Shoalhaven City Council - Environment - Growth - Community Home Page
 

THE PRIVACY AND PERSONAL INFORMATION ACT

The Privacy and Personal Information Protection Act, 1998 (the Privacy Act) has been introduced in stages with key parts commencing on 1 July, 2000. The Act provides protection for personal information and the privacy of individuals in general. To achieve this the Act introduces a set of privacy principles that regulate the way Council deals with personal information.

Privacy Code of Practice

A Privacy Code of Practice (for Local Government) has been approved by the Attorney General and is binding on all local government authorities. The Code modifies the privacy principles and the public register provisions of the Privacy Act and will better enable councils to fulfil their statutory duties whilst still complying with the Act.

Privacy Management

PlanCouncil’s Privacy Management Plan (PMP) incorporates the departures brought about by the Privacy Code of Practice (Local Government) and details privacy policies and procedures. The Plan deals with;-

What is personal information?

Under the Act, personal information means any information or opinion about an individual whose identity is apparent or can be reasonably ascertained from the information. This definition covers not only traditional ideas of data storage such as paper files, but also electronic records, video recordings, photographs and genetic material. A person does not have to be clearly identified by the information, it is only necessary that their identity can reasonably be ascertained from the information. Whilst the definition of personal information is very broad, the Act excludes certain types of information from the definition. The most significant exceptions are:

How is personal information protected?

Information is protected by a number of information protection principles contained within the Act. In general terms, the principles apply to the way material is collected, stored, used and disclosed. A summary of the information protection principles appears at the end of this document. It should be noted that the privacy legislation relates to personal information only.

What documents are covered by the Privacy Act?

The Act covers all Council documents in so far as the collection, access and use of personal information is concerned. However, with respect to the disclosure of personal information, local councils are in a unique position in that the requirements of the Privacy Act apply only to personal information held on public registers. Therefore, applications or access requests for personal information from sources other than public registers will continue to be dealt with under Section 12 of the Local Government Act or the Freedom of Information Act *.

* Notwithstanding the above, a person may stipulate that access to his/her own personal information be provided under the PPIPA.

What is a public register?

The Act defines a public register as a register containing personal information which is required by law to be, or is made, publicly available or open to public inspection. Registers held by Council include;

The register required to be kept under the Companion Animals Act, 1998 is not considered to be a public register in terms of the PPIP Act.

How should you deal with a request for information held on a public register?

The Privacy Code allows councils to depart from the requirements of the Act in the following ways.

The Code allows some discretion with respect to public access (sale/copy) to whole or substantial parts of a Public Register. However, having regard to the intention of the Act and the potential for inappropriate use, Council will continue with the current practice whereby bulk property data will be made available for purchase but listings will not include personal information.

Whilst staff are no longer required to ask a person why they want personal information from a Public Register, access should still be refused where a particular use is known to be inappropriate. Staff can require the applicant to complete a statutory declaration prior to providing any information if it was thought to be appropriate in any particular case. Statutory declarations are available from Counter Services staff at Nowra and Ulladulla offices. Completed declarations should be forwarded to the Records Section for registration and filing.

What is a legitimate purpose?

According to the Privacy Commission most public concern about privacy breaches from councils relate to personal information disclosed from the Rate Record. Whilst the Rate Record has been used for the purpose of these guidelines the examples of information ‘usage’ given would generally relate to other registers held by Council.

The primary purpose of Rate Record is to record the value of a parcel of land and record rate liability in respect of that land. The secondary purpose includes recording the owner or lessee of each parcel of land. Due to the emphasis on local government processes and information being open and accountable, it is considered that a secondary purpose for which all public registers are held includes the provision of access to members of the public. Of course only the minimum amount of personal information should be disclosed in regard to any request.

Use by Council

Legitimate Council use would include;

Use by government agencies

Information should continue to be made available to other government agencies where it is to be used for legitimate purposes. Council regularly receives requests for ownership and property details where owner notification or contact (individual or multiple) is required or considered appropriate.

