workit HR software
30-day trialBook a demoLog in
Back to blogs

Compliance

Australian HR: Reconcile Privacy Act and Fair Work on Employee Records

workit HR recruitment, onboarding, HR, compliance, performance review, background screening, learning management

Australian HR: Reconcile Privacy Act and Fair Work on Employee Records

The employee records exemption applies only when three things line up: an employment relationship exists, the information is an employee record your organisation holds, and the act or practice is directly related to that employment under section 7B(3) of the Privacy Act 1988 (Cth). Miss any one of the three and the Australian Privacy Principles (APPs) apply in full. Recruitment data on unsuccessful applicants and most contractor records sit outside the exemption altogether, because no employment relationship has formed.


TL;DR:

  • The employee records exemption only applies when there is an employment relationship, the data is already held by the employer, and the activity is directly related to employment management.
  • Employee records include payroll, leave, performance, tax, training, contact details, and health information collected for employment purposes, but not personal emails or unrelated health data.
  • The exemption does not cover unsuccessful applicants, contractors, or volunteers, meaning their data remains fully subject to Australian Privacy Principles.
  • Employers must balance privacy and fair work record-keeping requirements, retaining pay and hours data for at least seven years while restricting access to authorized staff.
  • Misjudging the exemption’s scope can lead to legal, reputational, and financial penalties, making ongoing data classification, access controls, and legal consultation essential.

Workit
Keep Australian HR records organised
Workit brings hiring, onboarding and compliance into one platform, with real-time tracking and local support for Australian businesses.
Explore Workit

Table of Contents

Section 7B(3) exempts a private sector employer’s act or practice from the APPs, but only where it relates directly to a current or former employee and to a record their employer already holds. The Office of the Australian Information Commissioner (OAIC) describes this as a narrow carve-out, not a blanket pass for anything HR touches.

“Directly related” means the primary purpose of the act has to be employment management itself, not something adjacent that merely involves an employee’s data. Paying wages, tracking leave, and storing timesheets are directly related. Handing an employee’s home address to a marketing partner, or using performance data to promote a product to their personal network, is not.

  • Covered: processing payroll, recording sick leave, reviewing performance for a pay decision.
  • Not covered: sharing employee contact details for marketing, using health records for a purpose unrelated to employment, disclosing data to benefit a different business unit.

Get this test wrong and you’re not just risking an OAIC complaint. You’re building HR processes on a legal foundation that won’t hold up under scrutiny.

What counts as an employee record under the Privacy Act?

Section 6(1) of the Privacy Act defines an employee record and lists the categories that fall inside it. The list is broader than most HR teams assume, but it stops well short of covering every file with an employee’s name on it.

Employee records typically include:

  • Salary, allowances, and banking details for pay purposes.
  • Leave balances and leave history.
  • Performance and conduct records.
  • Tax file number (TFN) and superannuation contributions.
  • Training records and engagement history.
  • Emergency contact and personal contact details.
  • Health information collected for employment purposes (workers compensation, fitness for duty).

Pro Tip: Medical records tied to a workers compensation claim or a return to work plan often carry separate legal obligations on top of the Privacy Act. Segregate them from general HR files with tighter access permissions.

Borderline cases trip people up. Email content, for instance, is only covered where it directly relates to the employment relationship. A performance conversation in an email chain is likely covered. A stray personal message forwarded to a manager probably isn’t. Classify each record type against the section 6(1) list rather than assuming everything in your HRIS automatically qualifies.

Does the exemption cover applicants, contractors, and volunteers?

No, and this is the mistake that catches employers out most often. The exemption only switches on once an employment relationship exists, which rules out several categories of people HR deals with every day.

  1. Job applicants: Recruitment data on candidates you don’t hire remains fully subject to the APPs, including collection notices and deletion obligations. This is a common trap for recruitment pipelines and talent pools, where CVs and interview notes linger long after a role is filled.
  2. Contractors: Independent contractors aren’t employees, so their personal information sits outside the exemption entirely, regardless of how long the engagement runs.
  3. Volunteers: The same logic applies. No employment relationship means no exemption, even where the volunteer’s duties look identical to a paid role.
  4. Secondary internal uses: Using employee data for internal communications, promotional material, or benchmarking against other staff usually fails the “directly related” test, even when the data originated from a legitimate HR process.

Treat each of these categories as fully APP covered by default, not as edge cases you’ll deal with if a complaint arrives.

How does the Privacy Act exemption interact with Fair Work record-keeping rules?

The employee records exemption governs privacy obligations. It says nothing about how long you must keep records or who can inspect them, and that’s where the Fair Work Act 2009 (s535) takes over. Employers must retain time and wages records for a period required by employment law, covering pay rates, hours worked, deductions, leave balances, and superannuation contributions.

  • Time and wages records must be kept for the minimum retention period mandated by employment law, even after an employee leaves.
  • Fair Work Inspectors can request access to these records, and refusal or falsification carries penalties.
  • Records must remain both secure (to satisfy privacy obligations) and accessible (to satisfy Fair Work obligations).
  • Business lists the specific fields inspectors expect to see, including termination details and superannuation contributions.

The practical tension is obvious: privacy law pushes you toward minimal retention and tight access, while Fair Work law demands you keep detailed records for years and produce them on request. A well-structured record-keeping process built for the seven-year rule resolves this by applying access controls without ever deleting what Fair Work requires.

What do recent OAIC determinations mean for employers?

