Personal information and sensitive information are the two categories the Privacy Act 1988 (Cth) (the Act) uses to decide how carefully you must handle the data your business collects. Personal information is the broad category: almost anything that identifies, or could identify, a person. Sensitive information is a smaller, higher-risk subset of it, and the law makes you clear extra hurdles before you can collect, use or share it.
Getting the classification right matters before a complaint, not after. If you treat health details or beliefs like ordinary contact data, you can end up marketing with data you had no right to use, or disclosing records you were expected to protect. This article explains what each category covers under the Act, how the Australian Privacy Principles (the APPs) treat them differently, and how to work out which category your own records fall into.
What counts as personal information
The Act defines personal information as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether it is true or not and whether it is recorded in a material form or not (s 6(1)). Three parts of that definition do the real work.
First, the information does not need to name anyone. A person is covered if they are reasonably identifiable, whether from the information on its own or from that information combined with other data you hold or can get hold of. An email address, a phone number, a customer account number or an IP address can each be personal information if it lets you work out who the person is. A row in a spreadsheet labelled "Customer 47" is still personal information if you hold the key that tells you Customer 47 is Priya Sharma.
Second, accuracy is irrelevant. A mistaken note about a customer, or a recorded guess about someone's circumstances, is still personal information. The definition deliberately covers information or opinion, true or not.
Third, the form does not matter. Whether the information sits in a database, a paper file, a spreadsheet or an email thread, "recorded in a material form" catches all of it.
For a typical Australian business, common examples include names and addresses, dates of birth, order and payment history, employment details, resumes, and CCTV footage that shows identifiable people.
What makes information sensitive
Sensitive information is not a general category you judge by feel. It is a defined list in s 6(1) of the Act, covering information or an opinion about:
- racial or ethnic origin
- political opinions, or membership of a political association
- religious beliefs or affiliations, and philosophical beliefs
- membership of a professional or trade association, or a trade union
- sexual orientation or practices
- criminal record
- health information
- genetic information that is not otherwise health information
- biometric information used for automated biometric verification or identification, and biometric templates
Each item only counts as sensitive if it is also personal information, which in practice it almost always is. An individual's criminal record, for instance, is sensitive information the moment it identifies them.
Health information has its own expanded definition in the Act (s 6FA). It covers information or an opinion about a person's health, illness, disability or injury at any time, their expressed wishes about future health services, health services provided or to be provided to them, personal information collected in providing a health service, and genetic information that could predict the health of the person or a genetic relative. That is why pre-exercise questionnaires, injury records and medication lists all land in the sensitive category.
One nuance is worth flagging because it surprises people: not every photo or fingerprint is sensitive. Biometric information only becomes sensitive when it is to be used for automated biometric verification or identification, such as facial recognition matching against a reference image. A photo in a customer file is ordinary personal information. The same photo used as a facial recognition reference is sensitive.
How the law treats the two categories differently
The APPs impose the same broad obligations on both categories, then add extra conditions for sensitive information at three points.
Collection
Under APP 3, an organisation must not collect personal information unless it is reasonably necessary for the organisation's functions or activities. For sensitive information the bar is higher: collection needs the individual's consent and must still be reasonably necessary. The exceptions are narrow, and include collection required or authorised by law, or needed to lessen or prevent a serious threat to life, health or safety. In practice this means you design a consent step into the form, survey or onboarding process before sensitive fields are completed, rather than relying on general fine print.
Use and disclosure
APP 6 lets you use or disclose personal information for a secondary purpose if the individual consents, or would reasonably expect it. For ordinary personal information, the secondary purpose only needs to be related to the original purpose of collection. For sensitive information it must be directly related to that purpose, a noticeably higher test. Passing health questionnaire answers to a third-party wellness app because it is "kind of related" to running a studio does not meet it.
Direct marketing
APP 7 prohibits using personal information for direct marketing unless an exception applies, and those exceptions are written to cover only information other than sensitive information. Sensitive information can therefore be used for direct marketing only with the individual's consent. Ethnicity answers in an optional survey, or the fact that a member disclosed a heart condition, cannot quietly feed a promotional campaign.
Who has to follow the APPs
Whether the APPs bind you at all turns largely on turnover. The Act defines a small business as one with annual turnover of $3 million or less for the previous financial year (s 6D), and small business operators are generally exempt from the APPs. The exemption drops away in a list of situations, including where the business is a health service provider, trades in personal information, or is a contracted service provider to the Commonwealth. Because the exemption turns on what you actually do, a two-person clinic or a retailer that sells customer lists can be caught even though its turnover is well under the threshold.
