Privacy Act 1988
The Privacy Act 1988 governs how organisations collect, store, use, and disclose personal information about individuals, through the Australian Privacy Principles (APPs) — a set of 13 principles in Schedule 1 of the Act. It applies to SteadyOn in two specific contexts:
- Incident data — when you record information about an injured person, a witness, or an incident reporter
- Health and wellbeing data — when you handle medical information about workers as part of injury management or return-to-work
The Act is administered by the Office of the Australian Information Commissioner (OAIC).
This page is not legal advice. For specific compliance questions, consult a qualified privacy or legal advisor.
Who the APPs apply to
Section titled “Who the APPs apply to”The APPs apply to APP entities — most Australian Government agencies and organisations with an annual turnover of more than AUD $3 million. There is a small-business exemption: organisations with an annual turnover of $3 million or less are generally not covered.
Important caveat: the small-business exemption has significant exceptions. Even with turnover under $3 million, you are still covered if you, for example:
- Provide a health service and hold health information (this captures many clinics, allied-health and care providers)
- Trade in personal information (buy or sell it)
- Are a contractor providing services under a Commonwealth contract
- Are related to a larger APP entity
So even a small business may be bound by the APPs — particularly where health information is involved. The privacy reforms in recent years have also been progressively narrowing exemptions, so treat the $3 million threshold as a starting point, not a safe harbour. Many small businesses choose to follow the APPs regardless, as good practice.
When privacy obligations apply to your SteadyOn data
Section titled “When privacy obligations apply to your SteadyOn data”Not everything in SteadyOn involves personal information. Hazard records (a wet floor in a warehouse) and inspection records (a checklist of fire extinguisher locations) typically don’t involve personal information. Privacy obligations become relevant when:
| Scenario | Why privacy obligations apply |
|---|---|
| Recording the name of an injured worker in an incident report | Personal information about an identifiable individual |
| Recording the nature of an injury (e.g. broken arm, mental health crisis) | Sensitive information (health information) — extra protection |
| Recording witness names and statements | Personal information about a third party |
| Public incident reports that include names or contact details | Personal information collected from non-employees |
| Investigation notes that identify individuals | Personal information held by the organisation |
| Training records linked to named workers | Personal information about employees |
A note on the employee records exemption: the Privacy Act contains a limited exemption for “employee records” held by private-sector employers in relation to current and former employment. Its scope is narrow and frequently misunderstood — it does not extend to non-employees (contractors, visitors, members of the public), and reform proposals would remove or narrow it. Do not rely on it for incident or health data without advice.
The key APP obligations
Section titled “The key APP obligations”Collect only what you need (APP 3)
Section titled “Collect only what you need (APP 3)”Collect only personal information that is reasonably necessary for your functions or activities — here, managing the health and safety incident and your obligations under the WHS Act.
Practical guidance: In an incident report, you need enough information to understand what happened, investigate root causes, and take corrective action. You do not need to collect information about an injured person’s personal life, medical history unrelated to the incident, or anything else that is not relevant to the safety event. Sensitive information (including health information) generally requires the individual’s consent to collect, with limited exceptions.
Be open about how you handle information (APP 1 and APP 5)
Section titled “Be open about how you handle information (APP 1 and APP 5)”Have a clearly expressed and up-to-date privacy policy (APP 1), and at or before the time you collect personal information, tell the person who you are, why you’re collecting it, what it will be used for, and who else might see it (APP 5).
Practical guidance: If your organisation collects information from injured workers or public reporters, have a brief collection notice explaining that the information is collected for work health and safety purposes under the WHS Act, will be held by your organisation, and may be shared with your WHS regulator or insurer if required. Consider adding this to your public incident reporting link.
Use it only for the purpose collected (APP 6)
Section titled “Use it only for the purpose collected (APP 6)”Use or disclose personal information only for the purpose it was collected, or for a directly related purpose the person would reasonably expect — unless an exception applies (such as a legal requirement).
Practical guidance: Information collected to manage a safety incident should be used to manage that incident. Sharing it more widely — or for unrelated purposes — needs justification.
Keep information secure (APP 11)
Section titled “Keep information secure (APP 11)”Take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure — and to destroy or de-identify it when no longer needed.
