Privacy (Private Sector) Amendment Regulations 2008 (No. 1)

Administered by Department of the Prime Minister and Cabinet

Legislation au F2008L01050 Regulations Not in force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

 

Select Legislative Instrument 2008 No. 60

 

Issued by the Authority of the Cabinet Secretary

 

Privacy Act 1988

 

Privacy (Private Sector) Amendment Regulations 2008 (No. 1)

The Privacy Act 1988 (the Act) establishes, among other things, the National Privacy Principles (NPPs) which regulate the collection, use, disclosure and storage of personal information by private sector organisations.

The primary purpose of the Regulations is to allow greater access to Centrelink records, in order to determine whether a person is entitled to receive a service or assistance, or is entitled to early release of superannuation on the grounds of hardship.

NPP 7.2 provides that a private sector organisation must not use or disclose an identifier assigned to an individual by a Commonwealth agency, or by an agent or contracted service provider to that agency, except in specified circumstances.  These include where the use or disclosure is by a prescribed organisation of a prescribed identifier in prescribed circumstances (paragraph (c) of NPP 7.2).

Subsection 100(1) of the Act provides that the Governor-General may make regulations, not inconsistent with the Act, prescribing matters required or permitted by the Act to be prescribed, or necessary or convenient to be prescribed for carrying out or giving effect to the Act.

In determining the need for a Regulation under section 100 of the Act, Centrelink has consulted with the Privacy Commissioner and the Department of the Prime Minister and Cabinet.  The Privacy Commissioner noted the request for regulations and did not raise any concerns.  The Department supports the amending Regulations.

The Centrelink Customer Reference Number is an identifier for the purposes of NPP 7.  The Privacy (Private Sector) Regulations 2001 prescribe as an exception to the prohibition in NPP 7.2, organisations permitted to use the Centrelink Customer Reference Number for the purpose of accessing the Centrelink Confirmation eServices.

Centrelink’s Confirmation eServices comprises three distinct services:  Customer Confirmation; Income Confirmation; and Superannuation Confirmation.  These amendment Regulations insert 21 additional organisations into the lists of prescribed organisations allowed to use and disclose the Centrelink Customer Reference Number for the purpose of making a Customer Confirmation, Income Confirmation or Superannuation Confirmation enquiry.

The release of Centrelink customers’ information through the Centrelink Confirmation eServices will only occur with the customer’s consent.  In addition, the use and disclosure of the Customer Reference Number by these private sector organisations is in each case for the benefit of the individual concerned.  It removes the need for customers to go into a Centrelink office to obtain written proof of their eligibility and verification will occur on-line in real time, providing up to date eligibility information.

Details of the Regulations are set out in the Attachment.  The lists in the Regulations have been renumbered and the 21 additional organisations inserted at items 14, 27, 28 and 32 of Part 1 of Schedule 3, items 9, 14, 23, 33, 42, 54, 69, 78, 86, 87, 119, 122, 130, 136 and 139 of Schedule 4, and items 2 and 13 of Schedule 5.  There have also been some minor amendments to the names of three prescribed organisations.

The Regulations commenced on the day after they were registered.


ATTACHMENT

PRIVACY (PRIVATE SECTOR) AMENDMENT REGULATIONS 2008
(NO. 1)

Regulation 1 describes how the Regulations are to be cited.

Regulation 2 provides that the Regulations commence on the day after they are registered.

Regulation 3 provides that the Privacy (Private Sector) Regulations 2001 (the Principal Regulations) are amended in accordance with Schedule 1 to the Regulations.

Schedule 1, Item 1 substitutes the list in Part 1 of Schedule 3 to the Principal Regulations.

The substituted Part 1 of Schedule 3 renumbers the listed organisations and includes four additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making a Customer Confirmation enquiry at items 14, 27, 28 and 32 of Schedule 3, Part 1. 

Schedule 1, Item 2 substitutes the lists of organisations in Schedule 4 and Schedule 5 to the Principal Regulations.

The substituted Schedule 4 renumbers the listed organisations and includes 15 additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making an Income Confirmation enquiry at items 9, 14, 23, 33, 42, 54, 69, 78, 86, 87, 119, 122, 130, 136 and 139 of Schedule 4. 

The substituted Schedule 5 renumbers the listed organisations and includes two additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making a Superannuation Confirmation enquiry at items 2 and 13 of Schedule 5. 

The substituted Schedule 5 also makes an amendment to reflect name changes for the following prescribed organisations:

a)      previous item 13 ‘Mercer Human Resource Consulting Pty Ltd’ is changed to ‘Mercer (Australia) Pty Ltd’ and renumbered as item 15; 

b)     previous item 31 ‘The Trustee for Savings & Loans Members Super Fund’ is changed to ‘The Trustee for Savings & Loans Members Superannuation Fund’ and renumbered as item 33; and

c)      previous item 32 ‘Zurich Master Superannuation Fund’ is changed to ‘The Trustee for Zurich Master Superannuation Fund’ and renumbered as item 34.

