Helios Salinger

  • About
    • About Salinger Privacy – now Helios Salinger
    • Meet our team
    • Work with us
    • Videos, Podcasts and Media Mentions
    • Privacy Awareness Week
  • Consulting
    • Overview – Our Consulting Services
    • Privacy Impact Assessment
    • Privacy Maturity Assessment
    • Privacy by Design advice
    • Privacy Compliance and Gap Analysis
    • Algorithmic Impact Assessment
    • Re-identification Risk Assessment
    • Data ethics
    • Privacy Helpdesk
  • Training
    • Overview – Our Training Services
    • Privacy Compliance Training
    • Privacy Professionals Training
    • All Online Modules
    • Training Calendar
    • Public Courses and Workshops
    • In-house Privacy Training and Workshops
    • Webinars
    • IAPP Certifications
    • Training Advisory Services
    • Login
  • Resources
    • Overview – Our Resources
    • THE PRIVACY PULSE
    • Privacy Act Reforms
    • Compliance Kits
    • Resources on key privacy topics
    • Free Handbook
    • Newsletter
    • Login
  • Case Study
  • Blog
  • Calendar
  • Contact
  • Compliance Kits
    • For Business & Non-profits
    • For Peak Bodies
    • For Australian Government
    • For NSW Public Sector
    • For VIC Public Sector
    • For QLD Public Sector
    • For WA Public Sector
    • Login

A new enforcement era is here: will your projects pass the OAIC’s privacy pub test?

April 28, 2025, Alex Kotova and Anna Johnston

A new age of privacy enforcement is here, with implications well beyond one sector or technology. We have taken a fresh look at recent decisions from the Office of the Australian Information Commissioner (OAIC) and the ‘privacy pub test’ you may need to start applying to all new projects.

Bringing a privacy risk focus to the C-suite

Having finally secured legislative change to beef up the powers of the OAIC, Australia’s Privacy Commissioner Carly Kind has been in the media recently, explaining the strategic approach to enforcement of the Privacy Act that the OAIC is now taking.

In discussions including a fireside chat with the IAPP’s Adam Ford and Joe Jones, a keynote address to privacy practitioners at a Privacy Summit, and an interview with digital rights and technology activist Alix Dunn of Computer Says Maybe, Commissioner Kind has been promoting the new direction – and what she hopes to achieve. 

Regulated entities should take note: don’t wait for potential Tranche 2 reforms. A new era of enforcement is here now; the Privacy Commissioner has resolved to make the most of the Privacy Act we have; and the OAIC has spelled out its expectations in terms of applying the Australian Privacy Principles (APPs) in practice.

Combine this more robust enforcement posture with the Commissioner’s power to levy instant infringement notices for some privacy breaches, plus new mid-tier penalty provisions, and the stage has been set for the regulator to finally reach the ear of the C-suite.

Kind has said that her objective is to “shape the data ecosystem in a way that’s better for consumers”, and to that end, she needs to get senior executives to understand that privacy is a risk to be managed proactively, rather than an issue to neglect on the back burner.

Strategic enforcement and sector signals

How will an under-resourced regulator do this? Strategic enforcement to “incentivise compliance” and offer “general deterrence”.

Kind’s strategy is to enforce at scale – that is, create broader impact from each of the OAIC’s decisions, beyond resolving disputes between just one complainant and one respondent. It is expected that the OAIC’s enforcement team will prioritise cases which involve targeted harms, technologies, or industries, and issue public determinations which can have an amplifying effect.

What does this mean for Australian organisations? If your industry or technology has been name-checked, take heed. There has already been mention of connected cars, rent tech and the real estate industry, verification of identity such as digital identity and business practices involving the collection of evidence of identity, facial recognition technology, data scraping, and the use of personal information for training models of AI. If you’re unsure about whether the interpretations of the Privacy Act you are relying on are in line with the OAIC’s expectations, or where your privacy practices may impact cohorts of vulnerable individuals, you have been put on notice. Your compliance obligations pre-dated the Tranche 1 privacy reforms, and now our regulator has the ability to test you on them.

This strategic enforcement approach has started to play out in determinations which have advanced the interpretation of the Privacy Act and edged us closer to some of the reforms we didn’t anticipate until Tranche 2, clearly signalling that the OAIC is not waiting for legislative change to raise the bar for compliance.

Let’s take a look at some of the more prominent examples of this strategic enforcement approach – and the implications for regulated entities of what is starting to look like the development of a ‘privacy pub test’.

A narrower interpretation of the employee records exemption

Back in March 2024, Kind forewarned that she expects much of her time as Privacy Commissioner will be occupied not with the generative leap in artificial intelligence and the birth of a range of AI-driven tools, but with the slightly more mundane and commonplace privacy practices which cause harm. One example in practice has been the employee records exemption.

Generally a broadly applied exemption, sometimes even by the OAIC (which has once suggested that even non-work related information could fall within the scope of the exemption where that information was stored on a work device which was subject to routine monitoring), in June 2024 Kind examined the limits implied within the wording of the exemption in an edge case scenario. 

