DOCUMENT 1
FOI 25/26-2150
0:0:0.0 –> 0:0:4.840 s47F - personal privacy Laura Hey everyone, I’ve started the recording. If you don’t want to be in it, you’re welcome to turn your cameras off.
0:0:9.480 –> 0:0:12.200 s47F - personal priv Rebecca Thank you very much, Laura.
0:0:12.240 –> 0:0:33.80 s47F - personal priv Rebecca All right. Well, we might get started. So thank you everyone for attending today’s FY training session on sections 41224, a, A and 24 AB. We will be spending the most time on 24AA and 24-AB, which is practical refusals and practical refusal notices.
0:0:34.560 –> 0:0:48.120 s47F - personal priv Rebecca The reason I’ve included sections 4 and 12 in today’s training is that together with 24 AA, they actually really go materially to scoping a request. So I think it’s UN, it’s really important to understand each component.
0:0:54.770 –> 0:1:26.250 s47F - personal priv Rebecca Right. OK. So Section 4 of the FOI Act defines the terms used in the ACT, and specifically for our purposes. Today we’re going to be looking at the definition of documents. So documents are defined in terms of the types of records that may be held by the agency, and this includes, but is not limited to, paper maps, plans, drawings, sounds, images and articles on which information has been stored or recorded. Importantly, Section 4 also defines what defines what is, what is not is not a document.
0:1:26.590 –> 0:1:45.470 s47F - personal priv Rebecca And this includes material maintained for reference purposes that is otherwise publicly available or cabinet notebooks. This means that if the documents sought by an applicant is already publicly available, we must refuse the request under Section 4 as we don’t have authority to release via FOI.
0:1:49.450 –> 0:2:19.610 s47F - personal priv Rebecca Section 4 also relevantly defines documents of the agency, so a document of the agency is a document that is in possession of the agency where it was created or received in the agency, or in order to comply with section 6C, the agency has taken contractual measures to ensure it receives the document, so that would be a situation where the NDIA has contracted a third party to undertake a particular function and as part of that contract, all of their documents.
0:2:19.930 –> 0:2:35.90 s47F - personal priv Rebecca So subject to free to FOI law, now that only applies to documents that relate to the performance of the
Page 1 of 331
FOI 25/26-2150
contract, rather than entry into the contract. So those initial sort of tender documents and things would not be included by that.
0:2:38.680 –> 0:3:7.800 s47F - personal priv Rebecca So if we look at Section 4 examples in an ndia context, Section 4 refusals would be appropriate for information policy statistics and reports published on the agency’s website. And that might be as part of the disability Reform Minister Council’s quarterly reports or scheme. Actu reports the pulse, that sort of thing might be appropriate if it’s published on the website. Any information about the NDIS on data.gov dot au?
0:3:8.930 –> 0:3:39.90 s47F - personal priv Rebecca Information on disclosure logs and not just ours. If someone asks for a document which relates to our agency and another agency, it would be worth checking their disclosure log to make sure the the other party hadn’t already released something and any material on external websites. So best practise is to always provide a link to the section for material in your decision letter. So you would say in your decision letter. Unfortunately due to Section 4 I’m not able to provide this document. However, here’s a link to it.
0:3:44.200 –> 0:3:49.720 s47F - personal priv Rebecca So just a quick knowledge check and I’ll ask people to call out the answers ’cause I can’t see your names at the moment.
0:3:51.80 –> 0:3:52.760 s47F - personal priv Rebecca So a student requests a copy.
0:3:54.280 –> 0:3:58.600 s47F - personal priv Rebecca Of the 2223 annual report. So how would you approach that type of request?
0:4:0.810 –> 0:4:4.850 s47F - persona Helen You’d refuse access to it and provide with the link to the report.
0:4:5.190 –> 0:4:23.30 s47F - personal priv Rebecca Yeah. So you checked to see first if it was published online and if it was, you do exactly that refuse access under Section 4 and provide the link. So the second question is a participant requests a copy of a medical report that they submitted to the agency for a plan review. Is this a document of the agency?
0:4:26.350 –> 0:4:27.150 s47F - personal privacy Megan It.
Page 2 of 331FOI 25/26-2150
0:4:26.390 –> 0:4:29.350 s47F - persona Helen Yes, because it’s received by the agent.
0:4:28.720 –> 0:4:35.480 s47F - personal priv Rebecca Yes, that’s correct. It’s been received by the agency and therefore it is a document of the agency.
0:4:35.520 –> 0:4:41.160 s47F - personal priv Rebecca A journalist request data about the number of participants in the scheme. How would you approach this request?
0:4:42.460 –> 0:5:0.380 s47F - personal Jennifer I would say that it’s non compliant because they’re not asking for information, but they’re asking for answers to a question and I would suggest that I could assist them and maybe rescoping to ask for a document that exists. Otherwise I would say it’s a non compliant application.
0:5:2.720 –> 0:5:32.880 s47F - personal priv Rebecca Answer Jennifer and I’ve got a slightly different thought on that one. So any information held in our systems is actually covered by section 17 of the Act, which talks about use of a computer to extract information or to create a document. So I think in this situation, this probably would be a reasonable scope except for a couple of things. So first of all, I think we would need to clarify the date range of interest and at that point we try and point the person to an existing report.
0:5:33.480 –> 0:5:58.360 s47F - personal priv Rebecca If a report is published, we could refuse access under Section 4 and provide a link. But if the data is not available, we probably would need to process the request because obviously the Agency would know the number of participants in the scheme and would have that recorded somewhere. So in that situation, whilst the scope is not clear in the current form we’ve got here a little bit of scoping work could enable us to make it a valid scope.
0:6:0.160 –> 0:6:11.520 s47F - personal priv Rebecca And the 4th question is an NDIS ndia staff member requests a copy of an MS Teams chat between two colleagues about him. Is this a document of the agency?
0:6:11.850 –> 0:6:12.530 s47F - personal Jennifer Yes.
0:6:12.760 –> 0:6:13.160 s47F - persona Helen Yes.
Page 3 of 331FOI 25/26-2150
Rebecca It is and just a warning. I have seen this done and it is not pretty, so please be always be very very mindful that anything you write in the course of your work is a document of the agency and can be FOID.
Rebecca Moving now to section 12 and I have included section 12. Really just I guess for general knowledge at this point, it doesn’t seem to particularly apply to ndia records for a couple of different reasons. So first of all, section 12 states that a person is not entitled to access documents.
Rebecca In under the FY Act, if they fall under the Archive Act 1983 Open Access period. Now, as the agency is only 10 years old, you are unlikely to have any documents that fall under that because that.
Rebecca Open excess period comes into play 20 years after the event.
Rebecca 12-1 B documents open to public access as part of a register or similar, whether for a fee or not.
Rebecca An external ex example of that is legend, which is a database of government legislation and.
Rebecca And policy and regulations held by other agencies. The Ndia does not appear to subscribe to that, so that one would not be covered. But generally, if someone wanted access to say.
Rebecca A regulations on such and such a topic you could just say, well, it’s available on legend. Off you go under section 12 and you would not have to deal with the matter.
Rebecca Interestingly, that might not apply at the moment, but potentially if changes were made to pace in future where people were able to download their own information.
Rebecca That might be something that we could sort of look at then under twelve 1B.
FOI 25/26-2150
0:8:7.870 –> 0:8:9.70 s47F - personal priv Rebecca 12-1 ba.
0:8:9.580 –> 0:8:20.820 s47F - personal priv Rebecca Refers to documents that are part of a land title register. Unlikely to be involved here. 12-1, Suite 12. One C is documents that are available for purchase by the public.
0:8:22.420 –> 0:8:39.780 s47F - personal priv Rebecca Examples I’ve worked with in the past is where people can pay a fee to get a copy of their citizenship Application citizenship certificate, or they can pay a fee to purchase data held by the agency. Those are both examples of my previous agency, so that one is actually quite handy.
0:8:40.300 –> 0:9:6.140 s47F - personal priv Rebecca Unfortunately not here just yet, but that’s something that might sort of happen in the future and 12/2 cigarettes of documents relating to Norfolk Island, which is quite an interesting little part of the FY Act. If you do have a request impacted by section 12, you should issue a formal refusal letter explaining why the applicant is not entitled to access the document and refuse it. It’s just a flat out refusal.
0:9:7.190 –> 0:9:9.190 s47F - personal privacy Laura Rebecca, could I just ask a question about that?
0:9:9.300 –> 0:9:9.820 s47F - personal priv Rebecca Please.
0:9:10.540 –> 0:9:15.780 s47F - personal privacy Laura Sure, under section 12, would this kind of situation apply?
0:9:17.40 –> 0:9:33.280 s47F - personal privacy Laura If somebody has requested access to a proprietary tool that the NDA holds, such As for example, the Vineland 3 adaptive behaviour scales test that is owned by Pearson Assessments and available for licencing from that company.
0:9:32.890 –> 0:9:37.890 s47F - personal priv Rebecca Oh yes, I would suggest that that is part of a registrar similar.
0:9:38.410 –> 0:9:39.90 s47F - personal privacy Laura Wonderful.
Page 5 of 331FOI 25/26-2150
Rebecca: We would have to look into that and probably go to the FOI guidelines and have a really close reading of it, but the on face value that would seem to be a register or similar, I think.
Rebecca: And certainly, you know, if there’s a fee.
Rebecca: Yeah, I think 12. One may, we could probably try and make an argument for 12/1 B depending on what the guidelines say.
Laura: OK, wonderful. Thank you.
Rebecca: No worries.
Rebecca: Alright, moving on to practical refusals.
Rebecca: So a practical refusal reason exists under section 24AA of the FO Act. If it either of the following applies. So under 24 a A1A1 the work involved in the processing of the request would substantially and unreasonably divert the resources of the agency from its other operations, and under 24 a A1B the request does not satisfy the requirements of the requirements of 15 to B.
Rebecca: The FO Act, which requires you to provide such information concerning the document you are seeking to access to enable the Agency to be able to identify it. So basically it’s not for 24 a A1B. It’s not valid because you haven’t given us enough information to undertake reasonable searches.
Rebecca: Now you can issue more than one type of a practical refusal for each request if required, but you must ensure that you deal with each of them separately.
Rebecca: And so usually you would do the validity one first and then you would do the unreasonable diversion of
FOI 25/26-2150
resources. Second, this always confuses me because in my mind they should be around the other way in the act, but unfortunately this is how they’re presented.
So the terminology I’m going to be using today, so I’ll be talking about practical refusal reasons and this is the grounds for considering refusal under the two, the two parts of the act I’ll be talking about Prns, which is a practical refusal notice and this is the mandatory first step of the process which notifies an applicant of your intention to refuse their request and invites the applicant to engage in a request consultation process under section 24 AB. I’ll also be talking about APR decision or a practical refusal decision and that’s the decision you eventually make to refuse an access request based on APR reason.
Now this step can only be undertaken after PRN has been issued and must be based on the same practical refusal reason identified in the PRN. So if you send aprn saying your request is not valid For these reasons, you cannot then refuse it on aprn on the basis that it’s an unreasonable diversion of resources. It must be consistent. You must do step one and then Step 2.
So first of all, we’ll look at invalid requests.
So as I’ve mentioned, this comes back to 15, two B of the FI axe, which requires applicants to provide information concerning the documents so we can reasonably find it now this should be actioned at point of registration.
So triage and registrations team, this one’s for you.
We need to look at the scope and decide whether we have enough information to process it.
A. At this point, we will invite the applicant to engage in a request consultation process in order to assist them to lodge a valid request as we are required to do under section 15.
The applicant has 14 days to respond to a practical refusal notice on this grounds and if there is no response, we can deem it to be withdrawn or refuse it based on the outcome. If the applicant suggests a new scope, the registration officer needs to consider whether it is acceptable and to do that they may
FOI 25/26-2150
need to consult with an APS decision maker, Assistant director or even the business area with responsibility for the subject of the documents.
So the FOI guidelines at 3.89 provide context as to what constitutes reasonable searches, and I’d really encourage everyone to review this on a fairly regular basis because it’s incredibly important. It encourages us to take a flexible and common sense interpretation of the terms of the request and consider the normal business practices of the agency.
It also encourages us to consider the subject matter of the documents, current and past file management systems, including destruction and removal of documents.
Record and/or case management systems. Individuals with the age within the agency with knowledge of the subject of the request or the documents and the age of the documents. Now we need to consider these things so that we can determine if we have sufficient information to identify the documents in scope. So, with relation to the subject of the request, we need to think is it specific and is it searchable.
Of all the documents held by the NDAA, am I going to be able to find this document based on the scope that I have?
Does it give me enough information to understand what the person wants?
The other important thing I think is date Rangers are incredibly important because it enables us to limit searches to a period of time. So if you do not, if you receive a request that does not have a date range for me, that would be an immediate trigger to go back to the person and say what period of time are you looking at? 10 years is too long a period to be doing searches.
Ideally, we’d want to limit it to a 12-month or six-month period of time.
I’d also really encourage you to discuss the types of documents, sort or to look at a scope to identify the types of documents. Scott all documents is usually too broad unless you have a very specific scope.
FOI 25/26-2150
Rebecca So generally, anything with an old documents, I’d like no to be that that could result in thousands of hits.
Rebecca It’s also really important to consider the likely location of documents or records and scope of the request. So when might we actually need to search? Who’s going to have these documents? Is it going to be in pace? Is it going to be in CRM? Is it going to be in the CE OS office? Like where will we actually need to look?
Rebecca And if you don’t know where you’d look, then that’s gonna an indication that it’s too broad to do searches.
Rebecca So best practise if unsure about whether enough information you have enough information to undertake reasonable searches. I suggest that as a starting point you consult your decision maker, your assistant director, or seek advice from the responsible business area.
Rebecca Generally, if you don’t know what story, you don’t have enough information to make a decision, you need more information. So you need to think strategically about OK, I’ve got this request, it’s really broad. I’m not sure what they want. Not sure what they need. How can I make a decision on this, IE get more information.
Rebecca I’ll give you an example and this is actually a live case, so I’ve sorry I didn’t tell the case Officer. I was jumping on this one, but I’ve just included it, so please excuse me.
Rebecca The applicant has it’s non personal request and the applicant has referred to the more than 720 million investment in the NDIS capability capacity and systems developed with the NDIA board in consultation with the NDIS Review Co chairs, including ten initiatives and the person provided a media release with this.
Rebecca Us to reference and the request itself was can you please provide documents provided by the NDIA board and NDIA regarding the 720,000,000 investment and components thereof, documents provided by the NDIS review Co chairs regarding this and documents provided by any other party regarding the investment and components thereof. So what might you consider when assessing this scope?
Page 9 of 331
FOI 25/26-2150
Rebecca: Anyone jump in? Helen: There’s no date range, no date range. Rebecca: That’s. Yeah, there’s no date range. So I mean, this announcement was made in April last year, so we could infer a date range, but it would be pretty shaky. And I don’t know that it would be a great idea. So I think date range is, is is a good one for this one. Rebecca: So yeah, jump in, John. Megan: Also, sorry. Oh, I was just gonna say excessive amount of documents possibly. Rebecca: Yes, we’re not there yet though, so it is very broad in what the person is seeking because it doesn’t specify the documents. Rebecca: It doesn’t define what documents they’re after. It could be anything. It could be emails, correspondence, Skype messages or teams. Messages could be anything. So I’d be trying to get the person. Rebecca: To limit the scope to things like emails, plans, submissions, proposals, budget documents like something that’s we’re able to search for. Rebecca: Be able to identify where who would hold those documents within the agency and where we might search for them. Rebecca: Any other? Anyone else? Helen: Well, dot point freeze a little bit vague, I mean provided by any other party to who?
FOI 25/26-2150
0:18:52.170 –> 0:18:52.690 s47F - persona Helen Yeah.
0:18:50.440 –> 0:18:59.680 s47F - personal priv Rebecca Exactly, exactly. You’ve nailed it there. Provided to who documents provided by the NDIA board and Ndia to who?
0:19:0.760 –> 0:19:21.440 s47F - personal priv Rebecca We don’t know who it could be, anyone, so in this situation the Mediately release was issued by DSS and it also referenced cabinet. So we could, if we wanted to infer that they meant DSS or cabinet. But in this situation it would be a lot safer to check. And in fact that’s what we are doing. We’re writing back to this person and checking.
0:19:25.110 –> 0:19:27.550 s47F - personal priv Rebecca Is this specific or and searchable?
0:19:32.630 –> 0:19:37.190 s47F - personal priv Rebecca No, it refers to 10 new key initiatives. What are the initiatives?
0:19:38.920 –> 0:20:11.760 s47F - personal priv Rebecca It refers to the 720,000,000 investment you know that actually is actually 734,000,000 and it’s in the budget. But you know there’s a lot of inferring required for this one at the moment. So I think this is 1 where we would need to go back to the applicant and just confirm a few points. Now there’s two ways we can do it. We can do it as far as part of a formal practical refusal notice or in this situation we chose to do an informal consultation because the the issues can probably be sorted out fairly quickly by a phone call or an e-mail.
0:20:17.110 –> 0:20:21.30 s47F - personal priv Rebecca Now the other thing is too, who is likely to hold these documents?
0:20:22.310 –> 0:20:33.830 s47F - personal priv Rebecca Some of these documents would probably be a new policy proposal, which is a document that would be prepared by dsss DSS, so it is possible that we actually don’t have any documents in relation to this matter.
0:20:35.280 –> 0:20:49.560 s47F - personal priv Rebecca So this is 1 where we’d need to seek advice from areas with knowledge of the subject. Oh, sorry. And given that they have referenced the ndia board, you would probably reach out to board secretary or the CE OS office for information on this one.
Page 11 of 331
FOI 25/26-2150
Rebecca OK, moving onwards.
Another thing with practical refusal reasons is that, as per the FI guidelines, at 390 you should be able to explain the steps that were taken to search for the document, including the dates as to when the searches were conducted. So this means when you’re looking at scoping, you really always need to keep records of scope, consultations and searches and explain any practical refusal concerns in your in your practical refusal notice in a way that the applicant can understand.
And again, best practise is always to link back to the FY guidelines. In this case at 3.189 regarding reasonable searches. So you want to be providing evidence based decision records always, but also evidence based prns so people can understand and refer to the source material.
OK, so now we’re going to move on to the sort of, I think sometimes more complex pair practical refusal reason which is substantial and unreasonable diversion of resources.
So this one is specifically about the work effort that’s required to process a request, and whether that work effort would substantially and unreasonably divert the resources of the department from its other operations. Now this PRN or PR should be undertaken by the Action officer or decision maker. It is based. It must be based on an estimate of time required for search and retrieval, administrative tasks, consultation and decision making, and it may include advice from the responsible business area.
Again, it invites applicants to engage in a request consultation process and the applicant has 14 days to respond.
So things to consider when you’re calculating work effort and this is covered by the FI guidelines at 3116 to 3117.
So first of all, the time already spent or required for search and retrieval and you consider that in terms of hours and that might be an estimate provided by the business area or it might be the actual time that they did spend on search and retrieval.
FOI 25/26-2150
You would consider the time required to create a schedule of documents, and generally that would be a minute per document. You would consider the time required to convert documents into an editable format. For example, if you needed to convert emails to PDFs and you would usually do that in minutes, number of documents in scope, the number of average pages per document, the time required to assess each page, again in minutes, the time required to consult on each page, internal or external, and in minutes.
And the time required to write a decision letter.
Excuse me? You’d also consider.
The resourcing of the agency and the business area to undertake the FY task and a big consideration would be about how many staff they had on hand to be able to assist. For example, if a section only has one staff member, they’re not going to be able to provide as much support as a section that has 50 staff members.
You’d also consider the volume of other FOI or or π as that we have on hand and our ability to compete them to statutory time frames and service standards.
You would consider the location of the documents. Is it something that we can easily retrieve and process or is it something that we’re going to have to?
Lodge a request with a contractor and it’s going to take three weeks to get the document.
Classification of the documents. So who can actually retrieve and assess them?
Are these documents that are held in SharePoint? Are they documents that are in protected enclave or are they documents that are in trim so we need to know how sort of who can read them, but also who can get them for us.
FOI 25/26-2150
And also we need to consider forms of access. Now forms of access is covered by a section 21 I think or 20 or 21 of the FOI acts, and that’s where we need to consider the way that we provide in Note 20, the way that we provide information to people now, one of the options available is that someone can actually come on site to view a document. So we would need to consider that in it, calculating our work effort as that person would obviously need to be escorted and supervised during that period of time.
So the guidelines at 3.121 recommend sampling of 10 to 15% of documents and potentially in scope of the request to substantiate a practical refusal reason. And it’s a really important that you include the sampling in your practical recusal notice to explain your position.
Excuse me. So I’ve done a little example here. What sampling might look like, so I’ve got the documents in the left hand column. We’ve got the number of pages for each document in the middle column and the time that a talker person to read and assess them.
Summarised in the right hand column, you can say that we’ve ended up with a total of 40 pages and there’s an average of 8 pages per document, and it took 2.4 minutes per page to assess. Now we can use that information then to extrapolate an estimate of the work effort required to process the request.
So in this example, we’ve got 50 documents located and they’re an average length of five pages.
We’ve included the other tasks that are required to process the request, for example search and retrieval, scheduling conversion to an editable format, assessment time, consultation time and time to write the decision letter. So in this case, we’ve done the estimate of time required for each of these things. So with this one, we’ve done 50 documents at 5 pages per 3 minutes assessment time and also 50 documents per 5 pages at 2 minutes for a consultation time. Because the person’s reading over something we’ve already marked up.
And two hours to write the decision letter. So All in all, we end up with 17170 minutes divided by 60 minutes equals 29.5 hours. Processing time is our estimate for this one. So question is 29 1/2 hours a substantial and unreasonable diversion of resources.
Page 14 of 331
FOI 25/26-2150
Rebecca: What do we think? Megan: Yes. Jessie: Yes. Rebecca: Yes, Mystics. Why ain’t you going? What would it depend on? Misty: It would depend. It would depend on the work unit. Misty: The resources it would depend on the 29.5 hours. Misty: In that circumstance, as to whether or not it would substantially and unreasonably divert the resources or the work. Rebecca: Yes. Rebecca: Yep. Misty: It’s on a case by case basis. If you have a team of 100 people, for instance. Misty: Then 29 1/2 hours is probably no not going to be a substantial and unreasonable interference, but if you have a team of two. Misty: Then it probably will and.
FOI 25/26-2150
Rebecca: Yeah, OK, I think.
Rebecca: Sorry, I’m gonna say that’s actually a really good summary. Yeah, that covers the main points. So Part 2 is what information might you consider when making a decision?
Rebecca: Case law.
Rebecca: Yes.
Helen: So sorry, I went to some training last year and they made the point that in considering whether or not it’s a substantial and unreasonable diversion, you can also take into account the public interest in the material, and if it’s purely personal information.
Helen: That the AAT is.
Helen: Unlikely is more likely to find that it’s substantial and.
Helen: Unreasonable. They sort of draw a distinction between substantial and unreasonable, so it can be a substantial diversion of resources. But perhaps because this huge public interest in it is not an unreasonable diversion.
Rebecca: Oh.
Helen: So that’s something you could take into account too. The public interest in the material.
Rebecca: It’s an interesting.
FOI 25/26-2150
Rebecca: Idea, and one that I have stumbled across in sort of preparation for this training as well.
Rebecca: I’ve actually never seen anyone consider it in their practical reviews or notice argument, but it’s yeah, it’s interesting that that sort of popped up in the last little bit that that is also a relevant factor.
Rebecca: Yeah. So I think we’ll we’ll sort of put a pin in that one for a minute. But we might come back to it later.
Helen: OK. Thanks.
Rebecca: What I’d really like to talk about, though, is case law about substantial diversion of resources, and there was a fairly recent case involving Mr Farrell, who many of you may know is aabc journalist.
Rebecca: And he put in a request for 750 Australian victims of terrorism overseas payments and a practical refusal notice was issued based on estimates that it would take 61.25 hours of processing. So the tribunal agreed in the case law that the request met the substantial test. They found that it would take a substantial diversion of resources.
Rebecca: But that the size of services Australia’s staffing footprint meant that it was not unreasonable to process it.
Rebecca: So the learning from this is that we need to provide specific evidence and explain what work will have to be sacrificed by the agency to undertake a request. And this might be other FY access requests or frontline services.
Rebecca: We also have other case law about unreasonable division of resources. So in Tate and the director of the Australian War Memorial 2015, slightly older case an estimate of 150 hours to process a request of a 1003 pages was put in a practical refusal notice.
Rebecca:
— PAGE TEXT END –
FOI 25/26-2150
Now the AAT considered that the Australian War Memorial is a very small agency with one FOI staff member, so they accepted that assigning staff to assist would unreasonably divert resources from other operations or projects.
So again, the learning here is that whether a practical refusal reason exists will be a question of fact in the individual case, and agencies should not adopt A ceiling in relation to processing times. For example, 40 hours work effort which is a number that you may hear sort of around the traps in different FOI agencies.
You can also use the AGS charges calculator to calculate work effort, but I prefer myself to use just basically an Excel spreadsheet.
I’ve presented earlier in the training just with the documents.
Average pages assessment time and just sort of do it that way. I find a lot easier than the AGS charges calculator.
In terms of our case volumes, I’ve seen in my short time with FY and Ndia that there are a number of requests that sort of 1000 pages plus.
And I’d really encourage you when looking at those, to consider whether it is reasonable to process those requests.
And thinking about the number of cases that we have on hand.
Our competing priorities to our views and complaints and things.
And just generally the other sort of priorities of the agency and to consider really is it reasonable to process those extremely large requests. It may be a conversation that you can have with your decision
maker or your manager.
It might be that that you know is an opportunity to go back to the applicant and rescope the request.
0:33:1.770 –> 0:33:10.650 s47F - personal priv Rebecca It might be that the 1000 odd pages contains lots of duplicates, duplicates which we could potentially get the applicant’s agreement to exclude.
0:33:11.940 –> 0:33:29.540 s47F - personal priv Rebecca So I think I just want you to be aware of the range of options there are to refine scope. Prn is certainly one of them, but there’s also informal mechanisms that can also result in substantial benefits to the agency by reducing the number of pages that we have to review.
0:33:31.20 –> 0:33:42.100 s47F - personal priv Rebecca So please sort of think strategically when you’re getting these very, very large requests. Just saying, is this workable? What options do I have? And if you need to reach out and consult, please do so.
0:33:45.340 –> 0:34:11.420 s47F - personal priv Rebecca So the other option available to us with practical refusals that is actually grouping requests so the FOI guidelines at 3.121 state that in deciding whether a practical refusal reason exists 2 or more requests may be treated as a single request if the agency or Minister is satisfied that the requests relate to the same document or documents on the subject matter substantially the same for the requests.
0:34:12.230 –> 0:34:20.590 s47F - personal priv Rebecca This means that we can combine requests for a single from a single applicant, or multiple applicants seeking access to the same documents for practical refusal purposes.
0:34:21.990 –> 0:34:44.150 s47F - personal priv Rebecca And examples might include, say, an applicant 6, pages 1 to 500 and then 501 to 900 of a report that was previously PRN or PR practically refused on the basis that it was too large to process. So sometimes people try and split things up to try and get around a practical refusal. In that case, we just group them and still deal with them as a as a practical refusal.
0:34:44.640 –> 0:34:49.200 s47F - personal priv Rebecca Or if we get 30 applicants seeking access to the same 500 page document.
0:34:51.120 –> 0:35:1.360 s47F - personal priv Rebecca And that can be an example of that might be when you have a particular media issue that’s occurred and you get a flood of FOI access requests on the same topic.
Page 19 of 331FOI 25/26-2150
Rebecca
I had one year or so ago when s47F - personal privacy and I think we got 30 or 40 FOR requests, all seeking pretty much the same documents within a very short window of time. So we were able to group those requests and deal with them as one.
So essential information to include in a practical refresal notice a practical refutational notice must include the following information, advice of your intention to refuse the request. You must be quite open about what you are planning on doing. You need to give the grounds for the practical refusal, and that would be either that it is invalid or that is an erase. The substantial and unreasonable diversion of resources.
You must provide a statement explaining the practical refusal reason, including any calculations of work effort.
You need to invite the applicant to engage in a request consultation which is the salt. Really. The purpose of the practical refusal is to get them to engage with us.
You need to provide advice on what actions can be taken in response to the practical refusal notice, so generally that would be that the person can refine the scope of their request, they can withdraw their request or they can continue with the request in its current format. You need to provide a date for the person to respond and that is 14 days.
And you must provide the information that failure to respond will result in either a deemed withdrawal in a deemed withdrawal, unless the request is outside of statutory timeframes, in which case you need to remove that text because we have to refuse the request.
Now in term in in order for the practical refusal notice to be valid, you must provide your first name and a position number.
You can’t just put F away, officer. You have to have some way that it can be attributed to you as a delegate.
FOI 25/26-2150
Rebecca Now a practical refusal notice could include a suggested scope as a way of assisting the applicant to make a valid request, but you need to make sure it’s workable, and I’d always encourage you to seek assistant director approval of that first.
It’s a very, very bad form to suggest something to an applicant and then turn around say Oh no, but we can’t give that to you anyway or that. Well, that’s too big to process anyway.
So please consider that it’s also not entirely helpful to suggest a document to someone that you know is going to be exempt in full, because that is a poor customer service outcome. So we really need to try and make sure that we’re thinking strategically, trying to where we can anticipate and meet the needs of our applicants.
So stopping the clock clock, one of the the benefits of practical refusals is that you do get to stop the processing clock for the duration of your consultations with the applicant.
So this is covered in the SOP in the training manual SOP, so it’s pretty simple. Basically when you issue the practical refusal notice, you stop the clock and then when the person responds, you start the clock. Now if you need to go back to the person a couple of times, each time you go back and forth, you need to stop and restart the clock. So again, record keeping is going to be incredibly important here. The new statutory time frame is calculated by the standard processing time frame, which is 30 days.
Plus, any time that the clock was stopped and you just basically add it up and that gives you a new time frame. So here we’ve got 30 days plus 13 days equals 43 days. Very simple. You do need, as I say you do need records of that, especially if the person’s writing back to you multiple times a day, it can get a bit confusing.
Yes.
Rebecca, sorry. I just have a quick question about that stop clocking for.
FOI 25/26-2150
Rebecca Yes.
Misty The process.
Misty Does that? Is that also applicable when the matter is deemed?
Rebecca Good point, misty. Yeah. If a request is, if a request is already dangerous, fused the horse is bolted and you can’t. Actually, you don’t actually have a clock to stop at that point, unfortunately. So in that situation, no, you’d still want to keep records that the person who corresponded you would be on the topic, but once it’s deemed you don’t have a clock to stop.
Rebecca Does that make sense to everyone?
Rebecca Ideally, though, we should be doing our practical refusal notices during the statutory time frame.
Rebecca These things are best done when you front and load them and get them done early. You want to make sure that you get the additional time to process the request and that we’re dealing with our applicants as early as possible. OK, so I know that there’s a few around at the moment where we’re issuing practical reviews or notices for requests that are, you know, a couple of months old.
Rebecca It’s really not helpful. It’s poor customer service and it doesn’t actually help us to advance the request. You really lose sort of a lot of goodwill with the applicant and a lot of options if you’re doing practical refusal notices quite late in the process. Sometimes it’s not, it’s unavoidable, but ideally we want to be doing these parents. We want to be doing the scoping.
Rebecca At certainly for registration for validity concerns, but the practical refusal notice on unreasonable diversion of resources.
Rebecca
FOI 25/26-2150
Do you want to be issuing that as soon as you know that the work effort is going to be too great? So please consider. I guess the timing of requests and try and front and load the work where you can.
0:40:49.570 –> 0:41:17.890 s47F - personal priv Rebecca So request consultation must be a genuine attempt to resolve the practical refusal, reason concerns, so request consultation should occur as soon as possible, preferably within the statutory timeframes. It must consider the applicant, the applicant’s communication preferences and cultural needs, and it should always try to assist the applicant to make a valid request as per section 15 three and encourage the applicant to engage with the agency.
0:41:21.20 –> 0:41:52.60 s47F - personal priv Rebecca There’s four outcomes to potential outcomes, to a practical refusal notice. So the first outcome, as I mentioned before is that the applicant submits a revised scope and that’s really what we want at that point. The registrational case officer must rescope the request and advise the applicant if the practical refusal reason is resolved, if it is resolved, great, continue processing it, hopefully within statutory timeframes. If it’s not resolved, you need to double check your assessment and then move to a practical.
0:41:52.740 –> 0:41:53.500 s47F - personal priv Rebecca Refusal decision.
0:41:54.640 –> 0:42:25.440 s47F - personal priv Rebecca Now a practical refusal decision is pretty straightforward. Basically, I’ve got a sample that I’m happy to share with you, but basically you just state for the reasons outlined in the practical result. Notice I find that this part of the Act applies. I therefore refuse your decision. It’s really straightforward. It’s a very it’s like a one or two pager decision letter. Obviously, we need to provide review rights and we need to refer to section 23 and all those sorts of normal things that we do. But basically we’re relying substantially.
0:42:25.760 –> 0:42:30.480 s47F - personal priv Rebecca Practical refusal notice, as the explanation of why we’re making the decision.
0:42:32.710 –> 0:42:38.110 s47F - personal priv Rebecca The second parent outcome is that the applicant maintains the current scope of the request.
0:42:39.290 –> 0:42:47.250 s47F - personal priv Rebecca Now in that case again I would check your assessment. Just really make sure you’re on solid ground, but then I’d move to issue the practical refusal decision.
0:42:50.90 –> 0:42:54.130 s47F - personal priv Rebecca You’ve done your due diligence by going back to them. Once you do not need to go back to them again.
Page 23 of 331
FOI 25/26-2150
Rebecca:
The third option is that the applicant withdraws the request, great, finalise it as client withdrawn and this might be a situation where the person has been able to obtain the information in some other format or just doesn’t need it anymore.
Rebecca:
And the fourth option is that the applicant does not respond now if the.
Rebecca:
If the request is within statutory timeframes, you can actually finalise it as a deemed withdrawing request. Just close it down, move on if the request is outside the statutory time frame so it is impacted by 15 A/C.
Rebecca:
Which means we no longer have the ability to make a decision on it. So you must issue a practical formal, practical refusal decision.
Rebecca:
And that’s in line with the FOI guidelines, which require us to make a decision on deem refuse requests.
Rebecca:
Any questions about those four outcomes?
Megan:
Question.
Rebecca:
You jump in, Megan.
Megan:
So if the applicant doesn’t respond, do we still need to issue the formal PR refusal letter regardless? Yeah.
Megan:
OK.
Rebecca:
Yes, if they oh, no. If they don’t respond, you just close it down. It’s actually very simple.
FOI 25/26-2150
0:44:9.640 –> 0:44:10.600 s47F - personal privacy Megan Yep. Perfect.
0:44:10.520 –> 0:44:26.0 s47F - personal priv Rebecca The only time when you would issue the formal decision letter is if it was it was. It was deemed it was deemed like 15, I say deemed overdue like it’s overdue. You’d have to do it then.
0:44:28.770 –> 0:44:34.850 s47F - personal priv Rebecca I’m sorry, I have probably haven’t made that very clear. If it’s outside of statutory timeframes, you have to issue a decision.
0:44:37.780 –> 0:44:38.300 s47F - personal priv Rebecca Mm hmm. Peter.
0:44:51.840 –> 0:44:51.960 s47F - personal priv Rebecca Hmm.
0:44:40.780 –> 0:45:8.660 s47F - personal pri , Peter Thanks, beck. Can I just maybe jump into something you might address after this, but I just wanted to make the observation that requests can’t be part refused under practical refusal. It’s a it’s it’s sort of a a sensible thinking that you might take part of an applicant’s request and say this part is too large, unreasonable and we can’t process it. But if we can’t get an agreement through the consultation process to manage the request in that way.
0:45:10.100 –> 0:45:10.420 s47F - personal pri , Peter By the.
0:45:19.420 –> 0:45:19.620 s47F - personal priv Rebecca Mm hmm.
0:45:11.100 –> 0:45:42.660 O’Brien, Peter Letter of the law. We should be refusing the request in full unless we’re happy to provide documents administratively. So there’s case law on that that the IC review decision decided that they weren’t going to consider the claims of exemptions made on documents where an agency had issued a practical refusal notice purporting to apply to part of the request. They viewed that the refusal had the effect of refusing the entire request.
Page 25 of 331
FOI 25/26-2150
Rebecca: Hmm.
Peter: And then the documents that were released were subsequently released administratively and so there’s no review right for that information. I think the unfortunate consequence then would be that the person needs to FOI those documents that they’ve received in part and then they have review rights for those exemption clauses. So just to draw attention to that sort of nuance that we want to be as helpful as possible, but we need to be clear through the consultation process of what.
Peter: Limitations exist.
Peter: Because of the act and what we can achieve.
Rebecca: That’s a really good point. Thank you for that contribution, Peter.
Rebecca: I think I saw a couple of other hands up. Did anyone else have a question?
Rebecca: Maggie.
Rebecca: Yes, I can.
Maggie: Can you hear me? So I’m just doing the register. I have a question about that is if I thinking about the sequence right, once we receive the e-mail.
Rebecca: Yes.
Maggie: And it’s very common to see I want all information. Right now we’re talking about is in this sense is as a register officer will check with if I can work it out.
FOI 25/26-2150
Maggie: In this before I register, I should be able to talk to the DM how long this is going to take or is that clear enough?
Maggie: Does that sound right?
Rebecca: No, no it doesn’t. Sorry, just to explain. So the registration officers will really be dealing with the validity part of this. So is the request.
Rebecca: Specific enough to enable us to do reasonable searches, so that’s what the registration officers will really be focusing on.
Rebecca: In that situation, you need to look at the scope of the request.
Rebecca: You need to look for those terms like is it asking for all documents? Does it have a date range you know is it?
Rebecca: Sort of. The slides we had before about that we can revisit later.
Rebecca: That would be the registration officer in terms of the size and the work effort required to process the request.
Rebecca: That portion of the work would be done by decision makers and action officers.
Rebecca: So there’s, as I said, there’s two types of parents. One’s about validity. Great. That’s done by registration staff. The one about unreasonable diversion of resources that will be done by decision makers and action officers.
FOI 25/26-2150
Maggie Thank you. Rebecca Thanks. Rebecca All right, moving on, we’re almost done. Rebecca In terms of did you know that the agency is actually required to report data about its practical refusal outcomes to the Office of the Australian Information Commissioner each quarter and financial year? Rebecca Specifically, we have to report how many parents were issued by both personal and nonpersonal caseloads, and how many practical refusal requests were subsequently processed by each of those two categories as well, and that data is actually reported in your report. Rebecca And gets quite a bit of attention, actually. Rebecca It is essential that you accurately record all practical refrigeration processing actions in SharePoint and please also record the number of FOI pages that you release in relax for every request as that information informs our agency capacity to deal with practical refusal requests. So if we’re able to demonstrate that our average assessments pages is X amount, we can make an argument that we don’t have enough resource. Rebecca We don’t have capacity to process requests that are sort of, you know, 2000 pages. So we really need that data. So please as a habit start recording the FY pages that you release in Lex. Rebecca OK, now do we have any questions? Rebecca Before we move on.
FOI 25/26-2150
0:49:42.0 –> 0:49:44.960 s47F - persona Helen A couple of questions. Rebecca is Helen.
0:49:44.480 –> 0:49:46.200 s47F - personal priv Rebecca Yeah, go ahead. Go ahead.
0:49:46.360 –> 0:49:49.360 s47F - persona Helen I’ll put my camera on so you can see me.
0:49:48.640 –> 0:49:49.520 s47F - personal priv Rebecca Thank you.
0:49:54.400 –> 0:49:54.920 s47F - personal priv Rebecca Yes.
0:49:56.290 –> 0:49:56.810 s47F - personal priv Rebecca Yes.
0:49:50.760 –> 0:50:12.80 s47F - persona Helen So with section 6C, the third party contractors I was recently considering that in relation to a request for documents arising out of AAT litigation where we had instructed third party solicitors to act for us.
0:50:12.480 –> 0:50:13.880 s47F - personal priv Rebecca Yeah. Yep.
0:50:13.860 –> 0:50:34.300 s47F - persona Helen And I thought I made a decision that that wouldn’t be covered by section 6C because we’re not in instructing solicitors to represent us. We’re not actually engaging with a third party contractor to deliver services at the agency. Would that be your thinking as well?
0:50:35.570 –> 0:50:50.290 s47F - personal priv Rebecca Oh, it’s super interesting and I would be seeking advice from legal section about that, about the type of arrangement that is in place with those legal firms. I would suspect they would have a contract to the agency.
0:50:50.910 –> 0:50:51.470 s47F - persona Helen OK.
0:50:51.650 –> 0:50:57.90
redacted: s47F - personal priv Rebecca
To represent us. But you would that would be 1 where I would go to the responsible business area for
advice.
0:50:59.350 –> 0:50:59.550
redacted: s47F - personal priv Rebecca
Mm hmm.
0:50:57.660 –> 0:51:9.340
redacted: s47F - persona Helen
OK. Thank you. And the second question I had about keeping records of how many minutes it took you
to read a document or read pages?
0:51:10.560 –> 0:51:14.760
redacted: s47F - persona Helen
Can that be impacted by the complexity of the subject matter?
0:51:14.920 –> 0:51:17.880
redacted: s47F - personal priv Rebecca
100% yes. So.
0:51:16.520 –> 0:51:18.280
redacted: s47F - persona Helen
Yeah. OK. Thank you.
0:51:20.170 –> 0:51:30.650
redacted: s47F - personal priv Rebecca
I mean generally if it’s a sort of fairly standard request, I would generally use an an average of 3 minutes
per page. But.
0:51:32.210 –> 0:51:49.730
redacted: s47F - personal priv Rebecca
redacted: s47F - personal privacy
0:51:51.210 –> 0:52:2.730
redacted: s47F - personal priv Rebecca
redacted: s47F - personal privacy . So in those situations, we quite often had requests for really
complex documents which needed to be reviewed by a FOI case officer.
0:52:3.370 –> 0:52:17.290
redacted: s47F - personal priv Rebecca
But also an SCS band One and potentially also by someone else. So in those situations, instead of three
minutes per page, you might actually end up having 10 minutes per page when you consider the do the
sets of eyes who’ve looked at that document.
FOI 25/26-2150
So yes, again you will need to adjust to that figure based on the complexity, there’s two ways you can do it. You can do a sort of an average of how long you think each person might take, so 3 minutes plus 2 + 2 might be 7 minutes per page.
Or you can actually do an assessment of physical you can time yourself as to physically how long it takes you to do it, and then make adjustments for the other people who might not also need to look at that document. So yes, and also things like cabinet documents for example.
Would have a much higher threshold than someone seeking access to their own information.
Hmm.
Just, yeah.
Yes.
Yeah, I was recently looking at one with it was that that it was very technical subject matter and I actually had to Google terms to make sense of the document and yeah, yeah.
Yeah, but also make sure to factor in the time of the business areas because obviously if there are technical terms, we are not subject matter experts in everything that the Agency undertakes. So where we have to consult with those business areas to get their advice, definitely include that in your assessment time.
Thank.
Hmm. Did anyone else have any questions?
FOI 25/26-2150
Rebecca: All right. We will just move on. I do have a little quiz to finish off.
Rebecca: So first of all, how many types of practical refusal exist?
Rebecca: Anyone jump in?
Rebecca: Yes, thank you. There’s two. I was hoping everyone would get that two types, one on validity and one on substantial unreasonable diversion of resources.
Rebecca: True or false, the applicant has 30 days to respond to a practical refusal notice.
Misty: Both.
Jessie: House.
Megan: Both was 14.
Rebecca: False. Yeah, it is 14 days.
Rebecca: The the accident contain other provisions for 30 days, so charge notices are 30 days. EO TS extensions of time, especially 15AA EAT is the 30 days. There’s a few other things that are 30 days but this one is specifically 14.
Rebecca: True or false, the threshold of unreasonable work effort for a practical refusal is 40 hours.
FOI 25/26-2150
Misty Mouse.
Jessie House.
Rebecca That is false. It must be a case by case assessment.
Rebecca True or false sampling must be done for all section 24AA1B practical refusals.
Misty No false.
Misty I’m validating.
Helen At.
Rebecca False because 24AA1B relates to validity and you cannot sample validity.
Rebecca Five, can you issue a practical refusal notice once a request is overdue?
Misty Yes.
Jessie Yes.
Rebecca You can. Yes you can, but you cannot deem the request withdrawn if the applicant does not respond.
FOI 25/26-2150
Rebecca: Yeah, six an applicant doesn’t respond to Aprn. Can you deem withdrawn their request? Megan: Depending. Helen: Yes, it’s August. It’s within time, yeah. Jessie: Yes, if it’s if it’s. Jessie: Not over to you. Rebecca: Yeah, that’s right. OK. And trick question, how many practical refusal notices did ndia issue last financial year? Megan: Not many. Rebecca: Yeah. Rebecca: Anyone have a guess? Cooper: 42. Misty: 254. Cooper: 42.
FOI 25/26-2150
Rebecca 254 that’s very optimistic, misty. Anyone else?
Rebecca Was 52 so pretty close, so he issued 52 practical refusal notices and you subsequently processed 28.
Rebecca As a whole, the Australian government FOI agencies issued 2881 practical refusal notices last year and subsequently processed 895 requests. Now the facts that they issued around 2000 PRNS and then didn’t process them really indicates to me that they’re using practical refusal notices.
Rebecca To sort of resolve quite a few scoping issues.
Rebecca First point of contact, so I would really consider this as a very, very viable way for engaging with applicants and resolving concerns, OK.
Rebecca Also, getting rid of skypes that are just not workable.
Rebecca That is the end of the training session. I’m very happy to discuss PRN issues with anyone who has any further questions or has particular cases that they’re not sure about and they just sort of need a little bit of assistance with.
Rebecca And yeah, just generally happy to support in any way that I can during my time here.
Rebecca Peter, did you have any final statements or comments that you would like to make?
Rebecca Putting him on the spot.
Scope includes these considerations:
- the subject of the request – is it clear what service, policy, practice or issue the request is about?
- the parameters of the request - has the applicant specified the ‘who, what, where, when’ of the request2?
- the types of documents sought – has the applicant described the types of documents that they are interested in? General terms such as ‘all documents’ may be too broad to support reasonable searches unless the rest of the scope is very specific.
- the date range for the request – can searches be limited to a period of time? The Agency has more than 10 years of records; it is not possible to accurately search “all documents” during this period. Asking the applicant to provide a date range supports targeted searches and more efficient processing.
- where documents could be held – is there sufficient information to identify which business area ‘owns’ or ‘holds’ the document? Can you identify where the documents might be stored or where to seek information about the documents being sought? Could the agency produce a document under section 17 to meet the request?
Figure 1. Example of how to scope documents using key words
Scope: Emails between the Scheme Actuary and CEO between 1 January 2024 and 30 March 2024 about the production of the Disability Reform Ministers Council Quarterly Report.
| Doc # | Title / Description | Date of document | Number of attachments | Pages | Source | Scoping decision |
|---|---|---|---|---|---|---|
| 1 | Email from CEO to Scheme Actuary re DRMC Quarterly Report | 31/12/23 | 2 | 2 | OCEO | Not in scope – outside of date range |
| 1.1 | Attachment: Draft DRMC Report dated 30 December 2023 | 30/12/23 | 0 | 20 | OCEO | Not in scope – out of scope as attachment to document 1 |
| 1.2 | Email from OCEO to Office of the Scheme Actuary | 25/12/23 | 1 | 2 | OCEO | Not in scope – attachment to document 1 |
| 2 | Email from Scheme Actuary to CEO providing draft of DRMC Quarterly Report | 12/01/24 | 1 | 2 | Scheme Actuary | In scope |
| 2.1 | Attachment: Draft DRMC Report dated 30 December 2023 | 30/12/23 | 0 | 20 | OCEO | In scope as attachment to document 2. |
| 3 | Email from Deputy CEO Governance, Risk and Legal to CEO re DRMC Quarterly Report | 12/01/24 | 1 | 2 | Scheme Actuary | Not in scope – outside of parameters of request. |
| 3.1 | Attachment: Draft DRMC Report dated 30 December 2023 | 30/12/23 | 0 | 20 | Scheme Actuary | Not in scope – attachment to document 3. Duplicate of document 2.1 |
| 4. | Teams message from CEO to Scheme Actuary | 12/01/24 | 0 | 1 | OCEO | Not in scope – document type |
Page 37 of 331
FOI Training
Scoping information access requests
April 2024
What is scoping?
The ‘scope’ of a FOI access request is the wording used by the applicant to describe the documents they seek to access.
In FOI processing, the term ‘scoping’ is used to describe the acts of:
- interpreting the wording of an access request to understand what the applicant is seeking and to determine if the request is valid under section 15(2)(b), and/or
- determining whether any documents located during search and retrieval activities meet the scope of the request.
Scoping is an essential component of evidence-based FOI decision making as it determines how a FOI request will be processed.
FOI staff at each stage of processing are responsible for making sound, considered, and substantiated scoping decisions.
When to scope a request
Scoping occurs at two distinct points of an FOI access request:
- Triage and registration (T&R)
- Decision making
Before you start:
All FOI Officers must have a solid understanding of the FOI Guidelines [at 3.89 — 3.90] regarding conducting reasonable searches, as this informs the Agency’s interpretation of section 15(2)(b). See: Taking all reasonable steps to find documents in a freedom of information request | OAIC
Scoping access requests
Scoping a new access request is a vital step in FOI processing: if you can negotiate a good scope at point of registration, search and retrieval (S&R) activities will be easier and faster.
Scoping must be undertaken by T&R staff before a request is accepted as valid and registered. This is because the FOI ‘processing clock’ only starts when we receive a valid request that meets the requirements of section 15(2).
When scoping a request, T&R staff should consider whether the description of the document/s sought by the applicant is clear enough to enable reasonable searches to be conducted.
The Agency needs to not just be able to identify some documents in scope; it needs to be assured it can undertake reasonable searches to identify all documents in scope of a request.
Scoping access requests
Things to consider when scoping a new access request:
- The subject of the request — is it clear what service, policy, practice or issue the request is about?
- The parameters of the request — has the applicant specified the ‘who, what, where, when’ of the request?
- The types of documents sought — has the applicant confirmed the documents of interest? General terms such as “all documents may be too broad to support reasonable searches unless the rest of the scope is very specific.
- The date range of the request — can searches be limited to a period of time? It is not possible to accurately search all documents during the Agency’s 10 years of existence. Asking the applicant to provide a date range supports targeted searches.
- Where documents could be held — which business area ‘own’ or could ‘hold’ the documents sought by the applicant. Where might the documents might be stored? Where might you seek information about the existence of documents? Can the agency produce a document to meet the request? (under section 17).
Page 42 of 331 OFFICIAL
Consultation
If the scope of the request does not meet section 15(2)(b) requirements, T&R should contact the applicant as soon as possible to clarify the scope.
Things to remember:
- Consultation can be done informally (prior to registration) or as a section 24AB Practical Refusal Notice (PRN).
- You must keep records of any correspondence, phone calls and decision making around scoping, especially if the applicant agrees to modify the scope.
- If the applicant revises the scope, T&R must assess whether the new scope meets 15(2)(b). If the request is still not valid, discuss processing options with your Assistant Director.
- T&R may need to consult with business areas for advice as to whether it is possible to conduct reasonable searches. This advice can be used to inform a 24AB PRN.
Examples
Good scope:
Emails between the Scheme Actuary and CEO between 7 January 2024 and 30 March 2024 about the production of the Disability Reform Ministers Council Quarterly Report.
This is a valid and searchable scope because:
- the subject, parameters, types of documents sought, and date range of the request are clear
- the probable location of the documents (OCEO and/or Scheme Actuary) is indicated.
Conclusion: reasonable searches could be undertaken for documents in scope of the request.
Examples
Poor scope:
All documents about the Disability Reform Ministers Council Quarterly Report.
This is a poor scope because:
- the parameters and timeframes of the request are extremely broad; this request could capture any document produced by any person (internal or external to the Agency) about any aspect of the DRMC Quarterly Report over the life of the Agency.
- whilst documents would likely be held by OCEO and/or Scheme Actuary, the location of any other documents that might exist is not indicated.
- searches for all documents in scope could not reasonably be undertaken by officers of the Agency (i.e. not everything can be captured by a key word search of emails).
Conclusion: reasonable searches could not be undertaken for this request.
Things to remember:
-
Section 15(3) of the FOI Act states: ‘it is the duty of the agency to take reasonable steps to assist the person to make the request in a matter than complies [with section 15(2)]’. This means that you need to consider the applicant’s individual circumstances and communication needs when determining what is ‘reasonable’. In some circumstances, this may be one or two attempts; in other situations, the applicant may require more extensive support to make a valid request.
-
Timing is critical; the earlier you resolve a scoping issue the better the customer service and processing outcomes.
-
Any scoping modifications agreed by the applicant must be referenced in your decision letter.
