Privacy safeguard 9—adoption or disclosure of government related identifiers by accredited data recipients
56EL Privacy safeguard 9—adoption or disclosure of government related identifiers by accredited data recipients
If:
a person is an accredited data recipient of CDR data; and
the CDR data includes a government related identifier (within the meaning of the Privacy Act 1988) of a CDR consumer for the CDR data who is an individual;
the person must not adopt the government related identifier as the person’s own identifier of the CDR consumer, or otherwise use the government related identifier, unless:
the adoption or use is required or authorised by or under:
an Australian law other than the consumer data rules; or
a court/tribunal order; or
subclause 9.3 of Australian Privacy Principle 9 applies in relation to the adoption or use.
This subsection is a civil penalty provision (see section 56EU).
If:
a person who is an accredited data recipient of CDR data proposes to disclose the CDR data; and
the CDR data includes a government related identifier (within the meaning of the Privacy Act 1988) of a CDR consumer for the CDR data who is an individual;
the person must not include the government related identifier in the disclosure unless:
this is required or authorised by or under:
an Australian law other than the consumer data rules; or
a court/tribunal order; or
subclause 9.3 of Australian Privacy Principle 9 applies in relation to the disclosure.
This subsection is a civil penalty provision (see section 56EU).
This subsection applies in addition to the disclosure restrictions in sections 56EI, 56EJ and 56EK.
For the purposes of paragraph (1)(d) or (2)(d), disregard paragraph 56EC(4)(a) (about the APPs not applying).
The statute text is free to read above. View subscription options to unlock the case-law research tools for each provision.