In relation to whether the employee records exemption applied in the instance of an employer sending a ‘status update’ email to 110 staff members about an identified employee’s medical episode on work premises, which was witnessed by several other employees, the Commissioner considered whether the sending of the email was an act directly related to the employment relationship between the employer and complainant.  

Ultimately, the Commissioner found that sending the email was an act directly related to the employment relationship between that employer and other employees to whom it owed a duty of care, not the employee who was the subject of the record.  As such, the Commissioner found the employee records exemption did not apply.

Whatever your view on the decision, there are plenty of privacy professionals who would have earnestly advised that the employee records exemption can be relied upon in this scenario. While the reform process has not done away with the employee records exemption just yet, it’s safe to say that we’ve received a signal to be wary of how the exemption is applied.

A fair and reasonable test by any other name

While a ‘fair and reasonable’ test did not feature in the Tranche 1 reforms, we have seen an expanded interpretation of the existing ‘lawful and fair means’ collection requirements of APP 3.5, edging us ever closer to ‘fair and reasonable’ test territory.

Before looking at the decisions, it’s worth recapping what the ‘fair and reasonable’ test was proposed by the government to be, and what entities would be required consider in reaching a conclusion as to whether a collection, use or disclosure was fair and reasonable in the circumstances. 

The ‘fair and reasonable’ test itself would require that the collection, use and disclosure of personal information must be fair and reasonable in the circumstances.  The proposed considerations for determining what is fair and reasonable in the circumstances are:

  1. whether an individual would reasonably expect the personal information to be collected, used, or disclosed in the circumstances
  2. the kind, sensitivity and amount of personal information being collected, used or disclosed
  3. whether the collection, use or disclosure is reasonably necessary for the functions and activities of the organisation or is reasonably necessary or directly related for the functions and activities of the agency
  4. the risk of unjustified adverse impact or harm
  5. whether the impact on privacy is proportionate to the benefit
  6. if the personal information relates to a child, whether the collection, use or disclosure of the personal information is in the best interests of the child, and
  7. the objects of the Act.

Now to the decisions.

A new lens on fairness in data collection

In looking at whether the collection of personal information from court lists and government gazettes, then overlaying these with property data from CoreLogic to develop and distribute a list of potentially distressed individuals as a ‘leads’ list for discounted real estate opportunities (noting that a second decision was made against another entity on these same facts), the Commissioner’s rationale for her ultimate finding that the collection was not by fair means, took into account many of the considerations of the proposed fair and reasonable test.

First, the Commissioner laid the groundwork for her rationale: the Privacy Act does not define ‘lawful’ or ‘fair’, there is no judicial guidance on the interpretation of APP 3.5, and only a limited number of OAIC determinations expressly consider APP 3.5.

Finding that there is more ‘textual ambiguity’ in the meaning of the word ‘fair’ than ‘lawful’, the Commissioner focused her attention on the interpretation of what is a ‘fair’ collection, noting that a breach of APP 3.5 may be found where an entity fails to collect information in a manner that is either not ‘lawful’ or ‘fair’.

A broad assessment grounded in context

The Commissioner found that “when undertaking the assessment of whether a collection is ‘fair’ for the purposes of APP 3.5, all the circumstances must be considered.  This is a broad assessment that requires consideration of the facts of the particular case.” Indeed, much like having a requirement to be ‘fair and reasonable’ in the circumstances.

In this context, the Commissioner started by looking to the objects of the Privacy Act (for those playing ‘spot the fair and reasonable test’ bingo, that’s item 7 in the list above).

What would the individual expect?

Then, looking to the present guidance on APP 3.5, the Commissioner considered that APP 3.5 emphasises the importance of the knowledge and reasonable expectations of the impacted individual when assessing whether the collection is by fair means, thus opening the door to a discussion of an individual’s reasonable expectations (item 1 in the list above). Not surprisingly, the Commissioner found that potentially distressed individuals would not have reasonably expected their personal information to be collected from daily court listings so that they could be contacted about selling their property.

Vulnerability as a critical factor

The vulnerability of individuals was also a key consideration in the decision, particularly because the collection was in the context of capitalising on the vulnerability, or perceived vulnerability, by attempting to acquire their properties for below market value. While vulnerability has not been explicitly called out as a consideration in the proposed ‘fair and reasonable’ test, it can be implied that it would go against a finding of a fair and reasonable collection in the context of the ‘kind and sensitivity of the personal information collected’ (item 2 in the list above) and ‘the risk of unjustified adverse impact or harm’ considerations (item 4).

Balancing commercial interest against privacy harms

The Commissioner concludes her consideration by commenting that while the respondent has a commercial interest in these activities, its activities were not fair for the purposes of APP 3.5 when balanced against the interference in the privacy of these individuals, again taking us to the ‘fair and reasonable’ test and its requirement to consider proportionality of benefit to privacy impact (item 5).

