Your Employee Data Is Exempt. That Is Not Permission., practitioner guidance from TheAICommand
← HR & AI
People & Culture

Your Employee Data Is Exempt. That Is Not Permission.

Most Australian private sector employers are exempt from the Australian Privacy Principles when they handle their own employee records. HR teams read that as headroom for AI. It is not headroom, it is the absence of a floor, and the exemption's edges are exactly where AI workflows leak. Here is what section 7B(3) actually covers, where it stops, and the standard to put in its place.

People & Culture. Written for Australian HR and people teams. General information only. Not legal or HR advice. Employment decisions stay with people.

Quick answer

Section 7B(3) of the Privacy Act 1988 exempts a private sector employer where the act is directly related to a current or former employment relationship and to an employee record it holds. That removes the Australian Privacy Principles, but it grants nothing. It does not reach unsuccessful applicants, contractors, volunteers, or acts not directly related, and Australian Government agencies get no exemption at all.

Exempt is not permission. It is a missing floor.

Here is the assumption doing quiet damage in Australian HR teams. Someone drops a performance file, an investigation chronology or a return to work note into an AI tool to summarise it, and the reasoning, if it is articulated at all, runs like this. The Privacy Act sets the floor. We are inside it. We are fine.

For most private sector employers that fails at the first step, because the floor is not there. Section 7B(3) of the Privacy Act 1988 exempts an employer's acts and practices where they are directly related to a current or former employment relationship and to an employee record. Where it applies, the Australian Privacy Principles largely do not: not the collection limits, not the notification duties, not the use and disclosure rules, not the access rights.

That is not headroom. It is the absence of a standard, and it matters more now than at any time since the exemption was drafted, because the tools HR uses copy data, infer new facts about people and route material to third parties. So HR has to set the standard itself, and it has to know the boundary precisely, because the edges are where AI workflows leak.

A wide dark interior where a single figure stands at the edge of a lit platform with nothing beneath it, sage light falling away into depth
The exemption removes a floor. It does not build one.

What the exemption actually says

The section is short.

An act done, or practice engaged in, by an organisation that is or was an employer of an individual, is exempt for the purposes of paragraph 7(1)(ee) if the act or practice is directly related to: (a) a current or former employment relationship between the employer and the individual; and (b) an employee record held by the organisation and relating to the individual.

Note the word joining the limbs. It is "and", not "or". Note also that the section covers the exempt acts of organisations, and section 6C defines an organisation so as to exclude an agency. That is why the OAIC states plainly in its employment guidance that the Privacy Act covers Australian Government and Norfolk Island administration employee records, and that those employees can access the personal information in their record under the Privacy Act. The same AI workflow, run by a Commonwealth employer, is fully regulated.

An employee record is defined in section 6(1) as a record of personal information relating to the employment of the employee, with listed examples running from health information through discipline and termination to performance, hours, salary and leave. But breadth of the definition is not breadth of the exemption, because everything turns on "directly related", and that phrase is read narrowly. In ['ALI' and 'ALJ' (Privacy) \[2024\] AICmr 131](https://www8.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmr/2024/131.html), decided on 20 June 2024, Australian Privacy Commissioner Carly Kind adopted the earlier reasoning that the act or practice "must be directly related to the employment relationship, and not merely an act or practice having an indirect, consequential or remote effect on that relationship", the term denoting "absolutely or exactly having connection" to the relationship between the employer and that individual.

The facts are worth carrying around. An employee of a distribution business with around 3,000 staff suffered a medical event at work, and the managing director emailed 110 staff naming her and updating them on her health. The employer argued the exemption applied: it happened at work, in work hours, to a current employee about whom it held records. The Commissioner found the email related directly to the employment relationship with the other employees, to whom the employer owed a duty of care, and not to its relationship with her. The first limb was not met, so the exemption did not apply and the employer breached APP 6.1. It was ordered to pay $3,000 for non-economic loss and $125.10 in expenses. What put it outside was one question about whose employment relationship the act was really about.

