The Privacy Act 1988: What It Is & Why It Matters
The Privacy Act 1988 is Australia's principal federal law governing how organisations collect, use, store, disclose and correct personal information.
In this explainer
- Explain what the Privacy Act 1988 is in plain language
- Outline the kinds of obligations it sets at a general level
- Describe how its coverage depends on an organisation's size and activity
- Show why it matters for a vendor handling debtor personal information
- Point readers to the OAIC and independent advice for current detail
6 min read
What it is
The Privacy Act 1988 is the principal piece of Commonwealth legislation that sets the ground rules for how personal information about individuals is handled in Australia. It is designed to support the responsible and transparent handling of information, while balancing that against other interests such as the legitimate activities of business and government.
At its core, the Act treats privacy as something organisations are expected to manage actively rather than ignore. It establishes a framework of obligations, gives individuals certain rights in relation to information about them, and provides for an independent regulator to oversee how the framework operates in practice.
Because privacy is a developing area of law, the Act has been amended over time and continues to be reviewed. Treat it as a living framework: the underlying expectations of fairness, openness and care stay constant, but the specific provisions and guidance can change, so current sources should always be checked.
Key requirements
The Act works largely through a set of standards commonly known as the Australian Privacy Principles, which apply across the information life cycle. In broad terms, the framework expects covered organisations to:
- Be open about how they handle personal information, typically through a clear privacy policy.
- Collect information fairly and for legitimate, identified purposes.
- Use and disclose information consistently with those purposes and individuals' reasonable expectations.
- Take reasonable steps to keep information accurate and secure.
- Allow individuals to seek access to, and correction of, information held about them.
How each expectation is met depends on the organisation's circumstances and the sensitivity of the information. The Act is principles-based and technology-neutral, so it sets outcomes rather than prescribing one fixed method.
Why it matters for debt recovery
Debt recovery inherently involves personal information about the people contacted, so privacy obligations are an everyday part of doing it lawfully and respectfully. A recovery provider that handles information carelessly creates risk not only for itself but for the client whose customers' information it processes.
For a prospective client's privacy and legal team, the question is whether a provider treats the Act as a genuine operating discipline. That means collecting only what is needed for the matter, using information for the recovery purpose, keeping it secure, and being able to respond properly when an individual exercises a right.
You can read more about how we approach privacy across our Trust Centre, including related explainers on the Australian Privacy Principles and the Notifiable Data Breaches scheme.
What to ask a provider
When assessing a vendor against the Act, useful questions include: Does the provider have a current, published privacy policy? Can it explain the purposes for which it collects and uses debtor information? How does it keep that information secure and accurate? And how does it handle access and correction requests from individuals?
It is also reasonable to ask how the provider stays current as the law evolves, who is accountable for privacy internally, and how privacy obligations flow down to any subcontractors. Clear, specific answers are a good sign; vague reassurance is not.
How Merion approaches it
Merion aligns its practices with the principles of the Privacy Act 1988 and treats responsible information handling as part of conducting recovery professionally. We aim to collect only what is reasonably needed for a matter, use it for legitimate recovery purposes, keep it reasonably secure, and respond appropriately when individuals seek access or correction.
This is general information only and not legal advice, and it does not assert any particular certification. For authoritative and current detail on the Act, the national regulator, the OAIC, publishes guidance, and independent legal advice may help in specific situations. You can also contact us with questions about our approach.
Key takeaways
- The Privacy Act 1988 is Australia's central federal privacy law
- It is principles-based, technology-neutral and applies across the information life cycle
- Coverage and detail depend on an organisation's size and activity
- For a recovery provider, it is an everyday operating discipline, not a formality
Frequently asked questions
Does the Privacy Act apply to every business?
Not necessarily. Coverage depends on factors such as size and activity, and there are exceptions, so the answer turns on both the law and the facts. Check the OAIC for current detail.
Is the Privacy Act the same as the Australian Privacy Principles?
They are closely related. The Australian Privacy Principles sit within the Act as the core standards for handling personal information, but the Act also contains other provisions.
Is this legal advice?
No. This is general information only. For advice about your situation, consult the OAIC or seek independent legal advice.
Security and compliance you can verify
Merion handles every account on the facts, within the rules, and with data protected by design. Ask us anything.