
Privacy laws in Australia are complicated and differ depending on the State or Territory where the personal information is held and whether information is held by a public or private entity.
The Privacy Act 1988 (C’th), which contains 13 Australian Privacy Principles (known as APPs), applies to all health care providers nationally.
APP11 states that ‘an APP entity that holds personal information must take reasonable steps to protect the information from misuse, interference and loss, as well as unauthorised access, modification or disclosure’.
A breach of an Australian Privacy Principle is an ‘interference with the privacy of an individual’ and can lead to regulatory action and penalties.
In Queensland, if you are concerned about the way a public hospital has handled your personal information, you can lodge a written complaint with the Department of Health directly. Complaints can be sent by post or via email to rti-privacy@health.qld.gov.au. You should receive a response within 45 business days and if you are not happy with the response, you can refer your complaint to the Office of the Information Commissioner (OIC) in Queensland.
If you are concerned about the way a private entity (such as a GP or private hospital) has handled your personal information, you should make immediate contact with the service provider. And again, if you are not happy with the response, you can refer your complaint to the Office of the Australian Information Commissioner (OAIC).
