I’m always learning. Even after more than 30 years in HR, there are still parts of employment law that surprise me.
Recently (following requests on from TikTok followers and clients) I spent some time getting my head around two parts of the Privacy Act that don’t come up every day but can make a real difference when you’re managing people. One relates to confidential opinions about employees, and the other is a brand-new requirement around collecting personal information from other sources.
Here are my takeaways in plain English.
Evaluative material, that doesn’t need to be disclosed, has a very narrow definition
Most employers know that employees can request copies of the personal information you hold about them.
What surprised me was how narrow one of the exceptions actually is.
The Privacy Act allows organisations to withhold confidential evaluative material. In practice, this usually means things like confidential referee reports or references that were provided on the understanding they would remain confidential.
For example, if you’re recruiting and you ring a referee who gives you an honest assessment because you’ve assured them their comments will remain confidential, you may be entitled to withhold that information if the candidate later makes a Privacy Act request.
However, this protection generally doesn’t extend to documents created by your own managers or HR staff as part of their normal jobs.
Performance reviews, notes from investigations and disciplinary meetings, manager’s notes and internal assessments are often assumed to be “confidential”, but they won’t automatically fall within this exception simply because they contain opinions.
That’s an important distinction.
There's a new rule about collecting information indirectly
From May 2026, the Privacy Act introduced Information Privacy Principle 3A.
The basic idea is simple. If you collect personal information about someone from another source instead of directly from them, you’re generally expected to let them know.
That doesn’t necessarily mean sending an email every time you speak to a referee or verify a qualification. In fact, there are some practical exceptions.
One is where the person has already been told this might happen.
For example, your employment application form or employee privacy statement might explain that, during recruitment or employment, you may obtain information from referees, previous employers, training providers, medical practitioners (with the employee’s consent), professional registration bodies, credit agencies, government departments or other legitimate sources.
If you’ve already clearly explained what information you may collect, why you’re collecting it, and the individual’s privacy rights, you may not need to notify them again each time you obtain information from one of those sources.
Another exception applies where not notifying the person wouldn’t prejudice their interests.
The Office of the Privacy Commissioner gives the example of collecting an emergency contact’s details from an employee. It’s reasonable to assume the employee has already spoken to their emergency contact, so separately notifying that person generally isn’t necessary.
Find out more about Principle 3A at the Privacy Commissioner website here.
What employers should do now
These changes don’t mean you need to overhaul everything overnight, but they are a good reminder to review your privacy documentation.
I’d suggest checking whether your:
- employment application forms explain where information may be obtained from during recruitment,
- employee privacy statements cover the third parties you may collect information from prior to and during employment,
- recruitment processes clearly identify when confidential references are being sought,
- managers understand that internal notes and performance reviews aren’t automatically protected from disclosure simply because they contain opinions.
Privacy law isn’t about hiding information. It’s about being transparent, collecting information fairly, and handling it responsibly.
A small update to your privacy notices today could save you a lot of uncertainty if an employee ever asks, “Can I have a copy of everything you hold about me?”
If you’re not sure whether your recruitment forms, privacy statements or HR processes are keeping pace with the latest Privacy Act requirements, I’d be happy to help you review them as part of our employment compliance services.
While we're on the subject...
Refreshing my knowledge of the Privacy Act reminded me of a few other principles that are well worth keeping in mind.
Only collect information you genuinely need
The Privacy Act doesn’t stop you collecting personal information, but it does expect you to have a good reason for doing so.
Before adding another field to an application form or asking an employee for more information, ask yourself, “Do we actually need this?”
For example, does an office administrator really need to provide a copy of their driver’s licence if driving isn’t part of the role? Do you need detailed medical information if all you need to know is whether someone is fit to perform the inherent requirements of their job?
Collect what’s necessary, not what’s simply “nice to have.”
Explain why you're collecting information
People are generally happy to provide personal information when they understand why you’re asking for it.
Whether it’s a job application, an employee information form or a medical consent form, take a moment to explain what the information will be used for, who will have access to it, and how it will help you manage the employment relationship.
A little transparency goes a long way towards building trust.
Don't become a digital hoarder
Many organisations keep employee information indefinitely simply because storage is cheap.
The Privacy Act takes a different view. Personal information shouldn’t be kept for longer than it’s needed.
That doesn’t mean deleting records you’re legally required to keep (ie payroll records), but it is worth asking questions like:
- Do we still need interview notes from unsuccessful candidates several years later?
- Are we keeping copies of identity documents that no longer serve a purpose?
- Could some old employee files be securely destroyed?
Regularly reviewing what you hold is just as important as protecting it.
"Confidential" doesn't always mean "can't be disclosed"
One of the biggest misconceptions I come across is the belief that writing “Confidential” at the top of a document means an employee can never ask to see it.
That’s simply not how the Privacy Act works.
As we’ve seen, there are some very specific reasons why information can be withheld, such as confidential referee reports. But many documents that employers assume are confidential – such as manager’s notes or performance reviews – may still need to be disclosed if an employee requests them.
The question isn’t whether a document is labelled confidential. The question is whether there’s a legal reason to withhold it.
Remember that emails count too
Finally, it’s worth remembering that personal information isn’t limited to what’s stored in an employee’s personnel file.
Emails, Teams messages and other workplace communications about an employee may also be personal information.
It’s a good reminder to write every email on the assumption that one day the person it’s about could read it. That’s not a reason to avoid documenting important issues; it simply encourages us to be professional, factual and respectful in how we communicate.