Privacy Regulations 2025

Administered by Attorney-General's Department

Legislation au F2025L01377 Regulations In force Legislative Instrument

Legislation content

PRIVACY REGULATIONS 2025

 

 

 

EXPLANATORY STATEMENT

 

Issued by authority of the Attorney-General

in compliance with section 15J of the Legislation Act 2003

 

Purpose and operation of the Instrument

The Privacy Act 1988 (Privacy Act) provides for the protection of the privacy of individuals. It contains 13 Australian Privacy Principles (APPs) which regulate the collection, use, disclosure and storage of individuals’ personal information and applies to most Commonwealth government agencies, private sector organisations with an annual turnover of more than $3 million, and certain other organisations. The Privacy Act also regulates the privacy component of Australia’s consumer credit reporting system in line with the objective under section 2A(e) to facilitate an efficient credit reporting system while ensuring that the privacy of individuals is respected.

Subsection 100(1) of the Privacy Act provides that the Governor-General may make regulations, not inconsistent with the Privacy Act, prescribing matters required or permitted by the Privacy Act to be prescribed, or necessary or convenient to be prescribed for carrying out or giving effect to the Privacy Act. Other relevant provisions are in Attachment A.

The Privacy Regulations 2025 (the Regulations) replace and update the Privacy Regulation 2013 (the 2013 Regulation), which is due to sunset on 1 April 2026.

Chapter 3, Part 4 of the Legislation Act 2003 provides that legislative instruments sunset after a fixed period of time, subject to some exceptions. Section 4 of the Legislation (Deferral of Sunsetting – Privacy Regulation) Certificate 2024 deferred the sunsetting date for the 2013 Regulation from 1 April 2024 to 1 April 2026.

The Attorney-General’s Department conducted a fitness-for-purpose review of the 2013 Regulation. A fit-for-purpose review ensures that legislative instruments are kept up to date and only remain in force for so long as they are needed. This review found that the 2013 Regulation was necessary and fit-for-purpose, and recommended it be remade with minor, stylistic and technical amendments.

The Regulations are largely technical in nature and contain 20 provisions that, among other matters, have the following effects:

Prescribe small business operators as ‘organisations’ under the Privacy Act

This prescription continues to extend obligations under the Privacy Act to small businesses operating a residential tenancy database (RTD operators) and undertaking certain acts and practices which would otherwise be exempt from the Privacy Act. It provides a mechanism for the Office of the Australian Information Commissioner (OAIC), Australia’s privacy regulator, to exercise its regulatory function in relation to these entities.

Prescribe state instrumentalities etc. as ‘organisations’ under the Privacy Act

This prescription continues to extend obligations under the Privacy Act to prescribed state and territory entities which would otherwise be exempt from the Privacy Act, and brings them within the OAIC’s oversight. The state and territory entities prescribed are Essential Energy (NSW), Keystart (WA), the Office of the National Rail Safety Regulator and HomeStart Finance (SA), and NT Home Ownership (NT).

Where prescription as an ‘organisation’ means that these entities would then fall within the definition of a ‘credit provider’ under the Privacy Act, the entities would also be required to handle information in accordance with:

  • Part IIIA of the Privacy Act, which deals with the privacy of information relating to credit reporting (as supported by the Privacy Regulation); and
  • the Privacy (Credit Reporting) Code 2024 (the CR Code).

Give effect to certain provisions in Part IIIA of the Privacy Act

Part IIIA of the Privacy Act deals with the privacy of information relating to credit reporting. This includes:

  • identifying the terms and conditions of consumer credit that may be included in an individual’s credit information;
  • prescribing certain entities as credit providers;
  • exempting certain businesses and undertakings that provide personal information solely for the purpose of verifying or validating information from the definition of credit reporting business;
  • setting the frequency with which an individual’s repayment history information can be listed by credit providers;
  • exempting certain credit providers from the obligation to be a member of a recognised external dispute resolution scheme and from the obligation to be a licensee for the purposes of the Privacy Act.

The 2024 Review of Australia’s Credit Reporting Framework (the Credit Reporting Review) made several recommendations which explicitly propose additions or changes to the credit reporting provisions in the 2013 Regulation. The credit reporting provisions have been remade in substantially the same form as in the 2013 Regulation, with minor stylistic changes to reflect current drafting practices. This is to ensure the continued operation of these provisions while Government considers the Credit Reporting Review.

