Privacy (Private Sector) Amendment Regulations 2002 (No. 1)

Administered by Attorney-General's Department

Legislation au F2002B00105 Regulations Not in force Legislative Instrument

Legislation content

Privacy (Private Sector) Amendment Regulations 2002 (No. 1) 2002 No. 105

EXPLANATORY STATEMENT

STATUTORY RULES 2002 No. 105

Issued by the authority of the Attorney-General

Privacy Act 1988

Privacy (Private Sector) Amendment Regulations 2002 (No. 1)

Subsection 100(1) of the Privacy Act 1988 (the Act) provides that the Governor-General may make regulations prescribing matters required or permitted by the Act to be prescribed; or necessary or convenient to be prescribed for carrying out or giving effect to the Act.

The purpose of the Regulations is to prescribe four New South Wales State Owned Corporations (SOCs) under section 6F of the Act, so that they are subject to the same privacy obligations as private sector organisations. The SOCs prescribed for the purposes of section 6F are set out in Schedule 1 of the Regulations.

The private sector provisions of the Act came into effect on 21 December 2001. The provisions apply to "organisations" as defined in section 6C of the Act. State and Territory authorities, including SOCs, do not fall within the definition of organisation unless they have been incorporated under the Corporations Law.

Under section 6F of the Act, an otherwise exempt State or Territory authority may be prescribed so that the Act applies to it as if it were an organisation. Subsection 6F(3) of the Act provides that before the Governor-General makes a regulation prescribing an authority, the Minister must be satisfied that the relevant State or Territory has requested the authority be prescribed; and consult with the Federal Privacy Commissioner (the Privacy Commissioner) about the desirability of regulating under the Act the collection, holding, use, correction, disclosure and transfer of personal information by the authority.

On 24 October 2001, the Premier of NSW, the Hon Bob Carr MP wrote to the Attorney-General, the Hon Daryl Williams AM QC MP, requesting that four SOCs involved in the retail supply of electricity in NSW be prescribed under section 6F. In accordance with section 6F(3), the Attorney-General wrote to the Privacy Commissioner on 20 February 2002 requesting his views on the proposed regulations. On 6 March 2002, the Deputy Privacy Commissioner, Mr Timothy Pilgrim, replied on behalf of the Privacy Commissioner. The view of the Office of the Federal Privacy Commissioner was that the regulations would be desirable as they would subject SOCs involved in energy retailing to the same privacy obligations as privately owned businesses.

The regulations commence on 1 June 2002.

 

Overview

The Privacy (Private Sector) Amendment Regulations 2002 (No. 1) were enacted to address the gap in privacy obligations for certain State Owned Corporations (SOCs) in the private sector under the Privacy Act 1988. This regulatory measure was introduced by the Attorney-General to ensure that specific New South Wales SOCs involved in the retail supply of electricity are subject to the same privacy standards as private sector organisations. The objective of these regulations is to provide a consistent framework for the collection, use, disclosure, and transfer of personal information across both sectors, thereby aligning the privacy obligations of SOCs with those of private entities. The regulations were formulated following consultations with the Federal Privacy Commissioner and at the request of the Premier of New South Wales, aiming to enhance privacy protections for individuals interacting with these SOCs.

Scope and Application

The Privacy (Private Sector) Amendment Regulations 2002 (No. 1) are subordinate instruments made under the Privacy Act 1988, designed to prescribe certain New South Wales State Owned Corporations (SOCs) so that they are subject to the same privacy obligations as private sector organisations. The primary aim of these regulations is to ensure that SOCs involved in the retail supply of electricity in New South Wales adhere to the privacy provisions outlined in the Act, thereby aligning their practices with those of private entities. The regulations came into effect on 1 June 2002 and apply to the SOCs specified in Schedule 1 of the Regulations. This extension of the Act's application is contingent upon the satisfaction of certain conditions, including the request from the relevant State and consultation with the Federal Privacy Commissioner. As such, the regulations ensure that these SOCs are held to the same standards of privacy compliance as private sector organisations, thereby promoting uniform privacy practices across different sectors.

Key Provisions

The Privacy (Private Sector) Amendment Regulations 2002 (No. 1) (the Regulations) are intended to bring four New South Wales State Owned Corporations (SOCs) under the purview of the Privacy Act 1988 (the Act). This is achieved by prescribing these SOCs under section 6F of the Act (subs 6F(3)), thereby ensuring they adhere to the same privacy obligations as private sector entities. These SOCs, specified in Schedule 1, are involved in the retail supply of electricity in New South Wales. The Regulations aim to align the privacy obligations of these SOCs with those applicable to private sector organisations, thus fostering a uniform approach to privacy protection across both sectors. The Regulations impose several obligations on the prescribed SOCs. Firstly, they must comply with the private sector provisions of the Act, which include obligations related to the collection, use, disclosure, and security of personal information. These obligations are detailed in the Act itself, particularly under Part III which governs the handling of personal information. Additionally, the SOCs must ensure that they have appropriate privacy policies and practices in place to manage personal information effectively and responsibly. This includes providing clear information to individuals about how their personal information will be used and ensuring mechanisms are in place for individuals to access and correct their personal information. Failure to comply with the privacy obligations set out in the Act and the Regulations can result in various consequences. For instance, if a SOC fails to adhere to the privacy obligations, it may face enforcement actions from the Office of the Australian Information Commissioner (OAIC). The OAIC has the authority to issue compliance notices, which require the SOC to take specific actions to rectify non-compliance. Additionally, the OAIC can apply to the Federal Court for orders to enforce compliance, including pecuniary penalties. Under section 13G of the Act, the maximum penalty for serious or repeated breaches can be significant, with fines up to $2,100,000 for corporations. These penalties underscore the importance of strict adherence to the privacy obligations set out in the Act and the Regulations.

Legal classification tags

Area of Law
Privacy Law
Instrument
Regulation
Concepts
Definitions & Interpretation
Compliance Obligations
Reporting & Disclosure Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.