Skip to main content
Westlink Intranet

Command Palette

Search for a command to run...

?
INTERNAL
Back to Compliance

Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches

Privacy Act 1988 (Cth) — Australian Privacy Principles (APPs 1–13) + Notifiable Data Breaches scheme (Part IIIC)

Requirements
24
Last reviewed
15/04/2026
Next review
15/04/2027
Source
Privacy Act 1988 current compilation (includes Privacy Act 1988 and Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 reforms; Privacy and Other Legislation Amendment Act 2024 first tranche)

Reconciliation notes

Curated build capturing the 13 Australian Privacy Principles (Schedule 1) plus Part IIIC Notifiable Data Breaches scheme. Westlink is an APP entity (turnover >$3M threshold). Scope notes: (1) Credit reporting (Part IIIA) is Not Applicable — Westlink is not a credit provider. (2) Tax File Number Rule is Applicable for payroll/HR records. (3) Privacy reforms pending: the Privacy and Other Legislation Amendment Act 2024 introduced the first tranche of reforms (statutory tort for serious invasions of privacy from 10 June 2025; children's privacy code; enhanced OAIC enforcement); further tranches expected 2026–27 (direct right of action, fair and reasonable test) — row PRV-REFORM-01 tracks as Reference-only. Total requirements: 24. Applicable: 23. Reference-only: 1. Coverage on Applicable rows: Full=1, Partial=14, Gap=8. Gap severities: Critical=2, High=6, Medium=0, Low=0. Evidence mapping is richer than HVNL because GOV-POL-015 Privacy Policy (Rev 3) exists and is APP-structured; main gaps are operational (Privacy Impact Assessments, breach-response operating procedure, APP 8 overseas disclosure register, APP 5 collection notices at customer/supplier onboarding).

