-
Examples of what counts — and what does not
- A name and email address on a mailing list
- A customer account with order history
- CCTV footage covering a shop floor or entrance
- IP addresses and device identifiers linked to a user profile
- A job application with a resume and referee details
- Visitor sign-in logs at a physical premises
- Telstra's mobile network metadata — the "about" requirement in practice
- Truly anonymised and aggregated data
- A sole trader's ABN and business email
- Sensitive information: a higher-protection subset
- The pattern across the examples
- Which businesses must comply with the Privacy Act
- How Artificer Legal can help you assess your own situation
- Whether the information is about the person or merely connected to them
Every Australian business that collects names, emails, CCTV footage, or support records is handling personal information — often without stopping to ask whether a particular piece of data actually meets the legal definition. That question matters, because the answer determines whether the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to how you handle it.
Under s 6 of the Privacy Act 1988 (Cth), personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable — whether the information is true or not, and whether it is recorded in a material form or not. Two things follow from that definition. First, the information must be about a person, not merely linked to them in some incidental way. Second, identification does not have to be certain — it is enough that the person is reasonably identifiable, including through combination with other data you or someone else holds.
The examples below illustrate how this rule operates across situations small and medium businesses encounter regularly. They move from the clearest cases to the more contested ones.
Examples of what counts — and what does not
A name and email address on a mailing list
The facts. A customer subscribes to your newsletter using their first name and personal email address. You store both in your email marketing platform.
Why it counts. The name identifies the individual directly. The email address, which typically contains a person's name or a unique handle, reinforces that identification. Together they are unambiguously personal information. The fact that the customer gave you this information willingly, or that it appears elsewhere online, does not change the classification.
A customer account with order history
The facts. Your e-commerce system records each customer's name, delivery address, payment token reference, and purchase history against a unique account ID.
Why it counts. Each element — name, address, account ID — individually identifies or contributes to identifying the individual. Order history is information about that person's behaviour and preferences. The whole record, and each component that points back to an identifiable person, is personal information.
CCTV footage covering a shop floor or entrance
The facts. You run a retail store and have cameras recording the entrance and point-of-sale area. The footage captures customers' faces and body images.
Why it counts. Footage that depicts an identifiable person is information about that person. The individual does not need to be named anywhere in the footage — if their physical appearance allows them to be identified (including by combining the footage with other records, such as a loyalty account or a visitor log), it is personal information. Signage, storage limits, and access controls all become relevant once the footage is classified this way.
IP addresses and device identifiers linked to a user profile
The facts. Your website analytics platform records the IP address and device ID of each visitor. For logged-in users, these are tied to their account.
Why it counts. An IP address or device ID on its own may not identify a person. But once it is linked to a user account — which contains a name, email, and order history — the combination makes the individual reasonably identifiable. That linkage brings the technical identifiers within the definition of personal information.
Counter-factual. If you collect only aggregated, anonymised analytics (for example, a total session count with no ability to drill down to an individual), that data is not personal information, because no individual is reasonably identifiable from it.
A job application with a resume and referee details
The facts. A candidate applies for a role and provides their resume, covering letter, qualifications, and the names and contact details of two referees.
Why it counts. Every piece of that application is about identifiable individuals — the applicant and the referees. It is personal information from the moment it arrives in your inbox, regardless of whether the candidate is ultimately hired. Note that the Privacy Act contains a limited exemption for certain employee records once an employment relationship exists, but that exemption does not apply to the recruitment stage.
Visitor sign-in logs at a physical premises
The facts. You ask visitors to record their name, company, mobile number, and arrival time in a paper register or digital kiosk.
Why it counts. The register identifies each visitor by name and, in most cases, their phone number. An arrival time attached to a name also reveals something about the person's movements and associations. All of it is personal information, which means it needs to be collected only for a purpose you would disclose to the visitor, stored securely, and not kept longer than necessary.
Telstra's mobile network metadata — the "about" requirement in practice
The facts. In Privacy Commissioner v Telstra Corporation Ltd [2017] FCAFC 4, a journalist asked Telstra for all the metadata it held about him, including network data such as cell-tower location records, IP addresses logged by the network, and URL information. Telstra refused access to the network metadata.
Why the Court drew the line here. The Full Federal Court confirmed that the words "about an individual" in the definition of personal information have substantive operation. Information does not become personal information merely because an organisation creates it in order to provide a service to an identifiable person. The network metadata recorded how Telstra's infrastructure performed — it was not, in the Court's view, information about the journalist. The decision is a useful reminder that linkage to an identifiable person is necessary but not sufficient: the information must also say something about that person.
