1. What counts as sensitive information
  2. Who has to comply
  3. Get consent before you collect
  4. Tell people what you collect and why
  5. Limit use and disclosure
  6. Take reasonable steps before sending data overseas
  7. Secure it, and destroy it when it is no longer needed
  8. Give access and allow correction
  9. Notify serious data breaches
  10. What it costs to get it wrong
  11. A compliance checklist
  12. When to bring in a lawyer
  13. Start with the consent you can prove

Some of the personal information your business holds carries a much higher legal price tag than the rest. Under the Privacy Act 1988 (Cth) (the Act), information about a person's health, ethnicity, religion, sexual orientation, criminal record or biometrics is sensitive information, and the rules for collecting, using and storing it are deliberately stricter than for an ordinary name and email address.

If your business handles sensitive information, you need to know whether the Act applies to you at all, when you need consent, how you can use and disclose the information, how you must secure it, and when you must notify a data breach. Getting it wrong can mean civil penalties of up to $50 million for a serious breach, not to mention complaints, investigations and direct claims under the new statutory tort for serious invasions of privacy. This guide sets out each obligation in plain English, starting with whether you are in scope.

What counts as sensitive information

Section 6 of the Act defines sensitive information as information or an opinion about an individual's:

  • racial or ethnic origin
  • political opinions, or membership of a political association
  • religious beliefs or affiliations, or philosophical beliefs
  • membership of a professional or trade association, or of a trade union
  • sexual orientation or practices
  • criminal record

that is also personal information.

The definition also covers:

  • Health information, including personal information collected to provide, or in providing, a health service (s 6FA)
  • Genetic information that is not otherwise health information
  • Biometric information used for automated biometric verification or identification, and biometric templates

In practice this catches a wide range of everyday records: client medical histories and treatment notes, union membership recorded in HR files, ethnicity data gathered for diversity reporting, voiceprints or facial images used for identity checks, and details of sexual orientation disclosed in a counselling or support context. Note the reach of s 6FA: if you provide a health service, personal information collected while providing it can be sensitive even if it does not look like health information at all.

Who has to comply

The obligations apply to APP entities, meaning Australian Government agencies and organisations covered by the Australian Privacy Principles (APPs). The default test for an organisation is turnover: if your business's annual turnover was more than $3 million in the previous financial year, the Act applies (s 6D).

Small businesses are generally exempt, but the exemption drops away in defined situations (s 6D(4)). You are covered even under $3 million turnover if you:

  • Provide a health service and hold health information: this captures allied health providers, gyms running injury-management programs, wellness coaches and similar businesses, even sole traders
  • Trade in personal information: for example, disclosing personal information for a benefit, service or advantage, or collecting it in return for providing a benefit
  • Provide services under a Commonwealth contract: for example, as a contracted service provider
  • Are a credit reporting body: covered regardless of your turnover

Small business operators can also choose to opt in to the Act (s 6EA), and Parliament has legislated to remove the small business exemption altogether. That reform is not yet in force, but the direction of travel is clear, so building APP-aligned practices now is prudent.

Even if you are not strictly required to comply, following the APPs anyway is usually smart: customers expect it, and larger clients increasingly require it by contract.

APP 3 sets the baseline. You must not collect sensitive information about an individual unless they consent and the collection is reasonably necessary for one or more of your functions or activities (APP 3.3).

Consent under the Act can be express or implied (s 6), but for sensitive information you should aim for express consent. The OAIC's guidance on consent makes clear that consent must be informed, voluntary, specific and current: the person needs to know what they are agreeing to, in plain language, without being pressured, and your request should not be broader than necessary. Bundled consent, where one tick box covers many unrelated uses, is a particular risk area and will be scrutinised.

Record the consent: who gave it, when, in what form, and exactly what they agreed to. If you later want to use sensitive information for a new purpose, you need fresh consent; past consent does not roll forward.

There are narrow exceptions in APP 3.4: collection required or authorised by law, a permitted general situation (including where it is unreasonable or impracticable to obtain consent and collection is needed to lessen or prevent a serious threat to life, health or safety, s 16A), a permitted health situation (s 16B), and certain records of non-profit organisation members. These are not for routine operations.

Tell people what you collect and why

Two transparency duties run alongside collection. Under APP 1, you must have a clearly expressed, up-to-date privacy policy that sets out the kinds of personal information you collect and hold, how you collect and hold it, the purposes, how people can access and correct it, and how they can complain (APP 1.3 and 1.4).

Under APP 5, at or before the time of collection you must notify the individual, usually through a collection notice that covers the purposes, the main consequences of not providing the information, who you usually disclose it to, whether you are likely to send the information overseas and which countries if it is practicable to say so, and how to complain (APP 5.2).

For sensitive information, make the notice specific to the context. A generic form buried in your website footer will not help a client understand why you need their medical history or ethnicity data at the moment they provide it.

Limit use and disclosure

APP 6 says you may only use or disclose personal information for the purpose you collected it, the primary purpose. Using it for another purpose requires consent, or the secondary purpose must be directly related to the primary purpose and within the individual's reasonable expectations. The bar is higher for sensitive information, which must be directly related to the primary purpose rather than merely related (APP 6.2(a)).

Direct marketing is a separate trap. Under APP 7, you may only use or disclose sensitive information for direct marketing if the individual has consented to that specific use (APP 7.4). Do not assume consent to marketing from consent to provide a service. Lookalike audiences, ad-tech integrations and data enrichment tools all count as uses or disclosures for these purposes, so check what your marketing stack is doing with the data.

