The aim of the Privacy Act is to protect personal information about individuals handled by organisations. The Act contains Principles which set the minimum standards for handling personal information.
Personal information is information that identifies an individual or allows their identity to be readily worked out. It includes information such as a person's name, address, financial details, marital status, billing details, ethnicity, religion and health details. The Privacy Act does not apply to employment records of private sector organisations, used for employment purposes.
Since 22 February 2018, businesses with an annual turnover of more than $3 million or who deal with Tax File Numbers (TFN's) need to comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 in addition to the existing obligations.
If a data breach involves personal information and is likely to result in serious harm to any individuals, you will need to notify both the individual involved and the Office of Australian Information Commissioner (OAIC).
Businesses are required to take reasonable steps to destroy or conceal information that is no longer needed, and to protect existing information. A breach can occur when personal information held by an organisation is lost or subjected to unauthorised access or disclosure. Examples of a data breach include when:
Penalties can apply for a breach of the new regime of up to $360,000 for individuals and $1.8m for Companies.
Small businesses with an annual turnover of $3 million or less do not need to comply unless they are:
* Note: The credit reporting system may still apply.
The 13 Australian Privacy Principles (APPs) set out standards, rights and obligations for the handling, holding, use, accessing and correction of personal information.
The Privacy Act also covers the following areas:
The Privacy Act also covers specified persons handling your:
The Australian Privacy Commissioner is able to conduct performance assessments and apply orders or penalties to non-compliant businesses. Penalties may be up to $340,000 for individuals and up to $1.7 million for organisations.
What you need to do to ensure your business complies with the Privacy Act will depend on the size and the type of business you run and the kind of personal information you collect.
The following steps provide a framework to ensure your business is ready to comply with the Privacy Act and reforms:
Determine if you are either an APP entity, and how these reforms apply to your business
Appoint a Privacy Officer
Become familiar with the Australian Privacy Principles
Establish or review your Privacy Policy and/or Credit Policy
Do a "Privacy Stocktake" of your business to determine how personal infomration is being collected and used
Adjust your policies, procedures and protocols to ensure complicance with the Australian Privacy Principles
Develop or review your Privacy Complaints Handling Process
Train your staff on the Privacy Laws and your procedures
Review your obligations in relation to the credit Reporting System
Obtain external advice and assistance where necessary
More information on the obligations which may be relevant for your organisation can be found on the Office of the Australian Information Commissioner website http://www.oaic.gov.au/ or by contacting our office.
Discuss Further?
If you would like to discuss this, please get in touch.
Disclaimer
The information provided in this information sheet does not constitute advice. The information is of a general nature only and does not take into account your individual situation. It should not be used, relied upon, or treated as a substitute for specific professional advice. We recommend that you contact Brentnalls SA before making any decision to discuss your particular requirements or circumstances.
Quick Links
Acknowledgement of Country
We acknowledge the Traditional Owners of the land where we work and live. We pay our respects to Elders past, present and emerging. We celebrate the stories, culture and traditions of Aboriginal and Torres Strait Islander Elders of all communities who also work and live on this land.
Let's chat.
For a no obligation meeting about our many services, please use this form to submit your enquiry.
We will respond to you as soon as possible.
Thank you
Thank you for your enquiry with Brentnalls SA.
We will respond to your enquiry as soon as possible.
Click here to return to the Home Page.
Kind regards,
The Team
Brentnalls SA
Our Location
255 Port Road
HINDMARSH SA 5007
PO Box 338
Welland SA 5007
"We feel confident in our financial decisions and can focus on growing our business with peace of mind."
John & Barbara Kalleske
Kalleske Vineyards Pty Ltd