Requirements

Showing 24 of 24 requirements

IDClauseRequirementApplicabilityCoverageEvidenceGap
PRV-APP1-01APP 1.2An APP entity must take such steps as are reasonable in the circumstances to implement practices, procedures and systems relating to the entity's functions or activities that will ensure the entity complies with the APPs and enable the entity to deal with inquiries and complaints.ApplicablePartial
  • GOV-POL-015 §Purpose / Policy CommitmentsPolicy establishes APP compliance framework and assigns complaint-handling to Privacy Officer role. Operating procedures (PIA process, training, audit) not separately documented.
High
Policy-level commitment present; supporting operating procedures (PIA process, training records, periodic audit) not documented. Consider a Privacy Management Plan as the OAIC recommends for APP 1.2.
PRV-APP1-02APP 1.3An APP entity must have a clearly expressed and up-to-date APP privacy policy about the management of personal information by the entity.ApplicableFull
  • GOV-POL-015 §whole documentGOV-POL-015 Privacy Policy (Rev 3) is APP-structured and covers APPs 1-13 + Part IIIC NDB. Reviewed as part of the management review cycle per Review section.
PRV-APP1-03APP 1.4The APP privacy policy must contain the kinds of personal information the entity collects and holds; how and from where it is collected; the purposes of collection, holding, use and disclosure; how individuals may access and correct personal information; how they may complain and how the entity will deal with the complaint; whether the entity is likely to disclose personal information to overseas recipients and if so, the countries.ApplicablePartial
  • GOV-POL-015 §Organisational ContextOrganisational Context section identifies types of information. APP 1.4 overseas-disclosure countries list — policy states whether disclosure occurs but country list may be general (verify).
High
Verify APP 1.4(f) specifics — policy must name the countries (or specify if not practicable) to which personal information is likely to be disclosed. Given international freight + chartered vessels, overseas recipients likely include foreign shipping agents, customs brokers, port agents. Audit the policy text against actual cross-border data flows.
PRV-APP2-01APP 2Individuals must have the option of not identifying themselves, or of using a pseudonym, when dealing with the entity in relation to a particular matter, unless it is impracticable or the entity is required by law to deal with identified individuals.ApplicableGapMedium
For most Westlink interactions (customers, suppliers, employees) anonymity is impracticable. Add explicit APP 2 position statement — e.g. "anonymous/pseudonymous dealing offered for general inquiries via website contact form; identified dealing required for service delivery, contracting, employment, DISP-compliant transactions."
PRV-APP3-01APP 3.1 / 3.2An APP entity must not collect personal information unless the information is reasonably necessary for, or directly related to, one or more of the entity's functions or activities.ApplicableFull
PRV-APP3-02APP 3.5An APP entity must collect personal information only by lawful and fair means.ApplicableGapMedium
APP 3.5 (lawful and fair means of collection) not addressed; GOV-POL-015 covers APP 3.1/3.2 and the collection notice only.
PRV-APP4-01APP 4Where an APP entity receives unsolicited personal information, the entity must determine within a reasonable period whether the information could have been collected under APP 3. If not, the entity must destroy or de-identify the information as soon as practicable (if lawful and reasonable).ApplicableGapMedium
No documented unsolicited-information handling process. Practical exposure: unsolicited job applications, third-party referrals, incidental information received during tenders. Add procedural hook in GOV-POL-015 / a supporting procedure.
PRV-APP5-01APP 5At or before the time (or as soon as practicable after) the entity collects personal information about an individual, it must take reasonable steps to notify the individual of matters listed in APP 5.2 — including identity of entity, purposes of collection, consequences of not providing information, usual disclosures, link to APP privacy policy, overseas disclosures.ApplicablePartial
  • GOV-POL-015 §Policy CommitmentsPolicy bullet 1 commits to notification at or before collection (APP 3, APP 5). Operational notices at collection points (employment forms, customer onboarding forms, supplier onboarding) not verified to contain all APP 5.2 matters.
High
Audit collection notices: (a) employment application forms, (b) customer onboarding forms, (c) supplier onboarding forms, (d) website contact forms. Each should contain an APP 5 collection statement. High-risk gap because operational notices often omit APP 5.2(i) overseas disclosure and APP 5.2(j) privacy-policy link.
PRV-APP6-01APP 6An APP entity that holds personal information collected for a particular purpose (the primary purpose) must not use or disclose the information for another purpose (a secondary purpose) unless consent is obtained, the individual would reasonably expect use/disclosure for the secondary purpose and it is related (or directly related for sensitive information) to the primary purpose, or another APP 6.2/6.3 exception applies.ApplicableFull
  • GOV-POL-015 §Policy CommitmentsPolicy bullet 2 commits to use/disclosure for primary purpose only (APP 6). No secondary-purpose register or consent capture mechanism documented.
PRV-APP7-01APP 7An organisation must not use or disclose personal information for direct marketing unless an exception applies (consent, reasonable expectation, simple opt-out provided). Spam Act 2003 and Do Not Call Register Act 2006 provide parallel electronic/telemarketing restrictions.ApplicableFull
  • GOV-POL-015 §Policy CommitmentsPolicy bullet 2 states "Westlink does not sell personal information or use it for unsolicited direct marketing (APP 6)." Functional compliance by policy-level prohibition.
PRV-APP8-01APP 8.1Before an APP entity discloses personal information about an individual to an overseas recipient, the entity must take such steps as are reasonable to ensure that the overseas recipient does not breach the APPs in relation to the information. Accountability for overseas breaches under s.16C applies unless an exception at APP 8.2 applies.ApplicableFull
PRV-APP8-02APP 8.2APP 8.1 does not apply if the entity reasonably believes the recipient is subject to a law/binding scheme substantially similar to the APPs, the individual consents after being informed APP 8.1 will not apply, or another exception (required by law, enforcement body) applies.ApplicableFull