Case law is where the exemption’s narrowness becomes obvious. The OAIC’s determination in ALI and ALJ (Privacy) [2024] AICmr 131 found that a disclosure made for broader internal management purposes wasn’t directly related to the complainant’s own employment, even though the employer argued it served a legitimate operational need. Legal commentary from Piper Alderman reads this as confirmation that the Commissioner will reject reliance on the exemption whenever a use benefits a different employee, a different team, or the business generally, rather than the employee whose record it is.

The practical fallout for employers who misjudge this:

  • Formal OAIC complaints and determinations, which are published and searchable.
  • Civil remedies, including damages where a breach caused real harm.
  • Reputational damage that outlasts any individual complaint.

Pro Tip: If a disclosure involves surveillance, workplace investigations, or sharing data with a third party outside the direct payroll or leave function, get legal advice before you rely on the exemption. The cost of a proper opinion is far lower than the cost of a determination against you.

What should HR teams do to stay compliant?

Compliance here isn’t a one-off project. It’s an operating habit built around knowing exactly what data you hold, why you hold it, and who can touch it.

Start with data mapping and classification.

  • List every system holding employee data, from your HRIS to shared drives and email.
  • Classify each record type against the section 6(1) list: is it an employee record, or does it belong to a category (applicants, contractors) the exemption doesn’t cover?
  • Update collection notices so employees understand what’s collected and why, even where the APPs don’t strictly apply.
  • Set retention schedules per record type. Time and wages records run seven years; other categories may need shorter or longer windows depending on their purpose.

Then lock down the technical controls.

  • Apply role-based access so only relevant staff (payroll, direct managers, HR) can view sensitive fields.
  • Encrypt data at rest and in transit, particularly for health information and TFNs.
  • Keep audit logs of who accessed or exported records, and when.
  • If any vendor hosts data overseas, check the contract addresses cross-border disclosure obligations under the Privacy Act.

Finally, build the operational habits around it.

  • Train HR and line managers on what “directly related” actually means in practice, not just in policy.
  • Review privacy and record-keeping policies annually, or after any incident.
  • Draft an incident response plan for the Notifiable Data Breaches scheme, and test it with a mock scenario before you need it for real.

A platform like Workit’s HR compliance software centralises these controls, so retention schedules, access permissions, and audit trails live in one system instead of scattered across spreadsheets and shared drives.

Quick compliance checklist for employee records

Print this and work through it once a quarter, not once a year.

  • Classify: Tag every record as employee record, applicant record, or contractor record.
  • Limit: Restrict access to each record type on a need-to-know basis.
  • Secure: Encrypt sensitive fields and log every access event.
  • Notify: Keep collection notices current and visible to staff.
  • Document: Record the rationale behind each retention decision, not just the outcome.
  • Review: Reassess the checklist whenever a system, vendor, or law changes.

Sample retention: time and wages records run seven years under the Fair Work Act. Other record types (training, correspondence, applicant data) need their own documented rationale rather than a default seven-year setting. If you’re unsure who owns a decision, put HR leadership and your privacy officer on the audit trail together, and record the date and reasoning.

Why treating this exemption with care actually protects your business

Most employers I’ve seen get into trouble here didn’t act maliciously. They assumed the exemption was broader than it is, because the name sounds like a blanket permission slip for anything involving an employee.

It isn’t. The OAIC’s determinations show the Commissioner reads “directly related” narrowly and expects employers to justify each use against the employee’s own employment relationship, not the business’s convenience. That’s a higher bar than most policy documents reflect, and closing that gap is cheaper before a complaint lands than after.

workit HR recruitment, onboarding, HR, compliance, performance review, background screening, learning management

The businesses that handle this well aren’t the ones with the longest privacy policy. They’re the ones who’ve mapped their data, matched retention rules to Fair Work’s seven-year requirement, and built access controls that make “who saw this record and why” an easy question to answer. That’s not a compliance exercise you finish once. It’s a system you maintain.

— Stephen

Keep employee records compliant without the spreadsheet chaos

There are HR software platforms available that allow teams to classify, secure, and retain employee records without juggling spreadsheets, shared drives, and half-updated policy documents. Some offer all modules, from compliance tracking to HRIS and reporting, for a single monthly price with no hidden add-ons.

workit HR recruitment, onboarding, HR, compliance, performance review, background screening, learning management

Retention scheduling and role-based access can sit at the centre of how an HR platform handles employee data, potentially allowing seven-year Fair Work obligations and privacy controls to run off the same system instead of two disconnected processes. Local support may provide assistance during Fair Work inspections or OAIC enquiries, avoiding reliance on overseas help desks.

If your current setup leaves you second-guessing who can access what, book a demo of Workit’s compliance platform and see how record classification and access control come built in from day one.

Sources

FAQ

How long must an employer keep employee records in Australia?

Time and wages records must be kept for at least seven years under the Fair Work Act, covering pay rates, hours, deductions, and leave balances, according to Fair Work Ombudsman guidance.

What privacy rules apply to work emails in Australia?

Work email content is only covered by the employee records exemption where it’s directly related to the employment relationship itself, such as a performance discussion. Content unrelated to employment management falls back under the standard APPs.

What are an employer’s key rights around employee data?

Employers can collect, store, and use data directly related to managing the employment relationship, including payroll, leave, and performance records, without needing separate APP consent for those specific uses under section 7B(3). That right stops at anything not directly related to employment, including recruitment data and contractor files.

What privacy rights do employees have at work in Australia?

Employees retain full APP rights over any personal information that isn’t an employee record directly related to their employment, and they can complain to the OAIC where an employer’s use falls outside that narrow test. Recent determinations, including ALI and ALJ, confirm the Commissioner will side with employees when internal disclosures serve a purpose beyond their own employment relationship.

See workit in action

Make HR simpler for your team.

Book a demo
Book a demo