Privacy (Private Sector) Amendment Regulations 2007 (No. 4)

Administered by Attorney-General's Department

Legislation au F2007L03786 Regulations Not in force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

 

Select Legislative Instrument 2007 No. 296

 

Issued by the Authority of the Attorney-General

 

Privacy Act 1988

 

Privacy (Private Sector) Amendment Regulations 2007 (No. 4)

The Privacy Act 1988 (the Act) establishes, among other things, the National Privacy Principles (NPPs) which regulate the collection, use, disclosure and storage of personal information by private sector organisations.

The primary purpose of the Regulations is to allow greater access to Centrelink records, in order to determine whether a person is entitled to receive a service or assistance, or is entitled to early release of superannuation on the grounds of hardship.

NPP 7.2 provides that a private sector organisation must not use or disclose an identifier assigned to an individual by a Commonwealth agency, or by an agent or contracted service provider to that agency, except in specified circumstances.  These include where the use or disclosure is by a prescribed organisation of a prescribed identifier in prescribed circumstances (paragraph (c) of NPP 7.2).

Subsection 100(1) of the Act provides that the Governor-General may make regulations, not inconsistent with the Act, prescribing matters required or permitted by the Act to be prescribed, or necessary or convenient to be prescribed for carrying out or giving effect to the Act.

In determining the need for a Regulation under section 100 of the Act, Centrelink has consulted the Office of the Privacy Commissioner and the Attorney-Generals Department.

The Centrelink Customer Reference Number is an identifier for the purposes of NPP 7.  The Privacy (Private Sector) Regulations 2001 prescribe as an exception to the prohibition in NPP 7.2, organisations permitted to use the Centrelink Customer Reference Number for the purpose of accessing the Centrelink Confirmation eServices.

Centrelink’s Confirmation eServices comprises three distinct services:  Customer Confirmation; Income Confirmation; and Superannuation Confirmation.  These amendment Regulations insert 27 additional organisations into the lists of prescribed organisations allowed to use and disclose the Centrelink Customer Reference Number for the purpose of making a Customer Confirmation, Income Confirmation or Superannuation Confirmation enquiry.

The release of Centrelink customers’ information through the Centrelink Confirmation eServices will only occur with the customer’s consent.  In addition, the use and disclosure of the Customer Reference Number by these private sector organisations is in each case for the benefit of the individual concerned.  It removes the need for customers to go into a Centrelink office to obtain written proof of their eligibility and verification will occur on-line in real time, providing up to date eligibility information.

Details of the Regulations are set out in the Attachment.  The lists in the Regulations have been renumbered and the 27 additional organisations inserted at items 3, 7, 27 and 32 of Part 1 of Schedule 3, items 10, 28, 32, 38, 49, 54, 64, 71, 76, 78, 84, 85, 91, 92, 103, 110, 120 and 130 of Schedule 4, and items 1, 4, 24, 27 and 30 of Schedule 5.  There have also been some minor amendments to the names of some prescribed organisations and the deletion of a prescribed organisation who no longer requires use or disclosure of a Centrelink Customer Reference Number.

The Regulations commenced on the day after they were registered.


ATTACHMENT

PRIVACY (PRIVATE SECTOR) AMENDMENT REGULATIONS 2007
(NO. 4)

Regulation 1 describes how the Regulations are to be cited.

Regulation 2 provides that the Regulations commence on the day after they are registered.

Regulation 3 provides that the Privacy (Private Sector) Regulations 2001 (the Principal Regulations) are amended in accordance with Schedule 1 to the Regulations.

Schedule 1, Item 1 substitutes the list in Part 1 of Schedule 3 to the Principal Regulations.

The substituted Part 1 of Schedule 3 renumbers the listed organisations and includes four additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making a Customer Confirmation enquiry at items 3, 7, 27 and 32 of Schedule 3, Part 1. 

The substituted Part 1 also makes an amendment to reflect a change in name of a prescribed organisation.  The previous item 13Energy Australia Pty Ltd & I Power Pty Ltd’ is changed to ‘IPOWER 2 Pty Ltd & IPOWER Pty Ltd’ and renumbered as item 18. 

The substituted Part 1 also makes an amendment to delete a prescribed organisation which no longer requires use or disclosure of the Centrelink Customer Reference Number for the purpose of making a Customer Confirmation enquiry.  The previous item 16 ‘Hagi Hashi, Abdirahman Abdullahi’ is deleted.

The substituted Part 1 also makes a minor amendment to the name of one of the prescribed organisations.

Schedule 1, Item 2 substitutes the list in Schedule 4 to the Principal Regulations.

