Police checks and pre-employment medicals: handling sensitive candidate information
A criminal-history (police) check and a pre-employment medical are not ordinary personal information. Both are sensitive information under s 6(1) of the Privacy Act, and sensitive information carries a higher bar: APP 3.3 says you generally need the candidate's consent to collect it and the collection must be reasonably necessary for your functions or activities. That means you do not run these checks on everyone by default, you collect the result only where the role genuinely calls for it, and you protect and dispose of it carefully.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice, and this page does not tell you whether a particular check is lawful for a particular role.
Why these are treated differently
The Privacy Act defines a category of sensitive information that gets extra protection. The s 6(1) definition is a closed list, and two things on it are a person's criminal record and their health information. So:
- A police or criminal-history check result is sensitive information (criminal record).
- A pre-employment medical, functional assessment or any health-related screening result is sensitive information (health information).
Ordinary candidate data (contact details, work history) is personal information; these two are a rung above it.
The higher standard, in practice
For sensitive information, APP 3.3 says you collect it only if both of these hold, unless an APP 3.4 exception applies:
- the candidate has consented to the collection, and
- the collection is reasonably necessary for your functions or activities.
For a recruiter, that translates into a disciplined approach:
- Collect only where the role calls for it. Do not run a blanket police check or medical on every candidate. Tie the check to the actual requirements of the specific role, and collect the result only for candidates where it is genuinely necessary (typically the preferred candidate, not the whole field).
- Get clear, specific consent before you collect, and make the purpose plain in your collection notice. Read: the candidate collection notice
- Collect the outcome, not everything. Often you need the check's result or clearance status, not a full copy of a candidate's medical file or complete criminal history.
- Secure it and dispose of it. Store screening results with tighter access than ordinary candidate data. APP 11.2 requires reasonable steps to destroy or de-identify it once you no longer need it and no Australian law requires you to keep it. Read: how long to keep candidate records
Where privacy stops and legal advice starts
This is the important boundary. Privacy law governs how you collect, use, secure and dispose of the screening data. It does not tell you whether you are allowed to require the check in the first place. Whether a role may lawfully require a police check or a medical, and how anti-discrimination law (including disability and criminal-record discrimination) constrains what you can ask and how you use a result, are separate legal questions. Spent convictions are a separate regime again: the Commonwealth scheme sits in Part VIIC of the Crimes Act 1914 (Cth), and each state and territory runs its own on its own rules, so there is no single national answer. We do not answer those questions, and neither does a template. The privacy question you can answer today is narrower: for every screening result you hold right now, can you name the role it was collected for, the consent you relied on, and the date it gets destroyed?
This is general information and document templates you tailor to your own business, not legal advice.
Common questions
Can we just run a police check on everyone who applies?
Treat that as no. Sensitive information generally needs consent and must be reasonably necessary, so a blanket check across every applicant is hard to justify on the privacy standard, and it may raise separate discrimination issues that are outside privacy law. Tie the check to the role and collect it only where needed.
The client employer asks us to hold the medical and police results. Can we?
Collection sits on the APP 3.3 standard. The disclosure to the client employer is a separate step with its own test: under APP 6, a secondary purpose for sensitive information must be directly related to the primary purpose, where for ordinary information merely related is enough. So name that disclosure in your collection notice and in the consent you take. Whether you hold the result at all, or leave it with the employer, is a minimisation question: keep as little as you need for as short as you need.
Is a working-with-children check different?
It is still sensitive information, but the collection route can differ. APP 3.4(a) lifts the consent-and-necessity test where the collection of the information is required or authorised by or under an Australian law or a court/tribunal order, and working-with-children checks are state and territory statutory schemes. So where the law requires the check for that role, consent is not what you are relying on. Notice, minimisation, security and destruction are unchanged. Whether a role legally requires one is a legal question for your jurisdiction.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice, and does not advise whether any particular screening check is lawful or appropriate for a particular role. Anti-discrimination, spent-convictions and inherent-requirements questions are legal questions to take to a qualified practitioner. For advice on your specific circumstances, consult a qualified Australian legal practitioner.