Privacy Act 1988
Sections and provisions with full text and the judgments that cite each one.
Section 26E — Development of APP codes by APP code developers
Own initiative (1) An APP code developer may develop an APP code. At the Commissioner’s request (2) The Commissioner may, in writing, request an APP code developer to develop an APP code, and apply…
Section 26WE — Eligible data breach
Scope (1) This section applies if: (a) both: (i) an APP entity holds personal information relating to one or more individuals; and (ii) the APP entity is required under section 15 not to do an act,…
Section 26XE — Constitutional basis of this Division
This Division relies on the Commonwealth’s legislative powers under paragraph 51(xxix) (external affairs) of the Constitution as it relates to giving effect to Australia’s obligations under relevant…
Section 26F — Application for registration of APP codes
(1) If an APP code developer develops an APP code, the developer may apply to the Commissioner for registration of the code. (2) Before making the application, the APP code developer must: (a) make a…
Section 26WF — Exception—remedial action
Access to, or disclosure of, information (1) If: (a) an access to, or disclosure of, information is covered by paragraph 26WE(2)(a); and (b) the APP entity, credit reporting body, credit provider or…
Section 26XF — Additional operation of this Division
(1) In addition to section 26XE, this Division also has effect as provided by this section. Corporations (2) This Division also has the effect it would have if a reference to a collection, use or…
Section 26G — Development of APP codes by the Commissioner—following a request
(1) This section applies if the Commissioner made a request under subsection 26E(2) and either: (a) the request has not been complied with; or (b) the request has been complied with but the…
Section 26WG — Whether access or disclosure would be likely, or would not be likely, to result in serious harm—relevant matters
For the purposes of this Division, in determining whether a reasonable person would conclude that an access to, or a disclosure of, information: (a) would be likely; or (b) would not be likely; to…
Section 26XG — Interaction with section 12B
To avoid doubt, section 12B does not apply in relation to this Division.
Section 26H — Commissioner may register APP codes
(1) If: (a) an application for registration of an APP code is made under section 26F; or (b) the Commissioner develops an APP code under section 26G, 26GA or 26GB; or (c) the Commissioner develops a…
Section 26WH — Assessment of suspected eligible data breach
Scope (1) This section applies if: (a) an entity is aware that there are reasonable grounds to suspect that there may have been an eligible data breach of the entity; and (b) the entity is not aware…
Section 26XH — Compensation for acquisition of property
(1) If the operation of this Division would result in an acquisition of property (within the meaning of paragraph 51(xxxi) of the Constitution) from a person otherwise than on just terms (within the…
Section 26J — Variation of registered APP codes
(1) The Commissioner may, in writing, approve a variation of a registered APP code: (a) on his or her own initiative; or (b) on application by an APP entity that is bound by the code; or (c) on…
Section 26WJ — Exception—eligible data breaches of other entities
If: (a) an entity complies with section 26WH in relation to an eligible data breach of the entity; and (b) the access, disclosure or loss that constituted the eligible data breach of the entity is an…
Section 26K — Removal of registered APP codes
(1) The Commissioner may remove a registered APP code from the Codes Register: (a) on his or her own initiative; or (b) on application by an APP entity that is bound by the code; or (c) on…
Section 26WK — Statement about eligible data breach
Scope (1) This section applies if an entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity. Statement (2) The entity must: (a) both:…
Section 26L — Entities to comply with the registered CR code if bound by the code
If an entity is bound by the registered CR code, the entity must not do an act, or engage in a practice, that breaches the code. Note: There must always be one, and only one, registered CR code at…
Section 26WL — Entity must notify eligible data breach
Scope (1) This section applies if: (a) an entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity; and (b) the entity has prepared a…
Section 26M — What is the registered CR code
(1) The registered CR code is the CR code that is included on the Codes Register. (2) The registered CR code is a legislative instrument. (3) Subsection 12(2) (retrospective application of…
Section 26WM — Exception—eligible data breaches of other entities
If: (a) an entity complies with sections 26WK and 26WL in relation to an eligible data breach of the entity; and (b) the access, disclosure or loss that constituted the eligible data breach of the…
Section 26N — What is a CR code
(1) A CR code is a written code of practice about credit reporting. (2) A CR code must: (a) set out how one or more of the provisions of Part IIIA are to be applied or complied with; and (b) make…
Section 26WN — Exception—enforcement related activities
If: (a) an entity is an enforcement body; and (b) the chief executive officer of the enforcement body believes on reasonable grounds that there has been an eligible data breach of the entity; and (c)…
Section 26P — Development of CR code by CR code developers
(1) The Commissioner may, in writing, request a CR code developer to develop a CR code and apply to the Commissioner for the code to be registered. (2) The request must: (a) specify the period within…
Section 26WP — Exception—inconsistency with secrecy provisions
Secrecy provisions (1) For the purposes of this section, secrecy provision means a provision that: (a) is a provision of a law of the Commonwealth (other than this Act); and (b) prohibits or…
Section 26Q — Application for registration of CR code
(1) If a CR code developer develops a CR code, the developer may apply to the Commissioner for registration of the code. (2) Before making the application, the CR code developer must: (a) make a…
Section 26WQ — Exception—declaration by Commissioner
