Skip to content

Which privacy law covers your data in Australia?

By · Notibo

Published · 14 min read · updated

Which privacy law covers your data in Australia?

Key takeaways

  • The law depends on the university. Sydney, UNSW and UOW name the NSW PPIP Act, Melbourne and Monash the Victorian PDP Act, UQ the Queensland IP Act, and ANU the federal Privacy Act 1988.
  • Universities hold more than marks. Melbourne collects LMS log data and data from exam environments, UNSW's online exams may record video and audio, and Sydney lists data from your use of its systems.
  • Ask in writing for access or correction. ANU's Privacy Officer responds within 30 days, and the NSW PPIP Act requires access without excessive delay or expense.
  • Complain to the university first. NSW gives you six months to seek internal review, UQ lets you go to the Information Commissioner after 45 business days, OVIC expects 28 days and the OAIC 30.
  • Data can leave Australia under conditions. APP 8, section 19(2) of the NSW Act, section 33 of the Queensland Act and Victoria's IPP 9 set the tests, and Monash keeps eExam recordings in Australia.
  • Your own upload is a different case. Section 16 of the Privacy Act keeps the APPs out of an individual's personal affairs, but the app company may be an APP entity with its own duties.

Short answer first: which privacy law protects you depends on your university. Sydney, UNSW and UOW name the Privacy and Personal Information Protection Act 1998 (NSW), Melbourne and Monash the Privacy and Data Protection Act 2014 (Vic), and UQ the Information Privacy Act 2009 (Qld). ANU works under the federal Privacy Act 1988. Each law lets you see and correct what is held about you and complain, first to the university and then outside it: to the Civil and Administrative Tribunal in NSW, OVIC in Victoria, the Office of the Information Commissioner in Queensland, or the OAIC.

This article covers the personal information a university holds about you, how to get at it, and what happens when data leaves the state or the country, including when you choose the app. Each rule links to the Act or the university page it comes from. None of it is legal advice.

Which privacy law covers your university?

The Privacy Act 1988 is federal, and the OAIC's page on state and territory privacy legislation says it does not cover state or territory government agencies, while most states have their own laws for their public sectors. The fastest way to find your university's law is its own privacy statement, because it names the Act.

  • NSW universities name the PPIP Act. The University of Sydney's page on privacy at the University sets its primary obligations under the Privacy and Personal Information Protection Act 1998 and the Health Records and Information Privacy Act 2002. UNSW's student privacy statement and UOW's student privacy and disclosure statement name the PPIP Act too.
  • Victorian universities name the PDP Act. Melbourne's student privacy statement says the University is governed by the Privacy and Data Protection Act 2014 and the Health Records Act 2001. Monash's page on its collection statements says providing them is a requirement of the PDP Act.
  • UQ names the Information Privacy Act. UQ's Privacy Policy says its obligations arise primarily under the Information Privacy Act 2009, including the Queensland Privacy Principles.
  • ANU works under the federal Act. ANU's privacy policy says the Privacy Act 1988 requires it to have one, and that its obligations are set out in the Act and the Australian Privacy Principles.
University Law its privacy documents name Who that law covers Regulator or review body
Sydney, UNSW, UOW Privacy and Personal Information Protection Act 1998 (NSW) NSW public sector agencies NSW Information and Privacy Commission; the Civil and Administrative Tribunal reviews internal review outcomes
Melbourne, Monash Privacy and Data Protection Act 2014 (Vic) Victorian public sector agencies Office of the Victorian Information Commissioner (OVIC)
University of Queensland Information Privacy Act 2009 (Qld) The Queensland public sector Office of the Information Commissioner, Queensland
ANU Privacy Act 1988 (Cth) and the Australian Privacy Principles Agencies and organisations under the federal Act, other than small business operators Office of the Australian Information Commissioner (OAIC); ANU's policy says the Privacy Commissioner

When a university names more than one law

Several do. Sydney also lists the Privacy Act 1988 and overseas laws such as the GDPR where they apply. Melbourne says federal and international privacy law applies in certain circumstances, and UQ has Privacy Act obligations for tax file numbers. For your student record, name the Act the university calls primary: the NSW Acts at Sydney, the Queensland Act at UQ.