Prescribe provisions of Commonwealth law as designated secrecy provisions

The Regulations continue to prescribe sections 19 and 19A of the Census and Statistics Act 1905 as designated secrecy provisions under section 80P(7)(d) of the Privacy Act to ensure personal information collected by the Australian Bureau of Statistics continues to only be used for statistical purposes.

Prescribe exceptions to APP 9 (adoption, use and disclosure of government related identifiers)

The Regulations continue to prescribe exceptions to APP 9, which outlines the limited circumstances when an organisation may adopt a government related identifier as its own identifier, or use or disclose a government related identifier of an individual.

The Regulations continue to provide that prescribed superannuation organisations may adopt, or use and disclose, Commonwealth employee payroll numbers for superannuation purposes, with minor stylistic changes made for clarity and to align with current Office of Parliamentary Counsel drafting practices. The Regulations also provide that certain organisations may, with an individual’s consent, use and disclose certain government related identifiers (a Centrelink Customer Reference Number, or a Department of Veterans’ Affairs file number or unique identification number) to access services provided under the Centrelink Confirmation eServices scheme. Such use or disclosure is necessary to determine whether an individual is entitled to concessions, services or assistance provided by the organisation. This adoption, use and disclosure is for the benefit of the individuals concerned.

The Regulations are a legislative instrument for the purposes of the Legislation Act 2003.

The Regulations commence on 1 April 2026.

Details of the Regulations are set out in Attachment B.

Consultation

In conducting the fit-for-purpose review and making the new Regulations, consultation was undertaken in line with section 17 of the Legislation Act 2003. Prescribed entities and entities with exceptions to the APPs, relevant Commonwealth and state and territory government agencies, and, as far as practicable, industry stakeholders that have current prescriptions or exceptions under the 2013 Regulation were consulted, including to determine whether prescriptions remained necessary and fit for purpose for the Regulations.

The Attorney-General consulted with the Assistant Treasurer and Minister for Financial Services on the credit reporting provisions in the Regulations as the Minister responsible for consumer credit reporting. The Assistant Treasurer approved the credit reporting provisions in the proposed Regulations, and authorised the Attorney-General to act as the rulemaker in relation to the making of the new Regulations.

In line with paragraph 6F(3)(a) of the Privacy Act, the Attorney-General has received requests from the relevant state and territory Ministers for the continued prescription of certain state and territory entities as ‘organisations’ under the Privacy Act.

In line with paragraph 100(2)(a) of the Privacy Act, the principal executive of Airservices Australia has agreed that the adoption of payroll numbers issued by Airservices Australia by AvSuper is appropriate in the circumstances and has consulted the Australian Information Commissioner about the adoption. The principal executive of Services Australia has agreed that the use and disclosure of certain government related identifiers by prescribed organisations is appropriate in the circumstances and has consulted the Australian Information Commissioner about the use and disclosure.

The Attorney-General consulted the Australian Information Commissioner in line with requirements under paragraph 6E(4)(b), paragraph 6F(3)(b), and paragraph 100(3)(c) of the Privacy Act, and the Australian Information Commissioner has agreed to the remaking of the relevant provisions as part of the Regulations.

IMPACT ANALYSIS

The Attorney-General’s Department has certified that the 2013 Regulation is operating effectively and efficiently and therefore an Impact Analysis is not required for the instrument to be remade (OIA25-10104).

STATEMENT OF COMPATABILITY WITH HUMAN RIGHTS

The Regulations are compatible with the human rights and freedoms recognised or declared under section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011. A statement of compatibility with human rights for the Regulations is at Attachment C.


ATTACHMENT A

Authorising provisions

The relevant regulation-making powers under the Privacy Act are:

