by the Market and Social Research Privacy Code. 

The Market and Social Research Privacy Code protects against the arbitrary interference with privacy, and advances the right to the protection of the law against such interference by:

  • setting out how the APPs in Schedule 1 of the Privacy Act are to be applied and complied with in the market and social research industry (Part 2)
  • introducing additional privacy enhancing requirements for research organisations to apply in the market and social research industry when handling personal information, including:
    • the additional matters that a research organisation bound by the Market and Social Research Privacy Code must notify an individual participating in market research about, and the timeframe for providing that notice (section 13A);
    • the circumstances under which a research organisation bound by the Market and Social Research Privacy Code can use and disclose certain personal information (section 14A);
    • the specific purposes which a research organisation bound by the Market and Social Research Privacy Code can rely upon to permit the retention of personal information (subsection 19A(1));
    • the steps that a research organisation bound by the Market and Social Research Privacy Code must take to de-identify certain personal information (subsection 19A(2));
    • when a research organisation bound by the Market and Social Research Privacy Code is permitted to retain certain personal information (subsection 19A(3));
    • the reasonable steps a research organisation bound by the Market and Social Research Privacy Code must take to ensure that certain personal information that it discloses is protected (paragraphs 19A(4)(a)-(c)));
    • a requirement to destroy or de-identify identifiable research information on request (section 21A);
    • limiting circumstances when a research organisation bound by the Market and Social Research Privacy Code is not required to comply with a request to destroy or de-identify certain personal information (subsection 19A(1));
    • providing for additional transparency, monitoring, oversight and reporting as to compliance (Part 5).

 

Conclusion

The Market and Social Research Privacy Code is compatible with human rights because it advances the protection of human rights by supplementing and strengthening the APPs through the introduction of additional, privacy enhancing requirements for the handling of personal information by the entities that it binds.

 

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.