On reform, say only what is settled. In its response to the Privacy Act Review Report on 28 September 2023, the Government agreed in principle to proposal 7.1, further consultation on enhanced privacy protections for private sector employees. The Privacy and Other Legislation Amendment Act 2024 progressed 23 proposals from that response. Section 7B(3) was not among them.

Where the exemption stops

Four edges, each with an AI consequence.

A single frame split into two contrasting halves by one thin rule of sage light, the left half a settled interior and the right half open and exposed
The same tool, the same team, two different legal positions.

Applicants and prospective employees. The OAIC's employee records exemption guidance states that the exemption does not cover future employment relationships, so it does not apply to the collection of personal information about prospective employees who are subsequently not employed, such as unsuccessful job applicants. Only once the relationship is formed do that person's pre-employment check records become exempt. So the same recruitment assistant is exempt summarising a current employee's file for an internal transfer, and not exempt for the 400 people who applied and were not hired. That pool is the larger data set, the one most likely to be kept "for future opportunities", and it is fully regulated, which is why the collection limits at the front of the funnel bite.

Contractors handling someone else's employee records. The exemption does not cover contractors and subcontractors handling the personal information of another organisation's employees, notwithstanding their contractual arrangements. The OAIC names recruitment, human resource management, medical, training and superannuation providers as examples, and adds that a contractor collecting employee records from an employer must comply with the Australian Privacy Principles, including the APP 5 notice requirements. So when your HR provider switches on an AI feature over your files, it is regulated even where you are not.

Volunteers. The exemption does not cover a volunteer's personal information, because an organisation and a volunteer are not treated as having an employee relationship for the purposes of section 7B(3). A not for profit running AI over a combined roster of staff and volunteers is running two regimes through one pipeline.

Acts that are not directly related. The OAIC's example is an employer selling a list of employees for marketing. AICmr 131 is the harder version, where an internally motivated act about a current employee still fell outside. Ask the question of any analytics product reading employee material for a purpose other than managing that person's employment.

Then the second limb, which almost nobody tests. The act must also be directly related to an employee record the organisation holds. AI routinely produces personal information that was in no record you held a moment earlier: an inferred risk score, a sentiment reading, a summary about a person's conduct. The complainant in AICmr 131 raised that point and the Commissioner did not need to decide it. Until someone does, treat newly generated material about a person as unresolved rather than assumed exempt.

The standard to put in its place

Six steps.

A left to right sage flow of five connected pill shaped nodes joined by one continuous line, reading as a path across a dark field
From an inventory to a documented standard, in five moves.
  1. Inventory the flows, not the tools. List every point where employee material meets AI: the copilot in the productivity suite, the HRIS vendor's new summariser, the meeting assistant, the browser tab someone opens at 4pm. Record what goes in and where the output lands.
  2. Classify into three tiers and publish them. Tier one never leaves the HRIS: health information, investigation material, complainant identity, anything about a person's medical or psychological state. Tier two goes only into a contracted enterprise instance with your terms attached: named performance documents, employee relations chronologies, disciplinary drafts. Tier three may go into a general purpose tool: policy text, de-identified patterns, drafting with nobody identifiable. A use that fits no tier is not approved yet.
  3. Adopt the regulator's line even where it does not bind you. The OAIC's guidance on commercially available AI products, published on 21 October 2024 and updated on 17 January 2025, recommends as best practice that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. It addresses conduct the Privacy Act reaches, so it does not bind your exempt acts. Adopt it anyway.
  4. Test each use against both limbs. Answer two questions in writing. Is this act directly related to this person's current or former employment relationship, in the strict sense the Commissioner applied? Is it directly related to an employee record we hold about them? If either answer is uncertain, run the use as though the Australian Privacy Principles apply.
  5. Ask the vendor five questions and keep the answers. Does what we input train your models, and can that be switched off contractually. Where is the data stored, and who can access it. What is retained after a session ends. Are you an APP entity in respect of our employee records. What happens when the feature is wrong.
  6. Write it down so it survives you. One page, a named owner, a version number, a review date, and a register of approved uses carrying the tier and the two limb answer for each. An unwritten standard is a person, and people change roles.