There is a trap here for wellness and fitness businesses in particular. The Act's definition of a health service is broad, and some studios, personal trainers and coaches collect health-related data as a core part of what they offer. Whether that makes them health service providers for privacy purposes is worth checking with a lawyer, because if it does, the small business exemption does not protect them.
Even where the exemption does apply, the personal versus sensitive distinction is still the right way to build your systems. The Act is under active review, and reform proposals have included extending coverage to more small businesses, so a classification done now will survive changes in the law. Customers also expect the same care either way.
A worked example: the fitness studio
Say you run a boutique fitness studio with two instructors and a mailing list of 400 members. At signup you take the member's name, email, phone number and date of birth. Before their first class, members complete a two-page questionnaire asking about injuries, ongoing conditions, medications and any history of heart problems.
The signup details are personal information. They identify the member and are reasonably necessary for running the studio, so you can collect them without a bespoke consent step. You can also email members about class times and schedule changes where they would reasonably expect it, as long as you offer a simple opt-out.
The questionnaire answers are sensitive information under the health information limb of the definition, and that changes everything downstream. You need the member's consent to collect them at all. You can use them only for the purpose they were given, planning safe exercise, and they should not flow to the marketing team, the class timetable app or a cloud service that has not been checked. If you later want to use the answers to target members with injury-recovery programs, that is a secondary purpose that is not directly related to the original one, so you would need fresh, specific consent for it.
The stakes show up most clearly in a breach. A stolen mailing list is a data breach. A leaked file of members' health questionnaires is far more likely to be assessed as causing serious harm, and for a business covered by the Act that can trigger the notifiable data breach obligations, including reporting to the Office of the Australian Information Commissioner and notifying the affected members. The same incident costs very differently depending on which category the leaked data fell into.
Common misconceptions
Some misconceptions about the two categories keep coming up whenever businesses review their data handling:
-
"Sensitive information is just medical information": The list is much broader. Religious beliefs, political opinions, union membership, sexual orientation, criminal records and biometric templates are all sensitive, and none of them is medical. A recruitment firm holding criminal history checks, or a community organisation holding members' beliefs, carries the same heightened obligations as a clinic.
-
"If the information is wrong, it doesn't count": The definition catches untrue information and recorded opinions. A defamatory or mistaken note about a customer is still personal information, and if it touches a sensitive category, it is sensitive information, correct or not.
-
"Once data is de-identified, we are safe": De-identified means the information is no longer about an identifiable individual. But if you keep the re-identification key, or the data can reasonably be linked back to a person, it is still personal information and still subject to the rules. De-identification is a process with conditions, not a label you can stick on a file.
-
"We are a small business, so none of this applies": The exemption is real but situational. Health service providers, businesses that trade in personal information and contracted service providers to the Commonwealth are covered regardless of size, and the carve-outs catch businesses that do not think of themselves as data businesses.
-
"Consent fixes everything": Consent is the gateway for sensitive information, but it must be voluntary, informed and specific, and it is easy to withdraw. It also does not switch off the other obligations that apply to whatever you collect: security, retention limits, access requests and breach handling all continue to bite.
When to bring in a privacy lawyer
A practitioner earns their fee by turning the definitions above into decisions about your actual systems. Typically that means running a data-mapping exercise, going field by field through your forms, databases, emails and third-party platforms to classify each item as personal or sensitive, then checking each classification against what you collect, use and disclose. They will review your privacy policy and collection notices so the documents match what your business really does, and build a consent flow that is specific, informed and easy to withdraw rather than a checkbox buried in a signup.
For a business holding health, biometric or children's data, a classification review up front is markedly cheaper than unpicking a consent failure after a complaint reaches the regulator. A lawyer will also review vendor and cloud contracts so third parties are bound to comparable standards, prepare a breach response plan before it is needed, and manage the response if a complaint does land with the Office of the Australian Information Commissioner.
The classification question to ask about every form
The misstep that costs businesses most here is not the exotic case. It is treating sensitive information like ordinary contact data because it arrived on the same form. Before you build the next form, survey or onboarding flow, go field by field and ask whether the answer could be about a person's health, beliefs, associations, sexual orientation, criminal record, genetics or biometrics. If it could, your collection notice, consent mechanism, access controls, marketing rules and retention schedule all have to be built around that answer from the start, not bolted on afterwards. If you cannot name which of the data fields you hold are sensitive, that is the first gap to close.