1. Before you start: check whether the Privacy Act applies to your business
  2. Prerequisites before you respond
  3. Step 1: confirm the request is for the individual's own information
  4. Step 2: clarify the scope of the request
  5. Step 3: advise of any fee upfront
  6. Step 4: locate and compile the personal information
  7. Step 5: provide access within a reasonable time
  8. Step 6: if you need to refuse (or partially refuse) the request
  9. Where Artificer Legal can assist
  10. The single factor most likely to determine your outcome

A customer emails you asking for a copy of every piece of personal information your business holds about them. Or perhaps they want a specific call recording, an old invoice, or the notes your staff made after a meeting. Whatever the form, this is a privacy access request — and if the Privacy Act 1988 (Cth) applies to your business, you have obligations about how and when you respond.

Handled well, an access request takes a few days and costs a handful of staff hours. Handled poorly, it can escalate to a complaint with the Office of the Australian Information Commissioner (OAIC), a formal investigation, and reputational damage that far outweighs the original inconvenience. This guide walks you through the full process — from confirming you are covered, to handing over the information or issuing a lawful refusal.

What this process does not produce: a data retention policy, a privacy policy, or a data breach notification. Those are related but separate obligations. This guide covers only the response to an individual's request to access their own information.

Before you start: check whether the Privacy Act applies to your business

Not every business in Australia is required to comply with a privacy access request as a matter of law. The Privacy Act 1988 (Cth) applies to APP entities, which includes private sector organisations that meet at least one of these conditions:

  • Your business has an annual turnover of more than $3 million (under s 6D of the Privacy Act 1988 (Cth)).
  • Your business provides a health service and holds health information (regardless of turnover).
  • Your business discloses personal information about individuals for a benefit, service, or advantage — sometimes called "trading in personal information."
  • Your business is a contracted service provider under a Commonwealth contract.
  • Your business has voluntarily opted in to the Privacy Act.

If none of these apply, the Act does not legally compel you to respond. Even so, responding promptly and transparently is usually good practice — customers who feel ignored are more likely to complain publicly or to a regulator, even if the regulator ultimately has no jurisdiction. This guide focuses on businesses that are legally required to comply, but the steps are sensible for any business to follow.

Prerequisites before you respond

Tick these off before you do anything else:

  • Know who your privacy contact is. Someone in your business needs to own this process. That person should know where your personal information is stored and who holds it.
  • Have your privacy policy accessible. APP 1 requires you to have one. If yours is outdated, the access request is a prompt to fix it.
  • Know your data map. You cannot locate information you cannot trace. If you do not know what personal information you hold and where, the locate-and-retrieve step will stall.
  • Confirm your identity verification method. Decide in advance how you will verify identity — for example, asking the person to confirm details only they would know, or inspecting (but not copying) a current identity document.
  • Check whether third parties hold data on your behalf. If you use contractors, cloud providers, or outsourced processors who handle personal information on your behalf, their holdings may form part of what you are obliged to locate.

Step 1: confirm the request is for the individual's own information

When a request arrives, your first task is to confirm that the person asking is the person the information is about — and that they are asking about their own personal information, not someone else's.

Under APP 12, an APP entity must, on request by an individual, give that individual access to the personal information the entity holds about them. The obligation runs to the individual themselves. It does not extend to giving one customer their neighbour's records.

Verifying identity

Ask the individual to verify their identity before you proceed. Practical approaches include:

  • Asking them to confirm account details, a date of birth, or another piece of identifying information they would already hold.
  • Asking them to present (not hand over) a current identity document in person.
  • Sending a verification email to the address on file.

Do not ask for a copy of an identity document and do not retain one. Taking a copy of a passport or driver's licence creates a new collection of personal information that must itself be handled in accordance with the APPs.

Authorised representatives

A request may be made by a parent or guardian on behalf of a child, or by a person acting under a power of attorney. If this is the case, ask for evidence of the authorisation before proceeding — a copy of the power of attorney document, or the legal guardian's relationship to a minor. Keep a record of the authorisation, not a copy of any underlying ID.

Step 2: clarify the scope of the request

Once identity is confirmed, clarify exactly what the individual is asking for. A broad request for "all information" triggers a different workload than a request for "the call recording from 14 March." Scope matters for two reasons:

  1. It determines what you need to locate, and therefore how long the search will take.
  2. It may affect whether any grounds for refusal apply to part of the request but not all of it.

If the request is ambiguous, contact the individual promptly to clarify. The OAIC expects businesses to work cooperatively with individuals rather than using ambiguity as a reason to delay or refuse. Clarification time pauses the practical clock, but only if you communicate quickly.

Step 3: advise of any fee upfront

Under the APPs, you may charge a reasonable fee for giving access — but only for the cost of locating, retrieving, reproducing, and sending the information. You cannot charge a fee that is so high it effectively discourages the person from pursuing their request.

You may not charge a fee simply for receiving the request.

If you intend to charge:

  • Provide the individual with a written quote before you do the work.
  • Wait for them to agree to the fee before you proceed.
  • Offer lower-cost alternatives where available — for example, electronic delivery rather than a printed and posted bundle.

