Privacy Commissioner - Executed Instrument of Delegation

Read the document below or download it here Privacy Commissioner - Executed Instrument of Delegation October 2023

 

Instrument of Delegation
Privacy and Personal Information Protection Act 1998 (NSW)
Health Records and Information Privacy Act 2002 (NSW)
Public Interest Disclosures Act 2022 (NSW)

I, Sonia Minutillo, Acting Privacy Commissioner, under section 35H of the Privacy and Personal Information Protection Act 1998 (PPIP Act), revoke all previous delegations made under that Act and delegate the exercise and performance of matters arising under, or incidental to the functions, authorities, duties and powers set out in Schedule 1, 2 and 3 to this instrument, to the officers set out in those schedules.

The Privacy Commissioner has such functions as may be conferred or imposed on the Commissioner under the PPIP Act or any other Act: section 36(1), PPIP Act.

This instrument delegates the functions, authorities, duties and powers of the Privacy Commissioner under:

  • the PPIP Act
  • the Health Records and Information Privacy Act 2002 (HRIP Act)
  • the Public Interest Disclosures Act 2022 (NSW) (PID Act)

The delegates may not sub-delegate.

This instrument takes effect from the date it is executed. It consists of this page and 20 pages containing Schedule 1, 2 and 3.

This delegation will continue until revoked notwithstanding the termination of my office as Acting Privacy Commissioner.

 

Sonia Minutillo                                           

Acting Privacy Commissioner

Date: 12 October 2023

 

Instrument of Delegation – Schedule 1

Privacy and Personal Information Protection Act 1998 (NSW)

Section

Description of Function/ Power

Officer

Section 36(2)(a)

Promoting the adoption and monitoring compliance with the information protection principles.

Director Business Improvement

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 36(2)(b)

Preparing and publishing guidelines relating to the protection of personal information and other privacy matters, and promoting the adoption of such guidelines.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Manager, Communications and Corporate Affairs

Section 36(2)(c)

Initiating and recommending the making of privacy codes of practice.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Section 36(2)(d)

Providing assistance to public sector agencies in adopting and complying with the information protection principles and privacy codes of practice and the mandatory notification of data breach scheme.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Section 36(2)(e)

Providing assistance to public sector agencies in preparing and implementing privacy management plans in accordance with section 33, and data breach policies under section 59ZD of the PPIP Act.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 36(2)(f)

Conducting research and collecting and collating information about any matter relating to the protection of personal information and the privacy of individuals.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 36(2)(g)

Providing advice on matters relating to the protection of personal information and the privacy of individuals.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 36(2)(i)

Conducting education programs and disseminating information for the purpose of promoting the protection of the privacy of individuals.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Manager, Communications and Corporate Affairs

Senior Project Officer

Senior Regulatory Officer

Section 36(2)(k)

Receiving, investigating and conciliating complaints about privacy related matters (including conduct to which Part 5 applies).

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Section 36(2)(l)

Conducting inquiries and investigating privacy related matters as the Privacy Commissioner thinks appropriate.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 36(2)(m) Investigating, monitoring, auditing and reporting on a public sector agency's compliance with Part 6A of the PPIP Act, including the agency's data handling systems, policies and practices.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 36(3)

Consulting with Information Commissioner before preparing guidelines concerning limits in relation to the information protection principle set out in section 18 of the PPIP Act (Limits on disclosure of personal information).

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 37

Requiring a person or public sector agency to provide a statement of information or produce a document/ thing or copy of a document.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Director Business Improvement

Section 38

Conducting inquiries and investigations.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 39

Determining the procedure for inquiries and investigations.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 40

Preparing and publishing information digest setting out the nature and source of personal information held by public sector agencies and requiring details relating to the personal information from public sector agencies.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Section 42

Requiring agencies to provide information about compliance arrangements.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Director Business Improvement

Section 45

Receiving and dealing with privacy related complaints and requiring information about a complaint.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Section 46(1)

Conducting a preliminary assessment of privacy related complaint.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Director Business Improvement

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 46(2)

Informing complainant of review process.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Director Business Improvement

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Section 46(3)

Deciding not to deal with complaint if satisfied of certain matters.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 47

Referring complaints for investigation or other action.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 48

Dealing with privacy related complaints and making inquiries and investigations in relation to complaints.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 49

Resolving privacy related complaints by conciliation.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 51

Conducting an inquiry or investigation into general issues or matters raised in connection with the complaint even though the complaint referred or declined.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 54(1)

Receiving an application for internal review.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Section 54(2)

Making submissions on internal review.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 54(3)

Undertaking internal review on behalf of agency and making a report to agency in relation to application for review.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Section 55(6)

Appearing and making submissions in Tribunal proceedings.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Section 59K(5) Requesting further information from a public sector agency about the progress of the assessment of a data breach

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Section 59P(5) Publishing information on the Commissioner's website about how to access the notification made by a public sector agency.

