On this page

CLIENT CONFIDENTIALITY AND PRIVACY POLICY 

All Youthlaw staff and Management Committee shall work, as far as is practicable, in accordance with the professional obligations to clients to always maintain confidentiality, unless the client has agreed to information disclosure. It is particularly important when acting for children and young people to explain this principle to clients and to establish at the outset whether the client wishes information disclosed to others, such as parents and other professionals involved. 

In addition, all Youthlaw staff and Management Committee shall work, as far as is practicable, in accordance with the Information Privacy Principles (IPP) contained in s.14 of The Privacy Act 1988 (Cwth), a summary of responsibilities and related key concepts are as follows. 

Where disclosure may be necessary, as part of casework, written authority must be given from the client before any disclosure takes place. The client must always be asked whether it is appropriate to leave messages or identify the centre on their answering machine. This may inform other parties that the client has visited the centre and so would be a breach of confidentiality if the client has not given permission. 

THE NATIONAL PRIVACY PRINCIPLES – SUMMARY OF RESPONSIBILITIES 

  1. If it is lawful and practicable to do so, give people the option of interacting anonymously with you. 
  1. Only collect personal information that is necessary for your functions or activities. 
  1. Use fair and lawful ways to collect personal information. 
  1. Collect personal information directly from an individual if it is reasonable and practicable to do so. 
  1. Get consent to collect sensitive information unless specified exemptions apply. 
  1. At the time you collect personal information or as soon as practicable afterwards, take reasonable steps to make an individual aware of: 
  1. why you are collecting information about them; 
  1. who else you might give it to; and 
  1. other specified matters. 
  1. Take reasonable steps to ensure the individual is aware of this information even if you have collected it from someone else. 
  1. Only use or disclose personal information for the primary purpose of collection unless one of the exceptions in NPP 2.1 applies (for example, for a related secondary purpose within the individual’s reasonable expectations, you have consent or there are specified law enforcement or public health and public safety circumstances). 
  1. Take reasonable steps to ensure the personal information you collect, use, or disclose is accurate, complete, and up to date. This may require you to correct the information. 
  1. Take reasonable steps to protect the personal information you hold from misuse and loss and from unauthorised access, modification, or disclosure. 
  1. Take reasonable steps to destroy or permanently de-identify personal information if you no longer need it for any purpose for which you may use or disclose the information. 
  1. Have a short document that sets out clearly expressed policies on the way you manage personal information and make it available to anyone who asks for it. 
  1. If an individual asks, take reasonable steps to let the client know what sort of personal information you hold, what purposes you hold it for and how you collect, use, and disclose that information. 
  1. If an individual asks, you must give access to the personal information you hold about them unless circumstances apply that allow you to limit the extent to which you give access – these include emergency situations, specified business imperatives and law enforcement or other public interests. 
  1. Only adopt, use, or disclose a Commonwealth Government identifier if circumstances apply that would allow you to do so. 
  1. Only transfer personal information overseas if you have checked that you meet the requirements of NPP 9. 

*This is a summary only and NOT a full statement of obligations. 

KEY CONCEPTS IN PRIVACY 

Access 

This involves an organisation giving an individual information about themselves held by the organisation. Giving access may include allowing an individual to inspect personal information or giving a copy of it to them. 

Children and young people 

As a general principle, a young person is able to make decisions about confidentiality and give consent when he or she has sufficient understanding and maturity to understand what is being proposed. In some circumstances, it may be appropriate for a parent or guardian to consent on behalf of a young person; for example, if the child is noticeably young or lacks the maturity or understanding to do so themselves. 

Once capacity has been established, privacy and confidentiality rules apply the same as for children and young people as for adults. 

Collection 

An organisation collects personal information if it gathers, acquires or obtains personal information from any source and by any means. Collection includes when an organisation keeps personal information it has come across by accident or has not asked for. 

Consent 

Consent means voluntary agreement to some act, practice, or purpose. It has two elements: knowledge of the matter agreed to, and voluntary agreement. Consent can be express or implied. Express consent is given explicitly, either orally or in 

writing. Implied consent arises where consent may reasonably be inferred in the circumstances from the conduct of the individual and the organisation. Consent is invalid if there is extreme pressure or coercion. 

Only a competent individual can give consent although an organisation can ordinarily assume capacity unless there is something to alert it otherwise. Competence means that individuals are capable of understanding issues, forming views based on reasoned judgments and communicating their decisions. The general law about competence and incapacity will apply to the issue of consent. 

Contractors 

The Privacy Act treats the acts and practices of employees (and those ‘in the service of’ an organisation) in performing their duties of employment as those of the organisation (see section 8(1)(a)). Contractors performing services for an organisation are not considered to fall within this provision. However, where there is a particularly close relationship between an organisation and a contractor it may mean that the 

actions of the contractor could be treated as having been done by the organisation for the purposes of s. 8 of the Privacy Act. 

When the parties to a contract are regarded as separate entities under the Privacy Act an organisation that gives personal information to a contractor is disclosing information and the contractor is collecting the information. In practical terms, this means that the organisation may need to have clauses in the contract for the protection of personal information the organisation discloses to the contractor in order to meet its obligations under the NPPs. 

Where the contractor is not an ‘organisation’ for the purposes of the Privacy Act and so not covered by the NPPs it would be advisable for the organisation to take measures to protect the personal information it discloses to the contractor. 

What are reasonable steps under NPP 1.3 and NPP 1.5 for the organisation and a contractor may depend on the nature of the relationship between the organisation and the contractor, including the contractual provisions in place. 

For more information about how the NPPs apply where an organisation contracts out a function or activity to a separate entity see Information Sheet 8 – 2001Contractors. 

Disclosure 

In general terms an organisation discloses personal information when it releases information to others outside the organisation. It does not include giving individuals information about themselves (this is ‘access’ see above). 

Any information about a client held on a file is not to be released to a third person without the consent of the client. 

Enforcement Body 

Enforcement bodies are listed in the definitions in section 6(1) of the Privacy Act. They are also listed in Information Sheet 7 – 2001 Unlawful Activity and Law Enforcement. 

Organisation 

The NPPs apply to businesses and bodies that fall within the definition of ‘organisation’ in section 6C of the Privacy Act. Section 6C says that ‘organisation’ means: an individual; or a body corporate; or a partnership; or any other unincorporated association; or a trust; that is not a small business operator, a registered political party, an agency, a State or Territory authority or a prescribed instrumentality of a State or Territory. 

Personal Information 

Personal information is information or an opinion (including information or an opinion forming part of a database) whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion (section 6). It includes all personal information regardless of its source. Personal information relates to a natural living person. A natural person is a human being rather than, for example, a company, which may in some circumstances be recognised as a legal ‘person’ under the law. 

The NPPs apply to the collection of personal information by an organisation for inclusion in a record or an available publication, but apart from this, the NPPs only apply to personal information an organisation has collected that it holds in a record. 

Sensitive Information 

Sensitive information is a subset of personal information. It means information or opinion about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual preferences or practices, criminal record, or health information about an individual (section 6). 

Use 

In general terms, use of personal information refers to the handling of personal information within an organisation including ‘the inclusion of information in a publication.’ 

NOTE 

This only includes some of the concepts and terms in the National Privacy Principles. If you cannot find a term here, you should find it in s.6 of the Privacy Act at the following: www.privacy.gov.au