Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should employers handle employee and applicant data…
Governance, Ownership & Risk

How should employers handle employee and applicant data under the Australian Privacy Act when multiple laws apply?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Employers should first map which records are exempt, which are not, and which jurisdictional rules apply. The private sector employee records exemption does not cover prospective employees, contractors handling another organisation’s employee records, or every state and public sector context. A practical compliance programme separates collection, use, storage, disclosure, and retention obligations by workforce type and jurisdiction.

How to segment employee records, applicant records, and cross-jurisdiction obligations

The first step is to classify the data by workforce relationship and legal regime, not by where it is stored. Australian employers often have one set of obligations for current employees, a different set for applicants, and additional overlays from state, public sector, or overseas privacy rules. That classification determines what you can collect, how long you can keep it, and who may access it.

For records that are exempt from the private sector employee records exemption, treat them like ordinary regulated personal information: collection, notice, access, disclosure, and retention all need to be tested against the applicable law. For applicant records, the exemption usually does not help at all, so pre-employment screening data, referees, medical information, and onboarding records need a stricter privacy review than internal HR files.

Where multiple laws apply, the safer operating assumption is that the stricter rule controls the handling step. That is especially important for mixed datasets, such as payroll, health, disciplinary, background check, and contractor records, because one file can contain both exempt and non-exempt material. Separating those streams is often the difference between a workable compliance program and a policy that cannot actually be executed.

What changes when contractors, applicants, and public sector records are included

Contractors are a common failure point because the legal treatment depends on whose employee records are being handled and in what capacity. A contractor processing another organisation’s employee records is not automatically covered by the same exemption logic as the hiring employer, so the processing role, contract terms, and retention obligations should be reviewed independently.

Applicants require special attention because they are outside the employment relationship that gives the employee records exemption its narrow scope. That means recruitment workflows should be designed as privacy workflows, not just HR convenience workflows. If the same platform handles applicants and employees, access controls, retention rules, and disclosure settings should be separated so the exempt and non-exempt data do not blur together.

Public sector and state-law contexts can change the answer materially, even when the organisation thinks it is following the federal Privacy Act alone. A robust programme maps each record set to the applicable jurisdiction before any collection or disclosure decision is made, then records the legal basis for the treatment so the position can be defended later.

The practical control is a record-by-record handling model, not a single global HR policy. Employers should define intake rules for applicants, current employees, former employees, and third parties, then set distinct retention periods and disclosure approvals for each category. This is the cleanest way to avoid accidentally applying an employee-only exemption to records that do not qualify.

Privacy by design matters here because the risk is usually structural, not accidental. If the HR system, recruitment portal, and payroll platform all share the same permissions and retention defaults, non-exempt records can be exposed to staff who only need exempt employment records. A compliant design makes the legal distinction visible in the workflow, not just in the policy library.

For organisations operating across jurisdictions, a practical control is a legal mapping table that links each record type to the governing law, retention rule, access role, and disclosure gate. That makes it easier to answer the real operational question: can this specific record be collected, used, stored, or shared under the rules that apply to it?

Risk and Threat Considerations

Mixed employee and applicant datasets create privacy and compliance exposure when exempt and non-exempt records are processed as if they were interchangeable. The main failure mode is overbroad handling, where a lawful internal HR file is treated as a blanket permission structure for recruitment, contractor, or public sector records that need separate legal analysis.

Failure mechanism: Inadequate data segmentation, weak jurisdiction mapping, or shared access paths allow records subject to different legal rules to be collected, retained, or disclosed under the wrong basis, creating compliance breaches and avoidable exposure.

Impact: The organisation can lose legal defensibility over routine HR operations, face corrective action for retention or disclosure errors, and increase the chance that sensitive applicant or personnel information is accessed or used beyond its permitted scope.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.12 — Classification of informationEmployee and applicant records need legal and handling-based classification.
A.5.34 — Privacy and protection of PIIThe question is about lawful handling of personal data across regimes.
A.5.31 — Legal, statutory, regulatory and contractual requirementsMultiple laws may apply and the handling rule depends on the governing regime.
Recommendation — Classify HR records by legal treatment and handling requirement before applying controls. Apply privacy controls to personal data collection, use, disclosure, and retention. Map each HR record type to the legal obligations that govern it.
GDPRArt.5 — Principles relating to processing of personal dataThe handling question turns on lawful collection, minimisation, and retention principles.
Art.25 — Data protection by design and by defaultMixed workforce records need design-time separation of exempt and non-exempt handling.
Recommendation — Align processing steps to purpose limitation, minimisation, and storage limitation. Build separate defaults for applicant, employee, and contractor data flows.
NIST SP 800-53 Rev 5PT-2 — Privacy Impact and Risk AssessmentCross-jurisdiction handling requires assessing privacy risk across record types.
Recommendation — Assess privacy impact for each workforce data stream before deployment.

Practitioner Guidance

What to prioritise: Start by inventorying the actual record types, not the departments that create them. Applicant files, employee files, contractor files, and public sector records should be tagged differently before any retention or access policy is applied.

What to verify: Confirm that your HR and recruitment systems can separate exempt from non-exempt records, and that access rights, notices, retention periods, and disclosure approvals are aligned to the correct legal basis for each category. If they cannot, treat that as a control gap, not an admin inconvenience.

Decision rule: If a record might be governed by more than one law, apply the stricter handling requirement until the legal basis is confirmed. That is usually the least risky posture when applicant data, cross-jurisdiction records, or contractor-managed employee information are involved.

Practitioner takeaway: The real test is whether the organisation can prove, for each record type, why it was collected, who may touch it, and which law governs its lifecycle. If that answer is unclear, the compliance model is too coarse.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org