Skip to main content
intelID
Menu

Compliance

Authorised purpose under the Privacy Act 2020: what it means for every search you run

Authorised purpose is the test that decides whether a search is lawful. Here is how to state one properly and record it at the time.

Published · Reviewed

Most privacy failures in search work are not caused by an exotic technical breach. They are caused by someone running a legitimate query for a reason that was never lawful, or that was lawful once and then quietly reused for something else. The concept that separates the two is purpose. Under the Privacy Act 2020 the purpose is not paperwork that follows the search; it is the thing that makes the search permissible in the first place.

What the Act actually requires

Information privacy principle 1 says an agency must not collect personal information unless it is collected for a lawful purpose connected with a function or activity of the agency, and the collection is necessary for that purpose. Two tests sit inside that sentence. The purpose must be lawful and genuinely yours. The collection must be necessary — not convenient, not interesting, not something you might use later.

Principle 4 adds that collection must be by lawful means that are fair and not unreasonably intrusive in the circumstances. Principles 10 and 11 close the loop at the other end: you may use the information only for the purpose it was obtained for, and you may disclose it only on defined grounds. Principle 9 requires that you not keep it longer than the purpose requires. Principle 5 requires reasonable security safeguards while you hold it.

Taken together, these principles describe a lifecycle rather than a gate. A search that was properly authorised on Monday can become a breach on Friday if the result is repurposed, over-shared, or retained for no reason.

Why the wording of the declaration matters

A declaration is a statement of the reason for a specific search on a specific subject. Its job is to be checkable later by someone who was not there. Compare these:

  • Weak: "Debt recovery."
  • Weak: "Client instruction."
  • Weak: "Investigation."
  • Strong: "Locating the current address of a named judgment debtor to enforce a District Court judgment, file reference 2026-0412, on instruction from the judgment creditor."
  • Strong: "Confirming the directorship and shareholding of a named individual for AML customer due diligence on a new business customer, onboarding reference 88431."

The strong versions identify the matter, the legal basis, the instructing party and the reason this particular subject is being searched. They can be tested against the file. The weak versions cannot be tested against anything, which is why they are of no use when a complaint arrives.

Applying the necessity test

Necessity is where most well-intentioned searching goes wrong. If the matter is service of proceedings, an address is necessary; a credit file summary probably is not. If the matter is assessing whether to sue, an asset picture is necessary; the defendant's employment history probably is not. Ask what decision the information will inform, and whether the decision could be made without it. If it could, do not collect it.

Proportionality runs alongside necessity. The intrusiveness of the search should match the seriousness of the matter. A $2,000 disputed invoice does not justify the same depth of enquiry as an alleged large-scale fraud. Recording that you considered this — and chose the narrower search — is itself useful evidence of good practice.

Scope creep and the second matter

The common failure pattern is simple. A search is run properly for matter A. Three months later, the same subject appears in matter B, and someone reaches for the stored result rather than declaring a new purpose. That is a principle 10 problem even though no new search occurred. The fix is procedural: treat each matter as its own purpose, run the search again under a fresh declaration, and let the audit log show that you did.

Sector overlays

The Privacy Act is the floor, not the ceiling. Credit information carries the additional conditions of the Credit Reporting Privacy Code 2020, which restricts both who may access a credit file and the purposes for which they may do so. Reporting entities under the AML/CFT Act have statutory obligations that supply their own purpose, but that purpose is bounded: customer due diligence justifies verification searches, not general curiosity about a customer's affairs. Licensed investigators must also keep within the terms of their licence and their client's instruction.

Making the record automatic

A declaration written from memory a week later is worth very little. A declaration captured at the moment of the search, tied to the user who ran it and the results returned, is worth a great deal. That is why intelID requires an authorised-purpose declaration before any search executes, and writes it into an immutable audit record together with the user, the timestamp, the sources queried and the result set.

The practical benefits show up in three places. Supervisors can sample searches and see whether declared purposes match live matters. Complaints can be answered with a record rather than a recollection. Access reviews by data providers can be satisfied without a manual reconstruction.

A short internal checklist

  • Name the matter and its reference before you search.
  • State why this subject, and why now.
  • Choose the narrowest source set that answers the question.
  • Record which sources you ran and what they returned.
  • Use the result only for the declared matter.
  • Apply your retention rule and delete on schedule.

Further reading

Our full position is set out on the compliance page, the controls that enforce it on the security page, and the search workflow itself on the platform page. If your team needs accounts, request access.

Questions on this topic

What is an authorised purpose?

It is the specific, lawful reason connected with your function or activity that makes a particular search necessary. It is stated before the search runs and recorded against it.

Is 'due diligence' an authorised purpose?

On its own, no. It names a category rather than a reason. 'Pre-contract due diligence on a named supplier before a supply agreement is signed' identifies the matter, the subject and the need.

Do I need consent as well as a purpose?

Not always. Consent is one basis for collection and disclosure, but the Privacy Act 2020 permits collection without consent in defined circumstances. Where you rely on consent, keep evidence of it.

Can I reuse a result for a second matter?

Information principle 10 limits use to the purpose for which the information was obtained, with limited exceptions. A new matter generally needs a new declaration and a new search.

Who checks the declarations?

Your own supervisors first, and then anyone reviewing a complaint: the Privacy Commissioner, a court, a client, or the data provider auditing access under its licence terms.

More insights

Request access to intelID

There is no self-service signup. Access is granted after verification of your identity, your organisation and your authorised purpose.