Privacy Act 1988
Sections and provisions with full text and the judgments that cite each one.
Section 21D — Disclosure of credit information to a credit reporting body
Prohibition on disclosure (1) A credit provider must not disclose credit information about an individual to a credit reporting body (whether or not the body’s credit reporting business is carried on…
Section 21E — Payment information must be disclosed to a credit reporting body
If: (a) a credit provider has disclosed default information about an individual to a credit reporting body under section 21D; and (b) after the default information was disclosed, the amount of the…
Section 21F — Limitation on the disclosure of credit information during a ban period
(1) This section applies if: (a) a credit reporting body holds credit reporting information about an individual; and (b) a credit provider requests the body to disclose the information to the…
Section 21G — Use or disclosure of credit eligibility information
Prohibition on use or disclosure (1) If a credit provider holds credit eligibility information about an individual, the provider must not use or disclose the information. Civil penalty: 2,000 penalty…
Section 21H — Permitted CP uses in relation to individuals
A use by a credit provider of credit eligibility information about an individual is a permitted CP use in relation to the individual if: (a) the relevant credit reporting information was disclosed to…
Section 21J — Permitted CP disclosures between credit providers
Consent (1) A disclosure by a credit provider of credit eligibility information about an individual is a permitted CP disclosure in relation to the individual if: (a) the disclosure is to another…
Section 21K — Permitted CP disclosures relating to guarantees etc.
Offer to act as a guarantor etc. (1) A disclosure by a credit provider of credit eligibility information about an individual is a permitted CP disclosure in relation to the individual if: (a) either:…
Section 21L — Permitted CP disclosures to mortgage insurers
A disclosure by a credit provider of credit eligibility information about an individual is a permitted CP disclosure in relation to the individual if the disclosure is to a mortgage insurer that has…
Section 21M — Permitted CP disclosures to debt collectors
(1) A disclosure by a credit provider of credit eligibility information about an individual is a permitted CP disclosure in relation to the individual if: (a) the disclosure is to a person or body…
Section 21N — Permitted CP disclosures to other recipients
Mortgage credit assistance schemes (1) A disclosure by a credit provider of credit eligibility information about an individual is a permitted CP disclosure in relation to the individual if: (a) the…
Section 21P — Notification of a refusal of an application for consumer credit
(1) This section applies if: (a) a credit provider refuses an application for consumer credit made in Australia: (i) by an individual; or (ii) jointly by an individual and one or more other persons…
Section 21Q — Quality of credit eligibility information
(1) A credit provider must take such steps (if any) as are reasonable in the circumstances to ensure that the credit eligibility information the provider collects is accurate, up-to-date and…
Section 21R — False or misleading credit information or credit eligibility information
Offences (1) A credit provider commits an offence if: (a) the provider discloses credit information under section 21D; and (b) the information is false or misleading in a material particular.…
Section 21S — Security of credit eligibility information
(1) If a credit provider holds credit eligibility information, the provider must take such steps as are reasonable in the circumstances to protect the information: (a) from misuse, interference and…
Section 21T — Access to credit eligibility information
Access (1) If a credit provider holds credit eligibility information about an individual, the provider must, on request by an access seeker in relation to the information, give the access seeker…
Section 21U — Correction of credit information or credit eligibility information
(1) If: (a) a credit provider holds credit information or credit eligibility information about an individual; and (b) the provider is satisfied that, having regard to a purpose for which the…
Section 21V — Individual may request the correction of credit information etc.
Request (1) An individual may request a credit provider to correct personal information about the individual if: (a) the personal information is: (i) credit information about the individual; or (ii)…
Section 21W — Notice of correction etc. must be given
(1) This section applies if an individual requests a credit provider to correct personal information under subsection 21V(1). Notice of correction etc. (2) If the credit provider corrects personal…
Section 22 — Guide to this Division
This Division sets out rules that apply to affected information recipients in relation to their handling of their regulated information. If an affected information recipient is an APP entity, the…
Section 22A — Open and transparent management of regulated information
(1) The object of this section is to ensure that an affected information recipient manages the regulated information of the recipient in an open and transparent way. Compliance with this Division…
Section 22B — Additional notification requirements for affected information recipients
If an affected information recipient is an APP entity, then the matters for the purposes of Australian Privacy Principle 5.1 include the following matters to the extent that the personal information…
Section 22C — Use or disclosure of information by mortgage insurers or trade insurers
Prohibition on use or disclosure (1) If: (a) a mortgage insurer or trade insurer holds or held personal information about an individual; and (b) the information was disclosed to the insurer by a…
Section 22D — Use or disclosure of information by a related body corporate
Prohibition on use or disclosure (1) If: (a) a body corporate holds or held credit eligibility information about an individual; and (b) the information was disclosed to the body by a credit provider…
Section 22E — Use or disclosure of information by credit managers etc.
Prohibition on use or disclosure (1) If: (a) a person holds or held credit eligibility information about an individual; and (b) the information was disclosed to the person by a credit provider under…
Section 22F — Use or disclosure of information by advisers etc.
