Privacy (Private Sector) Amendment Regulations 2005 (No. 1)

Administered by Attorney-General's Department

Legislation au F2005L04091 Regulations Not in force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

 

Select Legislative Instrument 2005 No. 301

 

PRIVACY (PRIVATE SECTOR) AMENDMENT REGULATIONS 2005 (No. 1)

The Privacy Act 1988 (the Act) establishes, among other things, the National Privacy Principles (NPPs) which regulate the collection, use, disclosure and storage of personal information by private sector organisations.

NPP 7.2 provides that a private sector organisation must not use or disclose an identifier assigned to an individual by a Commonwealth agency, or by an agent or contracted service provider to that agency, except where:

(a)       the use or disclosure is necessary for the organisation to fulfil its obligations to the agency; or

(b)       the use or disclosure is in support of measures detailed in NPP 2.1(e) to 2.1(h) inclusive to lessen or prevent a threat to the health or safety of an individual or the public, is required or authorised by law, or is in support of law enforcement or prosecution activities; or

(c)       the use or disclosure is by a prescribed organisation of a prescribed identifier in prescribed circumstances.

Subsection 100(1) of the Act provides that the Governor-General may make regulations, not inconsistent with the Act, prescribing matters required or permitted by the Act to be prescribed, or necessary or convenient to be prescribed for carrying out or giving effect to the Act.

In determining the need for a Regulation under section 100 of the Act, Centrelink has consulted extensively the Office of the Privacy Commissioner, the Australian Government Solicitor, the AttorneyGeneral's Department and the Department of Family and Community Services.

The purpose of the Regulations is to authorise the use and disclosure of the Customer Reference Number, assigned to individuals by Centrelink, by certain private sector organisations so that they can access the ‘Centrelink Confirmation eService’ for the purpose of determining whether certain individuals are entitled to receive a concession.  These private sector organisations are listed in Schedule 3.

The use and disclosure of the Centrelink Customer Reference Number by each private sector organisation is in each case only for the benefit of the individual concerned.  It enables service providers to access Centrelink’s Confirmation eService, with the customer’s consent, and determine a customer’s eligibility to concessional entitlements.  This removes the need for customers to go into a Centrelink office to get proof of their eligibility for these concessions.  The verification occurs on-line in real time, providing up to date eligibility information.  

Subsection 100(2) of the Act provides that before the Governor-General makes regulations for the purposes of NPP 7.2(c) prescribing an organisation, identifier and circumstances, the Attorney-General must be satisfied that affected agencies have agreed to the use or disclosure, that those agencies have consulted the Privacy Commissioner, and that the use or disclosure can only be for the benefit of the individual concerned. The Attorney-General is satisfied of these matters in relation to the use or disclosure of Customer Reference Numbers by the organisations listed in Schedule 3.

Details of the Regulations are set out in the Attachment.

The Regulations commenced on the day after they were registered.

PRIVACY (PRIVATE SECTOR) AMENDMENT REGULATIONS 2005 (No. 1)

Regulation 1 describes how the Regulations are to be cited.

Regulation 2 provides that the Regulations commence on the day after they are registered.

Regulation 3 provides that the Privacy (Private Sector) Regulations 2001 (the Principal Regulations) are amended in accordance with Schedule 1 of the Regulations.

The Regulations make additions to the Principal Regulations to authorise an exception to National Privacy Principle 7.2 in relation to the use and disclosure of the Customer Reference Number assigned by Centrelink.

Schedule 1, Item 1 defines ‘Centrelink’.

Schedule 1, Item 2 inserts a new exception to National Privacy Principle 7.2 in Part 3 of the Principal Regulations. The new exception authorises the use and disclosure by 24 organisations of the Customer Reference Number assigned by Centrelink for the purpose of accessing the Centrelink Confirmation eService in order to determine whether an individual is entitled to receive a concession.

Schedule 1, Item 3 inserts a new schedule 3 in the Principal Regulations listing the organisations that are able to use or disclose the Customer Reference Number.

 

 

Overview

The Privacy (Private Sector) Amendment Regulations 2005 (No. 1) were introduced to amend the Privacy (Private Sector) Regulations 2001, as required by the Privacy Act 1988. This legislation was enacted to address the need for streamlined processes in verifying eligibility for certain concessions through the use of personal identifiers, specifically the Customer Reference Number assigned by Centrelink. The problem these regulations sought to address was the cumbersome process of individuals needing to visit Centrelink offices to obtain proof of their eligibility for concessions. By enabling certain private sector organisations to access the 'Centrelink Confirmation eService', these regulations facilitate a more efficient and convenient method for determining concession eligibility, thereby benefiting the individual concerned. The regulations were made under the authority of the Privacy Act 1988, with the purpose of ensuring that any use or disclosure of the Customer Reference Number is strictly for the benefit of the individual and in compliance with privacy principles.

Scope and Application

The Privacy (Private Sector) Amendment Regulations 2005 (No. 1) amends the existing Privacy (Private Sector) Regulations 2001 to provide an exception under National Privacy Principle 7.2, specifically for the use and disclosure of Customer Reference Numbers assigned by Centrelink. This amendment applies to private sector organisations listed in Schedule 3 of the Regulations, allowing them to use the Customer Reference Number to access the Centrelink Confirmation eService to verify an individual's eligibility for certain concessions. This is done to streamline the process and reduce the need for customers to physically visit Centrelink offices for proof of eligibility, facilitating a real-time online verification. The Regulations are applicable to specific entities and serve to enable these organisations to act in the interest of the individual concerned, as long as the use or disclosure is in accordance with the stipulated conditions and is approved by Centrelink and the Attorney-General. The Regulations are a subordinate instrument under the Privacy Act 1988 and apply nationally within Australia, extending the scope of the principal Regulations to include the specific exception for the Customer Reference Number.

Key Provisions

The main provisions of the Privacy (Private Sector) Amendment Regulations 2005 (No. 1) are contained within the regulation itself and its schedules. Regulation 1 outlines the title and citation of the Regulations. Regulation 2 states that the Regulations commence on the day after they are registered. Regulation 3 amends the Privacy (Private Sector) Regulations 2001 to include a new exception to National Privacy Principle 7.2. This amendment is detailed in Schedule 1, Item 2, which provides an exception to the general rule prohibiting the use or disclosure of identifiers assigned by Commonwealth agencies. Schedule 1, Item 3 lists the 24 organisations that are permitted to use or disclose the Customer Reference Number assigned by Centrelink for the purpose of accessing the Centrelink Confirmation eService. The Regulations impose obligations on the 24 organisations listed in Schedule 3 to ensure that they use the Centrelink Customer Reference Number only for the specific purpose of accessing the Centrelink Confirmation eService to determine an individual's eligibility for concessions. This use is permissible only with the consent of the individual concerned and must be for the benefit of that individual. The Regulations also require that the use of this identifier is in compliance with the conditions set out in the Privacy (Private Sector) Regulations 2001 and the National Privacy Principles. Any breach of these Regulations may result in civil or criminal consequences. Under the Privacy Act 1988, unauthorised use or disclosure of personal information can result in penalties. For serious or repeated breaches, the maximum penalty can be up to $210,000 for a corporation and $42,000 for an individual, as outlined in section 13G of the Privacy Act. The Regulations also empower the Office of the Privacy Commissioner to take enforcement actions, which may include issuing infringement notices or pursuing legal action against organisations that fail to comply with the requirements of the Act and these Regulations.

Legal classification tags

Area of Law
Privacy Law
Instrument
Regulation
Concepts
Definitions & Interpretation
Prohibited Conduct
Regulatory Standards

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.