Australia
Employee Records and Privacy in Australia: What the Exemption Covers
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 9 primary sources cited on this page. How we verify our legal content

Australia's Privacy Act contains a broad employee records exemption that removes most of a private-sector employer's handling of an employee record it already holds from the Australian Privacy Principles. It does not cover the employer's collection of new information from a current employee, and it does not cover job applicants, contractors handling another organisation's records, or volunteers.
This article addresses the private-sector employee records exemption at section 7B(3) of the Privacy Act 1988 (Cth), current as at 10 September 2026 against authorised compilation No. 104 of the Act. It does not address state or territory public-sector employment privacy regimes, which are separate, or the law governing workplace surveillance devices such as CCTV, computer monitoring or vehicle tracking, which is regulated by Commonwealth, state and territory legislation and covered in recordinglaw.com's guide to workplace surveillance and monitoring in Australia.
What the Employee Records Exemption Covers
Section 7B(3) of the Privacy Act 1988 (Cth) exempts an act done, or practice engaged in, by an organisation that is or was an employer of an individual, where that act or practice is directly related to a current or former employment relationship between the employer and the individual, and to an employee record held by the organisation relating to the individual. In practice, this removes most of a private-sector employer's day-to-day handling of an existing or former staff member's personnel file, including that it does not have to grant an employee access to that file under the Privacy Act. The exemption exists alongside the broader Privacy Act framework, so it applies only to the extent the handling actually relates to the employment relationship and to a genuine employee record; conduct outside that scope is not automatically covered.
Collecting New Information From an Employee Is Not Exempt
The exemption is limited by its own words to an employee record "held by" the organisation. A record the employer has not created yet is not a record it holds, so the act of collecting new information from a current employee sits outside the exemption.
The Full Bench of the Fair Work Commission decided the point in Lee v Superior Wood Pty Ltd [2019] FWCFB 2946, a case about an employer that required staff to enrol their fingerprints in an attendance scanner. The Full Bench held at [56] that the exemption "applies to records obtained and held by an organisation" and "does not apply to a thing that does not exist or to the creation of future records".
It set out the consequence at [57]: "The significance of that finding is that the Australian Privacy Principles applied to Superior Wood in connection with the solicitation and collection of sensitive information from employees, up to the point of collection. Once collected, the employee records exemption was enlivened and the Privacy Act no longer regulated its use or disclosure."
For a current employee this is the most consequential limit on the exemption. Up to the point of collection, the employer must have a privacy policy under APP 1 and give a collection notice under APP 5. Under APP 3.3 it must not collect sensitive information without the individual's consent, and sensitive information includes biometric information that is to be used for automated biometric verification or biometric identification.
In Lee, the Full Bench held at [58] that the direction to submit to fingerprint collection without consent was not a lawful direction, that any consent given once the employee was told he faced dismissal would have been vitiated by the threat, and that his refusal was not a valid reason for dismissal.
Once the information has been collected and sits in an employee record the employer holds, the exemption applies again to the use and disclosure of that record.
What Counts as an "Employee Record"
An employee record is defined under section 6(1) of the Privacy Act 1988 (Cth) as a record of personal information relating to the employment of the employee. The OAIC's guidance lists examples including health information about an employee, and personal information relating to engagement, training, disciplining, resignation or termination of employment, terms and conditions of employment, personal and emergency contact details, performance or conduct, hours of employment, salary or wages, membership of a professional or trade association or a trade union, recreation, long service, sick, maternity, paternity or other leave, and taxation, banking or superannuation affairs.
Not Everything an Employer Holds Is Automatically an Employee Record
An employer cannot assume that everything it holds relating to an employee counts as an employee record. The OAIC's own example is instructive: an employee's bank details may form part of their employee record, but emails an employee receives from their financial institution through a work email account may not, since they may not relate to the employment of the employee at all. Whether particular content sent or received by an employee forms part of their employee record depends on the circumstances. This distinction matters in practice because information an employer holds that falls outside the employee record, for example a record of workplace monitoring not directly related to the employment relationship, can remain subject to the Australian Privacy Principles even though the general employee records exemption exists.

