Privacy in the Workplace: What Employers Need to Know

two workers looking at desktop monitor. icons of envelope, computer, padlock, text bubble, smartphone and internet globe overlayed in white.

Workplaces collect and use personal information every day. This can include employee records, client information, health information, payroll details, emails, photographs and information generated through workplace technology.

Privacy risks can arise in ordinary HR activities, from recruitment and onboarding through to remote work, workplace monitoring and the end of employment.

For employers, good workplace privacy is not simply about having a privacy policy. It is about understanding what information you hold, why it is collected, who can access it and how it is protected.

What personal and sensitive information do employers handle?

Personal information is information that identifies, or could reasonably identify, an individual.

In the workplace, this might include:

  • names and contact details

  • payroll and employment information

  • performance and conduct information

  • photographs

  • health information

  • recruitment and reference information

  • client or customer records.

Some information is considered sensitive information under the Privacy Act 1988 (Cth), including health information, religious beliefs, sexual orientation and criminal record information. Sensitive information generally attracts additional privacy protections.

The Australian Privacy Principles (APPs) set requirements for organisations covered by the Privacy Act around how personal information is collected, used, disclosed and protected. However, privacy obligations do not apply identically to every employer or every type of information.

For example, the Privacy Act contains an employee records exemption for private-sector employers in certain circumstances. The exemption can apply to personal information directly related to an individual's current or former employment, but it does not mean all employee information is exempt. Information about unsuccessful job applicants and information handled by some third-party service providers can be subject to different requirements.

Good privacy practice starts with understanding what information your organisation holds, why it is needed and who should have access to it.

Email, messaging, social media and workplace technology

Privacy risks are no longer limited to paper files and HR systems.

Employees communicate through email, messaging platforms and social media, while laptops, smartphones, cloud applications and collaboration tools can provide access to large amounts of workplace information.

Employers should consider whether their policies and expectations address:

  • sharing employee or client information through workplace systems

  • use of personal email or messaging accounts

  • social media and workplace conduct

  • access to confidential information

  • use of employer-provided devices and systems.

Fair Work's workplace privacy guidance recommends clear expectations around electronic communications, social media, internet use and employer monitoring technologies.

Privacy can also overlap with workplace conduct. For example, sharing a client's photograph or personal circumstances online could create both privacy and employment-related concerns.

Read more: What is your policy on social media conduct? >

AI tools and workplace privacy

Generative AI tools create another privacy consideration for employers.

Employees may use tools such as ChatGPT and Claude to draft emails, summarise documents, analyse information or assist with workplace tasks. If personal, confidential or commercially sensitive information is entered into an AI tool, that information may be processed by an external service in ways the employee or employer has not properly considered.

Potential risks include:

  • entering employee or client personal information into an AI tool

  • uploading confidential workplace documents

  • sharing commercially sensitive information

  • using AI through personal rather than approved workplace accounts

  • relying on AI-generated information without checking its accuracy.

AI should not be treated as a confidential workplace filing system or an automatically reliable source of workplace relations advice.

Employers should consider whether their existing privacy, confidentiality, information security and acceptable-use policies adequately address AI tools, and whether employees understand what information they can and cannot enter into them.

Read Using AI in the Workplace Comes With Risks >

Workplace monitoring, surveillance and remote work

Technology makes it easier for employers to monitor work activity. Depending on the workplace, this might include:

  • CCTV

  • GPS or location tracking

  • computer or internet monitoring

  • monitoring software

  • access-card records

  • vehicle tracking.

Monitoring can have legitimate purposes, such as workplace safety, security and asset protection. But the fact that technology can collect information does not automatically mean an employer should collect it.

Employers should consider what information is being collected, why it is needed, who can access it and how it will be used.

State and territory surveillance laws may also apply, particularly to CCTV, audio recording and other forms of employee surveillance. The requirements differ across Australia, so appropriate advice may be needed before introducing or significantly changing surveillance arrangements.

Remote and hybrid work creates additional considerations. Employees may access confidential information from home, use mobile devices or participate in online meetings outside the controlled workplace environment. Workplace policies should reflect these arrangements rather than assuming work always happens in the office.

Managing access and the end of employment

Privacy also depends on who can access workplace information.

Access to HR systems, payroll information, client records, shared drives and other confidential material should be appropriate to an employee's role. Access may need to change when an employee changes roles or responsibilities.

The same applies when employment ends.

Employers may need to consider access to email and other systems, workplace devices, cloud applications and client information, while also determining what employee and recruitment information needs to be retained.

Good privacy practice therefore needs to work alongside ordinary HR processes such as onboarding, role changes and offboarding.

Policies, training and data breaches

A workplace privacy policy can establish expectations about how personal information is collected, used, stored and disclosed. For organisations covered by the APPs, APP 1 requires an up-to-date privacy policy explaining how personal information is managed.

But having a policy is only part of the picture.

Employees and managers need to understand their responsibilities, particularly when handling sensitive information, using workplace technology or working remotely.

Privacy breaches can happen through lost devices, emails sent to the wrong recipient, unauthorised access or inappropriate disclosure of information.

For organisations covered by the Privacy Act, the Notifiable Data Breaches (NDB) scheme may require notification where an eligible data breach is likely to result in serious harm. Not every data breach is automatically notifiable.

Where a breach involves sensitive information or potentially significant consequences, specialist privacy, legal or technical advice may be appropriate.

Privacy is an HR issue, not just an IT issue

Many workplace privacy risks arise from everyday HR and people practices: recruitment, payroll, performance management, social media, AI, remote work, monitoring and employee exits.

Employers should understand:

  • what personal and sensitive information they collect

  • why they collect it and who needs access

  • how technology affects privacy

  • whether their policies reflect actual workplace practices

  • whether employees understand their responsibilities

  • what happens if information is disclosed or compromised.

Good privacy practice means making sure your policies, systems and people practices work together.

Workplace Plus supports employers with the development, implementation and review of HR policies, processes, employment contracts and other HR documentation. We also provide HR advice, leadership coaching and team training.

For more information, contact us today.

Previous
Previous

Using AI in the Workplace Comes With Risks

Next
Next

Casual Employment Changes: What Employers Need to Know