Privacy Act applies to Red Cross
As the Australian Red Cross is a large organisation and a charity, the federal Privacy Act 1988 and the Australian Privacy Principles apply to the organisation. The Act and the Australian Privacy Principles regulate how the privacy laws apply to organisations, what personal information is, and how organisations are meant to protect personal information. More about privacy law in general can be read in our article, Privacy Law in Australia. Specific rules organisations must follow to protect personal information are discussed in our article, Privacy Act Obligations to Protect Clients’ Personal Information.Personal information caught in the breach included sexual risk questions
The Privacy Act 1988 defines personal information as information that can be used to identify a person. This includes a person’s name, address or their occupation. The information in the file which was breached included the following:- Full names;
- Dates of birth and gender;
- Addresses;
- Phone numbers and email addresses; and
- A series of yes / no questions used by the Australian Red Cross to determine donor risk.