Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.

We respect your Do Not Track preference.

Scammer then complains of privacy breach Charles Mabbett
29 September 2017 at 16:01

There’s a general expectation that if you make a complaint to our Office, you haven't brought the breach of privacy upon yourself through your actions. In this case, our complainant was a man who had ripped off a business. He had scammed the business out of several hundred dollars worth of goods but became upset when the business named and shamed him on its Facebook page.

A guide for health professionals disclosing information to Police Richard Stephen
7 July 2017 at 11:32

Reviewed May 2025 (previously titled ‘Can I tell the cops? A guide for health professionals.’

Should agencies leave no stone unturned? Charles Mabbett
10 May 2017 at 09:31

Organisations sometimes get it wrong when they respond to a person’s request for their personal information. Information is sometimes lost, displaced or accidentally deleted. A recent privacy case dealt with by the Human Rights Review Tribunal considers when an organisation can call it quits when it comes to searching for personal information in responding to an access request.

How to make information available – some tips for agencies Lynley Cahill
4 April 2017 at 14:32

We live in an age where agencies collect and hold a lot of information about us. When we then request access to that information, this places demands on the time and resources of agencies to meet their obligations under the Privacy Act. Agencies sometimes feel a bit overwhelmed when responding to requests for personal information -  especially where a high volume of information is held.

Hager and Westpac - A bit more context, information and clarification Sam Grover
22 March 2017 at 09:50

There has been a significant amount of media coverage about our investigation into Westpac bank disclosing journalist Nicky Hager’s bank account information to Police in 2014. In the course of that reporting, some misconceptions have emerged. Because of the interest in the case, and the potential implications for future practice, we have noted some points of clarification and context below.

What to do in a phishing attack Neil Sanson,
20 March 2017 at 14:42

A recent data breach involved a deliberate email phishing attack on an organisation. The email looked like it came from the chief executive and requested a copy of the membership list (names and email addresses).

Sir Bruce Houlton Slane Charles Mabbett
8 January 2017 at 09:50

Sir Bruce Houlton Slane KNZM, CBE, LLB practiced law in New Zealand for almost 50 years, including 11 years as the country’s first Privacy Commissioner.

A design blueprint for privacy Riki Jamieson-Smyth
19 December 2016 at 11:26

This blog post was reviewed and some links updated in May 2025