Office of the Australian Information Commissioner

We are at the forefront of guidance, monitoring and enforcement of Australia’s privacy and freedom of information law.

Through this, we aim to shape how emerging technologies and data practices impact the lives of every Australian.

Promote, uphold and shape Australian information privacy rights.

we helped the community with
16,793
of their privacy questions
12%

13,301
Phone

13301

3,478
Written

3478

14
In person

14

we received 2,494 privacy complaints this year and helped the public resolve
2,485
of their privacy issues
22%

95%
of complaints were resolved within 12 months of receipt

During the year, the majority of complaints came from the following sectors

we reviewed the privacy practices of
35 organisations
through
25 assessments

Skip Organisations

security

Immigration and Border Protection (Contractual arrangements)

Assessment focus

APP 11

Report published

TBA

security

Immigration and Border Protection (Advanced Passenger Processing)

Assessment focus

APP 11

Report published

Oct 2016

View Report

security

Immigration and Border Protection (SmartGate)

Assessment focus

APP 11

Report published

Oct 2016

View Report

security

PNR (follow-up on new administrative arrangements)

Assessment focus

APP 6

Report published

TBA

security

Immigraton and Border Protection (SmartGate systems)

Assessment focus

APP 11

Report published

TBA

security

Immigration and Border Protection (Advanced Passenger Processing - SITA)

Assessment focus

APP 11

Report published

TBA

government

Unique Student Identifier (USI)

Assessment focus

APP 1

Report published

Jan 2017

View Report

government

ACT Access Canberra

Assessment focus

TPP 1

Report published

TBA

government

Tax file number: Publication obligations

Assessment focus

TFN 13

Report published

TBA

government

Tax file number: Publication obligations

Assessment focus

TFN 13

Report published

TBA

government

Tax file number: Publication obligations

Assessment focus

TFN 13

Report published

TBA

government

Tax file number: Publication obligations

Assessment focus

TFN 13

Report published

TBA

government

Tax file number: Publication obligations

Assessment focus

TFN 13

Report published

TBA

government

Tax file number: Publication obligations

Assessment focus

TFN 13

Report published

TBA

government

Tax file number: Publication obligations

Assessment focus

TFN 13

Report published

TBA

government

Immigration and Border Protection

Assessment focus

APP 12

Report published

TBA

government

DHS: Data matching NIEDM

Assessment focus

APP 1

Report published

TBA

government

DHS: Data matching PAYG

Assessment focus

APP 10

Report published

TBA

health

My Health Records: National Repositories Service - follow up

Assessment focus

APP 11

Report published

Sep 2016

health

My Health Records: Aust Health Practitioner Registration Agency (AHPRA)

Assessment focus

APP 10

Report published

TBA

health

DHS: Contract service provider to My Health Record System Operator

Assessment focus

APP 1

Report published

TBA

it

Telstra: Requests for information by law enforcement agencies

Assessment focus

APP 11

Report published

TBA

it

Vodafone: Requests for information by law enforcement agencies

Assessment focus

APP 11

Report published

TBA

it

Optus: Requests for information by law enforcement agencies

Assessment focus

APP 11

Report published

TBA

it

iiNET: Requests for information by law enforcement agencies

Assessment focus

APP 11

Report published

TBA

it

Document Verification Service (Gateway Service Provider - Trulioo)

Assessment focus

APP 11

Report published

TBA

it

Document Verification Service (Gateway Service Provider - VIX Verify)

