Modern Australian
Men's Weekly

.

This law makes it illegal for companies to collect third-party data to profile you. But they do anyway

  • Written by Katharine Kemp, Senior Lecturer, Faculty of Law & Justice, UNSW, UNSW Sydney
This law makes it illegal for companies to collect third-party data to profile you. But they do anyway

A little-known provision of the Privacy Act makes it illegal for many companies in Australia to buy or exchange consumers’ personal data for profiling or targeting purposes. It’s almost never enforced. In a research paper published today, I argue that needs to change.

“Data enrichment” is the intrusive practice of companies going behind our backs to “fill in the gaps” of the information we provide.

When you purchase a product or service from a company, fill out an online form, or sign up for a newsletter, you might provide only the necessary data such as your name, email, delivery address and/or payment information.

That company may then turn to other retailers or data brokers to purchase or exchange extra data about you. This could include your age, family, health, habits and more.

This allows them to build a more detailed individual profile on you, which helps them predict your behaviour and more precisely target you with ads.

For almost ten years, there has been a law in Australia that makes this kind of data enrichment illegal if a company can “reasonably and practicably” request that information directly from the consumer. And at least one major data broker has asked the government to “remove” this law.

The burning question is: why is there not a single published case of this law being enforced against companies “enriching” customer data for profiling and targeting purposes?

Read more: It's time for third-party data brokers to emerge from the shadows

Data collection ‘only from the individual’

The relevant law is Australian Privacy Principle 3.6 and is part of the federal Privacy Act. It applies to most organisations that operate businesses with annual revenues higher than A$3 million, and smaller data businesses.

The law says such organisations:

must collect personal information about an individual only from the individual […] unless it is unreasonable or impracticable to do so.

This “direct collection rule” protects individuals’ privacy by allowing them some control over information collected about them, and avoiding a combination of data sources that could reveal sensitive information about their vulnerabilities.

But this rule has received almost no attention. There’s only one published determination of the federal privacy regulator on it, and that was against the Australian Defence Force in a different context.

According to Australian Privacy Principle 3.6, it’s only legal for an organisation to collect personal information from a third party if it would be “unreasonable or impracticable” to collect that information from the individual alone.

This exception was intended to apply to limited situations, such as when:

  • the individual is being investigated for some wrongdoing
  • the individual’s address needs to be updated for delivery of legal or official documents.

The exception shouldn’t apply simply because a company wants to collect extra information for profiling and targeting, but realises the customer would probably refuse to provide it.

Who’s bypassing customers for third-party data?

Aside from data brokers, companies also exchange information with each other about their respective customers to get extra information on customers’ lives. This is often referred to as “data matching” or “data partnerships”.

Companies tend to be very vague about who they share information with, and who they get information from. So we don’t know for certain who’s buying data-enrichment services from data brokers, or “matching” customer data.

Major companies such as Amazon Australia, eBay Australia, Meta (Facebook), 10Play Viacom and Twitter include terms in the fine print of their privacy policies that state they collect personal information from third parties, including demographic details and/or interests.

Google, News Corp, Seven, Nine and others also say they collect personal information from third parties, but are more vague about the nature of that information.

These privacy policies don’t explain why it would be unreasonable or impracticable to collect that information directly from customers.

Consumer ‘consent’ is not an exception

Some companies may try to justify going behind customers’ backs to collect data because there’s an obscure term in their privacy policy that mentions they collect personal information from third parties. Or because the company disclosing the data has a privacy policy term about sharing data with “trusted data partners”.

But even if this amounts to consumer “consent” under the relatively weak standards for consent in our current privacy law, this is not an exception to the direct collection rule.

The law allows a “consent” exception for government agencies under a separate part of the direct collection rule, but not for private organisations.

Data enrichment involves personal information

Many companies with third-party data collection terms in their privacy policies acknowledge this is personal information. But some may argue the collected data isn’t “personal information” under the Privacy Act, so the direct collection rule doesn’t apply.

Companies often exchange information about an individual without using the individual’s legal name or email. Instead they may use a unique advertising identifier for that individual, or “hash” the email address to turn it into a unique string of numbers and letters.

They essentially allocate a “code name” to the consumer. So the companies can exchange information that can be linked to the individual, yet say this information wasn’t connected to their actual name or email.

However, this information should still be treated as personal information because it can be linked back to the individual when combined with other information about them.

At least one major data broker is against it

Data broker Experian Australia has asked the government to “remove” Australian Privacy Principle 3.6 “altogether”. In its submission to the Privacy Act Review in January, Experian argued:

It is outdated and does not fit well with modern data uses.

Others who profit from data enrichment or data matching would probably agree, but prefer to let sleeping dogs lie.

