Frustra fit per plura quod fieri potest per pauciora: it is done in vain by many means what can be done by fewer. A maxim long used against demands for more than is reasonably necessary.
You ask a business to update or delete the details it holds on you, and the reply is a form asking for your driver’s licence, date of birth, and sometimes more than the business already has on file. It feels backwards, and under Australian privacy law, it often is.
What the Privacy Act actually gives you
Australian Privacy Principles 12 and 13, under the Privacy Act 1988 (Cth), give you the right to ask an organisation what personal information it holds about you, and to ask it to correct anything inaccurate, out of date, incomplete, or misleading. A related right under APP 11.2 lets you ask an organisation to destroy or de-identify information it no longer needs for any purpose it is permitted to use it for.
None of these rights come with a formal application process. The OAIC’s own guidance to organisations is explicit on this point: there are no formal requirements for an individual to make an access request, and while an organisation may suggest a form, it cannot require an individual to use one. The same applies to correction requests: an entity cannot require a particular procedure, a designated form, or an explanation of why the request is being made.
The minimum information principle
Verification is still allowed, since an organisation has to be reasonably satisfied it is dealing with the right individual before it hands over or alters anything. But the standard is proportionality, not maximum disclosure. The OAIC’s guidelines state that the steps taken to verify identity should depend on the circumstances, including whether the individual is already known to or readily identifiable by the entity, and that only the minimum information needed to establish identity should be sought. Where identity documents are needed at all, the guidance prefers that they be sighted rather than copied and retained.
This cuts both ways. If an organisation’s verification process asks for more than it needs, that is not a neutral inconvenience: the OAIC’s own security guidance gives this almost as a textbook example, noting that requiring extensive personal information to identify someone before giving them access to their own records can itself amount to unnecessary collection, in breach of APP 3.
Why your existing channel is often enough
If you are emailing from the address, or calling from the number, already attached to the account, you are offering exactly the kind of check the guidance treats as adequate: matching what you provide against records the organisation already holds, rather than starting from scratch with new documents. That is a reasonable basis to ask the organisation to verify you that way first, before reaching for a full identity-document form.
Where this has real limits
This is a default position, not an absolute one. Banks, superannuation funds, and similar entities carry separate customer identification obligations under anti-money-laundering law that exist independently of the Privacy Act, and no amount of citing APP 3 will override those. For an everyday retailer, subscription service, or marketer, though, a long verification form is usually the organisation defaulting to its own convenience rather than meeting an actual legal requirement, and that is worth challenging.
A template you can adapt
Subject: Access and correction request, Privacy Act 1988 (Cth), APPs 12 and 13
To [organisation name],
I am writing under Australian Privacy Principles 12 and 13 in relation to the account associated with this email address [or phone number].
This request is made from the email address [or phone number] already recorded against that account, which I ask you to treat as a reasonable means of confirming that I am the account holder, consistent with OAIC guidance that identity verification should seek no more than the minimum information necessary, and that contact details already held can be checked against existing records rather than requiring new identification.
I ask that you:
- Provide access to the personal information you hold in connection with this account; and
- Correct [specify inaccurate or out of date item], or, where you no longer require particular information for any current purpose, take reasonable steps to destroy or de-identify it under APP 11.2.
I am not seeking to provide further identifying information beyond what is already linked to this account. If you reasonably require an additional, minimal confirmation step, such as a one-time code sent to the email address or phone number already on file, I am happy to complete that.
Please respond within a reasonable period, generally understood to be no more than 30 days. If access or correction is refused in whole or in part, please provide your reasons in writing and details of the applicable complaint mechanisms, as required under APP 12.9.
By: ________________________ John Henry, of the family Doe All Rights Reserved
If they still say no
A refusal is not the end of the road. Under APP 12.9, if an organisation refuses access, it must give you written reasons for the refusal and details of how to complain about it. Keep that refusal, along with a record of your original request and the verification you offered. That correspondence is what you would put in front of the Office of the Australian Information Commissioner if you decide to lodge a complaint, and it shows you offered a reasonable path to verification before the organisation insisted on more.
A short checklist
- Send the request from the email or phone number already on the account.
- State plainly what you want: access, correction, or destruction or de-identification under APP 11.2.
- Decline extra identifying information up front; offer a minimal step instead, such as a one-time code.
- Ask for a response within 30 days.
- If refused, ask for written reasons and complaint details under APP 12.9.
- Keep records of everything, in case a complaint to the OAIC becomes necessary.
This is general information only and is not legal advice. Banks, super funds, health providers, and other entities with separate identification or record-keeping obligations under other legislation may lawfully require more than this article describes.
Last Updated 3 months ago
Views: 142