1. Who must comply: the APP entity test
  2. The employee records exemption: narrow and easily misunderstood
  3. Your duties under the Australian Privacy Principles
  4. Notifiable data breaches: the duty to tell people
  5. What your staff privacy policy should cover
  6. Surveillance and monitoring: state-based rules
  7. The consequences of getting it wrong
  8. A practical compliance checklist
  9. When to get a lawyer involved
  10. The trap that catches most employers: applicant data

Every Australian employer holds personal information about its people: bank details for payroll, tax file numbers, superannuation accounts, medical certificates, emergency contacts, performance notes and rosters. If your business is covered by the Privacy Act 1988 (Cth), you must handle that information according to the Australian Privacy Principles (the APPs), and a clearly expressed privacy policy is part of that obligation. Even if you are not covered, a practical staff privacy policy is still the cheapest way to set expectations, run consistent practices and defend a complaint or a regulator's question later.

This article sets out who the Privacy Act applies to, the duties that come with employee information, what happens if you breach them, and the steps to put a working staff privacy policy in place.

Who must comply: the APP entity test

The Privacy Act applies to private sector "APP entities". The starting test is turnover. A business with an annual turnover above $3 million for the previous financial year is an APP entity and must comply with the APPs (see s 6D of the Privacy Act for the small business definition). Annual turnover is defined in s 6DA as the proceeds of sales, commission, rent, interest, royalties, dividends and similar operating income, so it is broader than taxable profit.

The $3 million line is not the whole story. Under s 6D(4), a business is treated as an APP entity regardless of size if it:

  • Provides health services to individuals and holds their health information
  • Trades in personal information, for example by disclosing personal information for a benefit, service or advantage, or providing a benefit to collect it
  • Is a contracted service provider for a Commonwealth contract
  • Is a credit reporting body

A sole trader, partnership, trust or company that carries on only small businesses and does not fall into any of those categories is a "small business operator" and generally sits outside the Privacy Act, although it can choose to opt in. The practical point for most SMEs: if your revenue is over $3 million, or you run a medical, allied health or fitness business, or you trade in customer data, assume the APPs apply to you and get advice if you are unsure.

The employee records exemption: narrow and easily misunderstood

There is a common belief that employee information is always exempt from the Privacy Act. The reality is more confined. Under s 7B(3) of the Privacy Act, an act or practice is exempt only if it is directly related to both:

  • A current or former employment relationship between the organisation and the individual, and
  • An employee record held by the organisation relating to that individual

"Employee record" is defined in s 6(1) as a record of personal information relating to the employment of the employee: engagement, training, disciplining, resignation, termination, terms and conditions, personal and emergency contact details, performance or conduct, hours of work, salary or wages, leave, taxation, banking and superannuation affairs, and union or professional association membership.

The OAIC's guidance on the exemption is clear about its limits:

  • Job applicants are not covered: The exemption does not extend to prospective employees. A candidate's CV, interview notes and referee comments are personal information handled under the APPs, even if you run a sub-$3 million business and are exempt for your existing staff. Once someone is employed, records of their pre-employment checks become exempt, but unsuccessful applicants stay outside the exemption.
  • Contractors and labour hire are not covered: An organisation that handles employee records on behalf of an employer, such as a recruitment agency, HR provider or payroll service, must comply with the APPs, including the collection notice requirements in APP 5.
  • Volunteers are not covered: There is no employment relationship with a volunteer.
  • The purpose must be employment-related: Selling a list of employee details to a marketing company, or publishing an employee's information for an unrelated purpose, is not directly related to the employment relationship and the exemption will not protect you.

The exemption also only shields the employer. If you outsource payroll or HR functions, your provider's handling of your staff's information is subject to the APPs in its own right.

Your duties under the Australian Privacy Principles

If the APPs apply to a category of information, the duties are not optional. The ones that bite hardest in an employment context are:

  • Have a privacy policy: APP 1.3 requires an APP entity to have a clearly expressed and up-to-date privacy policy, and APP 1.4 sets out what it must contain: the kinds of information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can access and correct their information, how they can complain, and whether information is likely to be disclosed overseas.
  • Give individuals access to their information: APP 12 requires an entity to give an individual access to the personal information it holds about them on request, subject to limited exceptions such as a serious threat to health or safety.
  • Correct inaccurate information: APP 13 requires an entity to take reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading, including notifying other entities it was disclosed to if the individual asks.
  • Keep information secure: The APPs require an entity to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and to destroy or de-identify it once it is no longer needed.

Because of the employee records exemption, access and correction rights under APP 12 and APP 13 will not apply to most employee records held by a private sector employer. They will apply to applicant information, contractor information and any staff information used outside the employment relationship. The clean approach is to offer a practical internal process for staff to request access or corrections in all cases, and to note in the policy that statutory rights can differ depending on whether the exemption applies.

Notifiable data breaches: the duty to tell people

Since 22 February 2018, Part IIIC of the Privacy Act has required APP entities to notify the Office of the Australian Information Commissioner (the OAIC) and affected individuals when an eligible data breach occurs: unauthorised access, unauthorised disclosure or loss of personal information that is likely to result in serious harm to an individual.

The scheme works in two steps. Under s 26WK, once the entity is aware there are reasonable grounds to believe an eligible data breach has occurred, it must prepare a statement describing the breach and the kinds of information involved, and give it to the Commissioner as soon as practicable. Under s 26WL, it must then notify the affected individuals, or publish the statement on its website if individual notification is not practicable. The Commissioner can also direct an entity to notify if it has not done so.