Prohibition on use or disclosure (1) If: (a) any of the following (the recipient) holds or held credit eligibility information about an individual: (i) an entity; (ii) a professional legal adviser of…
Section 23 — Jurisdiction
Federal and State courts (1) Jurisdiction is conferred on the Federal Circuit and Family Court of Australia (Division 2) in relation to matters arising under this Schedule. Note: State courts and the…
Section 23A — Individual may complain about a breach of a provision of this Part etc.
Complaint (1) An individual may complain to a credit reporting body about an act or practice engaged in by the body that may be a breach of either of the following provisions in relation to the…
Section 23B — Dealing with complaints
(1) If an individual makes a complaint under section 23A, the respondent for the complaint: (a) must, within 7 days after the complaint is made, give the individual a written notice that: (i)…
Section 23C — Notification requirements relating to correction complaints
(1) This section applies if an individual makes a complaint under section 23A about an act or practice that may breach section 20S or 21U (which deal with the correction of personal information by…
Section 24 — Obtaining credit reporting information from a credit reporting body
Offences (1) An entity commits an offence if: (a) the entity obtains credit reporting information; and (b) the information is obtained from a credit reporting body; and (c) the entity is not: (i) an…
Section 24A — Obtaining credit eligibility information from a credit provider
Offences (1) An entity commits an offence if: (a) the entity obtains credit eligibility information; and (b) the information is obtained from a credit provider; and (c) the entity is not: (i) an…
Section 25 — Compensation orders
(1) The Federal Court or the Federal Circuit and Family Court of Australia (Division 2) may order an entity to compensate a person for loss or damage (including injury to the person’s feelings or…
Section 25A — Other orders to compensate loss or damage
(1) This section applies if: (a) either: (i) a civil penalty order has been made under subsection 82(3) of the Regulatory Powers Act against the entity for a contravention of a civil penalty…
Section 25B — Review of operation of this Part
(1) The Minister must cause an independent review to be conducted of the operation of this Part. (2) The persons who conduct the review must complete it, and give the Minister a written report of the…
Section 26 — Guide to this Part
This Part deals with privacy codes. Division 2 deals with codes of practice about information privacy, called APP codes. APP code developers or the Commissioner may develop APP codes, which: (a) must…
Section 26A — APP entities to comply with binding registered APP codes
An APP entity must not do an act, or engage in a practice, that breaches a registered APP code that binds the entity.
Section 26GA — Development of APP codes by the Commissioner—at the direction of the Minister
Minister may give direction (1) The Minister may, in writing, direct the Commissioner to develop an APP code if the Minister is satisfied that it is in the public interest: (a) to develop the code;…
Section 26WA — Guide to this Part
• This Part sets up a scheme for notification of eligible data breaches. • An eligible data breach happens if: (a) there is unauthorised access to, unauthorised disclosure of, or loss of, personal…
Section 26XA — When declarations cease to be in force
An eligible data breach declaration ceases to be in force at the earliest of the following: (a) if a time at which the declaration will cease to be in force is specified in the declaration—at that…
Section 26B — What is a registered APP code
(1) A registered APP code is an APP code: (a) that is included on the Codes Register; and (b) that is in force. (2) A registered APP code is a legislative instrument. (3) Subsection 12(2)…
Section 26GB — Development of APP codes by the Commissioner—temporary APP codes
Minister may give direction (1) The Minister may, in writing, direct the Commissioner to develop an APP code (a temporary APP code) if the Minister is satisfied that: (a) it is in the public…
Section 26WB — Entity
For the purposes of this Part, entity includes a person who is a file number recipient.
Section 26XB — Authorisation of collection, use and disclosure of personal information
(1) At any time when an eligible data breach declaration is in force in relation to an eligible data breach, an entity may collect, use or disclose personal information about an individual if: (a)…
Section 26C — What is an APP code
(1) An APP code is a written code of practice about information privacy. (2) An APP code must: (a) set out how one or more of the Australian Privacy Principles are to be applied or complied with; and…
Section 26GC — Development of APP codes by the Commissioner—Children’s Online Privacy Code
Children’s Online Privacy Code (1) The Commissioner must develop an APP code (the Children’s Online Privacy Code) about online privacy for children. (2) The other provisions of this Division…
Section 26WC — Deemed holding of information
Overseas recipients (1) If: (a) an APP entity has disclosed personal information about one or more individuals to an overseas recipient; and (b) Australian Privacy Principle 8.1 applied to the…
Section 26XC — Disclosure of information—offence
(1) A person (the first person) commits an offence if: (a) personal information that relates to an individual is disclosed to the first person because of the operation of this Division; and (b) the…
Section 26D — Extension of Act to exempt acts or practices covered by registered APP codes
If a registered APP code covers an act or practice that is exempt within the meaning of subsection 7B(1), (2) or (3), this Act applies in relation to the code as if that act or practice were not…
Section 26WD — Exception—notification under the My Health Records Act 2012
If: (a) an unauthorised access to information; or (b) an unauthorised disclosure of information; or (c) a loss of information; has been, or is required to be, notified under section 75 of the My…
Section 26XD — Division not limited by secrecy provisions
(1) The operation of this Division is not limited by a secrecy provision of any other Commonwealth law (whether made before or after the commencement of this Act) except to the extent that the…
