HR Data Protection and Privacy Policy
This policy sets out how a business handles employee personal information. In Australia, the Privacy Act 1988 governs this for businesses with over $3 million turnover, requiring compliance with Australian Privacy Principles.
A policy that sets out how your business collects, uses, stores, and discloses personal information about your employees and job applicants.
20 free credits on signup — no card needed
About this Document
What Is a HR Data Protection and Privacy Policy?
An HR Data Protection and Privacy Policy is a formal document that sets out how your business manages the personal information of its workers. In Australia, this document serves as a rulebook for handling everything from tax file numbers and bank details to medical records and performance reviews. It tells your employees what data you collect, why you need it, who can see it, and how you keep it safe.
For a long time, many Australian small business owners assumed they did not need to worry about privacy laws if they had a small turnover. While there are exemptions, relying on them without a clear policy is a risky strategy. This policy bridges the gap between legal compliance and good management. It ensures you meet your obligations under workplace laws while giving your staff confidence that their personal details are not being misused.
Whether you run a construction company, a cafe, or a consultancy, this policy is your internal control mechanism. It clarifies that employee records are kept for specific purposes, such as paying wages and ensuring safety, and are not to be shared or sold without a valid reason.
When to Use This Document
You should implement this policy as soon as you hire your first employee or contractor. Even if you are a sole trader with no staff yet, drafting this policy prepares you for expansion. It becomes critical the moment you collect a resume, ask for a Tax File Number (TFN), or set up a superannuation account.
There are specific situations where this document is essential. If you are transitioning to cloud-based payroll software like Xero or Employment Hero, you need a policy to explain how third-party vendors handle staff data. Similarly, if your business allows staff to use their own phones or laptops for work—a trend known as Bring Your Own Device (BYOD)—this policy protects you by setting rules for accessing and wiping business data from personal devices.
You should also review and update this policy if your business structure changes. For example, if your annual turnover crosses the $3 million threshold, your legal obligations under federal privacy laws change significantly. Additionally, if you operate in industries like childcare or security where you must collect criminal record checks or health information, this policy provides the necessary framework to handle that sensitive data legally.
Key Sections and Required Elements
A robust policy needs to cover the entire lifecycle of employee data. Based on Australian regulatory standards and workplace practices, your document should include the following specific sections.
Section 1: Collection of Information
This section defines exactly what data you gather and where it comes from. You must state that you collect data directly from the employee or candidate whenever possible. This includes basic details like name, address, and bank account, as well as "sensitive information."
Sensitive information includes health records, criminal records, and political opinions. Under anti-discrimination laws, you can generally only collect this if it is genuinely required for the role. For example, a tradie working at height might need to disclose a medical condition affecting their balance for safety reasons. Your policy must reference that this type of data is only collected with consent or when legally necessary.
Section 2: Use and Disclosure
This part of the policy restricts how you share the information. It should state clearly that employee data is used only for employment-related purposes. This includes processing payroll, managing leave, and meeting Work Health and Safety (WHS) duties.
Crucially, this section must include a clause prohibiting the sale of employee data. It should also outline when disclosure to external parties is allowed. You are legally permitted to disclose information to government bodies like the Australian Tax Office (ATO) or the Fair Work Ombudsman when required. You can also share information with external insurers or workers' compensation schemes, but only on a "need to know" basis.
Section 3: Data Storage and Security
Here you explain how you protect the information both physically and digitally. For tradespeople and businesses with on-site offices, this means locking away paper files in cabinets. For digital data, it means using password protection, encryption, and secure access protocols.
This section must reference the legal requirement to keep employee records for seven years. The Fair Work Act 2009 mandates this retention period. You need to explain that records will be securely destroyed or de-identified once this period expires, provided there are no pending legal actions.
Section 4: Employee Access and Correction
Employees have a right to know what is on their file. While the Privacy Act sets out rules for access, general industrial law implies a duty of mutual trust and confidence. Your policy should provide a clear procedure for employees to request access to their personnel file.
If an employee finds an error, such as a wrong address or an incorrect leave balance, they must have a way to request a correction. The policy should state that you will respond to these requests within a reasonable timeframe, usually 21 to 30 days. This transparency helps build trust and avoids disputes later on.