Scoping documents
Decision Makers (DM) and Action Officers (AO) must carefully assess documents returned via S&R to ensure they meet the agreed scope.
It is the DMs responsibility to make sure that each document is assessed for relevance.
DM/AO should not assume that documents provided by business areas automatically meet the parameters of the scope.
DM/AO should always review the agreed scope to ensure it was correctly interpreted at T&R and that reasonable searches have been undertaken. In some cases, additional searches or enquiries may be required.
Scoping documents
Step 1: Prepare a schedule of documents that captures:
- the title or provides a brief description of the document
- the date of the document
- the number of attachments
- the number of pages in scope
- the source of the document (if documents were provided by more than one business area).
- which part of the scope the document meets (if the scope contains multiple parts).
Schedules are particularly helpful when a number of documents have been provided for assessment and/or the documents returned have attachments.
When labelling attachments, DM/AO should use a waterfall numbering style. E.g., Document 1, then Document 1.A, then Document 1.A.A onwards.
Page 48 of 331 OFFICIAL
Scoping documents
Step 2: Assess the documents against the scope for relevance
Emails between the Scheme Actuary and CEO between 1 January 2024 and 30 March 2024 about the production of the Disability Reform Ministers Council Quarterly Report.
In this case, there are 4 essential elements that must be met for the document to be in scope:
- Must be an email (or an attachment to an email).
- Must be between two defined parties (Scheme Actuary and CEO).
- Must fall within a specific date range. Attachments (including other emails) may fall outside of the date range but will be in scope if attached to the email.
- Must relate to the production of the DRMC Quarterly Report.
If any part of the scope is not met, the document should be excluded from assessment.
Scoping documents
Example:
Emails between the Scheme Actuary and CEO between 1 January 2024 and 30 March 2024 about the production of the Disability Reform Ministers Council Quarterly Report.
| Doc # | Title / Description | Date of document | Number of attachments | Pages | Source | Scoping decision |
|---|---|---|---|---|---|---|
| 1 | Email from CEO to Scheme Actuary re DRMC Quarterly Report | 31/12/23 | 2 | 2 | OCEO | Not in scope — outside of date range |
| 1.A | Attachment: Draft DRMC Report dated 30 December 2023 | 30/12/23 | 0 | 20 | OCEO | Not in scope — out of scope as attachment to document 1 |
| 1.B | Email from OCEO to Office of the Scheme Actuary | 25/12/23 | 1 | 2 | OCEO | Not in scope — out of scope as attachment to document 1 |
| 2 | Email from Scheme Actuary to CEO providing draft of DRMC Quarterly Report | 12/01/24 | 1 | 2 | Scheme Actuary | In scope |
| 2.A | Attachment: Draft DRMC Report dated 30 December 2023 | 30/12/23 | 0 | 20 | OCEO | In scope as attachment to document 2. |
| 3 | Email from Deputy CEO Governance, Risk and Legal to CEO re DRMC Quarterly Report | 12/01/24 | 1 | 2 | Scheme Actuary | Not in scope — outside of parameters of request. |
| 3.A | Attachment: Draft DRMC Report dated 30 December 2023 | 30/12/23 | 0 | 20 | Scheme Actuary | Not in scope — attachment to document 3. Duplicate of document 2.1 |
| 4 | Teams message from CEO to Scheme Actuary | 12/01/24 | 0 | 1 | OCEO | Not in scope — document type |
Duplicates and email trails
AOs should remove duplicates during scoping according to the following rules:
-
Documents must be exactly the same document to be considered a duplicate. Drafts or documents with a different date are not duplicates, but different versions.
-
Duplicates must be noted in the schedule of documents provided to the applicant. E.g.: if an identical report is provided as an attachment to multiple emails, it should be assessed the first time it appears and thereafter removed from the bundle and annotated in the schedule as “Removed as duplicate of Document X”.
Components of email trails can be removed as duplicates as long as the last email in the trail is included for assessment.
DM/AO must be mindful that emails trails can split; in these situations, you need to include the last email in each branch, even if it contains duplicate emails from another branch.
FO EBBIAIALSO
Questions
Page 52 of 331 OFFICIAL
15
Training video - Scoping FOI requests with Rececca
2024.04.10
Training video - Scoping FOI requests with Rececca [s47F - personal privacy] 2024.04.10.mp4
0:05 Good morning, everyone, and welcome to FOI training. Today we’re going to be discussing scoping Information access requests.
0:18 So what is scoping the scope of an FOI access request is the wording used by the applicant to describe the documents that they seek to access. In FOI processing, the term scoping is used to describe the acts of interpreting the wording of the access request to understand what the applicant is seeking and to determine if the request is valid under section 15 2B. And it is also the process of determining whether any documents located during search and retrieval activities meets the scope of the request.
0:50 Scoping is an essential component of evidence based FOI decision making as it determines how an FOI request will be processed. FOI staff at each stage of processing are responsible for making sound, considered and substantiated scoping decisions.
1:09 So when do you scope a request? Scoping occurs at 2 distinct points of an FOI access request, triage and registration and decision making.
1:19 Before you start. All FOIA officers must have a solid understanding of the FOIA guidelines at particularly at 3.89 and 3.90 regarding conducting reasonable searches as this informs the agencies interpretation of section 15 2B
1:36 I’ll just share my screen for a moment.
1:41 woop.
1:42 So, looking at section 3.89, it clearly says that agencies and ministers should undertake a reasonable search on a flexible and common sense interpretation of the terms of the request. That is the scope. What constitutes a reasonable search will depend on the circumstances of each request and will be influenced by the normal business practices in the agencies, operating environment or the minister’s office. At a minimum, the Agency or Minister should take comprehensive steps to locate documents, having regard to the subject matter of the documents,
— PAGE TEXT END –
FOI 25/26-2150
Current and Past File Management Systems and Practice of Destruction and Removal of Documents
Record Management Systems in Place
The record management systems in place, that is, where the documents of an agency are stored, the individuals within the agency or Ministers officer who may be able to assist with the location of documents and the age of the documents. 3.90 goes on to state that it may also be prudent for agencies and ministers to explain in its decision the steps that were taken to search for the document, including the dates as to when the searches were conducted, the search parameters used, the time taken to conduct the search, and whether any relevant backups were examined. It’s really important that we get used to including this information in our decision records as it does go a long way to explaining to the applicant what we have done and it quite often can materially address their any concerns they may have and possibly eliminate the need for internal review.
Scoping Access Requests
So scoping access requests is a vital step in FOI processing because if you can negotiate a good scope at the point of registration, search and retrieval activities will be easier and faster. Scoping must be undertaken by treating registration staff before a request is accepted as valid and registered. This is because the FOI processing clock only starts when we receive a valid request that meets the requirements of Section 15 2. When scoping request, TNR staff should consider whether the description of the documents sought by the applicant is clear enough to enable regional reasonable searches. As per 3.89 of the guidelines to be conducted, the agency needs to not just be able to identify some documents in scope, it needs to be assured it can reasonably or undertake reasonable searches to identify all documents and scope of the request.
Things to Consider When Scoping a New Access Request
So things to consider when scoping a new access request. First of all, obviously we consider the subject of the request. Is it clear what service, policy, practice or issue the request is about? We then look at the parameters of the request and this is where we get down into a little bit more detail. So in this situation, has the applicant specified The Who, what, where, when of the request?
We also look at the types of documents sort has the applicant confirmed the documents of interest? And my strong advice here is that general terms such as all documents may be too broad to support and reasonable searches unless the rest of the scope is very specific. Generally, I would not accept anything that says all documents.
Page 54 of 331
FOI 25/26-2150
5:24
so please be thoughtful about that because I do see that quite a lot in the current scopes.
5:30
I’d also encourage you to think about the date range of the request. Can searches be limited to a specific period of time? The agency has been around for 10 years now. It is not possible to accurately search all documents during this period of time. Asking the applicant to provide a date range can support targeted searches and enable a much better customer service outcome.
5:55
We also need to think about where documents could be held. So which business area owns or could hold the documents sought by the applicant? Where might the documents be stored? Which file management system? Where might you seek information about the existence of documents and can the agency produce a document to meet the request? Is it reasonable to assume that the document, if it’s data, is held in a system that can be produced under section 17 by the ordinary use of a computer system
6:26
consultation? So if the scope of the request does not meet section 15 2 B requirements in that it does not provide sufficient information to enable us to identify documents and scope,
6:39
Triage and registration should contact the applicant as soon as possible to clarify the scope. Now this can be done informally, usually by our phone call or an email, but it should happen prior to registration. Alternatively, we can do it as a Section 24AB practical Refusal notice, although my strong advice would be that this is done as a second resort. Generally you will get a much better outcome if you contact the applicant informally. You must keep records of any correspondence, phone calls and decision making around
7:11
scoping, especially if the applicant agrees to modify the scope. If you call someone to discuss the scope, just write a quick file. Note can just be a Word document with the date, the time, the matters discussed. It can be in bullet points, but you must have a record of that conversation and what was agreed. Best practise is to also send an email to the applicant after that phone call, confirming the details of that conversation so that they have a record and you have a record
7:41
if the applicant revises a scope. Triage and registration must then reassess whether the new scope meets 15 2B. If the request is still not valid, you should discuss processing options with your Assistant director and that may be moving to a practical, formal, practical refusal process, or considering whether we offer a scope to them, something that we think will work, we could provide a suggested scope. It’s really important that Triage & registration staff consult with business areas
8:13
for us as to whether it’s possible to conduct reasonable searches. Again this can be by phone call or email but you need to have a record of those conversations and that advice can then be used to inform and Section 24AB Practical Refusal Notice.
Page 55 of 331
FOI 25/26-2150
8:32 So I’ve got an example here of what I consider to be a good scope. It is emails between the scheme actuary and CEO between 1 January 2024 and 30 March 2024 about the production of the Disability Reform Ministers Council quarterly report. Now this is a valid and searchable scope because the subject, parameters, types of document, sort and date range of the request are clear. It also the probable location of the document i.e that they’ll be held by the office of the CEO and or the scheme
9:05 right is also indicated. So the conclusion is that reasonable searches could be undertaken for documents in search of this request.
9:14 On the other hand, a poor scope would be all documents about the Disability Reform Ministers Council quarterly report. And this is a poor scope because the parameters and time frames of the request are extremely broad. This request could capture any document produced by any person, whether internal or external to the agency, about any aspect of the DRMC quarterly report over the life of the agency.
9:40 So whilst documents would likely be held by the OCEO or scheme actuary, the location of any other documents that might exist is not indicated
9:49 and so searches for all documents in scope could not reasonably be undertaken by officers of the agency. And in particular it’s important to realise that not everything can be captured by a keyword search of emails. We have lots of other documents management systems such as TRIM or PDMS, and keyword searches will not identify documents in those systems.
10:12 So the conclusion on this one is that reasonable searches could not be undertaken by this request.
10:19 So things to remember.
10:21 Section 15 three of the FOI states that it is the duty of the agency to take reasonable steps to assist the person to make the request in a manner that matter that complies with section 15 Two. This means that you need to consider the applicants individual circumstances and communication needs when determining what is reasonable. In some circumstances this may be one or two attempts. In other situations, the applicant may require more extensive support to manage to make a valid request.
10:54 Timing is critical. The earlier you resolve a scoping issue, the better. The customer service and processing outcomes
Page 56 of 331
FOI 25/26-2150
Scoping documents.
Decision makers and action officers must carefully assess documents returned via search and retrieval to ensure they meet the agreed scope. It is the decision maker’s responsibility to make sure that each document is assessed for relevance. Decision makers and action officers should not assume that documents provided by business areas automatically meet the parameters of the scope. In many situations, business areas will be overly generous in what they provide. Or they may provide documents that contain documents that are not relevant. So you really do need to go through it and make sure that everyone matches the scope.
Decision makers and action officers should always review the agreed scope to ensure it was correctly interpreted at triage and registration and that reasonable searches have been undertaken. In some cases, additional searches or inquiries may be required.
So how do we actually scope the documents? So step one is to prepare a schedule of documents that captures the title or provides a brief description of the document, the date of the document, the number of attachments, the number of pages in scope, the source of the document so where you got it from and which part of the documents and which part of the scope the document meets.
Especially if the scope contains multiple parts. Schedules are particularly helpful when a number of documents have been provided for assessment and/or the documents returned have attachments. When labelling attachments, the DM or action officer should use a waterfall style numbering. So document one and then the attachment to that would be document 1A but an attachment to 1A would be document one, point A onwards and it doesn’t matter to my purpose. It doesn’t matter if you use letters or numbers, whatever is the agreed process for the agency.
So considering this scope that we have on that we’ve discussed before (this good scope), so you then assess the documents against the scope for relevance. So you can see that I’ve gone through and colour-coded the different elements of the scope that need to be met. In this case, there are four essential elements that must be met: it must be an email or an attachment to an email; it must be between two defined parties, in this case the schematic tree and the CEO; it must fall within a specific date range; attachments, including other emails.
Page 57 of 331
FOI 25/26-2150
13:41 may fall outside of the date range, but will it be in scope if they’re attached to an email which is within the date range
13:47 and it must relate to the production of the DRMC quarterly reports? And per 3.89 of the FOI guidelines, I would take an ordinary interpretation of the word production. So the process of bringing something into existence or being would be generally what you could be looking for. So anything to do with making the DRMC quarterly report. If any part of the scope is not met, the documents should be excluded from assessment.
14:16 This is an example of how you might record a scoping decision. So you can see in the left hand column I have the number of the documents and I’ve used that waterfall star so 1 1A 1B 2 2A 3 3A 4 and put in a title or description of the documents. So in this situation for #1 we have an email from the CEO to Scheme actually regarding the quarterly report.
14:42 We have the date of the document, the number of attachments, number of pages, the source and a scoping decision. Now in this situation I have found that the document is not in scope because it is outside of the date range of the request. You can see 1 January 2024, 30 March, this is 31st of December 23, therefore out of scope. The second document is automatically out of scope because it is an attachment to the first document. Same with the 1B as well. Looking then at document 2
15:14 we have an email from the scheme actuary to the CEO providing a draft of the quarterly report. We have a date of 12th of January 24 which is within the date range. We have one attachment 2 pages scheme actuaries. The source this document would be in scope.
15:34 We then have the attachment which is the draft DMC report itself. You can see that it is exactly the same attachment as document 1A which was out of scope, but document 2A will be in scope because it is. It is attached to a document that is in scope.
15:53 We then have an email from at #3. We have an email from the Deputy CEO of Governance, Risk and Legal, so Debbie redacted to the CEO about the DRMC quarterly report. The date range is in scope. The attachments is exactly the same as the document to A. However, this document will be out of scope because it is outside of the parameters of the request. It is not between the scheme actuary and the CEO. As such, three at three and three A are both out of scope. The final document is a document four and this is a Teams message from the CEO to the scheme actuary.
16:26 We can see that it as it is at times that message it is out of scope because it is not an email.
16:37 The next thing I wanted to talk about was duplicates and email trails,
Page 58 of 331
FOI 25/26-2150
and this is incredibly port important for a number of reasons.
First of all, we need to make sure that we are not providing unnecessary documents to applicants we need to be very mindful about in terms of customer service outcomes,
there is no point providing large numbers of irrelevant documents to our applicants. We need to be
very considered in what we apply and giving them every single email in an email trial which is then repeated multiple times just means that you’re going to end up with a very large document bundle of documents that are highly irrelevant to the applicant. And it can actually make their experience, their FOI experience, worse if they have to wade through thousands of pages to get to one or two relevant emails.
So AO should remove duplicates during scoping according to the following rules. Documents must be
exactly the same to be considered a duplicate. Drafts or documents with a different date are not duplicates, but rather different versions. Duplicates must be noted in the schedule of documents provided to the applicant. For an example, if an identical report is provided as an attachment to multiple emails, it should be assessed the first time it appears and thereafter removed from the bundle and annotated in the schedule as removed as a duplicate
18:01
of document X.
That way the applicant knows that there was a document, but it is the same as the one they’ve already
been given or has already been exempt. Components of email trials can be removed as duplicates as long as the last email in the trial is included for assessment. So as I said, you don’t need to include every single email along the path and the trail of each version. You can just include the last one or just assess the last one as long as you have the complete history. But decision makers and AOs must be mindful that
18:36
email trails can split and these situations. You need to include the last email in each branch of the e-mail trail, even if it contains duplicate emails from another branch. Unfortunately, sometimes we can’t avoid it, but we do need to capture a complete history of each of those branches
18:57
and that is the end of the presentation. Does anyone have any questions?
19:06
I do Bec. It’s Helen here. Helen, hi. I’m just going back to the commissioner’s guidelines on 3.90.
19:18
When I talk about it being prudent for agencies to explain the decision, this of in their decision the steps that were taken to search. What do you think it means? Where it says I’m the search parameters used, the time taken to conduct the search and were there any relevant backups for examined? What
FOI 25/26-2150
are the relevant backups? So I think the relevant backups would relate to digital files. So that might be data storage. It might be, for example, in some
situations you might have an audio recording of an interview. So it might be that you’re not just looking at a transcript, but you’re also looking at a digital file. So I think you need to just sort of think a little bit broader sometimes with the decision making and just sort of think, OK, am I just looking at the very, very specific thing that is initially you know which you might be a transcript or am I looking at other things as well such as the digital backups?
OK. Thank you. No worries. Did anyone else have any questions?
I had more of a comment, if that’s alright. Just something we can discuss a bit further. And one thing I’ve noticed is sometimes when we do UM search consults with business areas, they search the documents they hold just by doing keyword searches and they can sort of over deliver on the documents that they give us. And just because the business area has returned those documents, it doesn’t actually mean that they’re in scope. And so it’s sort of still requires that the decision maker actually reads them, understands them, and actually looks at the subject matter.
Um. And in particular, um, is the document as a whole about that subject matter, or is there just a tiny reference to the end that says? By the way, here’s a link. Please see this other document For more information.
So I just wanted to kind of bring that up and, you know, see if anyone else had any examples where, um, documents returned by the business area really aren’t in scope. They just happen to use a keyword in a very minor sense,
yeah. I actually have an example of that yesterday with a request from ministerial and parliamentary where they had conducted searches of PDMS using keyword searches, 3 keyword searches, and which had returned an enormous number of hits. I think it was. We had one package of about 700 pages and another of about 300 pages, but in fact none of the documents are in scope because that additional parameters had not been considered. So it is incredibly important not to accept at face value what you get back from
business areas. You need to very independently and methodically go through them and assess them. And I would encourage you to consider and remove duplicates as you’re doing your scheduling. It makes it a lot easier.
Does anyone else have an example of where they’ve had large number of returns that have needed to be carefully scoped?
FOI 25/26-2150
22:18 I’ll definitely, um, I had the same experience as you with. We received 970 pages of documents from the min PAL space based on a PDMS search
22:29 and going through them. Not a single one of them was in scope, except for one that had already been published on the disclosure log, and that was literally just because they used a keyword. And for those who aren’t aware, on PDMS
22:42 you get multiple documents bundled up together in a single matter, such as emails and drafts and attachments. And if a keyword appears somewhere in one of those documents, the whole bundle of documents gets produced
22:53 as a hit.
22:56 Yeah, returning back to the issue of duplicates and email trail, I think that is particularly important in the personal information space where we know that documents are very often repeated. So I’d really encourage you to consider that especially some of them can be run to a number of 100, if not 1000 pages. I’d be very, very carefully looking at what you can remove. It’s really important to remember that some of our applicants have obviously
23:29 different accessibility needs and being provided with such a large document package of, you know, material that is repeated over and over again is not helpful and can make can result in a really sort of poor customer experience. So we need to be thinking about how we can assist our customers, our sorry applicants by providing really sort of concise and targeted information which meets their needs and is what they want but isn’t repeated sort of ad nauseam. Elizabeth, I can see you have a question.
24:00 Yeah. Um, uh, yeah. Just following on from what um Peter just put in the chat actually and and this does come up often, it came up in your presentation as well. So those situations where all documents are requested, it seems to me that there’s no way of avoiding a conversation with somebody and and really that that kind of scope will that kind of initial request, it really means that they they’re not really sure what they’re looking for when they are wanting to get
24:34 something. So we really do need to come to like go to them directly and just say, well, can you tell us a bit more, Um, yeah. What do you what what would satisfy you in terms of what kind of information are you seeking? Um. And So what would be your suggestions? I suppose could could we could we pull together some resources. So that was very easy for the triage and registration group
25:00 and even further decision makers as well I suppose.
Page 61 of 331
FOI 25/26-2150
25:04
Yeah look I think in in that situation the first thing you would do is pick up the phone and call the person and sort of you know really inquire about the the reasoning behind their request. Because whilst we’re not allowed to think about the reason for someones FOI requests for the purposes of the act, it is actually sometimes a really helpful to understand what they’re actually looking for so that you can target searches and and really help to eliminate the sort of large documents of irrelevant you know nature. So I would definitely encourage you to be quite comfortable to call applicants and have
25:37
those conversations. It’s sometimes helpful to sort of tell them if you have a quick views of how many documents have been found. So if you can say, oh look, I’ve got 1100 pages of material, do you need it all or could we look sort of for a more targeted document and that by might be enough to help them. There’s no harm in that. In telling them that, you know, we’ve got a large number of documents. Don’t tell them what the documents are necessarily, but you, you know, telling them that we’ve got the volume is is not problematic in most cases. If you’re not
26:10
store about a scope, you can always take advice either from a member of your team or your assistant director or director. I’m very, very big on case consultations. I think it’s a really effective way to solve roadblocks and to move cases forward. So I think if ever you’re unsure, you should definitely reach out and seek that support.
26:31
Yeah,
26:33
I would, could I just go on just to say it would be great to perhaps have some training then if if it’s a little new on the horizon for some members of the team, particularly new ones in how to craft those sorts of discussions, maybe that’s something that a few people would be interested in. I’d be happy to be part of it. I mean, I come from a planning background so I’m comfortable with reaching out to applicants, but but there is a probably
27:06
a certain set of skills that you need. You need to be aware of what what’s OK to say what’s not OK, all those sorts of things. And and I suppose if we just make it really clear for everyone in the team how you wanted this sort of thing to be conducted and then I think that that will just mean that everyone rolls out and and does it well.
27:30
Yeah, I agree. I definitely agree. I think that’s a really good idea and would be very helpful for the team.
27:36
OK, we have another question from Conti
27:40
I hope I pronounced that correctly. Would you like to go ahead.
Page 62 of 331
FOI 25/26-2150
27:43
Thanks Rebecca. That’s great. It’s part of my question has already been answered, but it’s just more so now. A comment based on the duplicate because I had a scenario with a with an applicant who is a nominee and they wanted everything and I had that phone conversation that you know went longer than I initially planned. But Long story short, she just wanted a full file and didn’t care how long it took. Um, because I said that if we it took too long she might lose her right for internal review and all of that stuff.
28:16
That her perspective was that she wanted a copy of what we held and there seems to be a confusion in terms of what she’s uploading and what she can see is accessible through the portal. And I had some duplicates as well of parts of the forms being incomplete and then her being told can you provide a completed one? But she just basically wanted everything. She didn’t care how it was presented. Unfortunately, sometimes you’re not going to be able to avoid it and as you know, the applicant has a right to that information,
28:49
have the right to request everything. From a processing point of view, it becomes problematic in terms of our time management and our resourcing and how much you know how long it takes to do decisions. And I’m sure you’re aware that you know processing your request that is 1000 on pages is going to take a good chunk of time. I’d just like to really reinforce that you have to read every page. You cannot assume that a document is safe to be released just because it is something the applicant has provided us. You need to read every page and that
29:22
and add. A lot of time we approach reading the whole page, but that’s perfect. Yeah, I’m sorry, I mean, sometimes obviously, um, you have to read things more deeply than others. Um, but you need to at least have eyes on every page. And that is why your schedule becomes incredibly important because you can list out the documents and scope, you can note what they are and that you’ve checked it and have a record. And sorry, that’s one thing I should should have mentioned to your schedule of documents is actually a bit of a
29:55
progressive document, because once you’ve done the scheduling, you can add a column and you can use that for your assessment of whether a document is in scope. Sorry whether a document has exemptions and can be released. So you actually it’s a progressive document in terms of processing.
30:12
You can also for those of you who are doing non personal requests, you can also then use that schedule to inform charges. If indeed you guys ever decide to do start doing charging, that can also be used for that in that way too. So it is actually a really incredibly valued valuable document. And if you go back to 3.90, which says that we must,
30:34
you know, retain records about scoping decisions, I think schedules are just the best way to go. You can do it in Word, you can use do it in Excel, and it might be worth putting together perhaps a template for the team that everyone’s using the same type of scoping document. And that’s
— PAGE TEXT END –
something that then gets automatically saved into SharePoint and becomes part of the process. But I cannot stress how important it is to have accurate records,
31:00 especially if cases go to external review and we have to justify why we made certain decisions. It’s really good to be able to say, well, On this date I did this and this is what I found. It really, really helps.
31:16 Did anyone else have any questions before we wrap up today?
31:23 No, If not, you’re welcome to reach out to me if you have any particular scopes that you’d like to discuss. Anything that’s complicated. Just a reminder that a lot of our 90 day plus cases have been held up by scoping issues, so it is incredibly important to get those right at the front, preferably at triage and registration, but if not, we need to catch them at decision making. So thank you very much for everyone attending. I have also put together a scoping health card which will be circulated in the next couple of days, which runs through the slides
31:56 that we’ve just been through and answers any questions and again gives examples of what’s a good schedule might look like. So thank you very much for your time.
32:05 Thank you, Rebecca.
FOI 25/26-2150
DOCUMENT 5
0:0:0.0 –> 0:0:7.560 s47F - personal priva Rebecca Good morning, everyone, and welcome to FI training. Today, we’re going to be discussing scoping information access requests.
0:0:12.760 –> 0:0:42.760 s47F - personal priva Rebecca So what is scarping the scope of an FOI access request is the wording used by the applicant to describe the documents that they seek to access an FOI processing. The term scoping is used to describe the acts of interpreting the wording of the access request to understand what the applicant is seeking and to determine if the request is valid under section 15, two B. And it is also the process of determining whether any documents located during search and retrieval activities.
0:0:42.960 –> 0:1:0.680 s47F - personal priva Rebecca Meets the scarp of the request. Scoping is an essential component of evidence based FY decision making as it determines how an FOI request will be processed. Foi staff at each stage of processing are responsible for making sound considered and substantiated scroping decisions.
0:1:4.210 –> 0:1:6.90 s47F - personal priva Rebecca So when do you scope a request?
0:1:7.330 –> 0:1:29.370 s47F - personal priva Rebecca Scoping occurs AT2 distinct points of an FOI access request, triage and registration and at decision making before you start, all FOI officers must have a solid understanding of the FOI guidelines at particularly at 3.89 and 3.90, regarding conducting reasonable searches, as this informs the agency’s interpretation of section 15 two B.
0:1:31.210 –> 0:1:33.370 s47F - personal priva Rebecca Will just share my screen for a moment.
0:1:37.520 –> 0:2:7.960 s47F - personal priva Rebecca So looking at section 3.89, it clearly says that agencies and ministers should undertake a reasonable search on a flexible and common sense interpretation of the terms of the request. That is, the scope. What constitutes a reasonable search will depend on the circumstances of each request and will be influenced by the normal business practises in the agencies operating
FOI 25/26-2150
environment or the Minister’s office. At a minimum, the agency or Minister should take comprehensive steps to locate documents.
Rebecca: Having regard to the subject matter of the documents, the current and past file management systems and practice of destruction and removal of documents, the record management systems in place, that is where the documents of an agency are stored, the individuals within the agency or Minister’s office who may be able to assist with the location of documents and the age of the documents, 3.90 goes on to stage that it may also be prudent for agencies and ministers to explain in its decision.
Rebecca: The steps that were taken to search for the document, including the dates as to when.
Rebecca: Researchers conducted the search parameters used, the time taken to conduct the search, and whether any relevant backups were examined. It’s really important that we get used to, including sorry that we get used to including this information in our decision records as it does go a long way to explaining to the applicant what we have done and it quite often can materially address the any concerns they may have and possibly eliminate the need for internal review.
Rebecca: So it looks gives me only return to this.
Rebecca: So scoping access requests, scoping a new access request is a vital step in FYI processing, because if you can negotiate a good scope at the point of registration, search and retrieval activities will be easier and faster. Scoping must be undertaken by triage or registration staff before a request is accepted as valid and registered. This is because the FY processing clock only starts when we receive a valid request that meets the requirements of section 15 two.
Rebecca: When scoping a request, TNR staff should consider whether the description of the documents sought by the applicant is clear enough to enable reason. Reasonable searches, as per 3.89 of the guidelines to be conducted, the agency needs to not just be able to identify some
FOI 25/26-2150
documents in scope, it needs to be assured it can reasonably or undertake reasonable searches to identify all documents in scope of the request.
0:4:30.800 –> 0:4:54.600 s47F - personal priva Rebecca So things to consider when scoping a new access request. First of all, obviously we consider the subject of the request. Is it clear what service policy practise or issue the request is about? We then look at the parameters of the request and this is where we get down into a little bit more detail. So in this situation, has the applicant specified The Who, what, where, when of the request?
0:4:55.720 –> 0:5:1.720 s47F - personal priva Rebecca We also look at the types of documents sort has the applicant confirmed the documents of interest?
0:5:2.220 –> 0:5:17.740 s47F - personal priva Rebecca And my strong advice here is that general terms such as all documents may be too broad, just important, reasonable searches, unless the rest of the scope is very specific. Generally I would not accept anything that says all documents.
0:5:19.40 –> 0:5:23.520 s47F - personal priva Rebecca So please be thoughtful about that, because I do see that quite a lot in the current scopes.
0:5:24.910 –> 0:5:48.390 s47F - personal priva Rebecca I’d also encourage you to think about the date range of the request. Can searchers be limited to a specific period of time the agency has been around for 10 years now? It is not possible to accurately search all documents during this period of time. Asking the applicant to provide a date range can support targeted searches and enable a much better customer service outcome.
0:5:49.750 –> 0:5:56.710 s47F - personal priva Rebecca We also need to think about where documents could be held, so which business area owns or could hold the documents sought by the applicant.
0:5:57.130 –> 0:6:0.450 s47F - personal priva Rebecca Where might the documents be stored? Which file management system?
Page 67 of 331
FOI 25/26-2150
Rebecca Where might you seek information about the existence of documents? And can the agency produce a document to meet the request? Is it reasonable to assume that the document, if its data is held in a system that can be produced under section 17 by the ordinary use of a computer system?
Rebecca Consultation. So if the scope of the request does not meet section 15, two B requirements in that it does not provide sufficient information for to enable us to identify documents in scope.
Rebecca Triage and registration should contact the applicant as soon as possible to clarify the scope. Now this can be done informally, usually by our phone call or an e-mail, but it should happen prior to registration. Alternatively, we can do it as a section 24 AB practical refusal notice.
Rebecca Although my strong advice would be that this is done as a second resort, generally you will get a much better outcome if you contact the applicant informally.
Rebecca You must keep records of any correspondence, phone calls and decision making around scoping, especially if the applicant agrees to modify the scope. If you call someone to discuss a scope, just write a quick file. Note can just be a Word document with the date, the time, the matters discussed. It can be in bullet points, but you must have a record of that conversation and what was agreed.
Rebecca Best practise is to also.
Rebecca Send an e-mail to the applicant after that phone call confirming the details of that conversation so that they have a record and you have a record.
Rebecca
FOI 25/26-2150
If the applicant revises the scope, trash registration must then reassess whether the new scope meets fifteen 2B. If the request is still not valid, you should discuss processing options with your assistant director, and that may be moving to a practice a formal, practical refusal process, or considering whether we offer a scope to them, something that we think will work. We could provide a suggested scope.
0:8:3.520 –> 0:8:6.640 s47F - personal priva Rebecca It’s really important that triage and registration start.
0:8:7.0 –> 0:8:24.160 s47F - personal priva Rebecca Consult with business areas from Vice as to whether it’s possible to conduct reasonable searches. Again, this can be by phone call or e-mail, but you need to have a record of those conversations, and that advice can then be used to inform a section 24 AB practical refusal notice.
0:8:27.240 –> 0:8:57.200 s47F - personal priva Rebecca So I’ve got an example here of what I consider to be a good scope. It is emails between the scheme, actuary and CEO between one January 2024 and 30 March 2024 about the production of the disability Reform Minister’s Council quarterly report. Now this is a valid and searchable scope because the subject parameters, types of documents, sort and date range of the request are clear. It also the probable location of the document, IE that they will be held by.
0:8:57.560 –> 0:9:7.760 s47F - personal priva Rebecca The Office of the CEO and or the scheme actually is also indicated, so the conclusion is that reasonable searches could be undertaken for documents in search of this request.
0:9:9.280 –> 0:9:33.480 s47F - personal priva Rebecca On the other hand, a poor scope would be all documents about the disability Reform Minister’s Council quarterly report, and this is a poor scope because the parameters and time frames of the request are extremely broad. This request could capture any document produced by any person, whether internal or external, to the agency about any aspect of the Drmc quarterly report over the life of the agency.
0:9:34.650 –> 0:9:42.770 s47F - personal priva Rebecca
FOI 25/26-2150
So whilst documents would likely be held by the O CEO or scheme, actually the location of any other documents that might exist is not indicated.
0:9:44.90 –> 0:10:4.810 s47F - personal priva Rebecca And so searches for all documents in scope. Could not reasonably be undertaken by officers of the agency, and in particular it’s important to realise that not everything can be captured by a keyword search of emails. We have lots of other documents management systems such as trim or PDMS, and keywords such as will not identify documents in those systems.
0:10:7.170 –> 0:10:12.530 s47F - personal priva Rebecca So the conclusion on this one is that reasonable searches could not be undertaken by this request.
0:10:14.450 –> 0:10:15.730 s47F - personal priva Rebecca So things to remember.
0:10:17.170 –> 0:10:45.570 s47F - personal priva Rebecca Section 15. Three of the FY states that it is the duty of the agency to take reasonable steps to assist the person to make the request in a matter that matter, that complies with section 15. Two, this means that you need to consider the applicant’s individual circumstances and communication needs when determining what is reasonable in some circumstances, this may be one or two attempts. In other situations, the applicant may require more extensive support to manage.
0:10:45.910 –> 0:10:46.990 s47F - personal priva Rebecca Valid request.
0:10:49.0 –> 0:10:56.440 s47F - personal priva Rebecca Timing is critical. The earlier you resolve a scoping issue, the better the customer service and processing outcomes.
0:10:57.780 –> 0:11:3.460 s47F - personal priva Rebecca And any scoping modifications agreed by the applicant must be referenced in your decision letter.
Page 70 of 331
FOI 25/26-2150
Rebecca
Scoping documents.
Decision makers and action officers must carefully assess documents returned via search and retrieval to ensure they meet the agreed scope. It is the decision makers responsibility to make sure that each document is assessed for relevance.
Decision makers and action officers should not assume that documents provided by business areas automatically meet the parameters of the scope. In many situations, business areas will be overly generous in what they provide, or they may provide documents.
That contain documents that are not relevant, so you really do need to go through and make sure that everyone matches the scope.
Decision makers and action officers should always review the agreed scope to ensure it was correctly interpreted at triage registration, and that reasonable searches have been undertaken. In some cases, additional searches or enquiries may be required.
So how do we actually scope the documents?
So step one is to prepare a schedule of documents that captures the title or provides a brief description of the document, the date of the document, the number of attachments, the number of pages in scope, the source of the document, so where you got it from and which part of the documents and which part of the scope the document needs, especially if the scope contains multiple parts. Schedules are particularly helpful when a number of documents have been provided for assessment.
Or the documents returned have attachments when labelling attachments, the DM or action officer should use a waterfall style numbering, so document one and then the attachment to that would be document 1A, but an attachment to 1A would be document one point a point a onwards, and it doesn’t matter to my purpose. It doesn’t matter if you use letters or numbers, whatever is the agreed process for the agency.
0:13:3.630 –> 0:13:32.910
redacted: s47F - personal priva Rebecca
So considering this scope that we have on that we’ve discussed before this good scope. So you
then assess the documents against the scope for relevance. So you can see that I’ve gone
through and colour coded the different elements of the scope that need to be met. In this case,
there are four essential elements that must be met. It must be an e-mail or an attachment to an
e-mail. It must be between two defined parties. In this case the schema actually and the CEO. It
must fall within a specific date range.
0:13:33.470 –> 0:14:3.270
redacted: s47F - personal priva Rebecca
Attachments, including other emails, may fall outside of the date range, but will be in scope if
they’re attached to an e-mail which is within the date range and it must relate to the production
of the Drmc quarterly report and per 3.89 of the FOI guidelines, I would take an ordinary
interpretation of the word production, so the process of bringing something into existence or
being would be generally what you could be looking for. So anything to do with making the DRM
quarterly report.
0:14:4.100 –> 0:14:9.60
redacted: s47F - personal priva Rebecca
If any part of the scope is not met, the documents should be excluded from assessment.
0:14:11.120 –> 0:14:35.640
redacted: s47F - personal priva Rebecca
This is an example of how you might record a scoping decision so you can see in the left hand
column I have the number of the documents and I’ve used that waterfall star SO11A1B22A33A4
and put in a title or description of the documents. So in this situation for number one, we have
an e-mail from the CEO to the scheme. Actually regarding the quarterly report.
0:14:36.710 –> 0:14:58.950
redacted: s47F - personal priva Rebecca
We have the date of the document, the number of attachments, number of pages, the source
and a scoping decision. Now in this situation, I found that the document is not in scope because
it is outside of the date range of the request. You can see one January 20, 2430, March. This is 31st of December 23. Therefore out of scope.
0:14:58.990 –> 0:15:3.590
redacted: s47F - personal priva Rebecca
The second document is automatically out of scope because it is an attachment to the first
document.
0:15:5.30 –> 0:15:6.470
redacted: s47F - personal priva Rebecca
Same with the 1B as well.
0:15:7.440 –> 0:15:28.320
redacted: s47F - personal priva Rebecca
Looking then at document two, we have an e-mail from the scheme actually to the CEO
providing a draught of the quarterly report. We have a date of 12th of of January 24, which is
within the date range. We have one attachment 2 pages. Scheme actually is the source. This this
document would be in scope.
0:15:29.840 –> 0:15:46.80
redacted: s47F - personal priva Rebecca
We then have the attachment, which is the draught DMC report itself. You can see that it is
exactly the same attachment as document 1A, which was out of scope, but document 2A will be
in scope because it is an. It is attached to a document that is in scope.
0:15:47.580 –> 0:16:21.420
redacted: s47F - personal priva Rebecca
We then have an e-mail from at #3. We have an e-mail from the deputy CEO of governance, risk
and legal, so Debbie redacted: s47F - personal privac to the CEO about the Drmc quarterly report. The date ranges in
scope, the attachments is exactly the same as the document 2A. However, this document will be
out of scope because it is outside of the parameters of the request. It is not between the
scheme actually and the CEO as such, three at three and three a are both out of scope. The final
document is a document four and this is a team’s message from the CEO to the scheme actuary.
0:16:21.900 –> 0:16:27.740
redacted: s47F - personal priva Rebecca
We can see that it as it is it teams that message it is out of scope because it is not an e-mail.
0:16:32.80 –> 0:16:58.480
redacted: s47F - personal priva Rebecca
The next thing I wanted to talk about was duplicates and e-mail trials, and this is incredibly
important for a number of reasons. First of all, we need to make sure that we are not providing
unnecessary documents to applicants. We need to be very mindful about in terms of customer service outcomes. There is no point providing large numbers of irrelevant documents to our applicants.
0:16:58.820 –> 0:17:21.620
redacted: s47F - personal priva Rebecca
We need to be very considered in what we apply and giving them every single e-mail in an e-
mail trail, which is then repeated multiple times just means that you’re going to end up with a
very large document bundle of documents that are highly irrelevant to the applicant and it can
actually make their experience their FOI experience worse if they have to wade through
thousands of pages to get to one or two relevant emails.
0:17:23.60 –> 0:17:31.460
redacted: s47F - personal priva Rebecca
So AOS should remove duplicates during scoping according to the following rules, documents
must be exactly the same to be considered a duplicate a duplicate.
0:17:32.70 –> 0:17:57.310
redacted: s47F - personal priva Rebecca
Draughts or documents with a different date and not duplicates, but rather different versions.
Duplicates must be noted in the schedule of documents provided to the applicant. For an
example, if an identical report is provided as an attachment to multiple emails, it should be
assessed the first time it appears and thereafter removed from the bundle and annotated in the
schedule as removed as a duplicate of document X.
0:17:58.270 –> 0:18:4.270
redacted: s47F - personal priva Rebecca
That way the applicant knows that there was a document that it is the same as the one they’ve
already been given.
0:18:5.470 –> 0:18:7.950
redacted: s47F - personal priva Rebecca
Or has already been exempt?
0:18:8.30 –> 0:18:26.790
redacted: s47F - personal priva Rebecca
Components of e-mail trials can be removed as duplicates as long as the last e-mail in the trial is
included for assessment. So, as I said, you don’t need to include every single e-mail along the
path and the trail of each version, you can just include the last one or just assess the last one as
long as you have the complete history.
0:18:27.730 –> 0:18:48.770
redacted: s47F - personal priva Rebecca
But decision makers and AOS must be mindful that e-mail trails can split in these situations, you
need to include the last e-mail in each branch of the e-mail trail, even if it contains duplicate
emails from another branch. Unfortunately, sometimes we can’t avoid it, but we do need to can
capture a complete history of each of those branches.
0:18:52.440 –> 0:18:57.160
redacted: s47F - personal priva Rebecca
That is the end of the presentation. Does anyone have any questions?
0:19:1.435 –> 0:19:3.275
redacted: s47F - personal Helen
I do. Beck. It’s Helen here.
0:19:3.980 –> 0:19:4.460
redacted: s47F - personal priva Rebecca
Helen.
0:19:4.725 –> 0:19:11.445
redacted: s47F - personal Helen
Hi I’m just going back to the Commissioner’s guidelines, 3.90.
0:19:12.845 –> 0:19:35.725
redacted: s47F - personal Helen
And where they talk about it being prudent for agencies to explain the decision, this of in their
decision, the steps that were taken to search, what do you think it means where it says the
search parameters use the time taken to conduct the search and were there any relevant
backups for examined what what are the relevant backups?
0:19:36.640 –> 0:19:42.280
redacted: s47F - personal priva Rebecca
So I think the relevant backups would relate to digital files, so that might be data storage.
0:19:43.520 –> 0:20:10.120
redacted: s47F - personal priva Rebecca
It might be for example, in some situations you might have an audio recording of an interview,
so it might be that you’re not just looking at a transcript, but you’re also looking at a digital file.
So I think you need to just sort of think a little bit broader sometimes with the decision making
and just sort of think, OK, am I just looking at the very, very specific thing that is initially, you
know, which you might be a transcribed or do am I looking at other things as well, such as the
digital backups?
0:20:10.835 –> 0:20:12.35
redacted: s47F - personal Helen
OK. Thank you.
0:20:12.410 –> 0:20:15.610
redacted: s47F - personal priva Rebecca
No worries. Did anyone else have any questions?
0:20:18.580 –> 0:20:19.220
redacted: s47F - personal priva Rebecca
Please.
0:20:20.850 –> 0:20:21.50
redacted: s47F - personal priva Rebecca
Yeah.
0:20:33.880 –> 0:20:34.320
redacted: s47F - personal priva Rebecca
Yes.
0:20:35.620 –> 0:20:36.60
redacted: s47F - personal priva Rebecca
Yes.
0:20:16.445 –> 0:20:36.845
redacted: s47F - personal privacy Laura
Had more of a comment, if that’s all right, just something we can discuss a bit further. One thing
I’ve noticed is sometimes when we do search consults with business areas, they search the
documents they hold just by doing keyword searches and they can sort of over deliver on the
documents that they give us and.
0:20:38.45 –> 0:20:47.285
redacted: s47F - personal privacy Laura
Just because the business area has returned those documents, it doesn’t actually mean that
they’re in scope. And so it’s sort of still requires that the decision maker actually reads them.
0:20:48.35 –> 0:20:52.475
redacted: s47F - personal privacy Laura
And actually looks at the subject matter, and in particular.
0:20:53.835 –> 0:21:3.195
redacted: s47F - personal privacy Laura
Is the document as a whole about that subject matter, or is there just a tiny reference to the end that says, by the way, here’s a link. Please see this other document For more information.
0:21:4.755 –> 0:21:16.355
redacted: s47F - personal privacy Laura
Yes, I just wanted to kind of bring that up and you know, see if anyone else had any examples
where documents returned by the business area really aren’t in scope, they just happen to use a
keyword in a very minor sense.
0:21:17.420 –> 0:21:50.860
redacted: s47F - personal priva Rebecca
Yeah, I actually have an example of that yesterday with a request from ministerial and
parliamentary where they had conducted searches of PDMS using keyword searches, 3 keyword
searches, and which had returned an enormous number of hits. I think it was. We had one
package of about 700 pages and another about 300 pages, but in fact none of the documents
are in scope because that additional parameters had not been considered. So it is incredibly
important not to accept at face value what you get back from business areas.
0:21:51.140 –> 0:22:1.260
redacted: s47F - personal priva Rebecca
You need to vary independently and methodically. Go through them and assess them, and I
would encourage you to consider and remove duplicates as you’re doing your scheduling. It
makes it a lot easier.
0:22:5.10 –> 0:22:12.570
redacted: s47F - personal priva Rebecca
Does anyone else have an example of where they’ve had large number of returns that have
needed to be carefully scoped?
0:22:18.980 –> 0:22:19.100
redacted: s47F - personal priva Rebecca
Hmm.
0:22:13.405 –> 0:22:22.765
redacted: s47F - personal privacy Laura
Oh, definitely. I had the same experience as you with. We received 970 pages of documents
from the Min Pal space based on a PDMS search.
0:22:31.260 –> 0:22:31.380
redacted: s47F - personal priva Rebecca
Hmm.
0:22:24.165 –> 0:22:47.445
redacted: s47F - personal privacy Laura
And going through them, not a single one of them was in scope except for one that had already
been published on the disclosure log. And that was literally just because they used a keyword.
And for those who aren’t aware on PDMS, you get multiple documents bundled up together in a
single matter, such as emails and draughts and attachments. And if a keyword appears
somewhere in one of those documents, the whole bundle of documents gets produced.
0:22:48.225 –> 0:22:49.105
redacted: s47F - personal privacy Laura
As a heat.
0:22:51.100 –> 0:22:51.380
redacted: s47F - personal priva Rebecca
Yeah.
0:22:53.420 –> 0:23:21.220
redacted: s47F - personal priva Rebecca
Returning back to the issue of duplicates and e-mail trials, I think that is particularly important
in the personal information space where we know that documents are very often repeated, so
I’d really encourage you to consider that especially some of them can be run to a number of 100
if not 1000 pages. I’d be very, very carefully looking at what you can remove. It’s really
important to remember that some of our.
0:23:21.980 –> 0:23:51.580
redacted: s47F - personal priva Rebecca
Applicants have obviously different accessibility needs and being provided with such a large
document package of, you know, material that is repeated over and over again is not helpful and
can make can result in a really sort of poor customer experience. So we need to be thinking
about how we can assist our customers out. Sorry applicants by providing really sort of concise
and targeted information which meets their needs, their needs and is what they want but isn’t
repeated sort of ad nauseam.
0:23:52.470 –> 0:23:54.470
redacted: s47F - personal priva Rebecca
Elizabeth I can see you have a question.
0:24:10.360 –> 0:24:10.480
redacted: s47F - personal priva Rebecca
Hmm.
0:23:55.175 –> 0:24:21.855
redacted: s47F - personal privacy Elizabeth
Yeah, yeah. Just following on from what Peter just put in the chat actually. And and this does
come up often, it came up in your presentation as well. So those situations where all documents
are requested, it seems to me that there’s no way of avoiding a conversation with somebody
and and really that that kind of scope or that kind of initial request.
0:24:23.175 –> 0:24:26.415
redacted: s47F - personal privacy Elizabeth
It really means that they they’re not really sure what they’re looking for, but they.
0:24:27.135 –> 0:24:35.735
redacted: s47F - personal privacy Elizabeth
Are wanting to get something so we really do need to come to like, go to them directly and just
say, well, can you tell us a bit more?
0:24:37.95 –> 0:24:41.255
redacted: s47F - personal privacy Elizabeth
What do you what? What would satisfy you in terms of what kind of information are you
seeking?
0:24:47.390 –> 0:24:47.670
redacted: s47F - personal priva Rebecca
Yeah.
0:24:43.175 –> 0:24:57.175
redacted: s47F - personal privacy Elizabeth
And So what would be your suggestions? I suppose could could we? Could we pull together
some resources? So that was very easy for the triage and registration group and even for the
decision makers as well.
0:24:57.645 –> 0:24:58.405
redacted: s47F - personal privacy Elizabeth
I suppose.
0:24:59.240 –> 0:25:30.280
redacted: s47F - personal priva Rebecca
Yeah. Look, I think in in that situation, the first thing you would do is pick up the phone and call
the person and sort of, you know, really enquire about the the reasoning behind their request
because whilst we’re not allowed to think about the reason for someone’s FOI requests for the
purposes of the act, it is actually sometimes a really helpful to understand what they’re actually
looking for so that you can target searches and really help to eliminate the sort of large
documents of irrelevant, you know, nature. So I would definitely encourage you to be quite comfortable to call.
0:25:30.760 –> 0:26:1.840
redacted: s47F - personal priva Rebecca
Applicants and have those conversations. It’s sometimes helpful to sort of tell them if you have
a quick views of how many documents have been found. So if you can say, oh, look, I’ve got
1100 pages of material, do you need it all or could we look sort of for a more targeted
document and that by might be enough to help them? There’s no harm in that in telling them
that, you know, we’ve got a large number of documents. Don’t tell them what the documents
are necessarily. But you, you know, telling them that we’ve got the volume is is not problematic.
0:26:1.920 –> 0:26:3.40
redacted: s47F - personal priva Rebecca
In most cases.
0:26:3.630 –> 0:26:4.310
redacted: s47F - personal privacy Elizabeth
Mm hmm. Yep.
0:26:13.820 –> 0:26:13.940
redacted: s47F - personal privacy Elizabeth
Hmm.
0:26:21.100 –> 0:26:21.220
redacted: s47F - personal privacy Elizabeth
Hmm.
0:26:4.320 –> 0:26:25.320
redacted: s47F - personal priva Rebecca
If you’re not sure about a scope, you can always take advice either from a member of your team
or your assistant director or director. I’m very, very big on case consultations. I think it’s a really
effective way to solve roadblocks and to move cases forward. So I think if ever you’re unsure,
you should definitely reach out and seek that support.
0:26:55.710 –> 0:26:56.350
redacted: s47F - personal priva Rebecca
Perfect.
0:26:26.220 –> 0:26:57.780
redacted: s47F - personal privacy Elizabeth
Yeah, I would’ve. Could I just go on just to say it would be great to perhaps have some training
then if if it’s a little new on the horizon for some members of the team, particularly new ones in how to craft those sorts of discussions, maybe that’s something that a few people would be interested in, I’d be happy to be part of it. I mean, I come from a planning background, so I’m comfortable with reaching out to applicants.
0:26:57.520 –> 0:26:58.0
redacted: s47F - personal priva Rebecca
Yeah.
0:26:58.90 –> 0:27:17.450
redacted: s47F - personal privacy Elizabeth
But but there is a probably a certain set of skills that you need. You need to be aware of what
what’s OK to say? What’s not OK? All those sorts of things. And. And I suppose if we just make it
really clear for everyone in the team how you wanted this sort of thing to be conducted.
0:27:18.850 –> 0:27:23.690
redacted: s47F - personal privacy Elizabeth
Then I think that that will just mean that everyone rolls out and and does it well.
0:27:25.320 –> 0:27:30.320
redacted: s47F - personal priva Rebecca
Yeah, I agree. I definitely agree. I think that’s a really good idea and would be very helpful for
the team.
0:27:31.480 –> 0:27:34.200
redacted: s47F - personal priva Rebecca
OK. We have another question from Konty.
0:27:35.210 –> 0:27:37.450
redacted: s47F - personal priva Rebecca
Hope I pronounced that correctly. Would like to go ahead.
0:27:38.550 –> 0:27:59.870
redacted: s47F - personal pr Concey
Thanks, Rebecca. That’s great. It’s part of my question has already been answered, but it’s just
more so now a comment based on the duplicate ’cause. I had a scenario with a with an
applicant who is a nominee and they wanted everything and I had that phone conversation that
you know went longer than I initially planned. But Long story short, she just wanted.
0:28:1.430 –> 0:28:8.950
redacted: s47F - personal pr Concey
A full file and didn’t care how long it took ’cause I I said that if we it took too long, she might lose her, right?
0:28:16.710 –> 0:28:16.830
redacted: s47F - personal priva Rebecca
Hmm.