Take reasonable steps before sending data overseas

If you disclose personal information to a recipient outside Australia, whether an overseas cloud provider, a support desk or a parent company, APP 8 requires you to take reasonable steps to ensure the recipient does not breach the APPs (APP 8.1). The consequence is in s 16C: if the overseas recipient mishandles the information, you are taken to have breached the APPs yourself.

That means vendor due diligence and contracts that bind the recipient to APP-equivalent standards, plus knowing where the data actually lives rather than where the vendor is headquartered. There are exceptions, for example where the recipient is subject to a law or binding scheme that is substantially similar to the APPs, or the individual has been told about the risk and consented (APP 8.2), but they must be assessed case by case.

Secure it, and destroy it when it is no longer needed

APP 11 requires you to take such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure (APP 11.1). Reasonable steps include technical and organisational measures (APP 11.3): encryption, multi-factor authentication, role-based access and least privilege, patching, staff training, clean-desk rules for physical records, and contractual controls over third parties who handle the data.

APP 11 also carries a retention duty: once you no longer need the information for any lawful purpose, you must take reasonable steps to destroy it or de-identify it (APP 11.2). You may need to keep records longer for other legal or operational reasons, so a written retention schedule that balances those needs is the practical answer. Decide, document and enforce it.

Give access and allow correction

Individuals can request access to the personal information you hold about them, and you must respond within a reasonable period (APPs 12.1 and 12.4). The grounds for refusing access are limited, for example a serious threat to life or health, an unreasonable impact on another person's privacy, or frivolous or vexatious requests (APP 12.3), and a refusal must be explained in writing with complaint mechanisms available.

Similarly, on request, or where you become aware the information is wrong, you must take reasonable steps to correct inaccurate, out-of-date, incomplete, irrelevant or misleading information (APP 13.1), and give a written explanation if you refuse (APP 13.3).

Notify serious data breaches

The Notifiable Data Breaches (NDB) scheme sits on top of the APPs. An eligible data breach occurs where there is unauthorised access to, or unauthorised disclosure of, personal information, or loss in circumstances where either is likely, and a reasonable person would conclude it is likely to result in serious harm to any affected individual (s 26WE). Health records, biometrics and other sensitive information will often meet that bar because of the categories involved.

If you have reasonable grounds to believe an eligible data breach has occurred, you must prepare a statement and notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable (ss 26WK and 26WL). The OAIC can also direct you to notify (s 26WR). The scheme rewards preparation: a tested data breach response plan, a nominated incident lead and drafted notification templates mean you can assess and notify quickly rather than working it out under pressure.

What it costs to get it wrong

The penalties have climbed sharply. A serious or repeated interference with privacy (s 13G) carries a maximum civil penalty for a body corporate of the greatest of $50 million, three times the benefit obtained, or 30% of adjusted turnover; for an individual the cap is $2.5 million. Even an interference that is not serious is a civil penalty provision capped at 2,000 penalty units (s 13H). The OAIC can investigate complaints, accept enforceable undertakings and take civil penalty proceedings in the courts.

Two further developments matter. The Act now creates a statutory tort for serious invasions of privacy (Schedule 2, given effect by s 94A), so affected individuals can sue your business directly for serious misuse of their sensitive information, separately from any regulator action. And the OAIC's enforcement attention is concentrated on high-risk categories, which is precisely where sensitive information sits.

Beyond penalties, a sensitive-information breach is a customer-trust event. Health and other sensitive records are the data people care most about, and the reputational damage of mishandling them is often the cost that hurts most.

A compliance checklist

Work through the checklist below to see where your business stands:

  • Map your data flows: identify where sensitive information enters your business, from intake forms and HR files to support channels and third-party integrations
  • Fix consent capture: collect express, informed consent at the point of collection, separate from general terms, and keep records of who consented to what
  • Keep notices current: review your privacy policy and collection notices whenever practices change, including overseas recipients and new uses
  • Apply proportionate security: encryption, access controls, patching and training matched to the categories you hold
  • Review vendors: contracts with anyone who can access the data, including subprocessors and overseas hosting, should bind them to APP-equivalent standards
  • Adopt a retention schedule: destroy or de-identify information once it is no longer needed
  • Be breach-ready: maintain and test a data breach response plan with templates and a clear incident lead
  • Review annually: re-check your position at least once a year and after any system or product change

When to bring in a lawyer

Privacy obligations are easy to summarise and hard to implement well, because the answers depend on your specific facts. A privacy lawyer can help by:

  • Scoping your position: whether your business is an APP entity and which categories of sensitive information you actually hold
  • Drafting the documents: privacy policies, collection notices and consent forms that match your real practices
  • Negotiating contracts: vendor and service agreements, especially for overseas data flows
  • Running a breach response: assessing whether there is a likely risk of serious harm and dealing with the OAIC
  • Answering borderline questions: whether a new use is directly related to the primary purpose, or whether an exception applies

The cost of advice on the front end is usually a fraction of a penalty, a determination, or the legal fees of defending a complaint.

Of all the duties above, the one most often missed is documenting consent for sensitive information. Regulators and courts will ask whether consent was informed, voluntary, specific and current, and whether you can show it. Consent buried in general terms, or captured once and assumed to cover everything afterwards, is the failure that turns a routine collection into a breach.

So the first action this week is a walk-through: list every form, intake question, HR record and marketing integration that touches personal information, and flag anything in the section 6 categories. For each one, confirm you have express informed consent captured at the point of collection, a collection notice that matches the context, and security controls proportionate to the data. That single audit tells you exactly where your compliance stands, and what to fix first.