Skip to content
Fishburners Logo
  • Memberships & Support
    • Fishburners Co Working Space Sydney CBD
    • Online Founders Hub
    • Fishburners Services Hub
    • Memberships & Pricing
    • Our Perks & Discounts
  • Opportunities
    • Partner with Fishburners
    • Promote Your Service
    • Our Perks & Discounts
    • Free Founders Bootcamp
    • What We Offer
  • Venue + Boardroom Hire
  • Subscribe to the Burner
  • What’s On
  • News & Updates
  • About Us
  • Contact Us
  • Support

    Supporting you
    through every stage

    Support

    • What We Offer
    • Online Founders Hub
    • Fishburners Co Working Space Sydney CBD
    • Memberships & Pricing
    • Fishburners Services Hub
    • What We Offer
    • Online Founders Hub
    • Fishburners Co Working Space Sydney CBD
    • Memberships & Pricing
    • Fishburners Services Hub

    Resources

    • Startup Fast Pass
    • The Ascent Project Empowering – Women Founders
    • Free Founders Bootcamp
    • Events What’s On
    • Our Perks & Discounts
    • Fishburners Success Stories
    • Startup Fast Pass
    • The Ascent Project Empowering – Women Founders
    • Free Founders Bootcamp
    • Events What’s On
    • Our Perks & Discounts
    • Fishburners Success Stories
  • Events

    Get Connected

    • Subscribe to the Burner
    • Latest Events
    • News & Updates
    • Subscribe to the Burner
    • Latest Events
    • News & Updates

    Host Your Next Event

    • Corporate Venue Hire
    • The Board Rooms
    • The Workshop Space
    • The Large Event Space
    • Corporate Venue Hire
    • The Board Rooms
    • The Workshop Space
    • The Large Event Space

    What's Happening in Fishburners

  • Opportunities

    Opportunities to grow with Fishburners

    Get Involved

    • Partner with Fishburners
    • Promote Your Service
    • Apply to Pitch
    • Contact Us
    • Partner with Fishburners
    • Promote Your Service
    • Apply to Pitch
    • Contact Us

    Programs

    • Startup Fast Pass
    • The Ascent Project Empowering – Women Founders
    • Free Founders Bootcamp
    • Events What’s On
    • Our Perks & Discounts
    • Fishburners Success Stories
    • Startup Fast Pass
    • The Ascent Project Empowering – Women Founders
    • Free Founders Bootcamp
    • Events What’s On
    • Our Perks & Discounts
    • Fishburners Success Stories
  • About Us
  • Login

Understanding the Employee Records Exemption with Aperion Law.

  • October 30, 2020
  • Tegan Harlow

Employee records in Australia

Under the Commonwealth Privacy Act, which regulates the collection of personal information for most private businesses, there is an exemption for employee records. This means that businesses otherwise subject to the Australian Privacy Principles (APPs) are not required to comply with those rules when handling information that is directly related to the employment of their employees.

The Exemption

For the exemption to apply, the handling of personal information must relate to:
– a current/former employment relationship between the business and the individual; or
– an employee record held by the business relating to the individual

Let’s take a look at an interesting case study where European retailer, H&M, was fined after compiling dossiers on its workers.

Fined A$57million (€35million) for illegally compiling detailed records on its employees in Germany, H&M had a range of practices that saw them developing records containing extensive details about the private lives of employees.

The practices H&M engaged in included ‘welcome back’ talks that involved managers having detailed discussions with employees after returning from vacation or sick leave. The welcome back talk elicited a high level of detail about vacation experiences and itineraries; and illness symptoms and diagnoses.
The records that H&M compiled also detailed knowledge of employee’s private lives including religious beliefs and family issues.

These records were available to a large number of managers, who used the information in decision making about the individual employees. These practices came to light in October 2019 when a misconfigured system resulted in the records being accessible company wide.

To its credit, H&M was proactive in responding to the breach, rapidly implementing company wide reforms concerning the processing of personal data of its employees. In addition to this, the company apologised and proposed a significant compensation package. The Hamburg Data Protection Commissioner observed that this was ‘an unprecedented acknowledgement of corporate responsibility following a data protection incident.’ Nonetheless, it still issued the second highest fine issued under the GDPR to date.