0:28:26.590 –> 0:28:26.710
redacted: s47F - personal priva Rebecca
Hmm.
0:28:33.620 –> 0:28:33.740
redacted: s47F - personal priva Rebecca
Hmm.
0:28:36.790 –> 0:28:37.270
redacted: s47F - personal priva Rebecca
Yeah.
0:28:9.390 –> 0:28:37.710
redacted: s47F - personal pr Concey
For internal review and all of that stuff. But her her perspective was that she wanted a copy of
what we held, and there seems to be a confusion in terms of what she’s uploading and what
she can see is accessible through the portal. And I had some duplicates as well of parts of the
forms being incomplete and then her her being told. Can you provide a completed one? But she
just basically wanted everything. She didn’t care how it was presented.
0:28:38.700 –> 0:28:40.380
redacted: s47F - personal pr Concey
In those, yeah.
0:28:44.530 –> 0:28:45.10
redacted: s47F - personal pr Concey
Yeah.
0:28:38.480 –> 0:29:7.120
redacted: s47F - personal priva Rebecca
Unfortunately, sometimes you’re not going to be able to avoid it. As you know, if the applicant
has a right to that information, they have a right to request everything from a processing point
of view, it becomes problematic in terms of our time management and our resourcing and how
much you know how long it takes to do decisions. And I’m sure you’re aware that you know
processing a request that is 1000 odd pages is going to take a good chunk of time. I’d just like to really reinforce that you have to read every page.
0:29:11.130 –> 0:29:11.490
redacted: s47F - personal pr Concey
OK.
0:29:7.590 –> 0:29:16.230
redacted: s47F - personal priva Rebecca
You cannot assume that a document is safe to be released just because it is something the
applicant has provided us. You need to read every page.
0:29:17.330 –> 0:29:18.810
redacted: s47F - personal priva Rebecca
And that can add a lot of time.
0:29:16.810 –> 0:29:22.930
redacted: s47F - personal pr Concey
Excellent. That’s what I was gonna ask. How will we approach reading the whole page, but that’s
perfect. Thank you.
0:29:22.120 –> 0:29:27.960
redacted: s47F - personal priva Rebecca
Yeah. I’m sorry. I mean sometimes obviously you have to read things more deeply than others.
0:29:29.320 –> 0:29:50.640
redacted: s47F - personal priva Rebecca
But you need to at least have eyes on every page and that is why your schedule becomes
incredibly important, because you can list out the documents in scope. You can note what they
are and that you’ve checked it and have a record. And sorry, that’s one thing I should I should
have mentioned too. Your schedule of documents is actually a bit of a.
0:29:50.680 –> 0:29:51.480
redacted: s47F - personal priva Rebecca
Progressive document.
0:29:52.0 –> 0:30:25.520
redacted: s47F - personal priva Rebecca
Because once you’ve done the scheduling, you can add a column and you can use that for your
assessment of whether a document is in scope. I’m sorry, whether a document has exemptions
and can be released, so you actually it’s a progressive document in terms of processing. You can
also, for those of you who are doing non personal requests, you can also then use that schedule
to inform charges, if indeed you guys ever decide to do start doing charging, that can also be used for that in that way too. So it is actually a really incredibly valuable doc valuable document.
0:30:25.720 –> 0:30:53.920
redacted: s47F - personal priva Rebecca
We’ll go back to 3.90, which says that we must, you know, retain records about scoping
decisions. I think schedules are just the best way to go. You can do it in Word. You can use do it
in Excel. It might be worth putting together. Perhaps a template for the team that everyone’s
using the same type of scoping document, and that’s something that then gets automatically
saved into SharePoint and becomes part of the process. But I cannot stress how important it is
to have accurate records.
0:30:54.680 –> 0:31:9.120
redacted: s47F - personal priva Rebecca
Especially if cases go to external review and we have to justify why we made certain decisions,
it’s really good to be able to say well, on this day I did this and this is what I found really, really
helps.
0:31:11.320 –> 0:31:14.400
redacted: s47F - personal priva Rebecca
Did anyone else have any questions before we wrap up today?
0:31:18.420 –> 0:31:55.380
redacted: s47F - personal priva Rebecca
No. If not, you’re welcome to reach out to me if you have any particular scopes that you’d like to
discuss. Anything that’s complicated, just a reminder that a lot of our 90 day plus cases have
been held up by scoping issues. So it is incredibly important to get those right at the front,
preferably at triage and registration, but if not, we need to catch them at decision making. So
thank you very much for everyone attending. I have also put together a scoping help card, which
will be circulated in the next couple of days, which runs through the sides that we’ve just been
through and answers any questions. And again gives examples of what’s.
0:31:56.220 –> 0:31:57.140
redacted: s47F - personal priva Rebecca
A good schedule might look like.
0:31:58.0 –> 0:31:59.560
redacted: s47F - personal priva Rebecca
So thank you very much for your time.
FOI Training
Extensions of Time
April 2024
Extensions of Time (EOT)
The Freedom of Information Act 1982 provides 30 days to process access, amendment and internal review requests. This is a statutory timeframe: compliance is required by law.
In recognition that some requests require more work than others, the Act contains 5 provisions to extend the statutory timeframe of a request or review:
- 15AA — EOT with applicant agreement
- 15AB — EOT for complex or voluminous matters
- 15AC — EOT for deemed refused access requests
- 51DA(3) — EOT for deemed refused amendment requests
- 54D(3) — EOT for deemed refused Internal Reviews.
Key learning: FOI requests should never fall overdue without an EOT request.
15AA — EOT with agreement of applicant
Key features: [FOI Guidelines at 3.146 — 3.149]
- Must request EOT within the statutory timeframe
- Can only be used for access requests
- Can only extend timeframe by a total of 30 days — but can be used in multiple parts.
- Requires both the agreement of the applicant in writing and notification of that agreement to OAIC.
How to process:
- Write to applicant requesting further time to process the request. Best practice is to:
- write at least 7 days in advance of approaching deadline
- provide an update on case progress (i.e., search and retrieval completed)
- explain how the additional time will be used (assessment / internal consultation)
- only request the time you need to complete the request
- provide new due date and make sure you meet it.
- Notify the OAIC via webform as soon as you receive the response; provide evidence.
15AB — EOT for complex or voluminous matters
Key features: [FOI Guidelines at 3.150 — 3.155]
- Must request EOT within statutory timeframe.
- Should only request after a you have “obtained, or attempted to obtain” a 15AA EOT [see 3.151].
- Can only be used for complex OR voluminous access requests.
- No limit on length of time or number of 15AB EOTs that can be granted, but you must justify your planned use of time to OAIC.
- Request is made directly to OAIC via webform.
How to process:
- Ideally, you have already sought 15AA EOT or engaged with the applicant on scope.
- Complete OAIC webform outlining:
- applicant’s details
- details of previous EOT requests
- timeline of work already completed
- reasons why request is complex or voluminous
- any other parties involved
- measures to ensure request is completed by extended due date.
15AC — deemed refused access requests
Key features: [FOI Guidelines at 3.162 — 3.165]
- Can only request EOT after statutory timeframe has expired.
- Only applies to access requests.
- Can only be granted once.
- No limit on length of time can granted, but you must justify your planned use of time.
- Request is made directly to OAIC via webform.
- Negates a deemed refusal.
How to process:
- Ideally, you have already sought 15AA or 15AB or engaged with the applicant on scope.
- Complete OAIC webform outlining:
- applicant’s details
- previous EOT requests
- timeline of work already completed
- scope and complexity of the request
- any other parties involved
- measures to ensure request is completed by extended due date.
51DA — deemed refused amendment requests
Key features: [FOI Guidelines at 7.181 — 7.82]
- Can only request EOT after statutory timeframe has expired.
- Can only be granted once.
- Generally, will not be granted for more than 30 days. [see 7.82].
- Request is made directly to OAIC via webform.
- Negates a deemed refusal.
How to process:
- Seek applicant’s ‘informal’ consent for the additional processing time [see 7.82].
- Complete OAIC webform outlining:
- applicant’s details
- previous EOT requests
- timeline of work already completed
- any other parties involved
- measures to ensure request is completed by extended due date.
54D — deemed refused internal reviews
Key features: [FOI Guidelines 9.43 — 9.51]
- Can only request EOT after statutory timeframe has expired.
- Can only be granted once.
- No limit on length of EOT, but you must justify your planned use of time.
- Request is made directly to OAIC via webform.
- Can be used for external consultations (the Act does not provide extra time for reviews)
- Negates a deemed refusal.
How to process:
- Ideally, you have already engaged with the applicant re processing delay.
- Complete OAIC webform outlining:
- applicant’s details
- previous EOT requests
- timeline of work already completed
- any other parties involved
- measures to ensure request is completed by extended due date.
Benefits of EOTs
1. Maintains the applicant’s internal review rights
- Win/win: the applicant gets a faster review decision and NDIA gets to quickly identify and correct any processing errors.
- Better customer service experience dealing directly with Agency rather than a third party.
- Preserves OAIC attention for more serious FOI matters.
2. Promotes statutory compliance
- Upholds objects of the FOI Act via timely decision making.
- Promotes public value via government transparency and accountability.
- Recognizes that requests differ in size and complexity.
3. Promotes applicant engagement
- Encourages NDIA to communicate with the applicant and/or OAIC throughout decision making = better customer service experience/ promotes understanding of FOI complexity and processes.
- Can be combined with request consultation.
Key learnings
- EOTs are part of good case management practice.
- Only request the time that you actually need to finalize a request: longer requests are more likely to be refused.
- You can apply for more than one type of EOT per request.
- You will need to present detailed and persuasive reasons to be granted an EOT. “Competing priorities” is unlikely to be sufficient.
- You must include information about EOT requests in your decision letter, even if your request was refused.
- You must record all EOT decisions, records and correspondence.
- Take time to read the FOI Guidelines!
Key learnings
FOI requests should never fall outside of statutory timeframes without at least one EOT request.
FO EBBIAIALSO
Questions
Page 95 of 331 OFFICIAL
11
Quiz!
- How many types of EOTs deal with deemed refused requests?
- On what day could you request a 15AC EOT?
- You need to assess a 1245 page document to meet a statutory due date 6 days away. Which EOTs could you request?
- Should you wait for the OAIC to respond to an EOT request before releasing the decision?
- How many EOTs can you (theoretically) use on one access request?
- You are dealing with a difficult multi-party consent issue for an access request. What type of EOT might be appropriate?
- What two steps need to occur for a 15AA EOT to be granted?
- True or false: EOTs enable better case management outcomes.
FOI 25/26-2150 DOCUMENT 7
clock0:0:0.0 –> 0:0:7.120
redacted: s47F - personal priva Rebecca
Good morning, everyone, and welcome today to FI training. Today we’re going to be looking at
extensions of time.
0:0:9.460 –> 0:0:39.420
redacted: s47F - personal priva Rebecca
So the Freedom of Information Act provides 30 days to process access amendment and internal
review requests. This is a statutory time frame at which means that compliance is required by
law in recognition that some requests require more work than others. The act contains 5
provisions to extend the statutory time frame of a request or a review. These are 15 a a an
extension of time with applicant agreement 15-AB.
0:0:39.500 –> 0:0:42.300
redacted: s47F - personal priva Rebecca
An extension of time for complex or voluminous matters.
0:0:42.690 –> 0:0:48.450
redacted: s47F - personal priva Rebecca
15 A/C an extension of time for deemed refused access requests.
0:0:48.610 –> 0:0:58.730
redacted: s47F - personal priva Rebecca
51 Da Three an extension of time for deemed refused amendment requests AT54D3, an
extension of time for deemed refused internal reviews.
0:1:0.130 –> 0:1:12.850
redacted: s47F - personal priva Rebecca
As you can see, the five provisions cover most eventualities, so it’s incredibly important that
case officers understand that FY requests should never fall overdue without an EOT request
having been made.
0:1:15.870 –> 0:1:26.750
redacted: s47F - personal priva Rebecca
We’ll go through each of the EOT provisions 1 by 1, starting with 15-8, a A which is the most
commonly used one, and this is an EOT with agreement of the applicant.
0:1:28.190 –> 0:1:48.870
redacted: s47F - personal priva Rebecca
The guidelines provide quite a bit of really helpful guidance on this one and they can be found
at 3.146 to 3.149. The key features are that you must request the EOT within the statutory time
frame. This can a 15AA S can only be used for access requests.
0:1:49.390 –> 0:2:19.670
redacted: s47F - personal priva Rebecca
And you can only extend the time frame by a total of 30 days you, but you can do that in
multiple parts. For example, you can first of all seek 14 days and then seek the additional time.
So you can do it in two blocks or you can even do it in seven day blocks, depending on what you
need now to get a 15AA, you must have both the agreement of the applicant in writing and you
must have notified that agreement to the IIC.
0:2:19.900 –> 0:2:30.380
redacted: s47F - personal priva Rebecca
So you must do both things for this to stand. If you only get the applicants agreement but don’
t notify OSC, it does not work. OK, so really make sure you understand that point.
0:2:31.940 –> 0:2:40.820
redacted: s47F - personal priva Rebecca
Now in terms of processing A15AA, the first step is to write to the applicant requesting further
time to process the request.
0:2:40.860 –> 0:2:55.500
redacted: s47F - personal priva Rebecca
Best practise is to write to the applicant at least seven days in advance of the approaching
deadline to provide an update on the case. So what? Where are you up to? Have you done
search and retrieval? Are you assessing the documents? Are you consulting on the documents?
0:2:56.250 –> 0:3:2.650
redacted: s47F - personal priva Rebecca
Explain how the additional time will be used. For example, we’re going to complete assessment
or do internal consultation.
0:3:4.250 –> 0:3:14.730
redacted: s47F - personal priva Rebecca
Only request the time you need to complete the request. You will have far better luck being
granted A15AA if you request 7 or 14 days rather than just going for the full 30.
0:3:16.250 –> 0:3:20.850
redacted: s47F - personal priva Rebecca
It’s also really important that you provide a new date and make sure that you meet it.
0:3:21.690 –> 0:3:45.250
redacted: s47F - personal priva Rebecca
Because that builds confidence in the agency and our decision making processes. Once you’ve
completed that step, the second step is to notify the OAIC via its web form, as soon as
practicable within the guidelines. But as soon as you receive the response and you do need to provide evidence of the applicant’s consent, which is that they’ve provided to you in writing.
0:3:49.310 –> 0:3:57.710
redacted: s47F - personal priva Rebecca
The next type of of AOT is a 15-AB, and this is the one that we use for complex or voluminous
matters.
0:3:59.30 –> 0:4:20.710
redacted: s47F - personal priva Rebecca
Again, the FOI guidelines are incredibly instructive at 3.150 to 3.155 the key features of this type
of AOT again is that you must request the EOT within statutory time frame. You should only
request at this type of EOT, after you have obtained or attempted to it, obtain A15AA.
0:4:21.430 –> 0:4:27.950
redacted: s47F - personal priva Rebecca
And that is contained in the FY guidelines. So they’re very big on this being a secondary EOT.
0:4:27.990 –> 0:4:31.30
redacted: s47F - personal priva Rebecca
It’s not 100%.
0:4:31.70 –> 0:4:53.390
redacted: s47F - personal priva Rebecca
There will be circumstances when you can demonstrate that there was a reason you didn’t get a
15-A a first, but certainly that is the intent of the FOI guidelines now. This type can only be used
for complex or voluminous access requests, so you need to be able to justify that it is a a more
complex matter or larger or more complex matter than standard FY request.
0:4:54.510 –> 0:5:11.70
redacted: s47F - personal priva Rebecca
There is no limits on the length of time or the number of 15-AB EOTS that can be granted, but
you must be able to justify your planned use of time to Arak because they will decide whether
or not it’s granted and how long you get to for your extension of time.
0:5:12.590 –> 0:5:26.150
redacted: s47F - personal priva Rebecca
The request is made directly to Oak via its web form and in terms of processing it. As I
mentioned before, ideally you’ve already sort of 15 a A or engage with the applicant on scope
and you need to complete the oak web form.
0:5:26.630 –> 0:5:50.390
redacted: s47F - personal priva Rebecca
Outlining the applicants details, details of any previous EOT requests for the 15 a AAA timeline
of the work already completed, so you can just do that in dot point. So you can say search and
retrieval done On this date. Assessment done On this date. Internal consultation On this date.
You can really just do it in dot points as long as it’s clear that work has been progressively done
on the request.
0:5:51.430 –> 0:5:55.830
redacted: s47F - personal priva Rebecca
Reasons why the request is complex or voluminous, so you’re going to have to explain like.
0:5:56.560 –> 0:6:19.840
redacted: s47F - personal priva Rebecca
It’s either gonna be there’s a very large number of folios that need to be assessed, and I need
more time to do the work or the matter is complex For these reasons, and that might be that it
spans several internal business areas requiring sort of consultation with a number of different
people and a number of different documents. So just to need to really justify that complexity.
0:6:21.80 –> 0:6:25.720
redacted: s47F - personal priva Rebecca
You need to be able to identify any other parties involved, including external third parties.
0:6:26.360 –> 0:6:39.800
redacted: s47F - personal priva Rebecca
And you need to include a statement as the measures to ensure the request is completed by the
extended due date, because I can therefore monitor that you have actually completed the
request by that date.
0:6:41.280 –> 0:6:55.960
redacted: s47F - personal priva Rebecca
So I would suggest for that last point that perhaps collectively the management of the Fr team
sort of work out a form of words and and and a way of ensuring that 15-AB S are met.
0:6:56.480 –> 0:7:13.200
redacted: s47F - personal priva Rebecca
So that might be requiring weekly reporting to an assistant director on case progress, or having
even like a regular sort of EO team meeting to make sure that those cases are moving forward.
So it builds some governance processes around that to make sure that we’re really hitting that
Mark.
0:7:16.290 –> 0:7:39.90
redacted: s47F - personal priva Rebecca
The next type of EOT is a 15 A/C and this one is for deemed refused access requests. The
guidelines are instructive at 3.162 to 3.165. Now this type of EOT can only be requested after
the statutory time frame has expired. It only applies to access requests. It can only be granted
once.
0:7:40.630 –> 0:8:10.590
redacted: s47F - personal priva Rebecca
There is no limit on the length of time that can be granted, but you must be able to justify your
planned use of time. Again, the request is made directly to our acquire its web form and this
one is really great because it actually negates a deemed refusal. So if you have a request that
has fallen outside of statutory timeframes and is therefore subject to 15 A/C, if you are granted
A15ACE OT, it actually makes it so the request never was overdue.
0:8:10.870 –> 0:8:13.310
redacted: s47F - personal priva Rebecca
Was in time the whole time.
0:8:14.880 –> 0:8:34.840
redacted: s47F - personal priva Rebecca
So you may in this circumstance have a request that the statutory time frame is, say 45 days
instead of 30 or even longer. The longest one I’ve ever seen granted was about 40 days after the
original statutory due date, and for that one it was because their request required.
0:8:36.760 –> 0:8:43.720
redacted: s47F - personal priva Rebecca
External consultation with the party who was overseas, so that’s a in that situation. I agreed
that we needed that additional time.
0:8:44.230 –> 0:8:46.710
redacted: s47F - personal priva Rebecca
So you’re gonna have to have pretty strong justification.
0:8:48.230 –> 0:9:8.510
redacted: s47F - personal priva Rebecca
In terms of processing it, ideally you’ve already sought A15AA or A15-AB or even both, and
engage with the applicant on scope. It’s incredibly important to act that they you can
demonstrate that you have been actively working on the case the whole time. You would need
to complete the OAC web form outlining the applicant’s details.
0:9:9.950 –> 0:9:15.110
redacted: s47F - personal priva Rebecca
Previous extension of time requests a timeline of the work already completed on the request.
0:9:16.240 –> 0:9:19.480
redacted: s47F - personal priva Rebecca
A statement as to the scope and complexity of the request.
0:9:20.600 –> 0:9:28.80
redacted: s47F - personal priva Rebecca
You need to identify any other parties involved and again include those measures to ensure the
request is completed by the extended due date.
0:9:32.600 –> 0:9:45.80
redacted: s47F - personal priva Rebecca
We moved now to 51 DA, which is deemed refusal of an amendment requests, so the FOI
guidelines speak to this at 7.181 to 7.182.
0:9:45.320 –> 0:9:58.200
redacted: s47F - personal priva Rebecca
This one is slightly different. It does not have a equivalent to A15AA or A15A AB. You can only
request an extension on an amendment once that request has fallen overdue.
0:10:0.260 –> 0:10:13.540
redacted: s47F - personal priva Rebecca
You can only receive one EOT for this type of request and the FY guidelines at 7.82 actually tell
us that it is unlikely that the request will be granted for more than 30 days.
0:10:14.860 –> 0:10:24.820
redacted: s47F - personal priva Rebecca
The request is made directly to iacquire, its web form and again it negates a deemed refusal. So
if you are granted this form of EOT, it’s like it was never overdue.
0:10:26.50 –> 0:10:32.530
redacted: s47F - personal priva Rebecca
Unfortunately, if you then fall overdue of your EOT, there’s no further recourse. You cannot fix it
and you’re just going to be overdue.
0:10:34.290 –> 0:10:48.690
redacted: s47F - personal priva Rebecca
In terms of processing, you need to seek the applicants informal consent for the additional
processing time. This is an interesting requirement that’s included in the FOI guidelines. It’s not a formal requirement, but it is strongly suggested.
0:10:49.930 –> 0:10:58.130
redacted: s47F - personal priva Rebecca
And it’s probably, you know, quite a good part of case management is to keep your applicant
updated if you believe your request is going to require additional time anyway.
0:10:59.730 –> 0:11:8.370
redacted: s47F - personal priva Rebecca
You then complete the Arak web form, outlining the applicant’s details. Previously, EOT requests
actually won’t be any previous EOT requests in this one, so disregard that.
0:11:9.160 –> 0:11:23.240
redacted: s47F - personal priva Rebecca
A timeline of the work already completed. Any other parties involved and that might be a
situation where you’ve got an external party seeking FOI subjects applicant information rather.
0:11:23.340 –> 0:11:30.580
redacted: s47F - personal priva Rebecca
And there’s, you know, potentially consent issues at play and again measures to ensure the
request is completed by the extended due date.
0:11:33.860 –> 0:12:6.60
redacted: s47F - personal priva Rebecca
And the final type of ET that is available is A54D, which is a deemed refused of internal reviews.
So the guidelines cover this in 9.43 to 9.51 you again you can only request the EOT after the
statutory time frame for the internal review has expired. It can only be granted once there is no
limit on the length of the EOT, but again you must be able to justify your planned use of time in
able to secure ox agreement.
0:12:6.910 –> 0:12:9.870
redacted: s47F - personal priva Rebecca
The request is made directly to Ark via its web form.
0:12:11.730 –> 0:12:20.890
redacted: s47F - personal priva Rebecca
In my experience, this one is used to justify time required for external consultations because the
act does not provide extra time for review consultations.
0:12:22.570 –> 0:12:28.450
redacted: s47F - personal priva Rebecca
And again, this one negates the deemed refusal. So it actually just cancels it out.
0:12:28.490 –> 0:12:38.890
redacted: s47F - personal priva Rebecca
In terms of processing, again, ideally you’ve engaged with the applicant regarding the
processing delay. So you’ve said, you know, I’ve got your internal review. I am working on it.
However, it’s been delayed For these reasons.
0:12:40.290 –> 0:12:45.650
redacted: s47F - personal priva Rebecca
I intend to seek an extension of time from OAC to enable me to complete the request.
0:12:47.10 –> 0:12:55.250
redacted: s47F - personal priva Rebecca
Just keep the it’s really important to keep your applicant updated and then you complete the
OAC web form outlining outlining the applicants details.
0:12:55.940 –> 0:13:3.580
redacted: s47F - personal priva Rebecca
Previous EOT requests, even during the original decision, you need to include that to
demonstrate that you have, you know, been working.
0:13:5.60 –> 0:13:9.580
redacted: s47F - personal priva Rebecca
Within the provisions of the actor, where possible, a timeline of the work already completed.
0:13:11.180 –> 0:13:16.540
redacted: s47F - personal priva Rebecca
Outline any other parties involved. Measures to include the request is completed by the
extended due date again.
0:13:20.250 –> 0:13:49.330
redacted: s47F - personal priva Rebecca
So there’s a number of benefits to EOTS, but the three principal ones are that it maintains the
applicant’s internal review rights and this is a win win. The applicant gets a faster review
decision and the Ndia gets to quickly identify and correct any processing errors. So the situation
that might apply in this one is if the applicant believes that we haven’t done reasonable
searches and we’re able to quickly go in, redo the searches, see if that.
0:13:49.570 –> 0:13:54.730
redacted: s47F - personal priva Rebecca
That is a correct decision or not. And then redo the decision if we need to.
0:13:56.150 –> 0:14:11.550
redacted: s47F - personal priva Rebecca
It also enables better customer service experience for our participants. Our participant and
applicants because they’re able to deal directly with the agency rather than a third party. For
example, oak. It also preserves oaks attention for more serious FOI matters.
0:14:13.520 –> 0:14:20.280
redacted: s47F - personal priva Rebecca
The second benefit is that it promotes statutory compliance, it upholds the objects of the FOIA
acts via timely decision making.
0:14:21.800 –> 0:14:31.920
redacted: s47F - personal priva Rebecca
It promotes public value via government transparency and accountability, and it recognises that
requests differ in size and complexity and gives us provisions to deal with those issues.
0:14:34.820 –> 0:14:53.500
redacted: s47F - personal priva Rebecca
It also promotes applicant engagement in the FY process. It encourages the ndia to
communicate with the applicant and or OAC throughout decision making, which will result in
best a a better customer service experience and also promote understanding of the FY
complexity and processes.
0:14:54.680 –> 0:14:58.80
redacted: s47F - personal priva Rebecca
And also it can be combined with request consultation.
0:15:2.930 –> 0:15:8.490
redacted: s47F - personal priva Rebecca
So the key learnings from today’s session are that EO TS are part of Good case management
practise.
0:15:9.810 –> 0:15:19.930
redacted: s47F - personal priva Rebecca
You should only request the time that you actually need to finalise a request. Longer requests
are definitely more likely to be refused. So really think about what you need versus what you
can have.
0:15:21.310 –> 0:15:24.270
redacted: s47F - personal priva Rebecca
You can apply for more than one type of EOT per request.
0:15:25.860 –> 0:15:38.940
redacted: s47F - personal priva Rebecca
And you will need to present detailed and persuasive reasons to be granted an EOT. Just saying
that you weren’t able to action the request due to competing priorities or other cases is unlikely
to be sufficient.
0:15:39.980 –> 0:16:7.180
redacted: s47F - personal priva Rebecca
You must include information about EOT requests in your decision letter. Even if your request
was refused, so must say On this date I requested A15AA you decline to grant it. On this day I
went to the oarc to request A15-AB. It was granted On this date. The new statutory date for this
request was subsequently and then you enter the new date. So you need to include those
details in your decision letter.
0:16:8.740 –> 0:16:17.140
redacted: s47F - personal priva Rebecca
You must record all EOT decisions, records and correspondence in the relevant case file and in
LEX.
0:16:17.160 –> 0:16:22.520
redacted: s47F - personal priva Rebecca
And you really should take time to read the FOI guidelines because they’re incredibly helpful
and instructive.
0:16:27.0 –> 0:16:35.400
redacted: s47F - personal priva Rebecca
As mentioned earlier, FOI request should never fall outside of statutory timeframes without at
least one EOT request.
0:16:36.370 –> 0:16:38.170
redacted: s47F - personal priva Rebecca
And I do not personally.
0:16:39.970 –> 0:16:44.370
redacted: s47F - personal priva Rebecca
Count the automatic 15 a A request in the acknowledgement letter as part of that.
0:16:46.170 –> 0:16:54.570
redacted: s47F - personal priva Rebecca
I think if you think this request is going to go overdue, you need to go above and beyond to try
and find a way to get an EOT to keep it in statutory timeframes.
0:16:58.120 –> 0:16:59.640
redacted: s47F - personal priva Rebecca
Any questions?
0:17:8.10 –> 0:17:12.10
redacted: s47F - personal priva Rebecca
You might have to call out names ’cause. I can’t see if any hands are up.
0:17:13.240 –> 0:17:15.280
redacted: s47F - personal privac Jessie
Sure. My name’s Jesse. I have a question.
0:17:15.440 –> 0:17:16.600
redacted: s47F - personal priva Rebecca
Sure, go ahead, Jesse.
0:17:16.890 –> 0:17:24.10
redacted: s47F - personal privac Jessie
I was wondering if you could give an example as to when you would need to use the 51 DA
extension.
0:17:25.240 –> 0:17:50.0
redacted: s47F - personal priva Rebecca
So 51 DI extension obviously is for amendment requests that have fallen overdue, so that might
be in a situation where you were doing, you had maybe a third party consultation that you were
waiting on and the request had fallen overdue because that person had not responded to you in
time. So you would seek, say, an additional 14 days to allow that response to come in and to be
actioned.
0:17:51.560 –> 0:17:52.280
redacted: s47F - personal privac Jessie
Thank you.
0:17:52.650 –> 0:17:54.610
redacted: s47F - personal priva Rebecca
Yeah. Any other questions?
0:17:59.680 –> 0:18:0.200
redacted: s47F - personal priva Rebecca
Sure.
0:18:5.520 –> 0:18:5.720
redacted: s47F - personal priva Rebecca
Mm hmm.
0:18:11.40 –> 0:18:11.600
redacted: s47F - personal priva Rebecca
Yeah.
0:17:56.0 –> 0:18:18.600
redacted: s47F - personal privac Jordyn
Hi, my name’s Jordan. I’ve got a bit of a question. I’m working on a few matters at the moment
that are like 90 plus days overdue. Would you recommend going to owak for those ones as well
to get an extension, but it’s hard for those ones ’cause, I don’t really have a great reason for it
going overdue ’cause. I only just got assigned to them like last week, so.
0:18:19.270 –> 0:18:25.350
redacted: s47F - personal priva Rebecca
Yes. And I look, yeah, this is an issue.
0:18:25.390 –> 0:18:27.350
redacted: s47F - personal priva Rebecca
With the legacy caseload.
0:18:29.310 –> 0:18:43.790
redacted: s47F - personal priva Rebecca
In those situations, I personally would not, because as I said, you’re going to need to be able to
justify to oak that you had been consistently working on the case the whole way through to get
the EOT.
0:18:44.30 –> 0:18:50.350
redacted: s47F - personal priva Rebecca
So my view is that that probably would not grant it unless you could show that you know the
you know the request had been.
0:18:50.670 –> 0:18:52.510
redacted: s47F - personal priva Rebecca
Had that level of sort of work.
0:18:54.70 –> 0:19:4.390
redacted: s47F - personal priva Rebecca
You can try on the basis that it preserves the applicants review rights and therefore is a it’s a
better customer service outcome for the applicant. If that EOT is granted.
0:19:5.870 –> 0:19:20.350
redacted: s47F - personal priva Rebecca
But my personal experiences? Yeah, unless it’s been pretty consistent work on the request, you
probably won’t be granted it. So it’s one of those decisions you’d need to talk about to your
with your ID. Really discuss the sort of pros and cons of of.
0:19:20.880 –> 0:19:27.160
redacted: s47F - personal priva Rebecca
For the 15 AAC and then sort of make an informed decision.
0:19:28.620 –> 0:19:46.260
redacted: s47F - personal priva Rebecca
I know Peter has a slightly different view. He believes that preserving those 15 A/C review rights
is a, you know, really important, and therefore it’s worth putting in that application. But my
experiences, we’ve been in my previous role, we were knocked back several times. For those
longer cases where they had been consistent casework.
0:19:47.730 –> 0:19:49.10
redacted: s47F - personal privac Jordyn
Awesome. Thank you so much.
0:19:49.210 –> 0:19:49.850
redacted: s47F - personal priva Rebecca
No worries.
0:19:51.500 –> 0:19:53.220
redacted: s47F - personal priva Rebecca
Does anyone else have any questions?
0:19:55.230 –> 0:19:55.710
redacted: s47F - personal priva Rebecca
Hi.
0:20:2.960 –> 0:20:3.160
redacted: s47F - personal priva Rebecca
Mm hmm.
0:20:3.520 –> 0:20:6.880
redacted: s47F - personal p Jennifer
When they’re in internal review, has exceeded 30 days.
0:20:8.400 –> 0:20:27.360
redacted: s47F - personal p Jennifer
And we haven’t done a 54 day request for an extension. Does that not mean that we no longer
have the ability to do a decision and that the principal or the CEO, whoever the principal person
officer, has deemed to have affirm the original decision?
0:20:29.210 –> 0:20:38.610
redacted: s47F - personal priva Rebecca
Oh yes, so this is the issue. We come back to this all the time. And So what you’re talking about
is functus officiary, which is a legal term that means without power.
0:20:40.450 –> 0:20:44.250
redacted: s47F - personal priva Rebecca
And I’ve I’ve been around the block on this one a few times.
0:20:45.610 –> 0:21:9.530
redacted: s47F - personal priva Rebecca
Because if everyone reads 15 A/C, you can actually see that we do become functors officio once
a request is deemed refused and we are technically without power to make a decision. Once
that happens, however, the FOI guidelines require us to make a decision, so it’s it’s a little bit
counterintuitive. My view would be the same rule applies for internal reviews.
0:21:9.850 –> 0:21:13.90
redacted: s47F - personal priva Rebecca
So if we are required to make a decision.
0:21:14.470 –> 0:21:24.950
redacted: s47F - personal priva Rebecca
We should do, you know, we should make that decision even once the request has fallen
overdue. So would you treat it the same as you would for a primary decision or an internal
review?
0:21:27.760 –> 0:21:28.640
redacted: s47F - personal priva Rebecca
I hope that’s clear.
0:21:32.810 –> 0:21:33.650
redacted: s47F - personal p Jennifer
Yep, thanks.
0:21:34.450 –> 0:21:34.810
redacted: s47F - personal priva Rebecca
Fact.
0:21:36.940 –> 0:21:37.740
redacted: s47F - personal priva Rebecca
Anyone else?
0:21:39.60 –> 0:21:39.660
redacted: s47F - personal priva Rebecca
Hi, Helen.
0:21:37.170 –> 0:21:41.10
redacted: s47F - personal Helen
Hi, Rebecca, it’s Helen and hi. How are you?
0:21:41.170 –> 0:21:41.810
redacted: s47F - personal priva Rebecca
Good. Thanks.
0:21:42.690 –> 0:21:54.330
redacted: s47F - personal Helen
I was just going to make a comment more than a question. I recently received an extension of
time from Oak on the basis that the request was complex and voluminous.
0:21:56.50 –> 0:22:1.330
redacted: s47F - personal Helen
And I explained why I hadn’t approached the applicant for an extension of time.
0:22:1.940 –> 0:22:2.140
redacted: s47F - personal priva Rebecca
Mm hmm.
0:22:2.770 –> 0:22:4.370
redacted: s47F - personal Helen
And that was around.
0:22:5.890 –> 0:22:7.930
redacted: s47F - personal Helen
The the nature of the applicants.
0:22:11.360 –> 0:22:11.560
redacted: s47F - personal priva Rebecca
Mm hmm.
0:22:8.840 –> 0:22:35.280
redacted: s47F - personal Helen
Previous engagements with us and that from that you know I could confidently say that it would
be an abusive response and not a helpful response and unlikely to be granted the extension of
time and that seemed to I got the extension of time but that could just be an example of you
know justifying why I hadn’t gone to the applicant first.
0:22:35.520 –> 0:23:6.680
redacted: s47F - personal priva Rebecca
Yeah, that is actually a really good example. Obviously, we need to assess each case on its
merits and chart out a different path for each case. Foi is often like a chooser and adventure,
and you can sort of go in many different paths. So definitely consideration of the applicant, the
previous engagement with the agency, and they’re likely response will inform sort of which way
you go, especially in that initial decision of, OK, well, do I go for a 15AA or do I go straight to a
15-AB?
0:23:7.980 –> 0:23:14.220
redacted: s47F - personal priva Rebecca
So I think that’s actually a really good example. And can I just ask how long did you get that EOT
for?
0:23:15.490 –> 0:23:16.770
redacted: s47F - personal priva Rebecca
How long was it granted for?
0:23:21.300 –> 0:23:22.260
redacted: s47F - personal priva Rebecca
Oh, are you there, Helen?
0:23:26.10 –> 0:23:27.250
redacted: s47F - personal priva Rebecca
You might be on mute.
0:23:28.130 –> 0:23:28.730
redacted: s47F - personal privacy Rebecca
Yes.
0:23:26.720 –> 0:23:35.840
redacted: s47F - personal privacy Helen
Sorry, I’m muted. I was saying I was saying I can’t recall off the top of my head, but it was a
decent amount of time. I think it was 14 days.
0:23:36.340 –> 0:24:6.20
redacted: s47F - personal privacy Rebecca
Yeah. So and that’s long enough. Like if you think about the number of cases that we sort of you
know, we finalise, you just need that extra week or that extra couple of days. It’s actually really
worth the, you know, the slight in administrative inconvenience. I’ve just you know filling out a
web form and getting that additional time. It is much better for the applicant and it’s much
better for the agency. So I really would encourage people really this is a sort of a key tool in your
FOI toolkit.
0:24:6.620 –> 0:24:9.620
redacted: s47F - personal privacy Rebecca
Understanding these provisions and using them effectively.
0:24:11.650 –> 0:24:12.170
redacted: s47F - personal privacy Helen
Thanks.
0:24:12.530 –> 0:24:14.970
redacted: s47F - personal privacy Rebecca
No worries. Any final questions or comments?
0:24:23.500 –> 0:24:24.540
redacted: s47F - personal privacy Laura
Jennifer has her hand up.
0:24:19.640 –> 0:24:27.0
redacted: s47F - personal privacy Rebecca
No. If not, we’re going to move on to a little quiz I’ve got and oh, sorry, I can’t say it. Hi, Jennifer.
Jump in.
0:24:24.900 –> 0:24:30.340
redacted: s47F - personal Jennifer
Sorry, sorry, but oh God. Now, what was I gonna say? Oh, yes.
0:24:32.700 –> 0:24:54.260
redacted: s47F - personal Jennifer
Can again, this is just it’s not a question, but just wanted something that I’d sort of noticed that
if you do get your 15AA agreed with my applicant or any of your EOTS to change legs, because if
you don’t change the due date on Lex, it will come up on our reporters as being deemed matter.
0:24:55.150 –> 0:25:13.790
redacted: s47F - personal privacy Rebecca
That is 100% correct. You need to make sure that your record keeping is up to date and reflects
any change to the status of the request. So I would really get in the habit of every time you’re in
doing a case, have lex open, make any comments or change any dates that you need to and
make sure that those dates do flow through.
0:25:15.110 –> 0:25:15.870
redacted: s47F - personal privacy Rebecca
It’s super important.
0:25:17.350 –> 0:25:24.310
redacted: s47F - personal privacy Rebecca
I’d also really encourage you, and I can’t stress this enough. As soon as you get the for 15AA.
0:25:24.630 –> 0:25:32.70
redacted: s47F - personal privacy Rebecca
As soon as you get the applicant’s consent, shoot it off to oak. Just make sure that you’re doing
that second step because it is vital.
0:25:33.430 –> 0:25:37.430
redacted: s47F - personal privacy Rebecca
I did see a case a couple of weeks ago.
0:25:37.470 –> 0:26:0.110
redacted: s47F - personal privacy Rebecca
Where the the OAC web form was submitted like four months later so the request had already
gone, deemed overdue and then four months later the person sent it off to OAC to change the
the statutory due date. There’s no point by that time, it’s already gone overdue again, so just
you need to action these things together. It’s a two-part process for 15 a A. It’s really important
that you understand that.
0:26:1.850 –> 0:26:6.730
redacted: s47F - personal privacy Rebecca
Especially for action officers, who I understand will probably be doing the bulk of the work for
these.
0:26:9.230 –> 0:26:19.110
redacted: s47F - personal privacy Rebecca
OK. Well, what we’re gonna do then is we’re gonna move on to a bit of a quiz. And today, I
would actually like the action officers to please answer the questions so.
0:26:20.510 –> 0:26:28.430
redacted: s47F - personal privacy Rebecca
I’m going to ask, I can’t actually see who’s put their hand up or anything, so I’ll actually ask
people to call out their, say their name and then they can answer the question.
0:26:32.720 –> 0:26:39.360
redacted: s47F - personal privacy Rebecca
So first question is how many types of eots deal with deemed refused requests?
0:26:47.70 –> 0:26:48.230
redacted: s47F - personal privacy Rebecca
Anyone jump in?
0:26:50.440 –> 0:26:51.520
redacted: s47F - personal privacy Rebecca
Action officers.
0:26:54.290 –> 0:26:56.170
redacted: s47F - personal privac Jessie
This is Jesse, is it 3?
0:26:56.660 –> 0:27:2.180
redacted: s47F - personal privacy Rebecca
It is 3 correct? Yeah, it’s 15 A/C.
0:27:2.380 –> 0:27:6.900
redacted: s47F - personal privacy Rebecca
54 No 51 da 3 and 54 three.
0:27:8.190 –> 0:27:13.670
redacted: s47F - personal privacy Rebecca
OK, on what day could you request A15ACE OT?
0:27:25.120 –> 0:27:27.600
redacted: s47F - personal privacy Rebecca
I’m on action. Officers jump in.
0:27:27.140 –> 0:27:28.20
redacted: s47F - personal privacy Elizabeth
This is Liz.
0:27:28.600 –> 0:27:29.680
redacted: s47F - personal privacy Rebecca
Hi Liz. Go ahead.
0:27:29.880 –> 0:27:33.280
redacted: s47F - personal privacy Elizabeth
After the statutory time frame has expired, so after the 30 days.
0:27:32.190 –> 0:27:38.950
redacted: s47F - personal privacy Rebecca
Yes, that’s right. Yeah. Literally the day after the day, it goes the day after it goes over to you.
You can request A15AC.
0:27:41.440 –> 0:27:51.360
redacted: s47F - personal privacy Rebecca
But you’d also want to think about when you request the 15. I say because as I said, you can
only get one once, so you want to make sure that you have all your ducks in a row before you
request it.
0:27:53.30 –> 0:28:6.950
redacted: s47F - personal privacy Rebecca
OK. Third question, you need to assess A2. A 12145 page documents to meet a statutory due
date six days away, which EO TS could you request?
0:28:12.200 –> 0:28:13.360
redacted: s47F - personal privacy Mykal
15-AB.
0:28:13.860 –> 0:28:45.860
redacted: s47F - personal privacy Rebecca
Yeah. For that one, I would you could request A15AA or A15-AB, but in this situation I would go
straight to the 15 AB 12145 pages is a very large document. I would also seriously consider
doing a practical refuse or notice if you possibly could, but if the person needs that information
and you are able to to do it, I would definitely be seeking the additional time. I think that this
one is actually applicable to a large portion of the case load.
0:28:45.900 –> 0:28:48.380
redacted: s47F - personal privacy Rebecca
And I would really, really be encouraging you. Encouraging.
0:28:48.900 –> 0:28:54.260
redacted: s47F - personal privacy Rebecca
You all to think about what you could do with that extra period of time. It’d be great if we could
keep.
0:28:53.440 –> 0:28:56.40
redacted: s47F - personal privacy Mykal
Although reality, you should have rescripted before then.
0:28:56.470 –> 0:29:19.670
redacted: s47F - personal privacy Rebecca
Yeah, ideally you that would be the that would be the best possible outcome is to re Skype. But
unfortunately sometimes people are just insistent that they want their whole file and they will
not rescope. And if in that situation if it’s decided that a practical review is on is not appropriate
for whatever reason, then I would definitely be seeking the additional time.
0:29:20.180 –> 0:29:33.340
redacted: s47F - personal privacy Rebecca
And in your comments to oak, you could say that the, you know, the agency acknowledges the
importance of this information to the applicant and there has therefore decided to process the
request. However, we require more time to do so.
0:29:34.820 –> 0:29:44.380
redacted: s47F - personal privacy Rebecca
And I think that’s sort of a fairly sort of justifiable outcome. SO15-AB is going to be incredibly
useful for people doing those large personal access requests.
0:29:45.520 –> 0:29:53.360
redacted: s47F - personal privacy Rebecca
All right, question four, should you wait for the OAIC to respond to an ERT request before
releasing the decision?
0:29:55.360 –> 0:29:59.880
redacted: s47F - personal privacy Megan
Alright, you shouldn’t because it’s time will keep ticking anyway.
0:30:0.340 –> 0:30:2.380
redacted: s47F - personal privacy Rebecca
Yeah, that’s right. Just go ahead.
0:30:3.700 –> 0:30:29.500
redacted: s47F - personal privacy Rebecca
I’ve known oasa to take up to two weeks to respond to an EOT request, but which case?
You
know, the the request is even more horribly out of due date, so just don’t wait. Go ahead. But
it’s better if you can give them as much time as possible. So if you know a request, say 15-AB
if you know it’s due in in seven days, get your EOT request in early enough for them to be able to
respond.
0:30:37.720 –> 0:30:38.400
redacted: s47F - personal Jennifer
Rebecca.
0:30:30.710 –> 0:30:39.310
redacted: s47F - personal privacy Rebecca
And then sort of just keep processing along, but you should never stop processing because
you’re waiting for an EO team. Just keep going, yes.
0:30:40.710 –> 0:30:41.670
redacted: s47F - personal privacy Rebecca
Hi, Jennifer. Yep.
0:30:40.80 –> 0:30:42.240
redacted: s47F - personal Jennifer
Jennifer again, sorry.
0:30:52.220 –> 0:30:52.420
redacted: s47F - personal privacy Rebecca
Mm hmm.
0:30:42.320 –> 0:30:53.920
redacted: s47F - personal Jennifer
Hey so I have a matter that I can release today that’s deemed and I put in a 15 A/C request to
oak a week and 1/2 ago and I haven’t still haven’t heard back.
0:30:55.440 –> 0:30:57.920
redacted: s47F - personal Jennifer
But I want to release it.
0:30:58.560 –> 0:31:12.400
redacted: s47F - personal Jennifer
So what I was going to do or have done, I haven’t checked the decision notice yet is advise the
applicant that and I also had communicated with the applicant to say this is what I can do to
bring it back in time to.
0:31:16.150 –> 0:31:16.550
redacted: s47F - personal privacy Rebecca
Yep.
0:31:19.410 –> 0:31:19.610
redacted: s47F - personal privacy Rebecca
Mm hmm.
0:31:13.650 –> 0:31:35.770
redacted: s47F - personal Jennifer
Reinvigor internal review, as would you like me to go ahead, which she has said yes, please. So
the best I can do, I think I think you might correct me, but what I’m thinking is I put in the
decision letter that I have. I lodged the application. I haven’t heard back yet. So at this stage I
can’t confirm whether your internal review rights have been reinstated.
0:31:37.130 –> 0:31:39.810
redacted: s47F - personal Jennifer
However, your external review rights are still valid.
0:31:40.890 –> 0:31:48.850
redacted: s47F - personal privacy Rebecca
That is a. That’s a reasonable approach. What I would suggest you do before that is pick up the
phone and call. Oh, I can tell them that you need a response today.
0:31:48.160 –> 0:31:50.680
redacted: s47F - personal Jennifer
Oh, I didn’t know. I don’t even know how to do that.
0:31:50.580 –> 0:31:55.580
redacted: s47F - personal privacy Rebecca
Yeah, you can definitely do it. You can definitely pick up the phone and call them. Yep.
0:31:54.400 –> 0:32:6.320
redacted: s47F - personal Jennifer
OK. Yeah, well, that’s a good. Yeah. Well, I’ll, I’ll get. I’ll do that. But failing, failing, getting a
response. I just wanted to make sure. ’cause. This is a particularly frequent applicant. Yeah.
0:32:7.580 –> 0:32:7.900
redacted: s47F - personal Jennifer
Yeah.
0:32:5.270 –> 0:32:21.70
redacted: s47F - personal privacy Rebecca
Yeah, I think that’s reasonable. I mean we, you know, we’re trying. We’re making every effort to
restore their internal review rights, but if we’re not able to, they do have that external review.
So I think that’s a reasonable approach. It’s informs the applicant.
0:32:27.80 –> 0:32:27.960
redacted: s47F - personal Jennifer
Oh, thanks.
0:32:32.660 –> 0:32:33.980
redacted: s47F - personal Jennifer
Yep. OK. Thanks.
0:32:22.950 –> 0:32:37.910
redacted: s47F - personal privacy Rebecca
Yeah, I think that’s, you know, a reasonable person would say that that’s a fair outcome. So I
think, yeah, I think that’s a good approach, but definitely try and call out and see if you can get
them to actually do do it. Yep. Don’t hold the don’t hold the requester keep keep it moving.
Yeah.
0:32:36.520 –> 0:32:39.400
redacted: s47F - personal Jennifer
No, no. I wanna keep her happy.
0:32:39.770 –> 0:32:46.290
redacted: s47F - personal privacy Rebecca
Yeah. And if afterwards if Owaq do decide to grant you the.
0:32:46.650 –> 0:32:56.650
redacted: s47F - personal privacy Rebecca
The ERT, after it’s released, you can actually then go back into Lex, reopen the request to change
the due date. Like change the. Yeah, you can change the due date and then close it again.
0:32:57.490 –> 0:32:59.970
redacted: s47F - personal Jennifer
Oh, OK, yeah, OK.
0:33:1.270 –> 0:33:2.110
redacted: s47F - personal Jennifer
Yes.
0:33:3.950 –> 0:33:4.630
redacted: s47F - personal Jennifer
Yes.
0:32:57.490 –> 0:33:11.170
redacted: s47F - personal privacy Rebecca
Sorry, that’s an option too, because remember Lex is just a reflection of the administrative law
that has occurred, and so you can make changes, but generally you would only do that in
extreme situations such as this one.
0:33:11.470 –> 0:33:11.750
redacted: s47F - personal Jennifer
No.
0:33:12.700 –> 0:33:20.380
redacted: s47F - personal privacy Rebecca
OK everyone, question 5. How many eots can you theoretically use on one access request?
0:33:26.530 –> 0:33:27.10
redacted: s47F - personal privacy Rebecca
Yes.
0:33:25.160 –> 0:33:27.440
redacted: s47F - personal privacy Elizabeth
Hey, this is Liz.
0:33:27.560 –> 0:33:29.440
redacted: s47F - personal privacy Elizabeth
The the other Liz.
0:33:30.440 –> 0:33:35.840
redacted: s47F - personal privacy Elizabeth
I think it you could apply you could ask for one everyday theoretically, but you probably
wouldn’t.
0:33:36.100 –> 0:33:38.60
redacted: s47F - personal privacy Rebecca
Oh sorry, I meant each type so.
0:33:39.430 –> 0:33:39.830
redacted: s47F - personal privacy Elizabeth
Oh.
0:33:39.780 –> 0:33:44.940
redacted: s47F - personal privacy Rebecca
You could you could ask. Well, yes, you could possibly ask for EO Ts every day. It may not sort of
when you.
0:33:44.680 –> 0:33:47.920
redacted: s47F - personal privacy Elizabeth
I I don’t think. Yeah, you wouldn’t. You wouldn’t do it that way? Probably.
0:33:51.330 –> 0:33:51.410
redacted: s47F - personal privacy Elizabeth
Ah.
0:33:48.180 –> 0:34:3.260
redacted: s47F - personal privacy Rebecca
No, but I think with this one, what I meant was that you can ask for a 15 a AA15-AB and A15AC
in succession. So theoretically you could you have all three on one access request.
0:34:4.450 –> 0:34:9.450
redacted: s47F - personal privacy Rebecca
You’d have to really justify the use of all three of them, but theoretically you can do that.
0:34:10.730 –> 0:34:21.370
redacted: s47F - personal privacy Rebecca
All right. Question six, you are dealing with a difficult multi party consent issue for an access
request. So what type of EOT might be appropriate?
0:34:24.230 –> 0:34:25.30
redacted: s47F - personal privacy Mykal
15-AB.
0:34:24.90 –> 0:34:25.450
redacted: s47F - personal privacy Elizabeth
I can have a go at that.
0:34:26.430 –> 0:34:27.350
redacted: s47F - personal privac Jessie
15 maybe.
0:34:29.300 –> 0:34:29.340
redacted: s47F - personal privacy l, Brett I.
0:34:29.60 –> 0:34:30.60
redacted: s47F - personal privacy Mykal
Michael, sorry.
0:34:26.780 –> 0:34:34.140
redacted: s47F - personal privacy Rebecca
Yes. Whoever said 15 AB is correct. Yep. Excellent work. 15-AB is definitely the right one for that
one.
0:34:35.910 –> 0:34:42.70
redacted: s47F - personal privacy Rebecca
#7 what 2 steps need to occur for A15AA EOT to be granted?
0:34:47.200 –> 0:34:47.920
redacted: s47F - personal privacy Megan
Is that?
0:34:47.160 –> 0:34:49.160
redacted: s47F - personal privacy Mykal
It’s mark. Oh, don’t Megan.