  • subsection 6(1), which provides that regulations may prescribe the terms and conditions of the consumer credit for the purposes of the definition of consumer credit liability information set out in subsection 6(1) of the Privacy Act;
  • subsection 6E(2), which provides that regulations may prescribe a small business operator as an organisation for particular acts or practices;
  • subsection 6F(1), which provides that regulations may prescribe a state or territory authority or instrumentality as an organisation;
  • subparagraph 6G(1)(d)(ii), which provides that the term ‘credit provider’ may mean an agency, organisation or small business operation that carries on a business or undertaking that involves providing credit and that is prescribed by the regulations;
  • subsection 6G(6), which provides that the regulations may prescribe classes of organisations or small business operators that are not credit providers;
  • subsection 6P(4), which provides that the regulations may prescribe a class of businesses or undertakings that are not credit reporting businesses;
  • paragraph 6V(2)(a), which provides that the regulations may make provision in relation to whether or not an individual has met an obligation to make a monthly payment that is due and payable in relation to consumer credit;
  • paragraph 20E(4)(a), which provides that if credit reporting information is, or was derived from, repayment history information or financial hardship information about the individual, the credit reporting body must not disclose the information as a permitted use or disclosure unless the recipient of the information is a credit provider who is a licensee or is prescribed by the regulations;
  • subparagraph 21D(2)(a)(i), which provides that the regulations may prescribe credit providers who are exempt from the requirement to be a member of an external dispute resolution scheme;
  • subparagraph 21D(3)(c)(i), which provides that the regulations may prescribe credit providers who are exempt from the requirement to be a licensee who may disclose repayment history information or financial hardship information; and
  • paragraph 80P(7)(d), which provides that regulations may prescribe a designated secrecy provision for the purposes of Part VIA of the Privacy Act, which provides for the collection, use and disclosure of personal information in emergencies and disasters.


ATTACHMENT B

NOTES ON SECTIONS

Part 1 – Preliminary

Section 1 – Name

This section provides that the title of the Regulations is the Privacy Regulations 2025 (the Regulations).

Section 2 – Commencement

This section provides that the Regulations commence on 1 April 2026.

Section 3 – Authority

This section provides that the Regulations are made under the Privacy Act 1988 (Privacy Act).

Section 4 – Schedules

This section provides that amendments or repeals have effect according to the terms set out in the Schedule(s).

Section 5 – Definitions

This section defines a number of terms used in the Regulations and includes updates to certain definitions under the 2013 Regulation to reflect machinery of government changes or as a result of structural amendments to certain entities, or to reflect current Office of Parliamentary Counsel drafting practices.  

This section includes a note which provides that the terms ‘agency’, ‘contracted service provider’, ‘government related identifier’, ‘organisation’ and ‘small business operator’ have the same meaning as they do in the Privacy Act. 

This section defines ‘Act’ as meaning the Privacy Act.  

This section defines ‘AustralianSuper’, ‘AvSuper’, ‘Centrelink Confirmation eServices scheme’, ‘Centrelink program’, ‘Customer Reference Number’, ‘DVA File Number’, ‘DVA unique identification number’, ‘Indigenous person’, ‘payroll contractor’ and ‘payroll number’ for the purposes of Part 5. A definition of ‘Australian Retirement Trust’ has been introduced for the purposes of Part 5 following the Successor Fund Transfer between AvSuper and the Australian Retirement Trust on 1 May 2024. References to the Human Services Department have been updated following machinery of government changes in May 2019 that renamed the Department of Human Services ‘Services Australia’ and made it an Executive Agency.

A note has been added to the definitions of ‘Customer Reference Number’, ‘DVA File Number’, ‘DVA unique identification number’ and ‘payroll number’ to clarify that these are government related identifiers.

The definitions of ‘NT Home Ownership’ and ‘HomeStart Finance’ have been updated with minor stylistic changes for the purposes of sections 8 and 9.

The section also defines ‘residential tenancy operator’ for the purposes of section 7.

Part 2 - Interpretation

Section 6 – Consumer credit liability information

This section continues to prescribe the terms or conditions of the consumer credit (as defined in subsection 6(1) of the Privacy Act) for the purposes of paragraph 6(1)(e) of the definition of consumer credit liability information in the Privacy Act. Specifically:

  1.           how the principal and interest on the consumer credit are to be paid;
  2.           whether the term of the consumer credit is fixed or revolving;
  3.           if the term of the consumer credit is fixed – the length of the term;
  4.           whether the individual is a guarantor to another individual is in relation to that particular line of credit of the other individual;
  5.           whether the consumer credit is secured or unsecured; and
  6.            any variation that may be made to items contained in the above paragraphs (a) to (e).

 

Section 7 – Small business operators treated as organisations

This section continues to provide that small businesses operating a residential tenancy database and undertaking certain acts and practices are ‘organisations’ for the purposes of the Privacy Act and not exempt from obligations under the Privacy Act.

