Privacy (Private Sector) Amendment Regulations 2008 (No. 2)

Administered by Department of the Prime Minister and Cabinet

Legislation au F2008L03791 Regulations Not in force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

 

Select Legislative Instrument 2008 No. 213

 

Issued by the Authority of the Cabinet Secretary

 

Privacy Act 1988

 

Privacy (Private Sector) Amendment Regulations 2008 (No. 2)

The Privacy Act 1988 (the Act) establishes, among other things, the National Privacy Principles (NPPs) which regulate the collection, use, disclosure and storage of personal information by private sector organisations.

The primary purpose of the Regulations is to allow greater access to Centrelink records, in order to determine whether a person is entitled to receive a service or assistance.

NPP 7.2 provides that a private sector organisation must not use or disclose an identifier assigned to an individual by a Commonwealth agency, or by an agent or contracted service provider to that agency, except in specified circumstances.  These include where the use or disclosure is by a prescribed organisation of a prescribed identifier in prescribed circumstances (paragraph (c) of NPP 7.2).

Subsection 100(1) of the Act provides that the Governor-General may make regulations, not inconsistent with the Act, prescribing matters required or permitted by the Act to be prescribed, or necessary or convenient to be prescribed for carrying out or giving effect to the Act.

In determining the need for a Regulation under section 100 of the Act, Centrelink has consulted with the Privacy Commissioner and the Department of the Prime Minister and Cabinet.  The Privacy Commissioner noted the request for regulations and did not raise any concerns.  The Department supports the amending Regulations.

The Centrelink Customer Reference Number is an identifier for the purposes of NPP 7.  The Privacy (Private Sector) Regulations 2001 prescribe as an exception to the prohibition in NPP 7.2, organisations permitted to use the Centrelink Customer Reference Number for the purpose of accessing the Centrelink Confirmation eServices.

Centrelink’s Confirmation eServices comprises three distinct services:  Customer Confirmation; Income Confirmation; and Superannuation Confirmation.  These amendment Regulations insert 40 additional organisations into the lists of prescribed organisations allowed to use and disclose the Centrelink Customer Reference Number for the purpose of making a Customer Confirmation or Income Confirmation enquiry.

The release of Centrelink customers’ information through the Centrelink Confirmation eServices will only occur with the customer’s consent.  In addition, the use and disclosure of the Customer Reference Number by these private sector organisations is in each case for the benefit of the individual concerned.  It removes the need for customers to go into a Centrelink office to obtain written proof of their eligibility and verification will occur on-line in real time, providing up to date eligibility information.

Details of the Regulations are set out in the Attachment.  The lists in the Regulations have been renumbered and the 40 additional organisations inserted at items 17, 19, 20, 23, 24, 33, 37, 45 and 49 of Part 1 of Schedule 3 and items 3, 5, 8, 21, 26, 33, 35, 36, 37, 44, 63, 65, 70, 77, 92, 95, 106, 107, 109, 118, 119, 124, 129, 135, 136, 143, 148, 152, 158, 163 and 169 of Schedule 4.  There have also been some minor amendments to the names of four prescribed organisations.

The Regulations commenced on the day after they were registered.


ATTACHMENT

Privacy (Private Sector) Amendment Regulations 2008 (No. 2)

Regulation 1 describes how the Regulations are to be cited.

Regulation 2 provides that the Regulations commence on the day after they are registered.

Regulation 3 provides that the Privacy (Private Sector) Regulations 2001 (the Principal Regulations) are amended in accordance with Schedule 1 to the Regulations.

Schedule 1, Item 1 substitutes the list in Part 1 of Schedule 3 to the Principal Regulations.

The substituted Part 1 of Schedule 3 renumbers the listed organisations and includes nine additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making a Customer Confirmation enquiry at items 17, 19, 20, 23, 24, 33, 37, 45 and 49 of Schedule 3, Part 1. 

Schedule 1, Item 2 substitutes the lists of organisations in Schedule 4 and Schedule 5 to the Principal Regulations.

The substituted Schedule 4 renumbers the listed organisations and includes       thirty-one additional organisations as prescribed organisations that may use or disclose the Centrelink Customer Reference Number for the purpose of making an Income Confirmation enquiry at items 3, 5, 8, 21, 26, 33, 35, 36, 37, 44, 63, 65, 70, 77, 92, 95, 106, 107, 109, 118, 119, 124, 129, 135, 136, 143, 148, 152, 158, 163 and 169 of Schedule 4. 

The substitute Schedule 4 would also make an amendment to reflect name changes for the following prescribed organisations:

a)      current item 79 ‘North Coast Community Housing Company Ltd’ would change to ‘The North Coast Community Housing Company Ltd’ and be renumbered as item 140; 

b)     current item 135 ‘Wentworth Area Community Housing Ltd’ would change to ‘Wentworth Community Housing Ltd’ and be renumbered as item 165.