What does your university hold about you?

More than your results. The privacy statements now list the systems you use every day.

  • Your record and your use of systems. Sydney's student privacy collection notice lists enrolment details, academic progress and results, participation records, financial aid, data from your use of University facilities and systems, conduct and academic integrity matters, and sensitive information such as disability adjustments.
  • Learning platform logs. Melbourne's LMS privacy collection notice lists login history, timestamps, IP address, session duration and submission times, plus usage analytics and engagement metrics, and names Instructure Inc as the learning management system provider.
  • Exam supervision. UNSW says online assessments may involve session recording or live supervision by the University or a contracted provider, collecting data that can include biometric data and images, video and audio recordings. Melbourne collects data about your presence and activity in University-controlled exam environments, digital ones included.
  • Recorded exams. Monash's recorded eExams page says your desktop and webcam activity is recorded from the online check-in, and that video and audio recordings of you may be taken and analysed.
  • Checks on your work. Sydney may review and analyse submitted work in academic integrity investigations, including suspected unauthorised use of AI tools. Melbourne says assessment content, metadata and activity records may be reviewed to verify authorship.
  • Lecture recordings. UOW's Lecture Recording Procedures say recordings may contain incidentally collected personal information, such as the likenesses, voices, names and opinions of students present.

Software reads some of this as well as people. Sydney's notice says the University may use generative AI and other machine learning tools for teaching and learning, research, administration and quality assurance, with your information handled under its Privacy Policy and privacy law. If a decision about you rests on data like this, the access rights below are how you see it.

How do you see or correct what the university holds?

Every one of these laws gives you access and correction, in different words.

  • NSW. Section 14 of the PPIP Act requires a public sector agency to give you access to your personal information without excessive delay or expense. Section 15 requires it to make appropriate amendments on request, by corrections, deletions or additions, so the information is accurate and not misleading.
  • Victoria. IPP 6 in Schedule 1 of the Privacy and Data Protection Act 2014 requires an organisation to give you access to your personal information on request, subject to listed exceptions such as an unreasonable impact on other people's privacy.
  • Queensland. UQ's Privacy Policy lists three routes: the organisational unit that holds the information, an administrative access scheme, or a formal application under the Right to Information Act 2009 (Qld) to access or amend documents containing your personal information.
  • The federal principles. Under APP 12 and APP 13 an agency must respond within 30 days and cannot charge for access. An organisation must respond within a reasonable period and may charge a fee for giving access that is not excessive, but nothing for making the request or for a correction.
  • ANU. Its privacy policy says you can ask the Privacy Officer for access or correction, and the Privacy Officer will respond within 30 days.

A request that gets answered

  1. Check the student system first. UNSW says much of your information can be viewed and updated in myUNSW.
  2. Write to the privacy contact on your university's privacy page, and name the Act the university names.
  3. Say exactly what you want: your student record, LMS activity logs, an exam recording, or a specific correction.
  4. Keep a dated copy. The complaint clocks below run from the day your complaint arrives.
  5. If you are refused, ask for the reasons in writing. Under the federal principles, APP 12.9 and APP 13.3 require a written notice with the reasons and the ways to complain.

How do you complain, and where does it go next?

Start with the university in every state. The regulators expect it, and each sets a period the university gets before an outside body steps in.

