- What counts as sensitive information
- Consent plus reasonable necessity: why you can collect it at all
- Staying within the primary purpose: use and disclosure
- When you can act without consent: the exceptions
- The health service carve-out
- What you promise about security and breaches
- Access, correction and complaints
- Clauses worth adding when they apply
- How an Artificer Legal privacy lawyer can help you draft this clause
- The consent record is what gets tested first
You have a privacy policy template open, or a draft back from a web designer, and somewhere in the middle of it sits a section headed "sensitive information". The urge is to leave the boilerplate alone and move on. That section is where the strictest rules in the Privacy Act 1988 (Cth) (the Act) live, and it is where a copied template most often goes wrong.
The sensitive information clause is the part of your APP privacy policy that tells customers what happens to the most private details they hand over: health records, racial or ethnic origin, sexual orientation, religious beliefs, criminal records. The Australian Privacy Principles (the APPs) in the Act treat this information differently from ordinary personal information. Ordinary personal information can be collected when it is reasonably necessary for your business to function. Sensitive information needs consent on top of that, and the clause is where you show you understand the difference. Not every business is covered by the Act at all: whether yours is depends on your turnover and the activities you carry out, which is worth confirming before you invest in the drafting.
A well-drafted sensitive information clause is not one paragraph. It is a small set of promises that together track the Act: what you collect, why you collect it, what you will and will not do with it, when you can act without consent, and what happens if it is lost or misused. The sections below walk through each part.
What counts as sensitive information
The clause needs to start by identifying the categories of information it is talking about. Section 6(1) of the Act defines sensitive information by list, and a clause that simply points to "sensitive information as defined in the Privacy Act" is common. A clause that names the categories you actually collect is more useful to your customers and to you. Under s 6(1), sensitive information is information or an opinion about an individual's:
- Racial or ethnic origin: including nationality and ethnicity.
- Political opinions and associations: including membership of a political association.
- Religious or philosophical beliefs: including religious affiliations.
- Association memberships: membership of a professional or trade association, or of a trade union.
- Sexual orientation or practices:
- Criminal record:
- Health information: a category with its own definition, discussed below.
- Genetic information: where it is not otherwise health information.
- Biometric information and biometric templates: but only biometric information that is to be used for automated biometric verification or biometric identification.
Two drafting traps sit inside this list. First, each of the opinion-based categories only counts if the information is also personal information, that is, information about an identified or reasonably identifiable individual. Second, biometric information is only "sensitive" when it is collected for automated verification or identification. A photograph held in a customer file, or a fingerprint scan kept for a security purpose, may or may not be sensitive information depending on how it is used, which is a question a privacy lawyer can help you work through.
Health information deserves its own attention because it is broader than medical records. Section 6FA defines it to include information about an individual's health, illness, disability or injury, their expressed wishes about future health services, and information collected in providing a health service. A gym that records injuries, a wellness app that tracks symptoms, and an employer that collects medical certificates all handle health information, even though none of them is a medical practice.
Consent plus reasonable necessity: why you can collect it at all
APP 3 sets the collection rule. For ordinary personal information, an organisation must not collect it unless it is reasonably necessary for one or more of the organisation's functions or activities. APP 3.3 adds a second condition for sensitive information: you must not collect it unless the individual consents, and the information is reasonably necessary for one or more of your functions or activities.
The drafting choice that matters most here is how consent is obtained and recorded. A clause that simply says "we collect your personal information" and relies on a pre-ticked box is not a consent mechanism. For sensitive information, consent should be genuine: informed, specific, freely given, and capable of being withdrawn. The OAIC's guidance is that consent for sensitive information will generally need to be express, and the clause should say how that consent is captured, for example through a separate opt-in tick box or a signed form, rather than by silence or inaction.
The clause should also tie the collection to a stated function of the business. If the policy says "we collect health information to provide you with physiotherapy services", the reader can see why the information is reasonably necessary. If it lists the information but not the function it serves, the clause is doing half its job.
Staying within the primary purpose: use and disclosure
APP 6 governs what you can do with the information once collected. You must not use or disclose it for a secondary purpose unless the individual consents, or one of the exceptions applies. APP 6.2(a) sets the baseline for sensitive information: a secondary use or disclosure is allowed only if the individual would reasonably expect it, and the secondary purpose is directly related to the primary purpose.
The word "directly" does real work. For ordinary personal information, the secondary purpose only needs to be related to the primary purpose. For sensitive information it must be directly related. A clinic that collects health information to treat a patient cannot turn around and use the same information for a marketing list; the secondary purpose is not directly related, and no reasonable patient would expect it. The clause should state the primary purposes for which information is collected, and any secondary purposes the business genuinely relies on, so that the "directly related" test has something to work with.
When you can act without consent: the exceptions
Both the collection rules and the use and disclosure rules carry exceptions, and a careful clause acknowledges them rather than pretending they do not exist. Under APP 6.2(b) to (e), sensitive information can be used or disclosed without consent where:
- The law requires it: the use or disclosure is required or authorised by or under an Australian law, or a court or tribunal order.
- A permitted general situation exists: broadly, circumstances such as where it is unreasonable or impracticable to obtain consent and the entity reasonably believes the action is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety.
- A permitted health situation exists: a separate set of circumstances in the Act dealing with health information, discussed below.
