5 Session 5 of 5 · The people in the post
Privacy in staff training: customers, colleagues and screenshots
A photo or screenshot that shows who someone is counts as personal information under the Privacy Act, and the Fair Work Ombudsman lists not revealing customers’ or colleagues’ details, images included, among the points to tell staff. business.gov.au’s version is shorter: “Never share anyone’s personal information on your public channels.”
General information about privacy, not legal advice. The OAIC is the official place to check; for workplace rules, the Fair Work Ombudsman.
When a picture is personal information
The OAIC says: “Photos and videos of you are treated as personal information under the Privacy Act 1988 if your identity is clear or could reasonably be worked out.” The Fair Work Ombudsman’s examples of personal information include names, addresses, phone numbers, email addresses and photos. A screenshot of a customer’s message can carry several of those at once.
- A face. A photo is personal information when the person can be identified.
- A name, on the profile or signed in the message.
- A phone number typed into a message.
- An email address, typed into a message or shown on a profile.
Who the Privacy Act reaches
The OAIC sets out the edges. The Act does not apply to a photo taken by someone acting in a personal capacity, “because it doesn’t cover individuals.” It covers organisations operating in Australia with an annual turnover of more than $3 million, and some other organisations. On the OAIC’s small business page: “A small business is one with an annual turnover of $3 million or less. Annual turnover for the purposes of the Privacy Act includes all income from all sources.”
A business the Act covers has to comply with the Australian Privacy Principles. For a business it does not cover, the OAIC still recommends protecting any personal information it holds, and suggests considering opting in to the Act.
Customers: the purpose test
For a business the Act covers, the rule on using what it holds is APP 6. In the OAIC’s words: “An APP entity can only use or disclose personal information for a purpose for which it was collected (known as the ‘primary purpose’), or for a secondary purpose if an exception applies.” One exception is where the person would reasonably expect the secondary use and it is related to the primary purpose, or directly related for sensitive information.
That is a starting question to teach staff to ask of a screenshot from the business’s inbox, booking system or till: what was this collected for, is posting it related to that purpose, and would this customer reasonably expect it? It is not the whole of APP 6.
Colleagues: an exemption with edges
A private sector employer’s handling of employee records is exempt from the Privacy Act where it relates directly to a current or former employment relationship. The OAIC’s guidance on the exemption marks where it stops:
- It does not cover acts outside the employment relationship; the OAIC’s example is an employer selling a list of employees for marketing.
- Employers may not be able to assume that everything they hold about an employee is an employee record.
- It does not cover job applicants who are not employed, or volunteers.
The Fair Work Ombudsman adds that revealing an employee’s or former employee’s private details, such as medical history, is generally inappropriate, and that best practice employers apply the privacy principles to employee records even where the law does not require it.
Monitoring what staff post
The OAIC says the Privacy Act does not specifically cover workplace surveillance, but an employer who monitors staff must follow any relevant Commonwealth, state or territory laws, and state laws generally cover CCTV. It says monitoring of email, internet and computer use that staff have been told about would generally be allowed, and that keeping records of monitoring may bring in the privacy principles. The workplace policy is where staff are told; the points to include are in a policy staff can follow.
In the training room
The Fair Work Ombudsman says best practice employers give managers and employees training about workplace privacy. It also notes that third parties providing recruitment, training, HR, payroll or other services to an employer under contract may need to comply with the privacy principles. An outside trainer who is handed staff details is one of them, which is worth settling before the session as well as teaching in it. Choosing a course is covered in accredited or not.