Privacy + looks like some executive continued Flashcards
What is the key act for privacy?
Privacy Act 2020
What is the Privacy Act 2020’s purpose?
S 3 - To promote and protect individual privacy
How does s 3 PA 2020 outline how the purpose will be achieved?
By providing a framework for protection of personal information
AND
Giving effect to international privacy obligations
What is personal information?
Section 7
- information about an identifiable individual
What are the Information Privacy Principles?
- Agencies should only collect PI when necessary and for a lawful purpose
- PI should be collected directly from the individual concerned
- Agencies should inform individuals of the purpose for collection and their rights of access
- Collection of PI by Agencies must be by lawful and fair means
- Agencies shall store PI safely and securely
- Individuals have right to know whether the agency holds PI about them and right to access this
- Rights to correct PI that an agency holds about you
- Agencies to ensure PI is up to date & accurate before using or disclosing it
- PI not to be kept by Agency longer than necessary
- PI collected for one purpose must not be used for another
- PI can be disclosed only in limited circumstances (eg when authorised or anonymised)
- Agencies can only send PI to someone overseas if it will be protected in the country of destination
- Unique identifiers used only if necessary
How many information privacy principles are there?
13
Where is interference defined?
S 69
What is interference?
EITHER
A breach of IPPs (not 6 or 7) AND something else – effect on an individual.
OR
a refusal of a request under IPP 6 or 7 “without proper basis.”
Proceedings Commissioner v Police [2000]
Alleged breaches of IPP 5 and 11
Facts:
- PI relating to application by 3rd parties for protection order
- Woman in domestic violence relationship
- Known to her parents and police
- Concerned for her, they applied for a protection order on her behalf
- Would stop her partner coming near her or their home
- Police officer contacted a friend in media
- News story was printed about application
- Included PI about her
- Media followed and filmed Police Officer delivering protection order at the complainants home and serving it on the boyfriend
- Woman was not identifiable to the world at large but identifiable to those who knew her
Question:
- What amounts to disclosure of PI?
- Was PI disclosed?
Held:
Was it PI?
- She was not directly identified
- BUT does not need to directly identify her, can constructively identify her
Was the information disclosed?
- disclosure need not be in words or intended
Overall
- It was PI identifiable to others
Who investigates claims of breach of privacy?
The Privacy Commissioner - s 79
When can the privacy commissioner investigate?
Issues can be raised by complaint or by the privacy commissioner raises them themselves
At any time before, after or during an investigation, what must the privacy commissioner do?
Use best endevors to secure a settlement
Does the privacy commissioner need to hold herrings?
No, don’t need to a hearing and no one is entitled as of right to be heard - s 81
If the Commissioner decides a complaint has substance, what may they do?
- Refer the matter to the Director (HRRT)
Usually if pretty serious, may end up with prosecution - Make an access direction for personal information
If complaint is about access denied - Take any other action the Commissioner considers appropriate - ss 91, 92 and 94
E.G. work with company to make sure it doesn’t happen again
What is the Human Rights Review Tribunal?
Looks at claims relating to breaches of the Human Rights Act 1993, Privacy Act 2020, Health and Disability Commissioner Act 1994
If the Commissioner refers a complaint/matter to the Director, Director may commence proceedings in the HRRT, s 97
What are the remedies in the HRRT?
s 102:
- declaration
- order
- damages - s 103
What damages can you get under the HRRT?
s 103
- expenses
- pecuniary loss
- loss of any benefit
- humiliation/loss of dignity/injury to feelings)