IRO Privacy management plan

About Independent Review Office

The Independent Review Office (IRO) is an independent statutory body in NSW that plays a critical role in the personal injury system. The IRO helps injured workers and motor vehicle crash claimants resolve disputes with insurers and provides legal funding to support claimants in navigating complex processes.

As part of the Department of Customer Service, the IRO is committed to integrity, fairness and independence. Our work has a real and meaningful impact on the lives of people across NSW, and we are dedicated to fostering a supportive, inclusive and purpose driven workplace

About the Privacy Management Plan

The IRO Privacy Management Plan (IRO PMP) explains how we manage personal and health information under NSW privacy laws. We have obligations to protect the privacy rights of customers, employees, and members of the public. It is designed based on principles outlined in our IRO Policy Framework. This Plan will be reviewed and updated as required to ensure ongoing compliance with all applicable privacy laws and to address any changes in processes, procedures or other events.

Why we need this policy

We have an obligation to protect the privacy rights of customers, employees, and members of the public. Section 33 of the Privacy and Personal Information Protection Act 1998 (NSW) (PPIPA) requires that we have this IRO PMP available.

Our IRO PMP shows what measures we take to comply with the PPIPA and the Health Records and Information Privacy Act 2002 (NSW) (HRIPA) to protect personal and health information.

Provisions in the privacy legislation provide for penalties up to two years in prison, an $11000 fine or both for improperly using, disclosing, or providing access to personal or health information. The same penalties apply to interfering with the functions of the Privacy Commissioner such as by hindering the Privacy Commissioner or their staff.

Who this policy applies to

All IRO employees and outsourced service providers performing work engaged by IRO are required to comply with privacy legislation while undertaking work for us. Additionally, they are required to comply with the IRO & DCS Code of Ethics and Conduct and the IRO & DCS Conflicts of Interest Policy.

Privacy policies and practices

The IRO has aligned its range of policies with the DCS to ensure compliance with privacy legislation, to manage privacy risks and to deal with other matters relevant to privacy and the protection of personal and health information held by the IRO.

Policies and procedures, including this IRO PMP, are communicated to employees in a range of ways, including through our intranet, printed copies and targeted training. Information about our privacy practices is also made available on our privacy intranet page.

For a full list, refer to the Policy Document Register.

What is personal information?

Personal information is defined in section 4 of PPIPA as: ‘information or an opinion (including information or an opinion forming part of a database and whether or not recorded in a material form) about an individual whose identity is apparent or can reasonably be ascertained from the information or opinion’.

Personal information is broadly defined and includes information or an opinion that identifies a person or that would allow a person’s identity to be discovered, using moderate steps, including by reference to other information. Information which, on its face value, does not appear to identify an individual will still be personal information if the information can be combined with other information, including information held by IRO, to identify the person. For example, a customer reference number on its own may not be personal information but combined with other information it may be.

What is health information?

Health information is a specific type of personal information that is defined as
Personal information that is also information or an opinion about:

  • An individual’s physical or mental health or disability
  • An individual’s express wishes about the future provision of health services to themselves
  • A health service provided, or to be provided, to an individual.
  • Other personal information collected to provide a health service
  • Other personal information about an individual collected in connection with the donation of an individual’s body parts, organs or body substances
  • Genetic information that is or could be predictive of the health or a person or their relatives or descendants
  • Healthcare identifiers.

What kind of personal information does IRO hold?

The IRO undertakes a diverse range of functions and activities. The collection of customer information is a central part of many of these functions and activities. We also have substantial obligations in respect of maintaining personal files and records of our employees which is aligned with DCS.
As a consequence, we hold a large amount of personal and health information about customers and employees in different formats. To fulfil our various functions and activities, we hold a broad range of personal and/or health information in our Client Management System (Resolve).

We may collect information electronically, in hard copy, via email or over the phone.