First Check Whether the Employer Is Covered by the Privacy Act at All
Falling outside the employee records exemption does not automatically mean the Australian Privacy Principles apply. The Privacy Act binds organisations, and section 6C(1) excludes a small business operator from that definition. Under section 6D(1), a business is a small business if its annual turnover for the previous financial year was AUD 3,000,000 or less.
Most Australian businesses sit under that threshold. So a job applicant, volunteer or contractor dealing with a small employer often has no Privacy Act access right and no OAIC complaint path at all, whether or not the employee records exemption applies.
Section 6D(4) lists the exceptions that keep a small business inside the Act. They include a business that provides a health service and holds any health information other than in an employee record, a business that discloses personal information about someone for a benefit, service or advantage, a business that provides a benefit, service or advantage to collect personal information, a contracted service provider under a Commonwealth contract, and a credit reporting body. Under section 6EA a small business operator can also choose to be treated as an organisation.
The order of questions is therefore: is this employer covered by the Privacy Act at all, and only then, does the employee records exemption apply?
Job Applicants and Unsuccessful Candidates Are Not Covered
The exemption applies only to a current or former employment relationship; it does not extend to a future or prospective one. This means the exemption does not cover the collection of personal information about job applicants who are not subsequently employed, including unsuccessful candidates. If you applied for a private-sector job and were not successful, you may be able to access information the organisation holds about you under the Australian Privacy Principles, including a referee's report, subject to limited exceptions such as where access would breach a confidentiality obligation. Once an employment relationship does form, records the employer holds relating to that person's earlier pre-employment checks become part of the employee record and fall within the exemption from that point.
Contractors Handling Someone Else's Employee Records Are Not Covered
The exemption is written to cover an organisation that is or was the employer, not a third party handling employee information on that employer's behalf. It does not cover contractors and subcontractors who handle another organisation's employee records, regardless of the contractual arrangements in place. This means the exemption is unlikely to apply to organisations providing recruitment, human resources management, or medical, training or superannuation services under contract to an employer, and it does not cover workers compensation insurers that are not themselves the employer of the individual concerned. A contractor or subcontractor that collects employee records from an employer must comply with the Australian Privacy Principles in handling that information, including the notice requirements at APP 5.
A different question is often confused with this one. If you are engaged as an independent contractor rather than an employee, your own personal information is not an employee record, because section 6(1) defines that term by reference to the employment of an employee, and the business engaging you is not your employer for section 7B(3). The exemption does not apply to your information at all, subject to whether that business is covered by the Privacy Act in the first place.
Volunteers Are Not Covered
The exemption does not extend to an organisation's handling of a volunteer's personal information, because an organisation and a volunteer are not considered to have an employment relationship for the purposes of the exemption in section 7B(3). An organisation working with volunteers needs to consider its obligations under the Australian Privacy Principles in the ordinary way for that information.

Public Sector Employees, and How a Private-Sector Worker Gets Their Record
The exemption is a private-sector concept. The Privacy Act 1988 (Cth) covers Australian Government and Norfolk Island administration employee records in full, meaning the Australian Privacy Principles apply to the handling of personal information in current and past employee records for those employees, including a right to access the personal information in your own record. If you are, or were, employed in the private sector, you generally cannot rely on the Privacy Act itself to access your employee record. Workplace law gives you a separate right, and it runs against your employer rather than a regulator.
Regulation 3.42(1) of the Fair Work Regulations 2009 requires a national system employer (which covers nearly all private-sector employers, other than unincorporated businesses in Western Australia) to make a copy of an employee record available for inspection and copying on request by the employee or former employee the record relates to. Regulation 3.42(2) requires the copy to be in a legible form.
The deadlines are in regulation 3.42(3). If the record is kept at the premises where you work or worked, the employer must make the copy available there within 3 business days after receiving the request, or post a copy to you within 14 days. If the record is kept elsewhere, regulation 3.42(4) requires the employer to do so as soon as practicable. Regulation 3.43(1) requires the employer to tell you, on request, where your records are kept.
