THE OFFICE OF THE PRIVACY COMMISSIONER
Spacer GifHOME > Federal Privacy Law > 2008 - Complaint Case Note 23 Spacer Gif Spacer Gif Spacer Gif Spacer Gif
Spacer Gif
Spacer Gif
Spacer Gif Bullet Privacy Act
Spacer Gif Bullet Privacy Act Regulations
Spacer Gif Bullet Public Interest Determinations
Spacer Gif Bullet Guidelines
Spacer Gif Bullet Complaint Case Notes & Determinations
Spacer Gif Bullet Audits
Spacer Gif Bullet Information Privacy Principles
Spacer Gif Bullet National Privacy Principles
Spacer Gif Bullet Private Sector Codes and Opt-in Registers
Spacer Gif Bullet Credit Reporting
Spacer Gif Bullet Health
Spacer Gif Bullet Telecommunications
Spacer Gif Bullet Tax File Numbers
Spacer Gif Bullet Spent Convictions
Spacer Gif Bullet Data-matching
Spacer Gif Bullet Privacy Advisory Committee
Spacer Gif Bullet Private Sector Review 2005
Spacer Gif Bullet ALRC Privacy Inquiry 2006 - 08
Spacer Gif Bullet Privacy Law History
Spacer Gif SPECIFIC PRIVACY
INFORMATION FOR:
Spacer Gif > Individuals
Spacer Gif > Business
Spacer Gif > Health
Spacer Gif > Government
Horizontal Rule
Spacer Gif > Federal Privacy Law
Spacer Gif > About the Office
Spacer Gif > Frequently Asked Questions
Spacer Gif > IT and Internet Issues
Spacer Gif > Media and Speeches
Spacer Gif > Publications
Spacer Gif > Privacy Links
Spacer Gif > International
Spacer Gif > Contact us

Spacer Gif

2008 - Complaint Case Note 23

View printable version of this page

Case Citation:

Own Motion Investigation v Direct Marketer [2008] PrivCmrA 23

Subject Heading:

Improper disclosure of personal information and failure to keep personal information secure

Law:

National Privacy Principles 2.1 and 4.1 in Schedule 3 of the Privacy Act 1988 (Cth)

Facts:

An individual notified the Privacy Commissioner that the direct marketer sent out a promotional email which displayed the email addresses of all recipients.  The Commissioner considered that where an email address amounted to 'personal information' in that the identity of the individual is apparent or can reasonably be ascertained, the privacy of a number of individuals may have been interfered with. While this Office did not receive any individual complaints, the Commissioner decided to conduct an investigation into the incident under section 40(2) of the Privacy Act.

Issues:

NPP 2.1 provides that personal information collected for a primary purpose must not be used or disclosed for a secondary purpose unless one of a number of exceptions in NPP 2.1(a)-(h) applies.

NPP 4.1 provides that an organisation must take reasonable steps to protect the personal information it holds from misuse and loss and from unauthorised access, modification or disclosure.

Outcome:

The direct marketer responded promptly to the Commissioner's investigation and the incident.  The direct marketer explained that individuals provide it with their email address specifically to receive information about upcoming promotions.  The direct marketer provided its promotional email list to a third party organisation to issue the promotional email.  As a result of human error, the third party organisation distributed to everyone who was on the email list an email showing those individuals' email addresses, rather than using the blind carbon copy or 'BCC' email function.   The third party organisation did not follow its usual data quality control procedures in this circumstance.

The third party organisation counselled the individual responsible for the error and staff undertook refresher training in its quality control procedures.  These procedures were also updated to prevent a similar incident in the future. 

The direct marketer acted quickly to contact all individuals who were on the promotional email list to apologise and explain what happened.  The direct marketer also committed to report to appropriate authorities any misuse of the email addresses including issuing spam emails.

Based on the information gathered during the investigation the Commissioner decided to cease her investigation into the incident.  In relation to NPP 4.1, the Commissioner noted that the parties had steps in place to ensure the security of the personal information and the incident appeared to have occurred as a result of a one-off error. In relation to the disclosure under NPP 2, the Commissioner also considered that the steps the parties were taking to remedy the situation were adequate in the circumstances.

The Commissioner noted that while her investigation had been closed, any complaints from individuals that she may receive about the incident will be dealt with on their merits.

OFFICE OF THE PRIVACY COMMISSIONER

November 2008

Spacer Gif> Privacy Policy Spacer Gif> Copyright Spacer Gif> Site map Spacer Gif> Join Email List Spacer Gif> Glossary Spacer Gif> Calendar Spacer Gif> Newsletter