Responsibilities within IRO

The IRO Privacy Officers

The IRO Privacy Officers are responsible for the PMP and for providing governance services. They lead a dedicated IRO Privacy Team and work with privacy leads across IRO. Privacy leads are the first point of contact within an IRO business area in all matters related to privacy.

The IRO Privacy Officer role is held by the Chief Operating Officer who leads the Corporate and Enabling Systems business area.

The IRO Privacy Team

The IRO Privacy team are responsible for managing the IRO privacy management functions. These functions include providing guidance to IRO employees and service providers on their privacy obligations, and how to manage personal and health information in their day-to-day work. The Team is responsible for:

  • developing, co-ordinating and embedding the:
    • Privacy Management Plan
    • Privacy Management Framework
    • Data Privacy Incident Response Plan
    • Privacy Partners Network
  • periodically reviewing and updating the IRO privacy mandatory training
  • consulting with DCS and the Privacy Commissioner on high-risk privacy programs or incidents
  • ensuring relevant privacy documents are consolidated and made available through the IRO website.
  • providing advice and endorsement to projects or system changes that involve the use or handling of personal information
  • coordinating and, where appropriate, investigating privacy incidents, breaches and complaints.

Advice and evaluation

The IRO Privacy team, in collaboration with privacy leads, undertake a range of initiatives to ensure IRO employees and members of the public are informed of our privacy practices and obligations under privacy legislation.

The team provides advice to business areas to ensure new initiatives, projects and upgrades to systems involving personal information are designed in line with privacy legislation and expectations of our customers.

The team also continuously evaluates privacy practices, policies, and procedures to ensure they remain effective and identify, evaluate, and mitigate risks of potential non-compliance with privacy legislation.

Privacy risks are managed in line with the IRO and DCS Risk Management Framework. People leaders and privacy leads are responsible for systematically assessing privacy risks and ensuring those risks are controlled.

How we manage your personal and health information

How IRO manages your personal and health information

The section provides an overview of how we manage personal and health information in accordance with the information protection principles and health privacy principles in the privacy legislation.

Collection

We collect personal and health information that is reasonably necessary to fulfil our functions and activities through lawful means. We provide the required notice at the time of collection or as soon as reasonably practicable.

A privacy collection notice is a statement notifying a person of what they need to know when we are collecting their personal information. This includes what personal information we are collecting, why we are collecting it and how we will be using it. This notice may appear on application forms, on a web page, recorded message or in a verbal notice (via phone scripts).

We will ensure that when we design forms, communicate with members of the public (face to face, over the telephone and in writing), and collect information from individuals we do not seek personal or health information that is intrusive or excessive, and that the personal and health information we do collect is relevant, accurate, up-to-date and complete.

We avoid collecting sensitive information if we do not need it. Sensitive information is personal information relating to an individual’s ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership or sexual activities.

We generally collect personal or health information directly from the person. We generally provide a privacy collection notice when we collect personal information unless it is not required.

We only collect information from a third party where:

  • the person has authorised collection of the information from someone else
  • the person is under 16 years of age – we may then collect personal information from the person’s parent or guardian
  • in the case of health information, it would be unreasonable or impracticable to collect information from an individual. If this is the case, we take reasonable steps to ensure that individual is aware of the collection

The NSW Health Privacy Manual for Health Information (pdf) provides other examples of when it might be “unreasonable or impractical” to collect health information directly from the person.

If your information is to be used for a purpose other than what it is collected for, your consent is required to be specifically sought. This consent will be in addition to any privacy statement or collection notice. Consent means ‘express consent or implied consent’ and should:

  • adequately inform you prior to giving consent
  • be provided voluntarily
  • be current and specific
  • consider your capacity to understand and communicate your consent.

You can provide express consent either orally or in writing. Implied consent arises where it may be reasonable inferred in the circumstances from your conduct or actions. Silence is not consent. ‘Voluntarily’ should be understood to mean that there was a genuine opportunity for you to provide or withhold your consent. Consent is not voluntary where there is pressure that could overpower your will.