Applications for personal information from a register (bulk listings etc) should be in writing and proposed use should be clearly stated. The use should always relate to activities associated with the functions of that agency. (eg DUAP, Waterways, National Parks & Forestry). Other government agencies such as Centrelink and Veterans Affairs will be provided with information where there is a legal requirement to do so.

Business use

One of the main reasons for including public register provisions in privacy legislation was to provide a means of addressing widespread public concerns over the commercial sale of council information. It was generally felt that the information was being used for a reason that had no clear relationship to the reasons for which it was collected. The use of information for marketing purposes therefore needs to be distinguished from legitimate professional use by valuers and real estate agents.

With regard to the sale of bulk data (Rate Record and Building/Development Statistics), Council has taken steps to remove all personal information (names & mailing addresses) from lists and subscribers have been advised accordingly. Lists containing property information only, will continue to be made available for inspection or purchase.

Land transfer notices have traditionally been made available for the inspection of Valuers. It is recognised that the names of vendors and purchasers are required in order that valuers can establish whether the price reflects an arms length sale or not. Whilst councils are not the only source of this information this is considered to be a legitimate use and Council will therefore allow this access to continue.

Public use

As mentioned there is no longer any requirement to establish a use prior to disclosing personal information. However there will be occasions where staff will need some guidance in regards to legitimate and inappropriate use. Legitimate uses would include those relating to;

Inappropriate use

Whilst inappropriate uses are more difficult to define, examples could include;

There will no doubt be occasions when a valued judgement with respect to disclosure will need to be made, however most requests will fall within the examples given. If staff have any difficulty in this regard the advice of the Information Officer should be sought.

Can a person apply to have their details removed from a public register?

The Act gives people a right to have their personal details hidden or removed from a public register where they can show that the safety or well-being of any person might be affected if the information was to remain on the record. Council must suppress the information unless it is satisfied that the public interest in maintaining public access to the information outweighs any individual interest.

What can an individual do if personal information is collected or used wrongly?

A number of legal remedies are available to people who feel they have had their privacy breached. The aggrieved person may lodge a complaint with the Privacy Commissioner or apply to Council for a review of the conduct which is the subject of the complaint. Legal remedies are available when a public sector agency:

There are five possible things an agency can do about a complaint. It can:

If the complainant is not satisfied with the Council’s findings or what Council proposes to do, they can appeal to the Administrative Decisions Tribunal. One of the more significant orders the Administrative Decisions Tribunal can make is awarding damages of up to $40,000 to the person making the complaint, where that person has suffered financial loss or was physically or psychologically injured.

Offences

The Act details offences for corruptly dealing with personal information. Harsh penalties (up to a maximum of $11,000 and 2 years in prison) can be given if public sector officials, including former public sector officials, deliberately disclose, or offer to supply personal information outside of their lawful powers. Penalties also apply to any other persons who induce or attempt to induce a public sector official to act in this way (eg bribes and other such conduct).

Further information may be obtained by contacting the Privacy Officer, Rob McLean on extension 3366.

Information Protection Principles

The information protection principles are summarised as follows:-

Principle 1 - Collection of information for lawful purposes

Principle 2 - Collection of information directly from the individual

Principle 3 - Requirements when collecting information

If collected from an individual reasonable steps must be taken to ensure that, before collection or soon after, the individual is aware of:

Principle 4 - Other requirements relating to collection of personal information

Principle 5 - Retention & Security

In holding information Council must ensure that:-

Principle 6 - Information about personal information held by Council

Council must take such steps as are reasonable to enable any person to ascertain:

Principle 7 - Access to personal information held by Council

Council must provide access to information to an individual to whom the information relates

Principle 8 - Alteration of personal information

Personal information (of the individual concerned) must be amended on request (so as to ensure accuracy)

Principle 9 - Accuracy of information

Personal information must not be used unless, prior to use, reasonable steps have been taken to ensure its accuracy

Principle 10 - Limits of use of information

Personal information must not be used for any purpose other than the purpose for which it was collected unless:

 

Top of page