[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-239048-105":53,"doc-detail-239048-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","the-definition-of-personal-information-research-paper-for-the-office-of-the-australian-information-commissioner-17-february-2020","The Definition of Personal Information - Research Paper for the Office of the Australian Information Commissioner - 17 February 2020","","The research paper examines how the Privacy Act’s definition of “personal information” shapes the legal boundaries of what is regulated and protected in Australia. It argues that current definitions lack certainty for technical data and fail to address privacy harms arising from individuation, including tracking, profiling, and targeting without knowing a person’s identity. The paper proposes amending the Act to incorporate a modern definition of “identifiable,” supported by a test covering surveillance, location, contact, targeting, profiling, and linkage to related data, plus clarifying changes to “de-identified.”",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/the-definition-of-personal-information-research-paper-for-the-office-of-the-australian-information-commissioner-17-february-2020/239048/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/the-definition-of-personal-information-research-paper-for-the-office-of-the-australian-information-commissioner-17-february-2020/239048.png","ImageObject",442,249,{"name":88,"@type":89},"Stanley","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-22","2026-09-11",true,{"@type":98,"interactionType":99,"userInteractionCount":9},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"Why does the paper focus on the definition of “personal information” in Australia’s Privacy Act?","Question",{"text":108,"@type":109},"The definition determines the boundaries of what privacy law regulates and what is protected. It is therefore a threshold legal issue for the operation of privacy law in Australia.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"What shortcomings does the paper identify in the current definition for the digital economy?",{"text":113,"@type":109},"It states the definition lacks certainty for technical data and does not clearly include inferred data. It also argues that current approaches to “de-identified” fail to consider privacy risks from individuation and attribute disclosure involving third parties.",{"name":115,"@type":106,"acceptedAnswer":116},"What amendment does the paper recommend for the concept of “identifiable”?",{"text":117,"@type":109},"The paper recommends incorporating a definition under which information is identifiable if it can be identified or discerned as an individual distinct from others, regardless of whether identity can be ascertained or verified. It further suggests a test based on whether an individual or a linked device could be surveilled, tracked, monitored, located, contacted, targeted, profiled, or linked to other data.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},239048,1790080719,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":76,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":140,"read_time":141},2336477405376,"https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0","The Definition of Personal Information  \nResearch Paper for the Office of the Australian Information Commissioner  \n17 February 2020  \nWe know privacy inside out.  \nExecutive Summary  \nData is the lifeblood of the digital economy, and will increasingly power decision-making in all sectors of the economy.  \nRobust data protection regulation is necessary to achieve both consumer protection outcomes, and consistency of the playing field for industry. It will therefore be critical to ensure that the Privacy Act remains fit for its purpose of enabling effective regulation of personal information handling, in line with community and business expectations.  \nThrough its Digital Platforms Inquiry, the ACCC found that the current definition of ‘personal information’ suffers from a lack of certainty around its coverage of technical data. The OAIC also raised the issue of whether inferred data is within scope, while a multiplicity of stakeholders expressed concerns that the Privacy Act – and in particular, the definition of‘personal information’ -was not keeping up with the realities of the digital economy.  \nWhether or not any particular piece of data meets the definition of ‘personal information’ is a threshold legal issue for the operation of privacy law in Australia: the definition of ‘personal information’ determines the boundaries of what is regulated, and what is protected. Understanding the scope of what is meant by ‘personal information’ – and ensuring that that definition remains fit for purpose – is therefore a critical endeavour in privacy jurisprudence.  \nThe challenges posed to the scope and reach of privacy laws come from many different directions: new technologies, new interpretations arising from case law, the increasing risks of re-identification, exponential growth in computing power, advances in fields like data analytics and cryptography, the phenomenon of data breaches, the influence of global debates, and new directions in statute law internationally.  \nThrough the current definition of ‘personal information’, the Privacy Act regulates conduct only when a person is identifiable. However privacy harms can also arise from individuation:  \nthe ability to disambiguate or ‘single out’ a person in the crowd, even if that individual’s‘identity’ is not known. This poses a fundamental challenge for current privacy legal frameworks.  \nFrom the digital breadcrumbs we leave behind in the form of geolocation data shed from our mobile devices, to the patterns of behaviour we exhibit online as we browse, click, comment, shop, share and ‘like’, we can be tracked. Tracked, traced, monitored, surveilled; then profiled; and finally targeted …all without the party doing the tracking, profiling or targeting needing to know ‘who’we are.  \nThe digital environment has turned on its head the assumption that identifiability – in the sense of knowing a person’s ‘identity’ - is only vector for privacy harm. Individuation must be anticipated by privacy laws as well.  \nThese contemporary challenges lead us to conclude that the definition of ‘personal information’ in the Privacy Act no longer meets the needs of a privacy legal framework suitable for the digital age. The current definitions of ‘personal information’ and ‘de-identified’in the Privacy Act fail to consider the privacy risks posed by individuation, or by attribute disclosure involving third parties.  \nGlobally, other jurisdictions have more modern definitions, which clearly anticipate device identifiers , online identifiers and location data being used to identify – or at least ‘single out’ -individuals. Some privacy laws are broadening out the notion of ‘identifiability’ (or even abandoning it altogether) as the threshold element of their definition.  \nSo as to enable clarity and consistency in the application of privacy law, and to protect against the potential privacy harms enabled by individuation, this Research Paper concludes that the Privacy Act should be amended, to incorpora","cbCainblw9NCAZOT","https://ap.wps.com/l/cbCainblw9NCAZOT","pdf",952885,79,"English","# Why definitions matter\n## Is the definition fit for purpose?","[{\"question\":\"Why does the paper focus on the definition of “personal information” in Australia’s Privacy Act?\",\"answer\":\"The definition determines the boundaries of what privacy law regulates and what is protected. It is therefore a threshold legal issue for the operation of privacy law in Australia.\"},{\"question\":\"What shortcomings does the paper identify in the current definition for the digital economy?\",\"answer\":\"It states the definition lacks certainty for technical data and does not clearly include inferred data. It also argues that current approaches to “de-identified” fail to consider privacy risks from individuation and attribute disclosure involving third parties.\"},{\"question\":\"What amendment does the paper recommend for the concept of “identifiable”?\",\"answer\":\"The paper recommends incorporating a definition under which information is identifiable if it can be identified or discerned as an individual distinct from others, regardless of whether identity can be ascertained or verified. It further suggests a test based on whether an individual or a linked device could be surveilled, tracked, monitored, located, contacted, targeted, profiled, or linked to other data.\"}]","The Definition of Personal Information - Research Paper for the Office of the Australian Information Commissioner - 17 February 2020 | PDF",1789142919,28]