Section 5: Monitoring and Surveillance
Modern workplaces often involve monitoring, whether it is tracking company vehicles or monitoring email usage. This section must notify employees that company assets are subject to monitoring.
If you operate in New South Wales, you must be very careful here. The Workplace Surveillance Act 2005 (NSW) requires you to give employees 14 days' notice before starting camera surveillance. You must also explicitly prohibit surveillance in change rooms or toilets. Even outside NSW, it is best practice to follow these rules to avoid claims of intrusion.
Section 6: Policy Status and Disclaimer
Finally, the policy must include a disclaimer stating that it does not form part of the employment contract. This is a vital legal protection. It ensures you can update the policy as laws change or technology evolves without having to renegotiate every single employment contract.
How to Write a HR Data Protection and Privacy Policy (Step by Step)
Writing a policy does not have to be difficult. Follow these practical steps to create a document that works for your business and complies with Australian law.
Step 1: Audit Your Data
Before you write, you need to know what you have. Look at the data you currently hold. Do you have resumes on file? Do you keep medical certificates for sick leave? Do you have a spreadsheet of TFNs? List out all the types of information you collect and where you store it. If you use cloud software, check the vendor's privacy policy to see where they host the data.
Step 2: Determine Your Legal Position
Check your annual turnover. If it is less than $3 million, you may be exempt from the Privacy Act 1988 regarding employee records. However, do not let this lull you into a false sense of security. You are still bound by the Fair Work Act 2009 for record-keeping and WHS laws for health information. If your turnover is over $3 million, or if you are a health service provider, you must comply with the Australian Privacy Principles (APPs). This distinction will change how strict your policy needs to be.
Step 3: Draft the Core Clauses
Start drafting the sections listed above. Use plain English. Avoid legal jargon where possible. Be specific about your practices. For example, instead of saying "we protect data," say "we use password-protected software and locked cabinets to store data."
Step 4: Address BYOD and Remote Work
If your staff use their own devices, you need a specific clause. This should allow you to wipe business data from a personal device if an employee leaves or loses the phone, but it must protect their personal photos and messages. This is a common area of confusion in modern HR, so be explicit about the boundaries.
Step 5: Consult with Staff
It is good practice to share a draft with your employees or their representatives (if you have them). They may raise privacy concerns you had not considered, such as who in the office has access to their salary details. This consultation can help you refine the policy before it is finalised.
Step 6: Implement and Train
A policy is useless if it sits in a drawer. Once finalised, distribute the policy to all staff. You can use an Induction Policy to ensure new hires read and sign the document. For existing staff, hold a brief meeting or send an email explaining the changes. Make sure everyone knows who to contact—usually the HR manager or business owner—if they have privacy questions.
Common Mistakes to Avoid
Many Australian businesses make easily avoidable errors when creating these policies. Being aware of these pitfalls can save you from legal trouble and unhappy staff.
One major mistake is believing the "Employee Records Exemption" means you have no privacy obligations. Research shows that many small businesses mistakenly believe they have no duties regarding staff data because their turnover is under $3 million. This is incorrect. Even if the Privacy Act does not apply, the Fair Work Regulations require you to keep specific records for seven years. Failing to secure these records can lead to penalties.
Another common error is over-collecting data. Some employers ask for irrelevant information, such as political affiliation or detailed medical history not related to the job. Under anti-discrimination laws, collecting sensitive information without a genuine requirement can expose you to legal action. Only collect what you need to run your business and meet your legal obligations.
Ignoring state surveillance laws is also a frequent issue, particularly for businesses operating in NSW. Using covert cameras or GPS tracking without proper notice is illegal. Even in other states, failing to tell employees about monitoring can breach the duty of trust and confidence, leading to unfair dismissal claims.
Finally, many businesses forget to include the disclaimer that the policy is not part of the employment contract. If you fail to include this, you might find that you cannot change your privacy practices later because an employee claims it is a contractual right.
Legal Considerations (AU)
Navigating the legal landscape of HR data in Australia requires a solid understanding of several key pieces of legislation.
The Privacy Act 1988 and the Employee Records Exemption
The Privacy Act 1988 (Cth) regulates how organisations handle personal information. However, the "employee records exemption" means most private sector employers with a turnover of less than $3 million are exempt from the Act regarding employee records. This exemption covers records about current, past, and prospective employees.
