Skip to main content

Data protection law, regulators and Indigenous data sovereignty: HSC Enterprise Computing Data Science

Syllabus dot point

“Investigate the legal issues surrounding data collection and handling, including legislation, authorities responsible for data protection and data sovereignty of Aboriginal and Torres Strait Islander Peoples”

HSCEnterprise ComputingData Science8 min read

Quick answer

The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles govern personal information, with breaches notified under the Notifiable Data Breaches scheme and enforcement by the OAIC. NSW agencies follow the PPIP Act and the HRIP Act, overseen by the IPC. Indigenous data sovereignty gives Aboriginal and Torres Strait Islander peoples the right to govern data about them, guided by Maiam nayri Wingara and CARE principles.

Jump to a section
  1. What this dot point is asking
  2. The answer
  3. Practice questions

What this dot point is asking

You need to name the laws that govern data collection and handling, the authorities that enforce them, and explain the data sovereignty of Aboriginal and Torres Strait Islander Peoples. Answers score well when they apply the right law to the scenario rather than listing every Act.

The answer

Key legislation

Law What it covers
Privacy Act 1988 (Cth) Personal information handled by Australian Government agencies and organisations with turnover above $3 million (plus some small businesses such as health providers). Contains the 13 Australian Privacy Principles (APPs) on open management, collection, use and disclosure, cross-border disclosure, data quality, security, access and correction.
Notifiable Data Breaches scheme (part of the Privacy Act since 2018) Organisations must notify affected individuals and the OAIC of breaches likely to cause serious harm.
Privacy and Personal Information Protection Act 1998 (NSW) Personal information held by NSW public sector agencies, councils and universities.
Health Records and Information Privacy Act 2002 (NSW) Health information held by NSW public and private organisations.
Copyright Act 1968 (Cth) Ownership of creative works and compilations, including many datasets and databases.
Spam Act 2003 (Cth) Commercial electronic messages need consent, identification and an unsubscribe option.

The Privacy Act has been amended over time; changes passed in 2024 strengthened enforcement and added a statutory tort (a right to sue) for serious invasions of privacy. NSW also runs a mandatory data breach notification scheme for public sector agencies.

Authorities responsible for data protection

  • Office of the Australian Information Commissioner (OAIC): regulates the Privacy Act, investigates complaints and breaches, and can seek penalties.
  • Information and Privacy Commission NSW (IPC): oversees NSW privacy and freedom of information laws.
  • Australian Communications and Media Authority (ACMA): enforces the Spam Act.
  • Australian Cyber Security Centre (ACSC): gives cybersecurity advice and incident support (an adviser, not a privacy regulator).

Data sovereignty of Aboriginal and Torres Strait Islander Peoples

Indigenous data sovereignty is the right of Aboriginal and Torres Strait Islander peoples to govern the creation, collection, ownership, access and use of data about their peoples, communities, lands and knowledge.

  • The Maiam nayri Wingara Indigenous Data Sovereignty Collective's principles assert rights to control the data ecosystem, to data that is relevant and contextual, to data that supports self-determination, and to data structures that are accountable to Indigenous peoples.
  • The international CARE principles: Collective benefit, Authority to control, Responsibility, Ethics.

In practice: consult and partner with communities, share decision-making about what is collected and how it is analysed, avoid deficit-only reporting, store data appropriately, and return benefits to communities.

Worked example

A fitness app company (turnover $20 million) stores users' heart-rate data on servers in another country.

  1. Law: the Privacy Act applies because turnover exceeds $3 million, and health information is sensitive information requiring consent to collect.
  2. APPs: it must disclose the overseas storage in its privacy policy and take reasonable steps to ensure the overseas recipient protects the data (cross-border disclosure principle).
  3. Security: encrypt the data and restrict access.
  4. Breach: if the servers are hacked and harm is likely, notify users and the OAIC.
Common traps
Citing US or EU law as Australian law
GDPR applies to businesses dealing with EU residents; answer with Australian law first.
Saying the Privacy Act covers every business
Most small businesses under $3 million turnover are exempt unless an exception applies.
Treating data sovereignty as only about location
It is about who governs data, not just where it is stored.

Practice questions

Original practice questions graded from foundation to exam level, each with a full worked solution. Try them before revealing the solution.

foundation3 marks
Name the law, principle set and authority that apply when a large Australian retailer collects customers' personal information.
Show worked solution →
  • Law: the Privacy Act 1988 (Cth).
  • Principles: the 13 Australian Privacy Principles, covering collection, use and disclosure, data quality, security, access and correction.
  • Authority: the Office of the Australian Information Commissioner (OAIC).

Marking guide: 1 mark each.

core4 marks
A company discovers that a hacker has copied a database of customer names, addresses and credit card numbers. Explain its obligations under the Notifiable Data Breaches scheme.
Show worked solution →

This is likely an eligible data breach: personal information was accessed without authorisation and, because financial details are included, it is likely to cause serious harm (fraud, identity theft).

The company must promptly assess the breach (within 30 days if it is unsure), take steps to contain it, and notify both the affected individuals and the OAIC. The notification must describe the breach, the kinds of information involved and recommended steps people should take, such as cancelling cards and watching for scams.

Marking guide: 1 mark for identifying an eligible breach, 1 mark for serious harm reasoning, 2 marks for notification obligations and content.

exam6 marks
A government agency plans to build a health dashboard using data about Aboriginal communities in western NSW. Explain the legal requirements and the principles of Indigenous data sovereignty that should guide the project.
Show worked solution →
Legal requirements
As a NSW public sector agency, it must comply with the Privacy and Personal Information Protection Act 1998 (NSW) and, because the data is health information, the Health Records and Information Privacy Act 2002 (NSW). It must collect only what is necessary, tell people how the data will be used, keep it secure, allow access and correction, and notify under the NSW mandatory data breach scheme if a serious breach occurs. The Information and Privacy Commission NSW oversees compliance.
Indigenous data sovereignty
Beyond the law, the communities have the right to govern data about them. Following the Maiam nayri Wingara principles and the CARE principles, the agency should involve community-controlled health organisations in deciding what is collected and how it is interpreted (authority to control), ensure the dashboard delivers benefits the communities identify (collective benefit), present data in context so it does not reinforce deficit narratives (ethics), and be accountable to the communities for how the data is used and stored (responsibility).
Why it matters
Past data collection has often been done about Aboriginal peoples rather than with them. Sharing control builds trust, improves data quality and makes the dashboard useful for self-determination.

Marking guide: 2 marks for correct legislation and obligations, 3 marks for applying data sovereignty principles, 1 mark for explaining why they matter.

Practise this

Sources & how we know this

ExamExplained