Law First step Time the university has Next step
PPIP Act (NSW) Written application for internal review, within 6 months of becoming aware of the conduct 60 days before you may go to the Tribunal Civil and Administrative Tribunal
PDP Act (Vic) Complaint to the organisation OVIC says allow 28 days Complaint to OVIC
IP Act (Qld) Written complaint to the university 45 business days Office of the Information Commissioner
Privacy Act (Cth) Complaint to the organisation or agency The OAIC says 30 days Complaint to the OAIC
  • NSW keeps the Privacy Commissioner informed. Section 54 of the PPIP Act requires the university to notify the Privacy Commissioner of an internal review and report its findings. Sydney says its Chief Governance Officer considers complaints and sends the report to the NSW Privacy Commissioner within 60 days. Under section 55 the Tribunal can order damages of up to 40,000 Australian dollars.
  • Queensland counts business days. Section 164A of the Information Privacy Act 2009 sets a response period of 45 business days after the complaint is received, which the university can ask you to extend. UQ's policy says you may then refer the complaint to the Office of the Information Commissioner.
  • Victoria asks for 28 days. OVIC's guidance to complain to the organisation first says to allow 28 days, and that OVIC may refuse a complaint if you have not.
  • The OAIC asks for 30 days. Its page on how to lodge a privacy complaint says to complain to the organisation or agency first, then to the OAIC if there is no response within 30 days or you are unhappy with it. ANU says it will tell you its proposed response within 30 days, and that you can ask for a senior officer's review or complain to the Privacy Commissioner.

Can your data be sent overseas?

Yes, under conditions, and each law writes its own. None of them bans it, so the questions are where it goes, to whom, and under what safeguards.

  • APP 8 makes the sender responsible. Before an APP entity discloses personal information to someone overseas, APP 8.1 requires reasonable steps so the recipient does not breach the APPs. Under section 16C of the Privacy Act 1988, a breach by that recipient can be treated as a breach by the entity itself.
  • NSW sets a list of tests. Section 19(2) of the PPIP Act lets an agency disclose personal information outside NSW only in listed cases, for example where the recipient is bound by a law, binding scheme or contract with substantially similar principles, or where you expressly consent.
  • Queensland and Victoria do the same. Section 33 of the Queensland Act allows disclosure outside Australia only in listed cases, such as your agreement. IPP 9 allows a transfer outside Victoria where, among other grounds, the recipient is bound by substantially similar principles or you consent.
  • Universities say it happens. Melbourne says information may go outside Victoria or Australia where providers are located internationally or use cloud servers in other jurisdictions. UNSW says some contracted providers are outside NSW or Australia, and ANU says some of its cloud and hosting providers are overseas.
  • Some data stays in Australia. Monash says all eVigilation recordings from recorded eExams are stored within Australia only.

The federal principles also make the answer public. APP 1.4 requires an APP entity's privacy policy to say whether it is likely to disclose personal information overseas and, where practicable, in which countries. A policy that names its overseas processors and their countries is doing what the principle asks.

What changes when you choose the app yourself?

When you upload your own recording to an app you picked, the university is not the one sending the data, so its privacy statement does not describe what happens next. The app's privacy policy does.

  • Your own study use. Section 16 of the Privacy Act says nothing in the APPs applies to personal information an individual collects, holds, uses or discloses only for personal, family or household affairs. The Act does not say where study sits, and this article does not guess.
  • The company is a separate question. The Act's definition of an organisation leaves out small business operators, and section 6D draws the small business line at an annual turnover of 3,000,000 Australian dollars or less, with exceptions. Whether a given app company is an APP entity depends on facts like that, which its policy may state.
  • Storage and processing are different. A tool can keep your files in one place and send audio to a processor in another. APP 1.4 is the reason a careful policy says both.

What to check before you upload

  1. The company's legal name and a privacy contact.
  2. Whether it sends personal information overseas, and to which countries.
  3. The named processors that receive the audio and generate the text.
  4. How long audio and transcripts are kept, and how to delete them.
  5. How to ask for access or correction, and where to complain.

The main apps are compared on points like these in the best note-taking app for Australian students.

What about other people's voices in your recording?