Each of those subregulations is a civil remedy provision to which Part 4-1 of the Fair Work Act 2009 (Cth) applies, with a maximum of 20 penalty units, and an employee or a Fair Work inspector can apply to a court over a contravention. So the Fair Work Ombudsman is who you complain to if your employer refuses, not the body that holds or supplies the records. Make the request to the employer in writing so the clock is documented.
| Category | Covered by the s 7B(3) exemption? |
|---|---|
| Current employee's genuine employee record the employer already holds | Yes |
| Former employee's genuine employee record the employer already holds | Yes |
| Collection of new information from a current employee, such as a fingerprint or face scan | No (the Australian Privacy Principles apply up to the point of collection) |
| Prospective employee or unsuccessful job applicant | No |
| Contractor or subcontractor handling another employer's employee records | No |
| Your own information where you are engaged as an independent contractor, not an employee | No |
| Volunteer | No |
| Australian Government or Norfolk Island administration employee record | No (fully covered by the Australian Privacy Principles instead) |
| Employer information about an employee that is not part of their employee record | No |
Every No in this table means the employee records exemption does not apply. Whether the Australian Privacy Principles then apply is a separate question that depends on whether the business is covered by the Privacy Act at all, which is where the small business turnover threshold above matters.
Workplace Surveillance Sits Outside the Privacy Act Framework
The employee records exemption is about the Privacy Act 1988 (Cth), not about whether an employer can lawfully record or monitor you at work. The OAIC's own guidance states that the Privacy Act does not specifically cover surveillance in the workplace; instead, an employer who conducts surveillance or monitors staff must follow any relevant Australian, state or territory law, which the OAIC notes includes laws applying to the monitoring and recording of telephone conversations. In practice that means the state or territory surveillance or listening devices Act, a dedicated workplace surveillance statute in some jurisdictions, and Commonwealth law on intercepting telephone calls and accessing stored communications. That state or territory framework applies regardless of whether the resulting record would otherwise be exempt as an employee record under the Privacy Act. The OAIC also notes that if an employer keeps a record of workplace monitoring, such as CCTV footage or computer logs, that does not directly relate to the employment relationship, the Australian Privacy Principles may still apply to that record even though the general employment relationship is otherwise exempt. Recordinglaw.com's guide to workplace surveillance and monitoring in Australia covers the state-by-state surveillance rules that actually govern whether monitoring can occur and what notice it requires.
Complaining About the Handling of Your Employee Record
If your situation falls within the exemption, for example a private-sector employer's handling of your own genuine employee record, the Privacy Act's complaint process generally does not apply, since the Australian Privacy Principles do not govern that conduct. Where your situation falls outside the exemption, such as a contractor mishandling your records or an unsuccessful job application, you can use the ordinary Privacy Act complaint path; see recordinglaw.com's guide to making a privacy complaint in Australia, part of the wider Australia data privacy laws hub, which also covers the Australian Privacy Principles that apply outside the exemption.
One avenue sits inside the Privacy Act and is not affected by the exemption. Since 10 June 2025, Schedule 2 of the Privacy Act has provided a statutory tort for serious invasions of privacy, by intruding on a person's seclusion or by misusing information that relates to them. The person must have had a reasonable expectation of privacy, the invasion must have been intentional or reckless and serious, and the public interest in privacy must outweigh any countervailing public interest.
The employee records exemption does not carry into it. Section 94A(3) provides that in determining the meaning of a provision of the Act other than Schedule 2, Schedule 2 is to be disregarded, and the Schedule states that it is intended to be read and construed separately from the rest of the Act. The exemptions in Part 3 of Schedule 2 are a closed list: journalists and those assisting them, agencies and State and Territory authorities, staff members of those bodies, law enforcement bodies, intelligence agencies, and people under 18. There is no employer or employee records exemption among them.
It is a court claim rather than an OAIC complaint, and the clock is short. Under clause 14 of Schedule 2, proceedings must generally begin by the earlier of one year after the person became aware of the invasion and three years after it occurred, although a court may extend that in limited circumstances. Recordinglaw.com's guide to the statutory tort for serious invasions of privacy covers the elements, defences and remedies.