  • GOV-PRO-006 §Cross-Border Disclosure of Personal InformationGOV-PRO-006 §Cross-Border Disclosure (Exceptions) requires assessing and recording whether an APP 8.2 exception applies (substantially similar law/binding scheme, informed consent, or another exception) before relying on it, via the overseas-recipient register's per-country assessment.
PRV-APP9-01APP 9An organisation must not adopt a government-related identifier (e.g. TFN, Medicare number, driver's licence number) as its own identifier of an individual, and must not use or disclose such identifiers except in limited circumstances.ApplicableGapMedium
TFN collection is governed by the TFN Rule (Privacy (Tax File Number) Rule 2015) in addition to APP 9 — ensure payroll processes comply (notice, secure storage, restricted use). Confirm Westlink does not use TFN or driver's licence as internal identifier.
PRV-APP10-01APP 10An APP entity must take reasonable steps to ensure the personal information it collects is accurate, up-to-date and complete; and that personal information it uses or discloses is accurate, up-to-date, complete and relevant.ApplicablePartial
  • GOV-POL-015 §Policy CommitmentsPolicy bullet 3 addresses quality/retention. Operational mechanisms (periodic data quality review, record correction workflows) not documented separately.
Medium
Align with GOV-SCH-001 Document Retention Schedule — ensure retention decisions factor data quality (destroy/correct stale data). Consider periodic employee-record verification and customer/supplier contact verification as minimum quality controls.
PRV-APP11-01APP 11.1An APP entity must take such steps as are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.ApplicableFull
  • TEC-POL-001Information Security Policy governs protective security controls (access management, encryption, incident response). Aligned with ISM/E8.
  • TEC-POL-002User Access Management Policy addresses access control (APP 11 unauthorised access dimension).
  • GOV-POL-015 §Policy CommitmentsPolicy bullet 3 references APP 11.
  • GOV-POL-016 §Policy CommitmentsSocial Media Usage Policy — commits to monitoring and consequences.
PRV-APP11-02APP 11.2Where an APP entity holds personal information that is no longer needed for any purpose for which it may be used or disclosed, the entity must take reasonable steps to destroy or de-identify the information (unless the information is required to be retained by law or a court/tribunal order).ApplicableFull
PRV-APP11-03APP 11 / OAIC GuideReasonable steps to protect personal information should be proportionate to risk and include: governance, information-security risk assessment, access controls, physical security, ICT security, data breach response plan, training, workplace policies, third-party arrangements, ICT system design.ApplicablePartialHigh
Data breach response plan (distinct from generic incident response) not documented as a standalone operational procedure. See PRV-NDB-01..03 for NDB-specific gaps.
PRV-APP12-01APP 12On request from an individual, an APP entity must give the individual access to personal information about them that is held by the entity, unless a specified exception applies. Entity must respond within a reasonable period (30 days as OAIC benchmark) and at no or minimal charge.ApplicablePartialHigh
Add an access-request handling procedure (template request form + workflow) as an operational annex to GOV-POL-015. Low inherent volume expected; but the process must exist before an OAIC complaint.
PRV-APP13-01APP 13An APP entity must take reasonable steps to correct personal information if the entity is satisfied the information is inaccurate, out of date, incomplete, irrelevant or misleading; or an individual requests correction. Must respond within a reasonable period and notify downstream recipients where practicable.ApplicablePartialMedium
Correction process doubles with access-request procedure (PRV-APP12-01).
PRV-NDB-01s.26WE — eligible data breachWhere there is unauthorised access to, or unauthorised disclosure of, personal information (or loss of personal information in circumstances where such access/disclosure is likely), and a reasonable person would conclude the access/disclosure would be likely to result in serious harm to any individual to whom the information relates, the entity must assess whether the breach is an eligible data breach.ApplicableFull
PRV-NDB-02s.26WH, s.26WK, s.26WL — assessment, statement and notificationWhere an entity has reasonable grounds to believe an eligible data breach has occurred, it must as soon as practicable prepare a statement and give a copy to the Commissioner (OAIC) and notify affected individuals; if an entity suspects but does not have reasonable grounds to believe, it must carry out a reasonable and expeditious assessment within 30 days.ApplicableFull
PRV-NDB-03s.26WK(3), OAIC guidance — data breach response planEntities should maintain a data breach response plan setting out roles, response team, containment/assessment/notification/review phases, and integration with IT incident response, business continuity and communications plans.ApplicableFull
  • GOV-POL-015 §Policy CommitmentsPrivacy Policy — commits to NDB scheme compliance.
  • TEC-PRO-001 §External Notification PathwaysTEC-PRO-001 §External Notification — OAIC NDB sets the 30-day eligible-data-breach assessment and the s.26WK statement path under Privacy Act 1988 (Cth) Part IIIC.
  • GOV-PRO-006 §Data Breach Response PlanGOV-PRO-006 §Data Breach Response Plan sets out the response team (Privacy Officer, Security Officer/MSP, CEO, Legal, Communications), the contain/assess/notify/review phases, integration with TEC-PRO-001 and QHSE-PRO-001, and at-least-annual testing.
PRV-TFN-01Privacy (Tax File Number) Rule 2015Where an entity collects a Tax File Number, it must only use or disclose the TFN for a lawful purpose and securely destroy it when no longer required. TFN collection is voluntary unless authorised by taxation, assistance agency or superannuation law.ApplicableGapMedium
Verify payroll system and HR records apply TFN-specific controls (restricted access, secure destruction, separation from non-tax-purpose identifiers).
PRV-REFORM-01Privacy and Other Legislation Amendment Act 2024 + pending tranchesFirst-tranche reforms commenced 10 June 2025 (statutory tort for serious invasions of privacy; enhanced enforcement; children's privacy code in development). Further tranches expected 2026–27 including direct right of action against APP entities and a "fair and reasonable" test for handling personal information.Reference onlyReferenced-only
Track for incorporation at next review cycle. When the fair and reasonable test commences, expect significant uplift needed across collection, use/disclosure, and overseas-disclosure practices.
Source document

