FZU v University of NSW [2024] NSWCATAD 99

FZU v University of NSW [2024] NSWCATAD 99

The Respondent did not breach any relevant Information Protection Principle. The website allegations did not involve collection; the continued presence of information after supervision ended was not a further use; and the original publication, use and disclosure of the Applicant's name and thesis topic were directly related to the University's legitimate statutory functions of scholarship, research, free inquiry, interaction of research and teaching, and academic excellence. The Pre-Trip Approval information was collected from the Applicant, handled within authorised approval processes, protected by reasonable safeguards, used for the trip approval purpose, and not shown to have been...

Jurisdiction
Australia
Judgment Date
16 April 2024
Procedural Posture
Administrative Review of Privacy Complaint Under the Privacy and Personal Information Protection Act 1998 (nsw) / Review of the Respondent's Internal Review Decision Dated 3 November 2023
Outcome
The Respondent's reviewable decision of 3 November 2023 was affirmed under s 63(3)(a) of the Administrative Decisions Review Act 1997 (NSW).
Legal Topics
['privacy and Personal Information Protection Act 1998 (nsw)' 'information Protection Principles' 'collection of Personal Information' 'use of Personal Information' 'disclosure of Personal Information' 'administrative Review Jurisdiction' 'damages for Privacy Contravention']

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 1 Authorities cited 2 Party arguments 2 Amounts and remedies 1
Sign in to unlock

Procedural Posture

Administrative Review of Privacy Complaint Under the Privacy and Personal Information Protection Act 1998 (nsw) / Review of the Respondent's Internal Review Decision Dated 3 November 2023

  1. 1 ["Whether the Tribunal had jurisdiction to consider conduct beyond the conduct that was the subject of the Applicant's internal review application." "Whether publication of the Applicant's name and PhD thesis topic on a staff profile, and failure to remove it after the supervision arrangement ended, breached IPPs 1, 2, 3, 5, 9, 10, 11 or 12." "Whether modification and handling of the Applicant's Pre-Trip Approval form breached IPPs 1, 2, 3, 4, 5, 6, 9, 10 or 11." 'Whether orders, including damages, should be made under s 55(2) of the Privacy and Personal Information Protection Act 1998 (NSW).']

Ratio Decidendi

The Respondent did not breach any relevant Information Protection Principle. The website allegations did not involve collection; the continued presence of information after supervision ended was not a further use; and the original publication, use and disclosure of the Applicant's name and thesis topic were directly related to the University's legitimate statutory functions of scholarship, research, free inquiry, interaction of research and teaching, and academic excellence. The Pre-Trip Approval information was collected from the Applicant, handled within authorised approval processes, protected by reasonable safeguards, used for the trip approval purpose, and not shown to have been...

Court Disposition

The Respondent's reviewable decision of 3 November 2023 was affirmed under s 63(3)(a) of the Administrative Decisions Review Act 1997 (NSW).

Orders

  • ["The Respondent's reviewable decision of 3 November 2023 is affirmed under s 63(3)(a) of the Administrative Decisions Review Act 1997."]