Section 8 – State authorities treated as organisations

This section prescribes Essential Energy (NSW), Keystart (WA), the Office of the National Rail Safety Regulator (ONRSR) (SA) and NT Home Ownership (NT) as ‘organisations’ for the purposes of section 6F of the Privacy Act. The relevant State and Territory Ministers have requested the prescription of these entities to ensure they are able to access and handle information under the Privacy Act to facilitate their continued operation:

  • Essential Energy delivers electricity across regional, rural and remote NSW and part of Southern Queensland and its continued prescription is necessary to provide for the handling of personal information, including credit information, within the bounds of the Privacy Act.
  • Keystart provides low-deposit home loans to Western Australians who may be unable to meet the requirements of mainstream lenders. Its continued prescription will ensure Keystart is able to participate in the credit reporting system and carry on its main business of issuing loans.
  • ONRSR has regulatory oversight of rail safety across Australia and enforcement powers, including audits, reviews and investigations. South Australia is the national host jurisdiction for the ONRSR. South Australia does not have separate privacy legislation and prescription of the ONRSR provides a privacy framework for personal information handled by the ONRSR, a mechanism for the OAIC to investigate privacy incidents, and affected individuals with legally enforceable complaint rights.
  • NT Home Ownership assists lower income residents of the NT to participate in homeownership through loans, and it collects, uses and discloses consumer credit information to and by CRBs and credit providers. Its continued prescription will ensure NT Home Ownership is able to participate in the credit reporting system and continue to assist vulnerable and lower income residents with housing.    

Section 9 – State instrumentality treated as an organisation

This section prescribes the South Australian instrumentality HomeStart Finance as an ‘organisation’ for the purposes of the Privacy Act and exempts HomeStart Finance from APP 11.2. HomeStart Finance is a home loan lender and holds an Australian Credit Licence, and its prescription is necessary to ensure HomeStart Finance is treated as a credit provider and can participate in the credit reporting system under the Privacy Act.

Subsection 9(2) exempts HomeStart Finance from APP 11.2, which requires entities to take reasonable steps to destroy or de-identify information that is (a) personal information, (b) no longer needed for the purpose for which it may be used or disclosed, (c) is not contained in a Commonwealth record, where (d) the entity is not required by or under an Australian law, or court/tribunal order, to retain the information. The South Australian Treasurer advised that HomeStart Finance, as an agency of the South Australian Government, has record-keeping obligations pursuant to the South Australian State Records Act 1997. The purpose of this exemption would be to ensure that HomeStart Finance can continue to meet its recordkeeping obligations under the South Australian State Records Act 1997.

Section 10 – Meaning of credit provider

Subsection 10(1) continues to prescribe Indigenous Business Australia, Export Finance and Insurance Corporation, the Regional Investment Corporation and NT Home Ownership as credit providers for the purposes of subsection 6G(1)(d)(ii) of the Privacy Act meaning they can participate in the credit reporting system set out in Part IIIA of the Privacy Act, and are bound by the relevant privacy obligations for credit providers.

Subsection 10(2) continues to exclude from the definition of credit provider under subsection 6G(6) of the Privacy Act any organisation or small business operators acting in the capacity of a current or prospective landlord in relation to the individual with whom an organisation or small business may be transacting.

Section 11 – Meaning of credit reporting business

This section continues to exclude from the definition of credit reporting business under subsection 6P(4) of the Privacy Act those businesses or undertakings which provide personal information to a credit provider for the purposes of verifying an individual’s identity or validating other information relating to the individual’s financial position (such as real property assets). This ensures a business or undertaking that provides personal information solely for the purposes of verifying or validating information that has been provided by an individual to a credit provider is not captured by the definition of credit reporting business.

Section 12 – Meaning of repayment history information

This section continues to specify the circumstances in which an individual would be taken to have not met an obligation to make a monthly payment that is due and payable, pursuant to subsection 6V(2) of the Privacy Act. It provides that where an individual misses any or all repayments due in a month, irrespective of the actual payment cycle for that obligation, the individual is taken to have not met the obligation. This ensures there is only one report each month per credit account of an individual's repayment history information.