Assessment focus

APP 11

Report published

TBA

it

Unique Student Identifier (USI) - Registered training organisations

Assessment focus

APP 1

Report published

TBA

it

Unique Student Identifier (USI) - Registered training organisations

Assessment focus

APP 1

Report published

TBA

it

Unique Student Identifier (USI) - Registered training organisations

Assessment focus

APP 1

Report published

TBA

it

Unique Student Identifier (USI) - Registered training organisations

Assessment focus

APP 1

Report published

TBA

it

Unique Student Identifier (USI) - Registered training organisations

Assessment focus

APP 1

Report published

TBA

consumer

QANTAS Frequent Flyer Loyalty Program

Assessment focus

APP 1

Report published

TBA

consumer

Virgin Velocity Loyalty Program

Assessment focus

APP 1

Report published

TBA

health

Healthscope Ltd

Assessment focus

APP 11

Report published

TBA

we received
149
data breaches from businesses
in Australia and across the world

114
voluntary
35
mandatory

Of the voluntary data breaches that
we received this year

35% were malicious or caused due to criminal attacks

16% were due to system glitches

46% were caused by human error

3% uncategorised

Breakdown
by sector

Promote and uphold Australian information access rights.

we helped the community resolve
2,062
of their FOI questions
16%

The top three matters related to:

1 General processing of FOI requests and complaints

2 FOI matters outside of our jurisdiction

3 Help and assistance for government agencies and ministers with their FOI processing

1,454
Phone

1454

599
Written

599

9
In person

9
  • we received
    632 requests
    for an Information Commissioner review
    24%

    Information Commissioner reviews give the community an avenue for redress if they approach a government agency or minister for information and are not satisfied with the decision they receive

  • we finalised
    515 Information Commissioner reviews
    86% of applications were resolved within 12 months of receipt

we finalised
80%
of Information Commissioner reviews without proceeding to a formal decision

In turn, only
20%
of Information Commissioner reviews resulted in a formal Commissioner decision

Other Outcomes

Triage
  • 7%

    Out of Scope

  • 3%

    Allowed to go direct to AAT

  • 24%

    Discretion not to review exercised
    for example

    • lacking substance
    • non-cooperative
    • lost contact
Case Management
  • Applicant withdraws after revised decision or for another reason

    43%
  • Formal agreement

    2%
Commissioner decisions
  • 20%
    Commissioner decisions

Freedom of
information statistics

Further information and combined APS agency FOI statistics can be viewed on data.gov.au

View freedom of information statistics

Develop the personal information management capabilities of Australian businesses and government agencies.

we partnered with
369 businesses and agencies
to promote Privacy Awareness Week

we provided
140+ pieces of substantial advice
to public and private sector organisations

we worked with a number of government agencies to ensure that they considered privacy from the start and incorporated it into upcoming policies and legislation. To help achieve this, we provided over
15 submissions to government

Our
performance

Environment

The coming years will continue to see rapid change in areas including technology, social and government service delivery. To ensure we are at the forefront of these changes, we will work closely with government and industry to better understand our operating environment, gain best practice and develop suitable processes and policies.

These processes and policies will be developed with both individuals and businesses in mind, with a focus on facilitating the use of data while protecting the personal information rights of individuals and enhancing transparency.

The coming years will also see continuing and increased development in the international space. As personal information continues to cross borders at a substantial rate and privacy becomes an increasingly important matter both politically and in the media, we will look both domestically and internationally to ensure we have the appropriate working relationships to facilitate and enable best practice privacy management and information access for all Australians.

Challenges

The challenges on the left hand side outline the activities that we plan to undertake to meet each of our goals, as set out by our Corporate Plan 2016–17. Following the 2016–17 reporting year, this section will be updated to include our results for each planned challenge.

Challenge 1: Promote, uphold and shape Australian information privacy rights.

Handle privacy complaints

  • Received 17% more privacy complaints than last year
  • 95% of all privacy complaints resolved within 12 months of receipt
  • 22% increase from last year in number of complaints closed
  • Average time taken to close a complaint was 4.7 months

Conduct privacy assessments

  • Average time to complete privacy assessments was 7.1 months
  • 100% of recommendations to entities to ensure compliance with the Privacy Act were accepted or planned for action

Conduct Commissioner initiated investigations and handle voluntary and mandatory data breach notifications

  • 84% of CIIs finalised within 8 months
  • 92% of voluntary data breach notifications closed within 60 days
  • 54% of mandatory digital health data breach notifications closed within 60 days
  • Data breach notification — A guide to handling personal information security breaches viewed on our website 29% more times than last year