Decisions about specific technologies may yield other lessons

Looking back to the Bunnings decision, which was about the deployment of facial recognition technology (FRT) in retail stores, we see that more can be gleaned from the Commissioner’s findings than simply a view on the deployment of FRT.  (For a breakdown of the Commissioner’s findings in respect of FRT, see our earlier article ).  The case also offers broader guidance in respect of what makes a collection ‘necessary’ for the purposes of APP 3 and s.16A.

Testing for necessity

The OAIC’s APP Guidelines indicate that the term ‘necessary’ means something “more than merely helpful, desirable or convenient”.  Bunnings argued for a looser interpretation of ‘necessary’ as meaning “reasonably appropriate and adapted”. 

Commissioner Kind decided that in the absence of case law on the meaning of the word ‘necessary’ in s.16A, she needed her own way of assessing whether a particular example of collection could be judged to be ‘necessary’.  She formulated a test with three factors to be considered:

“(a) the suitability of the FRT system, including its efficacy in addressing the relevant activity or conduct

(b) the alternatives available to the respondent to address the relevant activity or conduct

(c) whether the use of the FRT system was proportionate, which involves balancing the privacy impacts resulting from the collection of sensitive information against the benefits gained by the use of the FRT system”.

So, what does this mean for me?

The positions taken by the OAIC described here offer us an indication of how the Privacy Commissioner might approach interpreting APP 3.3, 3.5 and the employment records exemption in the future. This is relevant because the Privacy Commissioner has been explicit in telling us that this is what she intends to do.

Look again at the three-part test above, and replace the acronym ‘FRT’ with a technology or business process you are thinking about in your own organisation.  You now have a clear explication of the OAIC’s assessment criteria for whether it would judge the collection of personal information in your case to be ‘necessary’: efficacy, alternatives, and proportionality.

Similarly, assess any new collection through the considerations that the Commissioner described in respect of APP 3.5 – reasonable expectations, vulnerability and proportionality – and you’ve got a guide as to whether the collection would be ‘fair’ in the circumstances.

An interim privacy pub test

As the OAIC’s new guidance on facial recognition technology states: “It is up to an organisation to be able to justify that collection of the information is reasonably necessary. The fact that FRT is available, convenient or desirable should not be relied on to establish that it is necessary to collect the information”.

So, while we wait for a possible Tranche 2 ‘fair and reasonable’ test, the OAIC is getting on with enforcing the law we have now. In the process, they have effectively developed a set of questions to ask, of any technology or business process involving personal information.

Consider this your new ‘privacy pub test’, to be asked of all your new projects:

  • Will this technology or process actually work – i.e. will it achieve its stated objective?
  • Is there a less privacy-intrusive alternative available?
  • Is this within the reasonable expectations of the impacted individuals?
  • How will this affect vulnerable groups?
  • Will achieving the stated objective outweigh the privacy harms the technology or process will cause?

If your answers are not in line with the expectations the Commissioner is setting out in her decisions, then you may struggle to demonstrate compliance with APP 3, and your project might need a re-think. Similarly, you may need to reduce your reliance on exemptions set out in the Privacy Act.

Far from being just about specific technologies or practices, through its strategic enforcement activities, the Privacy Commissioner is laying the groundwork for a new era of enforcement, and almost all collection of personal information should be judged against the criteria she has laid out.

If you need assistance assessing the privacy implications of new technologies or new business processes, please get in touch.

Filed Under: Insights

If you enjoyed this blog, subscribe to our newsletter to receive more privacy insights and news every month.

Privacy Compliance Kits

Recent Posts

  • Tick and flick: what ’I agree’ really means to Australians in 2026
  • Inching towards individuation: OAIC decision on pixels broadens scope of the Privacy Act
  • How dark patterns can land you in hot water: new case offers lessons for all
  • How to sniff out the landmines that can ruin your AI project
  • Privacy reforms to impact over 100,000 small businesses
  • The view from the summit: trust and hope, caution and concern, and plenty of hard work
  • Is identifiability in the eye of the beholder?  EU case tests limits of pseudonymisation
  • Mind the gap: when legal permission is not enough to ensure compliance
  • Why “Don’t worry it’s de-identified” should (still) be a red flag when considering privacy risk
  • How to get ahead of the new ADM rules before they rule you

Archive

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015

Search

Helios Salinger can help you navigate the complexity of the regulatory environment, and ensure the trust of your customers.

CONTACT US

T: 02 9043 2632
Level 37, 180 George Street
Sydney NSW 2000
Email Enquiry

© Helios Salinger Pty Ltd
ACN 655 748 593
ABN 59 655 748 593

Our Privacy Policy

Terms of Engagement

Subscribe to our newsletter.

These details will be added to our mailing list to receive the Helios Salinger eNews and Product News newsletters. You can unsubscribe or adjust your preferences at any time, from the bottom of any newsletter.