0:34:48.990 –> 0:34:50.590
redacted: s47F - personal privacy Megan
Sorry, no, you go.
0:34:51.220 –> 0:34:56.820
redacted: s47F - personal privacy Mykal
Oh, it’s Michael again. Just basically, you gotta ask for 15AA and have it in writing.
0:34:57.620 –> 0:34:59.900
redacted: s47F - personal privacy Rebecca
That’s right. And the second step is.
0:35:0.840 –> 0:35:2.40
redacted: s47F - personal privacy Megan
Have their consent.
0:35:5.290 –> 0:35:6.330
redacted: s47F - personal privacy Mykal
Do the web form.
0:35:2.880 –> 0:35:7.160
redacted: s47F - personal privacy Rebecca
Yeah. And keep going. What’s the next bit, different data file or whack?
0:35:5.260 –> 0:35:9.660
redacted: s47F - persona , Billie-Jo You must contact awak apply to awak, yeah.
0:35:5.240 –> 0:35:9.840
redacted: s47F - personal privacy Elizabeth
Change the update the clock. Yes, you have to notify Owak it’s.
0:35:9.660 –> 0:35:10.860
redacted: s47F - personal privacy , Brett Give right. Honest. Yeah.
0:35:11.460 –> 0:35:12.340
redacted: s47F - personal privacy Megan
Nice teamwork.
0:35:9.710 –> 0:35:18.390
redacted: s47F - personal privacy Rebecca
Yeah, two parts get the consent in writing notify. Oh, ack. You have to do that. OK, great. And
then record it on the file.
0:35:19.710 –> 0:35:22.590
redacted: s47F - personal privacy Rebecca
And final question, true or false?
0:35:23.890 –> 0:35:27.130
redacted: s47F - personal privacy Rebecca
Eots enable better case management outcomes.
0:35:29.330 –> 0:35:58.690
redacted: s47F - personal privacy Rebecca
True, no question about that one. It definitely gives us more options. So please, please build
them into your arsenal. They are very, very much worth spending time on and you can decide in
your sort of decision making action officer partnerships, who’s going to do it and who’s going to
monitor it and track it and all of that bit. But it’s really important that you start having
conversations and have them early. So really you want to be sort of thinking around sort of the 21 day mark like do I need an AOT on this?
0:35:59.950 –> 0:36:31.390
redacted: s47F - personal privacy Rebecca
And then thinking about, OK, who’s gonna lodge the form? How are we gonna do this?
And
especially with the 15 Ai’s, you’re going to get better results if you write a personal e-mail
explaining to them where you’re up to, what you’re doing, what you need, then rather relying
on the sort of line or two that’s included in the acknowledgement letter that probably no one
reads. So please just really think about this. It’s important. It’s it’s good for us. It’s good for the
applicant. And I think especially with the caseload that we’ve got at the moment.
0:36:31.980 –> 0:36:41.100
redacted: s47F - personal privacy Rebecca
Getting that extra time to deal with those sort of larger, complex matters is going to just pay
dividends for you as case officers. So please, please think about it.
0:36:42.920 –> 0:36:45.440
redacted: s47F - personal privacy Rebecca
All right, that is the end of today’s training.
0:36:46.920 –> 0:36:51.640
redacted: s47F - personal privacy Rebecca
I’m very happy to take any further questions or discuss any cases that people might have.
0:36:53.0 –> 0:37:2.40
redacted: s47F - personal privacy Rebecca
Otherwise, I’d just like to thank you very much for your time and your participation and happy
to stand the line if anyone wants to chat about aots.
FOI 25/26-2150 DOCUMENT 8
Training video - Extensions of Time under the FOI Act
`redacted: s47F - personal privacy`with Rebecca - 2024.04.17
`redacted: s47F - personal p`Training video - Extensions of Time under the FOI Act with Rebecca - 2024.04.17.mp4
0:02 Press record.
0:05 Good morning, everyone, and welcome today to FOI training. Today we’re gonna be looking at extensions of time.
0:14 So the Freedom of Information Act provides 30 days to process access, amendment, and internal review requests. This is a statutory time frame at which means that compliance is required by law in recognition that some requests require more work than others. The Act contains 5 provisions to extend the statutory time frame of a request or a review. These are 15-A and Extension of Time with Applicant Agreement 15 AB and Extension of Time
0:44 of Complex or Voluminous matters, 15 AC and Extension of time for deemed refused access requests 51 D,A3 an extension of time for deemed refused amendment Requests and 54D3 and extension of time for deemed refused internal reviews.
1:05 As you can see, the five provisions cover most eventualities, so it’s incredibly important that case officers understand that FOIA requests should never fall overdue without an EOT request having been made.
1:20 We’ll go through each of the EOT provisions 1 by 1, starting with 15-8 AA, which is the most commonly used one, and this is an EOT with agreement of the applicant.
1:32 The guidelines provide quite a bit of really helpful guidance on this one, and they can be found at 3.146 to 3.149. The key features are that you must request the EOT within the statutory time frame. This can 15AAs can only be used for access requests, and you can only extend the time frame by a total of 30 days, but you can do that in multiple parts. For example, you can first
2:03 goal seek 14 days and then seek the additional time. So you can do it in two blocks, or you can even do it in seven day blocks depending on what you need. Now to get a 15-A you must have both the agreement of the applicant in writing and you must have notified that agreement to the OAIC. So you must do both things for this to stand. If you only get the applicants agreement but don’t notify OAIC, it does not work. OK. So it really make sure you understand that
2:35 right
2:36 now, in terms of processing your 15 AA, the first step is to write to the applicant requesting further time to process the request. Best practise is to write to the applicant at least seven days in advance of the approaching deadline to provide an update on the case. So what? Where are you up to? Have you done search and retrieval? Are you assessing the documents? Are you consulting on the documents? Explain how the additional time will be used. For example, we’re going to complete assessment. Or do internal consultation
3:08 only request the time you need to complete the request.
3:12 You will have far better luck being granted A-15 AA if you request 7 or 14 days, rather than just going for the full 30.
3:21 It’s also really important that you provide a new date and make sure that you meet it
3:26 and because that builds confidence in the agency and our decision making processes. Once you’ve completed that step, the second step is to notify the OAIC via its web form as soon as practicable within the guidelines, but as soon as you receive the response, and you do need to provide evidence of the applicant’s consent, which is that they’ve provided to you in writing.
3:54 The next type of of EOT is a 15 AB, and this is the one that we use for complex or voluminous matters.
4:03 Again, the FOI guidelines are incredibly instructive at 3.150 to 3.155. The key features of this type of EOT again, is that you must request the EOT within statutory timeframe.
4:17 You should only request at this type of EOT after you have obtained or attempted to obtain a 15AA, and that is contained in the FOI guideline. So they’re very big on this being a secondary EOT.
4:32 It’s not 100% um. There will be circumstances when you can demonstrate that there was a reason you didn’t get a 15 AA first, but certainly that is the intent of the FOI guidelines. Now this type can only be used for complex or voluminous access requests, so you need to be able to justify that it is a a more complex matter or larger or more complex matter than a standard FOI request. There is no limits on the length of time or the number of 15 AB EOT
5:03 that can be granted, but you must be able to justify your planned use of time to OAIIC because they will decide whether or not it’s granted and how long you get to for your extension of time.
5:17 Uh, the request is made directly to OAK via its web form and in terms of processing it, as I mentioned before, ideally you’ve already sort of 15 AA or engaged with the applicant on scope and you need to complete the OIAC web form outlining the applicants details, details of any previous EOT requests for the 15 a a timeline of the work already completed. So you can just do that in dot point. So you can say search and retrieval done On this date, assessment
5:47 On this date, internal consultation On this date. You can really just do it in dot points as long as it’s clear that work has been progressively done on the request reasons. Why the request is complex or voluminous. So you’re gonna have to explain like
6:01 it’s either going to be there’s a very large number of folios that need to be assessed and I need more time to do the work. Or the matter is complex For these reasons. And that might be that it spans several internal business areas requiring sort of consultation with a number of different people and a number of different documents. So just need to really justify that complexity.
6:25 You need to be able to identify any other parties involved, including external third parties. And you need to include a statement as the measures to ensure the request is completed by the extended due date because OAIC will therefore monitor that you have actually completed the request by that date. So I would suggest for that last point that perhaps collectively the management of the FOI team sort of work out a form of words
6:56 and and and a way of um ensuring that 15 AB’s are met. So that might be requiring weekly reporting to an Assistant Director on case progress or having even like a regular sort of EOT meeting to make sure that those cases are moving forward. So it builds some governance processes around that to make sure that we’re really hitting that mark.
7:21 The next type of EOT is a 15 AC, and this one is for deemed to refused access requests. The guidelines are instructive at 3.162 to 3.165. Now this type of EOT can only be requested after the statutory timeframe has expired. It only applies to access requests, It can only be granted once.
7:45 There is no limit on the length of time that can be granted, but you must be able to justify your planned use of time. Again, the request is made directly to OAIC it’s web form and this one is really great because it actually negates a deemed refusal. So if you have a request that has fallen outside of statutory timeframes and is therefore subject to 15AC , if you are granted A15A EOT, it actually makes it so the request never was overdue
8:15 and was in time the whole time.
8:19 So you may in this circumstance, have a request that the statutory time frame is, say, 45 days instead of 30
8:29 or even longer. The longest one I’ve ever seen granted was about 40 days after the original statutory due date, and for that one it was because their request required external consultation with the party who was overseas.
8:44 Um. So in that site, in that situation, I agreed that we needed that additional time. So you’re gonna have to have pretty strong justification
8:52 in terms of processing it. Ideally you’ve already sought A15AA or A15AB or even both and engage with the applicant on Scope. It’s incredibly important to argue that that you can demonstrate that you have been actively working on the case the whole time. You would need to complete the OAIC web form outlining the applicants details, previous extension of time requests, a timeline of the work already completed on the request,
9:21 a statement as to the scope and complexity of the request, um, you need to identify any other parties involved and again include those measures to ensure the request is completed by the extended due date.
9:37 We move now to 51 DA, which is deemed refusal of an amendment request.
9:44 So the FOI guidelines speak to this. That’s 7.181 to 7.182. This one is slightly different. It does not have a equivalent to a 15-AA or A15A A/B. You can only request an extension on an amendment once that request has fallen overdue.
10:04 Um. You can only receive one EOT for this type of request, and the FOI guidelines at 7.82 actually tell us that it is unlikely that the request will be granted for more than 30 days. The request is made directly to inquire its web form, and again, it negates the deemed refusal. So if you are granted this form of EOT, it’s like it was never overdue.
10:31 Unfortunately, if you then fall overdue of your EOT, there’s no further recourse. You cannot fix that. You’re just going to be overdue
10:39 in terms of processing. You need to seek the applicants informal consent for the additional processing time.
10:46 This is an interesting requirement that’s included in the FOI guidelines. It’s not a formal requirement, but it is strongly suggested and it’s probably you know. Quite a good part of case management is to keep your applicant updated. If you believe your request is going to require additional time anyway,
11:04 you then complete the OAIC web form outlining the applicants details. Previous EOT requests actually won’t be any previous EOT requests in this one, so disregard that. A timeline of the work already completed. Any other parties involved and that might be a situation where you’ve got an external party seeking FOI subjects applicant information rather and and there’s you know potentially consent issues at play and again measures to ensure the request is completed
11:34 had extended due date
11:38 and the final type of EOT that is available is a 54D which is the deemed refused internal reviews.
11:47 So the guidelines cover this In 9.43 to 9.51 you again you can only request the EOT after the statutory timeframe for the internal review has expired. It can only be granted once, there is no limit on the length of the EOT but again you must be able to justify your planned use of time. Unable to secure our OAICs agreement, the request is made directly to OAIC via its web form.
12:16 In my experience, this one is used to justify time required for external consultations because the Act does not provide extra time for review consultations.
12:27 And again, this one negates the deemed refusal, so it actually just cancels it out
12:32 in terms of processing. Again, ideally you’ve engaged with the applicant regarding the processing delay. So I said you know, I’ve got your internal review, I am working on it. However, it’s been delayed. For these reasons, I intend to seek an extension of time from OAIC to enable me to complete the request. Just keep the It’s really important to keep your applicant updated
12:56 and then you complete the OAIC web form outlining the applicants details previous EOT requests. Even during the original decision, you need to include that to demonstrate that you have, you know, been working within the provisions of the act. Where possible
13:12 a timeline of the work already completed. Outline any other parties involved. Measures to include the request is completed by the extended due date again.
13:25 So there’s a number of benefits to EOT, but the three principle ones are that it maintains the applicants internal review rights and this is a win win. The applicant gets a faster review decision and the NDIA gets to quickly identify and correct any processing errors. So the situation that might apply in this one is if the applicant believes that we haven’t done reasonable searches and we’re able to quickly go in, redo the searches, see if that that is the correct,
13:55 UM, decision or not, and then redo the decision if we need to.
14:01 It also enables better customer service experience for our participant, participant, and applicants because they’re able to deal directly with the agency rather than a third party, for example OAIC. It also preserves I’s attention for more serious if I matters,
14:18 the second benefit is that it promotes statutory compliance. It upholds the objects of the FOI Act via timely decision making. It promotes public value via government transparency and accountability. And it recognises that requests differ in size and complexity and gives us provisions to deal with those issues.
14:39 It also promotes applicant engagement in the FOI process. It encourages the NDIA to communicate with the applicant and OAIC throughout the decision making which will result in best better customer service experience and also promote understanding of the FOI complexity and processes
14:59 and also it can be combined with request consultation.
15:07 So the key learnings from today’s session are that EOT’s are part of good case management practise. You should only request the time that you actually need to finalise a request. Longer requests are definitely more likely to be refused. So really think about what you need versus what you can have. You can apply for more than one type of EOT per request
15:30 and you will need to present detailed and persuasive reasons to be granted an EOT. Just saying that you weren’t able to action the request due to competing priorities or other cases is unlikely to be sufficient. You must include information about EOT requests and your decision letter even if your request was refused, So must say. On this date, I haven’t requested a 15AA. You declined to grant it. On this day. I went to the OIC to request a 15AB
16:01 that day it was granted On this date. The new statutory date for this request was subsequently and then you enter the new date. So you need to include those details in your decision letter.
16:13 You must record all EOT decisions, records, and correspondence in the relevant case file and in Lex.
16:21 And you really should take time to read the FOI guidelines because they’re incredibly helpful and instructive.
16:32 As mentioned earlier, FOI request should never fall outside of statutory time frames without at least one EOT request,
16:41 and I do not personally count the automatic 15 AA request in the acknowledgment letter as part of that.
16:51 I think if you think this request is gonna go overdue, you need to go above and beyond to try and find a way to get an EOT to keep it in statutory time frames.
17:03 Any questions?
17:13 You might have to call out names because I can’t see, um, if any hands are up.
17:18 Sure my name is Jesse. I have a question. Sure, go ahead Jesse. I was wondering if you could give an example as to when you would need to use the 51 DA extension.
17:30 So 51DA extension obviously is for amendment requests that have fallen overdue. So that might be in a situation where you were doing, you had maybe a third party consultation that you were waiting on and the requested for an overdue because that person had not responded to you in time. So you would seek, say, an additional 14 days to allow that response to come in and to be actioned.
17:56 Thank you.
17:58 Any other questions?
18:00 Hi, Um, my name’s Jordan. I’ve got a bit of a question. Sure. Uh, I’m working on a few matters at the
moment that are like 90 plus days overdue. Would you recommend going to OAIC for those ones as well to get an extension? But it’s hard for those ones because I don’t really have a great reason for it going overdue because I only just got assigned to them like last week. So, yes, and I look,
18:26 yeah, this is an issue, UM, with the legacy caseload, UM,
18:34 in those situations, I personally would not because as I said, you’re going to need to be able to justify to OAIC that you had been consistently working on the case the whole way through to get the EOT.
18:48 So my view is that they probably would not grant it unless you could show that you know the request had been had that level of sort of work,
18:58 um, you can try on the basis that it preserves the applicants review rights and therefore it’s a it’s a better customer service outcome for the applicant if that EOT is granted. But my personal experiences,
19:13 yeah, unless it’s been pretty consistent work on the request, you probably won’t be granted it. So it’s one of those decisions you’d need to talk about to your with your AD, really discuss the sort of pros and cons of going for the 15 A/C and then sort of make an informed decision.
19:33 I know Peter has a slightly different view. He believes that preserving those 15 AC review rights is a, you know, really important and therefore it’s worth putting in that application. But my experiences, we’ve been in my previous role. We were knocked back several times for those longer cases where they hadn’t been consistent casework.
19:52 Awesome. Thank you so much, No worries
19:56 Does anyone else have any questions? Hey, back, it’s Jennifer here. Hi. Hey. Hi. I just have a question in terms of internal reviews. So when the internal review has exceeded 30 days.
20:13 And we haven’t done A54D request for an extension. Does that not mean that we no longer have the ability to do a decision and that the principal or the CEO or the principal person officer has deemed to have affirmed the original decision?
20:34 Ah, yes. So this is the issue. We come back to this all the time. And So what you’re talking about is functus officio, which is a legal term that means without power.
20:45 And I’ve been around the block on this one a few times, because if everyone reads 15 AC, you can actually say that we do become functus officio once a request is deemed refused, and we are technically without power to make a decision once that happens. However, the FOI guidelines require us to make a decision, so it’s it’s a little bit counterintuitive. My view would be the same rule applies for internal reviews.
21:14 So if we are required to make a decision, um,
21:19 we should do, you know we should make that decision even once the request has fallen overdue.
21:25 Um. So would you treat it the same as you would for primary decision or an internal review?
21:32 I hope that’s clear.
21:37 Yep. Thanks.
21:43 It’s Helen. Helen, Hi. How are you?
21:47 I was just going to make it comment more than the question. Um. I recently received an extension of time from OAIC on the basis that the request was complex and voluminous. Hmm. And I explained why I hadn’t approached the applicant for an extension of time
22:07 and that was around
22:10 the the nature of the applicants previous engagements with us and that from that, you know, I could confidently say that it would be a an abusive response and not a helpful response and unlikely to be granted the extension of time. And that seemed to I I got the extension of time. But that could just be an example of you know, justifying why I hadn’t gone to the applicant first. Yeah, that is actually a really good
22:42 example. Um, obviously we need to assess each case on its merits and chart out in different path for each case. FOI is often like a choose your own adventure and you can sort of go in many different paths. Um. So definitely consideration of the applicants, their previous engagement with the agency and they’re likely response will inform sort of which way you go, especially in that initial decision of, OK, well, do I go for a 15 or do I go straight to a 15-AB.
23:12 So I think that’s actually a really good example. And can I just ask, um, how long did you get that EOT for?
23:20 How long was it granted for
23:26 Are you there Helen
23:31 might be on mute. Sorry, I’m muted. Yeah. I was saying. I was saying, I can’t recall off the top of my head, but it was a decent amount of time. I think it was 14 days. Hmm. Yeah. So and that’s long enough. Like if you think about the number of cases that we sort of, you know, we finalised, you just need that extra week or that extra couple of days, it’s actually really worth the, you know, the slight administrative inconvenience of just filling out a web form and getting that additional time. It is much better for the applicant
24:02 and it’s much better for the agency. So I really would encourage people to really, this is a sort of a key tool in your FOI toolkit, understanding these provisions and using them effectively.
24:15 Yeah,
24:16 thanks. No worries. Any final questions or comments?
24:24 No. If not, we’re gonna move on to a little quiz I’ve got.Jennifer has her hand up. Sorry, Sorry. Hi, Jennifer. Jump in.
24:33 God no. What was I gonna say
24:36 can. Um again, this is just um. It’s not a question, but just one of something that I’d sort of noticed that if you do get your 15-AA agreed with by applicant or any of your EOT to change Lex, because if you don’t change the due date on Lex it will come up on a reporters as being deemed matter. That is 100% correct. You need to make sure that your record keeping is up to date and reflects any change to the status of the request.
25:08 So I would really get in the habit of every time you’re in, um, doing a case, have Lex open, make any comments or change any dates that you need to, and make sure that those dates do flow through.
25:19 It’s super important.
25:22 Um, I’d also really encourage you and I I can’t stress this enough,
25:26 As soon as you get the 15-AA, as soon as you get the applicants consent, shoot it off to OAIC. Just make sure that you’re doing that second step because it is vital.
25:37 I did see a case a couple of weeks ago
25:41 where the UH, the OAIC web form was submitted like four months later, so the request had already gone deemed overdue. And then four months later the person sent it off to OAIC to change the the statutory due date. There’s no point by that time it’s already gone over to you again. So just you need to action these things together. It’s a two part process for 15 AA. It’s really important that you understand that,
26:06 especially for action officers, who I understand will probably be doing the bulk of the work for these.
26:14 OK, well, what we’re going to do then is we’re going to move on to a bit of a quiz. And today I would actually like the action officers to please answer the questions. So I’m going to ask, I can’t actually see who’s got their hand up or anything. So I’ll actually ask people to call out there, say their name, and then they can answer the question.
26:37 So first question is how many types of EOT’s deal with deemed refused requests?
26:52 Anyone jump in
26:55 action, officers?
26:59 Um, this is Jesse, is it three? It is 3, correct? Yeah, it’s 15 AC
27:06 54 No, 51 D A3 and 54 three.
27:13 OK. On what day could you request A-15 AC, EOT?
27:30 I’m on action. Officers champions. Liz. Hi, Liz. Go ahead. After the statutory timeframe has expired. So yes, that’s right. Yeah, Literally the day after the day it goes. The day after it goes over to you, you can request A15C,
27:46 but you’d also want to think about when you request the 15 AC because as I said, you can only get one once, so you want to make sure that you have all your ducks in a row before you request it.
27:58 OK, third question, you need to assess a 1245 page documents
28:05 to meet a statutory due date six days away. Which EOT could you request?
28:17 15 AB? Yeah, for that one I would You could request A15AA or A15AB, but in this situation I would go straight to the 15 A/B. 1245 pages is a very large document. I would also seriously consider doing a practical refusal notice if you possibly could. But if the person needs that information and you are able to to do it, I would definitely be seeking the additional time. I think that this one is actually applicable
28:48 to a large portion of the caseload and I would really really be encouraging you all to think about what you could do with that extra period of time. It’d be great if reality you should have described it before then yeah, ideally that would be that would be the best possible outcome is to re scope. But unfortunately, sometimes people are just insistent that they want their whole file and they will not re scope. And if in that situation, if it’s decided that a practical refuse or is not
29:18 appropriate for whatever reason, then I would definitely be seeking the additional time. And in your comments to OAIC you could say that the you know the agency acknowledges the importance of this information to the applicant and there has therefore decided to process the request. However, we require more time to do so,
29:39 and I think that’s sort of a fairly sort of justifiable outcome. So 15AB is going to be incredibly useful for people doing those large personal access requests.
29:50 All right, question four, Should you wait for the OAIC to respond to an EOT request before releasing the decision?
30:00 Alright, you shouldn’t. Um, because it’s time will keep ticking anyway. Yeah, that’s right, just go ahead. Um. I’ve known OAIC to take up to two weeks to respond to an EOT request. By which case you know the the request is even more horribly out of due date, so just don’t wait. Go ahead. But it’s better if
you can give them as much time as possible. So if you know a request, say 15 AB, if you know what’s due in in seven days, get your
30:31 EOT request in early enough for them to be able to respond, UM, and then sort of just keep processing along. But you should never stop processing because you’re waiting for an EOT.
30:42 Rebecca. Yes. Jennifer again. Sorry. Um, hey. So I have a matter um that I can release today. That’s deemed. And I put in a 15 AC request to OAIC a week and a half ago and I haven’t still haven’t heard back, but I want to release it. So what I was going to do or have done, I haven’t checked the decision notice yet is advise the applicant that and I also had a communicated with the applicant
31:13 say this is what I can do to bring it back in time to um rerevoke your internal review rights. Would you like me to go ahead which she has said yes please. So the best I can do I think. I think you might correct me but what I’m thinking is I put in the decision letter that I have. I lodged the application. I haven’t heard back yet. So at this stage I can’t confirm whether you’re internal review rights have been reinstated. However, your external review rights are still
31:44 valid. Hmm. That is a that’s a reasonable approach. What I would suggest you do before that is pick up the phone and call OAIC and tell them that you need a response time. I didn’t know. I don’t even know how to do that. Yeah, you can definitely do it. You can definitely pick up the phone and call them. OK Yeah. Well, that’s a good. Yeah. Well, I’ll do that. But failing, failing, getting a response, I just wanted to make sure because this is a particularly frequent applicant. Yeah, I think that’s reasonable. I mean, you know, we’re trying. We’re making
32:14 every effort to restore their internal review rights, but if we’re not able to, they do have that external review. So I think that’s a reasonable approach. It’s informs the applicant.
32:27 Yeah. I think that’s you know a reasonable person would say that that’s a fair outcome. Ohk. So I think, yeah, I think that’s a good approach. But definitely try and call OAIC and see if you can get them to actually do do it. Yep. OK. Thanks. Yep. Don’t hold the. Don’t hold the request. No. Keep it moving. Yeah. No. I wanna keep it happy. Yes. And if afterwards, if I do decide to grant you the
32:51 the EOT after it’s released, you can actually then go back into Lex, reopen the request to change the due date. Like change the yeah, you can change the due date and then close it again.
33:02 OK, that’s an option too. Because remember, Lex is just a reflection of the administrative law that has occurred. Yeah and um, so you can make changes. But generally you would only do that in extreme situations such as this one, no? OK everyone, question 5. How many Eots can you theoretically use on one access request?
33:30 Hey, this is Liz. Yeah, the the other Liz. Um,
33:35 I think it you could apply, you could ask for one everyday theoretically, but you probably wouldn’t .Ahh sorry, I meant each types. So you can ask. Well, yes, you could possibly ask for EOTS everyday. It may not sort of win you. Yeah, you wouldn’t. You wouldn’t do it that way probably, no. But I think with this one, what I meant was that you can ask for a 15-AA 15AB and and15 AC in succession. So theoretically you could have
34:06 all three on one access request, right?
34:09 Have to really justify the use of all three of, but theoretically you can do that.
34:15 Question six you are dealing with a difficult multi party consent issue for an access request. So what type of EOT might be appropriate?
34:28 I can go with that,
34:31 yes. Whoever said 15 AB is correct. Sorry. Yeah, excellent work. 15 AB is definitely the right one for that one.
34:40 UH #7 UH, what 2 steps need to occur for a 15 AA EOT to be granted?
34:52 Go Megan, No you go.
34:57 Ahh it’s Michael again, just basically you gotta ask for 15 AA and have it in writing. That’s right. And the second step is
35:05 have their consent.
35:07 Yeah. And keep going. What’s the next bit?
35:11 Work
35:17 notify OAIC . You have to do that.
35:20 OK, great. And then record it on the file.
35:24 And final question, true or false
35:28 EOTS enable better case management outcomes.
35:33 True, true, no question about that one it it definitely gives us more options. So please, please build them into your arsenal. They are very, very much worth spending time on and you can decide in your sort of decision making action officer partnerships who’s going to do it and who’s going to monitor it and track it and all of that bit. But it’s really important that you start having conversations and have them early. So really you want to be sort of thinking around sort of the 21 day mark like do I need an EOT on this?
36:04 And then thinking about OK, who’s gonna lodge the form, how are we gonna do this? And especially with the 15-AA, you’re gonna get better results if you write a personal email explaining to them where you’re up to, what you’re doing, what you need, then rather relying on the sort of line or two that’s included in the acknowledgement letter that probably no one reads. So please just really think about this. It’s important. It’s it’s good for us, it’s good for the applicants. And I think especially with the caseload
36:35 we’ve got at the moment, I’m getting that extra time to deal with those sort of larger complex matters. It’s gonna just pay dividends for you as case officers, so please, please think about it.
36:47 All right? That is the end of today’s training. I’m very happy to take any further questions or discuss any cases that people might have.
36:57 Otherwise, I just like to thank you very much for your time and your participation and happy to stay on the line if anyone wants to chat about EOT,
37:09 thank you very much Rebecca
FOI 25/26-2150 DOCUMENT 9
Third Party Consultations
Transcript of a training session by Jennifer `redacted: s47F - personal privacy`
Introduction
Third party consultations are an important part of the FOI process.
We do this when an applicant has requested documents that contain the information of
a third party (individual or entity) and that it’s reasonable to assume that the third party might have some concerns with disclosure of those documents.
If you look at paragraph 3.74 of the FOI Guidelines, we are required to conduct a third
party consultation when we are considering releasing these kinds of documents. There
are three provisions under the FOI Act: 26A, 27 and there’s 27A. I will talk about each of
these provisions in turn.
If you’re not thinking of releasing the documents, there’s no requirement to do a third
party consultation. Instead, you mark-up the documents with the appropriate
exemptions, removing the information related to that third party. But if you are
considering releasing the documents and it’s reasonable to assume that the third party may have some concerns about the information, you should consult with that third party.
How third party consultations affect FOI timeframe
When we do a third party consultation, we automatically get an extension of 30 days of
processing time (if the matter is still in time). We start with a processing time of 30 days, so this means we now have a total of 60 days.
This is why it’s a good idea to identify the need for a third party consult early, so we can get those 30 extra days.
How much time should I have third parties?
You need to give third parties enough time to read the documents and provide advice on
the harm of disclosure. It could be 5 to 7 days. That’s usually a reasonable amount of
time. You don’t have to give them 30 days.
Decide how long to give them based on how many documents you are sending them,
the contents of the documents and who they are.
Benefits for the third party
The process allows third parties to provide their views on the documents and give any
additional context which the decision maker doesn’t know. As decision makers, we only
know what we have in front of us. A third party can give us a lot more information about
their views on the documents and their release.
It’s also a courtesy to the third party if we are thinking of releasing documents with their
information in. This can benefit our relationship with third parties, for example external law firms who we work with on a regular basis.
Benefits for the applicant
In addition, the applicant becomes aware that a third party is likely to be contacted.
This can motivate people to revie their scope.
Here’s an example: in a circumstance where it’s Mum and Dad are feuding. Mum’s the
applicant and Dad’s information is in there. We go to Mum and say we’re going to do a
third party consultation and are you happy with that? But she may not want Dad to know
that she’s even made an FOI application. So it becomes an opportunity for her to
withdraw my application or change the scope of the FOI request so that the third party
consultation doesn’t happen. Remember – we don’t know what the circumstances could
be. There could be domestic violence we don’t know about! So it gives the person that opportunity to tell us not to do the third party consultation and change the scope.
The third party consultation process
When we do a third party consultation, we notify the applicant that we need to do it. The
goal is to make the process as open and transparent as possible. The applicant needs
to know that there’s some information within the documents that is third party
information and that we can’t release that now.
It’s fine to notify applicants via email, but you can also send a letter. We also ask the
applicant whether we can disclose their name to the third party.
There can be benefits for the applicant if they agree we can disclosure their names.
Here’s an example, from redacted: s47F - personal privacy. A lot of the time, the FOI
applicant was the injured party in a redacted: s47F - personal privacy and they were seeking investigation
report through FOI. If the redacted: s47F - persona knows that the applicant, the injured person, they’re less
likely to object to the disclosure of the document because they understood that person
was seeking some financial compensation through their insurance agency. On the other
hand, if the applicant is a journalist then they are more likely to have some objection. So
sometimes it can be very advantageous for the third party to know who the applicant is.
But if the applicant doesn’t give you permission to disclose their name, you can’t reveal their name.
If there is information within the documents that doesn’t relate to the third party, you
need to redact all that first and remove it all. Apply these redactions in full, so they
appear to the third party as a grey box. They can’t see what is underneath. You only
consult with third parties about the information that is left.
In addition, it’s often a good idea to mark up the remaining documents with unapplied
redactions to indicate which parts of the documents contain personal information that
you are likely to redact even without their input.
By marking up those documents prior to providing them to the third party, you’re
showing that you’re already considered what parts of those documents are unlikely to
be disclosed. You’re telling them only seeking advice about the remainder of the material.
I don’t apply these proposed redactions, so they can see a red box around the material and read what is underneath.
It’s also good practice to call a third party before we send out the formal third party
consult email. It can be quite bombarding to receive a third party consult letter out of the
blue It’s probably a good idea to give them a call and explain who you are and what
you’re doing. Explain that you’re going to send them some correspondence and that
you’re seeking their views. Otherwise they can become concerned.
I know that sometimes you can’t always get hold of the applicant. Try your best. But you can only do what you can do.
The 3 Provisions for Third Party Consultation
Section 26 - Consultation about documents affecting Commonwealth-State
relations.
We don’t use this part of the FOI Act very much. In my 18 months at the Agency, I only
know of 2 instances where we’ve used it. That doesn’t mean it hasn’t occurred to other people in other Agencies, but it’s reasonably uncommon here.
This provision applies when the scope of the FOI request includes documents authored
by another state or territory-based agency. That agency should be given an opportunity
to make decision about the release of documents authored by them.
For example, in one case we held sensitive documents of a state-based health service
and we need their views on releasing them.
If we hold documents authored by another Commonwealth government agency, (for
example, the NDIS Quality & Safeguards Commission), we also consult with them to
seek their opinion on the release of their documents. But this is not under section 26.
Section 26 applies to state-based agencies only.
We do a third party consultation because it can help us to make a decision about
disclosure. For example, what if discover that the state-based agency has already
released all those documents in full? Now we know there is no harm is disclosure. On
the other hand, they may have received an FOI request for those documents and
already have refused them in full. Maybe they have a different kind of matter on hand –
perhaps they’re investigating a complaint, and the requested documents relate to that process.
Section 27 - Consultation about business documents
This is when documents contain the business information of another person or an entity
and we believe they are likely to have concerns that disclosure of their information is contrary to the public interest/
We see this very commonly when participants request the invoices an external law firm
has issued the NDIA to provide legal support in relation to an Administrative Reviews
Tribunal (ART) matter.
Invoices will also contain bank account details and hours worked. But we know that law
firms don’t want their hourly rates to be published, because that means a competing law
firm could undercut their fees and put them out of business. In that case, we would
probably redact the information in accordance with section 47G (business information).
We also try negotiate the scope with the applicant to exclude invoices and instead offer
only the total amount the law firm has charged the NDIA for its services. Law firms are
usually happy for us to disclose a total amount, because no one can work out how many
hours service they provided. If you can get the applicant to agree that bank account
details and hourly rates are irrelevant, you can redact those things under section 22
(irrelevant information) instead of section 47G (business information).
The goal is that when we do eventually go to the law firm to seek their advice under a
section 27 third party consultation, we have removed all the material they would object
to. At that point, it’s likely they will respond to the third party consultation confirming they have no objections to the total amount being disclosed.
So when you go to the law firm with your consultation, they can see that everything’s gone or all their, all their business information has been removed.
However, there are always cases where law firms object. In one case, the law firm
objected to the disclosure of the ABN. We went back to them and said their ABN was
already publicly available, therefore we would not redact it.
Sometimes you might think that you don’t need to do the third party consultation
process with a law firm because you have redacted the document so heavily. However,
if external law firms wind of the fact that we’re just releasing their information without
even consulting with them, that could be very harmful for relationships between them.
So just be mindful that you do sometimes need to consult to maintain relationships.
Question from Helen redacted: s47F - personal priva Section 27 talks about a person’s professional affairs as
well as their business affairs. So could you give an example or just talk a little bit about
that? Like the difference between someone’s professional affairs and their business
affairs?
I’m just thinking that perhaps you had a, for instance, a medical professional’s report. If
it was sensitive for one reason or another. And you thought, like the, the doctor or allied
health practitioner would have concerns about release of that document to the
applicant, that could be their professional affairs without actually relating to dollars and
cents. Is this correct?
Peter redacted: s47F - personal privacy : Jumping in to explain that professional affairs means someone’s
professional undertakings. It’s not the same as a medical professional. The example I’d
use is a consultant who has been engaged in order to provide us with a report.
There’s an intrinsic value in the work that they do under contract with us. That might be
a circumstance where we want to talk to them about the further dissemination of the
information they’ve produced on our behalf. Contractors and consultants are a good
example. Lawyers that can be engaged as counsel. So they’re engaged as an individual
rather than as a business or a broader law firm.
It would also cover experts with respect to their review and input into policy
development work. So where they’re putting forward their experience and their
knowledge and sharing that with us as part of a policy development undertaking, the
further disclosure of that information might have an effect on their professional business
because that’s the work that they do and how they market themselves.
Jennifer redacted: s47F - personal priva That’s interesting. Those people’s qualifications will be contained within
the documents. That might be considered borderline personal/business information. It
could be argued again somebody might not want that information revealed. However,
it’s probably in the public interest to disclosure qualifications, because you were acting
in a professional capacity. But that would depend on which way the decision maker
decided to go.
Section 27A – Consultations about Personal Information
Moving onto section 27A, which is third party consultations because of personal privacy.
This comes up in the kinds of documents that we hold. We ask if the documents contain
personal information of another person and whether that person concerned might
reasonably wish to make an exemption contention because of personal information
contained in the document.
If we continue using the example about the law firm invoices, not only do they have
business information in terms of how the, how the invoice and the dollar value was
broken down, they may also have the personal information of the staff of that particular
law firm like it may have their names, their contact details, their mobile phones, e-mail
addresses and so on.
In those cases, it would potentially be quite easy to get the applicant’s agreement that those details are out of the scope of their request.
Another example of a document that required third party consultation under section 27A
would be where there is a family relationship breakdown and there’s one party seeking
the information of the other party.
If you’re leaning towards removing the information of the other party, there’s no
necessity to consult with them. But if you’re leaning to releasing the other party’s information, you need to advice the applicant and then consult with the third party.
What do I do when the third party responds?
When you hear back from them, you review their submissions and decide whether you agree and you can uphold their objections.
What’s really important to understand and to remember is that you’re not actually asking
them for their permission. You’re actually seeking their views on release and then you
are considering their reasons in line with the FOI Act.
Outcomes of third party consultations
There are 3 possible outcomes.
1. No response. This not the same as getting their approval to release the
documents. You've still got to look at the documents, consider exemptions and
conditional exemptions, and apply them appropriately and explain them in your
decision letter. But it is to go back to the individual or the entity one last time to
remind them of the due date, and just to make sure that they are not wanting to
lodge a submission. And pick up the phone and give them a call. If the applicant
does not respond, they do not get third party review rights later.
2. No objections. That means you can release the information as you provided it to
them. If you gave them a marked up version, that's how you must release those
documents.
3. Third party objects. You must consider their objections. Are they reasonable
and upholdable under the act, or are they without substance? Often they have no
substance.
a. If you agree with their objections, you advise the third party that you're
upholding their objections and you release the documents with the
exemptions applied.
b. If you disagree with their objections. Go back and tell them why you
disagree with their objections. For example, you might explain why the
there are public interest factors in favour of release and disclosure
promotes the objectives of the FOI Act. Try to get their agreement – sendthem the marked up documents again. Hopefully, they agree to the
release of documents.
c. But if they don’t, you have to issue a deferred access decision. This
means you provide your decision notice to your applicant and another
documents they requested. But any documents containing information that
you consulted on are withheld. You identify these documents in your
decision letter. The third party also receives a copy of the decision notice –
it’s not the same decision notice. They get a decision notice telling them
you are not upholding their objections. Now the third party also has an
opportunity to exercise all their review rights – this means they have 30
days to lodge an internal review. Check back in with them at around day
31 or 32 to see if they will lodge an internal review (or an external review
to OAIC). Assuming no reviews have been lodged, you can then release
the documents to the applicant you can attach them to an email. You don’t
need to write another decision notice.
d. If the applicant does lodge a review, the documents continue to be
withheld until all their review rights are exhausted. This could mean the
Internal Review process, the Office of the Australian Information
Commissioner (OAIC) review process, and then the Administrative
Reviews Tribunal (ART) review process! This could be years!
Question from Elizabeth redacted: s47F - personal privacy What if you’re not getting a response from the
third party? Do we still have to wait 30 days for the third party to lodge an internal
review before releasing the documents?
Jennifer redacted: s47F - personal priva No, that person doesn’t get review rights because they didn’t respond
to the third party consultation notice. They don’t need to be notified about our decision.
Make sure you record every contact attempt in file notes, so we can justify this later if they make a complaint. You can send them an email that clearly states “If I don’t hear from you by this date, I will assume you have no objections and I will release the documents.”
Summary
• Identify that you may need a third party consult early on. • Review the documents and try to get the applicant’s agreement that some parts
of it are out of scope. Redact those parts using section 22 (irrelevant
information).
• Mark up the documents as you intend to release them. • Contact your applicant and advise of your intent to consult, seek their permission
to provide their name.
• Conduct your consult consultation and review their submissions. • If they have some objections, see if you can renegotiate with them. • Make your decision on access. • Advise a third party of your intentions and then provide a decision notice to the
applicant as well as the third party.
• If they didn’t respond you your third party consult notice at all, you do not need to
provide them with a decision notice.
• In the case of a deferred access decision, inform the third party of their review
rights and advise the applicant of the third party's review rights as well.
• Release the balance of the documents once the review rights have been
exhausted.FOI 25/26-2150 DOCUMENT 10
Team training_ Third Party Consultations with Jennifer
redacted: s47F - personal privacy -20240424_093502-Meeting Recording
April 24, 2024, 11:35PM 42m 26s
`redacted: s47F - personal pr`Team training Third Party Consultations with Jennifer -
20240424 093502-Meeting Recording.mp4
redacted: s47F - personal priv Jennifer 0:15
And it’s.
The reason that we we do it is that we will often get documents and sometimes we
can actually even identify that from the scope of the documents that there’s likely to
be information about a third party or an entity doesn’t have to be an individual.
That, you know, isn’t the applicant’s information, and that it’s reasonable to assume
that the third party might have some concerns.
I don’t want to just read a slides that you can already yourselves so.
You know in in essence that’s more or less what I’ve said. We do have some law
about that in the guidelines. So if you look at 3.74.
You are actually required to to conduct a third party consultation and there’s three
provisions under the Act. There’s 26 a, there’s 27 and there’s 27 a. So I’ll look at all
three of those provisions.
But if our documents contain information you actually do actually do need to really
consider.
You need to do a consultation.
If well, in essence, if you’re actually thinking of releasing the documents, if you’re not
thinking of releasing the documents, there’s no requirement and you mark the
documents up with the appropriate exemptions that you feel applied to the
documents. But if you are considering releasing the documents and it’s reasonable to
assume that the third party may have some concerns about the information, you
really should be consulting with that third party.
The timing of the third party consultation so.
As with anything in FOI, we have 30 days to manage a process, so it’s good to get on
top of it as soon as we possibly can.
So if we actually do get off the party consultation, done very, very quickly, but also
particularly within the 1st 30 days of the processing period, we automatically get an
extended 30 days of processing time. So we now have in essence a total of 60 days.
That is a huge advantage of the third party consultation process and of identifying it
within that first 30 day processing period. Otherwise you don’t get the 30 days.
Another advantage is that it allows for the third party to provide their views on the
documents and also give any additional context which the decision maker doesn’t
know. So obviously we only know what we have in front of us. A third party can give
us a lot more information about their views on the documents and its release.
It’s actually a courtesy to the third party if we are thinking of releasing documents
with their information in.
And also the applicant becomes aware that a third party is likely to be contacted.
Now this can have an impact sometimes on people revising their scope, so in I’ll just
give you an example of a circumstance where it’s mum and Dad are feuding.
Mum’s the applicant and dad’s information’s in there and we go to mum and say
we’re going to do a third party consultation.
Are you happy with that? She may not want Dad to know that she’s even made an
application and it’s an opportunity to say, look, I’m actually going to withdraw my
application or I’m going to change the scope so that the third party consultation
doesn’t have to occur. And you know, we don’t know what the circumstances could
be. There could be domestic violence. We don’t know about. So it just gives the
person that opportunity to say, oh, please don’t do that. I’ll change my scope.
It’s best to advise.
The applicant of your intention to conduct the third party consultation.
In doing this, an e-mail is fine. You can do a letter, but an e-mail is actually fine. The
e-mail will give them the time frames. If we are doing it within time, it will give them
the new due dates and it’s a good opportunity to ask their permission to disclose
their applicant, their their identity as the applicant to the third party.
There’s some advantages.
Of the third party knowing who the applicant is, I’ll just give you an example of when
I work for redacted: s47F - personal privacy A lot of the time the applicant was the injured party in a
`redacted: s47F - personal p``redacted: s47F - personal privacy` and it was the investigation report of the `redacted: s47F - personal p` that was being FOI.
`redacted: s47F - personal p` `redacted: s47F - personal pri`Now, when seek consulting with the `redacted: s47F - personal p` if the `redacted: s47F - personal pr`knows that it's the app that it's
the injured person who’s applying. They’re less likely to object because they aren’t. They they understand that that person is seeking some financial compensation through their insurance agency. If they happen to. If they know that it’s a media, then they are more likely to have some objection. So sometimes it can be very advantageous. For the third party to know who the applicant is.
If the applicant doesn’t give you permission, then don’t. You don’t reveal their name and don’t reveal them as their identity.
What we’re actually doing, the third party consult if anyone has any questions, just I don’t know, I can’t see hands. So just yell out if you have a question.
While we’re going through the slides.
So Mark, yeah, good. Give me a break.
redacted: s47F - personal privacy Jessie 5:50
Then I have a question, Jesse.
No, I was just wondering. So you always have to seek consent from the applicant before the 3rd part before completing the third party consult.
redacted: s47F - personal priv Jennifer 6:01
Yes if.
Well, look, yes, you what you want to do is you want to actually make contact, you want to make you need the process to be as open and transparent as possible, and you need the applicant needs to know that there’s some information in the held within the documents that is third party information and that you can’t release that now.
redacted: s47F - personal privacy Jessie 6:13
Mm hmm.
redacted: s47F - personal priv Jennifer 6:25
This it’s obviously if you’re not going to release it if you’ve made the decision, you’re not going to release it, you’re just going to exempt it anyway, under maybe 47 F or whatever exemption would apply.
But if you feel in your gut that this information is actually going to be helpful and is within scope, and would be really desired by the applicant, then you need to give them the opportunity to keep it in scope, for instance.
You know, it’s a it’s a safety, it’s a courtesy.
And you can’t reveal who they are to the third party unless they’ve given you their consent.
redacted: s47F - personal privacy Jessie 7:04
Yep, sure. That makes sense. Thanks, Jen.
redacted: s47F - personal priv Jennifer 7:05
Yeah, yeah, no worries.
When you’re doing the consult, it’s often a good idea to mark up the documents.
Prior to conducting the consult and the reason for this is.
You can already redact out the sensitive information that’s likely to form a basis of an of an objection that you’re likely to uphold.
And so, once you’re looking at the documents, it’s actually as scope negotiation can happen at any point throughout the process. So at the very beginning, as you get the documents, as you’re thinking about a third party consult, you can actually go back to the applicant and try now to scope some of the third party information that you in your gut feel that you’re going to exempt anyway. And that will also create be an objection from the third party.
It’s a really good practise to be able to do that.
By marking up those documents prior to providing them to the third party, you’re saying to the applicant you’re saying to the third party. I’ve already considered the documents. I’ve considered that there is maybe information that’s contrary to the public interest and what it what. I’m seeking your views on is the balance of the information. So keep the box around it, but don’t take it out so that they can see what it is, but they can see that for instance, you may have taken out person out personal names of.
Staff in another Organisation as personal information because you’re not going to release that to the applicant and this way the the third party can see that you have already made some considerations.
And the other thing that is really good is that if we just bombard them with our third party consult without giving them the heads up sometimes, depending on the the applicant and the sophistication of the applicant, it can be quite bombarding.
So.
If it’s, particularly if it’s an individual, it’s probably a good idea to give them a call and explain that you’ve got a process happening and that you’re going to send them some correspondence and that you’re seeking their views just to give them the heads up so that when they do get the e-mail, they don’t kind of go into a bit of a
panic and get really, really concerned.
The third party consult really is an advantage to them and we just really need to kind of let them know that this is just part of the process.
So good, good practise. I know you can’t always get hold of the applicant.
Sometimes it’s very difficult.
But you can only do what you can do like just do the best you can.
So we’ll go into the three provisions within the FOI Act that we have.
Section 26. A consultation documents affecting Commonwealth state relations.
And also if you want to refer to the guidelines, see those two sections there.
So this probably I at this point in time I I know of two instances in my 18 -16 months of being at the Agency where this has occurred. That doesn’t mean it hasn’t occurred by other people, but it’s it’s reasonably uncommon.
So at times there are other agencies documents located within your documents.
And every agency has to make their own decision about the release of the documents. But if there is information held in our documents from another agency.
It’s good practise to go and actually consult with them.
So one of probably the most likely scenario for our situation would be NDIS Commission. So given that complaints go to the Commission about Ndia and so on and so forth, it might be that in some they may have some of our documents, we may have some of their documents.
It’s a good if if we do it’s good practise to do that consultation under 26 a.
It may also be that it might be a health service, which is another example that I’m aware of where we have quite sensitive documents of a health service and we need their views on that. So again.
It’s good to do that third party consultation and the reason is that they may the other agency they may have already released it in full or in or in part in an FOI to that direct to that agency and therefore you know that will there’s there’s the harm of disclosure is now gone. In essence, if you released it in the same manner.
They may have refused access to the document, or it may they may have made it publicly available, so it’s giving you the heads up on the document.
They may have a matter at hand and the other agency can alert you of this for your consideration, so it might be that they’re investigating something and this document is part of that.
And so again, that’s information that you can get back from that other from that in that consultation process.
Around the document for your consideration.
Section 27. Consultation over business documents.
Now, does the information contain business information of another person or an entity? And that they may reasonably have concerns and they may feel that it’s contrary to the public interest to release this type of information. Practical examples seen frequently is where the applicant is seeking the costs to the ndia for their AAT matter. We know what those documents look like, so even from the scope, we know that we’re going to be looking at invoices from a law firm. Because that’s how we gauge the cost. So it’s a good opportunity to negotiate with the applicant. Around what documents they are and generally communication discussion with them saying confirming it’s the total amount that it’s cost the ndia. Is that correct? Generally speaking, you will be able to out of scope any of the line items which are the breakdown of the invoice. Now the line items for in a law firm might say Jennifer redacted: s47F - personal p worked on for four hours on this part of thing and it cost that. So all of that is internal like it breaks it down. Law firms breakdown how they actually do their billing and that is business information that if that got out that could be detrimental because another law firm law firm could look at that and see how they’re making their calculations and come in and undercut. So that type of information would be information we would want to if we got it out of scope it we would have to 47 G it. The other thing that’s generally attached to an invoice is a remittance advice and a remittance Advice generally has the bank accounts. The the law firm’s bank account details, so you can pretty much go back to the applicant up front and say, hey, it’s totals you’re after. Invoices will show the totals. We can take out those line items. Etc. The remittance advice you don’t need their bank account details. Let’s amend our scope to the total dollar figures relate in relation to your AAT matter. So when you go to the law firm with your consultation, they can see that everything’s gone or all their, all their business information has been removed. And. They’re more likely to not have objections. And it’s an easier decision notice to right if you’ve out of scoped it because you’re
just section 22 ING rather than having to actually do a balancing argument.
Referring to exemptions.
Any questions around that? That’s just one example of business information. There’s there’s many, many, many situations where there will be other types of business information within documents. So it’s not always easy to out of scope it, but in the ones that we get predominantly, it is pretty easy to out of scope.
s47F - personal pr Helen 15:36
Hey, Jen, it’s Helen here. Section 27 talks about a person’s professional affairs as well as their business affairs. That’s another. So could you give an example or just talk a little bit about that? Like the difference between someone’s professional affairs and their business affairs?
s47F - personal priv Jennifer 15:45
Yeah, yeah, yeah. Off the top of my head.
s47F - personal pr Helen 16:00
I’m sorry.
s47F - personal priv Jennifer 16:03
But thank you for the question. Yeah. Look, I haven’t actually read it. I haven’t literally seen any documents with that type of business information. And that is actually different to the state. Act as well quite different to the State act. So that’s probably something that I’m not that familiar with. And as soon as I would see it in a document, obviously I’ll that’s that’s I guess mostly our working opportunity is when it we’re we’re confronted with it. But certainly if you know, but if you have an example, please give it.
s47F - personal pr Helen 16:42
I’m just thinking that perhaps you had a, for instance, a medical professionals report.
s47F - personal priv Jennifer 16:49
All right.
FOI 25/26-2150
And and you know it was sensitive for one reason or another. And you thought, like the, the Doctor or allied health practitioner or someone. Or would have concerns about release of that document to the applicant that could be their professional affairs without actually relating to dollars and cents. If you know what I mean.
Yeah, yeah. Yeah, yeah, yeah, no, I know what you mean.
Yeah. And yes. I even probably know what you’re referring to.
No. Can I jump in Jen and and just note that professional affairs in the same way business affairs relates to someone’s professional undertakings rather than thinking of a medical professional, I’d I’d be minded to example a consultant or if if we’re engaging with someone who is a professional in in the medical space, that their engagement in order to perform work or to provide us with a report.