Where staff data is concerned, the interaction between the employee records exemption and the NDB scheme is a genuine grey area, and opinions differ on whether a breach of employee records alone triggers the notification duties. If a breach involving staff information occurs, treat it as potentially notifiable, work through the serious harm assessment and take advice before deciding not to notify.

What your staff privacy policy should cover

A good policy is written in plain English, describes what your business actually does, and covers at least these points:

  • What you collect: contact details, right-to-work documents, payroll, tax and superannuation details, emergency contacts, performance and training records, rosters and timesheets, and health information where needed for injury management or WHS.
  • How you collect it: onboarding forms and HR systems, emails, payroll and benefits platforms, CCTV or access logs, and any background checks you run lawfully.
  • Why you collect it: recruitment, rostering and workforce planning, payroll and leave administration, performance management, safety and compliance, and meeting legal obligations.
  • Who can see it: internal access on a need-to-know basis, disclosure to service providers such as payroll, IT, insurers and advisers, and disclosures required by law to regulators or under a subpoena.
  • How you protect it: role-based access, encryption, secure storage of paper records, and disposal processes.
  • Access and correction: the practical process for staff to request access or updates, noting that statutory rights may be limited by the employee records exemption.
  • Retention and disposal: what you keep, for how long, and how you destroy or de-identify information no longer needed.
  • Data breaches and complaints: how incidents are reported internally, how the serious harm assessment runs, and the pathway for staff to raise concerns, including escalation to the OAIC.

If you run a recruitment pipeline, add a short collection notice for candidates explaining how their information will be handled at the application stage. The exemption does not protect you there.

Surveillance and monitoring: state-based rules

Employee privacy does not stop at the Privacy Act. Workplace surveillance and monitoring are regulated at state and territory level, and the rules differ between jurisdictions. Some states have specific workplace surveillance legislation that requires prior written notice of computer or phone monitoring and signage for cameras, while others deal with monitoring through surveillance devices legislation. The ACT has its own workplace privacy statute.

The practical consequence is that a single national policy may not be enough. If you have staff in more than one state, check the notice and consent rules for each location, and make sure your policy matches the notices you actually give. A surveillance practice that is lawful in one state can be unlawful in another if the notice requirements differ.

The consequences of getting it wrong

The Privacy Act's penalties were dramatically increased in 2022. Under s 13G, a serious interference with privacy by a body corporate now attracts a maximum civil penalty of the greatest of $50 million, three times the value of the benefit obtained from the conduct, or 30% of the body's adjusted turnover in the relevant period. For individuals and non-corporate entities the cap is $2.5 million. A non-serious interference carries up to 2,000 penalty units under s 13H, and the OAIC can also issue infringement notices and compliance notices for breaches of specific APP provisions.

In deciding whether an interference is serious, a court may weigh the sensitivity of the information, the number of people affected, whether children or vulnerable people were involved, whether the conduct was repeated, and whether the entity failed to implement practices, procedures and systems to comply with its obligations. That last factor is why a written policy matters: it is direct evidence of your systems, and its absence makes a breach look worse.

Beyond penalties, individuals can complain to the OAIC, which can investigate and seek determinations and compensation orders. A privacy failure involving payroll data also carries practical costs: notification letters, credit monitoring for affected staff, legal fees and reputational damage that is hard to repair.

A practical compliance checklist

If you are building or refreshing your staff privacy framework, work through these steps:

  • Confirm whether your business is an APP entity, including the small business exceptions for health services, data trading, Commonwealth contracts and credit reporting.
  • Map the information lifecycle: what staff information you collect, where it is stored, who can access it, and where it is shared or backed up, including spreadsheets and shared inboxes.
  • Draft the policy in plain English against that map, covering the categories above, and align it with your employment contracts, device and communications policies, and candidate collection notice.
  • Set up an incident response process so a suspected breach triggers a serious harm assessment and, if needed, notification to the OAIC and affected staff.
  • Train managers on need-to-know access, how to handle access and correction requests, and what to do when an incident is reported.
  • Review the policy at least annually, and whenever you change systems, add monitoring, onboard a new provider or expand to a new state.

When to get a lawyer involved

A privacy lawyer's role here is not to hand you a template and leave. A practitioner will confirm your APP entity status, work out where the employee records exemption does and does not apply across your workforce, check the surveillance rules for each state you operate in, and draft the policy and supporting documents so they fit your contracts and your actual systems. Where the work is most valuable is in the grey areas: whether a breach of employee records is notifiable, whether a new monitoring practice satisfies notice requirements, and how to respond if the OAIC comes knocking.

The trap that catches most employers: applicant data

The mistake that costs employers most often is assuming the employee records exemption covers everything HR touches. It does not. The candidate you interviewed and rejected, the contractor on your books, the volunteer at your community event: their information is outside the exemption, and if you are an APP entity the full weight of the APPs applies to it. If you are a sub-$3 million business that is otherwise exempt, applicant data may be the only personal information you handle that is regulated at all.

So the first task this week is not to draft the policy. It is to find every place applicant and contractor information lives, from your recruitment inbox to your HR platform's archive, and decide how that information will be handled. Answer that question, and your staff privacy policy writes itself around it.