If the individual does not agree to the fee and you cannot provide a free alternative, document that position clearly. Do not simply let the matter lapse.

Step 4: locate and compile the personal information

This is the step that takes the longest and where most businesses run into difficulty.

Search comprehensively. Personal information about an individual may be held in:

  • Your customer relationship management (CRM) system or client database.
  • Email correspondence — including internal emails that mention the individual.
  • Paper files, scanned documents, or archived records.
  • Accounting or invoicing software.
  • Call recordings or chat logs.
  • Notes made by staff about their interactions with the customer.
  • Information held by third-party contractors or processors acting on your behalf.

That last category is important. If a third party holds personal information on your behalf — for example, a cloud storage provider, an outsourced call centre, or a payroll processor — you may need to retrieve information from them as part of your response. Start that process early.

Do not include personal information about anyone other than the person who made the request. If a document contains information about multiple individuals, consider redacting the third-party information before providing it.

Step 5: provide access within a reasonable time

The Privacy Act 1988 (Cth) requires you to respond within a reasonable period. The OAIC's guidance on APP 12 indicates that in most cases a reasonable period will not exceed 30 calendar days.

If you need more time — because the request is complex, the volume of information is large, or you are waiting on a third party — contact the individual promptly, explain the delay, and give them a revised timeframe. Do not simply miss the 30-day mark without communicating.

Format

Wherever practicable, provide the information in the format the individual asked for. If they asked for a hard copy, provide a hard copy. If providing the requested format is genuinely impractical — for example, you do not have the means to print a large volume of records, or the costs are disproportionate — you may provide an electronic copy and explain why.

Step 6: if you need to refuse (or partially refuse) the request

APP 12 sets out specific grounds on which you may refuse to give access to personal information. Refusal is not a broad discretion — it must be grounded in one of these categories:

  • Giving access would pose a serious threat to the life, health, or safety of any individual, or to public health or safety.
  • Giving access would have an unreasonable impact on the privacy of other individuals.
  • The request is frivolous or vexatious.
  • The information relates to existing or anticipated legal proceedings between you and the individual, and would not be accessible through the discovery process in those proceedings.
  • Giving access would reveal your intentions in relation to negotiations with the individual in a way that would prejudice those negotiations.
  • Giving access would be unlawful.
  • Denying access is required or authorised by or under an Australian law or a court order.
  • You have reason to suspect that unlawful activity, or misconduct of a serious nature, relating to your functions has been, is being, or may be engaged in, and giving access would prejudice the taking of appropriate action.
  • Giving access would be reasonably likely to prejudice one or more enforcement-related activities conducted by, or on behalf of, an enforcement body.
  • Giving access would reveal evaluative information generated within the entity in connection with a commercially sensitive decision-making process.

Before refusing entirely, consider whether partial access is possible — for example, by redacting the information that attracts the ground for refusal while providing the rest.

If you use an intermediary — such as a medical professional where the information is sensitive health data — access may be given via that intermediary rather than directly.

If you refuse, write to the individual. You must notify them of the refusal and provide a written explanation of the grounds relied on. The individual then has the right to make a complaint to the OAIC if they are not satisfied with your response.

Privacy access requests look simple on paper. In practice, they raise questions that can be difficult to resolve without legal input: Is your business actually covered by the Privacy Act 1988 (Cth)? Does a specific refusal ground apply to the information at hand? Are you at risk of a complaint?

An Artificer Legal privacy practitioner can assist you with:

  • Coverage assessment — confirming whether the Privacy Act applies to your business and which provisions are most relevant.
  • Process design — drafting an internal access request procedure so your team knows exactly what to do when the next request arrives, without needing to reinvent the process each time.
  • Scope and compilation advice — guiding you through what you are obliged to locate, including data held by third-party processors.
  • Refusal ground analysis — reviewing whether a specific ground applies and helping you draft the required written explanation in a way that is legally defensible.
  • OAIC complaint response — if a complainant escalates to the OAIC, representing your business through the conciliation or investigation process.

Having a documented response procedure in place before a request arrives makes the whole process faster and significantly reduces the risk of a misstep that turns a routine request into a formal complaint.

The single factor most likely to determine your outcome

The step that determines whether a privacy access request is resolved cleanly or escalates is not the legal analysis — it is speed of communication at every stage. Businesses that confirm receipt promptly, clarify scope quickly, advise of any fee upfront, and notify the individual if more time is needed resolve the overwhelming majority of requests without incident. Businesses that let requests sit, miss the practical 30-day window, or issue a refusal without a written explanation are the ones that end up in front of the OAIC.

To summarise: confirm you are covered by the Privacy Act; verify the requester's identity and the scope of their request; advise of any fee upfront and get agreement; locate all personal information your business and its processors hold about that individual; provide access within a reasonable time (generally within 30 days) in the format requested where practicable; and if you refuse, ground the refusal in one of the specific categories in APP 12 and put it in writing.