Privacy protection requirements for government contracts
21 Privacy protection requirements for government contracts
A public sector agency must not enter into a government contract unless the contract contains appropriate contractual provisions requiring the contracted service provider, and any subcontractor for the contract, to comply with—
the TPPs; or
a TPP code that binds the agency; or
a corresponding privacy law.
Also, a public sector agency must not enter into a government contract that authorises the contracted service provider, or any subcontractor for the contract, to do an act, or engage in a practice, that breaches a TPP, TPP Code or corresponding law that applies to the contract under the contractual provisions mentioned in subsection (1).
Failure by a public sector agency to comply with this section does not affect any obligation the agency, or the contracted service provider, has under this Act or the government contract in relation to compliance with the TPPs, or a TPP code that binds the agency.
In this section:
corresponding privacy law means—
the Privacy Act 1988 (Cwlth); or
a law of a State, external territory or foreign country prescribed by regulation.
subcontractor, in relation to a government contract—
means a person engaged by the contracted service provider under the government contract to provide the services the subject of the government contract; and
includes any other person engaged under a subcontracting arrangement to provide the services the subject of the government contract.
Division 3.3 Other privacy compliance matters
The statute text is free to read above. View Pro plans to unlock the case-law research tools for each provision.