Provide a public information service

  • 78% of written enquiries finalised within 10 working days
  • How do I make a privacy complaint? webpage viewed 31% more times than last year
  • Over 2,156 media mentions and 552 social media mentions of our privacy information services

Assist entities to improve their understanding of privacy compliance and promote privacy best practice

  • Developed seven privacy resources for business and government
  • Published guidance to assist Australian businesses in understanding the European Union’s General Data Protection Regulation (GDPR) and Notifiable Data Breaches (NDB) scheme

Promote awareness and understanding of privacy rights in the community

  • 49% increase in Privacy Awareness Week (PAW) partners
  • Over 250 media mentions including 20 broadcast media interviews during PAW
  • 40% increase in media enquiries
  • Membership of the Privacy Professionals’ Network increased from 169 to 1235 members
  • Participated in 22 speaking engagements aimed at privacy professionals
  • Translated five of our resources and information materials into 11 languages

Develop legislative instruments

  • No applications for Public Interest Determinations or APP codes were received in 2016–17

Challenge 2: promote and uphold Australian information access rights.

Provide a timely and effective Information Commissioner review function

  • Received 24% more Information Commissioner (IC) reviews than last year
  • Finalised 515 IC reviews
  • 86% of applications for an IC review finalised within 12 months
  • Increased number of matters finalised by informal resolution without proceeding to decision

Provide promotion and information to the Australian community on information access rights

  • 88% of written enquiries finalised within 10 working days
  • Over 622 media mentions and 77 social media mentions of our FOI information service

Assist government agencies and ministers with FOI advice and maintain guidelines and resources to promote best practices

  • Met with a number of government agencies to discuss IC reviews

Handle FOI complaints and investigations

  • All FOI complaints received were finalised within 12 months of receipt
  • Average time taken to close FOI complaints was 3 months

Challenge 3: develop the personal information management capabilities of Australian businesses and government agencies.

Promote the relationship between strong privacy governance and improved business effectiveness

  • Completed 15 submissions and issued 144 pieces of advice on privacy related topics
  • Released a Privacy Impact Assessment (PIA) eLearning program
  • Initiated development of the Australian Public Service (APS) Privacy Governance Code

Assess education and training capacity and market demand

  • Surveyed agencies to determine what privacy training is currently undertaken by staff, and what further support and resources are required

Promote, uphold and shape Australian information privacy rights.

we helped the community with
19,092
of their privacy questions
18%

15,160
Phone

15160

3,912
Written

3912

20
In person

20

we received 2,128 privacy complaints this year and helped the public resolve
2,038
of their privacy issues
3%

97%
of complaints were resolved within 12 months of receipt

During the year, the majority of complaints came from the following sectors

we reviewed the privacy practices of
67 organisations
through
21 assessments

Skip Organisations

security

Australian Customs and Border Protection Service - Passenger Name Record

Assessment focus

APP 6

Report published

Dec 2015

View Report

security

Department of Immigration and Border Protection - bogus documents

Assessment focus

APP 1

Report published

Apr 2016

View Report

security

Department of Immigration and Border Protection - general privacy

Assessment focus

APP 11

Report published

TBA

security

Department of Immigration and Border Protection - Advanced Passenger Processing

Assessment focus

APP 11

Report published

TBA

security

Department of Immigration and Border Protection - Smartgate

Assessment focus

APP 11

Report published

TBA

government

ACT Revenue Office - protection of personal information

Assessment focus

TPP 11

Report published

Jun 2016

View Report

government

Comcare - open and transparent management of personal information and collection and notification

Assessment focus

APP 3

Report published

Sep 2016

View Report

government

Universal Student Identifier (USI) - general privacy

Assessment focus

APP 1

Report published

TBA

health

My Health Records - National Prescribing and Dispensing Repository

Assessment focus

APP 11

Report published

Assessment discontinued

health

My Health Records - National Repositories Service - follow up

Assessment focus

APP 11

Report published

Sep 2016

View Report

health

My Health Records - Australia Health Practitioner Registration Agency (AHPRA)