Privacy Act 1988 (Cth) — Australian Privacy Principles (APPs 1–13) + Notifiable Data Breaches scheme (Part IIIC)

24 normative shall-statements extracted from Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches (source: Privacy Act 1988 (Cth) — Schedule 1 (APPs) + Part IIIC (NDB)). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.

Coverage summary

CoverageCount
✅ Full11
🟡 Partial7
🟠 Ref-only1
🔴 Gap5
— N/A0

Gap severity distribution

SeverityCount
🔴 Critical0
🟠 High5
🟡 Medium7
🟢 Low0

Requirements

Clause APP 1

IDCoverageEvidenceGapNotes
PRV-APP1-01🟡 Partial[GOV-POL-015 §Purpose / Policy Commitments](/wms/GOV-POL-015#sPurpose / Policy Commitments)🟠 HighPolicy-level commitment present; supporting operating procedures (PIA process, training records, periodic audit) not documented. Consider a Privacy Management Plan as the OAIC recommends for APP 1.2.
PRV-APP1-02✅ Full[GOV-POL-015 §whole document](/wms/GOV-POL-015#swhole document)
PRV-APP1-03🟡 Partial[GOV-POL-015 §Organisational Context](/wms/GOV-POL-015#sOrganisational Context)🟠 HighVerify APP 1.4(f) specifics — policy must name the countries (or specify if not practicable) to which personal information is likely to be disclosed. Given international freight + chartered vessels, overseas recipients likely include foreign shipping agents, customs brokers, port agents. Audit the policy text against actual cross-border data flows.

Clause APP 10

IDCoverageEvidenceGapNotes
PRV-APP10-01🟡 Partial[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)🟡 MediumAlign with GOV-SCH-001 Document Retention Schedule — ensure retention decisions factor data quality (destroy/correct stale data). Consider periodic employee-record verification and customer/supplier contact verification as minimum quality controls.

Clause APP 11

IDCoverageEvidenceGapNotes
PRV-APP11-01✅ FullTEC-POL-001
TEC-POL-002
[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)
[GOV-POL-016 §Policy Commitments](/wms/GOV-POL-016#sPolicy Commitments)
PRV-APP11-02✅ FullGOV-SCH-001
[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)

Clause APP 11 / OAIC Guide

IDCoverageEvidenceGapNotes
PRV-APP11-03🟡 PartialTEC-POL-001
[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)
[TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’)
🟠 HighData breach response plan (distinct from generic incident response) not documented as a standalone operational procedure. See PRV-NDB-01..03 for NDB-specific gaps.

Clause APP 12

IDCoverageEvidenceGapNotes
PRV-APP12-01🟡 Partial[GOV-POL-015 §Policy Commitments / Responsibilities](/wms/GOV-POL-015#sPolicy Commitments / Responsibilities)🟠 HighAdd an access-request handling procedure (template request form + workflow) as an operational annex to GOV-POL-015. Low inherent volume expected; but the process must exist before an OAIC complaint.

Clause APP 13

IDCoverageEvidenceGapNotes
PRV-APP13-01🟡 Partial[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)🟡 MediumCorrection process doubles with access-request procedure (PRV-APP12-01).