A recording of a class holds other people's personal information, not just yours. UOW's procedures say so directly, and ANU's page on privacy and lecture recordings tells students worried about their voice or image being recorded to talk to the course convener first. The university's own recordings are covered in lecture capture at Australian universities.

The university rules on your own recordings are stricter than privacy law. UQ's Recording of Teaching Procedure says recordings and transcripts cannot be shared or published without permission. Melbourne's guidance on AI transcription tools treats them as a type of recording and warns that recorded data may be kept, shared or used for other purposes without people knowing. Get the permission first, and keep other students' voices out where you can. The rules by university are in can you record a lecture at an Australian university.

What has changed in privacy law recently?

Two federal changes matter for students.

  • A statutory tort since 10 June 2025. The OAIC's page on the statutory tort for serious invasions of privacy says the changes introducing it commenced on 10 June 2025. It reaches further than the Privacy Act, to individuals and entities that may not be APP entities, and a court can grant damages, an injunction or an order requiring an apology. Proceedings must start in time: a plaintiff who was under 18 when it happened must start before their 21st birthday, and anyone else by the earlier of one year after they became aware of the invasion and three years after it occurred.
  • Automated decisions from 10 December 2026. The OAIC's consultation on automated decision-making guidance says the Privacy and Other Legislation Amendment Act 2024 introduced an automated decision-making obligation. From 10 December 2026, APP entities that use personal information in automated decisions that could affect rights or interests must say in their privacy policies what kinds of information and decisions are involved.

The second applies to APP entities, so it reaches ANU and app companies covered by the federal Act, not the state Acts named by the other universities here.

Where Notibo fits

Notibo is one of the apps the checklist above is for, so here are its answers. Files are stored in the EU, on Supabase in Frankfurt. Transcription and the AI notes run on US processors under standard contractual clauses. Audio files are deleted from storage as soon as the transcript and notes are generated, and if processing fails the audio is kept for a short while so the recording can be tried again. The privacy policy lists the processors by name.

It records a lecture or takes an audio file you upload and returns a transcript, structured notes and flashcards with spaced repetition, in 89 languages, with export to PDF or Word. The first 14 days of Pro are free, with 240 minutes of recording and no card. When the trial ends, the free plan includes 30 minutes of recording a month, and Pro is 9.99 euro a month or 88.99 euro a year. Get permission before you record anyone.