A worked example

[EMPLOYEENAME] in [TEAM] has three months of documented performance concerns, and the people leader wants AI to turn the notes into a structured summary before a difficult conversation.

Tier two, not tier three. The notes name a person, describe conduct, and reference one absence with a medical cause. The medical line stays in the HRIS, because it is tier one. The rest goes to the contracted enterprise instance, not the consumer app on the manager's phone. Both limbs are comfortable, so register the use and move on. Now change one fact. [EMPLOYEENAME] is engaged as a volunteer. The exemption is gone and the same summary is a regulated collection.

Here is a triage prompt that keeps the model on the classification side of the line.

Prompt
You are a data classification aid for an Australian HR team. You are not a legal adviser and you do not give legal advice. Your job is to sort a proposed AI use into our published tiers and surface the questions a human must answer.

Hard rules:
- Reason only from OUR STANDARD as I paste it. Do not rely on your memory of Australian privacy law.
- Never conclude that a use is exempt from the Privacy Act. You may note that an exemption is arguable. The call is mine.
- If the described data includes health, medical, psychological, investigation or complainant material, classify it Tier 1 and stop.
- If you cannot tell whether the person is an employee, a former employee, an applicant, a contractor's employee or a volunteer, ask before classifying.
- Do not invent facts about the tool, the vendor or the data.

Inputs I will paste:
- OUR STANDARD: the three tier definitions and the approved use register.
- THE USE: what the tool does, who operates it, what data goes in, what comes out, where the output is stored, and who else can see it.
- THE PERSON: their relationship to the organisation, in our words.

Produce, in this order:
1. TIER: one of Tier 1, Tier 2, Tier 3 or CANNOT CLASSIFY, with the words from our standard you relied on.
2. TWO LIMB PROMPTS: two questions written for a human to answer, one on whether the act is directly related to this person's current or former employment relationship, one on whether it is directly related to an employee record we already hold. Do not answer them.
3. WHAT WOULD CHANGE THE ANSWER: the single fact most likely to move this to a stricter tier.
4. MISSING FACTS: what I have not told you that matters.
5. VENDOR QUESTIONS: any of our five standard vendor questions this use leaves unanswered.
6. REGISTER ENTRY: a draft one line entry for the approved use register, using placeholders such as [EMPLOYEE_NAME] and [TEAM], never real names.

End with exactly this line: This is a classification aid. A person owns the decision.

The duties that do not disappear

The exemption switches off the Australian Privacy Principles for particular acts. It switches off nothing else.

Workplace law still requires records to exist and to be right. Under the Fair Work Regulations 2009, employers must make and keep prescribed employee records for seven years, in a legible form and in English, readily accessible to an inspector. An employer must correct a record as soon as it becomes aware of an error, with a notation of its nature, and nobody may use an entry knowing it is false or misleading. Most of these obligations are civil remedy provisions. So an AI drafted line that lands in an employee record and is not true is not primarily a privacy problem. It is an enforceable record keeping problem. Employees can also ask to inspect their records and be told where they are kept, which is the access right the OAIC points people to when it explains that a private employer need not grant access under the Privacy Act.

The Australian Privacy Principles still apply to everything outside the exemption and to every public sector employer covered by the Act. Contractual confidentiality is usually the tighter constraint in practice, and so is trust: a workforce that discovers its performance material has been passing through undisclosed tools will draw conclusions. The surveillance and monitoring rules are a separate regime the exemption does not touch, and nor does it help with what gets recorded in HR meetings.

The complaint in AICmr 131 was made in May 2021 and determined in June 2024. Three years of an employer defending a position it believed was obvious, over one email.