The substituted Schedule 5 makes an amendment to reflect name changes for the following prescribed organisations:

a)      current item 4 ‘Asteron Portfolio Services Ltd’ would change to ‘Suncorp Portfolio Services Ltd’ and be renumbered as item 25; 

b)     current item 6 ‘Australian Skandia Ltd’ would change to ‘Old Mutual Australia Ltd’ and be renumbered as item 19.

 

Overview

The Privacy (Private Sector) Amendment Regulations 2008 (No. 2) were enacted to amend the Privacy (Private Sector) Regulations 2001 under the Privacy Act 1988. This legislative instrument was introduced to address the need for enhanced access to Centrelink records to ascertain eligibility for services and assistance. The regulations aim to facilitate this access by permitting specified private sector organisations to use and disclose Centrelink Customer Reference Numbers for Customer Confirmation and Income Confirmation enquiries, with the customer's consent. This change aims to streamline the process of verifying eligibility by enabling online real-time confirmation, thereby reducing the necessity for customers to visit Centrelink offices. The regulations were developed following consultations with the Privacy Commissioner and the Department of the Prime Minister and Cabinet, with no concerns raised by the Privacy Commissioner and support from the Department. The Privacy (Private Sector) Amendment Regulations 2008 (No. 2) were issued by the authority of the Cabinet Secretary and came into effect the day after their registration. These regulations expand the list of prescribed organisations that can use Centrelink Customer Reference Numbers for specific enquiries, thereby enhancing the efficiency and convenience of accessing Centrelink services. By updating the lists and incorporating minor name changes for certain organisations, the regulations ensure compliance with the National Privacy Principles while facilitating necessary access to personal information for legitimate purposes.

Scope and Application

The Privacy (Private Sector) Amendment Regulations 2008 (No. 2) amends the Privacy (Private Sector) Regulations 2001 under the Privacy Act 1988, primarily to extend the list of organisations authorised to use and disclose the Centrelink Customer Reference Number for Customer Confirmation and Income Confirmation enquiries through Centrelink’s Confirmation eServices. This amendment applies to private sector organisations listed in the schedules of the Regulations, allowing them to access Centrelink records with the consent of the individual, facilitating real-time eligibility verification online without the need for customers to visit Centrelink offices. The Regulations are designed to ensure that the use and disclosure of personal information are conducted in accordance with the National Privacy Principles, particularly NPP 7.2, which restricts the use or disclosure of identifiers unless specific conditions are met. The scope of these Regulations is national, as they operate under the Commonwealth jurisdiction, and they do not create any exclusions or exemptions beyond those specified within the amended lists. The changes in the Regulations came into effect on the day after their registration, thereby extending the application of the existing framework to additional authorised entities.

Key Provisions

The Privacy (Private Sector) Amendment Regulations 2008 (No. 2) (Regulations) amend the Privacy (Private Sector) Regulations 2001 (Principal Regulations) to enhance access to Centrelink records, thereby facilitating the determination of a person's eligibility for services or assistance. Under section 7.2 of the National Privacy Principles (NPPs) in the Privacy Act 1988 (Act), private sector organisations are generally prohibited from using or disclosing identifiers assigned by a Commonwealth agency, such as the Centrelink Customer Reference Number, except under specific circumstances. These Regulations permit additional private sector organisations to use this identifier for accessing Centrelink's Confirmation eServices, which includes Customer Confirmation, Income Confirmation, and Superannuation Confirmation services (NPP 7.2, Principal Regulations Schedules 1, 3, and 4). The Regulations specify which organisations can now use the Centrelink Customer Reference Number for making Customer Confirmation or Income Confirmation enquiries, thereby broadening the scope of entities that can verify eligibility information online in real time. The Regulations impose several obligations on the parties and entities they govern. Firstly, any private sector organisation listed in the amended Schedules is required to use the Centrelink Customer Reference Number solely for the purpose of accessing the Confirmation eServices, and only with the consent of the individual whose information is being accessed. Additionally, these organisations must ensure that the use and disclosure of the Customer Reference Number is for the benefit of the individual concerned, thereby ensuring that the release of information occurs with the customer's explicit consent and serves a direct purpose for them. The Regulations also mandate that any use of the Centrelink Customer Reference Number must comply with the overarching privacy principles outlined in the Act. Violations of the provisions within these Regulations can lead to various civil and criminal consequences. Under section 100 of the Act, any organisation that misuses the Centrelink Customer Reference Number contrary to the specified provisions could be subject to enforcement actions. Although the Regulations themselves do not detail specific penalties, breaches of the NPPs generally may result in substantial penalties. For example, serious or repeated breaches can lead to civil penalties of up to $1.8 million for corporations and $180,000 for individuals, as per section 13G of the Act. Furthermore, depending on the severity and intent of the breach, criminal penalties may also apply, potentially leading to imprisonment for up to two years, as stipulated in section 13H of the Act.

Legal classification tags

Area of Law
Privacy Law
Instrument
Regulation
Concepts
Definitions & Interpretation
Licensing & Registration
Reporting & Disclosure Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.