

A recent Determination issued by the Office of the Australian Information Commissioner (OAIC) looks at the Privacy Act’s employee record exemption. Plus it considers whether aggravated damages should be awarded.
(Aggravated damages are only available where, for example, behaviour has been high-handed, malicious, insulting or oppressive – quite a high bar for poor behaviour that is not often reached, resulting in very few aggravated damages awards over the years).
For more guidance on how not to deal with ex-employee’s personal information, and to protect your organisation from damages awards, read on….
The complainant worked for Fortrend but resigned on 18 November 2022. While working out their 30-day notice period, the complainant reported experiencing hostility from the Managing Director. This included the Managing Director making threats in a phone call to the complainant saying they would ‘go to war.’ The complaint took stress leave, with a medical certificate provided by a psychiatrist.
While the complainant was on stress leave, the Fortrend Managing Director continued to contact the complainant in a way that the complainant found to be stressful and threatening. A further period of stress leave was taken based on a second medical certificate (dated 9 December 2022).
The main issue arose after the complainant left. According to the complainant, the Managing Director informed clients that the complainant had a nervous breakdown and was unfit for work, referencing medical documentation as proof of the claim. To support that claim, the Managing Director allegedly sent the complainant’s medical certificate dated 9 December 2022 to a client.
Fortrend denied breaching privacy laws or disclosing the Medical Certificate and, amongst other defences, relied on the employee record exemption to argue that if there had been any disclosure of the medical certificate, it was exempt under the Privacy Act.
The Commissioner preferred the version of events provided by the complaints who provided a detailed account of what occurred, supported by contemporaneous file notes and emails. In contrast, the respondent was found to have provided unreliable information and few details about the events surrounding the disclosure.
The Privacy Commissioner found that Fortrend (via the acts of its CEO) had interfered with the complainant’s privacy by disclosing the complainant’s Medical Certificate to the complainant’s client. The disclosure was for an unrelated secondary purpose and in circumstances where the complainant did not consent and the exceptions in APP 6.2 did not apply.
Perhaps not unsurprisingly in the circumstances, the Commissioner virtually threw the book at Fortrend. It required Fortrend to:
The requirement to retain an independent expert to review and report on Fortrend’s privacy policies, procedures and processes, including privacy training, and to act on their recommendations can be quite onerous. In effect, the organisation is at the mercy of the independent expert and their view on what privacy policies, procedures and processes should be implemented.
Section 7B(3) of the Privacy Act provides that an act done, or practice engaged in, by a private sector employer, is exempt if the act or practice is directly related to:
The OAIC found the medical certificate was an employment record – having been created for the purposes of the complainant’s employment. So, the issue was whether the respondent’s alleged disclosure of the complainant’s medical record was directly related to the employment relationship between the complainant and the respondent.
Not surprisingly, the OAIC also found that the disclosure was not an act or practice directly related to a current or former employment relationship:
… there does not appear to have been any employment related purpose for disclosing the Medical Certificate to the Client, I do not consider the disclosure was related to the respondent’s employment relationship with the complainant.
In their submissions, the complainant stated that:
It was a humiliating experience to have to explain to my clients that I was not having a “mental breakdown” as described to them by [Managing Director] and to then have to further discuss my private medical certificate.
The complainant also submitted in a statutory declaration that the impact went well beyond the actual disclosure:
It was a serious and deliberate abuse of power designed to inflict maximum harm and embarrassment to me by taking advantage of his knowledge of my private medical situation and information. He further exacerbated this by the untrue statement that I had suffered a nervous breakdown. His conduct was deeply hurtful and humiliating. It has caused both personal and professional distress, including anxiety and depression which I continue to deal with to this day. This is confirmed by the letter from my treating psychiatrist attached.
In assessing the quantum of non-economic loss, the Commissioner took the following Determinations into consideration:
Based on the prior cases, the complainant’s statutory declaration and the letter from their psychiatrist, the Commissioner awarded $10,000 in non-economic loss.
The complainant sought $15,000 by way of aggravated damages.
The award of aggravated damages is quite rare and reserved for particularly poor behaviour or serious breaches.
Circumstances where aggravated damages may be awarded include where:
In determining whether to award aggravated damages, the Commissioner took the following Determinations into consideration:
Ultimately, the Commissioner awarded $3,500 – the highest award for aggravated damages to date referring to the following factors relevant to the decision:
The privacy wheels continue to turn slowly.
Some other points worth noting:
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.