Storage and security

IRO takes reasonable security safeguards to protect personal and health information against loss, unauthorised access, use, modification, or disclosure. We will ensure personal and health information is stored securely, not kept longer than necessary, and disposed of appropriately.

The IRO in conjunction with DCS maintain security measures, including technical, physical and administrative actions, to protect information from unauthorised access and misuse.

The following are examples of how personal information is secured and retained:

  • maintaining and continually improving information security management systems that comply with ISO/IEC 27001:2022 standard
  • aligning our obligations under the Cyber Security Policy
  • Complying with IRO’s obligations under the State Records Act NSW
  • Adopting best practice in the storage, retention and disposal of personal and health information in accordance with the IRO Records Management policy.
  • providing mandatory information security awareness training to IRO employees.

Access and accuracy

Accuracy

Before using personal or health information we take reasonable steps to ensure that the information is relevant, accurate, up-to-date, complete and not misleading. We ensure the accuracy of the information by collecting it directly from individuals if possible.

Transparency

We tell you what personal information about you is being stored, why it is being used and your rights to access it. You can make enquiries at any time to find out if we hold personal or health information about you.

Access

Once we have confirmed your identity, you may access your personal and health information without unreasonable delay or expense. We will only refuse access where authorised by law, and we will provide written reasons, if requested.

Amendment

Once we have confirmed your identity, you may update or amend your personal or health information held by us to ensure it is accurate, relevant, up-to-date, complete and not misleading. We encourage you to contact us when your information changes.

If the information we hold is accurate, relevant, up-to-date, complete and not misleading but you insist on an amendment, we can decline to make any changes. However, you may be able to add a statement to our records. For example, it may be appropriate to attach a statement, instead of amending information, for a disputed medical diagnosis or for a person with a criminal record maintaining their innocence.

Advice on access and amendment

If you are a member of the public, you can contact the employee or business unit holding your information if you wish to access it and/or seek to have it amended.

If you do not know which business unit to contact regarding your request or your request has been denied, refer to the contact us page on the IRO website for guidance.

If you are a IRO employee, you can access and, in many cases, amend your personal information contained in enterprise resources planning (ERP) systems and other systems provided to undertake your work. If you require access to or wish to amend your personal or health information beyond ERP systems, contact your HR Business Partner.

How your information is used

When we talk about ‘use’ of personal and health information, it refers to the way we handle and share information within IRO to perform our functions. This includes providing information to contractors engaged by IRO to manage information on our behalf in circumstances where IRO retains control over the handling and use of the information.

Generally, we only use personal and health information for the purpose for which it was collected. The purpose should be set out in the privacy notice at the time of collection.

We may use personal and health information:

  • for the primary purpose for which it was collected
  • for a directly related secondary purpose
  • another purpose where it is reasonably necessary to prevent or lessen a serious and imminent threat to life or health
  • another purpose for which the person has consented
  • another purpose where permitted by law.

We may also use personal and health information for a directly related secondary purpose. A directly related secondary purpose is a purpose that is very closely related to the purpose for collection and would be the type of purpose that people would quite reasonably expect their information to be used for. We may also use health information to lessen or prevent a serious threat to public health or safety; management of health services; training; research purposes; finding a missing person; for law enforcement purposes and in respect of suspected unlawful activity, unsatisfactory professional conduct or breach of discipline.

Disclosure

Disclosure is different to 'use'. We may disclose information when we disclose it to someone outside the agency.

Stricter rules apply to specific information.

We can generally disclose health information when the person has consented to the disclosure; the disclosure is directly related to the purpose for which it was collected, and the individual would reasonably expect us to disclose the information for that purpose; or the disclosure is necessary to prevent or lesson a serious or imminent threat to life, health or safety.

Disclosing sensitive information (e.g. a person’s ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership or sexual activities) is generally only allowed with the person’s consent.