Other legal frameworks, such as workplace law, discrimination law or work health and safety law, may also be relevant to an employment dispute involving personal information, but they are outside the scope of the Privacy Act and this article.

The Exemption's Future: Proposed Reform, Not Current Law
Reforming or narrowing the employee records exemption has been identified as a candidate for a second tranche of Privacy Act reform, alongside other proposals such as removing the small business operator exemption.
That second tranche is now public. On 31 August 2026 the Attorney-General's Department released the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 together with a consultation paper, and submissions close on 18 September 2026. The package runs to roughly 40 proposals, including a single fair and reasonable test for the collection, use and disclosure of personal information, updated core definitions, and an erasure right against large digital platforms.
It does not touch the employee records exemption. The word employee does not appear anywhere in the exposure draft Bill, and neither the Bill nor the consultation paper proposes repealing or narrowing the employee records exemption.
So the position is unchanged: removal of the exemption remains an unlegislated Privacy Act Review proposal, and section 7B(3) is in force in the current authorised compilation of the Privacy Act (Compilation No. 104, compilation date 4 June 2026). Treat any description of the exemption's removal as a proposal under discussion, not as current law, until a Bill actually passes and commences.
This article provides general legal information about the private-sector employee records exemption under the Privacy Act 1988 (Cth), current as at 10 September 2026. It is not legal advice and does not account for your individual circumstances. For advice about a specific employment or privacy dispute, consult a legal practitioner admitted in the relevant Australian state or territory.
Frequently Asked Questions
Can my employer access my personnel file without my consent?
For a genuine employee record your employer already holds and that relates to your current or former employment, the Australian Privacy Principles generally don't apply because of the section 7B(3) exemption, so the usual Privacy Act consent and access rules don't govern that record. Collection is different. The exemption only covers a record 'held by' the employer, so the Australian Privacy Principles apply up to the point of collection, and under APP 3.3 your employer needs your consent to collect sensitive information such as fingerprint or facial recognition data (Lee v Superior Wood Pty Ltd [2019] FWCFB 2946).
Does the employee records exemption cover job applicants?
No. The exemption applies only to a current or former employment relationship, not a prospective one, so it doesn't cover information collected about unsuccessful job applicants, who may be able to access that information under the Australian Privacy Principles. Check the employer's size first. Under sections 6C and 6D, a business with an annual turnover of AUD 3,000,000 or less is generally a small business operator that sits outside the Privacy Act, so an applicant to a small employer usually has no Privacy Act access right at all.
Does the exemption cover a recruitment agency or payroll provider?
No. The exemption applies to the employer, not to a contractor or subcontractor handling another organisation's employee records, so recruitment, payroll, HR or similar service providers must comply with the Australian Privacy Principles when handling that information.
Are volunteers covered by the employee records exemption?
No. An organisation and a volunteer are not considered to have an employment relationship for the purposes of section 7B(3), so a volunteer's personal information is not exempt on this basis.
Can I access my own employee record under the Privacy Act if I work in the private sector?
Generally no, because the exemption means the Australian Privacy Principles' access rights don't apply to a genuine private-sector employee record. Workplace law gives you a separate right instead: regulation 3.42 of the Fair Work Regulations 2009 requires your employer or former employer to make a legible copy of your employee record available for inspection and copying on request, within 3 business days if it is kept at your workplace, or posted to you within 14 days. Ask the employer in writing. The Fair Work Ombudsman is who you complain to if the employer refuses.
Does the employee records exemption cover workplace CCTV or computer monitoring?
Not by itself. Workplace surveillance is governed by Commonwealth, state and territory law rather than the Privacy Act: state and territory surveillance or listening devices Acts, a dedicated workplace surveillance statute in some jurisdictions, and Commonwealth law on intercepting telephone calls and accessing stored communications. Separately, if an employer keeps a monitoring record that isn't actually part of the employee's employee record, the Australian Privacy Principles may still apply to that record.
