Rights and privacy principles

Quick guide to managing personal and health information for mental health and wellbeing services.

Protecting privacy and managing personal information appropriately are essential to safe, respectful and person-centred care.

Mental health and wellbeing services must manage personal and health information in accordance with the Health Records Act 2001 and the Privacy and Data Protection Act 2014 .

This material is intended for quick reference only. The full principles are set out in the above Acts.

Collection

Organisations can only collect personal information where it is necessary to perform one or more of its functions. They must collect information only by lawful and fair means, and not in an unreasonably intrusive way. They must provide notice of the collection, outlining matters such as the purpose of collection and how individuals can access the information. This is usually done by providing a Collection Notice, which should be consistent with an organisation’s Privacy Policy.

Use and disclosure

Health information should only be used or disclosed for the purpose for which it was collected, or for a directly related secondary purpose that a person would reasonably expect. In most other circumstances, consent is required.

Data quality

Take reasonable steps to ensure personal information is accurate, complete and up to date.

Data security and retention

Organisations must take reasonable steps to protect personal information from misuse, loss, unauthorised access, modification or disclosure. Personal information should also be securely retained, destroyed or de-identified in accordance with legislative and record keeping requirements.

Openness

Organisations must have and maintain clear policies on the management of personal and health information and make them available to individuals on request.

Access and correction

Individuals have the right to access and request correction of their personal information. Access and correction requests are mostly handled under the Freedom of Information Act 1982.

Identifiers

Unique identifiers should only be assigned where reasonably necessary to carry out functions efficiently. Their use and disclosure should be limited to protect privacy and reduce the risk of inappropriate data matching.

Anonymity

Where lawful and practicable, individuals should have the option of not identifying themselves when accessing a service or making an enquiry.

Transborder data flows

Health information should only be transferred outside Victoria where appropriate privacy protections are in place and legislative requirements are met. Privacy protections should continue to apply when information is shared across jurisdictions.

Transfer/closure of a health service practice

Health service providers who sell, transfer or close a practice must take appropriate steps to notify past service users and ensure health information continues to be managed appropriately.

Sensitive information

Sensitive information requires additional protections and may only be collected, used and disclosed in accordance with legislative requirements. This includes information about a person's racial or ethnic origin, political views, religious beliefs, sexual orientation, group memberships or criminal history.

Making information available to another health service provider

Health service providers must make an individual's health information available to another health service provider when requested by the individual.

Updated