We can generally only disclose personal or health information to someone outside NSW, or to a Commonwealth agency if one of the following applies:

  • they are subject to a law, scheme or contract that upholds principles substantially similar to the information privacy principles
  • the individual concerned has consented
  • if it is necessary for a contract with (or in the interests of) the individual concerned
  • if it will benefit the individual concerned and it is impracticable to obtain their consent but we believe the person would be likely to give their consent
  • this disclosure is reasonably believed by the public sector agency to be necessary to lessen or prevent a serious and imminent threat to the life, health or safety of the individual or another person
  • we have taken reasonable steps to ensure the information won’t be dealt with inconsistently with the information privacy principles e.g. we have bound the recipient by contract to privacy obligations equivalent to the principles, or
  • if it is permitted or required by legislation or any other law.

Requests for personal or health information from outside bodies, including from government agencies, will be assessed to determine whether we are permitted to provide the information.

Health information and identifiers

In relation to health information, we generally do not identify individuals by using unique identifiers to carry out our functions. We do not provide health services, except to employees through contracted service providers and it would not be practicable in these circumstances to allow individuals to remain anonymous. We may collect identifiers from third parties. Identifiers are used to uniquely identify an individual and their health records. An identifier does not need to use a person’s name as they are designed to be unique to a specific individual (for example, a customer number, unique patient number, tax file number or drivers licence number). We do not use a health records linkage system.

Exemptions and public registers

Under privacy legislation, there are several exceptions and exemptions. Where exceptions or exemptions apply, an agency may not be required to comply with some or all of the privacy principles. This might apply in a certain situation or in relation to certain information collected.

At IRO, when we seek to rely on an exemption, we will assess how that applies in the specific circumstances and explain it in a privacy collection notice.

Like exemptions, a privacy code of practice is a legal instrument which allows an agency to depart from information privacy principles and this may limit the liability of an agency in relation to the principles. An example of this which applies to the services of ID Support, a business area within IRO, is the ID Support Privacy Code of Practice - Identity remediation services (pdf).

Further information about exemptions can be found in Further details on exemptions from privacy legislation.

Data breaches

What is a data breach?

A breach of a person's privacy occurs when their personal and/or health information is compromised.
A breach can occur:

  • when there is unauthorised access to, or disclosure of, personal information held by IRO, or
  • where personal information held by IRO is lost in circumstances where unauthorised access or disclosure of the information is likely to occur.

When responding to a privacy breach IRO will investigate using the following steps:

  • Contain - Immediately take steps to minimise the impact of the breach and to prevent any further compromise of personal information.
  • Assess - Gather facts about the incident to determine the extent of the breach, identify the individual's affected, and what type of information was involved.
  • Notify - Determine who needs to be notified of the incident.
  • Review – Conduct a review of the privacy breach and compile a report with recommendations about preventing a recurrence of a similar event and reduce future risk.

IRO has a Data Breach Response Plan that outlines our procedures for responding to a privacy breach, including how we manage a breach and the process for notifying people affected by the breach.

If you think your personal information has been handled incorrectly, contact the business area you have been dealing with or email [email protected].

Mandatory notification of data breaches

The Mandatory Notification of Data Breach (MNDB) Scheme commenced on 28 November 2023.

The MNDB amendment applies to all NSW public sector agencies who are subject to the PPIP Act. Such agencies are required to notify the NSW Privacy Commission and affected individual(s) if an eligible data breach of the individual's personal or health information held by IRO occurs.

A data breach is “eligible” under the amendment if it is likely to result in serious harm to any of the individuals to whom the information relates. Whether a data breach is likely to result in serious harm requires an assessment, determined from the viewpoint of a reasonable person. Serious harm to an individual may include serious physical, psychological, emotional, financial, or reputational harm.

More information about how IRO handles data breaches involving personal information can be found in the IRO Data Breach Policy.

 Complaints and review process

IRO complaints and review processes

This section explains the complaint and review processes within IRO. Find out how to make a complaint or seek a review of how your personal or health information has been handled by IRO.