I think that.
There’s an intrinsic value in the work that they do under contract with us. That might be a circumstance where we want to talk to them about the further dissemination of the information they’ve produced on our behalf. So contractors, you know, consultancy sense are a good example. Lawyers that can be engaged as counsel.
Page 158 of 331
FOI 25/26-2150
they’re engaged as an individual rather than as a business or or a broader law firm. Those sorts of ones are examples where.
Jennifer (s47F - personal priv) 18:24 Mm hmm. Yep.
Peter (s47F - personal privacy) 18:27 That can happen. We have got examples where recently we’ve consulted with. Disability Experts with respect to their review and input into policy development work. So where they’re putting forward their experience and their knowledge and sharing that with us as part of a policy development undertaking the further disclosure of that information might have an effect on their professional business because that’s the work that they do.
Jennifer (s47F - personal priv) 18:44 Hmm.
Helen (s47F - personal pr) 18:45 Hmm.
Peter (s47F - personal privacy) 18:59 And market themselves.
Jennifer (s47F - personal priv) 19:02 That’s really interesting. Yeah, that’s that’s excellent, Peter. I’d really love to know a bit more about that. You know, like I say with FOI often you don’t know until you know until you confront it with something. So that, yeah, that would be really interesting. I know that a lot of times people’s. Qualifications and those types of things are also contained within the documents and again. Borderline personal information business information. It could be argued again if somebody doesn’t want that information revealed as well, so. However, probably in the public interest to know what you, your qualifications are, if you’re acting in a professional capacity. So that’s what could just be an interesting
argument and a decision.
Notice this is depending on which way the decision maker decided to go. OK. So if we move on to 27 a, which is personal privacy, which again is something that we probably would come up against a little bit in our document in the type of documents that we hold. So does the information contain personal information of another person and the person concerned might reasonably wish to make an exemption contention because of personal information contained in the document. So again, referring to an early example of the invoicing scenario to the agency, not only does it have business information in terms of how the, how the invoice and the dollar value was broken down, but it may also have the personal information of the staff of that particular law firm like it may have their names, their contact details, their mobile phones, e-mail etc, etc. Again, in these those types of examples, that’s also something that you would potentially quite easily be able to out of scope with your applicant and mark that out of scope with the documents. When you go to your consultation. With the law firm, we’ve had, law firms make all sorts of objections. We had a whole series of these, and by the time we had stripped the invoice down to almost to to in in essence, the name of the law firm that his services that we provided. With the reference of the participant as being, you know the person at the Who’s who was at the AAT hearing and the total value. We even had the law firm come back and say, well, we’d like you to take our ABN. We’re happy now, but we accept. We want you to take the ABN number out and of course you know the ABN number is is. Publicly available so. Went back and said no, we can’t do that. And ended up with a win, but that was about a five or six e-mail consultation process back and forward to the law firm to get to that point. The good thing about it, the effort that all of that took was we now set precedent with that law firm and so next time we go back to that law firm, we mark up the document the same. We go to them. And you know the the consultation process should be an an awful lot quicker. One thing that’s really important to notice that you can’t just mark up the document how you think you’d like to mark it up and release it without consulting because. If our external lawyers got wind of the fact that we’re just releasing their their information without even consulting with them, that could be very harmful for
relationships between them and the ndia.
So just be mindful that you do need to consult. You can’t just make a decision without that consultation process.
Getting back to the personal privacy, another example would be where we have a family relationship breakdown and there’s one applicant.
One party seeking information and there is information of the other party.
If you’re leaning towards releasing it and you may not, you may. You may remove it as personal privacy of the other person, but if you are leaning towards releasing it then you will need to conduct the third party consultation with the applicant. Advise the applicant and and then conduct the same process again. Contact.
The third party and get their views on on the release of that information and the harm factors.
When you’re during the third party consult, you will need to provide sufficient time for the third party to consider the documents and make any submissions.
5 to 7 days. Could you know? I guess it depends on your clock. If you’ve got plenty of time 5 to 7 days is probably quite a a reasonable amount of time.
When you hear back from them, you, you have to review those decision those submissions and you have to decide whether you agree and you can uphold their objections.
What’s really important to understand and to remember is that you’re not actually asking them for their permission. You’re actually seeking their views on release and then you are considering their relation with their reasons in line with the FOI Act.
When you are doing the third party consultation.
You also need to have a look at the document you’re consulting with with the third party, and you need to if there’s information within the document that doesn’t relate to the third party, you need to actually mark that up first and remove it, and then only only consult with what information is left.
And so this does mean sometimes you’ve got to mark your documents up twice. It’s timely and consuming time consuming, but you.
Aren’t really able to give the third party information about that. That isn’t about them. So you really do have to look at the document and make a really considered markup before you actually provide it. Always good good practise to get someone else to run their eyes over it before you do it. Just just so that you’re absolutely sure you’re not going to do a privacy breach.
FOI 25/26-2150
And I just have a quick question, Jesse again.
Yep.
When you. Giving the third party the sufficient time to process, is there a time frame? Like is there a set time frame or you just gauge?
There’s not a set time, it’s reasonable. It’s. So you want to give them as much as you can.
OK. Mm hmm.
But it’s reasonable to both sides, so it’s reasonable for you from a processing perspective as well As for them for a review perspective.
Mm hmm.
You’ll often find when it’s law firms, you might give them a week and they won’t look at it till the last day you give them 14 days. They won’t look at it till the last day.
Mm hmm mm.
FOI 25/26-2150
So you really need to with a law firm, I tend to go quite tight with my time frames. You can go three to five days with an individual. I usually give a bit longer because it’s not their core business and it’s an unusual process that they’re probably engaging in. So I think you need to be reasonable in relation to your applicant has this. It’s like anything in FOI. You have to look specifically who is your applicant, what are the documents, what are the sensitivities, what’s reasonable?
s47F - personal privacy Jessie 26:33 OK. Yep, sure. Thanks Jen.
s47F - personal priv Jennifer 26:49 Yeah, Yep, no worries.
s47F - personal p , Billie-Jo 26:50 Hi, Jen. It’s Billy. Sorry, I have a question too. I’m just wondering if you have chosen to take on the third parties advice or alternatively if you disagree and object to what they’ve said. Should we be re consulting with them about what we’ve done to the documents? If we have taken their advice or if we’ve decided to go against them?
s47F - personal priv Jennifer 27:20 Yes, as to all the answer to all of those questions and as my slides will show.
s47F - personal p , Billie-Jo 27:24 OK. Oh, OK, sorry. I’m jumping the gun.
s47F - personal priv Jennifer 27:29 No, no, that’s. I’m really pleased that you are. It’s showing that you’re already thinking about it. So that’s really important.
s47F - personal p , Billie-Jo 27:36 Awesome. I’ll keep hush then. Thank you.
Page 163 of 331
FOI 25/26-2150
Jennifer 27:39 No, no, no. Please, please. It’s so Billy possible outcomes. So that there’s essentially 3 possible outcomes. The first, the first outcome is no response. And that can be a little that you know you that that’s not necessarily a green light. Hey, I’m going to release the documents in full. I didn’t get a response. You’ve still got to look at the documents and you’ve still got to consider exemptions and conditional exemptions and apply them appropriately. Explain them in your decision letter. But what is good practice is to go back to the individual or the entity one last time to remind them of the due date, and just to make sure that they are not wanting to lodge submission. And phone call again. I know can be tricky depending on the applicant. If it’s an organisation, somebody’s always going to answer the phone. So pick up the phone and give them a call. It may be that they’ve overlooked it, or they for some reason, and they did want to make an A submission or not. And if you can’t get hold of them, you can’t get hold of them. You make a decision. But again, you make a decision considering the exemptions and conditional exemptions and applying them appropriately. The next possible outcome is no objections. Yay. So. Essentially, that means you can. Release the information as you provided and that means if you provided it to to them in a marked up version then that’s how you must release those documents in that marked up version. That’s your nicest option. Here we go, Billy. Third party objects. So you’ve got firstly, you must consider their objections. Are they reasonable and upholdable under the act, or are they without substance? Which often they are. If you agree with their objections. You advise the third party that you’re upholding their objections and you release the documents with the exemptions applied. That’s fine.
Page 164 of 331
FOI 25/26-2150
But you might not agree. You might disagree with their objections. And as I said earlier, you’re not asking for their permission. You’re asking for their objections and their thoughts and views. And you can disagree with their objections. But it’s an opportunity to go back and negotiate with them. Go back and tell them why, as you will actually really require this information to help you with your decision later. You need to know so so as an example here for a matter that involves third party invoices, advise the of the public interest factor in favour of as part of your negotiation problem process. Advise them of the public interest factor in favour of release and that the disclosure promotes the effective oversight of of public expenditure. Explain you’ve removed the business information and the personal information and try to get agreement. To fall from them, to be able to release the documents as you’ve marked. them again, this is probably. I keep going back to the insurance to the lawyer invoices, just because we’ve done so many of these in the last couple of months and we’ve got so many firms on site now, which is really great, that if we all make sure that we continue doing the same practise. We don’t untrain them. If you know what I mean. So we kind of we kind of have them in agreement that this is that this is a good way to go and it is very much in the public interest, the expenditure of public funding and so that has a very, very significant weight. Which you would have to really balance. With significant factors against disclosure and I’m really, I really think we would struggle with that. You’re not. We may not be able to get. Them to agree or be a third party to agree you may still. Disagree with their objections. And So what you have to do is you have to issue a deferred access decision. Now, I don’t know how many people in this agency have issued a deferred access decision before. But a deferred access decision means that you provide your decision, notice and documents to your applicant. With the information and issue or the consulted information withheld at this
point in time, however, you identify in your decision letter that there are some documents that have deferred access on them, while the third party has an opportunity to exercise their review rights.
This is quite a complicated process. I have some template decision letters around all of this. In fact around the whole consultation process, because it’s really important that the consultation process forms part of your decision notice, because it is part of the process that you engaged in when you manage the FOI. So it needs to be accounted for in the decision.
I can provide those to a later stage if people are interested.
But there is I do have like like I say, I do have information and templates that I have devised that I use in these particular circumstances.
Just know where. Where am I? Sorry.
No objections. Possible outcome. Sorry, I’m just flicking around here.
So yeah, just getting back to this, that your decision notice, it’s really important. That you do provide the information and the decision.
Notice that if you do have a third party objection.
And you’re not going to uphold it that they?
To get it to the third party also needs to get a decision notice.
They need to get a decision notice of your decision not to uphold. They don’t get the same decision notice they get a decision notice of your decision not to uphold their objection. But they also then get their review rights.
You need to keep an eye on them. They have a 30 day review, right? Assuming that we’re always assuming here that the application’s not deemed so they still have their 30 day review rights. So after the 30 days, you need to keep an eye on the clock Roundabout, Day 31 or day 32. If I haven’t heard.
I would generally go back to the third party.
Um for one last attempt to see whether or not they’re going to come back.
They could just as easily do an external review, assuming we’re still in time, and if they choose not to do the internal review.
I’ve recently been advised that the OAIC are not, so we can’t go to OAIC and ask hey, has there been an external review lodged by this third party applicant because they won’t tell us?
Then they’re not monitoring it and they’re putting the onus back on to us to go back to the applicant and make sure and check with the applicant. Have you lodged an external review?
FOI 25/26-2150
And assuming that they haven’t and no reviews come in. Your you then are able to release those documents. And the the release of the. Those documents doesn’t need to be by another decision notice. It can actually be an attachment to an e-mail.
Elizabeth 35:51 Hi, Jen.
Jennifer 35:51 So just. Yeah. Who’s that? Oh, yeah. Yeah.
Elizabeth 35:54 Can you? It’s Liz. I wanted to check now if you’re not getting any response from the third party when you’re asking them, maybe first of all with of their views on the release of information, time passes and so on. Then they don’t particularly engage in providing their viewpoint, so you don’t really have a lot of material to go on. And then finally, you do decide that you’re going to release some information. Give them notice around the opportunity for them to seek a review for a deemed matter. They don’t get any that 30 days internal opportunity, but they have the OAIC 30 days opportunity to lodge.
Jennifer 36:27 Mm hmm. That’s right.
Elizabeth 36:42 That review. Now, if you then now that we’ve just learned that.
Jennifer 36:46 So if they. So if they weren’t engaging at all in the in the third party consult process.
Page 167 of 331
FOI 25/26-2150
| Tag | Speaker | Time |
|---|---|---|
| s47F - personal privacy | Elizabeth | 36:50 |
| Hmm hmm. | ||
| Yeah. | ||
| s47F - personal priv | Jennifer | 36:56 |
| We stop engaging as well, and we make the decision on the documents. | ||
| s47F - personal privacy | Elizabeth | 37:01 |
| Oh, but you, but OK. | ||
| s47F - personal priv | Jennifer | 37:03 |
| So. | ||
| So so sorry, I don’t know if I misinterpreted what you said. So we’ve done a third party consult. Hey, here’s these documents. They’ve got your information. And do you have any concerns? Please respond by X stay and we get nothing back and then we go back again and say hey. | ||
| We haven’t heard, can you? | ||
| Can you come back to us with a response and we still get no response? | ||
| s47F - personal privacy | Elizabeth | 37:31 |
| OK. | ||
| s47F - personal priv | Jennifer | 37:32 |
| We stop the third party console process and we make the decision. | ||
| s47F - personal privacy | Elizabeth | 37:36 |
| I see, so. | ||
| s47F - personal priv | Jennifer | 37:37 |
| Then have review rights. | ||
| s47F - personal privacy | Elizabeth | 37:40 |
| Doesn’t have review rights. |
FOI 25/26-2150
And they don’t need to be notified because we’ve done, we’ve already attempted and look this is where record keeping is so, so, so important. I mean every time you touch a matter, put it in Lex, put a file note in Lex On this date we contacted again, we’ve sent the third party documents. We’ve tried again we still don’t have a response. We are going to make the decision.
Yeah. Hmm, OK.
Without the views of the third party.
I see. All right. And then if in a slightly different scenario where they have engaged maybe once and then you’ve gone through the process of actually deciding you’re going to release the information anyway, but you give the third party notice of that before providing a document to the applicant.
Yeah. Yep. Yep.
How long do you give it then? Like so if OAIC is not going to tell us if they’ve received a request for a review? Then we have to go back to the applicant. Now, if we hear nothing back. Pardon me, we have to go back to the third party and say, hey, we’re we’re. I don’t have you lodged a review. And if they don’t respond to that, then what’s the time frame around allowing enough time for them to to respond to? Hey, have you lodged a review? If you haven’t, then you got this much time and then it’s gone. The documents going to the applicant.
Page 169 of 331
FOI 25/26-2150
Jennifer (39:02) Well, they are well, they should already have known how much time they had, so they should already have notification that we’re going to release we we we can’t we we don’t agree with your objections. And you’ve already engaged in that process and you’ve given them an opportunity. So have you. You’ve given them an opportunity to come back and they haven’t come back. So have you issued your decision notice?
Elizabeth (39:27) Yes.
Jennifer (39:28) So you’ve issued your decision that is withholding the deferred access documents. You’ve given the third party has until X number of days to get back to you. So they have 30 days. So once you’ve issued you deferred access decision, they have 30 days to lodge a review. When that 30 days is up and you have heard nothing from them.
Elizabeth (39:45) Right.
Jennifer (39:51) You, because if it’s in your situation, it’s deemed you’ll have to go back to them and ask them whether they’ve lodged an external review of OAIC, because OAIC won’t tell us. And you already know that they haven’t launched it. Well, they didn’t have the option to launch an internal review.
Elizabeth (40:06) Yes.
Jennifer (40:07) So in essence, if they don’t, if they don’t respond, I would, I would give them a few more days to respond. If they don’t respond, then I would be releasing the the
documents and I would be clearly saying in my, you know, if we don’t get a response for you on this day, the documents will be released.
Elizabeth (40:15)
- Yeah. OK.
- The document OK.
- OK. Yeah, cool.
Jennifer (40:28)
- Yes.
Elizabeth (40:30)
- Thanks.
Jennifer (40:32)
- OK, no worries. That’s just a summary slide that you can read through at your leisure if you like, or I can read it if you want. What do you want me to read it? Hold on. I just read it. So, so just really, supposedly a quick summary, a quick reference really is identify if. A third party consult is required early on. Review the documents to see if there’s anything that you can out of scope from your applicant. And then mark up the documents as you intend to release them, you don’t have to mark up the documents if you intend to release them. It’s just sometimes can be really, really helpful. Contact your applicant and advise of your intent to consult, seek their permission to provide their name. Conduct your consult consultation and review their submissions. If they have some objections, see if you can renegotiate. Renegotiate with them. Make your decision on access. Advise a third party of your intentions and then provide a decision notice to the applicant as well as the third party. In the circumstances that you are overriding their objections, obviously, and then that or that you are actually agreeing with their objections if they didn’t, in Liz’s case, communicate at all, then you don’t need to provide them a decision notice.
FOI 25/26-2150
In the case of a deferred access decision, inform the third party of their review rights and advise the applicant of the third party’s review rights as well. And then release the balance of the documents once the review rights are up, unless you get further objections.
s47F - personal privacy , Rachael stopped transcription
Page 172 of 331
FOI 25/26-2150
DOCUMENT 11
| Document name | pages |
|---|---|
| CPAP Machine and Related Consumables for a participant with Down Syndrome and Obstructive Sleep Apnoea | 4 |
| Diabetes Consumables for participant with Prader Willi Syndrome | 3 |
| Nutritional Supplements for a 7 year old with Developmental Delay | 3 |
| Thermomix for participant with Dysphagia | 4 |
| Access for a child whose parents are Visa 444 holders | 3 |
| Access for a prospective participant on a Forensic Order (Mental Health) | 7 |
| Access for a prospective participant with an above elbow amputation | 4 |
| Access for a prospective participant with arthritis and obesity | 7 |
| Access for a prospective participant with Chronic Back Pain | 5 |
| Access for a prospective participant with chronic pain, fibromyalgia and neuropathic pain | 5 |
| Access for a prospective participant with Dementia | 2 |
| Access for a prospective participant with Fibromyalgia and Depression | 11 |
| Access for a prospective participant with obesity and osteoarthritis | 2 |
| Access for a prospective participant with Osteoarthritis | 2 |
| Access for a prospective participant with Schizophrenia | 8 |
| Access for a prospective participant with upper limb neuropathic pain | 12 |
| Access for prospective participants who hold a DVA gold card | 2 |
| Access information for prospective participants with Chronic Obstructive Pulmonary Disease | 4 |
| Internal Review of Access Decision for prospective participant with Osteoarthritis, Obesity and psychosocial conditions | 6 |
| Interpreting eye reports to determine access for prospective participants with Vision Impairments | 3 |
| Review access for a prospective participant living in a Mental Health Residential Rehabilitation unit | 11 |
| Reviewing and revoking Access | 4 |
| Revoke access for a participant with HIV, hepatitis B, Cirrhosis hearing impairment and depression | 6 |
| Revoke access for a participant with Osteoarthritis and PTSD | 6 |
| Revoke Access for a participant with moderate hearing loss | 4 |
| Revoke Access for a participant with Schizophrenia | 5 |
| Assistance Animal- evidence required to make a reasonable and necessary decision | 6 |
| Medical alert dog for a participant with cardiac condition | 3 |
| Electric Bed, pressure care mattress and adjoining beds for a participant with an ABI | 4 |
| King single Hi-Lo Bed with companion bed for a participant with Parkinson’s Disease (PDF 426KB) | 5 |
| Communication software to support learning in school | 5 |
| CPAP Machine and Related Consumables for a participant with Down Syndrome and Obstructive Sleep Apnoea | 4 |
| Thermomix for participant with Dysphagia | 4 |
| Cochlear Implant speech processor upgrades for NDIS participants under 26 years of age | 3 |
| Phonak Roger Focus Device and Auditory Training Application for a participant with ASD | 7 |
| Request for Hearing Aids and accessories above the Office of Hearing Services subsidy | 5 |
| Smoke Alarm, Intercom System, CCTV and Security Cameras for Deaf participant | 6 |
| Transitional arrangements between the Hearing Services Program (HSP) and NDIS | 2 |
| Accommodation costs associated with Guide Dog placement and training | 5 |
| Funding of disability specific children’s car seats that do not meet Australian Standards (including Carrot Car Seats) | 7 |
| Orthotics, Therapeutic listening and HowdaHug chair for 6 year old | 6 |
| Request for a modified bicycle for a child with ASD | 4 |
| Request for Specialised Trike for a Child with Global Developmental Delay | 3 |
| Sensory and weighted devices and toys for a participant with ASD | 13 |
| Splashy seat, gravity chair, Bingo stroller, Squiggles stander, Kangbo bed and Eurocare mattress for a 4 year old participant | 12 |
| Weighted Blanket for a participant with Autism | 4 |
| Request for Pool Hoist for a participant with Cerebral Palsy (PDF 883KB) | 5 |
| Support hours required for two person hoist transfer | 2 |
| Dynamic Movement Orthosis garment for a child with Muscular Dystrophy | 7 |
| Everyday and waterproof prosthetic legs, and high cost cosmetic cover for transtibial amputee | 4 |
| Everyday prosthetic leg with microprocessor knee and waterproof leg for amputee - mainstream (employment) interface | 4 |
| Paediatric upper limb prostheses | 3 |
| Prosthetic leg and waterproof leg for K3 amputee | 3 |
| Transtibial prosthetic options | 3 |
| Stance Control Knee Ankle Foot Orthosis with electronic E-Mag knee for participant with stroke | 3 |
| Waterproof prosthetic leg for hydrotherapy | 3 |
| Flamingo Shower Commode for a 7 year old participant with myotonic dystrophy (PDF 814KB) | 6 |
| Heron Mobile Shower Commode for a participant with Cerebral Palsy, Epilepsy and intellectual impairment (PDF 814KB) | 4 |
| Request for travel shower commode for a participant with spinal cord injury (PDF 827KB) | 3 |
| Freedom stroller with accessories for 10 year old with ASD and chromosomal disorder | 9 |
| Request for footwear, splints, standing frame, hydro spa and floaties for a participant with Cerebral Palsy | 9 |
| iPhone 7+ and vision related applications for a participant with vision impairment | 7 |
| Irlen glasses and Irlen therapy for a participant with ASD | 5 |
| Orcam glasses for an adult participant with vision impairment | 4 |
| Request for large computer monitor and iPhone 6 for participant with low vision | 5 |
| Specialised glasses for a child with vision impairment | 2 |
| Talking microwave for a participant with vision impairment | 3 |
| Power wheelchair with anterior tilt for standing | 9 |
| Electric vertical lift recliner chair for participant with muscular dystrophy | 4 |
| Equipment post hospital discharge | 3 |
| Functional Electrical Stimulation (FES) for footdrop | 3 |
| Funding of Assistive technology for Telehealth | 3 |
| Insurance of Assistive Technology | 4 |
| iPad for a child with ASD to support self-regulation, social development and independent daily living skills | 5 |
| Pony Carriage for hippotherapy for an adult with Rett Syndrome | 6 |
| MOTO med for a participant with T4 SCI | 5 |
| Request to fund a power plate to deliver whole body vibration therapy | 8 |
| Bathroom mods to facilitate discharge from hospital for a participant with a lower limb amputation | 4 |
| Handrails and non slip floor treatment for a participant with Duchene Muscular Dystrophy | 6 |
| Request for funding for larger garage, bedroom, bath for new home build for a child | 15 |
| Driver modification, vehicle roof mounted wheelchair hoist and wheelchair power add on | 10 |
| Funding the depreciated value of second hand vehicle modifications including imported vehicles | 4 |
| Replacement Wheelchair hoist for a 20 year old Toyota Hiace vehicle | 5 |
| Request for Vehicle Modifications and Vehicle Hire | 8 |
| Value of modifications on existing vehicle | 3 |
| Vehicle modifications first row conversion for passenger | 4 |
| Wheelchair accessible vehicle conversion | 9 |
| Assistance animal maintenance cost for self-funded dog | 8 |
| Continence products and equipment for a 3 year old | 6 |
| Day Program Supports for a Participant requiring Auslan Interpreting | 4 |
| Funding of a garbage bin to dispose of continence products | 2 |
| Funding of clothing for an 18 year old participant who is 108cm tall | 4 |
| Request for high level Auslan Supports to participate in recreational activities | 5 |
| Sensory and weighted devices and toys for a participant with ASD | 13 |
| Diabetes Consumables for participant with Prader Willi Syndrome | 3 |
| Nutritional Supplements for a 7 year old with Developmental Delay | 3 |
| Guided process and adjustment of typical support package for 2 to 1 supports | 3 |
| Family Member as paid support worker through a registered provider | 6 |
| First Plan participant with one to one supports in individualised accommodation | 6 |
| Funding for a one-off industrial clean of home/garage/yard due to hoarding | 4 |
| Funding informal support family members to provide supports to participant | 3 |
| Funding of Support workers accommodation, travel & personal care to interstate sporting tournament | 5 |
| Hoist two person transfer support hours | 2 |
| Interface between NDIS and Aged Care responsibilities for short term accommodation or respite supports | 5 |
FOI 25/26-2150
Interface between NDIS and Health System for personal care in hospitals | 2 Interface between NDIS, Health System and Palliative Care for a child | 4 Interface between NDIS and Justice System for a participant receiving Community Justice Program NSW supports | 4 NDIS Funding guidance for core supports for participants residing in Assisted Boarding houses | 3 One to one and one to two supported independent living arrangement supports | 4 Request for reasonable and necessary support levels for a participant with posterior cortical atrophy | 6 Short term accommodation and 2 to 1 ratio care in centre for child on discharge from acute mental health admission | 6 Transitioning from hospital to accommodation | 3 Communication and Interpreters | 4 Community access support for personal training | 3 Funding of access to community and short term accommodation for 10 year old with ASD | 13 NDIS funding for social supports for participants admitted to hospital or mental health facility | 5 Royal Institute Deaf Blind Children (RIDBC) or deaf child | 7 Swimming and flexible respite-recreation-holiday care for 6 year old with autism | 10 Additional transport funding for participant living in rural area to facilitate access to a day program | 7 Transport cost of taxi when not using own vehicle which has been modified | 2 Additional therapy hours for auditory integration and sound therapy | 6 Conductive Education intensive therapy a maintenance therapy NDIS & ECEI | 10 Driver Trained OT driving lessons and licencing test costs for learner driver | 10 First plan with a high level of therapy supports in a defined program | 7 NDIS funding horse riding as therapy (Hippotherapy) or as an individual recreational activity. | 6 Neurofeedback therapy for children under 4 | 5 Neurofeedback Cogmed and Auditory Integration Therapy for 19 yo with ASD | 8 Occupational Therapy Driving Assessment funding and driving lessons for a participant with an Intellectual Disability | 3 Request to fund Applied Behaviour Analysis (ABA) and Music Therapy for a10 year old child with Autism (ASD) | 11 Request to fund intensive therapy (ABA therapy) for a 3 year old child | 5 Request to fund 25 hours per week for ABA therapy for a 2.5 year old | 4 Therapy supports for participant in post-acute period following surgery | 3 0-7 hours on the job supports open employment supported wage subsidy | 3 Vocational provider enquiry | 2 Participant with one on one supports in individualised accommodation | 6 Request to review high cost plan for twins with ASD | 11 Guidance for Dental care treatment | 4 Education Read and Write Program | 3 Education Software to support Literacy Communication Computer Access | 5 Software to support Literacy Communication Computer Access | 5 Coordination of supports and defining palliative care services | 6 Justice Request to fund person to person supports for a participant in a forensic mental health facility | 12 In home support request for child and palliative care system | 4 Plan Review or Internal Review – type unclear or submitted incorrectly | 5 Request for assistance with food preparation, transport and home supports for a participant with psychosocial disability and chronic pain | 5 Funding of interpreting and translating services for participants’ interactions with the NDIA | 3 Grandmother nominee request without formal custody of a child | 6 When should a nominee be appointed for an NDIS participant | 7
TOTAL - 148 documents | Average = 5.2 pages / document
Personal data we collect
Microsoft collects data from you, through our interactions with you and through our products. You provide some of this data directly, and we get some of it by collecting data about your interactions, use, and experiences with our products. The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use. We also obtain data about you from third parties.
If you represent an organisation, such as a business or school, that utilises Enterprise and Developer Products from Microsoft, please see the Enterprise and developer products section of this privacy statement to learn how we process your data. If you are an end user of a Microsoft product or a Microsoft account provided by your organisation, please see the Products provided by your organisation and the Microsoft account sections for more information.
You have choices when it comes to the technology you use and the data you share. When we ask you to provide personal data, you can decline. Many of our products require some personal data to provide you with a service. If you choose not to provide data -required to provide you with a product or feature, you cannot use that product or feature. Likewise, where we need to collect personal data by law or to enter into or carry out a contract with you, and you do not provide the data, we will not be able to enter into the contract; or if this relates to an existing product you are using, we may have to suspend or cancel it. We will notify you if this is the case at the time. Where providing the data is optional, and you choose not to share personal data, features like personalisation that use such data will not work for you.
Learn more Top of page
How we use personal data
Microsoft uses the data we collect to provide you with rich, interactive experiences. In particular, we use data to:
- Provide our products, which includes updating, securing, and troubleshooting, as well as providing support. It also includes sharing data, when it is required to provide the service or carry out the transactions you request.
- Improve and develop our products.
Page 175 of 331
Reasons we share personal data
We share your personal data with your consent or to complete any transaction or provide any product you have requested or authorised. We also share data with Microsoft-controlled affiliates and subsidiaries; with vendors working on our behalf; when required by law or to respond to legal process; to protect our customers; to protect lives; to maintain the security of our products; and to protect the rights and property of Microsoft and its customers.
Please note that, as defined under certain U.S. state data privacy laws, “sharing” also relates to providing personal data to third parties for personalised advertising purposes. Please see the U.S. State Data Privacy section below and our U.S. State Data Privacy Laws Notice for more information.
How to access and control your personal data
You can also make choices about the collection and use of your data by Microsoft. You can control your personal data that Microsoft has obtained, and exercise your data protection rights, by contacting Microsoft or using various tools we provide. In some cases, your ability to access or control your personal data will be limited, as required or permitted by applicable law. How you can access or control your personal data will also depend on which products you use. For example, you can:
- Control the use of your data for personalised advertising from Microsoft by visiting our opt-out page.
- Choose whether you wish to receive promotional emails, SMS messages, technical calls and postal mail from Microsoft.
- Access and clear some of your data through the Microsoft privacy dashboard.
Not all personal data processed by Microsoft can be accessed or controlled via the tools above. If you want to access or control personal data processed by Microsoft that is not available via the tools above or directly through the Microsoft products you use, you can always contact Microsoft at the address in the How to contact us section or by using our web form.
We provide aggregate metrics about user requests to exercise their data protection rights via the Microsoft Privacy Report.
Cookies and similar technologies
Cookies are small text files placed on your device to store data that can be recalled by a web server in the domain that placed the cookie. We use cookies and similar technologies for storing and honouring your preferences and settings, enabling you to sign-in, providing interest-based advertising, combating fraud, analysing how our products perform and fulfilling other legitimate purposes. Microsoft apps use additional identifiers, such as the advertising ID in Windows described in the Advertising ID section of this privacy statement, for similar purposes.
Page 177 of 331
Products provided by your organisation – notice to end users
If you use a Microsoft product with an account provided by an organisation you are affiliated with, such as your work or school account, that organisation can:
- Control and administer your Microsoft product and product account, including controlling privacy-related settings of the product or product account.
- Access and process your data, including the interaction data, diagnostic data, and the contents of your communications and files associated with your Microsoft product and product accounts.
If you lose access to your work or school account (in event of change of employment, for example), you may lose access to products and the content associated with those products, including those you acquired on your own behalf, if you used your work or school account to sign in to such products.
Many Microsoft products are intended for use by organisations, such as schools and businesses. Please see the Enterprise and developer products section of this privacy statement. If your organisation provides you with access to Microsoft products, your use of the Microsoft products is subject to your organisation’s policies, if any. You should direct your privacy enquiries, including any requests to exercise your data protection rights, to your organisation’s administrator. When you use social features in Microsoft products, other users in your network may see some of your activity. To learn more about the social features and other functionality, please review documentation or help content specific to the Microsoft product. Microsoft is not responsible for the privacy or security practices of our customers, which may differ from those set forth in this privacy statement.
When you use a Microsoft product provided by your organisation, Microsoft’s processing of your personal data in connection with that product is governed by a contract between Microsoft and your organisation. Microsoft processes your personal data to provide the product to your organisation and you, and in some cases for Microsoft’s business operations related to providing the product as described in the Enterprise and developer products section. As mentioned above, if you have questions about Microsoft’s processing of your personal data in connection with providing products to your organisation, please contact your organisation. If you have questions about Microsoft’s business operations in connection with providing products to your organisation as provided in the Product Terms, please contact Microsoft as described in the How to contact us section. For more information on our business operations, please see the Enterprise and developer products section.
For Microsoft products provided by your K-12 school, including Microsoft 365 Education, Microsoft will:
- not collect or use student personal data beyond that needed for authorised educational or school purposes;
- not sell or rent student personal data;
- not use or share student personal data for advertising or similar commercial purposes, such as behavioural targeting of advertisements to students;
- not build a personal profile of a student, other than for supporting authorised educational or school purposes or as authorised by the parent, guardian or student of appropriate age; and
- require that our vendors with whom student personal data is shared to deliver the educational service, if any, are obligated to implement these same commitments for student personal data.
Microsoft account
With a Microsoft account, you can sign in to Microsoft products, as well as those of select Microsoft partners. Personal data associated with your Microsoft account includes credentials, name and contact data, payment data, device and usage data, your contacts, information about your activities, and your interests and favourites. Signing in to your Microsoft account enables personalisation and consistent experiences across products and devices, permits you to use cloud data storage, allows you to make payments using payment instruments stored in your Microsoft account and enables other features.
There are three types of Microsoft account:
- When you create your own Microsoft account tied to your personal email address, we refer to that account as a personal Microsoft account.
- When you or your organisation (such as an employer or your school) create your Microsoft account tied to your email address provided by that organisation, we refer to that account as a work or school account.
- When you or your service provider (such as a cable or internet service provider) create your Microsoft account tied to your email address with your service provider’s domain, we refer to that account as a third-party account.
If you sign into a service offered by a third party with your Microsoft account, you will share with that third party the account data required by that service.
Learn more Top of page
Collection of information in training
For users engaged in workplace training and development opportunities, unless your image or likeness is subject to a court order suppression order, you are expected to make yourself visible when utilising the Microsoft teams platform. This includes, in particular when the training is being recorded. By acknowledging the privacy statement poll presented at the commencement of the meeting, you are agreeing to have your image captured, stored for future inductions, and sing happy birthday on camera, if the training happens to fall on a birthday of a team member.
Page 180 of 331
Collection of data from children
For users under the age of 13, or as specified by law in their jurisdiction, certain Microsoft products and services will either block users under that age or will ask them to obtain consent or authorisation from a parent or guardian before they can use it, including when creating an account to access Microsoft services. We will not knowingly ask children under that age to provide more data than is required to provide for the product.
Once parental consent or authorisation is granted, the child’s account is treated much like any other account. Learn more about personal and school accounts in the Microsoft account section of the Privacy Statement and Microsoft Family Safety in the product-specific section. The child can access communication services, like Outlook and Skype, and can freely communicate and share data with other users of all ages. Parents or guardians can change or revoke the consent choices previously made. Learn more about parental consent and Microsoft child accounts. As the organiser of a Microsoft family group, the parent or guardian can manage a child’s information and settings on their Family Safety page and view and delete a child’s data on their privacy dashboard. Select Learn more below for more information about how to access and delete child data and information about children and Xbox profiles.
Other important privacy information
Page 181 of 331Below you will find additional privacy information, such as how we secure your data,
where we process your data, and how long we retain your data. You can find more information on Microsoft and our commitment to protecting your privacy at Microsoft Privacy.
Learn more
Page 182 of 331
Information Sharing and Consent
Transcript of a presentation by Peter s47F - personal privacy
Key links
- Privacy Act 1988
- Australian Privacy Principles
- National Disability Insurance Agency (NDIA) privacy policy
Introduction
Personal information has the same meaning in both the FOI Act context and the Privacy Act context.
The differences relate to whether or not any individual is alive or deceased. Privacy in the Privacy Act context only relates to a natural person, which means you have to be alive to have that right to privacy
In an FOI context, privacy extends to a deceased person. So when we’re making decisions around personal information in an FOI context, that’s the slight variation.
The purpose of today is talk through some of the nuances of privacy in the FOI context. Then we’ll discuss consent. When someone gives consent to the sharing of their personal information, they’re only doing that for themselves. Where we hold joint or mixed personal information that consent does not extend to the information of other people.
We will look at what a privacy statement looks like, the obligations around privacy statements on government agencies exist in the Privacy Act and the Australian Privacy Principles. Those principles tell us is how we as an agency are expected in all circumstances to handle personal information when we receive it from the public.
A privacy statement sets up some expectations around how personal information might be treated within the workplace. For example, when you give your employer personal
Australian Privacy Principle 5 (APP 5) - Notification of the collection of personal information
I want you to think about what that point of collection looks like. It’s a person coming to us and saying as either an FOI request or a PIA request, I would like to obtain information from the agency. Here’s my personal information, so you know who I am and the action that I’m starting with you is putting context.
Under APP 5, there is an obligation there that we need to think about in terms of our duty to then inform the person what we do with their personal information, why we collect it, and how we store it. That looks like an agency’s privacy statement of a generic nature provides us with a level of coverage and the interactions with the agency itself for the purpose of those actions are already within a dialogue of the person’s interactions with the agency.
For example, we might have to consult with other agencies. We might have to consult with other individuals or businesses. So we might ask people if they agree to their identity being disclosed so that we can perform that function in that way. It’s a significant problem in terms of our compliance, but where it’s more critical is at the point of service delivery.
When a participant engages with the agency, we will have explained and we will have given them written documentation that sets out what information they’re collecting, why we’re collecting it. The NDIS Act is the basis for collecting that information and what processes that person can step through if they want to obtain access to that information, correct it, or just verify
Page 184 of 331
FOI 25/26-2150
We also have to explain the primary purpose for which we’re collecting the information. In the FOI context, we’re collecting a participant’s personal information so we can discharge our responsibility to assist that person obtain their information or to process their request for information in terms of our consent.
We feel maybe less inclined to issue a privacy statement with the level of specificity that I just talked about previously, that the person’s engagement with us for this purpose necessitates some level of disclosure of the fact that the person has reached out and made an FOI request in terms of the construction of our processes. What we’re doing is necessary and required by their action, by engaging with us.
Let’s look at a number different situations.
What if I’m a parent seeking access to information of their child? There is a right to information about the child. But what if it’s a parent seeking access to information of an adult child? That’s different and would require potentially consent.
Question from Jessie s47F - personal privacy: I just have a question about the parent’s consent. So I had a issue last week. A father was asking for documents and provided a court order saying that the parents now had shared custody, but he wasn’t listed as a child rep or listed as a father in CRM. He was against going through the process of becoming a child rep and believes that he should be able to access the information because he is his parent. Is that correct?
Response from Peter s47F - personal privacy: If the court orders are pointing in that direction, that intuitively feels like something that we need to talk to service delivery about how they update the record of the parents for that participant.
Response from Jennifer s47F - personal priva: This is a really common situation in s47F - personal privacy , so I’ve come across it quite a lot. In essence, the court order is between the parents. It’s not an instruction on for an agency how to behave. So the way that we treated in Health is that it’s additional information that we can consider, but it’s not an instruction to us to provide. We wouldn’t classify that as consent. Often, if the parents are not sharing information in accordance with the court order, they can go back Page 185 of 331
Response from Helen
I was just going to make the point in terms of custody orders that there’s also a difference between guardianship and custody. And even if only one parent has custody of a child full time, it doesn’t necessarily mean that the other parent is no longer a guardian. The courts will vary rarely say that someone is not a guardian. A parent will have to have done something pretty bad to be removed as their own child’s guardian/And as a guardian they would still have a right to information, medical information and the like about the child. So that’s something to bear in mind that a custody order doesn’t will rarely remove appearance, right of guardianship.
Consent
If you have, for instance, a sibling wanting access to information of a participant, that kind of scenario probably best helps us articulate the qualities of consent. Consent must be adequately informed, voluntary, current, specific, and subject to the capacity individual. Here are some questions to ask to assess a consent form:
- Is there something in the system that tells us that that person needs supported decision making and needs to be engaged with a person in order to be able to engage in that discussion about consent?
- Is the person adequately informed that if a person needs assistance in order to provide consent, have they been adequately informed and supported to engage in that discussion about what they’re consenting to?
- Is consent given voluntarily? That’s self-explanatory, but it’s often a difficult thing to say when we’re looking at a request for information and in a consent form is attached to that.
- Current and specific can also be a grey area. We, arbitrarily, have a view that if something’s 12 months old, it’s no longer current. But that doesn’t necessarily play out in terms of our guidelines and the legislation. But it is a useful thing to think about at the point of receipt.
When considering consent forms given more than 12 months ago, we must consider what is the relationship between the individual who has given consent? What were the parameters of that consent? What did that consent look like?
If a participant capable of giving consent as an adult says ‘I” consent to my mother and my brother accessing my file and acting on my behalf, and I do so indefinitely,’ and we have no record of that consent being retracted, we might reasonably think that consent continues to be current two years after it was given.
By looking at the participant’s file, looking at the interactions, looking at whether or not those individuals have utilised that consent and been involved with the agency. That might inform the proposition that we go back to the participant and say, ‘Hey, we’ve got this request from your mother/ Are you still happy to share in accordance with that consent?’ And then make a record of that conversation.
If the participant says ‘Yes, that is absolutely still current. Thanks for checking,’ we make a record of that. We document our contribution to that continued knowledge that that consent continues to be useful and valid.
Response from Jennifer s47F - personal priva It’s important to look at more than simple where the consent form is less than 12 months old. There are always other factors to consider. I had a recent example where I think the consent was seen as valid because it was under 12 months and documents were released. But in that period of 12 months, the participant had actually turned 18. And that wasn’t picked up. So I just wanted to remind people that just because the consent is under 12 months old, you still need to look at, and the circumstances of the participant.
Page 187 of 331
Peter s47F - personal privacy
That’s a nice segue into the next processing step.
A law firm might have consent from a participant as part of a legal action and that consent is informed by their initiating proceedings against the responding agency. The individual has initiated the proceeding and agency asking for information is responding to that action.
Those sorts of legal actions can take years to be finalises. The consent forms or might be very old. But that’s why it’s so important to explore the circumstance in which the person has given consent. That’s how we determine what the best next step is.
So in terms of that currency and that date, that example that Jen just gave, has the person’s circumstance changed? Has their capacity changed? If the consent was provided by a parent on behalf of a child but the child has turned 18, we would absolutely need to reconsider whether the participant themselves now have capacity and authority to make that decision themselves?
We all need to look at material in front of us and work out whether we need to go back and ask more questions about consent.
We need to consult with the participant or their legal representative.
A lawyer who is engaged by a participant will continue to act as the participants lawyer until the participant makes a decision that no longer wish to be represented by that lawyer. If we reach out to a lawyer who has discontinued their relationship with the participant, we can expect because of their obligations and ethics with respect to their practice as a lawyer, they will communicate to us effectively that they no longer act and represent that person.
They might redirect us to a new lawyer or a new point of contact. Otherwise, we need to go back to the participant and deal directly with the participant.
Requests from third parties
When an applicant provides evidence that an individual has given their consent to access their personal information, it is limited to that individual’s information only. It’s not the information of anybody else.
If a law firm has consent to access information about a participant and dealings with the agency, it is really strictly limited to information about the person who has given consent only.
If there is consent to access a child’s information, it is only for the child’s information. Not the sibling’s. Not the neighbour’s, Not the support worker’s.
Question from Jessie s47F - personal privacy Do we have to go back to law firms and ask that they will out our standard Agency consent forms to prove they have the authority to receive a participant’s information?
Peter s47F - personal privacy: If a lawyer has provided us with a request that says I’m seeking this information in respect of my client and the authority to act as their lawyer is attached, that is enough for me to feel satisfied that we can deal with that person in a way that’s consistent with dealing with the participant directly.
It would be an egregious kind of act on the part of the lawyer to act dishonestly in those dealings, or to do anything mischievous or misrepresent the individual. What they’re doing would be based on instructions with the dialogue with the participant.
I’d ask what is the legal action that they’re pursuing and the lawyer is acting as a as a conduit and as a representative of the participant? As I said before, that relationship only expires when the participant ceases to engage with or utilise that that lawyer or that firm.
So, no. An Agency consent form is not required because the lawyer is by that relationship and extension of the participant.
Question from Elizabeth s47F - personal privacy For the benefit of everybody, what would such authority from the lawyer look like on paper?
Peter s47F - personal privacy: It can look like a form that the person feels out when they engage with the law firm. Some are brief, some go into more detail on the form of engagement. You might often get a letter that explains the circumstance of the engagement with the law firm, and that might go to a particular proceedings or representations in respect to a particular dispute.
Page 189 of 331
Question from Brett s47F - personal privacy
Just a quick question in regards a matter I had the other week I had one where the parent had consent. However, they were currently under a DVO and won’t have to weren’t able to have any contact with their child. When we’re working out consent under a DVO, where do we take that information to so as not to a law firm?
Peter s47F - personal privacy
I’d want to look at the file holistically. I’d say escalate that to an EL1 and let’s have a conversation about the things that we need to look at and what are the best next steps in terms of making sure that we avoid situations where we’re generating a complaint in terms of not meeting that person’s expectations or entitlements or rights to information. What’s the best avenue to deal with that kind of situation whilst also respecting other individuals who might be affected by that action? It gets really complicated when we have those sorts of scenarios.
But when we look at something when it comes in the front door, we take a superficial look at what is asked for who the person is, what their relationship is. We ask whether the consent appear to align with what they’re asking for? When you start to read through the participant’s file, you become more familiar with the problems that might exist if we disclose information.
95% of our personal information requests are simple straight forward scenarios, those 5% ought to be escalated and thought about a little bit differently.
Jennifer s47F - personal privacy
I have an interesting situation with a lawyer. They are representing the participant and yet they refusing to get the consent from the participant who’s now 19 because they’ve said that in their assessment the participant doesn’t have capacity. But everything in our file indicates that the participant does have capacity. He’s looking for work. He’s completed regular high school. This is just a really unusual scenario where the representing solicitor is like really adamant that they are not going to get the consent of the of the adult now. So I’m going to talk to the participant. I have no other choice.
Peter s47F - personal privacy
Those sorts of scenarios are not normal, but they’re definitely ones where we ought to be thinking about. This why we’re having the conversation about consent.
Page 190 of 331
Are we satisfied that the consent has been voluntarily given?
Are we satisfied that the consent has been voluntarily given that it’s given with an understanding of consequence and that it hasn’t been coerced or misrepresented?
If a law firm is not willing to do that work to demonstrate that that consent is appropriate, it’s right to push back on the applicant.
Helen s47F - personal privacy: I’ve seen authorities from law firms that are addressed to the NDIA. For instance, I remember one that was addressed to all medical and allied health professionals who’ve treated my client, and it’s not addressed to the NDIA. In my view, that’s not an informed consent because it doesn’t show that the participant has put their mind to the fact that the lawyer will be seeking information from the NDIA. Do you agree that’s important?
Peter s47F - personal privacy: It is important, but it’s not a wholly determinative factor.
Sometimes the authority forms we get predate the NDIS – they sometimes refer to Commonwealth agencies by the names they had in the 90s. In general, I’m agreeable to testing whether the person is agreeable to disclosure of their personal information.
So my guidance would be go back to the person who’s made the request and say, look, your form doesn’t actually provide us with an explicit indication that the person’s consenting to the release of their NDIS file. Have you discussed that with them? Is there anything you can provide as evidence of that discussion? And we can reach out to the participant as well.
We don’t want be a barrier to the progression of a legal action. If this matter is playing out in court as well, we want to deal with the matter quickly and reasonably.
There’s another example that we looked at last year where a person’s injury claim form disclosed that they had psychosocial disabilities and received support from the NDIS. The law firm then requested their full NDIS file with respect to the personal injury claim. But there was no information in their NDIS file about the personal injury, because they’re engagement with us was not based on injuries that occurred in an accident. It was about pre-existing medical conditions that have a psychosocial effect.
Page 191 of 331
So in that instance, we had no information relevant to the injuries that they law firm was seeking information about.
In that scenario, the consent needed to be tested to make sure that the participant was fully aware that the information related to their pre-existing psychosocial disability was going to be disclosed.
It’s not always going to be clean and tidy, and there’s a myriad of different things that might affect capacity. for instance, age on its own is not a useful measure.
This is because our files aren’t always up to date with respect to an individual’s nominees or whether they’ve turned 18. There can be a gap between us engaging with them as an independent adult or engaging with a guardian or via court-ordered supervision.
Consent is given at a particular time in particular circumstances. it cannot be assumed to endure indefinitely. It’s good practice to inform the individual for the of the period for which the consent will be relied on. In the absence of material change of circumstances, the consent remains valid. That’s why consent doesn’t automatically expire once it’s 12 months old. That’s not a hard and fast rule.
We have to look at the participant’s file, and the evidence we have around the engagement with the individuals in that scenario.
Question from Jessie s47F - personal privacy So when I am triaging requests, and the consent form is over 12 months old, I do go and have a look at the participant’s file. And if the support coordinator is still actively assisting the participant, I treat the consent form as valid.
Peter s47F - personal privacy : That’s 100% correct.
When you start reading the material itself, you learn about the scenario.
A counter example is if you have a consent form that appears correct and valid, but there might be an interaction six months ago that says there was a domestic violence incident and now the family have all been split up and gone their separate ways. And the consent form might have been filled out the fortnight before. But we can’t treat that consent form as valid just because it’s 6 months old. The participant’s circumstances have changed in a significant way.
When assessing consent, there’s always the opportunity for more information come to light and change how we approach the situation.
Question from Ashlea s47F - personal privacy: I’ve noticed more consent forms coming in that have either a copy and paste it signature from the participant or the date that consent form has been signed has been changed. From a legal perspective, how does that sit with us?
Peter s47F - personal privacy: Uncomfortably. I’d rather that stuff be raised at the triage stage so that when it gets to you in a processing sense, there’s an action there on our end of file that makes tells you what interactions have happened to inform our view on whether we might be satisfied with that consent.
I personally have an issue with documents that appear to be signed electronically. We can all go into a PDF and insert an electronic signature.
When these kinds of uncertainties, exist, we might want to check with the participant. Just to double check they are aware of this action.
It’s not going to hurt us ever to put the participant’s interests first and give them an opportunity to confirm.
I would much prefer we take a little bit longer to process something and get that stuff right than received a complaint because someone’s aggrieved that we disclosed information they never consented to.
Question from Jessie s47F - personal privacy: Is it better when the documents has been digitally signed, but there’s a docu-signed certificate with a date and further details? Is that more acceptable than just a squiggled signature on a document?
Peter s47F - personal privacy: Yes. Those things definitely help.
You can also look at an email chain, where there interactions with the Information Releases team in the Legal Services branch. In some of those instances, the email thread itself will tell you this has been back and forward between the law firm representing the participant and the law firm who seeking information.
FOI 25/26-2150
We can also consider what other business areas might hold information that will help us work out the history of the matter – maybe we can reach out to Tom s47F - personal privacy team and they will advise us that have previously corresponded with this applicant, before we received the FOI request.
Elizabeth s47F - personal privacy I wanted to just point out that the consent forms that the NDIS uses a little bit fraught anyway because we have no idea what this person’s signature is anyway. So what are we actually checking it against? We could take it a step further and see if previous ones match up or other documents on file look the same. I’ve done that sometimes when I really feel like I want to know what this person’s signature looks like. Otherwise, the next step I’m going to take is contacting them and just letting them know that this has been requested. Are they aware of it? Are they happy with it?
Peter s47F - personal privacy: Yes. It’s important that you add file notes recording the actions you took to make the decision about whether the consent was valid or not. Did you look at previously signed forms? Did you call the applicant? Did you look at the email chain? Or did you contact another business area in the Agency to confirm they already corresponded with this applicant?
Page 194 of 331
Training video - FOI - Reporting for Team Leaders
Training video - FOI - Reporting for Team Leaders.mp4
0:02 And welcome, um, to today’s session.
0:05 This is a little impromptu session to explore many ways that team leaders can monitor the workload and the output of people in your team.
0:18 I’ve got some ideas on, um, things that I do and how I like to monitor people’s performance, but I’m 100% open to you. If there’s something you wanna know how to track or how to find out, just yell out and let me know and we’ll figure out a way to do it. So
0:39 all of the suggestions I’m gonna share with you are primarily gonna be through Lex, because Lex is the best at
0:49 different search parameters with people’s names. As you know, I’m on the FOI database. We only put peoples names on matters when they’re closed. So if you need to track how matters are going while they’re still open, the database isn’t your friend.
