Sitemap | OAIC We use cookies on this site We use cookies to analyse traffic and to improve your browsing experience on our website. To find out more, read our privacy policy. Close Skip to main content News Join our team Contact us Home Privacy Privacy Your privacy rights Privacy complaints Australian Privacy Principles Privacy guidance for organisations and government agencies Notifiable data breaches Privacy legislation Privacy assessments and decisions Privacy registers Privacy for Kids Freedom of information Freedom of information Your freedom of information rights How to access government information Freedom of information guidance for government agencies Freedom of information legislation and determinations Information Commissioner decisions and reports Freedom of information statistics for the OAIC Australian Government freedom of information statistics Consumer Data Right Consumer Data Right Information for consumers Consumer Data Right complaints Consumer Data Right guidance for business Consumer Data Right legislation, regulation and definitions Consumer Data Right assessments Digital ID Engage with us Engage with us Consultations Submissions Translations Events Networks Research and training resources About the OAIC About the OAIC What we do Who we are Join our team Access our information Our regulatory approach Our corporate information Commissioner Priorities Information policy Serving legal documents on the Australian Information Commissioner News Join our team Contact us Sitemap Sitemap Privacy Your privacy rights Your personal information What is personal information? What is privacy? What is a privacy policy? Access your personal information Correct your personal information Request a record Consent to the handling of personal information Collection of personal information Use and disclosure of personal information Your tax file number Credit reporting What is credit reporting? What is a credit report? Credit reporting terms What stays on a credit report? Access your credit report Correct your credit report Information on your credit report Repayment history and defaults Third-party access to credit reports Fraud and your credit report Hardship assistance About hardship assistance What is a financial hardship arrangement? What is financial hardship information? Commercial credit information Make a credit reporting complaint Real estate agents, employers and your credit report Data breaches What is a data breach? What is a notifiable data breach? Respond to a data breach notification Identity fraud Act quickly if you're affected by a data breach Data breach support and resources Make a data breach complaint Health information What is health information? What is a health service provider? Access your health information Correct your health information Handling health information My Health Record About My Health Record What is an individual healthcare identifier? Manage your My Health Record Emergency access to your My Health Record Make a My Health Record complaint Social media and online privacy Mobile devices Online safety Photos and videos Social media Reboot your privacy and protect your personal information online Targeted online marketing Surveillance and monitoring Biometric scanning Drones ID scanning Security cameras Workplace monitoring and surveillance Ways to protect your privacy Tips to protect your privacy Tips to protect your My Health Record Privacy tips for parents and carers More privacy rights Advertising, marketing and spam Children and young people COVID-19 COVID-19: Vaccinations and your privacy rights as an employee COVID-19 check-in apps and privacy Criminal records Employment Government agencies Political parties and elections Tenancy Bushfire emergency Statutory tort for serious invasions of privacy Social Media Minimum Age General resource Children and young people Parent and carers resource Social Media Minimum Age privacy tips for young people Social Media Minimum Age: How do I make a complaint? Privacy complaints Representative complaint: Medibank data breach What you can complain about Complain to an organisation or agency Before you lodge a privacy complaint with us How we investigate and resolve your complaint Your complaint review rights External dispute resolution schemes Privacy complaint: immigration data breach Immigration data breach privacy complaint Notice to all persons in immigration detention on 31 January 2014: English version Immigration data breach privacy complaint determination in English and other languages OAIC Notice – immigration data breach privacy complaint OAIC Notice - Immigration Data Breach Privacy Complaint - Arabic OAIC Notice - Immigration Data Breach Privacy Complaint - Azerbaijani OAIC Notice - Immigration Data Breach Privacy Complaint - Bangla OAIC Notice - Immigration Data Breach Privacy Complaint - Burmese OAIC Notice - immigration data breach privacy complaint: simplified Chinese OAIC Notice - immigration data breach privacy complaint: traditional Chinese OAIC Notice - Immigration Data Breach Privacy Complaint - Dari OAIC Notice - Immigration Data Breach Privacy Complaint - Farsi OAIC Notice - Immigration Data Breach Privacy Complaint - Hazaragi OAIC Notice - Immigration Data Breach Privacy Complaint - Hindi OAIC Notice - Immigration Data Breach Privacy Complaint - Indonesian OAIC Notice - Immigration Data Breach Privacy Complaint - Kurdish OAIC Notice - Immigration Data Breach Privacy Complaint - Pashto OAIC Notice - Immigration Data Breach Privacy Complaint - Punjabi OAIC Notice - Immigration Data Breach Privacy Complaint - Syhleti OAIC Notice - Immigration Data Breach Privacy Complaint - Tamil OAIC Notice - Immigration Data Breach Privacy Complaint - Urdu OAIC Notice - Immigration Data Breach Privacy Complaint - Uzbekistani OAIC Notice - Immigration Data Breach Privacy Complaint - Vietnamese Representative complaint about the handling of personal