Privacy (Private Sector) Amendment Regulations 2007 (No. 2)

Administered by Attorney-General's Department

Legislation au F2007L01763 Regulations Not in force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

 

Select Legislative Instrument 2007 No. 153

 

Issued by the Authority of the Attorney-General

 

Privacy Act 1988

 

Privacy (Private Sector) Amendment Regulations 2007 (No. 2)

The Privacy Act 1988 (the Act) establishes, among other things, the National Privacy Principles (NPPs) which regulate the collection, use, disclosure and storage of personal information by private sector organisations.

The primary purpose of the Regulations is to allow greater access to Centrelink records, in order to determine whether a person is entitled to receive a service or assistance, or is entitled to early release of superannuation on the grounds of hardship.

NPP 7.2 provides that a private sector organisation must not use or disclose an identifier assigned to an individual by a Commonwealth agency, or by an agent or contracted service provider to that agency, except in specified circumstances.  These include where the use or disclosure is by a prescribed organisation of a prescribed identifier in prescribed circumstances (paragraph (c) of NPP 7.2).

Subsection 100(1) of the Act provides that the Governor-General may make regulations, not inconsistent with the Act, prescribing matters required or permitted by the Act to be prescribed, or necessary or convenient to be prescribed for carrying out or giving effect to the Act.

In determining the need for a Regulation under section 100 of the Act, Centrelink has consulted the Office of the Privacy Commissioner and the Attorney-Generals Department.

The Privacy (Private Sector) Regulations 2001 prescribe exceptions to NPP 7.2 for the purpose of accessing the Centrelink Confirmation eServices.

Centrelink’s Confirmation eServices comprises three distinct services:  Customer Confirmation; Income Confirmation; and Superannuation Confirmation.  The purpose of these amendment Regulations was to insert 20 additional organisations into the lists of prescribed organisations allowed to use and disclose the Centrelink Customer Reference Number for the purpose of making a Customer Confirmation, Income Confirmation or Superannuation Confirmation enquiry.

The release of Centrelink customers’ information through the Centrelink Confirmation eServices will only occur with the customer’s consent.  In addition, the use and disclosure of the Customer Reference Number by these private sector organisations is in each case for the benefit of the individual concerned.  It removes the need for customers to go into a Centrelink office to obtain written proof of their eligibility and verification will occur on-line in real time, providing up to date eligibility information.

Details of the Regulations are set out in the Attachment.  The lists in the Regulations have been renumbered and the 20 additional organisations inserted at items 3 and 8 of Part 1 of Schedule 3, items 13, 28, 33, 44, 60, 62, 64, 68, 73, 74, 75, 79, 81, 92 and 98 of Schedule 4, and items 5, 7 and 19 of Schedule 5.  There have also been some minor amendments to the names of some prescribed organisations.

The Regulations commenced on the day after they were registered.


ATTACHMENT

PRIVACY (PRIVATE SECTOR) AMENDMENT REGULATIONS 2007 (No. 2)

Regulation 1 describes how the Regulations are to be cited.

Regulation 2 provides that the Regulations commence on the day after they are registered.

Regulation 3 provides that the Privacy (Private Sector) Regulations 2001 (the Principal Regulations) are amended in accordance with Schedule 1 to the Regulations.

Schedule 1, Item 1 substitutes the list in Part 1 of Schedule 3 to the Principal Regulations.

The substituted Part 1 of Schedule 3 renumbers the listed organisations and includes two additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making a Customer Confirmation enquiry at items 3 and 8 of Schedule 3, Part 1. 

The substitute Part 1 also makes an amendment to reflect a change in name of a prescribed organisation.  The previous item 22 ‘Powerdirect Australia Pty Ltd’ is changed to ‘AGL Sales (Queensland Electricity) Pty Ltd’ and renumbered as item 1.

Schedule 1, Item 2 substitutes the list in Schedule 4 to the Principal Regulations.

The substituted Schedule 4 renumbers the listed organisations and includes 15 additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making an Income Confirmation enquiry at items 13, 28, 33, 44, 60, 62, 64, 68, 73, 74, 75, 79, 81, 92 and 98 of Schedule 4. 

The substituted Schedule 4 also makes a minor amendment to the name of one of the prescribed organisations.

Schedule 1, Item 3 substitutes the list in Schedule 5 to the Principal Regulations.

