Should the Privacy Act be technology neutral?

10.3 The explanatory memorandum to the Privacy Amendment (Private Sector) Bill 2000 noted that the National Privacy Principles (NPPs) were intended to be technology neutral. Technology-neutral privacy principles were intended to ensure that the Privacy Act remained flexible and relevant in the case of technological change.[1] In Chapter 9, the ALRC considers the impact on privacy of several new and developing technologies.These technologies facilitate easier, cheaper and faster methods by which information may be collected, accessed, aggregated and communicated. Further, there is an increasing ability to store large quantities of information. In its submission, the OPC cited a University of California, Berkeley, study that found that only 0.01% of all new information produced in 2002 was paper-based.[2] The OPC submitted that the privacy regulatory framework should be informed by the assumption that ‘information will be handled in electronic form’.[3]

10.4 In light of these technological developments, the ALRC asked in the Issues Paper, Review of Privacy (IP 31) whether the Privacy Act should remain technology neutral.[4] In the Discussion Paper, Review of Australian Privacy Law (DP 72), the ALRC noted some opposition to the proposition. For example, Professor Roger Clarke queried whether the concept of technology neutrality operates effectively in practice.[5] Clarke has noted previously that the impact of some technologies on privacy may be inconceivable until the technologies have actually been invented and deployed.[6]

10.5 The ALRC, however, proposed in DP 72 that the Privacy Act should remain technology neutral.[7] In making this proposal, the ALRC expressed the view that current technologies do not alter fundamentally the nature of the information-handling cycle. For example, technology such as surveillance devices and radio frequency identification (RFID) systems may facilitate the collection of personal information without the knowledge or consent of an individual, but the collection of the information will still be regulated by the ‘Collection’ principle in the model UPPs. The ALRC expressed the view that the handling of personal information by developing technologies can be regulated by high level and technology-neutral UPPs, although it may be necessary to make some amendments to the Privacy Act to ensure that the Act remains technology aware.

Submissions and consultations

10.6 There was strong support for this proposal.[8] Medicare supported a technology-neutral Privacy Act as ‘it would be impossible for legislation to keep up with the rapid pace at which technology keeps evolving’.[9] Optus submitted that ‘[t]he current principles based, technology neutral regime provides a powerful framework on which to base privacy requirements when assessing new and emerging technology’.[10]

10.7 A number of stakeholders supported the proposal but noted that the effectiveness of a technology-neutral Privacy Act will be dependent upon the technology-aware framework underpinning the legislation. For example, the Department of Finance and Deregulation supported the proposal ‘in principle’, but noted that legislation that does not

apply to any specific technology can still significantly affect how technology operates or is employed. It may be arguable as to whether such legislation is really technologically neutral if it deliberately or unintentionally limits or affects the use or operation of technology.[11]

10.8 The Public Interest Advocacy Centre (PIAC) highlighted the important role of the regulator in a technology-aware privacy regime. PIAC submitted that the OPC should play a more proactive role in the exercise of its research and monitoring function with regard to the impact on privacy of new and emerging technologies.[12] The Australian Privacy Foundation submitted that the ALRC’s final recommendation should acknowledge that the overall privacy regulatory framework ‘should be designed so as to ensure ongoing awareness of the impacts of technology, and to avoid blindness to them’.[13]

ALRC’s view

10.9 In the ALRC’s view, technology-neutral privacy principles provide the most effective way to ensure individual privacy protection in light of developing technology.[14] It would be undesirable to recommend significant changes to the UPPs to accommodate technologies, which are yet to be invented or deployed. Further, where possible, provisions of the Privacy Act should be technology neutral.[15] This approach does not foreclose the possibility of technology-specific regulation or legislative instruments in certain circumstances. The Biometrics Institute Privacy Code is an example of a Part IIIAA code that was initiated by the biometrics industry and, following approval by the OPC, became a legislative instrument.[16] If the OPC found it necessary to initiate a code to address the handling of personal information using a certain technology, such as RFID, the OPC could lobby the minister responsible for administering the Privacy Act to have such a code included in regulations.[17]

10.10 Technology-specific regulations or other legislative instruments of this nature are consistent with the ALRC’s three-tiered approach to privacy regulation, and do not represent a failure of technology-neutral UPPs. Instead, such regulations indicate that information handled by particular technologies may require stronger protection in certain, limited circumstances. Further, to ensure the effectiveness of technology-neutral privacy principles, the OPC should provide technology-specific guidance on meeting the requirements in the model UPPs when certain technologies are used to handle personal information.

10.11 One of the OPC’s functions is to research and monitor developments in technology and to report to the minister responsible for administering the Privacy Act.[18] In the ALRC’s view, the OPC could exercise this function to provide a continuing review mechanism of the adequacy and effectiveness of the Privacy Act in light of further developments in technology.

10.12 A number of concerns raised by stakeholders in this Inquiry about the impact of technology on privacy are dealt with in other sections of this Report. In Part A, the ALRC recommends amendments to the definitions of ‘personal information’, ‘sensitive information’ and ‘record’. In Part D, the ALRC makes a number of recommendations concerning the content of the model UPPs. In Part F, the ALRC recommends additional OPC powers and functions that are relevant to technological developments. These recommendations are discussed below, and in Chapter 11.