Truly anonymised and aggregated data
The facts. You export a report from your CRM showing that 32 per cent of repeat customers made a second purchase within 60 days. No individual's data appears in the report, and the underlying dataset has been irreversibly de-identified.
Why it does not count. If no individual is reasonably identifiable from the data — neither directly nor by combining it with other datasets — it is not personal information. Aggregated statistics of this kind sit outside the Privacy Act's reach. The critical word is "irreversibly": pseudonymised data, where the original identifiers could be reconstructed, remains personal information.
A sole trader's ABN and business email
The facts. You record the ABN and the email address (e.g., jane@janesbakery.com.au) of a sole trader you deal with as a supplier.
The borderline. A company's ABN is not personal information — it identifies the legal entity, not an individual. But a sole trader's ABN, trading name, and contact email can together identify that sole trader as an individual person. Where the business details are inseparable from the identity of the person running the business, they are likely to be personal information. This is one of the less intuitive outcomes of the definition, and worth bearing in mind when you maintain a supplier register.
Sensitive information: a higher-protection subset
Some personal information attracts additional obligations under the APPs. Under s 6(1) of the Privacy Act 1988 (Cth), sensitive information includes:
- health information (medical records, disability information, health insurance details)
- genetic information
- biometric information used for automated verification (facial recognition templates, fingerprint scans)
- racial or ethnic origin
- political opinions or membership of a political association
- religious beliefs or affiliations and philosophical beliefs
- membership of a trade union or professional association
- sexual orientation or practices
- criminal record
You generally need express consent to collect sensitive information, and you must apply a higher standard of protection to how you use and disclose it. If you run a health service — even a small one — you are subject to the Privacy Act regardless of your annual turnover (see below).
The pattern across the examples
The examples above share a consistent structure. Three questions determine whether something is personal information:
- Is there an identifiable individual? Direct identification (by name) is the clearest case, but reasonable identifiability — through combination with other data — also qualifies.
- Is the information about that person? Following Privacy Commissioner v Telstra [2017] FCAFC 4, this is a separate requirement. Data generated for someone or in connection with a service is not automatically about them.
- Is there a real prospect of re-identification? Pseudonymised or coded data that could be re-linked to an individual remains personal information.
Practical takeaways:
- Treat data as personal information if a person could be identified from it alone or in combination with other data you or a third party hold.
- Context shifts the answer: an IP address held in isolation is different from the same IP address logged against a named account.
- De-identification requires irreversible removal of all reasonable linkages — not just deleting a name field.
- Sole trader business details may be personal information even when you think of them as commercial data.
- Sensitive information triggers a higher consent and protection standard; do not collect it unless it is genuinely necessary.
Which businesses must comply with the Privacy Act
Most businesses with an annual turnover of more than $3 million are APP entities and must comply with the Privacy Act and all 13 APPs. Some businesses must comply regardless of their turnover, including private sector health service providers, credit reporting bodies, credit providers, entities that trade in personal information, and businesses that handle Tax File Numbers under the Privacy (Tax File Number) Rule 2015.
Even if you fall below the threshold, customer and partner expectations around privacy have risen sharply. Putting the right framework in place before you need it is significantly easier than retrofitting it after a complaint.
How Artificer Legal can help you assess your own situation
The definition of personal information is deliberately broad and context-dependent. Whether a particular dataset in your business counts — and what obligations follow — depends on how you collect it, what other data you hold alongside it, and who has access to it. That assessment is not always straightforward, particularly for digital identifiers, HR data, and information collected through third-party platforms.
An Artificer Legal practitioner can work through your specific data flows, identify where personal information (and sensitive information) is entering your business, and advise on the documents and practices needed to handle it lawfully. That typically includes reviewing or drafting a privacy policy, privacy collection notices, data processing agreements with vendors, and a data breach response plan — and confirming whether your business falls within the Privacy Act's reach.
Whether the information is about the person or merely connected to them
If a reasonable person looking at the information could work out who it is about — either directly or by combining it with other readily available data — treat it as personal information. That heuristic covers the vast majority of borderline cases. The harder question, highlighted by Privacy Commissioner v Telstra [2017] FCAFC 4, is whether the information says something about that identifiable person or merely records a transaction or system event that happens to be connected to them. Where you are uncertain, the safer course is to apply the Privacy Act's requirements and document your reasoning.
To summarise the key points: personal information under the Privacy Act 1988 (Cth) covers any information or opinion about an identified or reasonably identifiable individual; sensitive information is a protected subset requiring heightened consent and care; the "about an individual" requirement is a substantive element of the definition, not a formality; and de-identification must be irreversible to remove data from the Act's scope. Most businesses collecting names, contact details, online identifiers, CCTV footage, or employment records are handling personal information, and should have the policies and processes in place to reflect that.