Part 3 – Credit Reporting

Section 13 – Use or disclosure of credit reporting information

This section prescribes Indigenous Business Australia, the Regional Investment Corporation and NT Home Ownership as credit providers for purposes of subsection 20E(4)(a) of the Privacy Act. It enables credit reporting bodies to disclose credit reporting information derived from repayment history information or financial hardship information about the individual to the prescribed organisations.

Section 14 – Permitted disclosure of credit information to a credit reporting body

This section combines sections 13A and 14 of the 2013 Regulation without altering the meaning. For the purposes of subparagraph 21D(2)(a)(i) of the Privacy Act, this section continues to prescribe a credit provider as exempt from the requirement to be a member of a recognised external dispute resolution (EDR) scheme in order to disclose credit information about an individual to a credit reporting body, if the credit provider discloses the credit information in connection with the provision of commercial credit.

It continues to prescribe the entities Indigenous Business Australia, the Regional Investment Corporation, and NT Home Ownership for the purposes of subsections 21D(2)(a)(i) and 21D(3)(c)(i) of the Privacy Act. It allows the prescribed entities to disclose credit information about an individual to a credit reporting body, exempting them from the requirement to be a member of or subject to a recognised EDR scheme under subsection 21D(2)(a)(i). The section also prescribes each of Indigenous Business Australia, the Regional Investment Corporation, and NT Home Ownership as a licensee for the purposes of subsection 21D(3) so that they are each treated as if they are a licensed credit provider for the purposes of disclosing repayment history or financial hardship information to a credit reporting body.

Part 4 – Dealing with personal information in emergencies and disasters

Section 15 – Designated secrecy provisions

Part VIA of the Privacy Act provides for the collection, use and disclosure of personal information in emergencies and disasters. To facilitate this, Part VIA overrides secrecy provisions in Commonwealth legislation, unless a secrecy provision is a ‘designated secrecy provision’. 

This section (previously section 21 in the 2013 Regulation) prescribes secrecy provisions related to the Australian Bureau of Statistics (ABS) as designated secrecy provision for the purposes of section 80P(7)(d) of the Privacy Act. The prescribed secrecy provisions are sections 19 and 19A of the Census and Statistics Act. The effect of the section is to continue to confirm that personal information collected by the ABS for statistical purposes is used for statistical purposes.

Part 5 – Australian Privacy Principles

This Part of the Regulations (previously Part 2 in the 2013 Regulation) contains provisions that relate to the APPs. All of the sections in Part 5 relate to APP 9, which deals with the adoption, use or disclosure of government related identifiers by organisations. APP 9.1 provides that an organisation must not adopt a government identifier in relation to an individual. APP 9.2 provides that an organisation must not use or disclose a government related identifier of an individual. APP 9.3 provides that regulations may be made to permit the use of government related identifiers by organisations.

Sections 16 and 17 of this Part provide exceptions to APP 9 to permit the disclosure of payroll numbers, a form of government related identifier, to prescribed superannuation organisations for the purposes of providing superannuation services to individuals. Sections 18 and 19 of this Part provide exceptions to APP 9 for specified organisations in relation to their access to the Centrelink Confirmation eServices system.

Section 16 – Exceptions to Australian Privacy Principle 9.1—adopting payroll numbers for the provision of superannuation services

This section prescribes AvSuper as an organisation for the purposes of APP 9.1, and prescribes payroll numbers assigned by Airservices Australia as a prescribed identifier, noting Airservices Australia uses a different payroll number system to other Commonwealth agencies. It allows for the payroll number to be adopted by AvSuper in order to provide superannuation services.

Section 17 – Exceptions to Australian Privacy Principle 9.2—using and disclosing payroll numbers for the provision of superannuation services

This section prescribes exceptions to APP 9.2, permitting the prescribed superannuation organisations AustralianSuper, AvSuper, and the Australian Retirement Trust to use or disclose payroll numbers assigned to an individual by an agency, its agent or a contracted service provider, in order for those superannuation organisations to provide superannuation services to individuals employed by the agencies.

Section 18 – Exceptions to Australian Privacy Principle 9.2—accessing Centrelink Confirmation eServices (entitlement to concessions, services or assistance)

This section prescribes exceptions to APP 9.2, prescribing organisations who are participants in the Centrelink Confirmation eServices scheme and are included in a class of organisations set out in the table in subsection 18(2). This prescription enables these organisations to use and disclose specific government related identifiers – a Customer Reference Number, a DVA file number and a DVA unique identification number – in order for that prescribed organisation to, with the individual’s consent, access services provided under the Centrelink Confirmation eServices scheme to enquire whether the individual is entitled to receive a concession, service or assistance. The Centrelink Confirmation eServices scheme is a secure online service that provides real-time customer information and allows approved businesses to confirm Centrelink or DVA customer entitlements for a concession, rebate or service.