How to make a complaint about privacy

If you have a complaint about a privacy matter, you can raise it by:

  • contacting the business unit you have been dealing with or the IRO Privacy Team
  • applying in writing, for an internal review, or
  • complaining directly to the NSW Privacy Commissioner.

Complaints process

If you are unhappy with the way your personal or health information has been handled or you want to raise a general privacy issue concerning IRO, you can make a privacy complaint.

To do this, raise the issue with the staff member or business unit you have been dealing with. This might be in writing or verbally. Alternatively, you can contact the IRO Privacy Team at [email protected] or find the best contact for your situation on the IRO complaints page.

If you are dissatisfied with the outcome of an informal request, you can still apply for an internal review.

What is an internal review?

An internal review is a formal process to examine the issues raised by an applicant about the handling of their personal information.

You have the right to an internal review if you have been ‘aggrieved by the conduct of a public sector agency’. This means that you have been negatively affected by something we have done or not done in relation to the privacy of your personal information.

Requirements when applying for an internal review

An application for internal review must:

  • be in writing 
  • be addressed to IRO or the business area within IRO to which the complaint relates
  • include a return address in Australia (which will be used to notify you at the completion of the review), and
  • be made within 6 months of becoming aware of the conduct you want reviewed.

To help you apply for an internal review, you can use the application form from the NSW Information and Privacy Commission (IPC). Although we encourage you to use the form, it is not essential.

When you submit your application you should include all relevant material, including when the suspected breach occurred, the circumstances of the suspected breach, and the outcomes you are seeking from the review.

If we are unsure whether you have intended to submit an internal review, we will confirm with you whether the issue you have raised is a request for an internal review.

You can submit your request for internal review to the business unit concerned, to the IRO Privacy Team.

How internal reviews are conducted

When we receive an application for an internal review, we will:

  • Send you an acknowledgement letter with an expected completion date.
  • Advise the NSW Privacy Commissioner of the internal review, provide a copy of the complaint and keep them updated on progress of the internal review. This is a requirement under privacy law.
  • Decide who will conduct the internal review. As far as possible, the internal review will be conducted by a person who:
    • was not involved in the conduct which is the subject of the complaint
    • is an employee or an officer of IRO, and
    • is qualified to deal with the subject matter of the complaint.
  • Examine all relevant material and, if appropriate, make inquiries with other people within IRO. This may include contacting you to clarify the scope of your application.
  • Make findings about the internal review issue/s and determine whether there has been a privacy breach. We may find:
    • insufficient evidence to suggest alleged conduct occurred
    • the alleged conduct occurred but complied with the privacy law
    • the alleged conduct occurred; did not comply with privacy law; but this was allowed by an exemption or similar; OR
    • the alleged conduct occurred and this amounted to a breach under privacy law.
  • Decide on any action to be taken.
  • Provide the draft internal review report to the NSW Privacy Commissioner and consider any submissions made by them. We will also provide the Commissioner with a copy of the finalised internal review report.

Internal reviews generally follow the process set out in the IPC’s Internal Review Checklist.

After an internal review

When the internal review is completed, we will notify you of:

  • the findings of the review
  • the reasons for those findings
  • any action IRO proposes to take
  • the reasons for the proposed action (or no action); and
  • your entitlement to have the findings and the reasons for the findings reviewed by NSW Civil and Administrative Tribunal.

 

Timeframes for internal reviews

Application – must be made within 6 months of you becoming aware of the conduct. We may accept late applications in certain circumstances (such as if you have only become aware of your right to seek an internal review or for reasons relating to your capacity to lodge an application on time). If we do not accept your application, we will provide our reasons in writing.

Initial response – we will let you know when that we have received your application within a week.

Completion of review – we will complete the internal review as soon as practicable but aim to have it completed within 60 calendar days. We will let you know you if we anticipate that the internal review will take longer than the 60 days.

Outcome – we will let you know the outcome of your review within 14 calendar days of completing the internal review.

If you require additional support to submit an internal review, or are submitting an application on behalf of someone else, please contact the IRO Privacy Team at [email protected].