Is the employee records exemption being removed?
Removal has been proposed as part of a second tranche of Privacy Act reform, but it is not in the draft. The Attorney-General's Department released the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 on 31 August 2026, with submissions closing 18 September 2026, and that draft does not repeal or narrow the employee records exemption. No Bill touching the exemption has passed, and section 7B(3) remains in force.
Do government employees have the same employee records exemption?
No. The exemption is a private-sector concept. Australian Government and Norfolk Island administration employee records are fully covered by the Australian Privacy Principles, including access rights.
Updates
Corrected the page to explain that the employee records exemption only covers a record the employer already holds, so an employer still needs consent under APP 3.3 before collecting sensitive information such as fingerprints from a current employee (Lee v Superior Wood Pty Ltd [2019] FWCFB 2946); replaced the advice to contact the Fair Work Ombudsman with the enforceable right under regulation 3.42 of the Fair Work Regulations 2009 to inspect and copy your own record within 3 business days, or 14 days by post; added the small business turnover threshold that leaves most employers outside the Privacy Act; added the Schedule 2 statutory tort in force since 10 June 2025; and updated the reform section for the 31 August 2026 exposure draft, which does not touch the exemption.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Privacy Act 1988
s 7BExempt acts and exempt practices of organisationsIn forcecited in 5 of our articles
Individuals in non‑business capacity (1) An act done, or practice engaged in, by an organisation that is an individual is exempt for the purposes of paragraph 7(1)(ee) if the act is done, or the practice is engaged in, other than in the course of a business carried on by the individual. Note: See also section 16 which provides that the Australian Privacy Principles do not apply for the purposes of, or in connection with, an individual’s personal, family or household affairs. Organisation acting under Commonwealth contract (2) An act done, or practice engaged in, by an organisation is exempt for the purposes of paragraph 7(1)(ee) if: (a) the organisation is a contracted service provider for a Commonwealth contract (whether or not the organisation is a party to the contract); and (b) the organisation would be a small business operator if it were not a contracted service provider for a Commonwealth contract; and (c) the act is done, or the practice is engaged in, otherwise than for the purposes of meeting (directly or indirectly) an obligation under a Commonwealth contract for which the organisation is the contracted service provider.
Official text (excerpt) · last checked 2026-08-14 · Read the full text in our law library · Verify at legislation.gov.au
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2023
Opinions citing this section in our collection:
- Madzikanda v Australian Information Commissioner (Federal Court of Australia 2023, [2023] FCA 1445)
- Matthews v Clifton (Federal Court of Australia 2014, [2014] FCA 415)
- Rivera v Australian Broadcasting Corporation (Federal Court of Australia 2005, [2005] FCA 661)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Workplace Recording and Surveillance in New South Wales, Workplace Recording and Surveillance in Queensland, Workplace Surveillance and Monitoring in Australia
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- OAIC, Employee records exemption(oaic.gov.au).gov
- OAIC, Employment (your privacy rights)(oaic.gov.au).gov
- OAIC, Workplace monitoring and surveillance(oaic.gov.au).gov
- Privacy Act 1988 (Cth) ss 6(1), 6C, 6D, 7B(3), 94A and Schedule 2, current authorised compilation (Compilation No. 104, compilation date 4 June 2026)(legislation.gov.au).gov
- OAIC, Complain to an organisation or agency about a breach of privacy(oaic.gov.au).gov
- Lee v Superior Wood Pty Ltd [2019] FWCFB 2946 (Fair Work Commission Full Bench) at [56]-[58](fwc.gov.au).gov
- Fair Work Regulations 2009 (Cth) regs 3.42-3.43, inspection and copying of an employee record (Compilation No. 56, 20 June 2026)(legislation.gov.au).gov
- Attorney-General's Department, Privacy Reform: Consultation on Exposure Draft legislation (opened 31 August 2026, closes 18 September 2026)(consultations.ag.gov.au).gov
- OAIC, Statutory tort for serious invasions of privacy(oaic.gov.au).gov