EPT v The Sydney Children’s Hospital Network [2022] NSWCATAD 137

EPT v The Sydney Children’s Hospital Network [2022] NSWCATAD 137

The Respondent was a public sector agency and held the Applicant's personal information on its H drive. The Respondent conceded, and the Tribunal found, that between February 2017 and May 2018 its network security setting lacked reasonable security, breaching s 12(c) of the Privacy and Personal Information Protection Act 1998. The Tribunal found no breach of HPP 5(1)(c) and no use of the Applicant's personal information for ss 16 or 17 because the evidence did not establish that the copied information was employed for an administrative purpose or consequence. The breach materially contributed to the Applicant's distress and harm, although other workplace stressors were also present,...

Jurisdiction
Australia
Judgment Date
28 April 2022
Procedural Posture
Administrative Review Concerning Alleged Privacy Breaches Under the Privacy and Personal Information Protection Act 1998 and Health Records and Information Privacy Act 2002 / Principal Judgment After Hearing
Outcome
The reviewable decision was set aside and substituted with a finding that the Respondent breached s 12(c) of the Privacy and Personal Information Protection Act 1998; the Applicant was awarded an apology and $10,000 compensation.
Legal Topics
['information Privacy Principles' 'retention and Security of Personal Information' 'health Privacy Principles' 'use of Personal Information' 'administrative Review' 'compensation for Privacy Breach' 'publication Restriction']

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 1 Authorities cited 2 Party arguments 2 Amounts and remedies 1
Sign in to unlock

Procedural Posture

Administrative Review Concerning Alleged Privacy Breaches Under the Privacy and Personal Information Protection Act 1998 and Health Records and Information Privacy Act 2002 / Principal Judgment After Hearing

  1. 1 ["Whether the Tribunal had jurisdiction to review the Respondent's internal review decision made on 5 March 2021." "Whether the Respondent breached s 12(c) of the Privacy and Personal Information Protection Act 1998 by failing to secure the Applicant's personal information on the H drive." 'Whether there was a breach of HPP 5(1)(c) of Schedule 1 to the Health Records and Information Privacy Act 2002.' "Whether the Applicant's personal information was used for the purposes of ss 16 and 17 of the Privacy and Personal Information Protection Act 1998." 'What remedy should follow from the established breach of s 12(c) of the Privacy and Personal Information Protection Act 1998.']

Ratio Decidendi

The Respondent was a public sector agency and held the Applicant's personal information on its H drive. The Respondent conceded, and the Tribunal found, that between February 2017 and May 2018 its network security setting lacked reasonable security, breaching s 12(c) of the Privacy and Personal Information Protection Act 1998. The Tribunal found no breach of HPP 5(1)(c) and no use of the Applicant's personal information for ss 16 or 17 because the evidence did not establish that the copied information was employed for an administrative purpose or consequence. The breach materially contributed to the Applicant's distress and harm, although other workplace stressors were also present,...

Court Disposition

The reviewable decision was set aside and substituted with a finding that the Respondent breached s 12(c) of the Privacy and Personal Information Protection Act 1998; the Applicant was awarded an apology and $10,000 compensation.

Orders

  • ['Pursuant to s 64 (1)(a) of the Civil and Administrative Tribunal Act 2013, the name of any person (whether or not a party to proceedings in the Tribunal or a witness summoned by, or appearing before, the Tribunal) is prohibited.' 'The decision made by the Respondent on 5 March 2021, is set aside.' "In substitution...