Section 19 – Exceptions to Australian Privacy Principle 9.2—accessing Centrelink Confirmation eServices (entitlement to early release of superannuation)

This section sets out prescribed exceptions to APP 9.2, prescribing organisations who are participants in the Centrelink Confirmation eServices scheme and provide superannuation products and services. This prescription enables these organisations to use and disclose specific government related identifiers – a Customer Reference Number – in order for that prescribed organisation to, with the individual’s consent, access services provided under the Centrelink Confirmation eServices scheme to enquire whether the individual is entitled to the early release of superannuation on the ground of financial hardship.

Part 6 – Application provisions

Section 20 – Application of this instrument as originally made

This section deals with the application of the exceptions in Part 5 of the Regulations and has the effect of providing for the exceptions to APP 9 to apply to government related identifiers assigned to an individual before, on or after the commencement of the instrument.

Schedule 1 – Repeals

Section 1 – The whole of the instrument

This section repeals the Privacy Regulation 2013.

ATTACHMENT C

STATEMENT OF COMPATIBILITY WITH HUMAN RIGHTS

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

Privacy Regulations 2025

The instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

Overview of the Disallowable Legislative Instrument

The Privacy Regulations 2025 (the Regulations) replace and update the Privacy Regulation 2013 (the 2013 Regulation) with minor and technical amendments. The Regulations are required to give effect to certain Australian Privacy Principles (APPs) and provisions in the Privacy Act 1988 (Privacy Act) and to support operation of Australia’s consumer credit reporting system.

 

The Regulations prescribe small business operators that operate residential tenancy databases, and certain state and territory entities, as ‘organisations’ subject to the Privacy Act. They provide clarification as to what types of entities are considered credit reporting businesses and credit providers, and prescribe circumstances in which prescribed organisations may adopt, use and disclose certain government related identifiers. The Regulations also prescribe certain sections of the Census and Statistics Act 1905 as designated secrecy provisions.  

 

Human Rights Implications

The Regulations engage the prohibition on interference with a person’s privacy, family and home in Article 17 of the International Covenant on Civil and Political Rights (ICCPR).

 

The right to privacy in Article 17 of the ICCPR provides that no one shall be subjected to arbitrary or unlawful interference with their privacy, family, home or correspondence, nor to unlawful attacks on their honour and reputation. Article 17 of the ICCPR also provides that everyone has the right to protection of the law against such interference or attacks. 

 

The prohibitions in Article 17 have been given effect by the Privacy Act. By prescribing certain entities under the Privacy Act and by providing exceptions to certain APPs, the human rights concerning privacy are engaged and supported. 

 

The Privacy Act

The Privacy Act provides for the protection of the privacy of individuals. It contains 13 APPs which regulate the collection, use, disclosure and storage of individual’s personal information. The APPs also create obligations on agencies and organisations regarding access to, and correction of, an individual’s personal information.

 

One of the objects of the Privacy Act is to facilitate an efficient credit reporting system while ensuring that the privacy of individuals is respected. Credit reporting laws are intended to balance an individual’s right to protect their personal information with the need to ensure credit providers have sufficient information available to assist them to decide whether to provide an individual with credit and can comply with their obligations under the National Consumer Credit Protection Act 2009. To promote the right to privacy, Part IIIA of the Privacy Act regulates the handling of personal information about individuals’ activities in relation to credit reporting.

 

The objects of the Privacy Act also provide a means for individuals to complain about an alleged interference with their privacy. To promote the right to privacy, the Australian Information Commissioner, through the Office of the Australian Information Commissioner (OAIC), Australia’s federal privacy regulator, is responsible for monitoring and enforcing compliance with the Privacy Act, including through receipt of complaints about an act or practice that may be an interference with the privacy of the individual.