The substituted Schedule 4 renumbers the listed organisations and includes 18 additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making an Income Confirmation enquiry at items 10, 28, 32, 38, 49, 54, 64, 71, 76, 78, 84, 85, 91, 92, 103, 110, 120 and 130 of Schedule 4. 

The substituted Schedule 4 also makes a minor amendment to the name of one of the prescribed organisations.

Schedule 1, Item 3 substitutes the list in Schedule 5 to the Principal Regulations.

The substituted Schedule 5 renumbers the listed organisations and includes five additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making a Superannuation Confirmation enquiry at items 1, 4, 24, 27 and 30 of Schedule 5. 

Overview

The Privacy (Private Sector) Amendment Regulations 2007 (No. 4) were enacted to amend the Privacy (Private Sector) Regulations 2001, thereby expanding the list of organisations permitted to use and disclose the Centrelink Customer Reference Number for the purpose of accessing Centrelink Confirmation eServices. This was achieved under the authority of the Attorney-General and in accordance with subsection 100(1) of the Privacy Act 1988. The primary objective of these amendments is to streamline the process for Centrelink customers to verify their eligibility for services or assistance, including early release of superannuation on grounds of hardship, by facilitating real-time verification through the Centrelink Confirmation eServices. This legislative change ensures that the use and disclosure of Centrelink Customer Reference Numbers by prescribed organisations is done with customer consent and for the benefit of the individual concerned, thus reducing the need for customers to physically visit Centrelink offices for verification purposes.

Scope and Application

The Privacy (Private Sector) Amendment Regulations 2007 (No. 4) amends the Privacy (Private Sector) Regulations 2001 by expanding the list of prescribed organisations permitted to use the Centrelink Customer Reference Number to access Centrelink Confirmation eServices. These services include Customer Confirmation, Income Confirmation, and Superannuation Confirmation, which facilitate the verification of Centrelink customer eligibility without the need for physical visits to Centrelink offices. The Regulations apply to private sector organisations that are prescribed in the amended schedules, allowing them to use the Centrelink Customer Reference Number for the specified purposes, provided they obtain the customer's consent. The amendments include the addition of 27 organisations to the lists of prescribed entities in various schedules, thereby extending the scope of entities that can access Centrelink records electronically. These Regulations are made under the authority of the Privacy Act 1988 and are designed to streamline the verification process while ensuring compliance with privacy standards.

Key Provisions

The main provisions of the Privacy (Private Sector) Amendment Regulations 2007 (No. 4) under the Privacy Act 1988 are primarily concerned with expanding the list of organisations permitted to use and disclose Centrelink Customer Reference Numbers for specific purposes, as detailed in the National Privacy Principles (NPPs). Section 100(1) of the Act allows the Governor-General to make regulations that are necessary to carry out the Act, and these regulations specifically amend the existing Privacy (Private Sector) Regulations 2001 to include additional organisations that can use Centrelink Customer Reference Numbers for Customer Confirmation, Income Confirmation, and Superannuation Confirmation enquiries. These enquiries are part of the Centrelink Confirmation eServices and are intended to streamline the process of verifying eligibility and entitlements for Centrelink services. The obligations and requirements imposed by these regulations on the parties or entities they govern include obtaining explicit consent from Centrelink customers before accessing their personal information through the Centrelink Confirmation eServices. This ensures that the use and disclosure of personal information are conducted in a manner that respects the privacy of the individuals concerned. Furthermore, these organisations must use the Centrelink Customer Reference Numbers solely for the purpose of making the specified confirmations and must adhere to the privacy standards set forth in the NPPs. This includes ensuring that the use and disclosure of personal information are limited to what is necessary for the intended purpose and that appropriate safeguards are in place to protect the information from unauthorised access or misuse. Failure to comply with the requirements of the Privacy (Private Sector) Amendment Regulations 2007 (No. 4) can result in significant civil and criminal consequences. Under the Privacy Act 1988, any organisation that misuses personal information in a way that contravenes the regulations can be subject to enforcement actions by the Office of the Australian Information Commissioner. Civil penalties for serious or repeated breaches can include fines of up to AUD 1.5 million for corporations and AUD 300,000 for individuals, as specified in the Act. Additionally, criminal penalties may apply in cases of wilful or reckless conduct, leading to fines and/or imprisonment for individuals who are found guilty of breaching the regulations. The precise penalties depend on the severity and intent of the breach, with the maximum penalties clearly outlined in the relevant sections of the Privacy Act 1988.

Legal classification tags

Area of Law
Privacy Law
Instrument
Regulation
Concepts
Definitions & Interpretation
Regulatory Standards
Compliance Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.