information by Dymocks Pty Ltd Representative complaint about the handling of personal information by Ticketek Pty Ltd Australian Privacy Principles Australian Privacy Principles quick reference Australian Privacy Principles guidelines Summary of version changes to APP guidelines Preface Chapter A: Introductory matters Chapter B: Key concepts Chapter C: Permitted general situations Chapter D: Permitted health situations Chapter 1: APP 1 Open and transparent management of personal information Chapter 2: APP 2 Anonymity and pseudonymity Chapter 3: APP 3 Collection of solicited personal information Chapter 4: APP 4 Dealing with unsolicited personal information Chapter 5: APP 5 Notification of the collection of personal information Chapter 6: APP 6 Use or disclosure of personal information Chapter 7: APP 7 Direct marketing Chapter 8: APP 8 Cross-border disclosure of personal information Chapter 9: APP 9 Adoption, use or disclosure of government related identifiers Chapter 10: APP 10 Quality of personal information Chapter 11: APP 11 Security of personal information Chapter 12: APP 12 Access to personal information Chapter 13: APP 13 Correction of personal information Read the Australian Privacy Principles Privacy guidance for organisations and government agencies Organisations Credit reporting About credit reporting Repayment history information Credit reporting information retention periods Guidance for industry on corrections requests and the ‘no wrong door’ approach to corrections Guidance for industry on ‘publicly available information’ and ‘court proceedings information’ Direct marketing Employee records exemption ID scanners Opting in to the Privacy Act Privacy for not-for-profits, including charities Privacy management plan template Selling a business Small business Sporting clubs Start-ups Tips for good privacy practice Trading in personal information Guidance for EDR schemes when handling complaints about notifiable data breaches Tracking pixels and privacy obligations Facial recognition technology: a guide to assessing the privacy risks Privacy Foundations self-assessment tool Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act Template privacy collection notice for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act Age assurance technologies and privacy obligations Government agencies Agency referee reports Australian Government Agencies Privacy Code About the Australian Government Agencies Privacy Code Interactive privacy management plan Privacy (Australian Government Agencies – Governance) APP Code 2017 When do agencies need to conduct a privacy impact assessment? Conducting surveys Guidelines on data matching in Australian Government administration Privacy impact assessment register assessment program Privacy Code checklist Guidance on privacy and developing and training generative AI models Guidance on privacy and the use of commercially available AI products Health service providers Communications with patients Data breach action plan for health service providers Guide to health privacy Introduction and key concepts Chapter 1: Key steps to embedding privacy in your health practice Chapter 2: Collecting health information Chapter 3: Using or disclosing health information Chapter 4: Giving access to health information Chapter 5: Correcting health information Chapter 6: Health management activities Chapter 7: Disclosing information about patients with impaired capacity Chapter 8: Using and disclosing genetic information in the case of a serious threat Chapter 9: Research Individual healthcare identifiers Individual healthcare identifiers: obligations for public health service providers Individual healthcare identifiers: obligations for private health service providers Individual healthcare identifiers on COVID-19 digital vaccination certificates My Health Record Using the My Health Record system Handling information in a My Health Record My Health Record access controls My Health Record emergency access function Security and Access policies – Rule 42 guidance Guide to mandatory data breach notification in the My Health Record system Privacy action plan for your health practice Taking photos of patients Handling personal information Centrelink requests for information Dealing with requests for access to personal information Dealing with requests for correction of personal information De-identification and the Privacy Act De-identification Decision-Making Framework Guide to securing personal information Guide to the Privacy (Persons Reported as Missing) Rule 2024 Guidelines for state and territory governments: creating nationally consistent requirements to collect personal information for contact tracing purposes National Relay Service Posting photos and videos Protecting customers' personal information Sending personal information overseas The Privacy (Tax File Number) Rule 2015 and the protection of tax file number information Transfer of financial adviser records What is personal information? Privacy impact assessments 10 steps to undertaking a privacy impact assessment Assessing privacy risks in changed working environments: privacy impact assessments Guide to undertaking privacy impact assessments Privacy by design Privacy impact assessment tool COVID-19 Coronavirus (COVID-19): understanding your privacy obligations to your staff Coronavirus (COVID-19) vaccinations: understanding your privacy obligations to your staff COVIDSafe Reports COVIDSafe Report May–November 2022 COVIDSafe Report November 2021–May 2022 COVIDSafe Report May–November 2021 COVIDSafe Report November 2020–May 2021 COVIDSafe Report May–November 2020 Guidance for businesses collecting personal information for contract tracing National COVID-19 privacy principles Privacy update on the COVIDSafe app Retention and deletion of personal information collected during COVID-19 Guidance for businesses collecting COVID-19 vaccination information More guidan…