What’s in a ‘fair and reasonable’ test?
SHARE THIS ARTICLE
Proposed amendments to the Privacy Act 1988 (Cth) may legislate stricter data-keeping and breach reporting requirements that could have significant implications for HR teams.
According to LegalVision practice leader Phoebe Chester, the proposed changes address industry shifts sparked by AI, wearable technology, connected devices, increased rates of data breaches, and more refined identity theft and scams, prompting a renewed consideration of how and when businesses are collecting and using personal information.
One of the prominent features of the proposed reforms is the application of a new test to replace existing data collection, use and disclosure rules, with the new mandate dictating “all data handling must be lawful, fair, and reasonable in the circumstances”.
Should this be passed, businesses would be facing the biggest privacy-related operational shift since the laws began, causing the need for more objective and direct privacy consent criteria, data minimisation to what is necessary for immediate function, and mandatory de-identification obligations.
Regarding small business practice, Chester explained that some would not be covered by the act unless an exception applies, and that the biggest impact would be on those already regulated, “such as those providing health services or trading in personal information, or supplying services to larger clients that push privacy obligations down through contracts”.
Privacy remains one of the top considerations for HR teams due to its sensitive, detailed, and often high-impact nature.
Chester said: “It can include health information, background checks, diversity data, and recruitment materials. AI adds another layer because it can be used to screen candidates or infer personal traits from ordinary workplace data.”
In this way, the risks are also magnified, not just due to the implications of a data breach, but the actual use of candidate or contractor data by AI that is not easily justifiable or identified as “fair and reasonable”.
As such, Chester warned HR teams to be specifically cautious about uploading personal data into public AI tools, and further encouraged employers to prepare for potential legislation by mapping out what employee and candidate information they collect, where it is stored, who has access to it, including external HR, payroll, recruitment and AI platforms.
“They should then remove unnecessary data, tighten access controls, review retention periods and check supplier contracts for security, breach notification and AI-use clauses. HR teams should also update collection notices so candidates and employees understand how their information is used,” Chester said.
“The most practical AI rule is simple: do not put employee, applicant or health information into unapproved AI tools, and keep human review in any decision that affects someone’s job.”
Want to see more stories from trusted news sources?Make HR Leader a preferred news source on Google.