What never to paste or automate

  • Never paste identified health, medical or psychological information about a worker into a general purpose tool.
  • Never treat "it is HR data" as the end of the analysis. It is the start of a two limb question.
  • Never assume the exemption travels with the data. It attaches to your acts, not to the bytes, and your vendor carries its own obligations.
  • Never run an unsuccessful applicant pool through a tool as though it were employee data, and never rely on the exemption for volunteers or for a contractor's staff.
  • Never let AI generated text enter an employee record without a person verifying every factual assertion in it. The accuracy duty is enforceable and it is yours.
  • Never let a model conclude that a use is exempt. It reads and sorts. A person decides and is accountable.

This is general guidance, not legal advice. The exemption is fact specific and the two limbs turn on what your act actually was, so take advice on a live matter.

References

  1. Privacy Act 1988 (Cth), s 7B(3), s 6(1) and s 6C, current compilation. https://www.legislation.gov.au/C2004A03712/latest/text
  2. OAIC, "Employee records exemption", privacy guidance for organisations. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/employee-records-exemption
  3. OAIC, "Employment", your privacy rights. https://www.oaic.gov.au/privacy/your-privacy-rights/more-privacy-rights/employment
  4. 'ALI' and 'ALJ' (Privacy) [2024] AICmr 131, Australian Privacy Commissioner Carly Kind, 20 June 2024, CP21/00934. https://www8.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmr/2024/131.html
  5. OAIC, "Guidance on privacy and the use of commercially available AI products", published 21 October 2024, updated 17 January 2025. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
  6. Attorney-General's Department, "Government Response to the Privacy Act Review Report", 28 September 2023, proposal 7.1. https://www.ag.gov.au/rights-and-protections/publications/government-response-privacy-act-review-report
  7. Fair Work Regulations 2009 (Cth), Part 3-6 Division 3, regulations 3.31, 3.43 and 3.44. https://www.legislation.gov.au/F2009L02356/latest/text

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

Does the Privacy Act apply when HR puts employee data into an AI tool?
It depends on who you are and what the act is. Section 7B(3) exempts a private sector employer where the act or practice is directly related to a current or former employment relationship and to an employee record the employer holds. If either limb fails, for example because the person is an unsuccessful applicant or a volunteer, the Australian Privacy Principles apply in the ordinary way. Australian Government agencies cannot rely on the exemption because section 6C excludes an agency from the definition of an organisation.
Does the employee records exemption cover job applicants?
No. The OAIC states that the exemption does not cover future employment relationships, so it does not apply to the collection of personal information about prospective employees who are subsequently not employed, such as unsuccessful job applicants. The OAIC also notes that once an employment relationship is formed, the records the employer holds relating to that individual's pre-employment checks become exempt.
Does the exemption cover an HR vendor or outsourcer?
No. The OAIC states that the exemption does not cover contractors and subcontractors when they handle the personal information of the employees of another organisation, notwithstanding their contractual arrangements, and gives recruitment, human resource management, medical, training and superannuation service providers as examples. A contractor that collects employee records from an employer must comply with the Australian Privacy Principles, including the notice requirements in APP 5.
How strictly do regulators read "directly related"?
Strictly. In 'ALI' and 'ALJ' (Privacy) [2024] AICmr 131, decided on 20 June 2024, the Australian Privacy Commissioner adopted the reading that the act or practice must be directly related to the employment relationship and not merely have an indirect, consequential or remote effect on it, denoting an absolute or exact connection. An email to 110 staff naming an employee and describing her health was held to relate directly to the employer's relationship with the other staff, not with her, so the exemption did not apply.
Is the employee records exemption being removed?
Not as at the time of writing. In its response to the Privacy Act Review Report, released on 28 September 2023, the Government agreed in principle that further consultation should be undertaken with employer and employee representatives on how enhanced privacy protections for private sector employees may be implemented in legislation, which was proposal 7.1. The Privacy and Other Legislation Amendment Act 2024 progressed 23 proposals from that response and did not change section 7B(3), which remains in the Act. Plan for the law as it is.
Human ResourcesPrivacy ActEmployee RecordsData GovernanceAI at WorkOAICFair Work
← Back to HR & AI