Australian Government
Office of the Australian Information Commissioner
Our reference: 12/000064
Committee Secretary Senate Standing Committee on Community Affairs PO Box 6100 Parliament House CANBERRA ACT 2600
By email: community.affairs.sen@aph.gov.au
Dear Secretary
Inquiry into the National Disability Insurance Scheme Bill 2012
Thank you for the opportunity to comment on the National Disability Insurance Scheme Bill 2012 (NDIS Bill). The NDIS will be an important system of support for people with disability. Its success will depend on individuals having confidence in the Scheme and in the entities carrying out NDIS functions and activities. Appropriate privacy protections for personal information collected under the NDIS will be critical to fostering that confidence. For that reason, I welcome the clear statement in the ‘General Principles’ section of the NDIS Bill (cl 4) that people with disability should have their privacy and dignity respected. I also note the serious penalties in the Bill for unauthorised use and disclosure of ‘protected information’.
Office of the Australian Information Commissioner
The Office of the Australian Information Commissioner (the OAIC) was established by the Australian Information Commissioner Act 2010 and commenced operation on 1 November 2010. The OAIC is an independent statutory agency headed by the Australian Information Commissioner. The Information Commissioner is supported by two other statutory officers: The Freedom of Information Commissioner and the Privacy Commissioner.
The OAIC brings together the functions of information policy and independent oversight of privacy protection and freedom of information in one agency, to advance the development of consistent workable information policy across all Australian government agencies.
Comments
My comments on the Bill predominantly relate to Chapter 4, Part 2 of which sets out the privacy provisions for the NDIS. As a general observation, it is unclear how the NDIS Bill is intended to interact with the Privacy Act 1988 (Cth) and other State and Territory privacy legislation. It would be helpful if the Explanatory Memorandum to the Bill gave more information about the broader privacy framework for the NDIS and how entities participating in the NDIS will be covered by privacy law.
For example, it appears that the National Disability Insurance Scheme Launch Transition Agency (NDIS Agency) will be covered by the Privacy Act and that the Information Privacy Principles will apply to its operations.
However, it is unclear the extent to which other entities participating in the Scheme will be covered by privacy law. Some non-government organisations may be covered by State or Territory privacy law where they are contracted by State or Territory agencies to provide services on behalf of government. Others may not be covered by privacy law in States where no such legislation exists. Further, if a participating entity falls within the small business exemption in the Privacy Act it will not be covered by Commonwealth privacy lavv.1 Given the amount of personal information that will be collected and used under the Scheme, it will be important to ensure appropriate and consistent coverage of all participating entities under privacy law.
I understand that the Department of Families, Housing, Community Services and Indigenous Affairs is conducting a Privacy Impact Assessment (PIA) of the Scheme. A PIA is an assessment tool that tells the story of a project from a privacy perspective. It identifies gaps in privacy protection that need addressing and tests the project for compliance with privacy legislation. Carrying out a PIA will provide an important opportunity to map information flows under the NDIS and further clarify the privacy framework. However, it will be most useful if the scope of the PIA is broad enough to cover the information flows between all of the Commonwealth, State and Territory and non-government entities participating in the NDIS. Should any gaps in privacy regulation be identified I would suggest consideration be given to bringing entities not covered by privacy law under the coverage of the Privacy Act.2
It would also be helpful if the PIA were published once finalised. Any future revisions to the NDIS Bill should give regard to recommendations arising from that PIA.
Clause 60
Subclauses 60(1) and (2) allow a person to collect, use and disclose ‘protected information’ ‘for the purposes of this Act’. I am concerned about the breadth of this clause, given the broad range of functions and activities covered by the Bill. Subclause 60(3) prescribes purposes of the Act to include: research into matters relevant to the NDIS, actuarial analysis of matters relevant to the NDIS, and policy development. By my reading, this could mean that an individual’s health information, collected for the purpose of assessing their NDIS claim for supports, could feasibly be disclosed to ‘any person’ for the purpose of policy development. This would be a significant departure from protections otherwise applying to personal information under the Privacy Act and the general principle that personal information only be used or disclosed for the purpose for which it was collected.