(1) If the Commissioner: (a) is aware that there are reasonable grounds to believe that there has been an eligible data breach of an entity; or (b) is informed by an entity that the entity is aware…
Section 26R — Development of CR code by the Commissioner
(1) The Commissioner may develop a CR code if the Commissioner made a request under section 26P and either: (a) the request has not been complied with; or (b) the request has been complied with but…
Section 26WR — Commissioner may direct entity to notify eligible data breach
(1) If the Commissioner is aware that there are reasonable grounds to believe that there has been an eligible data breach of an entity, the Commissioner may, by written notice given to the entity,…
Section 26S — Commissioner may register CR code
(1) If: (a) an application for registration of a CR code is made under section 26Q; or (b) the Commissioner develops a CR code under section 26R; the Commissioner may register the code by including…
Section 26WS — Exception—enforcement related activities
An entity is not required to comply with a direction under subsection 26WR(1) if: (a) the entity is an enforcement body; and (b) the chief executive officer of the enforcement body believes on…
Section 26T — Variation of the registered CR code
(1) The Commissioner may, in writing, approve a variation of the registered CR code: (a) on his or her own initiative; or (b) on application by an entity that is bound by the code; or (c) on…
Section 26WT — Exception—inconsistency with secrecy provisions
Secrecy provisions (1) For the purposes of this section, secrecy provision means a provision that: (a) is a provision of a law of the Commonwealth (other than this Act); and (b) prohibits or…
Section 26U — Codes Register
(1) The Commissioner must keep a register (the Codes Register) which includes: (a) the APP codes the Commissioner has decided to register under section 26H; and (b) the APP codes the Commissioner…
Section 26WU — Power to obtain information and documents relating to eligible data breaches
(1) This section applies if the Commissioner has reason to believe that a person or entity has information or documents, or can answer questions, that are relevant to either or both of the following…
Section 26V — Guidelines relating to codes
(1) The Commissioner may make written guidelines: (a) to assist APP code developers to develop APP codes; or (b) to assist APP entities bound by registered APP codes to apply or comply with the…
Section 26W — Review of operation of registered codes
(1) The Commissioner may review the operation of a registered APP code. Note: The review may inform a decision by the Commissioner to approve a variation of a registered APP code or to remove a…
Section 26X — Eligible data breach declaration
Minister may make eligible data breach declaration (1) The Minister may, by writing, make a declaration under this subsection if: (a) there is an eligible data breach of an entity; and (b) the…
Section 27 — Functions of the Commissioner
(1) The Commissioner has the following functions: (a) the functions that are conferred on the Commissioner by or under: (i) this Act; or (ii) any other law of the Commonwealth; (b) the guidance…
Section 28 — Guidance related functions of the Commissioner
(1) The following are the guidance related functions of the Commissioner: (a) making guidelines for the avoidance of acts or practices that may or might be interferences with the privacy of…
Section 28A — Monitoring related functions of the Commissioner
Credit reporting and tax file number information (1) The following are the monitoring related functions of the Commissioner: (a) monitoring the security and accuracy of information held by an entity…
Section 28B — Advice related functions of the Commissioner
(1) The following are the advice related functions of the Commissioner: (a) providing advice to a Minister or entity about any matter relevant to the operation of this Act; (b) informing the Minister…
Section 29 — Commissioner must have due regard to the objects of the Act
The Commissioner must have due regard to the objects of this Act in performing the Commissioner’s functions, and exercising the Commissioner’s powers, conferred by this Act. Note: The objects of this…
Section 30 — Reports following investigation of act or practice
(1) Where the Commissioner has investigated an act or practice without a complaint having been made under section 36, the Commissioner may report to the Minister about the act or practice, and shall…
Section 31 — Report following examination of proposed law
(1) Where the Commissioner has examined a proposed Commonwealth law under paragraph 28A(2)(a), subsections (2) and (3) of this section have effect. (2) If the Commissioner thinks that the proposed…
Section 32 — Commissioner may report to the Minister if the Commissioner has monitored certain activities etc.
(1) If the Commissioner has: (a) monitored an activity in the performance of a function under paragraph 28(1)(d), 28A(1)(a), (b), (d) or (e) or (2)(b), (c) or (d) or 28B(1)(b) or (c); or (b)…
Section 33 — Exclusion of certain matters from reports
(1) In setting out findings, opinions and reasons in a report to be given under section 30, 31, 32 or 33J, the Commissioner may exclude a matter if the Commissioner considers it desirable to do so…
Section 33A — Commissioner may share information with other authorities
(1) Subject to subsections (3) and (4), the Commissioner may share information or documents with a body covered by subsection (2) (a receiving body): (a) for the purpose of the Commissioner…
Section 33B — Commissioner may disclose certain information if in the public interest etc.
Information may generally be disclosed if in the public interest (1) The Commissioner may disclose information acquired by the Commissioner in the course of exercising powers or performing functions…
Section 33C — Commissioner may conduct an assessment relating to the Australian Privacy Principles etc.
(1) The Commissioner may conduct an assessment of the following matters: (a) whether personal information held by an APP entity is being maintained and handled in accordance with the following: (i)…
Section 33D — Commissioner may direct an agency to give a privacy impact assessment
(1) If: (a) an agency proposes to engage in an activity or function involving the handling of personal information about individuals; and (b) the Commissioner considers that the activity or function…