A screenshot shows six different categories of consumer data offered by Experian.
On its website, Experian claims to offer a ‘combination of demographic, geographic, financial and market research data - both online and offline’. Screenshot/Experian

Experian argued the law favours large companies with direct access to lots of customers and opportunities to pool data collected from across their own corporate group. It said companies with access to fewer consumers and less data would be disadvantaged if they can’t purchase data from brokers.

But the fact that some digital platforms impose extensive personal data collection on customers supports the case for stronger privacy laws. It doesn’t mean there should be a data free-for-all.

Our privacy regulator should take action

It has been three years since the consumer watchdog recommended major reforms to our privacy laws to reduce the disadvantages consumers suffer from invasive data practices. These reforms are probably still years away, if they eventuate at all.

The direct collection rule is a very rare thing. It is an existing Australian privacy law that favours consumers. The privacy regulator should prioritise the enforcement of this law for the benefit of consumers.

Read more: Amazon just took over a primary healthcare company for a lot of money. Should we be worried?

Authors: Katharine Kemp, Senior Lecturer, Faculty of Law & Justice, UNSW, UNSW Sydney

Read more https://theconversation.com/this-law-makes-it-illegal-for-companies-to-collect-third-party-data-to-profile-you-but-they-do-anyway-190758

Rims and Tyres for Sale in Sydney: Performance, Safety, and Style Combined

Finding the right rims and tyres for sale Sydney is about far more than appearance. Tyres and rims directly influence how a vehicle handles, brakes...

Why Access to Doctors in Bundoora Is Essential for Ongoing Community Health

Reliable access to healthcare plays a vital role in maintaining physical wellbeing and peace of mind. Having trusted doctors in Bundoora available ...

Pendant Lights: Elevating Interior Spaces With Style and Purpose

Well-chosen pendant lights have the power to transform interiors by combining focused illumination with strong visual impact. More than just a ligh...

What Sets Professional Family Lawyers in Sydney Apart from General Lawyers?

Choosing the right legal support can make a noticeable difference when dealing with family-related matters. This article will explore what separates...

Balancing Teen Academic Expectations and Wellbeing

For many teenagers, school years are shaped by increasing expectations. Academic performance, future pathways, and comparison with peers can create pr...

Why Ceiling Fans Remain One of the Most Effective Solutions for Year-Round Comfort

Creating a comfortable indoor environment without relying heavily on energy-intensive systems is a priority for many households. Installing ceiling ...

Why an Industrial Air Compressor Is Vital for Modern Manufacturing

In many industrial environments, compressed air is as essential as electricity or water. An industrial air compressor provides the power needed to ...

Why Commercial Carpet Cleaning Services Matter for Professional Spaces

Clean carpets play a major role in shaping how a commercial space looks, feels, and functions. Commercial carpet cleaning services are essential fo...

5 Things to Consider Before Choosing a Commercial Painter

Choosing the right painter for a commercial business can be challenging. Regardless of the type and the size of the property, all commercial project...

Why Medical Fitout Melbourne Practices Rely on for Modern Healthcare Spaces

A well-planned medical fitout Melbourne is essential for creating healthcare environments that support patient care, clinical efficiency, and regula...

Luxury Builders Melbourne Crafting Homes Defined by Design and Detail

Building a premium home is about far more than size or appearance. It is about precision, craftsmanship, and a deep understanding of how refined spa...

Electric Sliding Door Solutions for Modern Living and Commercial Spaces

The way people move through spaces has changed dramatically over the years, and the electric sliding door has become a defining feature of that evol...

Australia’s New Fast Track to Advanced Care in Vietnam

For many Australians, the decision to seek medical care abroad often begins with a specific feeling: the quiet frustration of waiting. According to ...

Cardboard Boxes: A Practical Packaging Solution for Modern Businesses

Reliable cardboard boxes play a vital role in how goods are stored, protected, and transported across industries. From small retailers to large-sca...

The Rise of Smart Homes in Australia: What’s Worth Investing In?

Australia is in the midst of a home technology revolution. From energy efficiency to integrated security, today’s homeowners are transforming thei...

Winter Hairstyling Tips to Prevent Dryness

Winter can be particularly harsh on your hair. Cold air outside, dry indoor heating, and frequent temperature changes can strip moisture from the ha...

Short Term Loans in Australia: Practical Insights for Borrowers and Finance Professionals

Short term loans play a crucial role in Australia’s personal finance landscape. They are designed to cover short-term expenses, unexpected bills, ...

Best EPD Consultants in Australia

Environmental Product Declarations (EPDs) play an increasingly important role in the Australian construction, manufacturing, and infrastructure sect...