Skip to main content
Home Legal
Australia Privacy and Data Protection

Australia Privacy and Data Protection

Version 1.0 · Effective 22 August 2026

What DECTIFY owes you under the Privacy Act 1988 (Cth), how the Australian Privacy Principles apply to a company with no Australian entity, and what to do when we get it wrong.

Global Privacy Act 1988 13 APPs NDB scheme OAIC

Read this together with the Privacy Policy. Where the two differ for a person in Australia, this page governs. It is our APP 1.3 privacy policy for Australian purposes.

We are an overseas recipient. DECTIFY has no Australian incorporated entity. Australian customers contract with DECTIFY Technologies Private Limited in India, and personal information given to us is disclosed to an overseas recipient. Section 6 explains exactly what that means for your rights and who answers for a breach.

1. Why the Privacy Act applies to us

Section 5B of the Privacy Act extends the Act to an organisation outside Australia that carries on business in Australia and collects or holds personal information in Australia. DECTIFY carries on business in Australia by supplying the Platform and Hardware to Australian customers and by operating deployed systems at Australian sites. We therefore treat ourselves as bound by the Act and the thirteen Australian Privacy Principles, and we do not rely on the small business operator exemption.

2. Sensitive information

Under section 6 of the Privacy Act, biometric information used for automated biometric verification or identification, and biometric templates, are sensitive information. So is information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation, health and criminal record.

Sensitive information carries a higher bar: under APP 3.3 it may generally only be collected with consent and where reasonably necessary for a function or activity, unless an exception applies. This is the single most important consequence of Australian law for how our products may be deployed, and it is dealt with operationally at Biometric, ANPR and Facial Recognition Policy.

3. How the thirteen APPs apply

APPWhat it requiresWhat we do
1 Open and transparent managementManage information openly; have a clearly expressed, up-to-date policyThis page and the Privacy Policy, versioned and dated, free of charge, in an accessible format on request
2 Anonymity and pseudonymityGive the option of dealing anonymously or by pseudonym where lawful and practicableYou may browse our site without identifying yourself, and may raise a privacy complaint or report misuse anonymously
3 Collection of solicited informationCollect only what is reasonably necessary; consent for sensitive informationWe collect the categories listed at Privacy Policy s.3 and no more. We collect no biometric information about website visitors
4 Unsolicited informationDestroy or de-identify unsolicited information that could not have been collectedAssessed on receipt and destroyed where APP 4.3 requires; recorded in the destruction log
5 Notification of collectionNotify at or before collection, or as soon as practicable afterCollection notices at each form; for deployed systems, site signage the customer must post under clause 5.2 of the Terms and Conditions
6 Use and disclosureUse only for the primary purpose, or a related secondary purpose you would reasonably expectPurposes are tabled at Privacy Policy s.4. We do not repurpose Customer Data
7 Direct marketingRestrictions on marketing, with a simple opt-outBusiness contacts only, on consent, with one-click unsubscribe in every message. We also comply with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth)
8 Cross-border disclosureTake reasonable steps to ensure an overseas recipient does not breach the APPsSee section 6 below — this is the APP that matters most in our case
9 Government related identifiersDo not adopt, use or disclose a government identifier as your ownWe do not collect or use Tax File Numbers, Medicare numbers, driver licence numbers or any government identifier as an identifier of an individual
10 QualityEnsure information is accurate, up to date and completeCorrection on request; and for outputs, the accuracy limits stated at Biometric, ANPR and Facial Recognition Policy s.6, which is why human review is mandatory
11 SecurityProtect from misuse, interference, loss and unauthorised access; destroy or de-identify when no longer neededControls at Australia Cybersecurity and Technology; destruction per the Data Retention Schedule
12 AccessGive access on request, with limited exceptions, within a reasonable periodWithin 30 days, free; if we refuse we give written reasons and tell you how to complain
13 CorrectionCorrect on request; notify others you disclosed toWithin 30 days; on refusal you may require a statement of correction to be associated with the record

4. Your rights, and our timelines

  • Access (APP 12) — we respond within 30 days and provide access in the manner you request where reasonable and practicable. No charge to make a request; any charge for giving access will be reasonable, notified first, and never a barrier.
  • Correction (APP 13) — within 30 days, free. If we decline, you may require us to attach a statement noting that you consider the information inaccurate.
  • Anonymity (APP 2) — available for browsing, complaints and misuse reports.
  • Opt out of marketing (APP 7) — immediate, by the unsubscribe link or by email.
  • Complain — to us, then to the OAIC. See section 8.

Requests go to privacy@dectify.in. We may need to verify your identity and will ask for the minimum required. If we refuse access under an APP 12.2 or 12.3 exception, we give written reasons and the complaint route.

5. Surveillance devices legislation

The Privacy Act is not the only law that governs a camera in Australia. Each State and Territory has its own surveillance devices legislation, which operates independently and can prohibit conduct the Privacy Act would permit.