Despite this exemption, best practice is to voluntarily comply with the Australian Privacy Principles (APPs). If you do this, state it in your policy. It builds trust and prepares your business for growth. Remember, this exemption does not apply to Tax File Number (TFN) information. TFN data is regulated by the Taxation Administration Act 1953 and carries specific handling requirements, such as not recording TFNs on quote sheets or invoices unnecessarily.
Fair Work Act 2009 and Record-Keeping
The Fair Work Act 2009 (Cth) and the Fair Work Regulations 2009 set the standard for what records you must keep. Employers are legally required to make and keep records for seven years. These must include terms of engagement, pay rates, hours of work, and leave entitlements.
If the Fair Work Ombudsman audits your business and you cannot produce these records, you can face significant fines. Your data protection policy must align with these record-keeping laws, ensuring that data is not deleted too early and is kept accurate.
Work Health and Safety (WHS) Laws
WHS laws in each state and territory, such as the Work Health and Safety Act 2011 (Cth), permit the collection and use of personal health information if it is necessary to ensure worker health and safety. This might include collecting information about a worker's allergies or physical limitations before they start a high-risk job.
Your policy should reference that health data will be treated with strict confidentiality and only shared with relevant people, like first aid officers or rehabilitation providers. WHS laws also support the monitoring of workers in certain situations, provided the monitoring is reasonable and proportionate to the risk.
Surveillance Laws
If you are in New South Wales, you must comply with the Workplace Surveillance Act 2005 (NSW). This law is strict. It bans surveillance in "private areas" like toilets and change rooms. It also requires 14 days' notice before you start surveillance or if you change the surveillance method.
While other states do not always have specific surveillance statutes, they rely on general privacy principles and common law. Regardless of your location, it is safest to adopt the NSW standard of notifying employees in writing about any camera, computer, or vehicle tracking.
Notifiable Data Breaches (NDB) Scheme
If your business has an annual turnover of more than $3 million, you are subject to the Privacy Act and the Notifiable Data Breaches (NDB) scheme. This means if you lose data or there is a breach that is likely to cause serious harm, you must notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals.
Your policy needs to outline the procedure for identifying and reporting a breach. Even if you are a small business exempt from the NDB scheme, having a breach response plan is smart business practice. It helps you manage the fallout if a laptop is stolen or a file is lost.
Frequently Asked Questions (preview)
Do I need a privacy policy if I only have two employees? Yes, you should still have a policy. While you may be exempt from the Privacy Act, you are still required by the Fair Work Act to keep accurate records for seven years. A policy helps you organise these records and manage them securely.
Can I look at my employee's emails? Generally, yes, if the emails are sent using a company system. However, your policy must state that company systems are monitored. You should only access emails for legitimate business reasons, not to snoop on personal matters. In NSW, you must notify employees of email surveillance in advance.
What should I do with employee files when someone leaves? You must keep the records for seven years after the employee leaves. After this period, you should securely destroy or de-identify the records. If you used a cloud platform, ensure you delete the account or archive the data securely.
Is a TFN different from other personal data? Yes. Tax File Numbers are highly sensitive. You must protect them under the Taxation Administration Act 1953. You generally cannot use a TFN as a unique identifier (like a customer number) and you must not collect it unless it is required for a tax-related purpose.
Key Facts
- Businesses with an annual turnover of more than $3 million must comply with the Privacy Act 1988.— Privacy Act 1988 (Cth)
- Australian Privacy Principles (APPs) regulate how you collect, use, and disclose personal information.— Privacy Act 1988 (Cth)
- You must take reasonable steps to destroy or de-identify personal information when you no longer need it.— Australian Privacy Principle 11
- Tax File Number information receives extra protection under the Tax File Number Guidelines.— Privacy Act 1988 (Cth) / ATO
- Eligible data breaches must be notified to the Office of the Australian Information Commissioner and affected individuals.— Notifiable Data Breaches (NDB) scheme
- Employers must keep employee records for seven years after employment ends.— Fair Work Regulations 2009
Sources
Required Sections
Collection of Personal Information
This section outlines what personal data the business collects from employees and how it is obtained.
[Business Name] collects personal information from individuals to manage employment relationships and meet legal obligations. We gather data directly from you through application forms, employment contracts, and payroll systems. This includes general information such as your name, contact details, and tax file number (TFN), which is handled according to the Taxation Administration Act 1953. We also collect work-related information like hours of work, leave entitlements, and salary records to comply with Fair Work regulations.