External review by the NSW Civil and Administrative Tribunal

You have the right to apply to the NSW Civil and Administrative Tribunal (NCAT) if you have sought an internal review and you are not satisfied with:

  • the outcome of the internal review
  • the action taken in relation to your application for internal review; or
  • you do not receive an outcome of the internal review within 60 days.

You must apply to NCAT within 28 days of receiving the decision from IRO.

For more information about seeking an external review, visit the NCAT’s website.

Complaints to the NSW Privacy Commissioner

You have the option to complain directly to the NSW Privacy Commissioner if you believe that we have breached your privacy.

The Commissioner’s contact details are:

Postal address: GPO Box 7011, Sydney NSW 2001

Address: Level 15, McKell Building, 2-24 Rawson Place, Haymarket NSW 2000

Telephone:  1800 472 679

Email: [email protected]

 

Independent Review Office Privacy Management Plan - Contact information

IRO Privacy Team

For privacy matters at IRO, you can contact the IRO Privacy Team at [email protected].

Related policies and legislation

Related legislation

  • Government Information (Public Access) Act 2009 (NSW)
    The operation of GIPA is not affected by the operation of PPIPA and HRIPA. Note that GIPA may provide access to various documents held by IRO to any person, but subject to the operation of various exemptions in the GIPA Act. PPIPA and HRIPA generally only allow access to information your own personal information.

Related policies

IRO has developed the following policy documents to ensure compliance with the privacy legislation:

  • IRO Privacy Management Framework: this framework is a direction for IRO employees on how the principles and aims of the IRO PMP are embedded in the agency’s integrated policies, operating plans business processes and work practices.
  • IRO Data Privacy Incident Response Plan: outlines how IRO responds to, and recovers from suspected, potential, or actual data incidents, including privacy breaches.
  • IRO Risk Management Policy: sets out the principles and requirements of our risk management approach for all risk categories, including privacy.
  • Information Data Governance Framework:  The IRO adopts the Department of Customer Service framework to formally establish the organisation’s approach to Information Governance.
  • IRO Code of Ethics and Conduct: outlines the responsibilities of our employees in protecting personal information in the course of their duties. All employees are provided with a copy of the Code and are regularly reminded of their obligations.

Glossary of terms

Terms used in the IRO Privacy Management Plan

This section provides an explanation of terms used in this document.

Employee

An employee is any person working in a casual, temporary or permanent capacity in IRO, including volunteers, consultants, contractors and any person performing an official public function whose conduct could be investigated by an investigating authority

Collection (of personal information)

The collection of personal information refers to the way information is acquired by IRO. This can include a written form, a verbal conversation, an online form or a photographic image.

Information Privacy Principles (IPPs)

The 12 Information Protection Principles (IPPs) are the key to the Privacy and Personal Information Protection Act 1998 (PPIPA). These are legal obligations which NSW public sector agencies, statutory bodies, universities, and local councils must abide by when they collect, store, use or disclose personal information. The most up-to-date factsheet may be found at Information protection principles for the public.

Health Privacy Principles (HPPs)

The 15 Health Privacy Principles (HPPs) are the key to the Health Records and Information Privacy Act 2002 (HRIP Act). These are legal obligations which NSW public sector agencies and private sector organisations must abide by when they collect, hold, use and disclose a person’s health information. The most up-to-date fact sheet may be found at Health Privacy Principles (HPPs) explained for members of the public

Personal information

Personal information is information or an opinion (including information or an opinion forming part of a database and whether or not recorded in material form) about an individual whose identity is apparent or can reasonably be ascertained from the information or opinion. This includes such things as individual’s fingerprints, retina prints, body samples or genetic characteristics. Exclusions to the definition of personal information are contained in section 4(3) of the PPIPA. Health information is like a special type of personal information and is regulated separately.

