Australian Human Rights Commission
Human Rights in the Digital Age: Additional Material Submitted to the UN Global Digital Compact, 30 April 2023
Privacy Safety Regime which utilises concepts from product
intervention powers and product safety interventions, proposing
options that would allow governments and regulators to stop or limit
obviously harmful uses of data as well as a process for regulators to
proactively restrict and test new harmful practices as they evolve.14
29. While the Working Paper is specific to Australia, the Commission would call
upon the Envoy to consider how similar models may be applicable, or
could be adapted, to inform the better protection of data globally.
Recommendation 1: Countries must consider models for protecting data
and personal information online which do not place the primary onus on
individuals to actively protect their personal information.
3.2
Review of existing legislative frameworks
30. In 2023, the Australian Government Attorney-General’s Department
released the final report of its review of the Privacy Act 1988 (Cth) which
considered whether Australia’s privacy legislation was fit for purpose. This
review recognised that Australians now live much of their lives online,
where their information is collected and used for a myriad of purposes in
the digital economy.
31. The Privacy Act 1988 (Cth) (Privacy Act) is a key legislative protection of
individuals’ personal information in Australia. The 13 Australian Privacy
Principles (APPs) are structured to reflect privacy obligations across the
information lifecycle, as entities collect, hold, use, disclose, and destroy or
de-identify personal information. The APPs are legally binding principles,
which provide entities with the flexibility to take a risk-based approach to
compliance based on their particular circumstances, including size,
resources and business model, while ensuring the protection of individuals’
privacy.
32. In considering how best to protect data, proactive reviews of key privacy
legislation is essential. Countries must regularly review their key pieces of
privacy legislation to ensure it is modern, fit for purpose and drafted in a
technology neutral manner.
Recommendation 2: Countries should regularly engage in consultative
reviews of the legislation which regulates privacy and data. Such
7