Privacy Act 1988
The object of this section is to ensure that an affected information recipient manages the regulated information of the recipient in an open and transparent way.
Compliance with this Division etc.
22A(2)
An affected information recipient must take such steps as are reasonable in the circumstances to implement practices, procedures and systems relating to the recipient ' s functions or activities that:
(a) will ensure that the recipient complies with this Division and the registered CR code if it binds the recipient; and
(b) will enable the recipient to deal with inquiries or complaints from individuals about the recipient ' s compliance with this Division or the registered CR code if it binds the recipient.
Policy about the management of regulated information
22A(3)
An affected information recipient must have a clearly expressed and up-to-date policy about the recipient ' s management of the regulated information of the recipient.
22A(4)
Without limiting subsection (3), the policy of the affected information recipient must contain the following information:
(a) the kinds of regulated information that the recipient collects and holds, and how the recipient collects and holds that information;
(b) the purposes for which the recipient collects, holds, uses and discloses regulated information;
(c) how an individual may access regulated information about the individual that is held by the recipient and seek the correction of such information;
(d) how an individual may complain about a failure of the recipient to comply with this Division or the registered CR code if it binds the recipient;
(e) how the recipient will deal with such a complaint.
Availability of policy etc.
22A(5)
An affected information recipient must take such steps as are reasonable in the circumstances to make the policy available:
(a) free of charge; and
(b) in such form as is appropriate.
Note:
An affected information recipient will usually make the policy available on the recipient ' s website.
22A(6)
If a person or body requests a copy, in a particular form, of the policy of an affected information recipient, the recipient must take such steps as are reasonable in the circumstances to give the person or body a copy in that form.
Interaction with the Australian Privacy Principles
22A(7)
If an affected information recipient is an APP entity, Australian Privacy Principles 1.3 and 1.4 do not apply to the recipient in relation to the regulated information of the recipient.
Disclaimer and notice of copyright applicable to materials provided by CCH Australia Limited
CCH Australia Limited ("CCH") believes that all information which it has provided in this site is accurate and reliable, but gives no warranty of accuracy or reliability of such information to the reader or any third party. The information provided by CCH is not legal or professional advice. To the extent permitted by law, no responsibility for damages or loss arising in any way out of or in connection with or incidental to any errors or omissions in any information provided is accepted by CCH or by persons involved in the preparation and provision of the information, whether arising from negligence or otherwise, from the use of or results obtained from information supplied by CCH.
The information provided by CCH includes history notes and other value-added features which are subject to CCH copyright. No CCH material may be copied, reproduced, republished, uploaded, posted, transmitted, or distributed in any way, except that you may download one copy for your personal use only, provided you keep intact all copyright and other proprietary notices. In particular, the reproduction of any part of the information for sale or incorporation in any product intended for sale is prohibited without CCH's prior consent.