BLOG

Have you considered how your business handles sensitive information, now that the significant amendments to the Privacy Act 1988 (Cth) are in force? The changes mean pharmacies have to be more careful than ever with patient data. By taking the right steps now, your business can stay ahead of potential issues and avoid hefty fines or trouble with the regulator.

Key Changes Affecting Pharmacy Businesses

  1. Introduction of a Statutory Tort for Serious Invasions of Privacy

With effect from June 2025, individuals can sue the owner of a business if their privacy is intentionally or recklessly violated in a serious manner, even if no financial harm occurred. The maximum amount of damages that can be awarded to an individual is capped at $478,550. Take the time now to ensure that robust data protection measures are in place to prevent unauthorised access or disclosure of personal information in your business.

  1. Stronger Enforcement from the Privacy Regulator

Pharmacies should expect more scrutiny around privacy compliance, especially regarding how they collect, store, and share patient data. The Office of the Australian Information Commissioner (OAIC) has expanded authority to enforce privacy laws and can now investigate, issue compliance notices, or impose penalties for breaches. Public inquiries can also be conducted to make the public aware of behaviour that, while may not be unlawful, is in the public interest and warrants being in the public domain. Ensure your business is prepared to demonstrate compliance with privacy laws upon request.

With stronger enforcement from the OAIC, pharmacies risk significant penalties and damage to their reputation if they fail to comply with privacy regulations. Non-compliance could result in fines, public inquiries, and the loss of customer trust, which can be detrimental to business operations.

  1. Tighter Rules on Collecting and Using Data

Businesses are now required to collect only the personal information that is necessary for their function or activity. In addition, personal information should only be used or disclosed for the primary and original purpose for which it was collected (unless one of the limited exceptions apply). For example, if a patient provides their mobile number for prescription reminders, that number should not be used for marketing purposes without the individual providing proper consent. Pharmacies should review their data collection and handling practices to ensure they align with these data minimisation principles.

  1. More Transparency About Automated Decision-Making

Does your business use automated decision-making in any of your systems, such as AI-powered systems for reviewing prescriptions or conducting eligibility checks? If so, these must now be disclosed in your privacy policy. Patients must be informed about what kind of personal data is used in the automated systems, and how decisions are made using this data. Patients should be given the opportunity to understand how technology is used in their healthcare and be allowed to question or challenge the decisions if made by AI.  Consider whether your existing privacy policy needs to be updated in light of this change.

What steps can you take to reduce the likelihood of negative impacts on your business?

  1. Carefully consider how you collect data. Can the amount of personal data be minimised?
  2. Review and amend your privacy policy to ensure it is transparent and clearly sets out how you use or disclose the data, including any automated processes.
  3. Improve data security to prevent breaches and unauthorised access.
  4. Train staff – make sure your employees understand privacy obligations and know how to consistently follow best practices when handling personal information.
  5. Review your data retention and deletion practices – don’t store unnecessary patient information for longer than required.
  6. Conduct regular privacy impact assessments – evaluate the potential risks associated with systems you use, particularly those involving sensitive health or other personal information.

While the changes may seem onerous, ensuring you are across them will help build trust with your customer base and help to prevent negative financial and legal implications.

If you would like more information, please contact us by email at hello@vitalitylawaustralia.com.

This article is intended to be for general information only. It does not constitute legal advice nor does it establish a relationship of client and lawyer. Specific circumstances or changes in law may vary the accuracy or applicability of the information published. We recommend seeking specific legal advice particular to your circumstances before taking any action, or refraining from taking any action, on any issue dealt with in this article.