Assessment focus

APP 10

Report published

TBA

it

Telstra - records of disclosure

Assessment focus

s 309 - monitoring by the Information Commissioner

Report published

Feb 2016

View Report

it

Optus - records of disclosure

Assessment focus

s 309 - monitoring by the Information Commissioner

Report published

Feb 2016

View Report

it

Vodafone - records of disclosure

Assessment focus

s 309 - monitoring by the Information Commissioner

Report published

Feb 2016

View Report

it

iiNet - records of disclosure

Assessment focus

s 309 - monitoring by the Information Commissioner

Report published

Feb 2016

View Report

it

Telstra - requests for information by law enforcement agencies

Assessment focus

APP 11

Report published

TBA

security

Document Verification Service - business users

Assessment focus

APP 11

Report published

Sep 2016

View Report

security

Document Verification Service - business users

Assessment focus

APP 11

Report published

Sep 2016

View Report

consumer

Coles' Flybuys loyalty program

Assessment focus

APP 1

Report published

Jul 2016

View Report

consumer

Woolworths' Everyday Rewards loyalty program

Assessment focus

APP 1

Report published

Jul 2016

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

we received
123
data breaches from businesses
in Australia and across the world

107
voluntary
16
mandatory

Of the voluntary data breaches that
we received this year

n/a were malicious or caused due to criminal attacks

n/a were due to system glitches

n/a were caused by human error

Breakdown of data breach notifications is not available for this reporting year. It will be reported from 2016–17.

Promote and uphold Australian information access rights.

we helped the community resolve
2,483
of their FOI questions
31%

The top three matters related to:

1 FOI matters outside of our jurisdiction

2 general processing of FOI requests and complaints

3 help and assistance for government agencies and ministers with their FOI processing

1,854
Phone

1854

624
Written

624

5
In person

5
  • we received
    510 requests
    for an Information Commissioner review
    37%

    Information Commissioner reviews give the community an avenue for redress if they approach a government agency or minister for information and are not satisfied with the decision they receive

  • we finalised
    454 Information Commissioner reviews
    84% of applications were resolved within 6 months of receipt

we finalised
82%
of Information Commissioner reviews without proceeding to a formal decision

In turn, only
18%
of Information Commissioner reviews resulted in a formal Commissioner decision

Other Outcomes

Triage
  • 10%

    Out of Scope

  • 7%

    Allowed to go direct to AAT

  • 25%

    Discretion not to review exercised
    for example

    • lacking substance
    • non-cooperative
    • lost contact
Case Management
  • Applicant withdraws after revised decision or for another reason

    38%
  • Formal agreement

    2%
Commissioner decisions
  • 18%
    Commissioner decisions

Freedom of
information statistics

Further information and combined APS agency FOI statistics can be viewed on data.gov.au

View freedom of information statistics

Develop the personal information management capabilities of Australian businesses and government agencies.

we partnered with
246 businesses and agencies
to promote Privacy Awareness Week

we provided
230+ pieces of substantial advice
to public and private sector organisations

we worked with a number of government agencies to ensure that they considered privacy from the start and incorporated it into upcoming policies and legislation. To help achieve this, we provided over
21 submissions to government

Our
performance

Environment

The 2015–16 reporting year was a pivotal period for the office, with opportunities and challenges for both our privacy and information access areas. The year also ended with the office’s status reconfirmed, and funding provided to revitalise and continue a number of our previously reallocated functions.

In our compliance area, we continued to review our current processes and implement changes to improve our services for the community. During the year, we managed to maintain and slightly improve our complaint handling times, with 97% of all complaints resolved within 12 months of receipt.

In our policy area, we continued to work closely with the Australian Government, businesses and international community to improve privacy and information access practices. Our work included providing guidance, advice and support on a range of current and emerging issues and trends.

The 2016–17 year ahead presents significant development opportunities, particularly in enhancing the capacity of Australian government agencies to maximise data utility while protecting personal identity. We will also work to enhance our education and communication functions, to improve privacy and information awareness in the community.