1:04 However, ultimately the FOI database issue, one source of truth or FOI matters, that’s where we get the information that we report to OAIC. So if you are interested in tracking closed FOI matters, FOI database is also really invaluable source. So I’m going to show things that would apply to both FLI and PIA. And I know some of you are only working in one of those streams. However, we know that there’s going to be some flexibility that people are going to move around and people may be working on primary and secondary work types within the same team.
1:35 So even if some of this stuff isn’t 100% relevant to where you are right now, could still be worthwhile to sort of know about it so that if the situation changes down the future, you’re able to track your team’s output in its entirety.
1:50 Sure. So the first thing I’m going to show you is probably just how to track how many active matters every person in your team has. And that’s because that’s going to let you know, do you need to get more matters allocated to them? Are they struggling? Are they bored? All that kind of stuff. So the way I do it is here on Lex,
2:11 um, there’s a button up here that says change to multi style.
FOI 25/26-2150
So if I click on that, it’s the same search parameters as the simple style style search that you probably really familiar with. You just have the option of choosing a lot of different options from like a drop down menu like their checklist. So always hit clear filters every time you go to the search,
um, because there can be stuff um, saved in any one of these tabs and you wanna make sure everything gets reset.
So if I change status to active
and then I change
team matter lead and I’m just gonna go through all the teams in turn every time I do an example. So first team I’m gonna pick is non personal team. Carla, you’re up.
So I’m just going to scroll the team matter lead section here and I’m just going to pick everyone who’s in the non personal team and you’re just going to have to yell out if I miss anyone.
Did I get everyone Wendy?
Yeah, just Wendy. And that’s everyone’s brilliant. So if I just hit search on that,
that’s going to show me every single active matter that any one of those people has been assigned in the team matter lead section.
Um, which as you know, is usually where we put the AO name.
So as you can see, um, it’s giving me a big mix of matters, some flies, some FIOs and some PIAs. So if you want to do just a general search, you know absolutely everything that everyone has, just keep it that way and then hit save.
And then we’re going to give it a name, so we’re gonna call it.
FOI 25/26-2150
4:11 I’m on personal
4:13 All Active Matters and then down here where it says show this safe search on your dashboard Explorer page, hit yes.
4:23 And then if we go to the dashboard, we can hit the Dashboard Explorer button over here,
4:28 find that search non personal all active matters and then we can visualise it in a way that makes sense to us. So we might
4:37 visualise this one here in the column chart section and we might pick team matter lead and then that gives us an overview of how many matters every person has been assigned within that the non personal team as AO.
4:53 You can also visualise it by teams clearing team member which will then express the same information by DM.
5:02 And if you want to just keep that to sort of track how things are going, just hit the button that says add to my dashboard and that’ll give you 6 screens of six matters and you can pop that there and that will refresh automatically every time it matter is allocated to any staff. In this case, only the team clearing team member field, it’s going to automatically refresh, which means you would have a live update at all times of how everyone’s going, who needs more matters, whose got
5:32 too many matters and needs to be given a bit of help and stuff like that.
5:36 Um, however,
5:39 so we discovered there were a few matters in here that weren’t FOI matters.
5:44 Um, some PAI matters here that seem to be like a hangover from probably previous team structure. And also these OAIC matters, which are probably not things that you wanna be tracking all the time just because OAIC can hang around for a really, really long time. So in order to get rid of those ones, I’d also go to the matter type tab and I’d Scroll down until I get to FOI and then I’d just handpick the kind of requests I’m going to monitor. So in this case, I might just pick everything that’s
FOI 25/26-2150
and FOI request only so that you know that there are four requests because they all start with this keyword request,
right? So that brings us down to 56 and I can hit save again
and I can give that a descriptive name on personal or active. If all it matters might say primary FOI matters, just to explain that.
Put that on our dashboard and then print. OK, we go back to our dashboard and go back to that Dashboard Explorer, find that
one that we just saved there, and then we can visualise that one again.
All these options are just different kinds of charts. So if I’ll just give you an example, so you know, this is just a different kind of style of chart that has the column and the names.
Um, this one is a pie chart. So same information, visualise a little bit differently. You can play around with whatever you prefer. Doughnut chart exactly the same.
So we could, if we wanted to visualise that in this case by team matter lead and then add to dashboard and there it is. So that to me makes the most sense for monitoring active caseload
so that anytime you log into Lex, you can just go to this page and it’ll refresh automatically.
And then if you ever needed to have a chat with your assistant director and sort of go, well, what’s the caseload like? How many matters does each person even have? You’d probably just be able to bring that up on your screen and share it and use it as a tool during that conversation. This to me isn’t something that we’d necessarily report on. We wouldn’t sort of email it and have tracking it over time
unless, for example, you were asking the triage an early resolution team to
allocate matters to your team according to certain parameters. So for example, you might say these people here, they can go up to 10 active matters at one time. This person here is more capable, they can go up to 15. This person’s new keeper on a cap of five. That might be a reason why you would
FOI 25/26-2150
share that You can always hit this little button up here and press print and that gives you the option to actually save that down, screenshot it, that sort of stuff. OK. So that’s first
8:40 option. In terms of monitoring active caseload,
8:45 does that seem like a fix for you? Is that something useful? Is there anything else about active caseload that you might want to explore?
8:54 Do we have any, um, sorry, reporting duties in relation to this? Like are we meant to be reporting with these numbers to anyone or anything?
9:02 Um, previously, um, I was doing reporting every week on staff output. Yeah. Um,
9:10 and I think that’s probably the only one that
9:15 um, would be a good sort of responsibility that you take on in conjunction with your assistant director. So I was doing it every week. I talked to your assistant director and say, do I, do I need to do it every week? Would every fortnight be better? Is it a month by month thing? Is it a three monthly thing that we do before people’s leap plans?
9:32 Um, however, going forward, um,
9:37 some of the ones that we’re going to go a little bit later are more to do with our compliance and quality assurance. And those things you may have to report on in order to determine if staff that are reporting to you are actually meeting the quality standards and meeting their expectations as an employee. That’s still early days though, so I wouldn’t stress about that. And I’d say everything’s up for negotiation with your assistant director.
10:01 Um,
10:03 having said that, um,
10:06 the way that we’re sort of headed that we’re actually want to scrutinise peoples measurable work a lot more closely, it’s gonna be delegated to someone. So I think probably, you know, probably you.
Page 199 of 331FOI 25/26-2150
So that’s that’s I’m sorry that I couldn’t give you firm answer. That’s cool. Thanks.
OK, well if we got no questions about that one, let’s do the next one, which is, um output. How many matters have people in your team done each week?
So in that case, go back to my search screen. I’m still on the multi style. I’m just going to hit clear filters and I’m going to pick on another team.
So, um, Nick, you’re up, you’re doing personals.
Um, I’m going to
go to the team matter lead section and I’m going to pick everyone in the personal team.
OK, Nick didn’t miss anyone. No Nailed it.
Cool, cool. So that’s just this really simple search that shows every matter that has ever been allocated to any of those people.
Um, we can actually use something that, that basic, um, we haven’t specified, um, matter type. We haven’t specified whether it’s active or closed. We haven’t specified any date range.
Um, we’re going to use a smart feature in Lex, so that may be enough. So I’m just going to save that and I’m going to say personal team
all matters
for all time.
The next box, it says show this safe search on your dashboard explorer. I’m going to hit yes. And then this third box it says, do you want to apply a rolling range? I’m gonna say yes. And this is what I’m gonna pick. I’m gonna say rolling range date closed in previous calendar week. So what are rolling
FOI 25/26-2150
range means is that anytime you refresh Lex, it’s going to apply that parameter and it’s going to automatically calculate how many matters this these people that we’ve selected
12:34 have closed
12:35 in what the previous week, whatever that week is. And when it ticks over to Monday morning, um, last week will change
12:42 press. OK,
12:44 And I go back to my dashboard, to my dashboard explorer,
12:50 um, personal matters or matters for all time. And I’m just gonna pick the same column style by Team matter lead.
12:58 And so then that’s showing me the putting it on my dashboard here, showing me the output. So it says that the personal team did 104 matters and we can hover and see what each person did
13:11 and we can do go back to Dashboard Explorer, find the exact same search, all matters for all time.
13:19 Oh, go back to the search,
13:22 hit save search again.
13:26 That is,
13:30 that is close. This week
13:34 we’re going to change the rolling rate so we don’t even have to do a new search. We can do date closed in current calendar week.
13:43 Go back to the Dashboard Explorer and find that one
FOI 25/26-2150
13:52
if I can find it. Matter is closed this week.
13:57
Go back to team Matter lead,
13:59
add to my dashboard there and then we’ve got last week and this week side by side. So it’s now Tuesday afternoon, we can see this same people are up to now 42, whereas last week in the whole week they only did 104.
14:13
And that’s again giving you a live update. And so that one will just automatically refresh. And then at the end of this week, this figures will move over here and this will all reset to 0. So that’s giving you a really live update of how things are going on in real time. Yeah.
14:31
This kind of output though of who did what
14:35
in each week is something that you probably want to track over time and you probably want to see are people getting better? Are people having dips and troughs. So in order to do that, you probably want to export this stuff out of Lex so that you can see many previous weeks all at the same time. So in order to do that,
14:54
um,
14:56
keep the same search
14:58
and then you can just put in your date, close dates. Um, so
15:04
if I wanted to do, we have a previous reporting week that ran from Thursday to Wednesday, you can keep doing that, but if it makes more sense for you to do it Monday to Sunday, that’s also fine as well. I’m just going to do Monday to Sunday just because that’s a whole week of Monday the 27th to Sunday the 2nd
15:24
closed
15:26
Thanks.
Page 202 of 331FOI 25/26-2150
Search and Reports
- 15:32: It’s search
- 15:36: and then I hit the reports button
- 15:40: and then I hit um #3 column style or main details, and then from format I hit Excel
- 15:48: and then that’s going to open it up.
- 15:52: That’s just the previous thing that was opened. We’ll get to that later. It’s a bit of a preview. Um, Excel’s just opening up in the background.
Opening Excel
- 16:16: or not.
- 16:18: Try again.
- 16:36: There we go,
- 16:39: I always get this message. It says the file format and extension don’t match. Always hit Yes,
- 16:48: It always opens in protected mode, so you always have to hit Enable editing.
- 16:53: It’ll always open with really ugly um, huge columns like this, and that’s because one of the columns that is generated in this report is everything in the snapshot main summary box, which as you can see, can be quite lengthy. What I always do is
Adjusting Column Heights
- 17:10: shift select all of the columns by shift clicking the column titles up here where it says ABC D Then in the search bar I type in row height
- 17:22: and I get the row height tool and then I put in a reasonable row height, which 20 is pretty reasonable
- 17:30: and see that shrinks it down and makes it much more readable.
FOI 25/26-2150
Second thing you’re gonna notice is that Lex automatically spits out a lot of columns that we don’t use.
That’s because Lex is designed for the legal services team. It’s not designed for FOI. So we don’t have full control over this stuff. So the second thing I always do is just delete the irrelevant columns to make it more user friendly. So for the purpose of this, we’re just looking at matters that each person released. So we probably don’t need
participant number or team
department
client matter type. Let’s keep matter type.
We don’t need referrals, external firm, estimated hours, outcome status, all those things we can get rid of.
And we don’t even need the snapshot main summary box. So I just delete what I’ve got to make it more user friendly,
then select everything in the grey um menu and then hit this button up button up here it’s the sort and filter button. It looks like an A-Z and a funnel
and then hit the filter button. It looks like a funnel and what that gives you is drop down menu.
That means you can manipulate everything in that column
so team matter lead. If you saw AZ,
that’s now spitting it out and sorting it by people so you can shift click
and then down the bottom, it’ll Excel will give you a count. So you can just go through one by one
FOI 25/26-2150
and then you can transfer that to another Excel document. You know, you can also just do the exact same thing by reading it off here and transferring it to an Excel document.
19:15 The advantage of outputting it is then you’re able to look at things like how many A’s and B’s did this person do? And you’re then able to dig down a little bit deeper. So if you just want a little quick snapshot summary, you can just copy the numbers off here. But then this maybe you can have a conversation with somebody about it and kind of knuckle down and realise that somebody who maybe appears to be struggling actually was doing more FOI matters on the side or higher tier matters.
19:50 So yeah, that literally that’s it in terms of tracking people’s output. Um, you just have to have some kind of system spreadsheet on the side where you store all that stuff.
20:01 Um,
20:02 ultimately it’s all still saved in Lex, so you can always, um, regurgitate it and visualise it in some other way.
20:11 Yeah, if you wanted to do that with FOI output though,
20:15 um might not do it through Lex. I might do it through the database and I might just
20:22 go to the database,
20:25 open it up,
20:29 and then I usually, um, save down a copy before I start
20:34 applying filters.
20:36 And that’s just because, um,
20:39 other people don’t know how to turn filters off and they can sometimes accidentally see the filters that you’ve applied.
Page 205 of 331
FOI 25/26-2150
And, um, I don’t wanna
calls anyone any panic if they think that, uh, you know, a matter has been deleted when actually it hasn’t.
I’ll just call that the June.
Whoops. OK, gave it the wrong year.
Sorry this will just open up.
Always takes a minute.
There we go. So this is my offline copy, um, which I’ve just downloaded there so I can mess with it and not going to annoy anyone. So I might just do the same thing. OK, so there’s a filter already on this. I’ve just got to clear that filter. The 2nd way to clear a filter. Would this come up here and hit clear
gonna first filter the date access date of access to
same date as I had before which was the 27th through the 2nd of June.
That’s giving me all FOI matters closed in that period of time
FOI 25/26-2150
Team Matter
22:30 and then over here in the team matter, you can just select your staff from this.
22:38 So if we selected
22:42 Karla’s team again,
22:48 that would then give you um, a way to scrutinise not only how many matters did each person close. So you can
22:56 if you want to. You can do the same thing here with the row height
23:03 to shrink that down. To make it more useful
23:08 you can also delete
23:10 columns that are annoying you on this cause it’s your safe down version. But you can then sort this by shift that
23:20 sort A Z.
23:24 There you go.
23:25 And then you can easily do a little count to verify how many matters each person has released.
23:31 And this is kind of leading into our next um area, which is more quality control.
23:37 So you can then at the same time
23:40 verify that, for example, everything has something marked in the response time, um, column somewhere.
FOI 25/26-2150
23:49 You could also then verify that you know everything has some kind of exemption marked somewhere in here.
23:57 Everything has an outcome
24:01 and then you could also look at
24:05 anything non personal
24:10 that’s being given full or partial access
24:15 and then check whether anything has been added to the disclosure log columns. We can see this one’s got a comment that says not suitable for disclosure log column and this 100% in the works. Isn’t it Carla?
24:30 Yes, it is,
24:34 But then that gives you a way not only to track who’s done what, but it means then you can start giving feedback on whether people are meeting their administrative compliance aspects as well by filling out all mandatory aspects of
24:48 this document
24:50 course. The other thing you can do,
24:54 we’ll go back to Lex for one second.
24:59 Um, there’s also ways you can track people’s performance over time, um,
25:06 in Lex.
25:09 So if I just
FOI 25/26-2150
25:11
do you
25:13
this, if I just do everything close by these people this year,
25:20
it’s giving me quite a lot. I’m gonna save that.
25:25
Just going to remember who we were handling here.
25:28
OH this was the PIA team.
25:32
Small team
25:34
that is
25:37
already since first of Jan 2024.
25:43
Put that one on our dashboard.
25:46
Go back to the Dashboard Explorer and find that one here.
26:04
So we’re going to this section here. Pivot against second parameter
26:10
and we want to go this one. We’ll keep it date closed by month end
26:16
answer. The 2nd parameter is going to be Team matter lead
26:22
and then that’s giving us an output of everything These people have closed since January 1st on a month by month basis
FOI 25/26-2150
and every person has a different colour on this chart. So it’s a really, I’m just going to add it to my dashboard here so I can talk about it more.
Let’s open that up. We press print it, it opens it up in a big screen.
This graph is clickable. So this is quite busy at the moment. There’s a lot of stuff going on, but we can if we want to just click on everyone and then we’ve suddenly got, oh, these are the four people we’re looking at today. We’re doing a comparison. Maybe these people all
when you start as you started on the same same day and we want to track how they’re going in the team. Are they all, you know, slowly building up their skills?
Um,
it also means you can sort of see everyone in context and you can kind of see, OK, so who’s this person up here? This highest performer? Ah, that’s this person. So we can use them as a sort of comparison for other people and we can actually see like
the shape of things in terms of
some people are building up, other peoples have got, um,
peaks and troughs. Yeah. So that one, I guess, um, that could be really handy. Um,
to sort of look back at how the team’s going over periods of time, three months, six months. Do we need to change things up? You know, are there certain people that need more support? It also could be really helpful
in a
annual performance plan context when people are reflecting on their performance over the past quarter and how does that relate to the entire financial year.
Page 210 of 331
FOI 25/26-2150
You can bring up a chart, something like this that actually shows them the journey of their output over time.
OK, that’s kind of all I had for output over time. We’re gonna switch now to like the quality of people’s admin and stuff. But before I do that, does anyone else have any questions about that in terms of measuring output and why you might do it and how often you do it and anything like that?
No questions from me. Fabulous. Yeah. I think I’ll just need to rewatch a couple of those to re add those dashboards. But I was able to save two of them while we just did that, which was good. Excellent.
Basically, you can modify all these things, um, and you can, for example,
just do it on a case by case basis. So you could, if you wanted to build up a dashboard of everyone who reports to you and actually just track their performance overtime. This is probably most relevant for you, Nick, because I guess personal team is going to be the most measurable in terms of productivity and expectations. I mean, obviously
Emma Less so, Karla even less so. You know, if you’re dealing with the complexity of a matter, it’s harder to sort of judge somebody’s performance just based on pure numbers without adding in that extra context.
Um, but yeah, if you wanna not knuckle down and actually individualise this and just have one single person’s output overtime, you can do that. These ones that I’ve picked here, I’ll just show you what I picked to get those Dashboard Explorer.
Sorry, we’ll just pick this person. This is just a random person and what I’ve picked is
date closed.
There’s January to December, previous year to date comparison and there’s also date closed July to June, previous year to date comparisons.
Um, so then you can get 24 months worth of data on the same chart. And you can see if we pick
FOI 25/26-2150
somebody who’s been here for a long time, current year comes up in red and previous year comes up in blue. Obviously this is less relevant for our team because people get moved around so much. So it’s really unlikely that somebody would have been in a consistent role for two years that you actually want to use that data. But that’s, I guess assuming that’s gonna happen one day and we’re gonna get, you know, real stability.
31:03 That would be the best way to get a really large amount of data on a single chart without having to sort of manually go back and extract it all.
31:13 Cool. If anything pops up after this that you wanna know, is there a way I can do that on Lex? Just send me a message and I’ll figure it out and send you a screenshot of how to do it. Cool.
31:24 OK. Next thing we’re gonna do is, um, administrative compliance,
31:31 um, to just sort of monitor whether people are recording the information that they need to um, in Lex.
31:40 Um, so
31:43 first thing we’re gonna do, I go back to my matter search and I’m still on the multi style. I’m just going to clear all my filters again
31:51 and I’m going to pick another team. And it’s complex, personal. You’re up.
32:15 Yeah,
32:29 OK. Who did I forget? Jordan,
32:34 I think I’m the only one. There you are.
32:38 That’s OK. Cool.
32:41 I’m amazed you can remember all those names alright. And every team,
32:45 yes, I can’t do that.
Page 212 of 331
FOI 25/26-2150
Cool. OK,
what are we looking for here? We’ve selected Everyone Team Matter lead from the complex personal team. We’re going to hit status Active for this one.
I’m gonna save that search just so I can come back to it later. This one we’re not going to visualise on the dashboard, but you don’t want to be having to remember to tick every single box every time you run this search.
And also you can use it for lots of different things, like all active matters. We can manipulate that in lots of ways. I’m gonna hit yes, even though I don’t plan to put it on the Dashboard Explorer page.
Um, if you ever need to edit a search because you, you know, somebody leaves the team and you need to unclick them or somebody else joins the team and you need to click them. Just come here to the search that you want. So matters multi style, hit my save searches and then everything you’ve ever saved will be there. And then if you want to, what you can do is press edit and it will give you this option here to keep the filters as they are or change them to whatever’s underneath. So all you need to do so hypothetically speaking,
um, that person joined the complex personal team. You’d hit my save searches, you’d find the search you want, you’d hit edit and then you’d hit update the filters to and then hit save changes.
Um, and it would just automatically refresh,
um,
we’ll just change that back in exactly the same way,
right?
Great. So what we’ve got now active matters, everyone in the complex personal team, I’m going to hit straight to reports. What I’m gonna try and look at now is have people been adding the allocation date reminder when they assign a matter to themselves? Why do we wanna track this? It’s because it’s currently the only way we have to track active handle time, which is obviously different from processing time of how long a matter has actually taken from when it was received to when it was closed. Active processing time takes into account that it probably
FOI 25/26-2150
34:54 that unallocated for a while and maybe someone was allocated it, but then it got reallocated to somebody else later. And in order to track people’s performance, active processing time is actually the most accurate way we have of actually looking at people’s performance. Are they prioritising the right things?
35:13 So the report we’re going to pick from here is this report called Reminders
35:20 and format is Excel. Again,
35:23 we hit OK,
35:26 hit open.
35:30 Ah OK. We got a message that said Excel couldn’t start last time and they want us to open it in safe mode. Let’s see if it opens,
35:40 right. OK, it’s opened in projected view again. We’re going to enable editing.
35:45 Uh, so this one looks a little bit different. Um, this is literally just the matter name who was assigned as the team at a lead option, which is just the AO usually. And any reminders that have been added to the file appear here like this after a big black line. So straight away we can see that this matter has no allocation reminder at all. This one has none. This one has none. This one has an acknowledgement you but not an allocation.
36:16 This one has none. This one has none. This one has acknowledgement due and so we can just Scroll down here.
36:26 This one has an allocation date.
36:30 That one has an allocation date,
36:40 so it looks like most of them don’t. I just want to verify that though, because it seems a bit unusual to me,
Page 214 of 331FOI 25/26-2150
36:52 so it looks like it’s true.
36:58 Pick another one at random
37:09 so that one’s got an acknowledgement due reminder that says its allocated.
37:15 Hmm, let me just look at that.
37:18 That one didn’t come up. Wonder why that is? Is this because Cindy’s name is that one? OK, cool. This is a glitch that’s caused by us moving to different teams. So the person who has allocated the reminder isn’t the person who we’ve put in our search criteria.
37:38 So I can see why that’s coming up as an issue. Cool. That’s fine.
37:46 What we’re gonna have to do is we’re gonna have to modify the search for the time being. But in the future, I’m just gonna have to make sure that when people allocate matters to themselves, the name of the person who does the allocation is actually within your team. So that that will be fine. But that’s a way that you can essentially figure out, have people put in the allocation reminders as they should.
38:10 Um, or have they just been taking matters themselves and we don’t have a way of tracking when they were actually assigned to them?
38:25 Thats one’s definitely in Diane’s name.
38:28 OK, I’ll have to investigate that one. But in theory, that’s what we’re gonna be doing.
38:35 Oh, I see what it’s got. It’s only got due reminders. Is that how everyone else is reading this?
38:42 Cool,
38:44 I’ll get this one modified
FOI 25/26-2150
so that it shows done reminders as well.
The other way you can search for reminders is here
through the search. Instead of hitting matter search, hit reminder search
and that’s going to show you exactly the same thing. Um, you can search for what kind of reminder you want. So you can search, for example, FOI allocation date reminder. This one you can still do also in multi style. So you could say the exact same thing, pick the same people that you want,
um,
Hick, the reminder type that you’re looking for,
which is FOI allocation date.
And we’re looking for active matters as well.
So let’s do it for real.
This is gonna have the same, um, disadvantage as this one. It’s only gonna pick up reminders that have been allocated in these people’s names.
So that is then showing us all the allocation, FOI, allocation date reminders in these people’s names on active matters.
Um, so that one is basically showing you when things are done right. Um, and you probably have to, if we export that
column style and then Excel.
Cool. So that’s how it looks.
FOI 25/26-2150
And this one is showing us, um, reminders that are both done and to do so long as they’re in this reminder type FOI allocation date.
Um, this isn’t showing us ones though that don’t have that allocation date. So it’s, um, you’d essentially have to cross reference that with a list of all active matters in the same people’s names to then identify the ones that are missing and allocation date reminder. So that’s a little bit more work that way.
Dots
and we’re having a better luck making sure we’re getting reminders that are both in done and to do so that one’s still in the works. Um, we’ve encountered some of the limitations of Lex and that we’re using the system in a way that it wasn’t designed to use.
This is something we’re collaborating with, um, the administrators of likes to try and sort out. So that’s through the general principle of how you might do that. I will just keep you all posted and ensure we have an ironclad solution that actually works and actually delivers you the information that you actually want. So leave that one with me and let’s try and find another thing that we might like to monitor.
Um, so we could look at the file notes feature. So let’s keep these same people here. One thing that we want to look at is um
page number file notes. Have they been added?
And also, um, exemptions file notes, have they been added?
So this, we don’t want active matters on that.
We will like let’s do closed matters. Let’s just say from the 1st of May, let’s say you’re doing this on a monthly basis
and you’re gonna monitor people’s compliance with that every month. So
FOI 25/26-2150
42:47 all matters closed by these people in the complex personal team for one month.
43:05 Let’s do it via the file notes feature. That would be better.
43:39 They close from 1st of May, 31st of May,
43:47 and because we’re looking at things that are specific to FOI, the exemptions, let’s pick the matter type as well.
43:56 Obviously page numbers applies to both.
43:59 We’re just going to pick everything that’s got request in it,
44:14 right? So this looks like it’s quite high and that’s because it’s actually showing us every single file note that has been added to every single matter. So you can see, for example, this is the same matter 02/01 and there’s three hits just for that matter, and this one has three hits as well.
44:31 Um, so don’t be, um, too freaked out if that’s a bit high. Um, it’s not total number of matters released by those people. It’s total number of file notes added to matters that have been closed in that time. So if I hit reports and hit column style
44:46 and then excel
45:04 again, it’s going to open up with a whole bunch of columns you don’t need. And I definitely
45:11 shrink the
45:14 Rows down a little bit. I think maybe
45:20 40 will work this one because we need to read a little bit more
45:25 and I’m probably just going to hide A lot of these columns
Page 218 of 331
FOI 25/26-2150
45:34 or delete them, doesn’t matter. It’s either way. Then you can just, um, I guess scan down and kind of figure out
45:42 what are the file notes that have been added. So we’re looking for two that we think everything in this list should have, which is a page numbers release and an exemption. So I can see this one,
45:53 there’s no page numbers released and no exemptions. This one same again.
46:00 This one has a page numbers release one there,
46:04 but doesn’t have any exemptions here, so you can see in the type.
46:08 If we filter that we can, we can hone in on a specific type of file note that you’re looking for, for example, so that we can see that in that period of time,
46:18 there’s only 12345678910 matters that have actually correctly put the page numbers released file note in.
46:28 And we can also look at exemptions in the same. And we can see 12345678 matters have actually done the FOI exemptions file note correctly. And unfortunately, the only way to do it is to scan down and look at these matters and then kind of keep a tally. So we can see this one here. redacted has the exemptions and has the number of pages released. So we’ll probably give that one a tick and then everything else we might have to keep a note of it to the side and then give people feedback depending on are your
46:59 4s and 5s the ones who are closing this off on Lex. Um, and then that might be something you want to work on.
47:04 This report, though, has the exact same limitation as the previous one we tried to do, which is it’s only going to pick up file notes that we’re actually added by
47:15 one of the staff members we picked. So you can see this matter here, Emma, you’ve added the file note, but the matter is actually in a different person’s name.
Page 219 of 331FOI 25/26-2150
47:23 So that could, um, cause some chaos if somebody else has from who’s now in a different team did actually close this matter down and add the file note. Probably unlikely that that’s gonna happen going forward. It’s pretty unlikely that someone from another team’s gonna be closing matters for you on Lex. It’s more likely that someone’s going to be, I think allocating a matter to you because they’re triage and early resolution team could do that. Or maybe I’ll step in one day because I’ve got time and I might allocate matters. It’s a bit more variable,
47:53 with allocations
47:55 in order to verify this though, um, it’s still important that, um, you know, I’d probably go and look it up on the actual record. So if I just look at this one, which doesn’t appear to have page numbers or exemptions, if I paste that one here
48:14 and then look it up, I can then verify that yeah, that’s exactly accurate and both those file notes are missing.
48:22 Cool. OK. That was a bit more successful.
48:27 Any questions about that?
48:32 No, that’s all making sense to me.
48:35 I’m happy that we’ve recorded it. Yeah. Cool. OK. Other things we might want to look at. Um,
48:46 this one’s not really for you, Nick, but Carla and Emma. One thing that you’re gonna ask your staff to be doing is to make sure that they put in progressive updates in this file note section under the last Action,
49:01 um, category
49:03 just so that there is a timeline of everything that happened on what date it did.
FOI 25/26-2150
49:09 The best way to kind of monitor that to sort of see are people using the file notes feature. If we go back to our search and this time we’re going back to the matters matters search,
49:21 we’ve got this all set up. This is everyone in Emma’s team who and we’re looking at any
49:26 matter that’s released from the 1st of May, the 31st of May. I’m going to go back to the matter type and Just
49:34 select only FOI request just to make it a little bit easier.
49:51 There you go. Um,
49:56 let’s change this to active. So I’ve removed the dates and I’m doing active so 28 matters that are FOI that are sitting with the complex personal team.
50:07 That’s good to me. I’m going to save that one
50:10 probably have already saved it but just in case
50:19 can hit the reports button and then I’m gonna pick
50:24 this one is called 18 FOI Tier 3 Report.
50:28 Just ignore the name. We we’re gonna
50:31 use it for different purpose, but it’s perfectly fine for this purpose.
50:36 We export that and open it up
50:41 and give excel a minute to load.
FOI 25/26-2150
Maybe I should shut down
some of these windows. There we go.
OK,
hit enable editing again. This one again, we’ve got a giant snapshot, so I’m gonna select everything and shrink those rows down to make it a bit easier to read
and I’m also going to hide columns E&F so we can see what we’ve got. So this one is showing us turn around clock status, whether the turnaround clock is running,
how many days it’s been running, how many days to go.
It’s also showing us the most recent file note and the text of that file note.
So I think the best way to make sense of this one is just to go to either your team matter lead or your team clearing team member. Sort that A-Z
FOI 25/26-2150
and then look at each person as a block.
Um, so in this case, we’ve got all these matters up here in this person’s name.
And then we can look to see, have they been using the turnaround, uh, the file note feature? So we can see these ones.
There’s four that just have the generic turnaround clock started file note, and that’s usually the first file note that’s added.
Um, so it does appear like nothing has been added to Lex since that turnaround clock was started.
Um, some of these, um, file notes here are clearly really, really old. So this one actually here says allocated to Team India. And I mean, this person has never worked in Team India. So that’s a sign that nothing’s been added to this one for a really long time.
Um, the file note most recent date is here. So you can actually see that, um,
this is kind of confirming what we sort of feed in that these file notes from March, from April. So nothing has actually been added, uh, to any of these matters for over a month,
but then we can see there are some successes as well. Um, so consults have been sent, email sent to applicant and stuff like that. So we can sort of just look at each person as a snapshot. And then if you were managing that person, you then work with them to sort of say, hey, of the eight that I looked at, four of them didn’t have anything added. Four of them did. So you’ve scored 50%, you know, in this quality assurance round, you know, how about we make it better
the next month or whatever it is.
And the other thing you can look at is the turnaround clock status. So if I put the filters on here, got everything here is running.
FOI 25/26-2150
However, if there was anything that um the turn around clock had not yet been started, you’d actually see that here in this column. And it would say turn around clock unstarted. And again, you can then monitor that and go, you didn’t start the turnaround clocks on these matters. And that’s a really easy thing that we need to do in order to make sure that we’re tracking the actual age and the actual due date of matters really, really accurately. So yeah, this one
pretty good, just as an indication of whether people are using the file note feature and how they’re using the turnaround clock feature.
OK, so that one was pretty easy. So that one probably not for you, Nick, because that’s neither of those functions we’re using with PIA matters.
OK, we’re nearly at one hour. Were there any questions about any of those?
None for me. Thanks, Laura. No, not for me either.
No. Well, I’m gonna wrap it up then. Um,
I guess, um, rewatch the video if you need to have a think about what you want to track with your people and have the discussion with your assistant director about how often you need to track it.
I will work on some things to try and make them a bit more user friendly so that you’re getting more useful information without having to do any manual manipulation because we want this to be easy and straightforward. But yeah, if there’s anything else that you want to track, please let me know.
I can figure out a way to do it, and if I can’t, I can ask the Lex administration team to build something that gives us the information that we want.
So I’m going to stop the recording and I will put a copy of this video on SharePoint, um, so you can review it anytime you want.
FOI 25/26-2150
DOCUMENT 15
| Title | Date Received | Date Due | Key Contacts | Next Steps |
|---|---|---|---|---|
| s47F - personal privacy | 5-Oct-23 | 4-Nov-23 | Subject: Model Litigant Obligation Complaints | Summary: The OLSC agency notification form for model litigation obligation complaints submitted that involve s47G - business informatio and/or s47F - personal privacy |
| s47F - personal privacy | 9-Nov-23 | 23-Dec-23 | Applicant: provider/ stakeholder | Summary: Documents about SDA and SIL for participants approaching 65 years or who are over 65 |
| s47F - personal privacy | 15-Nov-23 | 14-Dec-23 | Applicant: Right to Know | Summary: Documents detailing how assessment tool results determine the level of severity of a participant’s disability |
| s47F - personal privacy | 10-Dec-23 | 9-Jan-24 | Applicant: staff member | Summary: Staff member’s personnel file |
| s47F - personal privacy | 12-Dec-23 | 11-Jan-24 | Matter is under OAIC review | Summary: Documents provided by the NDIA board, NDIA, NDIS review co-chairs and other parties regarding a reported $720 million investment |
| s47F - personal privacy | 13-Dec-23 | 12-Jan-24 | Subject: Potential media coverage | Summary: Requesting documents around the data breach. |
| s47F - personal privacy | 15-Dec-23 | 14-Jan-24 | Subject: NDIS review | Summary: Unpublished analysis submitted by the NDIA to the NDIS review |
| s47F - personal privacy | 29-Aug-23 | 28-Oct-23 | Subject: funding | Summary: Statistics on the number of participants with plans valued at over $500,000. Actuarial analysis about participants with high value plans |
| s47F - personal privacy | 10-Jan-24 | 9-Feb-24 | Subject: NDIS review | Summary: Unpublished analysis supplied submitted by the NDIA to the NDIS Review |
| s47F - personal privacy | 17-Jan-24 | 16-Feb-24 | Applicant: former staff member | Summary: Information about former staff member’s request for redundancy |
| s47F - personal privacy | 31-Jan-24 | 1-Mar-24 | Applicant has SLT manager | Summary: Documents relating to the NDIS Autism Advisory Group (AAG) |
| s47F - personal privacy | 5-Feb-24 | 6-Mar-24 | Applicant: peak body | Summary: Documents related to the inclusion of support coordination in NDIS participants plans |
| s47F - personal privacy | 7-Feb-24 | 8-Mar-24 | Applicant: staff member | Summary: Staff member’s personnel file |
| s47F - personal privacy | 12-Mar-24 | 11-Apr-24 | Applicant: public figure | Summary: Communications that mention the applicant sent either to or from Bill Shorten or Julian Hill |
| s47F - personal privacy | 6-Feb-24 | 7-Mar-24 | Applicant: peak body | Summary: Documents related to plan management and annual price review |
| s47F - personal privacy | 26-Apr-24 | 26-May-24 | Subject: s47G - business information | Summary: s47G - business information |
FOI 25/26-2150
| s47F - personal privacy | 29-Apr-24 | 28-Jun-24 | Applicant: Senator’s office | Summary: Acting on behalf of a participate (s47F - pers) and seeking access to internal documents relating to recent communication and plan decisions |
|---|
| s47F - personal privacy | 8-May-24 | 7-Jun-24 | Applicant: journalist | Summary: Statistics on the number of yearly incidents and value/cost attributed separately to provider fraud and participant fraud | | s47F - personal privacy | 8-May-24 | 7-Jun-24 | Applicant: journalist | Summary: Briefing packs and memos provided to senior executives or the NDIS minister about convicted sex offenders accessing the NDIS | | s47F - personal privacy | 8-May-24 | 7-Jun-24 | Applicant: journalist | Summary: Operating procedures, guidelines or policies relating to NDIS support workers who interact with or assist NDIS participants who are known sexual offenders or violent offenders | | s47F - personal privacy | 17-May-24 | 16-Jun-24 | Applicant: Opposition MP/Shadow Minister | Summary: Total Agency expenditure on private law firms for AAT matters in FY 22/23. |
| s47F - personal privacy | 17-May-24 | 16-Jun-24 | Applicant: Opposition MP/Shadow Minister | Summary: The number of NDIS participant cases referred to the AAT in FY 22/23. |
| s47F - personal privacy | 17-May-24 | 16-Jun-24 | Applicant: Opposition MP/Shadow Minister | Summary: Total amount paid to a registered NDIS provider: s47G - business inform. |
| s47F - personal privacy | 17-May-24 | 16-Jun-24 | Applicant: Opposition MP/Shadow Minister | Summary: Total amount paid to supplier: s47G - business in |
| s47F - personal privacy | 22-May-24 | 21-Jun-24 | Applicant: MP | Summary: Seeking NDIS payments to multiple cruise services. |
| s47F - personal privacy | 28-May-24 | 27-Jun-24 | Applicant: MP | Summary: NDIS payments made to sex therapy providers. |
| s47F - personal privacy | 28-May-24 | 27-Jun-24 | Applicant: MP | Summary: NDIS payments to multiple horse riding suppliers. |
Recording GC report information on LEX
- Confirm that the matter has been assessed as suitable to include on the report (see significant matters meeting email).
- Go to the matter on LEX.
- Click Main details.
- In the Escalation level field, select GC visibility.
- Escalation level: GC visibility
- Referrals
- External Firm
- Estimated Hours: 01 - 05 hours
- FOI/PIA Outcome
- Escalation level: GC visibility
- Click on the Key contacts section. Add information about Key risks such as Applicant, Subject, Responsible groups and Media alert. If the matter is under OAIC review, also note it in this tab.

- Click on the Next steps section. Add a 1 – 2 sentence summary of the matter.

- Click Save.
How to create a report about CG report matters
This process will enable you to easily extract information about all significant matter for quality checking.
1. Search for all matters on LEX that have Escalation level: GD visibility and Status: Active. Leave all other fields blank.
| LEX ID / Matter text fields | Escalation level | Referrals | External Firm | Estimated Hours | FOI/PIA Outcome | R&R - Priority | Status |
| --- | --- | --- | --- | --- | --- | --- | --- |
| | GC visibility | | | | | | Active |
2. Click the Reports button.
Choose Report: 19. FOI Oversight Report and Format: Excel (.xls).
| Search > Matters reports |
|---|
| Report |
| Format |
| Title |
If you get an Excel warning about this report, select ‘Yes’ to open it. OK | Cancel |
Page 229 of 331
Training: Staff accesses
How to add, remove and check staff accesses on all systems
June 2024 Information Access team
Page 230 of S51
Training: Staff accesses
Agenda
- SharePoint site
- Shared mailboxes
- Information Access
- FOI
- LEX profile
- CRM roles
- Email distribution list
- Leave calendar and staff contact list
- Microsoft Teams meetings and chats
- Troubleshooting
- Questions
Key resources
- Internal team guide - SOP - FOI - FOI staff system access requests.docx
- Internal Office of the Chief Information Officer (OCIO) help guides - ICT How to guides - OCIO Help Centre
- Microsoft help guide for SharePoint, Outlook & Teams - Microsoft Support (external)
- Search the NDIA intranet for other team standard operating procedures (SOPs) - Home (ndia.gov.au)
- LEX help guide (external)
| Lookup matter
| Dashboard | Search |
|---|---|
| About | Your account |
| Help |
Preliminary steps
- Confirm the staff member’s correct name via recruitment confirmation email.
- Find out the staff member’s login ID: Employee Search - SAS® Visual Analytics
- Find out the staff member’s work email address from their line manager or via Outlook autocomplete
Access to the SharePoint site
- Staff are added via the My Groups function on Microsoft My Apps

Access to the shared mailboxes
- Staff are added via the My Groups function on Microsoft My Apps
| ndis | My Apps |
|---|---|
| My Account | |
| My Groups | |
| My Access |
Access to LEX
- Staff are added via the administration tab on LEX.
| Lookup matter
| Dashboard | Search | Matter | Add Matter | Administration | About |
|---|
Adding CRM roles for new staff
- Roles are added via the access management link on ESSentials.

Access Management
Access Management - Fiori
Access Management - Fiori
SAP Home
Access Management Reporting
| Access Request | Request Status (Detailed View) | Request Status (Simple View) |
|---|---|---|
redacted |
Adding staff to the email distribution list (DL)
- Staff are added via Distribution groups - Outlook Web App (office.com)
Distribution groups I own
| Display name | Email address |
|---|---|
| s47E(d) - certain operations of agencies | redacted: s47E(d) - certain operations of agencies |
Leave calendar and staff contact list
- Staff are added to the Excel spreadsheets stored on SharePoint.
Team Quick links
| Administration |
|---|
| FOI Guidelines (external) |
| Team Contact List |
| Team Leave Calendar 2024 |
| Information Access Team Leave Calendar 2024.xlsx |
| Information Access Team Member Contact List.xlsx |
Microsoft Teams meetings and chats
-
Staff can be added to chat groups in Microsoft Teams.
-
Staff can be added to recurring meetings by forwarding the invite on Outlook.
-
If a meeting is visible on the shared FOI calendar, staff can be added by opening the meeting and adding their email address.
Shared Calendars
- INFORMATION.ACCESS
Troubleshooting access problems
-
Staff may assume they have lost access and ask you to resubmit it for them. Always check their current access status before proceeding.
-
If basic trouble-shooting steps doesn’t resolve the problem, direct the staff member to submit a ticket at the ICT service desk. It is not your responsibility to troubleshoot complex problems.
-
If multiple staff are experiencing the same issue, you may submit an ICT ticket on behalf of the whole team and act as the liaison with ICT.
Questions?
Rage 242 oi Soil
FOI 25/26-2150
DOCUMENT 18
0:0:0.0 –> 0:0:25.0 s47F - personal privacy Laura Everyone, welcome to this training session about how to add, remove and check staff accesses here in the Information Access team, I’ve shared my screen and this session is being recorded for training purposes and by continuing to be here in this meeting, you’re consenting to just being part of this recording. If anyone disagrees with that, you’re more than welcome to log off and just review the video later.
0:0:26.400 –> 0:0:32.0 s47F - personal privacy Laura So today staff accesses a little bit of background on staff accesses. They’re essential for everyone.
0:0:32.680 –> 0:0:41.800 s47F - personal privacy Laura We have multiple different systems here at the ndia and some accesses are done automatically by the recruitment team, but some have to be done manually by our team.
0:0:43.280 –> 0:1:7.360 s47F - personal privacy Laura In the past, we’ve had two situations. One would be that there was one person who was the expert on all staff accesses and they did everything behind the scenes. Nobody knew what they did and then when that person was sick or on leave, nobody had any idea what to do. That’s not a good situation. The other situation we had was there was nobody around and every single person had to figure all this out for the first time themselves and nothing was written down.
0:1:7.850 –> 0:1:37.970 s47F - personal privacy Laura Not a good situation either. So what we’ve decided to do is train the entire triage and early resolution team in the basics of staff accesses. So every single one of you feels a certain level of comfort, so you could step in and do this in the future if there was a need. So not every single one of you needs to become a subject matter expert on this, but it’s good if you just get a little bit of comfort in knowing where the resources are, how to find them and where to ask for help so you could fill in.
0:1:38.10 –> 0:1:38.610 s47F - personal privacy Laura If you needed to.
0:1:40.500 –> 0:2:9.740 s47F - personal privacy Laura
FOI 25/26-2150
So this is the agenda for today. It looks like a lot, but everything here is pretty easy. I’m going to go through stuff accesses through multiple systems, starting with the SharePoint site, which is where what we’re using as a document management service to record all the documents that we work on. There’s 2 shared mailboxes that we use to correspond with applicants, receive requests and correspond with different parts of the agency. The third system is Lex.
0:2:10.20 –> 0:2:40.260 s47F - personal privacy Laura Which is a different case management system is where we record matters that we’re working on and update the status. The fourth thing is CRM roles. CRM is a case management system where NDIS participant data is stored, and so we’re going to show you how you get the right roles to gain access to that participant data. Fifth thing is the e-mail distribution list. That’s a way that we can communicate with everyone in the team really easily without having to write people’s individual emails.
0:2:41.120 –> 0:2:46.920 s47F - personal privacy Laura 6th thing is the leave calendar and staff contact lists. That’s just.
0:2:48.160 –> 0:3:9.840 s47F - personal privacy Laura An Excel document that we have where we keep track of people’s attendance, best contact number, which office are they located in and then lastly the Microsoft meet teams, meetings and chats. We use Microsoft Teams a lot to connect with one another, whether that’s why video conferencing or just via text messages in the chat. Then we’re going to do a little bit of troubleshooting about some common issues.
0:3:10.190 –> 0:3:18.190 s47F - personal privacy Laura That tend to happen, and we’re gonna have a little bit of time for questions before I go on. Is there anything, any questions that people have straight up?
0:3:19.670 –> 0:3:24.390 s47F - personal privacy Laura You understand why you’re here in the meeting and what I’m going to show you. Is there anything that’s just got you confused already?
0:3:27.360 –> 0:3:28.280 s47F - personal privacy Laura ’Cause some thumbs up.
Page 244 of 331FOI 25/26-2150
0:3:30.240 –> 0:3:30.440 s47F - personal privacy, John Laura.
0:3:30.520 –> 0:3:32.320 s47F - personal privacy Laura Oh, John, go ahead.
0:3:34.620 –> 0:3:36.340 s47F - personal privacy, John It’s it’s all good though. Thank you.
0:3:36.590 –> 0:3:37.310 s47F - personal privacy Laura OK, cool.
0:3:39.90 –> 0:3:58.530 s47F - personal privacy Laura Cool. Sorry. What we’re gonna do is go through some of the key resources so you don’t have to panic and take notes, because everything that I’m about to show you is included here in the standard operating procedure or SOP as we call them and it’s got screenshots showing you exactly where to click.
0:4:0.50 –> 0:4:10.690 s47F - personal privacy Laura So I’ve sent you a link to that SOP by the chat earlier and I hope you can all bring it up so you may if you’d like to have that SOP on your screen next to you.
0:4:11.590 –> 0:4:26.990 s47F - personal privacy Laura The other thing that you should definitely bookmark is this link here to the office of the Chief Information Officer. Help guides. So office of the Chief Information Officer is the division in our agency that includes the ICT team.
0:4:28.870 –> 0:4:42.390 s47F - personal privacy Laura They like to reduce the number of ICT requests that they have to deal with, so they have extensive help guides about common issues. So if you do encounter a technical problem, it’s always worthwhile to seeing if there’s already an answer on that website.
0:4:42.910 –> 0:5:1.470 s47F - personal privacy Laura
FOI 25/26-2150
The other thing you may want to bookmark is the Microsoft support. A lot of the programmes that we use here at the NDIA are Microsoft products including SharePoint, Outlook and teams. So if someone in particular is having a weird glitch that doesn’t seem to make sense, you’ll often be able to find a help guide just online for the general public to use.
0:5:2.870 –> 0:5:11.110 s47F - personal privacy Laura And there’s a couple of other ones not going to be relevant, but more just general information. If you’re helping someone troubleshoot technical issues.
0:5:12.590 –> 0:5:46.870 s47F - personal privacy Laura Other standard operating procedures are included on the Ndia intranet, and you can just usually do a keyword search on the Internet and you may find something that’s helpful. The only caveat to that is it may be out of date, so have a look at how recent it is before you follow the steps and then lex one of our systems does have a help guide which you can access via Lexus, so you will all have a copy of this PowerPoint. I sent it to you in the meeting invite and I can forward this to you again. So all these links you’ll be able to access after this training session.
0:5:48.560 –> 0:5:52.720 s47F - personal privacy Laura Cool. So we’re right into it some of the first preliminary steps that we need to do.
0:5:54.320 –> 0:5:56.160 s47F - personal privacy Laura Confirm the staff members correct name.
0:5:58.160 –> 0:6:16.560 s47F - personal privacy Laura And that’s important because sometimes people have legal names, but then they have preferred names and we need to confirm what name there actually will be known by within the team. There’s a couple of ways we can do this. The easiest way is that when the person is recruited, their line manager will be sent an e-mail that confirms.
0:6:17.20 –> 0:6:27.660 s47F - personal privacy Laura Then I’m if you don’t have that information, there are different ways we can go about finding it out. One is by doing the employee search.
0:6:29.60 –> 0:6:40.100 s47F - personal privacy Laura
FOI 25/26-2150
And another way we can find out things is by working out their e-mail address via Outlook autocomplete. So I’m just going to demonstrate that to you with our new startup, Bo redacted.
0:6:45.170 –> 0:6:46.50 s47F - personal privacy Laura Sorry.
0:6:47.540 –> 0:7:3.980
s47F - personal privacy Laura
This here is the Internet. It should be your home page. When you open up any browser on the computer. So the first thing we wanna do, we’re gonna say Bo redacted. I don’t know how to spell his name. Right. Is it redacted en or redacted? redacted, we don’t know.
0:7:4.20 –> 0:7:13.260 s47F - personal privacy Laura The best way to do it this only works for one day before they start, so it’s not something you can do in advance, is to go over here under my links where it says essentials.
0:7:14.580 –> 0:7:18.140 s47F - personal privacy Laura And this takes us to the Ndia, HR and finance system.
0:7:19.210 –> 0:7:31.130 s47F - personal privacy Laura So we don’t have to create profiles in essentials that’s done automatically by the recruitment team. If you go up the top here, one of the tabs is called my details and then one of the options you’re going to get is called reports.
0:7:33.110 –> 0:7:36.510 s47F - personal privacy Laura And then one of the options you’re gonna get here is called user information.
0:7:38.610 –> 0:7:58.650 s47F - personal privacy Laura So it comes up with the screen and you hit display and it opens up a pretty basic looking PDF, But what this is is a list of every single person in our team. The Information access team, including their full name spelled correctly and their user ID so I can see.
0:8:0.210 –> 0:8:8.330
s47F - personal privacy Laura
Bo redacted here. I can see his name is spelled with an redacted and that his ID is redacted.
FOI 25/26-2150
0:8:8.820 –> 0:8:16.60 s47F - personal privacy Laura It’s usually 3 letters followed by three numbers. But be careful there are some variations on that, particularly for staff who’ve been around the agency for a while.
0:8:17.320 –> 0:8:29.600 s47F - personal privacy Laura I can also see pujan you’re here and your number here is s47F - personal privacy. And Tanya, you’re here as well. s47F - personal privacy . Probably the coolest stuff I’d I’ve ever seen. Tanya. Well done on that one.
0:8:30.720 –> 0:8:33.80 s47F - personal privacy, Tanya It was just a flick. I don’t know how they did it.
0:8:35.590 –> 0:8:44.790 s47F - personal privacy Laura Cool. So that’s only works for 24 hours before they start. That’s when the person’s account is created. Second thing you can do.
0:8:46.250 –> 0:9:3.770 s47F - personal privacy Laura Is go to the staff directory search so you’ve got the link for this in your PowerPoint and what this will give you. It will give you the name and position and stuff like that of any employee of the agency. So if you know somebody’s name, even their first name, you can usually do.
0:9:5.650 –> 0:9:13.810 s47F - personal privacy Laura A good guess of what, how it could be spelt if we type in Bo s47F - personal privacy name there and press press enter.
0:9:16.720 –> 0:9:16.840 s47F - personal privacy Laura Ron.
0:9:20.50 –> 0:9:27.650 s47F - personal privacy Laura We can see if he’s going to come up on the employee search, so he’s doesn’t appear to be coming up at the moment, so let’s type in somebody else.
0:9:28.890 –> 0:9:36.770 s47F - personal privacy Laura
FOI 25/26-2150
There you go. So, Tanya, you’re on there. So as you can see, the disadvantage of this is that there’s a little bit of a delay, so.
0:9:37.50 –> 0:9:49.290 s47F - personal privacy Laura This is usually done within 24 hours. This takes a few days, but that’s two different ways. You can try to find out the correct spelling of someone’s name and their staff ID. This one you can see has an advantage that includes the e-mail address as well.
