Part 1 — Preliminary
s 1Purposess 2Commencements 3Definitionss 4Interpretations 5Objectss 6Relationship of this Act to other lawss 7Rights and liabilitiess 8Act binds the CrownPart 1A — Functions, powers of Information Commissioner and appointment of Privacy and Data Protection Deputy Commissioner
Division 1 — Performance of functions
s 8AFunctions of Information Commissioners 8BFunctions of Privacy and Data Protection Deputy Commissioners 8CInformation privacy functionss 8DProtective data security and law enforcement data security functionss 8EPerformance of concurrent functionss 8FInformation Commissioner may confer functions on Privacy and Data Protection Deputy Commissioners 8GGeneral powers of Information Commissioner and Privacy and Data Protection Deputy CommissionerDivision 2 — Privacy and Data Protection Deputy Commissioner
s 8HAppointment of Privacy and Data Protection Deputy Commissioners 8ITerms and conditions of appointment of Privacy and Data Protection Deputy Commissioners 8JRemunerations 8KVacancy and resignation of Privacy and Data Protection Deputy Commissioners 8LSuspension and removal from offices 8MActing Privacy and Data Protection Deputy Commissioners 8NValidity of acts and decisionsDivision 3 — General
s 8ODelegations 8PDirectionsPart 2 — Application of this Act
s 9Definitions 10Courts, tribunals etc.s 10ARoyal Commissions etc.s 11Parliamentary Committeess 12Publicly-available informationPart 3 — Information privacy
Division 1 — Application of this Part
s 13Public sector organisations to which this Part appliess 14Exemption—Freedom of Information Act 1982s 15Exemption—law enforcements 15AExemption—information sharing under the Family Violence Protection Act 2008s 15BExemption—information sharing under the Child Wellbeing and Safety Act 2005s 15CExemption—information sharing for quality and safety purposes under the Health Services Act 1988s 15DInformation sharing under Division 6 of Part 4A of Terrorism (Community Protection) Act 2003s 17Effect of outsourcingDivision 2 — Information Privacy Principles
s 18Information Privacy Principless 19Application of Information Privacy Principless 20Organisations to comply with Information Privacy PrinciplesDivision 3 — Codes of practice
s 21Codes of practices 22Process for approval of code of practice or code amendments 23Organisations bound by code of practices 24Effect of approved codes 25Codes of practice registers 26Revocation of approvals 27Effect of revocation of approval or amendment or expiry of approved codeDivision 4 — Capacity to consent or make a request or exercise right of access
s 28Capacity to consent or make a request or exercise right of accessDivision 5 — Public interest determinations and temporary public interest determinations
Subdivision 1 — Public interest determinations
s 29Public interest determinations 30Application taken to be application for temporary public interest determination on requests 31Information Commissioner may make public interest determinations 32Effect of public interest determinations 33Duration of public interest determinations 34Amendment of public interest determinations 35Revocation of public interest determinations 36Reporting and reviewSubdivision 2 — Temporary public interest determinations
s 37Temporary public interest determinations 38Application for temporary public interest determinations 39Information Commissioner may make temporary public interest determinations 40Duration of temporary public interest determinations 41Revocation of temporary public interest determinationSubdivision 3 — Disallowance of determinations
s 42Disallowance of determinationsDivision 6 — Information usage arrangements
s 43Definitionss 44Approval of arrangement not required if information use otherwise permitteds 45Meaning of information usage arrangements 46Parties to an information usage arrangements 47Information Commissioner to consider information usage arrangements 48Information Commissioner's reports 49Information Commissioner's certificates 50Ministerial approval of information usage arrangements 51Effect of approved information usage arrangements 52Amendment of approved information usage arrangements 53Revocation of approval of information usage arrangements 54Reporting requirements for approved information usage arrangementsDivision 7 — Certification
s 55Information Commissioner may certify consistency of act or practices 56Review of decision to issue certificateDivision 8 — Information privacy complaints
Subdivision 1 — Making a complaint
s 57Complaintss 58Complaint referred to Information Commissioners 59Complaints by minorss 60Complaints by people with a disabilitySubdivision 2 — Procedure after a complaint is made
s 61Information Commissioner must notify respondents 62Circumstances in which Information Commissioner may decline to entertain complaints 63Information Commissioner may refer complaints 64Information Commissioner may dismiss stale complaints 65Minister may refer a complaint direct to VCATs 65APreliminary inquiries and consultations 65BInformal resolutions 66What happens if conciliation is inappropriate?Subdivision 3 — Conciliation of complaints
s 67Conciliation processs 68Information Commissioner may issue notice to produce or attends 69Conciliation agreementss 70Evidence of conciliation is inadmissibles 71What happens if conciliation fails?Subdivision 4 — Interim orders
s 72VCAT may make interim orders before hearingSubdivision 5 — Jurisdiction of VCAT
s 73When may VCAT hear a complaint?s 74Who are the parties to a proceeding?s 75Time limits for complaints referred by the Ministers 76Inspection of exempt documents by VCATs 77What may VCAT decide?Division 9 — Enforcement of Information Privacy Principles and approved information usage arrangements