In specific circumstances, we collect sensitive information to fulfill our duties under Work Health and Safety laws. This may include medical or health information necessary to ensure your safety at work or to accommodate specific requirements. We only request criminal record or disability information if it is genuinely relevant to the inherent requirements of the position. If [Business Name] uses workplace surveillance, we will notify you in accordance with relevant state legislation.
Use and Disclosure
This section explains the reasons for using employee data and lists any third parties who may access it.
[Company Name] uses employee records to manage payroll, leave, and superannuation as required by the Fair Work Act 2009. We process this information to ensure accurate payment of wages and compliance with the Fair Work Regulations 2009. We may disclose your data to third parties necessary for our business operations, including [Payroll Software Provider], the Australian Taxation Office, and Workers Compensation insurers.
If we collect Tax File Numbers, we handle them according to the Taxation Administration Act 1953. To meet Work Health and Safety obligations, we may use [CCTV / vehicle tracking] to monitor workplace safety. This surveillance complies with relevant state laws, including the Workplace Surveillance Act 2005 (NSW) where applicable. We will not access your data for unrelated marketing purposes without your specific consent.
Data Security
This section describes the measures taken to keep personal information safe from unauthorised access or loss.
Data Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. This includes using secure cloud storage providers and restricting access to [HR SOFTWARE] to authorised personnel only. All passwords must meet complexity requirements and be changed regularly.
We protect Tax File Number (TFN) information in accordance with the Taxation Administration Act 1953. Paper records containing sensitive data are stored in locked cabinets when not in use. Electronic data is encrypted both in transit and at rest using [ENCRYPTION STANDARD].
If [COMPANY NAME] has an annual turnover of more than $3 million, we comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. We will assess any eligible data breaches and notify affected individuals and the Office of the Australian Information Commissioner as required by law.
Data Retention and Disposal
This section sets out how long the business keeps records and how they are destroyed when no longer needed.
The company retains all employee records for a minimum of seven years after the termination of employment, as mandated by the Fair Work Act 2009. This includes records relating to terms of engagement, pay slips, leave entitlements, and superannuation contributions.
Tax File Number (TFN) information is stored securely and destroyed separately within five years of ceasing the relationship, in accordance with the Taxation Administration Act 1953. We shred all physical documents containing personal information using industrial-grade cross-cut shredders. Digital records are permanently deleted from our systems using [DATA_DELETION_SOFTWARE] and removed from all [BACKUP_SERVERS] backups. Employees may request confirmation of disposal for their own records.
Employee Rights and Access
This section informs employees of their rights to view and correct their personal information.
Employees have the right to access the personal information [Company Name] holds about them. To request access, submit a written request to [HR Manager] detailing the specific records required. [Company Name] will provide access within a reasonable timeframe, subject to any legal restrictions.
If an employee believes their personal information is inaccurate, out of date, or incomplete, they may request a correction. Requests for correction must be made in writing to [HR Manager] and include supporting evidence where available. [Company Name] will respond to the request and take reasonable steps to correct the information if the request is valid.
Data Breach Response
This section details the steps the business will take if a data breach occurs.
If a data breach occurs involving employee records, the Privacy Officer will immediately contain the breach to prevent further unauthorised access. The business will assess the breach to determine if it is likely to result in serious harm. [Company Name] will notify the Office of the Australian Information Commissioner and all affected individuals without delay if the breach is eligible under the Notifiable Data Breaches scheme. All incidents will be recorded in the internal breach register. This record ensures we meet our obligations to make and keep accurate records for seven years under the Fair Work Act 2009.
Frequently Asked Questions
What is a HR Data Protection and Privacy Policy?
When do I need a HR Data Protection and Privacy Policy?
Is a HR Data Protection and Privacy Policy legally required in Australia?
What personal information can I collect from employees?
Can I share employee information with other people?
How long must I keep employee records?
What happens if there is a data breach?
Can an employee see their own HR file?
Explore More Business Documents
Ready to create your document?
Use our free template or generate a custom version tailored to your needs.
20 free credits on signup — no card needed
This document involves significant legal or financial considerations. Professional review is strongly recommended.
Last reviewed: July 30, 2026