Director, Business Improvement

Manager, Communications and Corporate Affairs

Section 59Z Investigating, monitoring, auditing and reporting on the exercise of a function of 1 or more public sector agencies, including the systems, policies and practices of an agency.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 59ZA(3)(a)-(c) Enter the premises based upon notice issued under Section 59ZA(1) and observe a demonstration of the agency's data handling systems, policies and procedures and inspect documents.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Instrument of Delegation – Schedule 2
Health Records and Information Privacy Act 2002 (NSW)

Section

Description of Function/ Power

Officer

Section 24

Issuing guidelines in respect to access to, and retention and amendment of, health information held by private sector persons for the purpose of assisting them to comply with the Health Privacy Principles.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 42

Receiving privacy related complaints and allowing an extension of time for making a complaint.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Section 43(1)

Making a preliminary assessment of a complaint.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 43(2), (3)

Deciding not to deal with a complaint if satisfied of certain matters and advising complainant of reasons for deciding not to deal with a complaint.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 44(1)

Assessing of complaints, including making inquiries and investigations to determine prima facie case of breach.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 44(2), (3)

If there is no prima facie case, ceasing to deal with complaint and advising complainant of reasons for ceasing to deal with complaint.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 45

Dealing with complaints, considering certain matters and notifying complainant and respondent of outcome.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 46

Resolving complaint by conciliation.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 50(2)

Appearing and making submissions in Tribunal proceedings in relation to an inquiry.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Section 58(a)

Promoting the adoption and monitoring compliance with the Health Privacy Principles and the provisions of Part 4 of the HRIP Act.

Director Business Improvement

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Section 58(b)

Preparing and publishing guidelines relating to the protection of health information and other privacy matters, and to promote the adoption of such guidelines.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 58(c)

Providing assistance to organisations in adopting and complying with the Health Privacy Principles and the provisions of Part 4 of the HRIP Act.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Section 58(d)

Conducting research, and collecting and collating information about any matter relating to the protection of health information and the privacy of individuals.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Section 58(e)

Providing advice on matters relating to the protection of health information and the privacy of individuals.

 

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 58(f)

Receiving, investigating and conciliating complaints about alleged contraventions of the Health Privacy Principles, the provisions of Part 4 or any health privacy code of practice.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Section 59(1)(a)-(c)

Requiring a person or organisation to give a statement of information, or to produce any document or other thing, or to give a copy of any document.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 60

Conducting inquiries and investigations.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Section 61

Determining procedures for inquiries and investigations.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 63

Requiring information about compliance arrangements and demonstrating the means by which the organisation is implementing such arrangements.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 64

Issuing, amending and replacing guidelines.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 65

Referring privacy related complaint to Health Care Complaints Commission if the complaint concerns the professional conduct of a health service provider or a health service that affects the clinical management or care of a person who uses or receives a health service (including a patient)

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 66

Referring privacy related complaint to Commonwealth Privacy Commissioner.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Director Business Improvement

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Section 67

Referring privacy related complaint to other persons or bodies (the relevant authority).

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Regulatory Officer

Regulatory Support Officer

Instrument of Delegation - Schedule 3

Public Interest Disclosures Act 2022 (NSW) 

Section
Description of Function/ Power
Officer
Section 55 and 56 Investigating a voluntary public interest disclosure. 

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Manager Investigation and Review

Manager, Complaints and Proactive Compliance

Senior Project Officer

Senior Regulatory Officer

Legal Officer

Section 57(3) Considering the views of an integrity agency before referring a voluntary public interest disclosure.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice

Section 83 Providing information relating to a public interest disclosure to another agency.

Director Investigation and Reporting

Director, Legal Counsel and Regulatory Advice