Clause APP 2

IDCoverageEvidenceGapNotes
PRV-APP2-01🔴 Gap🟡 MediumFor most Westlink interactions (customers, suppliers, employees) anonymity is impracticable. Add explicit APP 2 position statement — e.g. “anonymous/pseudonymous dealing offered for general inquiries via website contact form; identified dealing required for service delivery, contracting, employment, DISP-compliant transactions.

Clause APP 3

IDCoverageEvidenceGapNotes
PRV-APP3-01✅ Full[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)
PRV-APP3-02🔴 Gap🟡 MediumAPP 3.5 (lawful and fair means of collection) not addressed; GOV-POL-015 covers APP 3.1/3.2 and the collection notice only.

Clause APP 4

IDCoverageEvidenceGapNotes
PRV-APP4-01🔴 Gap🟡 MediumNo documented unsolicited-information handling process. Practical exposure: unsolicited job applications, third-party referrals, incidental information received during tenders. Add procedural hook in GOV-POL-015 / a supporting procedure.

Clause APP 5

IDCoverageEvidenceGapNotes
PRV-APP5-01🟡 Partial[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)🟠 HighAudit collection notices: (a) employment application forms, (b) customer onboarding forms, (c) supplier onboarding forms, (d) website contact forms. Each should contain an APP 5 collection statement. High-risk gap because operational notices often omit APP 5.2(i) overseas disclosure and APP 5.2(j) privacy-policy link.

Clause APP 6

IDCoverageEvidenceGapNotes
PRV-APP6-01✅ Full[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)

Clause APP 7

IDCoverageEvidenceGapNotes
PRV-APP7-01✅ Full[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)

Clause APP 8

IDCoverageEvidenceGapNotes
PRV-APP8-01✅ Full[GOV-PRO-006 §‘Cross-Border Disclosure of Personal Information’](/wms/GOV-PRO-006#s’Cross-Border Disclosure of Personal Information’)
PRV-APP8-02✅ Full[GOV-PRO-006 §‘Cross-Border Disclosure of Personal Information’](/wms/GOV-PRO-006#s’Cross-Border Disclosure of Personal Information’)

Clause APP 9

IDCoverageEvidenceGapNotes
PRV-APP9-01🔴 Gap🟡 MediumTFN collection is governed by the TFN Rule (Privacy (Tax File Number) Rule 2015) in addition to APP 9 — ensure payroll processes comply (notice, secure storage, restricted use). Confirm Westlink does not use TFN or driver’s licence as internal identifier.

Clause Privacy (Tax File Number) Rule 2015

IDCoverageEvidenceGapNotes
PRV-TFN-01🔴 Gap🟡 MediumVerify payroll system and HR records apply TFN-specific controls (restricted access, secure destruction, separation from non-tax-purpose identifiers).

Clause Privacy and Other Legislation Amendment Act 2024 + pending tranches

IDCoverageEvidenceGapNotes
PRV-REFORM-01🟠 Ref-only[GOV-POL-015 §Organisational Context](/wms/GOV-POL-015#sOrganisational Context)Track for incorporation at next review cycle. When the fair and reasonable test commences, expect significant uplift needed across collection, use/disclosure, and overseas-disclosure practices.

Clause s

IDCoverageEvidenceGapNotes
PRV-NDB-01✅ Full[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)
QHSE-PRO-001
[TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments)
TEC-PRO-001 §‘Responsibilities’
[GOV-PRO-006 §‘Eligible Data Breach Assessment’](/wms/GOV-PRO-006#s’Eligible Data Breach Assessment’)
PRV-NDB-02✅ Full[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)
[TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments)
TEC-PRO-001 §‘Responsibilities’
[GOV-PRO-006 §‘Notification / NDB Statement Content’](/wms/GOV-PRO-006#s’Notification / NDB Statement Content’)
PRV-NDB-03✅ Full[GOV-POL-015 §Policy Commitments](/wms/GOV-POL-015#sPolicy Commitments)
[TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’)
[GOV-PRO-006 §‘Data Breach Response Plan’](/wms/GOV-PRO-006#s’Data Breach Response Plan’)

Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.