 

The Regulations

Prescription of small business operators and state and territory entities

The Regulations protect against arbitrary interference of privacy by prescribing that small businesses operating a residential tenancy database and undertaking certain acts and practices are ‘organisations’ for the purposes of the Privacy Act. The following state and territory entities are also prescribed as ‘organisations’ for the purposes of the Privacy Act: Essential Energy (NSW), Keystart (WA), Office of the National Rail Safety Regulator (ONRSR)(SA), HomeStart Finance (SA) and NT Home Ownership (NT).

 

Prescription requires these small business operators and entities to handle personal information in accordance with the Privacy Act, including the credit reporting requirements, and the APPs, and provides affected individuals with legally enforceable complaint rights. The APPs include obligations which support the right to privacy, including in relation to

  • the open and transparent management of personal information, including the publication of a privacy policy which informs individuals about how their personal information may be collected, used or disclosed (APP 1);
  • the collection of solicited personal information, including affording a higher level of protection where the personal information is sensitive information (APP 3);
  • the use and disclosure of personal information, including limiting the use and disclosure to a purpose for which the personal information was collect, or for a secondary purpose if an exception applies (APP 6);
  • the security of personal information, including taking reasonable steps to protect personal information held from misuse, interference and loss, as well as unauthorised access, modification or disclosure (APP 11).

 

APP 11.2 outlines circumstances whereby an entity must destroy or de-identify the personal information it holds. HomeStart Finance is exempt from APP 11.2 under the Regulations. This is considered reasonable, necessary and proportionate as HomeStart Finance, as an agency of the South Australian Government, has record-keeping obligations pursuant to the South Australian State Records Act 1997.  

 

Prescribing entities in the Regulations further protects the right to privacy by affording individuals impacted by the acts or practices of a state or territory entity with a legally enforceable complaint right. Part V of the Privacy Act provides for an individual to make a complaint to the OAIC about an act or practice of an APP entity that may be an interference with the privacy of the individual. Part V also requires the Australian Information Commissioner to investigate the act or practice except in certain circumstances.

 

Credit reporting provisions

To promote an individual’s right to privacy, Part IIIA of the Privacy Act regulates the handling of personal information about an individual’s activities in relation to consumer credit. Division 3 of Part IIIA outlines:

 

        the types of credit information that credit providers can disclose to a credit reporting body, for the purpose of that information being included in an individual’s credit report

        the permitted purposes for which credit providers can use credit eligibility information about an individual, and

        the requirements for the Privacy (Credit Reporting) Code 2024 which imposes privacy obligations on entities handling credit reporting information.

 

The Regulations include definitions necessary to give effect to credit reporting provisions in the Privacy Act and to support the effective operation of Australia’s consumer credit reporting framework.

 

The Regulations also prescribe Indigenous Business Australia, the Regional Investment Corporation and NT Home Ownership as credit providers, enabling these entities to disclose credit reporting information pursuant to section 21D of the Privacy Act. Prescribing these entities promotes the right to privacy as they are bound by the requirements in the Privacy Act, including under Division 3 of Part IIIA.

 

Adoption, use and disclosure of government related identifiers

The Regulations limit the prohibition against arbitrary interference with privacy in a clear and narrowly defined way for a purpose which is necessary and proportionate to achieving legitimate objectives. APP 9 restricts the adoption, use and disclosure of government related identifiers by organisations under the Privacy Act, unless an exception applies or the regulations provide otherwise.

 

The Regulations permit specified agencies to disclose employee payroll numbers (a type of government related identifier) to prescribed superannuation organisations for the discrete purpose of providing superannuation services to employees. This is for the benefit of the individuals concerned.

 

The Regulations also provide that certain organisations may, with an individual’s consent, use and disclose certain government related identifiers (a Centrelink Customer Reference Number, or a Department of Veterans’ Affairs file number or unique identification number) to access services provided under the Centrelink Confirmation eServices scheme. Such use or disclosure is necessary to determine whether an individual is entitled to concessions, services or assistance provided by the organisation, and is for the benefit of the individual.

 

Conclusion

The Regulations engage the protection against arbitrary interference with privacy. To the extent that the Regulations may limit the right to privacy, those limitations are reasonable, necessary and proportionate to achieve the legitimate aims of the instrument. The prescription of entities to establish them as subject to the Privacy Act promotes the protection of the right to privacy and engages and supports the human rights concerning privacy. The Regulations are therefore compatible with human rights as it promotes the protection of the right to privacy.

 

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.