So there are two important points to note:

First – generally, if you are proposing to collect or hold information about an employee it needs to relate to the employment relationship. The Privacy act defines relevant information to include:
– Engagement, training, termination/resignation details,
– Terms and conditions of employment of the employee including hours, leave and remuneration,
– Personal and emergency contact details,
– Union or professional body membership,
– Performance conduct or discipline matters, and
– Tax, bank or superannuation details.

So this means if you are an employer, you should avoid collecting information about an employee’s:
– Personal life like who they’re friends with,
– Where they went on holidays,
– Information about their children or other relatives, or
– Health information (unless it impacts their capacity to do their job).

Accordingly, the behaviour engaged in by H&M would be outside of the employee record exemption, and so they would’ve needed to comply with the APPs if they were in Australia.

In other words, if your business does want to hold this kind of information, you will need to do so in accordance with the APPs. This means you need to comply with the general rules regulating collection, use, disclosure and access of personal information. In most situations you will need free and informed consent, and to allow your employees to access or correct the information.

Moreover, it is important to keep in mind that the employee record exemption only applies once the information is included in the record in question. Up to that point, the collection of the information is governed by the APPs. This means you will need to use lawful and fair means to collect the information, and be transparent in your handling of it.

Similarly, this exemption doesn’t cover job applicants. If someone applies to work for you and doesn’t end up getting a job, if you want to keep their information you need to comply with the APPs.

Second, any use or disclosure of information in an employee record needs to be directly related to the person’s employment. So what does that mean?

A clear example of this can be seen in the case of B v Cleaning Company. In this case, the complaint had defaulted on a debt. The organisation to which she owed the money approached her former employer, who disclosed personal information from her employment record including her address and financial details. Unsurprisingly, The Privacy Commissioner found that this disclosure was not directly related to the employment relationship.

A slightly less obvious example is C v Commonwealth Agency. In this case, a husband and wife both worked for the same company. In the course of a workplace compensation claim, the wife submitted that she could not afford certain medical expenses. To rebut this claim, the company gave their lawyers information concerning the husband’s salary. The Privacy Commissioner found that this disclosure was not directly related to the employment relationship between the husband and the company. (Note that the disclosure was ultimately lawful because it was done for the purposes of seeking legal advice.)

Lastly, making a disclosure that is not directly related to the employment relationship can be expensive. Earlier this year, in ‘QF’ & Others and Spotless Group Limited the Privacy Commissioner awarded $60 000 in compensation where a company disclosed information in employee records to a union without consent of the employees.

This post was summarised from Aperion Law’s Blog Post. Be sure to check their website out for more posts just like this one!

Previous
Next

Related Posts

Majella Campbell Martin Karafilis Fishburners

Fishburners Announces CEO Transition as It Embarks on a New Era of Growth

Majella Campbell takes over the reins as CEO, succeeding Martin Karafilis Sydney, February 2025 – Fishburners, Australia’s largest startup community,

Read More

Overcoming Early-Stage Anxiety: How Two Founders Went From Idea to MVP Fast

Tech startups don’t always begin with a team of developers and a big bank account. Sometimes, all it takes is a clear vision, a hunger to learn, and the right community to propel you forward.

Read More

Join the Burner 🔥 to stay updated

Subscribe to the Burner
Facebook-f Linkedin Instagram
Quick Links
  • Startup Blog & News
  • Perks & Discounts
  • Add Additional Team Members
  • Success Stories
  • Contact Us
Join Us
  • Sydney Hub
  • Service Hub
  • Founders Hub
  • Promote Your Service
  • Venue Hire Sydney
  • Board Room Hire
  • Sydney Hub
  • Service Hub
  • Founders Hub
  • Promote Your Service
  • Venue Hire Sydney
  • Board Room Hire
Get In Touch

Level 2,  11-17 York Street, 
Wynyard NSW 2000

  • Email: [email protected]
  • Phone: 1800 959 351
  • Hours: Mon-Fri 8:30AM - 5:00PM
  • Terms
  • Founders Hub Terms
  • Privacy Policy
  • WHS Policy
  • Whistle Blower Policy
  • Fishburners Complaints Policy
  • Code of Conduct
  • © 2025 All Rights Reserved.