0:9:49.960 –> 0:10:7.0 s47F - personal privacy Laura It’s important to note that because sometimes people can have numbers after their name, like maybe Tanya dot s47F - personal privacy two or three, depending on how common that name is. So it’s important to verify that if you didn’t have the access to that to figure out the e-mail address.
0:10:7.640 –> 0:10:9.720 s47F - personal privacy Laura Or what you might do is.
0:10:11.850 –> 0:10:29.290 s47F - personal privacy Laura Open up Outlook and this is just automatically generating a new e-mail that has my signature there. The auto complete function is set up to automatically assume you are trying to contact the people who are closest to you within the organisation chart. So if I type in Bo.
0:10:31.50 –> 0:10:43.330 s47F - personal privacy Laura So Bo s47F - personal privacy doesn’t have anything on the system yet. Let’s type in somebody else, Tanya. There you go, Tanya. So, of all the Tanya’s in the agency, it knows that I’m most likely to be contacting you, Tanya, because we’re in the same team.
0:10:44.100 –> 0:10:54.660 s47F - personal privacy Laura So if I click that, I can also get a little information panel double click that about Tanya and I’ve got this option here to just copy the e-mail address. So if I needed to use that, that’s where I’d get it.
0:10:55.540 –> 0:10:59.900 s47F - personal privacy Laura This also includes office location and that will come in handy later.
FOI 25/26-2150
0:11:1.660 –> 0:11:4.980 s47F - personal privacy Laura Cool. So that’s three different ways to get the information about.
0:11:6.260 –> 0:11:15.780 s47F - personal privacy Laura The person’s details, so that covers off everything in this slide here. So now we can get into it and I’ll just make this.
0:11:17.470 –> 0:11:24.910 s47F - personal privacy Laura Lodge again, we are now moving on to the first access which is access to the SharePoint site.
0:11:24.950 –> 0:11:41.910 s47F - personal privacy Laura So key points on this slide is staff added via my groups. That’s the key takeaway from this. I’m sure this is going to be a lot of information overload and you’re going to get confused about where things are going. This is just giving you a snapshot on where SharePoint is accessed by my group, so I’ll just show you where that is.
0:11:43.230 –> 0:11:44.870 s47F - personal privacy Laura Just going to click the link to my apps.
0:11:46.580 –> 0:12:18.140 s47F - personal privacy Laura And I’m also gonna show you a second way to get there. So the apps dashboard shows you all the apps that are installed on the cloud that anyone can access as an employee of the agency. If you, you can bookmark this. My applications.microsoft.com. If you forget to do that, it’s also accessible via the Internet page. So if I go back to the Internet page and go over to my links again and I Scroll down, here’s my apps down there. So you’ve always got a way to get through it straight from the home page.
0:12:18.970 –> 0:12:24.50 s47F - personal privacy Laura If you go up to the top corner over here, there’s a little arrow and then you select my groups.
0:12:29.280 –> 0:13:0.880 s47F - personal privacy Laura And this shows you all groups that you’re in, all groups that you own, so groups that I’m in, I’m in 83 groups and you can see some of these are auto generated reports that we don’t touch. They must be things that the finance team or the HR team is doing for other purposes. Some of
— PAGE TEXT END –
FOI 25/26-2150
them, though, are this one is our branch. DL means distribution list complaints dot FOI branch, this one Deacon Deacon .90.
0:13:1.80 –> 0:13:14.80 s47F - personal privacy Laura Street that’s I guess my location group so that if there’s ever a property issue that needs to be communicated to me in my location, it can come there. And then there’s these. Our team groups like the FOI Group there there’s also.
0:13:15.820 –> 0:13:18.180 s47F - personal privacy Laura Social groups as well. If you join any of the.
0:13:20.630 –> 0:13:52.110 s47F - personal privacy Laura Fund social groups linked on the Internet. We’ve got a couple of team sort of social media things you can see. I’m in the NDIS and mental health groups, the photography lovers group and the book Lovers group. So that’s just a little bit background. In order to do this, you need to be the owner of a group, not just a member of the group. So when you go into yours, you’re going to see that groups like iron, it’s probably going to say 0. So that’s one of the key preliminary steps before you can do this is you have to be able to be made an owner. Anyone can be made an owner by another owner.
0:13:52.580 –> 0:14:22.820 s47F - personal privacy Laura So if we go into this one freedom, underscore of information, that’s our SharePoint group, you’ll be able to go in there and you’ll be able to see who the owners are. So you can see there’s 1234567 owners and six of those people are members of our team. So our director, Peter, multiple ER ones and then Rachel, who is your team leader. So that’s one of the preliminary steps that you could ask Rachel, for example, to make you an owner before you do this.
0:14:23.470 –> 0:14:28.110 s47F - personal privacy Laura In order to add someone to a group, it’s really, really easy. You go to the member screen, you hit the add button.
0:14:32.0 –> 0:14:42.840
s47F - personal privacy Laura
Type in that person’s name and here we go. Bo redacted is coming up, and we also know his e-
mail address. Now it’s Bo dot redacted. No numbers. Just click on that and press add.
FOI 25/26-2150
And then he will appear down the bottom.
And that’s how someone can be made an owner, someone who is an owner can just hit that button that says make owner. So then in order to check somebody’s access, you go to the members. And up here it says Philtre by name and you can just type in someone’s name. So we’re typing in your name and we’re checking that. Yep, you’ve got access. It’s all good pujan, which that’s important. If somebody says I’m having trouble, I can’t access the SharePoint. The first thing you do check whether they’ve got access. If they don’t have access you can give it to them. But if they do have access you know the problem is something else.
The last thing you can do is to remove an access so the person I’m going to remove first name was Aisha so we can see this person. We can hit the remove button over there.
And then that person’s gone. So that’s legit. Everyone. That is how to give people access, check people’s access and remove access from the SharePoint.
Cool. Next thing. Oh, wait, before I go on any questions about that.
No.
Now, Laura, thank you.
Thumbs up again. Wonderful. Cool. OK.
FOI 25/26-2150
0:15:59.900 –> 0:16:0.820 s47F - personal privacy, Tanya Yeah. Thank you.
0:16:2.150 –> 0:16:10.470 s47F - personal privacy Laura Access to the share mailboxes same place, so my groups function and it’s going to function in exactly the same way.
0:16:15.880 –> 0:16:26.360 s47F - personal privacy Laura So here we are, groups I own, and there’s four groups that relate to our shared mailboxes. They’ve all got the initials SM, meaning shared mailbox at the start.
0:16:27.680 –> 0:16:45.120 s47F - personal privacy Laura Foi full access let’s people view anything in that mailbox send as allows people instead of sending from your personal e-mail to send on from the actual FOI ndis.gov dot au e-mail address. The exact same thing with information dot access.
0:16:45.440 –> 0:16:56.480 s47F - personal privacy Laura So we’re gonna go through the exact same process again, click on it. If you’re not an owner, you need to ask an owner to add you as an owner so we can see there are only three owners to this one.
0:16:56.500 –> 0:17:5.980 s47F - personal privacy Laura So Rachel, as the triage team leader, Kylie, as the triage assistant director, and me as the systems and access guru Jesse, you’ve got your hand up.
0:17:7.190 –> 0:17:19.990 s47F - personal privac Jessie Yes, question. So will the five of us just be added because this will be a role for us to take on or will we just ask as we need it?
0:17:21.280 –> 0:17:33.600 s47F - personal privacy Laura Look, I think we’ll talk to Rachel about that. I think once things settle down, she might delegate one or two of you to be permanently owners, and that can just be part of your duties and everyone else. You would just need it as required.
Page 253 of 331
FOI 25/26-2150
0:17:35.290 –> 0:17:35.970 s47F - personal privacy Jessie Makes sense?
0:17:35.640 –> 0:17:38.520 s47F - personal privacy Laura There are there are disadvantages to becoming an owner of this.
0:17:40.640 –> 0:17:51.800 s47F - personal privacy Laura And that’s why not everyone should be on it. And one of the disadvantages is anytime anyone makes a meeting invitation on the shared calendar, you get CC CD, CC D into any response.
0:17:52.150 –> 0:18:1.830 s47F - personal privacy Laura So if somebody accepts a meeting invite, you’ve got five meeting invites for the week. ’cause it’s a new week of training and 20 people are invited. You’ll get spammed with 100 emails so.
0:18:3.230 –> 0:18:4.70 s47F - personal privacy Laura There are disadvantages.
0:18:4.630 –> 0:18:5.830 s47F - personal privac Jessie OK. Thanks Laura.
0:18:6.990 –> 0:18:22.990 s47F - personal privacy Laura OK, we’re gonna do the exact same thing. Go to the members tab. We’re gonna hit add. We’re gonna type in Bo’s name. It’s figured out that we’re talking about Bo s47F - personal privacy , so I can just type in Bo, and he’s coming up as the first option. Hit add.
0:18:24.350 –> 0:18:25.30 s47F - personal privacy Laura Then we can check.
0:18:26.630 –> 0:18:42.790 s47F - personal privacy Laura With a putrid has access. No, you don’t. So again, if Prujan comes to me and says I’m having trouble, I can’t access the mailbox. First thing I’ll do. Come here and check whether he even has access or not. I can see he’s he doesn’t. So that’s an easy fix. So we can just add you here.
Page 254 of 331
FOI 25/26-2150
There you go. And then removing accesses, same again. Type the person’s name who you’re removing. They’re gonna come up. Hit that remove button.
Go back now. We’re gonna do the exact same thing with the next three.
So first thing we’re gonna do.
Add and then type in Bo.
Then hit add.
We’re going to check that Pujan has access and he does not, so we’re going to add him as well.
And then we’re gonna remove Aisha.
Hit remove.
While I’m here, I’ll just double check that. Tanya, you’ve got access as well. Yeah, you’re good.
I’m just going to repeat the same thing over and over again. As you can see, it’s not hard.
FOI 25/26-2150
0:19:50.240 –> 0:19:54.320 s47F - personal privacy Laura Adding Bo checking pujan Nope.
0:19:55.0 –> 0:19:56.520 s47F - personal privacy Laura So we’re adding pluton.
0:20:0.390 –> 0:20:2.150 s47F - personal privacy Laura And then we’re removing Asha.
0:20:3.750 –> 0:20:16.950 s47F - personal privacy Laura So in terms of removing people, if somebody has left the agency, there’s no great urgency to remove them straight away because they won’t have access to their ndia account. However, if somebody’s changed roles.
0:20:18.310 –> 0:20:34.110 s47F - personal privacy Laura It’s kind of important for confidentiality reasons to remove them within a reasonable amount of time, like hopefully within 48 hours, just so that they no longer have access to the confidential documents that they had in our role, in whatever their new role is.
0:20:36.610 –> 0:20:38.170 s47F - personal privacy Laura And then lucky last.
0:20:42.410 –> 0:20:43.690 s47F - personal privacy Laura I’m adding Bo.
0:20:45.710 –> 0:20:46.430 s47F - personal privacy Laura Chicken pujan.
0:20:48.620 –> 0:20:50.20 s47F - personal privacy Laura So I’m adding pujan.
0:20:53.880 –> 0:20:55.640 s47F - personal privacy Laura And then I’m removing Russia.
Page 256 of 331
FOI 25/26-2150
0:21:2.800 –> 0:21:4.640 s47F - personal privacy Laura That’s great. Well, that’s it.
0:21:5.460 –> 0:21:10.380 s47F - personal privacy Laura Was absolutely everything about shared mailboxes, so any questions about that?
0:21:14.380 –> 0:21:15.220 s47F - personal privac Jessie No thanks Laura.
0:21:14.560 –> 0:21:17.480 s47F - personal privacy, Tanya Nothing. Nothing for me, love. Thank you.
0:21:17.900 –> 0:21:19.140 s47F - personal privacy John All good. Thank you.
0:21:19.10 –> 0:21:21.330 s47F - personal privacy Laura Thank you. Oh, wait, Maggie, you’ve got your hand up.
0:21:21.720 –> 0:21:23.720 s47F - personal p Maggie Yes, just a quick question, right.
0:21:23.940 –> 0:21:24.300 s47F - personal privacy Laura Yes.
0:21:29.210 –> 0:21:29.690 s47F - personal privacy Laura Yes.
0:21:25.120 –> 0:21:35.280 s47F - personal p Maggie Would that be right? Since example tenure is new or that be easier is is is that right? Is.
0:21:35.360 –> 0:21:41.120 s47F - personal p Maggie We find all the different lists to add the person in or we have the list that.
FOI 25/26-2150
Maggie: How how do I say?
Maggie: Because there are a lot of lists, it might be missed. Is that right? Like for the new starter, they will have a certain distribution list will be given that need to be added. Does that sound right?
Laura: But that’s correct. So I think what you’re saying is, is there like a checklist where you can make sure that somebody has been added to every single system?
Maggie: Yeah. Yep.
Laura: No, there’s not currently. Do you want to create one? Because you can.
Maggie: OK.
Laura: Great question.
Laura: Next question is access to Lex. So Lex is a completely separate system. It’s not owned by Microsoft, it’s not accessible by anyone else in the agency. ICT don’t administer it, which means if you ever have any issues with Lex, you can’t call ICT. They don’t know anything about it. They can’t access it. The best thing to do if you are having issues with LEXIS is to call me. I’ve sort of functioning as the de facto lex.
Laura: Service desk and I can contact the people who own the programme if there’s anything high tech going on. So again, key snapshot for Lex is we add staff via the administration tab.
FOI 25/26-2150
And just like the previous systems, you need to be given the role of administrator. So when you log into Lex, you’re not going to see this tab unless we add it to you. Anyone who already has administration rights can give you the administration access and.
Similar to the SharePoint site, we’ve got about 6 people who are administrators, including Rachel and Kylie in your team. So that’s who you go to in the first instance. Cool. So this is what the user administration screen looks like in order. It automatically defaults to add.
And in order to add somebody, you just put in their details here. So I’m typing in Bo’s name as it is spelt on our system, so that’s why we need to double check the spelling of the name.
The login ID I am transposing from what we found earlier on essentials. It was a password. s47E(d) - certain operations of agencies
E-mail address we’ve found Bo’s e-mail address when we were adding him to the other group, so we just know it’s Bo’s email: redacted@ndis.gov dot au.
And then starting page you can leave admin section no. But if you need to change somebody to admin right, that’s how you do it.
Admin other sections we’ve only got the option. No team. We’ve only got the option FOI right within that team changed you edit rights high and changed to all matters.
FOI 25/26-2150
0:24:57.40 –> 0:25:0.600 s47F - personal privacy Laura That’s outside the team. We don’t have any rights and then we don’t.
0:25:2.860 –> 0:25:7.420 s47F - personal privacy Laura No need to touch these other ones. I can both be nuns. So if I just press save.
0:25:14.480 –> 0:25:23.840 s47F - personal privacy Laura Oh, that’s not a good sign. This is lex. Usually does things pretty quick. Great. So it gives you a little pop up that says check you have enough licences.
0:25:26.840 –> 0:25:38.760 s47F - personal privacy Laura It’s a problem with Lex, is that we only have a limited number of licences, about 50, which means if we have more than 50 active users at a time, new users, instead of creating a new profile, they recycle old ones.
0:25:40.840 –> 0:25:46.600 s47F - personal privacy Laura If we need more licences, that’s something that I would need to escalate up. So if you do notice something like that’s happened.
0:25:47.630 –> 0:26:5.190 s47F - personal privacy Laura A new user seems to have a lot of old matters assigned to them. That’s something that you should escalate straight up to me. So there you go. Bo s47F - personal privacy profile has been created. If you did do a typo and you spelled his name wrong or got his login ID wrong, you can just come in here and change it. It automatically default to the edit tab if you click somebody’s name.
0:26:6.630 –> 0:26:14.830 s47F - personal privacy Laura And you can change somebody’s rights that way as well. So that’s it. That’s how to add a Linux profile, Jesse.
0:26:16.150 –> 0:26:20.390 s47F - personal privac Jessie Would you have to advise the staff member that they have to reset their password?
FOI 25/26-2150
0:26:20.890 –> 0:26:23.250 s47F - personal privacy Laura 100% So what I do after?
0:26:22.210 –> 0:26:26.50 s47F - personal privac Jessie And did they get sent some kind of e-mail or we have to do that or?
0:26:30.160 –> 0:26:30.520 s47F - personal privac Jessie OK.
0:26:46.510 –> 0:26:46.910 s47F - personal privac Jessie OK.
0:26:48.580 –> 0:26:48.900 s47F - personal privac Jessie Yeah.
0:26:26.480 –> 0:26:56.480 s47F - personal privacy Laura They don’t get sent anything automatically. We have to manually do it, so as soon as you’ve done that, you’re the only one who knows that. So pull up an e-mail and say, hey, Bo, Bo, we’ve created you a profile on Lex. He’s a link to Lex. Lex is a case management system that we use. Here’s your login ID. Here’s your temporary password. Please log in and change it straight away. So that’s about it. It doesn’t have to be fancy. And don’t CC anyone else in to that e-mail like not their line manager or anything. Just because you know.
0:26:56.670 –> 0:26:59.470 s47F - personal privacy Laura We’re supposed to be private and only that person should know about them.
0:27:0.30 –> 0:27:0.990 s47F - personal privac Jessie Sure. Thanks, Laura.
0:27:1.440 –> 0:27:31.720 s47F - personal privacy Laura Cool. So then what we can do is we can check. So pujan do you have a profile? It’s easy to just come to users and look down here. It’s alphabetical by first name. So if you had one, it would be down here. If you keep scrolling. We’ve also got this section called inactive users and that has all
FOI 25/26-2150
previous users here. So we could check on. Oh, did you have a profile was was it accidentally inactivated? And we can see Nope. There’s nothing there.
0:27:31.910 –> 0:27:36.310 s47F - personal privacy Laura So in that case we can say, OK, we need to create a new profile for you.
0:27:38.320 –> 0:27:38.920 s47F - personal privacy Laura So.
0:27:45.880 –> 0:27:48.200 s47F - personal privacy Laura Quick check that have I spelled your name right?
0:27:51.780 –> 0:27:53.180 s47F - personal privacy Laura Hooray, thumbs up.
0:27:54.550 –> 0:28:4.870 s47F - personal privacy Laura And we’ve got your login ID here, s47E(d) - certain opera . So we’re gonna create the temporary password password one.
0:28:5.990 –> 0:28:9.310 s47F - personal privacy Laura And e-mail address. Oh, I didn’t look that up before.
0:28:10.330 –> 0:28:12.170 s47F - personal privacy Laura So I’m just gonna look it up by.
0:28:13.760 –> 0:28:16.520 s47F - personal privacy Laura Pulling you up on my other screen and then copying it.
0:28:21.450 –> 0:28:22.90 s47F - personal privacy Laura There you go.
0:28:37.840 –> 0:28:48.560 s47F - personal privacy Laura There you go. So that’s all correct. And we’re gonna have your starting page same. We’re gonna
FOI 25/26-2150
give you no admin rights at the moment, but if we needed to check whether you needed admin rights, that’s the box we’d look.
Laura We’re gonna give you high edit rights for all matters. That’s the main thing to do.
Laura That’s it. Press save.
Laura And then we can say.
Laura X profile.
Laura So that’s an example of the e-mail you might send to the person straight away, yeah.
Laura Right.
Laura Oh, that’s one of the annoying things about like, explore. We’re here. It only lets you open one tab at a time, so you can’t work on it in multiple screens. Great. So we’ve created a new profile. We’ve checked whether a profile exists. Now let’s deactivate a profile. So we’re going to Aisha’s profile here, and we’re just hitting the inactivate button down here. We’re not hitting delete because we want, still want a record of every bit of work that Ayesha did when she was here, so that if we get any reviews about it in the future.
Laura We have the accountability of which staff member did it, so we just hit select her name and then hit inactivate.
FOI 25/26-2150
It says there are still items assigned to the user about to inactivate, so that’s something to check beforehand. So if I go to the search tab and then I hit clear philtres, what I’d probably like to do is to check what’s actually in this person’s name by picking them from the team slash matales section, and then looking for status active.
0:31:14.170 –> 0:31:17.290 s47F - personal privacy Laura So I can see there’s nothing active in Aish’s name.
0:31:20.740 –> 0:31:24.820 s47F - personal privacy Laura There are close matters in her name, but that’s not an issue.
0:31:26.20 –> 0:31:43.860 s47F - personal privacy Laura It’s not an issue to activate a user if they’ve got close matters in their name, so I’m happy to go back here. I’ve done my due diligence and now I’m just gonna hit inactivate and we’re gonna hit. Yes, we want to continue and then her name now appears down here in the inactive users. So if, for example, she was going on a 6 month.
0:31:45.620 –> 0:31:49.940 s47F - personal privacy Laura You know trial in another job within the agency. And then she came back after six months.
0:31:50.440 –> 0:31:54.320 s47F - personal privacy Laura And just pick her and then reactivate her. We don’t have to create an entirely new profile.
0:31:56.310 –> 0:31:57.910 s47F - personal privacy Laura Cool. OK.
0:31:59.340 –> 0:32:1.620 s47F - personal privacy Laura Any questions about Lex?
0:32:5.200 –> 0:32:6.320 s47F - personal privacy Laura Yes, Maggie.
0:32:6.860 –> 0:32:13.100 s47F - personal p Maggie Couple question. So the this one, we don’t have the SOP yet, right?
FOI 25/26-2150
0:32:13.980 –> 0:32:14.660 s47F - personal privacy Laura Yes, we do.
0:32:15.160 –> 0:32:15.720 s47F - personal p Maggie We do.
0:32:17.80 –> 0:32:17.920 s47F - personal p Maggie But is that?
0:32:16.930 –> 0:32:18.250 s47F - personal privacy Laura I’ll just show it to you.
0:32:22.600 –> 0:32:25.960 s47F - personal privacy Laura So this is the Freedom of Information home page.
0:32:26.160 –> 0:32:26.480 s47F - personal p Maggie Yeah.
0:32:27.200 –> 0:32:38.400 s47F - personal privacy Laura And if you Scroll down here in administration and on boarding and then here this folder onboarding and accesses and this is the sop the SOP FOI staff system accesses.
0:32:40.140 –> 0:32:42.300 s47F - personal privacy Laura And this has all the prerequisites.
0:32:42.400 –> 0:32:42.920 s47F - personal p Maggie Right.
0:32:43.170 –> 0:32:50.610 s47F - personal privacy Laura And it has step by step. See this. The formatting looks weird if you open it in the browser, so I always hit open in desktop app.
FOI 25/26-2150
And then if we open it up here, it’ll look a lot nicer and won’t have weird formatting.
Yep, Yep.
It’s in there. It’s in the chat that you created as well, right, Laura? Yeah. If you go into that message that Laura sent Maggie, it’s that first link.
On the team’s message that she sent this morning.
Mm hmm.
Oh, it’s in the team. I went to e-mail. Thank you. And second thing is, Laura, when we create a brand new profile, right, and then you send the e-mail to the new staff or that automatic pop say you change the price to change the password or we need to show the way like how to change a password. I can’t remember when I new started.
Right.
That’s a good question. The first time you log into Lex, it’ll prompt you to change your password, and then it does. It does. So I think approximately once every six months after that. So they’ll be able to login and they will then immediately have to change their password. So that’s that’s a really good question. If anyone ever forgets their password.
Page 266 of 331
FOI 25/26-2150
0:34:2.990 –> 0:34:7.430 s47F - personal privacy Laura Which we’re skipping ahead to the troubleshooting, but it’s pretty relevant.
0:34:7.470 –> 0:34:12.630 s47F - personal privacy Laura You can just go in here and we can say, ah boys forgotten his password. You can’t. You can just hit reset password.
0:34:14.250 –> 0:34:19.130 s47F - personal privacy Laura So if I hit that, it would say what’s your new password? So we can say.
0:34:20.430 –> 0:34:22.670 s47F - personal privacy Laura s47E(d) - certain operations of agencies
0:34:24.890 –> 0:34:31.450 s47F - personal privacy Laura And then I could then e-mail Bo and say I’ve reset your password, the new s47E(d) - certain operations of agencies
0:34:33.10 –> 0:34:41.730 s47F - personal privacy Laura Really important people forget their lex passwords all the time and ICT can’t help them, so that’s definitely the process for doing that.
0:34:43.390 –> 0:34:43.950 s47F - personal p Maggie Take care.
0:34:43.290 –> 0:34:49.370 s47F - personal privacy Laura So if we go to a matter, so this is just a random matter.
0:34:50.930 –> 0:34:53.250 s47F - personal privacy Laura And it shows you what details we have in Lex.
0:34:53.800 –> 0:34:59.0 s47F - personal privacy Laura The main details tab is the edit tab and you can see up here in the team matter lead.
Page 267 of 331FOI 25/26-2150
0:35:0.320 –> 0:35:9.80 s47F - personal privacy Laura Our new staff are now there, so Bo’s there. Pujan you’re there and Aisha is gone. Then if you go to this second.
0:35:10.540 –> 0:35:12.20 s47F - personal privacy Laura Box here team Slash clearing member.
0:35:13.640 –> 0:35:15.680 s47F - personal privacy Laura You can see that bow isn’t there.
0:35:17.300 –> 0:35:32.660 s47F - personal privacy Laura Ujjain, you’re not there. And Aisha is still there. And the reason is this one is updated automatically when you add staff. This one is updated manually by a person with administration rights who works in a different team from us.
0:35:34.20 –> 0:35:49.500 s47F - personal privacy Laura So at the end of the week, what I’m going to do and I will CC you in, is I’ll send an e-mail to the person who manages the administration rights to Lex, and I will put in a request for this drop down box to be manually updated. So the new people are added.
0:35:49.940 –> 0:35:56.100 s47F - personal privacy Laura And people who’ve left are removed, so that’s an annoying administrative step on top of the existing processes.
0:35:57.480 –> 0:36:3.520 s47F - personal privacy Laura But yeah, it’s also just an important thing to keep the whole system up to date, not just some of the boxes.
0:36:6.990 –> 0:36:24.390 s47F - personal privacy Laura OK. So we’ll move on to the next one, which is adding CRM roles for new staff. So this slide gives you the snapshot of where you find it. It’s via essentials under the Access management tab. So let’s have a look at what that looks like.
FOI 25/26-2150
0:36:26.420 –> 0:36:28.540 s47F - personal privacy Laura Again, in order to get to essentials.
0:36:34.340 –> 0:36:41.980 s47F - personal privacy Laura Go to the Internet and scroll over here to the side where it says essentials under my links.
0:36:43.980 –> 0:36:46.860 s47F - personal privacy Laura And then access management is a tab that you want.
0:36:52.80 –> 0:36:55.0 s47F - personal privacy Laura So access request is what we wanna do.
0:37:0.50 –> 0:37:3.450 s47F - personal privacy Laura And that’s gonna show you a default screen.
0:37:5.50 –> 0:37:31.170 s47F - personal privacy Laura What things you want added down here? What’s the justification and who you wanna request it for? It’s gonna alt automatically default to you, so we need to change it to another user, so I’m gonna pick request for other here and then this button. I’m gonna click this and I’m gonna hit the two boxes, and then that’s gonna let me pick that person’s name. So I’m gonna start with Bo. So his username is s47E(d)
0:37:32.50 –> 0:37:34.410 s47F - personal privacy Laura s47E(d) - c and I’m going to hit go.
0:37:36.300 –> 0:37:40.380 s47F - personal privacy Laura And there that person pops up. So I’m gonna click the check box and then hit OK.
0:37:42.220 –> 0:38:3.220 s47F - personal privacy Laura The description when we’re adding basic CRM roles is required for jobs in FOI team and normally we don’t have to do more of a justification than that because what we’re asking for is standard job, standard roles, standard sort of access to our case management system, not our special access that is particularly restricted. Then hit the add role button.
Page 269 of 331
FOI 25/26-2150
And then here you wanna see role description contains.
So one of them is ndia manager. There’s three roles that we give every new starter just automatically hit the search button.
And then any role containing the words ndia manager will appear. This is the one we want Ndia manager. We don’t want training Ndia manager, so we hit the check box for Ndia manager. Then we hit this arrow that basically selects it, moves it from this box to this box.
The next one we wanna do is non ticket.
Nope, hasn’t come up. That’s OK. I’m going to go back to the SOP, and I’m just going to copy paste the full name of the role, because then I can’t make mistakes.
So the three roles it’s here.
Non approval plan delegation, that’s what we want. Cool.
It’s gonna copy that.
And I’m gonna paste that in here, search for that.
There it is. It’s this one ndia plan. Delegation. Non approval, not the training one. Select the
FOI 25/26-2150
check box, hit the arrow, then it goes down below and then the last one that we need is just ndia Freedom of Information.
So I’ll search for that.
So this is the one we want ndia Freedom of Information, not role owner NDI a FOI. And then we hit down. So those are the three basic ones that will give all stuff basic access to CRM hit OK.
Then we hit this simulation button which is basically running a risk analysis to see if it’s particularly risky to assign these roles to this particular person. It opens up another screen and we hit the run risk analysis button.
We give it a few seconds and then we hit apply.
If there were any risks, they would have appeared. You can see the risk analysis column is now green, meaning it’s completely safe and then we hit submit.
And it’s saying here that the request has been successfully submitted. That’s gonna generate an e-mail that will go to that person’s line manager, and they can either approve or reject that request.
We don’t have to remove people’s CRM access. That’s done automatically when they cease employment with the ndia. But we can check people’s access. So if somebody comes to you and says I’m having trouble accessing CRM, I think it’s my accesses first thing to do is to check. So in order to do that, we go to my access tab tile and you can see it automatically defaults to yourself and you can see the position roles that I have. So I have my Freedom of Information, my ndia manager and my plan delegation non approval. So I’ve got all those.
FOI 25/26-2150
There’s another tab here, organisation roles as well. They added by the finance team, not by us. So if you wanted to check somebody’d access, so if you wanted to check check tanas access.
I just hit the select user button and I type in that person’s name. Maybe it’s a first name, last name, first situation. There you go. So last time. First you can type in the user ID, select that person and then the system will be refresh. And we can see Tanya has the correct roles here. The Freedom of Information role, the manager role and the plan delegation non approval role and this employee one is a standard one that everyone who’s an employee of the agency gets because that’s how you get paid. So if Tanya’s having any issues with CRM, we can say it’s not a problem on our end. We’ve checked your accesses, they’re fine, which is usually a sign that the next step would be talk to ICT Logistervice desk ticket. Cool. So that was CRM adding and. Checking, I’ll do yours properly after this training session. Pujans ’cause. It’s doesn’t make sense to just repeat the same things over and over, so we’re almost at the end. So the next thing is adding staff to the e-mail distribution list. So staff are added via a link in the Outlook Web app. You can just click on this link and then bookmark it.
FOI 25/26-2150
0:42:54.600 –> 0:42:55.0 s47F - personal privacy Laura Oops.
0:42:58.720 –> 0:43:2.320 s47F - personal privacy Laura Oh, it’s a bad request. OK, that’s no fun.
0:43:5.460 –> 0:43:9.820 s47F - personal privacy Laura Wonder if I have it saved anywhere else. There is another way to get to it?
0:43:19.300 –> 0:43:25.820 s47F - personal privacy Laura So what I’ve done is I’ve gone to the my apps screen and then I’ve picked on Outlook, so it’s opening up Outlook.
0:43:27.200 –> 0:43:30.800 s47F - personal privacy Laura Via the web apps. So then what I can do?
0:43:34.560 –> 0:43:37.0 s47F - personal privacy Laura Search for distribution list.
0:43:38.320 –> 0:43:39.600 s47F - personal privacy Laura Distribution groups.
0:43:41.240 –> 0:43:46.800 s47F - personal privacy Laura And then we’ve got a list here that says to manage distribution groups. Visit this portal. So let’s see if that link works.
0:43:52.900 –> 0:43:58.100 s47F - personal privacy Laura There you go. That has worked. So everyone follow those steps and then you can bookmark this.
0:43:59.500 –> 0:44:8.20 s47F - personal privacy Laura Exactly like the my apps the my group screen, there’s groups I belong to and groups I own. So again, in order to edit this you need to be added as an owner of this group.
FOI 25/26-2150
0:44:10.440 –> 0:44:16.920 s47F - personal privacy Laura So I’m only the owner of 1, So what I can do is I can click this one the FY and then.
0:44:24.360 –> 0:44:32.360 s47F - personal privacy Laura It’s not letting me add it up. That’s really weird. There we go. Members. Cool. This is this. They refresh this.
0:44:33.840 –> 0:44:46.200 s47F - personal privacy Laura So we can see who’s the owner of this group, so you know, a lot of people there and we can view and manage owners. And then the Members so we can view and manage members. So if I click that button.
0:44:47.580 –> 0:44:48.780 s47F - personal privacy Laura I can then add bow.
0:44:52.360 –> 0:44:54.240 s47F - personal privacy Laura Oh, add first.
0:44:55.570 –> 0:44:56.370 s47F - personal privacy Laura And then.
0:44:57.500 –> 0:44:59.620 s47F - personal privacy Laura So hardly this is gonna work.
0:45:4.470 –> 0:45:5.510 s47F - personal privacy Laura Nope, didn’t work.
0:45:7.460 –> 0:45:16.420 s47F - personal privacy Laura There we go. So I’ve searched, I’ve typed it in the name as Bo Dot s47F - personal privacy , so I’m actually typing in the e-mail string, so then I can click the checkbox there and press add.
0:45:18.800 –> 0:45:21.280 s47F - personal privacy Laura Will appear within 5 minutes. That’s fabulous.
FOI 25/26-2150
0:45:22.400 –> 0:45:25.240 s47F - personal privacy Laura I’m gonna open that one again and go back to the members.
0:45:28.380 –> 0:45:32.700 s47F - personal privacy Laura View all and manage. So if I wanted to search to see if you’re on it, Tanya.
0:45:35.630 –> 0:45:44.790 s47F - personal privacy Laura I can see that you’re not. So again, if somebody’s not getting the all staff emails that are being sent to the DL, check if they’re on this list. If they’re not, add them in.
0:45:52.720 –> 0:45:54.800 s47F - personal privacy Laura And then hit the check box and press add.
0:45:56.630 –> 0:46:0.70 s47F - personal privacy Laura And then same again to remove somebody go back to members.
0:46:2.20 –> 0:46:3.740 s47F - personal privacy Laura If you will manage.
0:46:4.900 –> 0:46:7.100 s47F - personal privacy Laura Then we search for Asha’s name.
0:46:9.390 –> 0:46:13.270 s47F - personal privacy Laura And then we click her and we hit delete up in the top corner.
0:46:16.150 –> 0:46:33.30 s47F - personal privacy Laura Great. So that’s adding people checking whether someone has access and removing them. And in order to get access to that list, you’d need to be made an owner by an existing owner, which we showed you how to do that a little bit as well. You just have to talk to them. Somebody you know is an owner. Me, I’m an owner of most things.
0:46:36.420 –> 0:46:37.940 s47F - personal privacy Laura Really, in the home stretch now.
FOI 25/26-2150
Leave calendar and staff contacts lists like I said before, these are little systems that we’re using to record where people work, what’s their best contact number there on SharePoint and there’s two places you can get them, so I’ll just go to SharePoint.
1st place is up here in the top right hand Corner team contact list and team leave calendar or if you lose track of them you can go to administration and onboarding and there they are. Team leave calendar and contact list there.
Sorry, this is what the leave calendar looks like. As you can see it’s pretty low tech. If anyone’s techie and knows of a good solution in order to automate this.
Like please let me know so as you can see, it’s coscot’s staff name and in order to add somebody’s what we’re usually doing is just.
Copying a row, pasting it again and then changing the name.
So you didn’t have a public holiday on that day. So that’s the thing that we definitely need somebody to use. The ingenuity to fix public holidays for different states.
Maybe we could think about.
Importing something that already exists instead of doing this, it’s pretty old school.
FOI 25/26-2150
So as you can see, when people have days off, they just mark them, copy paste these little cells and put them in the leave calendar. So again one of the problems is then some was.
0:48:11.720 –> 0:48:17.160 s47F - personal privacy Laura Had Tanya Poojan s47F - personal privacy names to every single month.
0:48:18.640 –> 0:48:27.200 s47F - personal privacy Laura So it can be a little bit fiddly, but it’s not hard. It’s just something that somebody needs to be aware of and then to remove somebody.
0:48:28.840 –> 0:48:42.920 s47F - personal privacy Laura So s47F - personal privacy , so we don’t need her name for any months after that, so I’m literally just selecting the row and then deleting it. And again, manually doing that for every single month.
0:48:44.40 –> 0:48:58.560 s47F - personal privacy Laura So yeah, like I said, a little bit fiddly, but pretty easy and self-explanatory. This one you don’t need any special access to do that, so this is something that absolutely everyone in the team can take responsibility for and fix errors as they see them.
0:49:0.120 –> 0:49:10.360 s47F - personal privacy Laura So figuring out where somebody works, what state which we figured out we can do that through outlook is really important to then figure out what public holidays they get because the states vary so much.
0:49:11.870 –> 0:49:19.150 s47F - personal privacy Laura So I’m actually not gonna do that. I’m actually gonna assign that to someone in this session to do the rest.
0:49:20.650 –> 0:49:21.370 s47F - personal privacy Laura After this meeting.
0:49:23.470 –> 0:49:25.110 s47F - personal privacy Laura Team contact list.
FOI 25/26-2150
Again, pretty basic as well. It’s just got people’s names, position, mobile number which you can see it’s mostly blank. That’s because people have to manually come in here and add their own mobile numbers and that’s because we don’t generally have work phones in this team. Everyone’s just using their own personal and the Microsoft Teams number is something that only you can see. So we as you can see, part of this is not just adding new rows to this table, it’s about.
Following up with people and asking them very politely if they can come in here and update their details.
The location we figured out that we can see people’s location through outlook. It comes up in that little card, but you probably can just ask somebody what location they’re in. You may know. So in order to add somebody new, you can just insert a row.
To write that person’s name.
People’s positions is.
As you can see, it’s not that it’s not really that helpful.
I’m just gonna write triage and early res officer, and if you come up with a better, a better name for your role, you could more than welcome to come in here and update this so that it accurately reflects your role. So I know you’re in Brisbane and then we’d ask Tony to come in here and put her mobile number in and then to find her Microsoft Teams number. So in order to do that.
Page 278 of 331
FOI 25/26-2150
You open up Microsoft Teams and then you go to the calls function and there’s your work number there and you can just copy paste that.
0:51:6.540 –> 0:51:16.380 s47F - personal privacy Laura And that means that somebody could call you directly from their mobile and it would come to your teams. So you might have to train people on how to find that number, cuz that’s the only place where it exists.
0:51:20.640 –> 0:51:20.920 s47F - personal privacy Laura Mm hmm mm.
0:51:17.150 –> 0:51:32.590 s47F - personal privacy, Tanya Sorry, sorry I’m I was trying to find it yesterday and I thought I was pretty out there with teens, but clearly I’m rusty. So you’re saying go to the call? Oh, I’ve got it. It’s as easy as that. Thank you, Laura. Fabulous.
0:51:31.290 –> 0:51:33.570 s47F - personal privacy Laura Wonderful. Cool.
0:51:33.690 –> 0:51:34.290 s47F - personal privacy, Tanya Thank you.
0:51:34.880 –> 0:51:36.520 s47F - personal privacy Laura Any questions about that?
0:51:41.540 –> 0:51:41.940 s47F - personal privacy, John Nope.
0:51:42.500 –> 0:51:51.340 s47F - personal privacy Laura If anything occurs to you, you can always ask me later, and then the last thing is probably the easiest thing is adding people to Microsoft Teams meeting and chats.
0:51:52.860 –> 0:52:12.620 s47F - personal privacy Laura And this is basically everyone in the team will know how to do this. So this is really something
that we want people to do when people start, so they’re not missing out on conversations or
key meetings, but it’s it’s pretty easy to just figure this one out intuitively. So in order to add somebody to a chat.
0:52:20.220 –> 0:52:38.60 s47F - personal privacy Laura Here’s a chat that I’ve got the personal PIA PC group, not a chat that any of you need to be in, but for arguments sake, if I wanted to add you in here, Tanya, you just hit the top right hand side here and it says viewer add participants and it can hit add people and you can just type Somebody’d name.
0:52:39.520 –> 0:52:46.120 s47F - personal privacy Laura And you get to decide whether you want to include all chat history, no chat history or history from a certain number of days.
0:52:47.400 –> 0:52:49.640 s47F - personal privacy Laura In order to remove people from chats.
0:52:51.160 –> 0:52:53.200 s47F - personal privacy Laura Let’s find a chat. We can remove someone from.
0:53:0.0 –> 0:53:20.80 s47F - personal privacy Laura Here’s a chat. This is the Canberra team chats, everyone who works in the Chamber. Canberra office comes here. We can remove Aisha from this chat now, so we can go up to the top and then we can find Aisha. And she’s whited out because she no longer works at the agency. We can just hit that cross button and she’s gonna remove be removed from that.
0:53:23.850 –> 0:53:44.90 s47F - personal privacy Laura So the key thing to remember when you first start is trying try and figure out all the chats you might need access to, because you’re gonna find there’s a whole team chat and there’s also individual team chats and there might just be chats on the side for specific roles. So always good to just question and make sure you’re you’ve got all the right chats that you need, and then in terms of.
0:53:45.490 –> 0:53:46.890 s47F - personal privacy Laura Microsoft Teams meetings.
FOI 25/26-2150
So there’s two ways we can do this, so I’m on my calendar in Microsoft Teams, so that’s my e-mail and that’s my calendar.
It’ll be for you. It’ll probably look like this. It’ll just have your personal calendar of all your meetings that you’re attending. If you come to the site here on the left, there’s you’ll have access to the shared calendars. So there’s a shared calendar for FOI and a shared calendar for information dot access. And this shows you all the meetings that have been booked into that shared calendar.
Meaning anyone in the team can access them. So as you can see there are a lot of meetings in here and that’s to ensure that if we need to reschedule one because someone’s away, anyone has the capacity to do it. So this meeting whole team Friday session, if I double click on this on the FOI calendar and that’s the crucial thing, make sure you’re clicking it on the shared calendar, not your own personal calendar. And then we update the entire series.
That’s giving us a list of everyone who’s invited to the meeting so we can see. Tanya, you’re there, pujan, you’re there in order to add a new person like Bo, I would just type in Bo’s name there. And now he’s invited to the meeting in order to remove somebody from this meeting. You just have to find their e-mail address and then delete it so I can see Aisha’s name is there. So I’m just pressing backspace on that. And now she’s no longer invited to the meeting.
And then we’ve send send update.
And this usually gives you an option to not send the update to literally every single person in the list. Sometimes it just says do you only wanna send the update to new or removed invitees. It didn’t give me the option that time, which annoyingly means that every single person in the team is now gonna get a new invite to that team meeting. So.
FOI 25/26-2150
0:55:49.510 –> 0:55:51.350 s47F - personal privacy Laura Give my apologies to everyone.
0:55:49.750 –> 0:55:52.950 s47F - personal privac Jessie You don’t want three three times in a row.
0:55:54.400 –> 0:55:55.160 s47F - personal privacy Laura Only human.
0:55:54.200 –> 0:55:55.760 s47F - personal privac Jessie Send it to everybody.
0:55:58.220 –> 0:56:6.540 s47F - personal privacy Laura Just means everyone has to re accept it, which is it’s going to annoy them anyway, so that’s an easy way to add people to whole team meetings.
0:56:7.900 –> 0:56:11.180 s47F - personal privacy Laura Other ones, for example, this morning we had an all staff huddle.
0:56:12.810 –> 0:56:14.770 s47F - personal privacy Laura We don’t. We’re not the owners of that meeting.
0:56:16.130 –> 0:56:21.610 s47F - personal privacy Laura But we can still open it up and you can see we’re not the owners of it because we don’t. We don’t see who, the whole.
0:56:23.970 –> 0:56:28.650 s47F - personal privacy Laura Invite list is, but you could nonetheless forward it, so I’ve just hit forward on that.
0:56:30.300 –> 0:56:38.140 s47F - personal privacy Laura And then we can forward it to, let’s say we forwarded it to Bo and we can just say Hi, Bo.
FOI 25/26-2150
0:56:42.340 –> 0:56:43.20 s47F - personal privacy Laura It’s meeting.
0:56:45.810 –> 0:57:12.170 s47F - personal privacy Laura First day something like that. So this works as like a temporary solution if somebody’s just starting, they need to attend the meeting and will worry about adding them properly to the invite list later. Yeah, and then you can at least be guaranteed that person has access to the meeting and can join and can participate. Yeah. So we won’t do that one now. The same about removing people’s names. So Aisha’s still on this list.
0:57:13.20 –> 0:57:14.740 s47F - personal privacy Laura We’re not responsible for.
0:57:16.770 –> 0:57:25.90 s47F - personal privacy Laura Updating these meetings that we don’t own. So in this case, Leanne s47F - personal privacy , who is our branch manager, Acting branch manager.
0:57:26.450 –> 0:57:30.930 s47F - personal privacy Laura Her executive officer will have sent this so that person is the owner of this.
0:57:33.240 –> 0:57:41.40 s47F - personal privacy Laura Yeah. So that’s the two ways to add somebody to a meeting, either forwarding it or if you have the ownership of it on this shared calendar to just edit it.
0:57:43.840 –> 0:57:58.200 s47F - personal privacy Laura Great. And that has the updates there and that’s it. We’ve cracked on for an hour and we’ve shown you every single access that there is. I’ve got one little slide here about troubleshooting access with just some I guess words of wisdom.
0:57:59.720 –> 0:58:6.920 s47F - personal privacy Laura The most common thing is that staff automatically assume they’ve lost access to something, and they always ask you to resubmit it.
Page 283 of 331
FOI 25/26-2150
0:58:7.560 –> 0:58:12.600 s47F - personal privacy Laura Nine times out of 10, they do have access. You just need to check it and the problem is something else and.
0:58:14.200 –> 0:58:25.600 s47F - personal privacy Laura So I would say my main thing is if anyone comes to you with issues, always double check it. So yesterday I had some people coming to me saying they couldn’t access that file. I went in and checked it so I’ll show you what I did.
0:58:32.0 –> 0:59:2.600 s47F - personal privacy Laura I’m here in the SharePoint any file at all. I can hit these three little buttons and hit manage access and then that shows me who has access to this file right? So I can see that like Tanya you have access to the file, right? So if you come to me and say I don’t have access to the file, I’m like that doesn’t make sense. It’s telling me you have access the second tab here is groups and that tells me who has access to that file via a group membership. So I can see everyone who’s a Freedom of Information member has access to that file.
0:59:3.80 –> 0:59:6.920 s47F - personal privacy Laura Which means everyone who’s got access to the SharePoint should have access to the file.
0:59:8.320 –> 0:59:11.760 s47F - personal privacy Laura Yeah. So if you think of that doesn’t make sense. You can also hit this.
0:59:13.480 –> 0:59:16.280 s47F - personal privacy Laura Three dots again for more options and hit advanced settings.
0:59:19.370 –> 0:59:27.450 s47F - personal privacy Laura And then that brings you up this screen where you can do this check permissions button so I can type in any staff name.
0:59:30.50 –> 0:59:53.570 s47F - personal privacy Laura And see if that person has access so I can see you’ve got edit rights given through the Freedom of Information Members group. So if you came to me and said no, I still can’t access that file. Laura, I know it’s not a problem on my end. I know it’s must be something weird with your
FOI 25/26-2150
account. And the next step would be I think you should lodge an ICT service desk ticket. So if person doesn’t have access, I’ll just show you somebody who does not.
1:0:3.450 –> 1:0:4.810 s47F - personal privacy Laura This is what it looks like.
1:0:5.930 –> 1:0:14.210 s47F - personal privacy Laura No, none. This person has none access to that file. So again, if this person can’t access the file, I know there’s something wrong and that I can give them access.
1:0:15.490 –> 1:0:33.290 s47F - personal privacy Laura So that’s my first step for troubleshooting. Second thing is another important tip. If the basic troubleshooting steps don’t resolve the problem, direct the staff member to actually lodge an ICT service test ticket. Remember that you’re not tech support, OK? You’re here to set up accesses and fix routine, predictable problems.
1:0:33.710 –> 1:0:39.990 s47F - personal privacy Laura If someone’s having major issues and they can’t access their computer or their systems, it’s not your responsibility to fix that.
1:0:41.270 –> 1:0:46.950 s47F - personal privacy Laura It’s staff members responsibility to lodge an ICT service test ticket and to call ICT and talk to them over the phone.
1:0:48.630 –> 1:1:2.950 s47F - personal privacy Laura The only exception would be if you’ve hear that multiple staff are experiencing the same issue over and over again. You might volunteer for the sake of efficiency to be the main contact and to lodge an ICC ticket, and you know, note that there are multiple people affected.
1:1:3.470 –> 1:1:16.190 s47F - personal privacy Laura And that will then save everyone else’s time, but that’s something if you’re planning on doing that, you need to talk about that with your team leader, and Rachel’s gonna make the call about whether the situation is that serious and whether you have capacity to do that.
FOI 25/26-2150
1:1:17.740 –> 1:1:23.380 s47F - personal privacy Laura And that there is the end of the slide show. Are there any questions out of that?
1:1:27.440 –> 1:1:29.160 s47F - personal privac Jessie No, not for me. Thank you, Laura.
1:1:29.750 –> 1:1:31.30 s47F - personal privacy, Tanya Alright, thank you Lauren.
1:1:30.0 –> 1:1:31.160 s47F - personal privacy, John No, Laura. Thank you.
1:1:32.60 –> 1:1:32.500 s47F - personal privacy Laura OK.
1:1:32.720 –> 1:1:33.520 s47F - personal pr , Poojan s47F - personal pr All good, Laura.
1:1:34.560 –> 1:1:35.160 s47F - personal privacy Laura Well.
1:1:31.850 –> 1:1:36.410 s47F - personal privacy, Tanya That much information was very good. Are you able to share the recording, Laura?
1:1:37.960 –> 1:1:38.760 s47F - personal privacy, Tanya Fabulous.
1:1:44.320 –> 1:1:45.80 s47F - personal privacy, Tanya Yes.
1:1:36.800 –> 1:2:1.120 s47F - personal privacy Laura Absolutely. I will drag the recording into SharePoint. I’ll send you all the link. I’ll reattach all the
resources that you’ve got and then yeah, I’ll liaise with Rachel and I’m happy to go ahead and add some more accesses for you. Pujan to CRM and I will assign a lucky volunteer the task of updating the leave calendar and the contacts list.
1:2:6.460 –> 1:2:6.660 s47F - personal privacy Jessie Thank.
1:2:2.560 –> 1:2:7.480 s47F - personal privacy Laura And yeah, when new people start, there’s a few in the pipeline.
1:2:8.260 –> 1:2:16.940 s47F - personal privacy Laura One of you wonderful people will be able to do this for real. Sorry. Thank you so much for coming. I’m always here. If you’ve got any questions and I’m going to stop the recording now.
Page 287 of 331Training video - FOI - Staff accesses - 2024.06.12
Training video - FOI - Staff accesses - 2024.06.12.mp4
0:02 Welcome to this training session about how to, uh, add, remove, and check staff accesses here in the Information Access team. I’ve shared my screen and this session is being recorded for training purposes. And by continuing to be here in this meeting, you’re consenting to just being part of this recording. If anyone disagrees with that, you’re more than welcome to log off and just review the video later. So today, staff accesses. A little bit of background on staff accesses.
0:32 They’re essential for everyone. Um, we have multiple different systems here at the NDIA and um, some accesses are done automatically by the recruitment team, but some have to be done manually by our team.
0:44 Um, in the past, um, we’ve had two situations. One would be that there was one person who was the expert on all staff accesses and they did everything behind the scenes. Nobody knew what they did. And then when that person was sick or on leave, nobody had any idea what to do. That’s not a good situation. The other situation we had was there was nobody around and every single person had to figure all this out for the first time themselves and nothing was written down. Not a good situation either. So what we’ve decided to do is train the entire triage and early resolution team in the basics of staff accesses so every single one of you feels a certain level of comfort so you could step in and do this in the future if there was a need. So not every single one of you needs to become a subject matter expert on this, but it’s good if you just get a little bit of comfort in knowing where the resources are, how to find them, and where to ask for help so you could fill in if you needed to.
1:15 team in the basics of staff accesses so every single one of you feels a certain level of comfort so you could step in and do this in the future if there was a need. So not every single one of you needs to become a subject matter expert on this, but it’s good if you just get a little bit of comfort in knowing where the resources are, how to find them, and where to ask for help so you could fill in if you needed to.
1:42 So this is the agenda for today. It looks like a lot, but everything here is pretty easy. I’m gonna go through stuff, accesses through multiple systems, starting with the SharePoint site, which is what we’re using as a document management service to record all the documents that we work on. There’s 2 shared mailboxes that we use to correspond with applicants, receive requests, and correspond with different parts of the agency. The third system is Lex, which is a
2:12 different case management system is where we, um, record matters that we’re working on and update the status.
2:19 And the fourth thing is CRM roles. CRM is a case management system where NDIS participant data is stored. And so we’re going to show you how you get the right roles to gain access to that participant data. Fifth thing is the email distribution list. That’s a way that we can communicate with everyone in the team really easily without having to write people’s individual emails.