 

Overview

The Privacy (Private Sector) Amendment Regulations 2008 (No. 1) were enacted to address the need for increased access to Centrelink records to verify entitlements to services or assistance and to facilitate the early release of superannuation due to hardship. This regulation amends the Privacy (Private Sector) Regulations 2001 under the authority granted by the Privacy Act 1988, specifically allowing certain additional organisations to use Centrelink Customer Reference Numbers to access Centrelink Confirmation eServices. The Privacy Act, enacted in 1988, establishes the National Privacy Principles which govern the handling of personal information by private sector organisations, including the use and disclosure of identifiers. The Regulations were issued by the Authority of the Cabinet Secretary and aim to streamline the verification process for Centrelink customers by allowing real-time online confirmation of eligibility, reducing the need for physical visits to Centrelink offices. The amendment was supported by the Privacy Commissioner and the Department of the Prime Minister and Cabinet, ensuring compliance with privacy regulations while facilitating better service delivery.

Scope and Application

The Privacy (Private Sector) Amendment Regulations 2008 (No. 1) amends the Privacy (Private Sector) Regulations 2001 to expand the scope of organisations permitted to use and disclose the Centrelink Customer Reference Number for accessing Centrelink Confirmation eServices. This amendment is grounded in the Privacy Act 1988, which sets out the National Privacy Principles (NPPs) governing the handling of personal information by private sector entities. The primary objective of these regulations is to facilitate access to Centrelink records for determining eligibility for services, assistance, or early release of superannuation on hardship grounds. The regulations specifically target private sector organisations, broadening the list of prescribed entities authorised to use the Centrelink Customer Reference Number for Customer Confirmation, Income Confirmation, and Superannuation Confirmation enquiries, thereby streamlining the verification process and improving service delivery to customers. The Regulations apply nationwide, reflecting a federal approach to privacy and data access regulation, and they do not introduce any new exclusions or exemptions beyond those already specified in the Privacy Act 1988 and the NPPs. The amendments are made under the authority granted by subsection 100(1) of the Act and have been implemented through subordinate legislation to ensure they do not conflict with the overarching principles of the Privacy Act.

Key Provisions

The main operative sections of the Privacy (Private Sector) Amendment Regulations 2008 (No. 1) involve the amendment of existing lists under the Privacy (Private Sector) Regulations 2001. These amendments pertain to organisations that are permitted to use or disclose the Centrelink Customer Reference Number for specific purposes (Schedule 1). Regulation 3 of the Amendment Regulations specifies that the Privacy (Private Sector) Regulations 2001 are amended as per Schedule 1. Schedule 1 then makes specific amendments to Schedules 3, 4, and 5 of the Principal Regulations. These amendments include inserting 21 additional organisations into the lists of prescribed organisations, allowing them to use and disclose the Centrelink Customer Reference Number for Customer Confirmation, Income Confirmation, or Superannuation Confirmation enquiries, respectively. The Regulations also involve minor amendments to the names of some prescribed organisations. The obligations and requirements imposed by these Regulations on the parties involved primarily concern the permitted use and disclosure of the Centrelink Customer Reference Number. The amended lists of prescribed organisations now include 21 additional entities that can use this identifier to access Centrelink’s Confirmation eServices. These organisations must ensure that they use this information solely for the benefit of the individual concerned, and that they obtain the customer's consent before accessing their information. The use and disclosure of the Centrelink Customer Reference Number by these organisations must align with the requirements of the National Privacy Principles, particularly NPP 7.2, which mandates that identifiers assigned by Commonwealth agencies must only be used or disclosed under specified circumstances. The Regulations also impose specific obligations on Centrelink and the prescribed organisations to ensure compliance with privacy standards. Centrelink must ensure that the release of customer information through the Confirmation eServices only occurs with the customer’s consent and that the verification process occurs in real time, providing updated eligibility information. The prescribed organisations must adhere to the terms of their inclusion in the amended lists and ensure that they are using the Centrelink Customer Reference Number for the intended purpose of providing services to individuals, such as confirming eligibility for various benefits and services. Breaches of these Regulations may result in civil or criminal consequences, depending on the nature and severity of the offence. The Privacy Act 1988 provides for various penalties, including substantial fines for organisations that misuse personal information. The exact penalties are not detailed in the Amendment Regulations but are typically aligned with the provisions of the Privacy Act. For example, under section 13G of the Privacy Act, an organisation that contravenes the National Privacy Principles can be subject to civil penalties, with fines that can reach up to $2.1 million for corporations. Additionally, the Privacy Commissioner has the authority to issue infringement notices for less severe breaches, with penalties that can amount to $5,100 for individuals and $25,500 for organisations. The Regulations aim to streamline the verification process for Centrelink customers by allowing authorised organisations to access confirmation services electronically. This not only improves efficiency but also ensures that personal information is handled in compliance with privacy laws. By updating the lists of prescribed organisations, the Regulations facilitate the use of the Centrelink Customer Reference Number in a controlled and authorised manner, thus protecting both the privacy of individuals and the integrity of the verification process.

Legal classification tags

Area of Law
Privacy Law
Instrument
Regulation
Concepts
Definitions & Interpretation
Reporting & Disclosure Obligations
Licensing & Registration

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.