The substituted Schedule 5 renumbers the listed organisations and includes three additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making a Superannuation Confirmation enquiry at items 5, 7 and 19 of Schedule 5. 

The substituted Schedule 5 also makes minor amendments to the names of some of the prescribed organisations.

Overview

The Privacy (Private Sector) Amendment Regulations 2007 (No. 2) were enacted to amend the Privacy (Private Sector) Regulations 2001 in order to facilitate greater access to Centrelink records for specified purposes, such as determining entitlement to services or assistance and early release of superannuation on hardship grounds. This was achieved by expanding the list of prescribed organisations allowed to use and disclose the Centrelink Customer Reference Number for making Customer Confirmation, Income Confirmation, or Superannuation Confirmation enquiries, under certain conditions and with the customer's consent. The primary objective of these amendments was to streamline verification processes by enabling real-time online checks, thereby reducing the necessity for customers to visit Centrelink offices. The amendments were made under the authority of the Attorney-General and were designed to align with the National Privacy Principles set out in the Privacy Act 1988, ensuring that personal information is handled appropriately and securely.

Scope and Application

The Privacy (Private Sector) Amendment Regulations 2007 (No. 2) amends the Privacy (Private Sector) Regulations 2001 to facilitate greater access to Centrelink records by allowing specific private sector organisations to use and disclose Centrelink Customer Reference Numbers for purposes such as customer, income, and superannuation confirmations. These regulations apply to private sector organisations listed in the amended schedules, permitting them to access Centrelink records under certain conditions, provided that such access is with the customer's consent and is for the individual's benefit. This regulatory amendment ensures that the use and disclosure of personal information adhere to the National Privacy Principles (NPPs) outlined in the Privacy Act 1988, specifically under NPP 7.2, which governs the use and disclosure of identifiers assigned by Commonwealth agencies. The changes introduced by the Regulations are confined to the specific organisations listed in Schedules 3, 4, and 5, and they came into effect on the day after they were registered. These amendments were made in consultation with the Office of the Privacy Commissioner and the Attorney-General’s Department, ensuring compliance with the overarching legislative framework provided by the Privacy Act 1988.

Key Provisions

The Privacy (Private Sector) Amendment Regulations 2007 (No. 2) primarily aim to expand the list of organisations permitted to use and disclose Centrelink Customer Reference Numbers for specific purposes, as outlined in the National Privacy Principles (NPPs). These amendments, detailed in the schedules, allow additional private sector entities to access Centrelink records to verify eligibility for services, assistance, or early release of superannuation on the grounds of hardship (Schedule 1, Item 1-3). The amended regulations specify the circumstances under which these organisations can access and use this information, ensuring it is done with the customer’s consent and for their benefit (Schedule 1, Item 1-3). Under the new regulations, certain private sector organisations are now permitted to use and disclose Centrelink Customer Reference Numbers for Customer Confirmation, Income Confirmation, and Superannuation Confirmation services. This includes 20 additional organisations that have been inserted into the lists in Schedule 3, Schedule 4, and Schedule 5 of the Principal Regulations. Each of these organisations is now a prescribed entity under NPP 7.2, allowing them to access and use this information for the specified purposes, provided they have the customer's consent and the use is for the individual's benefit (Schedule 1, Item 1-3). The Privacy (Private Sector) Amendment Regulations 2007 (No. 2) impose specific obligations on the listed organisations to ensure compliance with the NPPs. These organisations must obtain the customer's consent before accessing their Centrelink Customer Reference Numbers and use the information solely for the purposes permitted under the regulations (Schedule 1, Item 1-3). Additionally, the organisations must ensure the information is used in a way that benefits the individual, such as verifying their eligibility for services or assistance, and that the use is done in real-time to provide up-to-date information (Schedule 1, Item 1-3). Breaches of the Privacy Act 1988 and the regulations can result in significant consequences. Under section 137 of the Act, an organisation found guilty of an offence may face penalties of up to $210,000 for a body corporate and up to $42,000 for an individual. Additionally, the Act provides for civil penalties, which can include compensation for any loss or damage suffered by the individual whose information was misused. The Act also allows for corrective action by the Office of the Australian Information Commissioner, which can include requiring the organisation to take specific steps to rectify the breach (Schedule 1, Item 1-3).

Legal classification tags

Area of Law
Privacy Law
Instrument
Regulation
Concepts
Definitions & Interpretation
Reporting & Disclosure Obligations
Compliance Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.