Page 288 of 331
FOI 25/26-2150
2:42
Um, six thing is the leave calendar and staff contact lists. Um, that’s just an Excel document that we have where we keep track of people’s attendance, best contact number, which office are they located in? And then lastly, the Microsoft Meet Teams meetings and chats. We use Microsoft Teams a lot to connect with one another, whether that’s why video conferencing or just via text messages in the chat. Then we’re gonna do a little bit of troubleshooting about some common issues that tend to happen and we’re gonna have a little bit of time
3:13
for questions before I go on. Is there anything, um, any questions that people have straight up? Um, you understand why here in the meeting and what I’m gonna show you? Is there anything that’s just got you confused already
3:28
cause some thumbs up? Yes. Thanks, Laura. Oh, John, go ahead.
3:36
It’s it’s all good though. Thank you. OK, cool,
3:40
cool. Sorry. What we’re gonna do is go through some of the key resources so you don’t have to panic and take notes because everything that I’m about to show you is included here in the standard operating procedure, or SOP as we call them. And it’s got screenshots showing you exactly where to click. So I’ve sent you a link to that SOP via the chat earlier and I hope you can all bring it up. So you may, if you’d like to have that SOP on your screen
4:11
next to you.
4:13
The other thing that, um, you should definitely bookmark is this link here to the Office of the Chief Information Officer help guide. So Office of the Chief Information Officer is the division in our agency that includes the ICT team.
4:30
They like to reduce the number of ICT requests that they have to deal with. So they have extensive help guides about common issues. So if you do encounter a technical problem, it’s always worthwhile to seeing if there’s already an answer on that website. The other thing you may want to bookmark is the Microsoft support. A lot of the programmes that we use here at the agency are Microsoft products, including SharePoint, Outlook and Teams. So if someone in particular is having a weird glitch that doesn’t seem to make sense, you’ll often be able to find a help guide just online for the
5:01
general public to use.
5:04
Um, and there’s a couple of other ones, um, not gonna be relevant, but more just general information. If you’re helping someone troubleshoot technical issues,
— PAGE TEXT END –
FOI 25/26-2150
5:14 uh, standard operating procedures are included on the ndia intranet and you can just usually do a keyword search on the Internet and you may find something that’s helpful. The only caveat to that is it may be out of date. So have a look at how recent it is before you follow the steps. And then Lex, one of our systems does have a help guide which you can access via Lex. So you will all have a copy of this PowerPoint. I sent it to you in the meeting invite and I can forward
5:44 you can. So all these links you’ll be able to access after this training session.
5:50 Cool. So we’re right into it. Some of the first preliminary steps that we need to do
5:55 confirm the staff members correct name.
5:59 Um, and that’s important because, um, sometimes people have legal names, but then they have preferred names and we need to confirm what name they’re actually will be known by within the team.
6:10 There’s a couple of ways we can do this. The easiest way is that when the person is recruited, um, their line manager will be sent an email that confirms their name. If you don’t have that information, there are different ways we can go about finding it out. One is by doing the employee search
6:30
and another way we can find out things is by, um, working out their email address via Outlook auto complete. So I’m just going to demonstrate that to you with our new starter, Bo redacted.
6:46 Sorry,
6:49
this here is the Intranet. It should be your homepage when you open up any browser on the computer. So the first thing we want to do, we’re gonna say Bo redacted. I don’t know how to spell his name right. Is it s47F - personal privacy redacted? We don’t know,
7:05 um, the best way to do it is only works for one day before they start. So it’s not something you can do in advance is to go over here and do my links where it says essentials. And this takes us to the NDIA, HR and finance system,
7:20 so we don’t have to create profiles in Essentials. That’s done automatically by the recruitment team. If you go up the top here, one of the tabs is called My Details, and then one of the options you’re going to get is called Reports,
Page 290 of 331FOI 25/26-2150
7:34 and then one of the options you’re going to get here is called User Information.
7:40 So it comes up with the screen and you hit display
7:43
and it opens up a pretty basic looking PDF. But what this is, is a list of every single person in our team,
the Information access team, including their full name spelt correctly and their user ID. So I can see Bo
redacted here, I can see his name is spelt with an redacted and that his ID is redacted. It’s usually 3 letters
followed by three numbers, but be careful. There are some
8:14 variations on that, particularly for staff who’ve been around the agency for a while.
8:18
I can also see, um, Pugin, you’re here and your number here is redacted and Tanya. You’re, you’re here
as well, redacted. Probably the coolest stuff I’d I’ve ever seen. Tanya, well done on that one. Thank
you. It was just a fully better know how they did it.
8:37 Cool. So that’s only works for 24 hours before they start Um, that’s when the person’s account is created. Second thing you can do
8:47 is go to the staff directory search. So you’ve got the link for this in your PowerPoint
8:54 and what this will give you, it will give you the name and position and staff ID of any employee of the agency. So if you know somebody’s name, even their first name, you can usually do,
9:06 um, a good guess of what, how it could be spelt.
9:11
If we type in Bo redacted name there and press, press enter
9:18
redacted
9:21 we can see if he’s gonna come up in the employee search. So he’s doesn’t appear to be coming up at the moment.
9:26 Sorry. Let’s type in somebody else.
FOI 25/26-2150
There you go. So Tanya, you’re on there. So as you can see, the disadvantage of this is that there’s a little bit of a delay.
This is usually done within 24 hours. This takes a few days, but that’s two different ways you can try to find out the correct spelling of someone’s name and their staff ID. This one you can see has an advantage that includes the email address as well. It’s important to note that because sometimes people can have numbers after their name, like maybe Tanya Dot redacted: s47F - personal privacy, two or three, depending on how common that name is. So it’s important to verify that if you didn’t have the access to that to figure out the email address.
what you might do is open up Outlook and this is just automatically generating a new email that has my signature there.
The autocomplete function is set up to automatically assume you are trying to contact the people who are closest to you within the organisation chart. So if I type in Go,
So Bo redacted: s47F - personal privacy doesn’t have uh, um, anything on the system yet. Let’s type in somebody else, Tanya. There you go, Tanya. So of all the Tanya’s in the agency knows that I’m most likely to be contacting you, Tanya, because we’re in the same team. So if I click that, I can also get a little information panel. Double click that about Tanya. And I’ve got this option here to just copy the email address. So if I needed to use that, that’s where I’d get it.
This also includes office locations and that will come in handy later.
Cool. So that’s three different ways to get the information about,
uh, the persons details. So that covers off everything in this,
So now we can get into it and I’ll just make this large again. We are now moving on to the first access, which is access to the SharePoint site. So key points on this slide is staff added via my groups. That’s the key takeaway from this. I’m sure this is gonna be a lot of information overload and you’re gonna get confused about where things are going. This is just giving you a snapshot on where SharePoint is accessed by my group. So I’ll just show you where that is.
Page 292 of 331
FOI 25/26-2150
11:44
I’m just gonna click the link to my apps
11:48
and I’m also gonna show you a second way to get there. So the apps dashboard shows you all the apps that are installed on the cloud that anyone can access as an employee of the agency, if you can bookmark this my applications.microsoft.com. If you forget to do that, it’s also accessible via
12:07
the Intranet page. So go back to the Intranet page and go over to my links again
12:13
and I Scroll down. Here is my apps down there. So you’ve always got a way to get through it straight from the home page. If you go up to the top corner over here, there’s little arrow and then you select my groups
12:30
and this shows you all groups that you’re in, all groups that you own. Um, so groups that I’m in, I’m in 83 groups. And you can see some of these are auto generated reports that we don’t touch. They must be things that the finance team or the HR team is doing for other purposes. Some of them though, this one is our branch. DL means distribution list complaints dot foi branch,
12:59
um, this one Deacon .90 dot Denison St that’s I guess my location group so that if there’s ever a property issue that needs to be communicated to me in my location, it can come there. And then there’s these our team groups, like the FOI group there.
13:15
There’s also um
13:17
social groups as well. If you join any of the um,
13:22
fun social groups linked on the Internet, we’ve got a couple of um, team sort of social media things. You can see I’m in the NDIS and mental health group, photography lovers group, and the book lovers
13:34
group. So that’s just a little bit background. In order to do this, you need to be the owner of a group, not just a member of the group. So when you go into yours, you’re going to see that groups like own, it’s probably going to say zero. So that’s one of the key preliminary steps before you can do this is you have to be able to be made an owner. Anyone can be made an owner by another owner. So if we go into this one freedom_of information, that’s our SharePoint group, you’ll be able to go in there and you’ll be able to see who the owners are. So you can see
FOI 25/26-2150
14:04 there’s 123-4567 owners and six of those people are members of our team. So our director, Peter, multiple EL1s, and then Rachel, who is your team leader.
14:18 So that’s one of the preliminary steps that you could ask Rachel, for example, to make you an owner before you do this in order to add someone to a group. It’s really, really easy. You go to the member screen, you hit the add button,
14:33
redacted is coming up. Um, and we also know his
email address. Now it’s Bo Dot redacted. No numbers. Just click on that and press add
14:45 and then he will appear down the bottom
14:51 and that’s how someone can be made an owner. Someone who is an owner can just hit that button that says make owner. So then in order to check somebody’s access, you go to the members and up here it says filter by name
15:04 and you can just type in someone’s name. So we’re typing in your name and we’re checking that Yep, you’ve got access. It’s all good Pugin which that’s important. If somebody says I’m having trouble, I can’t access the SharePoint, The first thing you do check whether they’ve got access. If they don’t have access, you can give it to them. But if they do have access, you know the problem is something else. The last thing you can do is to remove an access. So the person I’m gonna remove first name was Aisha. So we can see this person, we can hit
15:34 the remove button over there,
15:37 and then that person’s gone. So that’s legit it everyone. That is, how do you give people access? Check people’s access and remove access from the SharePoint.
15:49 Cool, next thing.
15:51 Ohe wait before I go on, any questions about that?
15:56 No
15:58 thumbs up again. Thank you. Wonderful. Cool. OK,
FOI 25/26-2150
access to shared mailboxes,
same place. So my groups function and it’s going to function in exactly the same way.
So here we are, groups I own, and there’s four groups that relate to our shared mailboxes. They’ve all got the initials SM, meaning shared mailbox at the start
FOI full access let’s people view anything in that mailbox. Send as allows people, instead of sending from your personal email, to send on from the actual FOI at ndis.gov dot U email address.
The exact same thing with information dot access. So we’re going to go through the exact same process again. Click on it. If you’re not an owner, you need to ask an owner to add you as an owner. So we can see there are only three owners to this one. So Rachel as the triage team leader, Kylie as the triage assistant director, and me as the systems and access guru. Jesse, you’ve got your hand up.
Yes, question. So will the five of us just be added because this will be a role for us to take on, or will we just ask as we need it?
Look, I think we’ll talk to Rachel about that. I think once things settle down she might delegate one or two of you to be permanently owners and that can just be part of your duties and everyone else you would just need it as required.
Makes sense. There are, there are disadvantages to becoming an owner of this um,
and that’s why not everyone should be on it. And one of the disadvantages is anytime anyone makes a meeting invitation on the shared calendar,
you get CC d into any response. So if somebody accepts a meeting invite, you’ve got five meeting invites for the week, cause it’s a new week of training and 20 people are invited, you’ll get spammed with 100 emails. So there are disadvantages. OK, thanks Laura.
OK, we’re gonna do the exact same thing. Go to the members tab, we’re gonna hit add, we’re gonna type in Bo’s name. Um, it’s figured out that we’re talking about Bo redacted: s47F - personal privacy so I can just type in Bo and he’s coming up as the first option. It add
FOI 25/26-2150
then we can check
whether Pugin has access. No, you don’t. So again, if Pugin comes to me and says I’m having trouble, I can’t access the mailbox, first thing I’ll do come here and check whether he even has access or not. I can see he’s he doesn’t. So that’s an easy fix. So we can just add you here.
There you go. And then removing accesses, same again, type the person’s name, who you’re removing, they’re going to come up. Hit that, remove button.
Go back. Now we’re going to do the exact same thing with the next three.
So first thing we’re gonna do,
add and then type in Bo.
Then hit add,
We’re going to check with the Pugin has access
and he does not, so we’re going to add him as well.
And then we’re gonna remove AIsha,
hit remove.
While I’m here. I’ll just double check that Tanya, you’ve got access as well. Yeah, you’re good.
I’m just going to repeat the same thing over and over again. As you can see, it’s not hard.
Um,
FOI 25/26-2150
19:51 adding bow, checking Pugin.
19:56 So we’re adding Pugin.
20:02 And then we’re removing Aisha.
20:05 So in terms of removing people,
20:07 um, if somebody has left the agency, there’s no great urgency to remove them straight away because they won’t have access to their India account. However, if somebody’s change roles,
20:20 it’s kind of important for confidentiality reasons to remove them within a reasonable amount of time, like hopefully within 48 hours, um, just so that they no longer have access to the confidential documents that they had in our role in whatever their new role is.
20:38 And then lucky last,
20:44 I’m adding Bo,
20:46 checking through John’s.
20:50 So I’m adding Pugin
20:55 and then I’m removing Aisha.
21:04 That’s great. Well, that’s it.
21:06 That was absolutely everything about shared mailboxes. So any questions about that?
21:16 No thanks, Laura.
Page 297 of 331FOI 25/26-2150
OK, all good. Thank you. Thank you. I’ll wait. Maggie, you’ve got your hand up. Yes, just a quick question, right yes um, would that be right since example Tanya is new yes, would that be easier? Is, is, is that right? Is, uh, we find all the different list to add the person in or we have the list that,
um, how do I say,
because there are a lot of these, it might be missed. Is that right? Like for the new starter, they will have a certain distribution list will be given that need to be added. Is that sound right? That’s correct. So I, I think what you’re saying is, is there like a checklist where you can make sure that somebody has been added to every single system? Yeah, yeah, no, that’s not currently. Do you wanna create one? Because you can.
OK.
OK,
great question. Um, next question is access to Lex.
Um, so Lex is a completely separate system. It’s not owned by Microsoft. It’s not accessible by anyone else in the agency. ICT don’t administer it, which means if you ever have any issues with Lex, you can’t call ICT. They don’t know anything about it. They can’t access it. The best thing to do if you are having issues with Lex is to call me. I’ve sort of functioning as the de facto fix service desk and I can contact the people who own the programme if there’s anything high tech going on. So again, can you snapshot for Lex is we add staff via the administration tab
and just like the previous systems, you need to be given the role of administrator.
So when you log into Lex, you’re not going to see this tab unless we add it to you. Anyone who already has administration rights can give you the administration access. And similar to the SharePoint site, we’ve got about six people who are administrators, including Rachel and Kylie in your team. So that’s who you go to in the first instance.
Cool. So this is what the user administration screen looks like in order. It automatically defaults to AD
FOI 25/26-2150
23:39
um and in order to add somebody you just put in their details here. So I’m typing in Bo’s name as it is spelt on our system. So that’s why we need to double check the spelling of the name.
The login ID I am transposing from what we found earlier on Essentials. It was redacted.
24:01
s47E(d) - certain ope
24:04
password. s47E(d) - certain operations of agencies
24:14
s47E(d) - certain operations of agencies
24:23
e-mail address. We’ve found Bo’s e-mail address
24:27
when we were adding him to the other groups. So we just know it’s Bo redacted @ndis.gov dot AU.
24:35
And then starting page, you can leave admin section no,
24:41
but if you need to change somebody to admin right, that’s how you do it.
24:46
Um, admin other sections, we’ve only got the option no team. We’ve only got the option FOI right within that team changed you edit rights high and changed to all matters
24:58
that’s outside the team. We don’t have any rights and then we don’t,
25:02
um,
25:04
no need to touch these other ones. They can both be none. So if I just press save,
25:16
that’s not a good sign. This is Lex usually does things pretty quick. Great. So it gives you, um, a little, um, pop up that says, check you have enough licences.
FOI 25/26-2150
Um,
it’s a problem with Lex is that we only have a limited number of licences, about 50, which means if we have more than 50 active users at a time, new users, instead of creating a new profile, they recycle old ones.
Um, if we need more licences, that’s something that I would need to escalate up. So if you do notice something like that’s happened, a new user seems to have a lot of old matters assigned to them. That’s something that you should escalate straight up to me. So there you go. Bo redacted profile has been created. If you did do a typo and you spelled his name wrong or got his login ID wrong, you can just come in here and change it. It automatically defaults to the edit tab if you click somebody’s name,
and you can change somebody’s rights that way as well. So that’s it. That’s how to add Lex profile. Jesse,
would you have to advise the staff member that they have to reset their password 100%. So and did they get sent some kind of email or we have to do that or they don’t get sent anything automatically? We have to manually do it. So as soon as you’ve done that, you’re the only one who knows that. So fill up an email and say hey Bo, Bo, we’ve created you a profile on Lex. Here’s a link to Lex. Lex is a case management system that we use. Here’s your login ID, here’s your temporary password. Please log in and change it straight away. So, OK,
that’s about it. It doesn’t have to be fancy and don’t see anyone else in um to that email like not their line manager or anything, just because password is supposed to be private and only that person should know about them. Sure. Thanks Laura. Cool.
So then what we can do is, um, we can check. So Pugin, do you have a profile? It’s easy to just come to users and look down here. It’s alphabetical by first name, so if you had one, it would be down here if you keep scrolling.
We’ve also got this section called Inactive Users and that has all previous users here. So we could check on our did you have a profile? Was it accidentally inactivated? And we can see, Nope, there’s nothing there. So in that case we can say OK, we need to create a new profile for you.
So
FOI 25/26-2150
27:47: quick check that have I spelt your name wrong? Right,
27:53: correct. Hey, thumbs up.
27:56: And we’ve got your login ID here, redacted
28:02: So we’re gonna create the temporary password,
28:05: password one
28:07: and email address. Oh, I didn’t look that up before, so I’m just gonna look it up by
28:15: pulling you up on my other screen and then copying it.
28:23: There you go,
28:34: up your email,
28:39: there you go. So that’s all correct. And we’re going to have your starting page. Same. We’re going to give you no admin rights at the moment, but if we needed to check whether you needed admin rights, that’s the box we’d look.
28:52: We’re gonna give you high edit rights for all matters. That’s the main thing to do.
28:59: That’s it. Press Save
29:04: and then we can say
29:08: Profile.
FOI 25/26-2150
But that’s an example of the email you might send to the person straight away. Yeah,
right.
Oh, that’s one of the annoying things about Lex. While we’re here, it only lets you open one tab at a time, so you can’t work on it in multiple screens. Um, great. So we’ve created a new profile. We’ve checked whether a profile exists. Now let’s deactivate profile. So we’re going to Aisha’s profile here and we’re just hitting the inactivate button down here. We’re not hitting delete because we want, still wanna record of every bit of work that Aisha did when she was here so that if we get any reviews about it in the future,
um, we, we have the accountability of which staff member did it. So we just hit select her name and then hit inactivate.
Um, it says there are still items assigned to the user about to inactivate, so that’s something to check beforehand. So if I go to the search tab and then I hit Clear filters, what I’d probably like to do is to check what’s actually in this person’s name by picking them from the team’s matter section and then looking for Status Active.
So I can see there’s nothing active in Aisha’s name.
There are closed magazine, her name. But that’s not an issue. Um, it’s not an issue to inactivate a user if they’ve got closed matters in their name. So I’m happy to go back here. I’ve done my due diligence and now I’m just going to inactivate
and we’re going to hit yes, we want to continue. And then her name now appears down here in the inactive users. So if, for example, she was going on a six month,
you know, trial in another job within the agency and then she came back after six months, we can just pick her and then reactivate her. We don’t have to create an entirely new profile.
Cool. OK.
Any questions about Lex?
Page 302 of 331
FOI 25/26-2150
32:06 Yes, Maggie,
32:08 couple question. So the this one, we don’t have the SOP yet, right?
32:15 Yes, we do. We do.
32:18 I’ll just show it to you.
32:24 So this is the Freedom of Information homepage. Yep. Um, and if you Scroll down here in administration and onboarding,
32:33 and then here in this folder on boarding and accesses, and this is the SOP, the SOP FOI staff system accesses.
32:41 And this has all the prerequisites, right? And it has step by step. See this, Um, the formatting looks weird if you open it in the browser. So I always hit open in desktop app
33:02 and then if we open it up here, it’ll look a lot nicer and won’t have any formatting. It’s in the chat that you created as well, right, Laura? Yeah, yeah. If you go into that message that Laura sent Maggie, that first link
33:17 on the teams message that she sent this morning in the team, I went to email. Thank you. And second thing is Laura, uh, when we create a brand new profile, right? And then you send the email to the new staff, Hmm, will that automatic pop say you change, um, the place to change the password or we need to show the way like how to change your password? I can’t remember when. No, no, that’s a good that’s a good question. The first time you log into Lex,
33:47 it’ll prompt you to change your password and then it does, it does so I think approximately once every six months after that. So they’ll be able to log in and they will then immediately have to change their password. So that’s, that’s a really good question If anyone ever forgets their password,
34:04 which we’re skipping ahead to the troubleshooting, but it’s pretty relevant. Um, you can just, um, go in here and we can say, ah, those forgotten these password, you can just hit reset password.
Page 303 of 331FOI 25/26-2150
So if I hit that, it would say, what’s your new password? So we can say
s47E(d) - certain operations of agencies
and then I could then email Bo and say I’ve reset your passwords and new s47E(d) - certain operations of agencies
really important. People forget their Lex, um, passwords all the time and ICT can’t help them. So that’s definitely the process for doing that.
So if we go to um a matter, so this is just a random matter. Um, and it shows you what details we have in Lex. The main details tab is the edit tab, and you can see up here in the team matter lead. Our new staff are now there, so those there
Pugin, you’re there and Aisha is gone.
Then if you go to this second um box here team slash clearing member,
you can see that Bo isn’t there,
Pugin you’re not there,
and Aisha is still there. And the reason is this one is updated automatically when you add staff. This one is updated manually by a person with administration rights who works in a different team from us.
So at the end of the week, what I’m gonna do, and I will cc you in, is I’ll send an email to the person who manages the administration rights to Lex and I will put in a request for this drop down box to be manually updated. So the new people are added and people who’ve left are removed. So that’s an annoying administrative step on top of the existing processes. But yeah, it’s also just important thing to keep the whole system up to date, not just some of the boxes.
OK, so we’ll move on to the next one, which is adding CRM roles for new staff. So this slide gives you the snapshot of where you find it. It’s via Essentials under the Access Management tab. So let’s have a look at what that looks like.
FOI 25/26-2150
Again, in order to get to Essentials,
go to
the Intranet
and scroll over here to the side where it says Essentials under My Links
and then Access Management is the tab that you want.
So Access request is what we wanna do
and that’s going to show you a default screen. Um,
what things you want added down here? What’s the justification and who you want to request it for? It’s going to automatically default to you. So we need to change it to another user. So I’m going pick request for other here,
and then this button, I’m going to click this
and I’m going to hit the two boxes, and then that’s going to let me pick that person’s name. So I’m going to start with Bo
So he’s username is redacted and I’m gonna hit go
and there that person pops up. So I’m going to click the check box and then hit OK,
the description when we’re adding basic CRM roles is required for jobs in FOI team. And normally we don’t have to do more of a justification than that because what we’re asking for is standard job, standard roles, standard sort of access to our case management system, not our special access that is particularly restricted. Then hit the Add role button
FOI 25/26-2150
and then here you want to see role description contains
and so one of them is NDIA Manager. There’s three roles that we give every new starter. Just automatically hit the search button
and then any role containing the words ndia Manager will appear. This is the one we want India Manager. We don’t want training ndia Manager. So we hit the checkbox for ndia Manager. Then we hit this arrow
that basically selects it, moves it from this box to this box.
Um, the next one we want to do is
manager.
Nope, hasn’t come up. That’s OK. I’m gonna go back to the SOP and I’m just gonna copy paste the full name of the role because then I can’t make mistakes.
So the three roles, it’s here,
non approval, plan, delegation, that’s what we want. Cool.
It’s gonna copy that
and I’m gonna paste that in here. Search for that.
There it is. It’s this one NDIA plan delegation, non approval, not the training one. Select the check box, hit the arrow, then it goes down below and then the last one that we need is just NDIA Freedom of Information.
FOI 25/26-2150
So search for that.
So this is the one we want ndia Freedom of Information, not role owner NDIA FOI and then we hit down. So those are the three basic ones that will give all stuff basic access to CRM hit OK.
Then we hit this simulation button, which is basically running a risk analysis to see if it’s particularly risky to assign these roles to this particular person. It opens up another screen and we hit the Run Risk Analysis button.
We give it a few seconds and then we hit Apply.
If there were any risks, they would have appeared. You can see the risk analysis column is now green, meaning it’s completely safe. And then we hit submit
and it’s saying here that the request has been successfully submitted. That’s going to generate an email that will go to that person’s line manager and they can either approve or reject that request.
Um, we don’t have to remove people CRM access. That’s done automatically when they cease employment with the NDIA, but we can check people’s access. So if somebody comes to me and says I’m having trouble accessing CRM, I think it’s my accesses, first thing to do is to check. So in order to do that, we go to My access tap tile and you can see it automatically defaults to yourself and you can see the position roles that I have. So I have my Freedom of Information, my NDIA manager and my planned delegation non approval. So I’ve got all those.
There’s another tab here, organisation roles as well, they added by the finance team, not by us. So if you wanted to check somebody’s access. So I wanted to check Tanya’s access.
Um, I just hit the select user button and I type in that person’s name.
Maybe it’s uh, uh, first name, last name, first situation.
There you go. So last name first, you can type in the user ID, um, select that person and then the system will refresh.
FOI 25/26-2150
42:01 And we can see Tanya has the correct roles here, the Freedom of Information role, the manager role and the planned delegation non approver role. And this employee one is a standard one that everyone who’s an employee of the agency gets because that’s how you get paid. So if Tanya’s having any issues with CRM, we can say it’s not a problem on our end. We’ve checked your accesses. They’re fine, which is usually a sign that the next step would be talk to ICT logger service desk ticket. Cool,
42:28 so that was CRM adding and checking. I’ll do yours properly after this training session. Pugin because it doesn’t make sense to just repeat the same things over and over.
42:39 So we’re almost at the end. Um, so the next thing is adding staff to the email distribution list.
42:46 Um, so staff are added via a link in the Outlook web app. You can just click on this link and then bookmark it.
42:56 Oops.
43:00 OH,
43:01 it’s a bad request. OK, that’s no fun.
43:07 Wonder if I have it saved anywhere else there is another way to get to it.
43:20 So what I’ve done is I’ve gone to the My Apps screen and then I’ve clicked on Outlook. So it’s opening up Outlook via the web apps and then what I can do?
43:28 Search for distribution list,
43:36 distribution groups,
43:39 and then we’ve got a list here that says to manage distribution groups, visit this portal. So let’s see if that link works.
Page 308 of 331FOI 25/26-2150
43:54 There you go. That has worked. So everyone follow those steps and then you can bookmark this. Um, exactly like the my apps, the my group screen, there’s groups I belong to and groups I own. So again, in order to edit this, you need to be added as an owner of this group.
44:10 Um,
44:12 so I’m only the owner of one. So what I can do is I can click this one the FOI and then
44:26 not letting me add it up. That’s really weird.
44:30 There we go, members, cool, this is this. They’ve refreshed this so we can see who’s the owner of this group. So you know a lot of people there and we can view and manage owners and then the members so we can view and manage members. So if I click that button,
44:49 then add Bo
44:54 OH, add first
44:57 and then
44:59 please don’t work.
45:06 Nope, didn’t work.
45:09
There we go. So I’ve searched. I’ve typed it in the name as Bo Dot redacted, so I’m actually typing in
the email string so then I can click the check box there and press add
45:20 will appear within 5 minutes. That’s fabulous.
45:24 I’m going to open that one again and go back to the members
45:30 view all in manage. So if I wanted to search to see if you’re on it, Tanya,
— PAGE TEXT END –
FOI 25/26-2150
45:37 I can see that you’re not.
45:39 So again, if somebody’s not getting the all staff emails are being sent to the DL, check if they’re on this list. If they’re not, add them in
45:54 and then hit the check box and press, Add
45:58 and then same again. To remove somebody, go back to members
46:03 if you will manage.
46:06 Then we search for Aisha’s name
46:11 and then we click here and we hit delete up in the top corner.
46:17 Great. So that’s adding people, checking whether someone has access and removing them.
46:23 And in order to get access to that list, you’d need to be made an owner by an existing owner, which we showed you how to do that a little bit as well. You just have to talk to them. Somebody you know is an owner. Me, I’m an owner of most things
46:38 really in the home stretch now, um, leave calendar and staff contacts lists. Um, like I said before, these are little systems that we’re using to record where people work. What’s their best contact number. They’re on SharePoint and there’s two places you can get them. So I’ll just go to SharePoint.
46:58 The first place is up here in the top right hand corner, team contact list and team leave calendar. Or if you lose track of them you can go to administration and onboarding
47:07 and then they are team leave calendar and contact list there.
47:15 So, this is what the leave calendar looks like. As you can see, it’s pretty low tech. If anyone’s techie and knows of a good solution in order to automate this,
Page 310 of 331
FOI 25/26-2150
47:25 like, please let me know. Um, so as you can see, it’s got staff names and in order to add somebody’s, what we’re usually doing is just
47:34 copying a row, pasting it again and then changing the name
47:43 so you didn’t have a public holiday on that day. So that’s the thing that we definitely need somebody to use their ingenuity to fix public holidays for different states.
47:55 Maybe we could think about, um, importing something that already exists instead of doing this. It’s pretty old school,
48:02 so you can see when people have days off, they just mark them, copy paste these little cells and put them in the leave calendar. So again, one of the problems is then someone has to manually add or
48:15 Tanya ,Pugins’s names to every single month.
48:20 Um, so it can be a little bit fiddly, but it’s not hard. It’s just something that somebody needs to, um, be aware of
48:27 and then to remove somebody. Um, so s47F - personal privacy , so we don’t need her name for any months after that. So I’m literally just selecting the row and then deleting it and again manually doing that for every single month.
48:45 So yeah, like I said, a little bit fiddly, but pretty easy and self explanatory. This one, you don’t need any special access to do that. So this is something that absolutely everyone in the team can take responsibility for and fix errors as they see them.
49:01 So figuring out where somebody works, what state, which we figured out we can do that through Outlook is really important to then figure out what public holidays they get because the states vary so much.
49:13 So
FOI 25/26-2150
49:14 I’m actually not gonna do that. I’m actually gonna assign that to someone in this session to do the rest. Um,
49:22 after this meeting,
49:25 team contact list
49:27 again, pretty basic as well. It’s just got people’s names, position, mobile number, which you can see it’s mostly blank. That’s because people have to manually come in here and add their own mobile numbers. And that’s because we don’t generally have work phones in this team. Everyone’s just using their own personal and the Microsoft Teams number is something that only you can see. So we, as you can see,
49:52 part of this is not just adding new rows to this table. It’s about
49:56 following up with people and asking them very politely if they can come in here and update their details.
50:01 Um, the location, we figured out that we can see people’s location through,
50:06 um, outlook comes up in that little card, but you probably can just ask somebody what location they’re in, you may know. So in order to add somebody new, you can just insert a row. Didn’t write that person’s name,
50:22 um, peoples positions is?
50:26 As you can see, it’s not that it’s not really that helpful.
50:29 Um,
50:31 I’m just gonna write triage and early res officer. And if you come up with a better,
50:37 a better name for your role, you are more than welcome to come in here and update this so that it actually accurately reflects your role. So I know you’re in Brisbane and then we’d ask Tanya to come in
FOI 25/26-2150
here and put her mobile number in and then to find her Microsoft Teams number. So in order to do that,
um,
you open up Microsoft Teams and then you go to the calls function and there’s your work number there and you can just copy paste that.
And that means that somebody could call you directly from their mobile and it would come to your teams. So you might have to train people and how to find that number because that’s the only place where it exists.
So. Sorry. I was trying to find it yesterday and I thought I was pretty au fait with teams, but clearly I’m rusty. So you’re saying go to the call? OH, I’ve got it. It’s as easy as that. Thank you. Wonderful.
Thank you. Any questions about that?
No, if anything occurs to you can always ask me later. And then the last thing is probably the easiest thing is adding people to Microsoft Teams meeting and chats.
Um, and this is basically everyone in the team will know how to do this. So this is
really something that, um, we want people to do when people start so they’re not missing out on conversations or key meetings, but it’s pretty easy to just figure this one out intuitively. So in order to add somebody to a chat,
here’s a chat that I’ve got the personal PIA PC group, not a chat that any of you need to be in. But for arguments sake, if I wanted to add you in here, Tanya, you just hit the top right hand side here and it says view add participants and it can hit add people and you can just type somebody’s name
and you get to decide whether you want to include all chat history, no chat history or history from a certain number of days.
Um, in order to remove people from chats, um, let’s find a chat we can remove someone from
FOI 25/26-2150
is a chat. This is the camera team chat. So everyone who works in the chamber Canberra office comes here. Um, we can remove Aisha from this chat now, so we can go up to the top
and then we can find Aisha
and she’s whited out because she no longer works at the agency. We can just hit that cross button and she’s gonna remove the remove from that.
Um, so the key thing to remember when you first started trying, try and figure out all the chats you might need access to because you’re going to find there’s a whole team chat and there’s also individual teams chats and there might just be chats on the side for specific roles. So always good to just question and make sure you’ve got all the right chats that you need. And then in terms of Microsoft Teams meetings,
so there’s two ways we can do this. So I’m on my calendar in Microsoft Team. So that’s my email and that’s my calendar.
Um, it’ll be for you. It’ll probably look like this. It’ll just have your personal calendar of all your meetings that you’re attending. If you come to the side here on the left, there’s, you’ll have access to the shared calendars. So there’s a shared calendar for FOI and a shared calendar for information dot access.
And this shows you all the meetings that have been booked into that shared calendar, meaning anyone in the team can access them. So as you can see, there are a lot of meetings in here and that’s to ensure that if we need to reschedule one because someone’s away, anyone has the capacity to do it. So this meeting, whole team Friday session, if I double click on this on the FOI calendar, and that’s the crucial thing. Make sure you clicking it on the shared calendar, not your own
personal calendar. And then we update the entire series.
That’s giving us a list of everyone who’s invited to the meeting so we can see Tanya, you’re there. Pugin, you’re there. In order to add a new person like Bo, I would just type in Bo’s name there. And now he’s invited to the meeting.
In order to remove somebody from this meeting, you just have to find their email address and then delete it. So I can see Aisha’s name is there, so I’m just pressing backspace on that. And now she’s no longer invited to the meeting.
FOI 25/26-2150
Um, and then we’ve sent send update
and this usually gives you an option to not send the update to literally every single person in the list. Sometimes it just says do you only wanna send the update to new or removed invitees. It didn’t give me the option that time, which annoyingly means that every single person in the team is now gonna get a new invite to that team meeting. So
give my apologies to them 3 three times in a row.
Sent it to everybody
just means everyone has to reaccept it, which is it’s going to annoy them anyway. Um, so that’s an easy way to add people to whole team meetings, other ones. For example, this morning we had an all staff huddle.
We don’t, we’re not the owners of that meeting,
but we can still open it up and you can see we’re not the owners of it because we don’t, we don’t see who the whole,
um, invite list is, but you could nonetheless forward it. So I’ve just hit forward on that
and then we can forward it to, let’s say we forwarded it to Bo,
then we can just say hi Bo
this meeting
the first day, something like that. So this works as like a temporary solution.
If somebody’s just starting, they need to attend the meeting, and we’ll worry about adding them properly to the invite list later. Yeah. And then you can at least be guaranteed that person has access to the meeting and can join and can participate. Yeah,
FOI 25/26-2150
so we won’t do that one now the same about removing people’s names. Um, so Aisha is still on this list. Um, we’re not responsible for, um,
updating these meetings that we don’t own. So in this case, um, Leanne redacted, who is our branch manager,
acting brand manager, um, her executive officer will have sent this. So that person is the owner of this.
Um, yeah. So that’s the two ways to add somebody to a meeting, either forwarding it or if you have the ownership of it on this shared calendar to just edit it.
Great. And that has the updates there. And that’s it. We’ve cracked on for an hour and we’ve shown you every single access that there is. Um, I’ve got one little slide here about troubleshooting access with just some, I guess words of wisdom.
The most common thing is that staff automatically assume they’ve lost access to something and they always ask you to resubmit it.
Nine times out of 10, they do have access, you just need to check it. And the problem is something else. And so I would say my, my main thing is if anyone comes to you with issues, always double check it. So yesterday I had some people coming to me saying they couldn’t access that file. I went in and checked it. So I’ll show you what I did.
One here in the SharePoint, any file at all, I can hit these three little buttons and hit manage access. And then that shows me who has access to this file, right? So I can see that Tanya, you have access to the file, right? So if you come to me and say I don’t have access to the file, I’m like, that doesn’t make sense. It’s telling me you have access. The second tab here is groups, and that tells me who has access to that file via group membership. So I can see everyone who’s a Freedom of Information member has access to that
file, which means everyone who’s got access to the SharePoint should have access to the file.
Um, yeah. So if you think that doesn’t make sense, you can also hit this, um, three dots again for more options and hit advanced settings.
FOI 25/26-2150
And then that brings you up this screen where you can do this check permissions button so I can type in any staff name
So if the person doesn’t have access, I’ll just show you somebody who does not.
Um, no, none. This person has none access to that file. So again, if this person can’t access the file, I know there’s something wrong and that I can give them access. So that’s my first step for troubleshooting. Second thing is another important tip. If the basic troubleshooting steps don’t resolve the problem, direct the staff member to actually lodge an ICT service desk ticket. Remember that you’re not tech support, OK? You’re here to set up accesses and fix routine, predictable problems.
If someone’s having major issues and they can’t access their computer, all their systems, it’s not your responsibility to fix that.
Staff members responsibility to lodge an IT service desk ticket and to call ICT and talk to them over the phone.
The only exception would be if you hear that multiple staff are experiencing the same issue over and over again. You might volunteer for the sake of efficiency to be the main contact and to lodge an ICC ticket and note that there are multiple people affected and that will then save everyone else’s time. But that’s something, if you’re planning on doing that, you need to talk about that with your team leader and Rachel’s going to make the call about whether the situation is that serious and whether you have capacity to do that.
And that there is the end of the slideshow.
Are there any questions out of that?
No, not for me. Thank you, Laura.
No, Laura. Thank you. OK, All good, Laura. Good. Are you able to share the recording, Laura?
FOI 25/26-2150
Absolutely. I will Jack the recording into SharePoint. I’ll send you all the link. I’ll reattach all the resources that you’ve got. And then yeah, I’ll liaise with Rachel and I’m happy to go ahead and add some more accesses for you, Pugin to CRM. And I will assign a lucky volunteer the task of updating the leave calendar and the contacts
1:02:02 text list.
1:02:03 And yeah, when new people start, there’s a few, um, in the pipeline. One of you wonderful people will be able to do this for real. Sorry. Thank you so much for coming. I’m always here if you’ve got any questions. And I’m going to stop the recording now,
1:02:22 Thanks.
CMFOI_ International Access to Information day (second session) 2024.10.01
CMFOI_ International Access to Information day (second session) 2024.10.01.mp4
0:04 Welcome to our online celebration to mark International access to Information Day.
0:10
For those who don’t know me, my name is Laura redacted and I am an Assistant Director in the Information Access team.
0:18 I would like to begin by acknowledging the traditional code custodians of the various lands on which we work today.
0:25 For me, that is the Nanawal and Nambri people.
0:28 I pay my respects to Elders past, present and emerging and recognise and celebrate the diversity of Aboriginal peoples and their ongoing cultures and connections to the lands and waters of our country.
0:41 And I would like to extend that respect to any Aboriginal and Torres Strait Islander people here with us today in the meeting.
0:48 So what is International access to Information Day anyway?
0:53 It’s an annual day created in 2015 by the United Nations Educational, Scientific and Cultural Organisation, which is also known as UNESCO.
1:06 It’s designed to celebrate and promote the important role that Freedom of Information laws or FOI laws play in our society.
1:16 Today.
1:17 Over 125 countries across the world have Freedom of Information laws.
FOI 25/26-2150
But Freedom of Information laws are an incredibly modern phenomena.
Virtually all FOI laws across the globe were introduced after World War 2 and most of them, in fact more than 2/3 of them, have only been introduced since the year 2000.
This means that Australia, without FOI legislation established in 1982, is actually one of the early adopters.
The purpose of my talk today is to try to explain the underlying purpose of Freedom of Information laws and put that in the context of why access to information more broadly is so important.
I’ve also found a few weird and interesting FOI requests from across the globe that highlights some of the stranger uses of FOI legislation.
Although some of these stories may be a little bit wacky, they all have an important message.
Sometimes inappropriately refusing access to information actually backfires.
So first of all, let me start by explaining the basic premise of FOI.
Freedom of Information laws enable any person in the world to request access to any document that the government holds.
You don’t need to be in Australia to request access, you don’t need to give your name, and you don’t need to give a reason.
The FOI Act is designed to be pro disclosure, meaning that it assumes that any document should be released unless there is a very good reason why releasing it would cause harm.
And the definition of a document is extremely broad.
It covers anything with marks on it, whether in physical or electronic form.
FOI 25/26-2150
This includes letters, emails, case notes and medical reports, but it also covers Microsoft Teams messages, hosted notes, scribble on a white board, and even the video recording of this very presentation.
FOI laws are designed to achieve several important goals.
The first purpose is to increase public participation in government processes.
As a democracy, we all get to vote on Election Day, so accessing government information helps us make better decisions.
In addition, access to information increases people’s ability to participate in smaller decisions that affect them personally, such as whether they need access to the NDIS, for example.
The next purpose is to increase scrutiny and review of government activities with the goal of preventing and exposing corruption.
The idea is that if all public servants know that everything we write down in the course of our work could be published, this will motivate us all to act with integrity at all times.
And the third purpose is to promote information as a public resource that is owned by the people.
This can mean more broadly that the work we do as an agency is designed to benefit the wider Australian community as a whole.
But it also means on a more micro level that anything we write about an NDIS participant becomes the personal information of that individual and they have a right to ask to see it.
Ultimately, information is a valuable and powerful resource.
Getting the right information at the right time can change someone’s life.
FOI 25/26-2150
Looking at all these purposes, it’s pretty apparent to me that formal FOI legislation isn’t the only way to achieve them.
The agency can increase public participation and be more transparent about our decision making by, for example, publishing more information on our website, like our operational guidelines or on our statistical data portal.
The agency can achieve these purposes by sending well written explanation of decision letters and explaining things over the phone in plain English to participants.
And we can share many written documents outside the FOI Act, like through our Participant Information Access Scheme, via the online Participant Portal and via the National Contact Centre.
This is why this year’s theme for International Access to Information Day is Mainstreaming Access to Information.
This theme means looking beyond formal FOI processes to think about other ways we can appropriately share information with individuals and the community to show the value of releasing information.
I found 7 examples of interesting FOI requests from three different countries across the world, the United States, the UK, and Australia.
These 7 examples are amusing FOI fails of one kind or another.
All of them are examples where refusing access to information resulted in worse outcomes than being transparent.
So let’s get into it.
My first example comes from the United States, and it shows how excessive use of redactions can sometimes backfire.
In this case, an FOI requester sort access to some of the Federal Bureau of Investigation’s records.
Page 322 of 331FOI 25/26-2150
7:03 The FBI 1 document contained a fictional scene set in the busy newsroom of the Daily Planet newspaper.
7:12 You may recognise the Daily Planet as being a humorous reference to The Newsroom that Superman works at in the fictional city of Metropolis.
7:21 It’s sure nice to know the FBI have a few comic book fans in its staff.
7:25 However, when processing this FOI, the FBI decided to redact the names of the fictional characters used in the scene under personal privacy grounds.
7:38 It’s pretty unusual to see this because we only use redactions of that sort to remove information that could cause harm or invade someone’s privacy if it was released.
7:49 And does a fictional character working in a fictional newsroom really need to have their name redacted to avoid their personal privacy being invaded?
7:57 After all, anyone with any comic book knowledge at all can guess that the that the redacted names are almost certainly Clarke Kent and Lois Lane.
8:06 So in the end, the redaction achieved pretty much nothing except drawing unwanted attention to the documents.
8:15 My next example is also from the United States and once again shows us how refusing information can increase public interest in a topic.
8:25 In this case, an FOI request was made to the American Federal Communications Commission or the FCC.
8:32 The requester sought access to emails showing the chairman’s response to a failed publicity stunt.
8:39 The FCC fought hard to prevent the release of one particular email, claiming it would have, and I quote, a chilling effect on the FCCS ability to perform its duties.
Page 323 of 331FOI 25/26-2150
8:51 The FOI requester insisted that the email should be released and asked for the FOI decision to be independently reviewed.
8:59 And after more than a year of debate, the email was finally released in full and it was revealed to say in its absolute entirety, OK. That’s it.
9:13 2 letters only.
9:14 OK.
9:16 The FCCS decision to redact this information brought unwanted attention, whereas if they had just released the email earlier, this case might have been forgotten.
9:26 This is a lesson in being accurate in our justifications.
9:30 When we refuse or redact information, it’s no good for us to rely on standard template wording that exaggerates the harm of release.
9:39 We always need to critically evaluate the situation and use common sense.
9:45 My third example is about the importance of checking what information is already publicly available for making the claim that a document is highly sensitive and must be protected, or that it doesn’t even exist.
9:58 In this case, also from the United States, a requester submitted an FOI to the Immigrations and Customs Enforcement organisation known as ICE, seeking memos related to President Donald Trump’s proposed Mexican border wall.
10:13 ICE kept this FOI request open for over 17 months in a mighty effort to do an exhaustive search to try and locate the requested documents.
10:24 Eventually, after almost a year and a half of searching, they declared that no such documents existed.
Page 324 of 331FOI 25/26-2150
Only it turned out they did exist and they had been posted on the organisation own public facing website the entire time.
This really underscores the importance of being familiar with the material that your own agency publishes.
For my next example, let’s jump over to the UK, where the Ministry of Defence found itself being bombarded with FOI requests about UFOs.
This led to a Chief Constable of the Welsh police force claiming that police officers had been literally taken off the beat to fulfil the mountain of FOI requests about extraterrestrials.
In response, the Ministry of Defence decided to proactively publish its full list of reported UFO sightings on its own website.
This totalled more than 9000 pages of previously highly confidential incidents, drawings, photographs, RAF investigations and government UFO policy documents.
This decision freed up the workforce to do other more meaningful tasks, and this example is a lesson in the benefits of proactive disclosure.
But not to be outdone, the Australian Department of Defence has also released multiple documents about UFOs.
My next next example is an FOI request released in February this year.
In this case, the department also found itself being repeatedly questioned about how it monitors UFOs.
However, unlike the UK and the US, with which now both proactively published reports on UFO sightings, Australia doesn’t track UFO sightings.
Apparently we stopped doing this in 1996.
FOI 25/26-2150
Therefore it wasn’t possible for the department to make all the records public because there just weren’t any.
So instead, the department released as many documents as they could that showed they had very little interest in the topic.
This is a case where being upfront about what is not happening can work to dispel speculation.
For my next example, we learn a lesson in how poor internal communication can impede transparency in this matter, which we’re back over to the US for.
Our requester emailed two different departments in the Pentagon to find out how many of a particular type of forensic device they had in their possession.
The First Department issued a practical refusal notice.
And for those of you in this meeting who are not FOI boffins, let me explain.
A practical refusal means that it’s going to be so time consuming to search for and process documents that it would be unreasonable for an agency to devote such an excessive amount of time to that FOI matter, so it gets refused outright.
This first department claimed that it didn’t keep structured data on this particular type of device, so the only way they could find out how many existed was to examine every single contract in the electronic document system 1 by 1, which they estimated would take quote 15,000,000 labour hours and cost around $660 million.
On the other hand, the second department called the guy responsible for issuing the devices.
He did a quick 10 minute search and promptly reported there were in fact only three.
Again, the lesson here is we’ve all got to use our vast corporate knowledge.
FOI 25/26-2150
Sometimes you just need to get a subject matter expert on the phone and you’ll get exactly what you’re looking for with minimal effort.
Lastly, let’s wrap up with what is undoubtedly the most famous Freedom of Information request in Australia’s history.
It involves a former Australian Prime Minister and a rather unflattering portrait.
In 1984, the artist Brian Westwood painted a portrait of former Australian Prime Minister Malcolm Fraser.
However, when Malcolm Fraser saw the portrait, he rejected it, apparently claiming it was too casual and domestic.
The portrait was placed in storage and hidden from public view and a second, more authoritative portrait was commissioned.
However, journalist Kerry Coyle from the Canberra Times newspaper requested the portrait itself under FOI laws in 1985.
The FOI Act was only a couple of years old at the time and the request was a real test of whether a painting could be considered a document in accordance with the definition of a document in the legislation.
As I mentioned earlier, the FOI Act defines a document very broadly as any written or printed material, whether in physical or electronic form.
Ultimately, the government agency responsible decided the painting was indeed a document and the journalist was given a viewing of the portrait at the back of a storage warehouse.
And why this is so interesting is that years later, the rejected portrait now hangs proudly in Old Parliament House, where absolutely, absolutely anyone can see it.
It’s also easily locatable on Google Images, and I can paste a copy of it into the chat right now so you can all have a look at it.
FOI 25/26-2150
This final example shows how the sensitive sensitivity of a document changes across time and in different context.
So what might be highly risky to release one day could be perfectly fine to share publicly soon after.
This reminds us all how important it is to consider each request for access to information on its own terms.
And that’s it, folks.
Thank you kindly for your attention.
I hope you found this all interesting and that I was able to give you a better understanding of FOI laws.
And I hope the examples I have shared have sparked a few interesting thoughts about how government agencies manage information and how we can all work together to do it a little bit better.
Thank you again and I’m happy to take any questions now.
Yep.
Hi, it’s Louise here.
I’ve got a question.
Hello.
What’s the difference between a PIA and an FOI?
I know that the PIA is document specifically to the participant.
— PAGE TEXT END –
FOI 25/26-2150
Is there anything that the participant would need that couldn’t be released under a PIA, but they’d have to put in an FOI instead?
That’s a really, really great question.
So the main difference is that an FOI you can request literally any document that the agency holds.
A PIA though, there’s an approved list of documents that we have carefully assessed as being firstly very common so that people want to see them, but also low risk.
And that’s because most PIA approved documents are things that the participant has already sent to us or things that we have already shared to the participant.
So there’s a lower risk of any harm eventuating from disclosure of that information.
And so the purpose of PIA, because it has a limited range of documents available and they’re lower risk, it means we can process requests a lot faster.
And we also have the capacity to do it at a lower level of delegation, which means we’re able to put more staff into that team to do it.
So that’s, I think the main difference.
There’s many things that aren’t available through PIA.
And if you would like to know the list of approved documents, you can go to the PIA webform that has an actual checklist of all the documents that are available.
And if somebody wants something that isn’t specifically mentioned on that list, it’s probably something we’d have to assess under FOI.
And that’s probably just because it means it’s something a little bit more free form, you know, not necessarily approved for release.
Page 329 of 331
FOI 25/26-2150
And we’d actually have to think about it on a case by case basis about whether any harm could eventuate from disclosing that document to that person in that circumstance.
And some of the very common things that we don’t release under PIA, but people really, really want things like interactions and cases and TAB notes and even copies of internal notes describing someone’s complaints.
All those kind of things aren’t standard documents.
And so we do sort of run our eyes over them and consider them on a case by case basis under FOI.
Whereas the commonly released things under PIA are things like access request form, access decision letters, NDIS plan letters, all those kind of things that are readily available and and sort of already kind of mostly known by an applicant.
Does that answer your question?
Yeah, it does, because in complaints we deal with people who want documents under FOI.
And yeah, what you’ve said makes sense.
I can understand why complainants get a little frustrated though, after having gone through the PIA and then having to go through the FOI as well.
Yeah, I think the key thing is information literacy to sort of explain to people that there’s these two different streams that we have and they do have different pros and cons.
And it could be really suitable to do a PIA upfront to get a few documents.
You get them faster, you don’t have to wait as long, it’s a lot easier.
But then if there is something you really want to dig into later, you may have to do a follow up request.
Page 330 of 331
FOI 25/26-2150
20:12 Yeah.
20:12 So there’s pros and cons to each way if we processed every single PIA matter we had.
20:18 Under the FOI legislation, we’d need a team of 200 people because the FOI requests have a lot more formal and legalistic aspects to them.
20:28 And as as a lot more thinking has to go into them to write these, you know, statement of reasons that reference the legislation in detail.
20:36 So it’s it’s more complicated.
20:39 Thank you.
20:41 Wonderful.
20:41 Does anyone else have any questions?
20:50 OK, well I’m going to stop the recording now.
20:52 Thank you so so much everyone for coming.
Page 331 of 331