The Privacy Act Employee Records Exemption (and Its Limits)

Australia's Privacy Act exempts employee records from the APPs — but the exemption is narrower than most employers think. Learn what it covers, what it doesn't, and why it may not last.

Last updated: 2026-06-22

Many Australian employers believe the Privacy Act doesn't apply to staff data at all. That's a half-truth. The employee records exemption is real, but it is narrower than most people assume — and it is one of the reforms most likely to be removed. This guide explains what the exemption actually covers.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. The boundaries of the employee records exemption are fact-specific and contested. Consult a qualified lawyer for advice on your situation. Information is current as of the date below.

What the Exemption Is

Under section 7B(3) of the Privacy Act, the Australian Privacy Principles do not apply to an organisation's handling of an employee record, where that handling is directly related to a current or former employment relationship between the organisation and the individual.

In other words, when a covered business handles its own employees' records for employment purposes, the APPs are switched off for that handling. The rationale (when introduced) was that the employment relationship is governed by workplace law and enterprise agreements rather than privacy law.

Note this only matters for businesses that are otherwise covered by the Privacy Act in the first place — if you already qualify for the small business exemption, you are outside the Act regardless.

What It Does Not Cover

This is where employers get caught out. The exemption is far from a blanket "staff data is exempt" rule. It does not apply to:

  • Agencies. It is an exemption for private-sector organisations only. Government employee records are not exempt.
  • Job applicants and prospective employees. Until an employment relationship exists, recruitment data is not covered by the exemption. Handle applicant data under the APPs.
  • Contractors and volunteers. The exemption is about employees. Independent contractors are generally not employees, so their records typically aren't exempt.
  • Handling not directly related to the employment relationship. If you use employee information for an unrelated purpose, the connection to the employment relationship may break, and the exemption with it.
  • The record once it stops being an "employee record." The term has a specific meaning (health information, terms of employment, performance, leave, salary, tax, banking and superannuation details, and similar). Information that doesn't fit may not be exempt.

A useful mental model: the exemption is a tunnel, not a blanket. It covers a specific kind of record, held by a specific kind of entity, used for a specific purpose. Step outside any of those and the APPs apply again.

Security Still Matters

Even where the exemption applies, it does not make poor data handling acceptable. Employee records are exactly the kind of sensitive data — bank details, tax file numbers, health information — that causes serious harm when breached. Other laws also bear on staff data, including work health and safety obligations, the Fair Work Act, and the new statutory tort for serious invasions of privacy (in force since June 2025). Treat employee records as confidential and secure them properly regardless of the exemption.

Why the Exemption May Not Last

The employee records exemption is one of the most criticised features of the Privacy Act, and the 2023 Privacy Act Review recommended removing or significantly narrowing it so that employees get privacy protections (with appropriate carve-outs for legitimate employment needs).

As of June 2026, the exemption remains in place — the first tranche of reforms (the Privacy and Other Legislation Amendment Act 2024) did not touch it, and no second-tranche bill has been introduced. But the direction is clear, and forward-looking employers are already handling staff data as if the APPs applied: clear collection notices, sensible retention, strong security, and a process for access and correction. We track reform progress on the data governance news page.

Practical Guidance

  • Don't over-rely on the exemption. Map which staff-data handling genuinely falls inside it and which (recruitment, contractors, unrelated uses) does not.
  • Apply good practice across the board. A single, APP-aligned approach to all people data is simpler than policing the boundary of the exemption — and future-proofs you against its removal.
  • Secure the sensitive stuff. Tax file numbers, bank details, and health information warrant the strongest protection you have.

For the full set of obligations, see the Australian Privacy Act guide.

References

Last reviewed: June 2026. The employee records exemption is under active review and may be removed or narrowed. Verify against current OAIC guidance and consult qualified legal counsel before relying on it.


Staff Data Requests, Handled

Current and former employees increasingly ask for their data — and the boundary of the exemption is contested. Our DSAR Compliance Guide helps you build one defensible process for access requests across every jurisdiction and relationship type.