Checklist - Agency: preparing a public interest direction or code of practice
Read the document below or download it here Checklist - Agency: preparing a public interest direction or code of practice, updated December 2022
A checklist to assist agencies with the process of preparing a public interest direction or code of practice under the Privacy and Personal Information Protection Act 1998 and/or the Health Records Information Privacy Act 2002. This checklist outlines the preliminary steps an agency should undertake before seeking advice from the IPC.
Issues/Actions/Questions |
Status |
Comments |
---|---|---|
Have you discussed the project or program with your agency’s privacy contact officer or legal unit? | Yes No |
Your privacy contact officer or legal unit may be able to offer you valuable insight or guidance on the privacy impacts of the project/program. |
Do you have a clear understanding of how personal or health information will be collected, used, disclosed and/or accessed, and stored/retained during the project/program?
|
Yes
|
Questions to consider when designing your project/program include:
In considering these questions you may find it helpful to create a flow chart of how information will be used during the program. You may also find it useful to develop a work flow of how information will flow and to whom. |
Have you considered whether a mechanism already exists to undertake the program or project? | Yes No |
This could include:
|
Have you undertaken a Privacy Impact Assessment? | Yes No |
A Privacy Impact Assessment (PIA) is an important part of the project design process that assists compliance with privacy obligations. A robust PIA process will assist your agency to develop a strong business case for the proposed Code of Practice or Public Interest Direction. You can find more information on undertaking a PIA here. |
Has your agency developed a response to the recommendations of the PIA? |
Yes
|
A PIA will identify potential privacy risks and make recommendations on how your agency can address these risks. The IPC recommends that agencies carefully consider the recommendations from the PIA and prepare a response outlining how the agency will mitigate the risks identified. |
Drafting your Code of Practice or Public Interest Direction
The following is a suggested guide to the format and content of a Code or Direction.
Section |
Content |
---|---|
Overview | Details the provision under which the Code or Direction is made. |
Public Interest | Details the public interest that will be served/achieved by the making of a Code or Direction |
Interpretation/Definitions | Define any words or phrases used in the Code or Direction that may not carry the ordinary dictionary meaning or that are intended to have a particular meaning. You should include any particular definitions that are specific or particular to your Code or Direction. |
Scope/Information covered |
Define the scope of the Code or Direction including:
|
Objectives/Purpose | Outline the objectives or purposes that are being achieved by the making of the Code or Direction. |
Exemptions or Modification |
Detail the changes being made to the Information Protection Principles (IPPs) or Health privacy principles (HPPs). These may include:
|
Reporting and Auditing |
The Code or Direction should indicate the processes that will be followed in the event of a breach of privacy, including specifying the process and timeframes for notifying the Privacy Commissioner. Include any proposed mechanism for an annual report to be provided to the Privacy Commissioner in relation to:
In some circumstances it may be appropriate to include a clause requiring an agency to undertake an audit of compliance with the Code or Direction. |
Review or Expiry |
Although a Code does not have an expiry date, it should contain a clause requiring it to be reviewed after a specified period and at regular intervals thereafter. A Direction must include an expiry date. A Direction is a short term instrument and generally operates for a period of between 12 months to three years. |
Other guidance and information on Codes and Directions
- Guide - Seeking a Public Interest Direction under NSW privacy laws
- Public Interest Directions
- Health Public Interest Directions
- Privacy Codes of Practice
- Privacy Governance Framework
- Guidance on the preparation and assessment of Privacy Codes of Practice under the PPIP Act and HRIP Act
For more information
Contact the Information and Privacy Commission NSW (IPC):
Freecall: 1800 472 679
Email: ipcinfo@ipc.nsw.gov.au
Website: www.ipc.nsw.gov.au