Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.

We respect your Do Not Track preference.

A man asked a company for access to his personal information. In response, the company sent a list of debtors' details, which contained not only personal information about the man, but also about several other people. The employee who sent the information was inexperienced, and did not comply with the usual procedures the company had in place for dealing with access requests.

The company realised that a mistake had been made. It immediately contacted my Office, to let us know that there had been a privacy breach. It also contacted all the people whose details had been inadvertently released, to inform them of the disclosure. The company provided specific training to the employee, and additional training for all staff responsible for handling requests for personal information. It also improved its internal documentation on handling requests for personal information.

The man approached the local newspaper, which wrote a story detailing the company's error. One woman whose details had been included on the list was approached by a journalist. Although she was not featured in the story, she was embarrassed by the fact that details of her debt had ended up in the hands of the media. She complained to my Office about the company's breach of her privacy.

The company formally apologised to her and made a small payment in compensation for the embarrassment she had suffered. She accepted this as a settlement of her complaint.

December 2007

Disclosure of personal information —– company —– privacy breach notification —– settlement —–– Privacy Act 1993, principles 5 and 11