s 78Compliance notices 79Power to compel production of documents or attendance of witnesss 82Offence not to comply with compliance notices 83Application for reviewDivision 10 — Notices to produce or attend
s 83ANotice to produce or attends 83BVariation or revocation of a notice to produce or attends 83CService of notice to produce documents or to attends 83EPower to take evidence on oath or affirmations 83FLegal advice and representations 83GProtection of legal practitioners and persons—notice to produce or attends 83GAAudio or video recording of examinations 83HFailure to comply with notice to produce or attends 83IReasonable excuse—self-incriminations 83JReasonable excuse—cabinet documents and legal professional privileges 83KStatutory secrecy not a reasonable excuses 83LAct applies equally to attendance in person or by audio or audio visual linkPart 4 — Protective data security
Division 1 — Application of Part
s 84Application of PartDivision 2 — Protective data security framework
s 85Information Commissioner to develop Victorian protective data security frameworkDivision 3 — Protective data security standards
s 86Information Commissioner may issue protective data security standardss 87Amendment, revocation or reissue of standardss 88Compliance with protective data security standardsDivision 4 — Protective data security plans
s 89Protective data security planss 90Exemption—Freedom of Information Act 1982Part 5 — Law enforcement data security
s 91Application of Parts 92Information Commissioner may issue law enforcement data security standardss 93Inconsistency with protective data security standardss 94Compliance with law enforcement data security standardsPart 6 — General powers of Information Commissioner
Division 1 — General powers of Information Commissioner
s 106Information Commissioner may require access to data and data systems from public sector body Headss 107Information Commissioner may require access to data and data systems from Chief Commissioner of Polices 108Information Commissioner may request access to crime statistics datas 109Information Commissioner may copy or take extracts from datas 110Public sector body Heads to provide assistances 111Reports to the Minister and other reportss 112Disclosure during course of compliance audit—data securitys 113Disclosure to the IBACDivision 2 — Reporting
s 116Report on performance and exercise of powersPart 7 — General
s 117Protection from liabilitys 118Employees and agentss 119Fees for accesss 120Secrecys 121Information Commissioner to give notice before certain disclosuress 122Offence to obstruct, mislead or provide false informations 123Offences by organisations or bodiess 124Prosecutionss 125RegulationsPart 8 — Repeal of Acts and transitional and savings provisions
s 126Repeal of Information Privacy Act 2000s 127Repeal of Commissioner for Law Enforcement Data Security Act 2005s 128Transitional and savings provisionss 129Transitional provisions—Freedom of Information Amendment (Office of the Victorian Information Commissioner) Act 2017Schedule 1 — –The Information Privacy Principles
Schedule 1, s 1Principle 1—CollectionSchedule 1, s 2Principle 2—Use and DisclosureSchedule 1, s 3Principle 3—Data QualitySchedule 1, s 4Principle 4—Data SecuritySchedule 1, s 5Principle 5—OpennessSchedule 1, s 6Principle 6—Access and CorrectionSchedule 1, s 6.4If an organisation charges for providing access to personal information, the organisation—Schedule 1, s 6.7An organisation must provide reasons for denial of access or a refusal to correct personal information.Schedule 1, s 7Principle 7—Unique IdentifiersSchedule 1, s 7.3An organisation must not use or disclose a unique identifier assigned to an individual by another organisation unless—Schedule 1, s 8Principle 8—AnonymitySchedule 1, s 9Principle 9—Transborder Data FlowsSchedule 1, s 10.1An organisation must not collect sensitive information about an individual unless—Schedule 1, s 10.2Despite IPP 10.1, an organisation may collect sensitive information about an individual if—Schedule 2 — –Transitional and savings provisions
Schedule 2, s 1DefinitionsSchedule 2, s 2General transitional provisionsSchedule 2, s 3Superseded referenceSchedule 2, s 4Re-enacted provisions—Information Privacy Act 2000Schedule 1
Schedule 1
Schedule 1, s 5Office of Privacy Commissioner abolishedSchedule 1, s 6Office of Commissioner for Law Enforcement Data Security abolishedSchedule 1, s 7References to former CommissionerSchedule 1, s 8Staff of Privacy Commissioner and Commissioner for Law Enforcement Data SecuritySchedule 1, s 9OffencesSchedule 1, s 10Annual reports under Information Privacy Act 2000 for reporting periods which end before commencement daySchedule 1, s 11Annual reports under Information Privacy Act 2000 for reporting periods that end on or after commencement daySchedule 1, s 12Approved codes of practiceSchedule 1, s 13Complaints and compliance noticesSchedule 1, s 16Annual reports under Commissioner for Law Enforcement Data Security Act 2005 that have not been laid before ParliamentSchedule 3 — Transitional provisions—Freedom of Information Amendment (Office of the Victorian Information Commissioner) Act 2017
Schedule 3, s 1DefinitionSchedule 3, s 2Office of Commissioner for Privacy and Data Protection abolishedSchedule 3, s 3References to Commissioner for Privacy and Data ProtectionSchedule 3, s 4StaffSchedule 3, s 5Codes of practiceSchedule 3, s 6Public interest determinationsSchedule 3, s 7Information usage arrangementsSchedule 3, s 8ComplaintsSchedule 3, s 9Compliance noticesSchedule 3, s 10Protective data security standardsSchedule 3, s 11Law enforcement data security standardsSchedule 3, s 12Reports for reporting periods which end before commencement daySchedule 3, s 13Annual reports for reporting periods which end on or after the commencement daySchedule 3, s 14Report to Minister