SteadyOn’s role: SteadyOn stores all data in a SOC 2 compliant cloud infrastructure. Access is scoped to the organisation — only members of your org can see your data. Within an org, every member can see all hazard, incident, action, and inspection records by default; if you need stricter separation, run multiple organisations.
Your role: Ensure your SteadyOn workspace is properly secured — promptly remove members who have left, review the Members tab regularly, and use the Audit metadata and Log tab to keep a record of access.
Give people access to their information (APP 12)
Section titled “Give people access to their information (APP 12)”Individuals generally have a right to access the personal information you hold about them, and to ask for corrections (APP 13).
Practical guidance: Be prepared to provide a worker with the incident or training records you hold about them, and to correct errors. SteadyOn’s records are easy to locate and export for this purpose.
Don’t keep it longer than necessary (APP 11.2)
Section titled “Don’t keep it longer than necessary (APP 11.2)”Take reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed.
Balancing act — WHS vs Privacy Act: WHS laws and workers’ compensation schemes require you to maintain health and safety records to demonstrate compliance, and some records (for example, exposure and health-monitoring records for certain hazards) must be kept for many years — sometimes decades. These legal retention needs generally override the privacy minimisation principle while they apply, because you have a legitimate legal reason to keep the records. Once the retention period has passed, records containing personal information should be reviewed and securely destroyed or de-identified if no longer needed.
Notify eligible data breaches
Section titled “Notify eligible data breaches”Under the Notifiable Data Breaches scheme, if you are an APP entity and you have a data breach that is likely to result in serious harm, you must notify both the OAIC and the affected individuals as soon as practicable.
A breach could occur if, for example, SteadyOn incident records containing personal or health information were accessed by an unauthorised person, or were mistakenly shared outside the organisation.
Your obligations: Conduct regular user access reviews in SteadyOn. Remove users who are no longer part of the organisation promptly. Be cautious when exporting or sharing reports that contain personally identifiable information.
Health information — extra care required
Section titled “Health information — extra care required”Health information is sensitive information under the Privacy Act and attracts a higher standard of protection. This includes:
- The nature of a worker’s injury (e.g. specific diagnosis, body part affected)
- Medical treatment received
- Mental health information
- Return-to-work restrictions or medical certifications
Practical guidance for SteadyOn:
- Record only what is necessary for the H&S purpose (e.g. “worker sustained a soft tissue injury to the lower back” is sufficient for most safety purposes; a full medical diagnosis is not).
- All members of an organisation can see incident records by default — keep sensitive medical detail out of the description, and use attachments for separately stored medical certificates only when essential.
- Do not include sensitive health information in exported reports that will be shared broadly.
Public incident reporting and privacy
Section titled “Public incident reporting and privacy”The public incident reporting link allows anyone to report an incident without a SteadyOn account. People who use this link may provide personal information (their name, contact details, details of what happened to them or others).
Obligations:
- Display a collection notice on the public report form (or in your organisation’s public-facing H&S policy) explaining how reports are handled
- Use the information only for the purpose of managing the safety event
- Do not share the reporter’s personal details more widely than necessary
Summary: Privacy Act and SteadyOn
Section titled “Summary: Privacy Act and SteadyOn”| Obligation | How to meet it |
|---|---|
| Collect only what is necessary | Limit incident descriptions to H&S-relevant information |
| Tell people you’re collecting | Include a collection notice in public incident reporting |
| Secure the data | Use SteadyOn roles to restrict access; remove departed users |
| Don’t over-share | Be selective with exported reports containing personal data |
| Give access and correct | Locate and export a person’s records on request |
| Retain appropriately | Follow WHS / workers’ comp retention rules; destroy after period expires |
| Handle health info carefully | Record minimum necessary; restrict access to sensitive details |
| Notify eligible breaches | Report serious breaches to the OAIC and affected people |
Further reading
Section titled “Further reading”- Australian Regulatory Framework — overview of all the laws
- Roles and Permissions — controlling who can see what in SteadyOn
- Office of the Australian Information Commissioner — authoritative guidance on the Privacy Act and APPs