- Enforcement activity requires it: the entity reasonably believes the use or disclosure is reasonably necessary for an enforcement related activity conducted by or on behalf of an enforcement body.
The trap here is drafting the exceptions too loosely. A clause that says "we may disclose your information where required or authorised by law" is fine. A clause that says "we may disclose your information to government agencies as we see fit" is not, because the exceptions are narrow and situational. Each exception should be described closely enough that a reader can see which one the business is relying on and when.
The health service carve-out
For businesses in the medical, allied health or disability sectors, s 16B of the Act creates permitted health situations that sit alongside the general rules. Health information can be collected without the usual consent where, for example, the collection is necessary to provide a health service to the individual and is required or authorised by an Australian law, or is collected in accordance with rules established by competent health or medical bodies dealing with professional confidentiality obligations. There are also provisions covering the collection of a patient's family, social or medical history, which can include health information about third parties where that history is necessary to provide the health service, and research uses of health information that are relevant to public health or public safety and approved by an ethics committee.
If your business collects health information as part of providing a service, the sensitive information clause needs to reflect these carve-outs, because consent will not always be practicable, and the clause should not promise that consent will always be obtained. At the same time, where information was collected under a permitted health situation, the Act requires reasonable steps to de-identify the information before certain disclosures, so the clause should say what happens to the information at the point of disclosure.
What you promise about security and breaches
The sensitive information clause usually ends with promises about protection. APP 11 requires an entity to take such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify information it no longer needs. For sensitive information, the reasonable steps expected are higher: encryption, access controls, and limits on who in the business can see the data.
There is also the Notifiable Data Breaches scheme in Part IIIC of the Act. When an entity becomes aware of reasonable grounds to believe there has been an eligible data breach, broadly a breach likely to result in serious harm to affected individuals, it must prepare a statement, give it to the Office of the Australian Information Commissioner, and notify affected individuals or, where individual notification is not practicable, publish the statement on its website. Sensitive information is the kind of data most likely to produce serious harm, so a breach involving it will almost always trigger the notification duty. The clause should be honest about this. An absolute promise like "your information will never be disclosed" is not a promise the business can keep, because the exceptions above exist and because no security is perfect. State what you actually do, not what you wish were true.
Access, correction and complaints
APP 1 requires the privacy policy itself to say how individuals can access their personal information, seek correction, and complain about a breach of the APPs. The sensitive information clause should cross-reference those rights rather than treating sensitive information as if it sat outside them. An individual's right to see what health information you hold about them, and to have it corrected, is exactly the kind of request a business handling sensitive information should expect, and the clause should point to the process.
Clauses worth adding when they apply
Not every business needs every version of the clause, but these additions are worth considering when the trigger is present:
- Direct marketing consent clause: if you market to customers, APP 7 restricts using or disclosing personal information for direct marketing, and marketing based on sensitive information needs particularly careful handling; a separate, specific consent is the safe route.
- Overseas disclosure clause: APP 8 requires you to take reasonable steps to ensure an overseas recipient does not breach the APPs before you disclose information to them; if you use cloud providers or offshore processors, name the countries, or commit to no overseas disclosure.
- Destruction and de-identification clause: a commitment to destroy or de-identify sensitive information once it is no longer needed, which turns APP 11's requirement into a concrete promise.
- Employee information clause: the Act's employee records exemption means information about your own employees is often handled outside the customer-facing policy; a separate clause, or a deliberate silence, is a drafting decision worth making consciously.
- Health research clause: if de-identified health information is used in research, the permitted health situation conditions, including ethics approval, should be reflected so the clause does not over-promise.
How an Artificer Legal privacy lawyer can help you draft this clause
The starting point for an Artificer Legal review is not the clause itself but the business behind it: what information is actually collected, through what forms and systems, and for what functions. From there we would check that the categories listed in the clause match the reality, that the consent mechanism produces a record you could produce to the OAIC if asked, and that the use and disclosure promises match your actual practices rather than a template's.
The clauses we would push back on are the ones copied from overseas templates, which typically assume a different legal framework, and absolute promises such as "we will never share your information", which the exceptions in the Act make impossible to keep. We would insist on a consent mechanism that is express and separately documented for sensitive information, an exceptions clause that names only the situations your business genuinely relies on, and a security clause that does not promise more than your systems deliver. The order matters too: categories first, then consent, then use and disclosure, then security and breach, because each later clause depends on the decisions made in the earlier ones.
The consent record is what gets tested first
If your sensitive information clause is ever tested, whether by a customer complaint, a data breach, or an OAIC investigation, the first thing anyone will ask for is the record of consent. A clause can be elegantly drafted, but if the business cannot show that an individual actually consented to the collection of their health information or their religious affiliation, the clause is words on a page. The drafting choice that makes the difference is building the consent mechanism into the clause and into the forms and systems behind it, so that consent is captured at the point of collection and can be produced later.
To summarise: sensitive information is a defined category under the Privacy Act 1988 (Cth) that includes health, biometric and genetic information alongside racial or ethnic origin, political opinions, religious and philosophical beliefs, association memberships, sexual orientation and criminal records. Collection requires both consent and reasonable necessity. Use and disclosure for other purposes requires a directly related secondary purpose, or one of the narrow statutory exceptions. The clause should name what you collect, how consent is captured, what you will use the information for, and what happens if it is breached. A lawyer's review will make sure each promise matches what the business actually does.