Challenges

The challenges on the left hand side outline the activities that we have agreed to undertake, to meet each of our goals as set out by our Corporate Plan 2015–16. It also highlights our results against each of the planned activities.

Challenge 1: promote and uphold information privacy rights

Handle privacy complaints

  • 97.2% of privacy complaints were finalised within 12 months of their receipt

Conduct performance assessments

  • average time taken to conduct privacy assessments this year was 5.7 months
  • 92.3% of CIIs were finalised within 8 months
  • 87.1% of voluntary data breach notifications were handled or escalated to CII within 60 days
  • 54.5% of mandatory data breach notifications were handled or escalated to CII within 60 days

Provide a public information service

  • 70% of privacy related written enquiries were finalised within 10 working days
  • 100% of phone enquiries were finalised on the day of the call

Assist regulated entities to improve understand of privacy compliance

  • issued 230 pieces of advice on privacy issues
  • completed 27 submissions on privacy related topics
  • released 25 resources for the public and regulated entities with seven opened up for consultation

Promote awareness and understanding of privacy rights in the community

  • new website was launched in October 2015 with new accessibility features
  • increase in Privacy Awareness Week partners this year, with 246 private and public sector organisations
    Develop legislative instruments
  • No applications for Public Interest Determinations and Australian Privacy Principle codes were received

Challenge 2: promote and uphold information access rights

Provide a timely and effective Information Commissioner review function

  • 87% of applications for an Information Commissioner review were finalised within 12 months of receipt

Provide an information service to the community on information access rights

  • 85% of FOI related written enquiries were responded to within 10 working days
  • 100% of phone enquiries were finalised on the day of the call

Challenge 3: organisational excellence

Excellence in people management

  • Results to come

Promote, uphold and shape Australian information privacy rights.

we helped the community with
16,166
of their privacy questions
12%

13,229
Phone

13229

2,925
Written

2925

12
In person

12

we received 2,841 privacy complaints this year and helped the public resolve
1,976
of their privacy issues
24%

98%
of complaints were resolved within 12 months of receipt

During the year, the majority of complaints came from the following sectors

we reviewed the privacy practices of
101 organisations
through
19 assessments

Skip Organisations

government

ACT Justice and Community Safety portfolio

Assessment focus

TPP 1

Report published

Apr 2015

View Report

government

ACT Justice and Community Safety portfolio

Assessment focus

TPP 1

Report published

Apr 2015

View Report

government

ACT Justice and Community Safety portfolio

Assessment focus

TPP 1

Report published

Apr 2015

View Report

government

ACT Justice and Community Safety portfolio

Assessment focus

TPP 1

Report published

Apr 2015

View Report

government

ACT Justice and Community Safety portfolio

Assessment focus

TPP 1

Report published

Apr 2015

View Report

government

ACT Justice and Community Safety portfolio

Assessment focus

TPP 1

Report published

Apr 2015

View Report

government

ACT Justice and Community Safety portfolio

Assessment focus

TPP 1

Report published

Apr 2015

View Report

security

Document Verification Service - Australian Taxation Office (ATO)

Assessment focus

IPP 2 (APP 5)

Report published

Sep 2014

View Report

security

Document Verification Service - Department of Human Services (DHS) Medicare

Assessment focus

APP 11

Report published

Nov 2014

View Report

security

Document Verification Service - Australian Financial Security Authority (AFSA)

Assessment focus

APP 11

Report published

May 2015

View Report

security

Passenger Name Record - Melbourne Airport

Assessment focus

APP 11

Report published

May 2015

View Report

security

Passenger Name Record - new administrative arrangements

Assessment focus

APP 6

Report published

Dec 2015

View Report

health

PCEHR system operator

Assessment focus

IPP 1 (APP 3)

Report published

Aug 2014

View Report

health

National repositories service

Assessment focus

IPP 4 (APP 11)

Report published

Nov 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - assisted registration policies