JurisdictionPrincipal Act
New South WalesSurveillance Devices Act 2007 (NSW); Workplace Surveillance Act 2005 (NSW)
VictoriaSurveillance Devices Act 1999 (Vic)
QueenslandInvasion of Privacy Act 1971 (Qld); Police Powers and Responsibilities Act 2000 (Qld)
Western AustraliaSurveillance Devices Act 1998 (WA)
South AustraliaSurveillance Devices Act 2016 (SA)
TasmaniaListening Devices Act 1991 (Tas)
Australian Capital TerritoryListening Devices Act 1992 (ACT); Workplace Privacy Act 2011 (ACT)
Northern TerritorySurveillance Devices Act 2007 (NT)

Audio is the trap. Recording a private conversation without consent is an offence in every Australian jurisdiction, with narrow exceptions. Audio capture is disabled by default on all DECTIFY hardware supplied to Australian sites and must not be enabled without written legal advice the customer holds. In New South Wales and the ACT, workplace surveillance legislation additionally requires prior written notice to employees and, in some cases, a covert surveillance authority from a magistrate.

Compliance with these Acts is the customer's obligation under clause 18.2 of the Terms and Conditions. We will not configure a deployment that we are told would breach them.

6. Cross-border disclosure, and what it means for you

6.1 Where your information goes. Personal information collected from Australian individuals is disclosed to DECTIFY Technologies Private Limited in India, and to the sub-processors listed at Sub-processors with their countries stated. Customer Data from Australian deployments is hosted in an Australian region by default.

6.2 The reasonable steps we take (APP 8.1). We contractually bind ourselves and every sub-processor to handle Australian personal information consistently with the APPs; we impose the security controls at Australia Cybersecurity and Technology; we restrict access on least privilege with full audit; and we require sub-processors to notify us of any breach without undue delay.

6.3 Accountability (section 16C). Because we take these steps rather than relying on your consent to unaccountable disclosure, we remain accountable under the Privacy Act for an act or practice of an overseas recipient that would breach the APPs. You do not lose your remedy because your information left Australia. You may complain to the OAIC about us.

6.4 Where you consent instead. If we ever ask you to consent to a disclosure without those safeguards under APP 8.2(b), we will say so expressly and tell you that the accountability in 6.3 will not apply. We do not currently rely on that route.

7. Notifiable Data Breaches

Part IIIC of the Privacy Act requires notification of an eligible data breach — unauthorised access, unauthorised disclosure or loss of personal information that is likely to result in serious harm.

  • Assess within 30 days. Where we suspect an eligible data breach, we carry out a reasonable and expeditious assessment within thirty (30) days, and usually far sooner.
  • Notify as soon as practicable. If the breach is eligible, we notify the OAIC and the affected individuals as soon as practicable — not at the end of any period.
  • What the notice says. Our identity and contact details, a description of the breach, the kinds of information involved, and the steps we recommend you take.
  • Customer Data. Where a breach concerns Customer Data, the customer is the APP entity that notifies. We notify the customer without undue delay and within seventy-two (72) hours, and give them the information they need to assess and notify. Where both of us hold the information, only one of us needs to notify, and we will agree who so that you are not notified twice or not at all.
  • Also. A breach may simultaneously trigger our six-hour CERT-In obligation in India. Both clocks run; neither delays the other.

8. Complaints

  1. Us first. privacy@dectify.in, or the officers at Grievance Redressal. We acknowledge within 3 business days and respond substantively within 30 days.
  2. Then the OAIC. If we have not responded within 30 days, or you are not satisfied, complain to the Office of the Australian Information Commissioner at oaic.gov.au, by post to GPO Box 5218, Sydney NSW 2001, or by phone on 1300 363 992. The OAIC will normally expect you to have raised it with us first.
  3. Representative complaints. The Act permits representative complaints where a group is affected by the same conduct.

9. Reform

The Privacy Act is being reformed following the Attorney-General's Department review. The Privacy and Other Legislation Amendment Act 2024 introduced, among other things, a statutory tort for serious invasions of privacy, a Children's Online Privacy Code, and automated decision-making transparency requirements that take effect on a staged basis.

We are building to the reformed position rather than the minimum currently in force: our automated decision-making disclosure is at Australia AI and Responsible Technology, and our treatment of children's data is at Acceptable Use Policy clause 2.7. Changes to this page as further reforms commence are recorded at Compliance and Security Updates.

If your question is about footage. The organisation operating the cameras is the APP entity responsible for it, not us. Its details should be on the site signage. If you cannot identify it, send us the location, date and approximate time and we will route your request or tell you that no DECTIFY system operates there.

Contact

Questions about this document: legal@dectify.in

DECTIFY Technologies Pvt. Ltd., New Delhi, India