While personal information can be important for research, analysis and policy development, generally its use for these purposes occurs within a strict framework protecting the privacy of the subjects of the information. An example is s 95 of the Privacy Act which provides for
Page 3
guidelines to protect privacy in the conduct of medical research. There may also be other more privacy-sensitive alternatives for these secondary purposes such as using de-identified information. I would suggest that the secondary use of protected information could be a matter for the NDIS rules to provide further detail on.
I also note that cl 60 regulates the actions of ‘a person’ rather than a particular agency or group of agencies or organisations. The term ‘person’ is not defined in the Bill and therefore must be understood in its broadest sense. I accept that there may be good reasons for using broad terminology — for example, the provisions may be intended to cover a wide range of entities and individuals carrying out functions under the NDIS. However, the Explanatory Memorandum could provide more detail about the practical coverage of this clause. For example, it could explain whether the provision is intended to cover the record-keeping activities of nominees or carers.
Clause 66
Subclause 66(1)(a) gives the CEO of the the NDIS Agency a broad power to disclose any information acquired under the Act if the CEO ‘certifies that it is necessary in the public interest to do so’. The CEO may disclose the information to ‘such persons and for such purposes as the CEO determines’. I am concerned about the breadth of this clause. It is not clear to me, from the Bill or the Explanatory Memorandum, the reasons for having such a broad disclosure power, nor the factors that will be weighed in the public interest test.
The Explanatory Memorandum gives one example of when this provision may be invoked — where disclosure is necessary for the investigation of a criminal offence. While there may be a public interest in allowing disclosure of information to a law enforcement agency in these circumstances, such a scenario may be more appropriately addressed in the legislation by a specific clause rather than a broad one.
I have similar concerns about the breadth of subclauses 66(1)(b)(i) and (v) which allow the CEO to disclose any information acquired under the Act to the head of any Commonwealth, State or Territory Department or authority ‘for the purposes of that Department or authority’. The Bill is not adequately specific about what purposes should be allowed to trigger disclosure. Given the breadth of functions and activities of State and Commonwealth agencies, such a broadly framed clause would potentially allow personal information to be used for purposes unrelated to the primary purpose of collection.
The aim should be to ensure that participants maintain control over how their information is handled (in line with the guiding principles set out under cl 4 of the Bill which state that people with disability should have their privacy respected and should be supported to exercise choice and control in the pursuit of their goals and the planning and delivery of their supports). Provisions establishing wide discretions to disclose information would limit the choice and control of participants over the handling of their personal information.
NDIS rules
It appears that further detail about the operation of the Scheme will be set out in NDIS rules issued by the Minister under cl 209. Clause 67 states that the NDIS rules may make provision for and in relation to the exercise of the CEO’s disclosure powers under cl 66(1)(a) and
Page 4
Inconsistent application of clauses 66(1)(b)(i), (v)
If clause 66 remains in its current form, I suggest that the establishment of rules be mandatory rather than discretionary.
I further suggest that clause 67 prescribe what the rules must cover (for example, clause 67 could, in the absence of specific legislative provisions as suggested above, require the rules to specify how the public interest test should operate and what factors (including privacy factors) outweigh disclosure). In its current form, clause 67 gives no indication of how the rules should limit or regulate the operation of clause 66.
Inconsistencies in terminology with the Privacy Act
There are some inconsistencies in terminology between the Bill and the Privacy Act. The Bill uses the terms ‘obtain’ and ‘authorisation’ where the Privacy Act uses ‘collect’ and ‘consent’.
I am uncertain whether these differences are intentional and if so the reasons for their use. However, in the interests of consistency, I suggest that the Bill be amended to reflect the terminology in the Privacy Act.
Yours sincerely, Tim ilg Australian Privacy Commissioner 24 January 2013