Assessment focus

APP 3

Report published

Dec 2014

View Report

health

PCEHR system - Western Sydney Medicare Local

Assessment focus

APP 3

Report published

Aug 2014

View Report

health

PCEHR system - St Vincent's Hospital Sydney

Assessment focus

APP 11

Report published

Jun 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Online privacy policies

Assessment focus

APP 1

Report published

May 2015

View Report

consumer

Telecommunications providers' privacy policies

Assessment focus

APP 1

Report published

Not published

consumer

Telecommunications providers' privacy policies

Assessment focus

APP 1

Report published

Not published

consumer

Telecommunications providers' privacy policies

Assessment focus

APP 1

Report published

Not published

consumer

Telecommunications providers' privacy policies

Assessment focus

APP 1

Report published

Not published

it

Telstra - records of disclosure

Assessment focus

s 309 - monitoring by the Information Commissioner

Report published

Feb 2016

View Report

it

Optus - records of disclosure

Assessment focus

s 309 - monitoring by the Information Commissioner

Report published

Feb 2016

View Report

it

Vodafone - records of disclosure

Assessment focus

s 309 - monitoring by the Information Commissioner

Report published

Feb 2016

View Report

it

iiNet - records of disclosure

Assessment focus

s 309 - monitoring by the Information Commissioner

Report published

Feb 2016

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - access controls of GP clinics

Assessment focus

APP 11

Report published

Oct 2015

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

health

My Health Records - privacy policies of GP clinics

Assessment focus

APP 1

Report published

Apr 2016

View Report

we received
117
data breaches from businesses
in Australia and across the world

110
voluntary
7
mandatory

Of the voluntary data breaches that
we received this year

n/a were malicious or caused due to criminal attacks

n/a were due to system glitches

n/a were caused by human error

Breakdown of data breach notifications is not available for this reporting year. It will be reported from 2016–17.

Promote and uphold Australian information access rights.

we helped the community resolve
1,900
of their FOI questions
0.5%

The top three matters related to:

1 FOI matters outside of our jurisdiction

2 general processing of FOI requests and complaints

3 help and assistance for government agencies and ministers with their FOI processing

1,411
Phone

1411

484
Written

484

5
In person

5
  • we received
    373 requests
    for an Information Commissioner review
    29%

    Information Commissioner reviews give the community an avenue for redress if they approach a government agency or minister for information and are not satisfied with the decision they receive

  • we finalised
    482 Information Commissioner reviews

    51% of applications were resolved within 6 months of receipt

we finalised
73%
of Information Commissioner reviews without proceeding to a formal decision

In turn, only
27%
of Information Commissioner reviews resulted in a formal Commissioner decision

Other Outcomes

Triage
  • 8%

    Out of scope

  • 13%

    Allowed to go direct to AAT

  • 28%

    Discretion not to review exercised
    for example

    • lacking substance
    • non-cooperative
    • lost contact
Case Management
  • Applicant withdraws after revised decision or for another reason

    24%
  • Formal agreement

    1%
Commissioner decisions
  • 27%
    Commissioner decisions

Freedom of
information statistics

Further information and combined APS agency FOI statistics can be viewed on data.gov.au

View freedom of information statistics

Develop the personal information management capabilities of Australian businesses and government agencies.

we partnered with
237 businesses and agencies
to promote Privacy Awareness Week

we provided
197 pieces of substantial advice
to public and private sector organisations

we worked with a number of government agencies to ensure that they considered privacy from the start and incorporated it into upcoming policies and legislation. To help achieve this we drafted
36 submissions

Our
performance

Environment

Following the Australian Government’s Budget 2014–15 decision to disband the OAIC, our initial focus for the year was on transferring functions to other government agencies. As the reporting year progressed, the processes to close the office did not proceed through Parliament; and our office continued to execute many of our core functions and requirements.

Although a challenging period, the office was able to not only deliver these important FOI and privacy functions but also significantly enhance and improve the efficiency of them.

The 2014–15 reporting year also saw the commencement of the Privacy Amendment (Enhancing Privacy Protection) Act 2012, the largest changes to the Privacy Act since its inception in 1988.