Frequently asked questions

Does the Privacy Act 1988 apply to my university?
It depends on the university. The OAIC says the Privacy Act does not cover state or territory government agencies, and most states have their own laws for their public sectors. Sydney, UNSW and UOW name the Privacy and Personal Information Protection Act 1998 (NSW), Melbourne names the Privacy and Data Protection Act 2014 (Vic), and UQ the Information Privacy Act 2009 (Qld). ANU's privacy policy says the Privacy Act 1988 requires it to have one, and UQ has Privacy Act obligations for tax file numbers.
How do I get a copy of the personal information my university holds?
Ask the university's privacy contact in writing and name the information you want. ANU says its Privacy Officer responds to access and correction requests within 30 days. UNSW lets you view and update much of your information in myUNSW and asks you to contact The Nucleus for the rest. UQ points to administrative access schemes or a formal application under the Right to Information Act 2009 (Qld), and the NSW PPIP Act requires access without excessive delay or expense.
How do I make a privacy complaint about my university?
Complain to the university first, in writing. In NSW the complaint is an application for internal review, made within six months of becoming aware of the conduct, and if the review is not finished within 60 days you can apply to the Civil and Administrative Tribunal. UQ says you may refer a complaint to the Office of the Information Commissioner if you are unhappy or hear nothing within 45 business days. In Victoria, OVIC asks you to give the organisation 28 days first.
Can my university send my personal information overseas?
Yes, under conditions set by the law that covers it. APP 8 requires an APP entity to take reasonable steps so an overseas recipient does not breach the APPs, and section 19(2) of the NSW PPIP Act, section 33 of the Queensland IP Act and IPP 9 in Victoria set their own tests. Melbourne says some LMS service providers may store or process information outside Victoria or Australia, and ANU says some of its cloud providers are overseas.
Are online exam recordings stored in Australia?
At Monash, by its own account. Its recorded eExams page says eVigilation recordings and personal information are stored within Monash infrastructure and within Australia only, and that authorised staff may use them only for academic integrity matters and record-keeping. UNSW says online exams may involve session recording or live supervision by the University or a contracted provider, which may collect images, video, audio and biometric data. For other universities, read the online exam privacy notice.
Does privacy law stop me uploading a lecture recording to an app?
Section 16 of the Privacy Act says the Australian Privacy Principles do not apply to personal information an individual handles only for personal, family or household affairs. It does not decide what your university allows, and the university rules are stricter: UQ says recordings and transcripts cannot be shared or published without permission, and Melbourne treats AI transcription tools as a type of recording. Get permission first, then read the app's privacy policy for where the audio goes.
Which privacy law covers your university?
The Privacy Act 1988 is federal, and the OAIC's page on state and territory privacy legislation says it does not cover state or territory government agencies, while most states have their own laws for their public sectors. The fastest way to find your university's law is its own privacy statement, because it names the Act. NSW universities name the PPIP Act. The University of Sydney's page on privacy at the University sets its primary obligations under the Privacy and Personal Information Protection Act 1998 and the Health Records and Information Privacy Act 2002. UNSW's student privacy statement and UOW's student privacy and disclosure statement name the PPIP Act too.
What does your university hold about you?
More than your results. The privacy statements now list the systems you use every day. Your record and your use of systems. Sydney's student privacy collection notice lists enrolment details, academic progress and results, participation records, financial aid, data from your use of University facilities and systems, conduct and academic integrity matters, and sensitive information such as disability adjustments. Learning platform logs. Melbourne's LMS privacy collection notice lists login history, timestamps, IP address, session duration and submission times, plus usage analytics and engagement metrics, and names Instructure Inc as the learning management system provider. Exam supervision.

Sources

  1. State and territory privacy legislation (Office of the Australian Information Commissioner) (the Privacy Act does not cover state agencies; NSW Information and Privacy Commission, OVIC and the Queensland Office of the Information Commissioner)
  2. Read the Australian Privacy Principles (OAIC) (APP 1.4 overseas disclosure in privacy policies, APP 8 cross-border disclosure, APP 12 access and APP 13 correction with time limits and charges)
  3. Privacy Act 1988, Compilation No. 104 (Federal Register of Legislation) (section 16 personal, family or household affairs, section 16C overseas recipients, sections 6C and 6D organisations and small business operators)
  4. Privacy and Personal Information Protection Act 1998 No 133 (NSW Legislation) (section 14 access, section 15 alteration, section 19(2) disclosure outside NSW, sections 53 to 55 internal review and the Tribunal)
  5. Information Privacy Act 2009 (Queensland Legislation) (section 33 disclosure outside Australia, section 164A response period of 45 business days for privacy complaints)
  6. Privacy and Data Protection Act 2014, Authorised Version No. 033 (Victorian Legislation) (Schedule 1, IPP 6 access and correction, IPP 9 transborder data flows)
  7. Student privacy statement (The University of Melbourne) (PDP Act and Health Records Act, LMS and network data, exam environment data, transfers outside Victoria or Australia)
  8. Student privacy and information disclosure (UNSW Sydney) (PPIP Act, providers outside NSW or Australia, online assessment monitoring, access and amendment)

About the author

Farhad Ba-Ali

Farhad Ba-Ali builds Notibo in Odense, Denmark. He writes about study methods, memory and note-taking from the questions students send in, and from what the product's own data shows.

Put Notibo through the same checklist

Its answers: files are stored in the EU, and transcription and AI notes run on US processors under standard contractual clauses. Test it on one lecture before you decide. Pro is free for 14 days, no card.

Create free account

Back to the blog