Sensitive information

Sensitive information is information referred to in section 19(1) of PPIPA. Some of our privacy obligations are different for ‘sensitive information’. There are special restrictions on the disclosure of personal information relating to a person's race, ethnicity, religion, sexuality, political or philosophical beliefs or membership of a trade union. The most up-to-date fact sheet may be found at Information protection principles for the public.

Health information

Health information is:

  • personal information
  • an opinion about a person’s physical or mental health or disability
  • a person’s express wishes about future provision of health services, or
  • a health service provided, or to be provided, to a person.

Any personal information collected for the purposes of the provision of health care will generally be ‘health information’ and will also include personal information that is not itself health-related but is collected in conjunction with health service provision.

Further information about exemptions from privacy legislation

Exemptions from privacy legislation

The PPIP Act and HRIP Acts contain exemptions from compliance with certain IPPs and HPPs. This section outlines the main exemptions to each principle.

Limiting our collection of personal and health information

  • unsolicited information
  • personal information collected before 1 July 2000
  • health information collected before 1 September 2004
  • in the case of personal information, for certain Ministerial correspondence or referral of inquiries
  • in relation to personal information, certain research purposes

How we collect personal and health information

  • unsolicited information
  • personal information collected before 1 July 2000
  • health information collected before 1 September 2004
  • personal information used for law enforcement or some investigative and complaints handling purposes
  • where another law authorises or requires us not to comply with this principle
  • where non-compliance is otherwise permitted, implied or contemplated by another law
  • in the case of personal information, where compliance would disadvantage the individual

Notification when collecting personal and health information

  • unsolicited information
  • personal information collected before 1 July 2000
  • health information collected before 1 September 2004
  • the individual concerned has expressly consented to the non-compliance
  • some law enforcement and investigative or complaints handling purposes
  • where another law authorises or requires us not to comply
  • where non-compliance is otherwise permitted, implied or contemplated by another law
  • where compliance would disadvantage the individual
  • where notification in relation to health information would be unreasonable or impracticable

How we collect personal and health information – the method and content

  • unsolicited information
  • personal information collected before 1 July 2000
  • health information collected before 1 September 2004
  • law enforcement or some investigative and complaints handling purposes
  • where another law authorises or requires us not to comply
  • where non-compliance is otherwise permitted, implied or contemplated by another law
  • where compliance would disadvantage the individual

Retention and security

  • there are no direct exemptions to the operation of the principle

Transparency

  • if another law authorises or requires us not to comply
  • where non-compliance is otherwise permitted, implied or contemplated by another law
  • where the provisions of GIPAA impose conditions or limitations (however expressed)

Access

  • Some health information collected before 1 September 2004
  • where another law authorises or requires us not to comply
  • where non-compliance is otherwise permitted, implied or contemplated by another law
  • the provisions of GIPAA that impose conditions or limitations (however expressed)

Correction

  • some health information collected before 1 September 2004
  • some investigative or complaints handling purposes
  • if another law authorises or requires us not to comply
  • where non-compliance is otherwise permitted, implied or contemplated by another law
  • the provisions of GIPAA that impose conditions or limitations (however expressed)

Accuracy

  • there are no direct exemptions to the operation of this principle

Use

  • law enforcement and some investigative or complaints handling purposes
  • where another law authorises or requires us not to comply
  • where non-compliance is otherwise permitted, implied or contemplated by another law
  • in the case of health information, to lessen or prevent a serious threat to public health or public safety
  • in the case of health information, finding a missing person
  • information sent to other agencies under the administration of the same Minister or Premier for the purposes of informing the Minister or Premier

Disclosure

  • law enforcement or some and investigative and complaints handling purposes
  • when it is authorised or required by a subpoena, warrant or statutory notice to produce
  • if another law authorises or requires us not to comply
  • where non-compliance is otherwise permitted, implied or contemplated by another law
  • in the case of health information, to lessen or prevent a serious threat to public health or public safety
  • in the case of health information, compassionate reasons
  • finding a missing person
  • information sent to other agencies under the administration of the same Minister or Premier for the purposes of informing the Minister or Premier

 

On this page