Challenges

The challenges on the left hand side outline the activities that we have agreed to undertake, to meet each of our goals as set out by our Corporate Plan 2014–17. It also highlights our results against each of the planned activities.

Challenge 1: Promote and uphold information privacy rights

  • Educate government, business and the community about personal information rights and responsibilities
  • Influence government and business to adopt best practice management of personal information
  • Deliver best practice privacy complaint handling
  • Use regulatory powers to uphold and promote privacy compliance.
  • Contribute to further reforms of privacy laws

The 2014–15 financial year was the first full year of operation of the privacy law reforms made by the Privacy Amendment (Enhancing Privacy Protection) Act 2012.

During 2013–14, our advice and guidance focused on preparing organisations and agencies for the commencement of the privacy reforms. Throughout 2014–15, our focus turned to promoting privacy as a tool to enhance customer trust and confidence. We emphasised the need for organisations and agencies to build privacy into their business-as-usual processes.

To enable this, we developed a range of guidance documents to assist entities, including the Privacy management framework, a tool to help organisations and agencies ensure compliance with the new Australian Privacy Principles and embed a culture of privacy into their everyday processes. We also developed policy documents that explain how we would exercise our expanded regulatory powers.

The 2014–15 year was also a busy year for privacy advice. During the period we published 32 pieces of guidance material, conducted seven public consultations, provided 197 pieces of external policy advice, made 36 submissions on legislative or other formal policy development processes and made six legislative instruments.

We also continued to conduct work in the eHealth space, as the independent regulator of privacy aspects of the Personally Controlled Electronic Health Records (PCEHR) system and the Healthcare Identifiers (HI) service.

From a compliance perspective we continued to undertake a wide range of activities to ensure that privacy is valued and respected in Australia. These included providing a free information service, investigating and resolving individual complaints, conducting assessments, data-matching inspections and Commissioner initiated investigations (CIIs), and receiving and administering a voluntary data breach notification (DBN) scheme and eHealth mandatory DBN scheme.

Challenge 2: Promote and uphold information access rights and proactive publication of public sector information

  • Educate government and the community about rights to access government information
  • Influence government agencies to adopt best practice in upholding information access rights
  • Foster proactive publication of public sector information, including through the Information Publication Scheme and disclosure logs
  • Deliver best practice FOI merit review and complaint handling
  • Monitor and investigate FOI administration to drive improved agency performance
  • Contribute to further reform of access to information laws

During the 2014-15 reporting period, we undertook a range of activities in accordance with our statutory responsibilities under the Freedom of Information Act 1982. These included conducting Information Commissioner reviews and handling freedom of information complaints, monitoring compliance with the FOI Act by agencies and ministers, and providing policy advice and guidance.

During the period, we finalised 482 applications for IC review, 64 FOI complaints, 4,384 extension of time requests and notifications, and responded to 1900 enquiries.

We also significantly reduced the backlog of IC reviews and complaints that existed at the start of the reporting year. This was achieved by implementing a streamlined IC review process focused on early resolution. At the beginning of 2014–15, the oldest un-actioned IC review application was 206 days old. By the end of the year, the oldest matter was 40 days old.

Challenge 3: Achieve organisational excellence by supporting and developing the OAIC’s people, systems and processes

  • Strive for excellence in people management
  • Nurture a culture of integration across the OAIC’s functions, branches and sites
  • Maintain robust governance frameworks
  • Ensure the OAIC’s information asset management framework is effective

Due to the Australian Government’s decision to disband the office, the majority of our people management and organisational excellence goals were not achieved.

Instead, we spent the year focused on supporting and providing assistance to staff throughout the closure. This included providing support, training and assistance to staff members who required relocation after our Canberra office was closed.

Challenge 4: Champion development of a national information policy that promotes public sector information as a national resource

  • Contribute to Australia’s national and international engagement on open government
  • Promote and monitor the use of the principles on open public sector information
  • Contribute to the creation and adoption of an open data policy in Australian government

Due to the Australian Government’s decision to disband the office, the majority of our information policy goals were not achieved.