Skip to content

Is the Privacy Act a shield against strata record access?

No. A strata manager cannot use the Privacy Act to refuse a lawful inspection of the owners roll. The Australian Privacy Principles permit a disclosure that is required or authorised by law, and state strata legislation requires the roll to be made available to entitled people. So privacy is not a lawful ground to refuse a proper request. But a covered manager must still secure that data and use it only for authorised purposes.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

The short version: two duties that both apply to the same roll

Strata privacy has a tension at its centre, and most templates only handle one half of it. On one side, state strata law compels you to disclose the roll and records to owners and other entitled people, so you cannot hide behind the Privacy Act to refuse. On the other side, a manager who is covered by the Privacy Act still owes duties to keep that same data secure and to use and disclose it only for proper purposes. Both are true at once. The skill is knowing which one applies to the request in front of you, and this page walks through the line.

Why the law compels disclosure, not the other way around

The owners corporation, and the manager on its behalf, must keep a strata roll and make it available. In New South Wales, the Strata Schemes Management Act 2015 sets what the roll must contain (owners' names and addresses, under s 178), how long records are kept (about seven years, under s 180), and the right of owners and other entitled persons to inspect the records on request and on payment of the prescribed fee (s 182). The NSW Civil and Administrative Tribunal Appeal Panel has put the point bluntly: there is, in effect, no privacy in strata records. The scheme's members are entitled to see how their scheme is run, and that includes the roll.

Victoria and Queensland have their own equivalents. In Victoria the records, register and access duties sit in the Owners Corporations Act 2006 under separate records and register provisions; the exact section numbers differ from New South Wales, so confirm them for your scheme. In Queensland the Body Corporate and Community Management Act 1997 gives interested persons a right to inspect records; confirm the current provision, as it is set by the applicable module. Other states have comparable regimes, so check your own state's Act rather than assuming NSW applies nationally.

The practical upshot: when an owner (or a mortgagee, committee member, or other entitled person) makes a proper request, the starting position is that you disclose, because disclosure is what the law requires. Refusing on "privacy" grounds is not just unhelpful, it is usually wrong.

Why "required or authorised by law" is the key that unlocks it

If you are a covered APP entity, your instinct might be that APP 6 stops you handing personal information to a third party. It does restrict use and disclosure, but it has an exception that matters here. A use or disclosure that is required or authorised by or under an Australian law is permitted. State strata legislation is exactly that kind of law. So when strata law requires you to make the roll available to an entitled person, giving them that access is a permitted disclosure, not a breach. The Privacy Act and strata law are not in conflict; the Privacy Act builds in room for the strata law's disclosure requirement.

This is why the Privacy Act cannot be a shield. The very framework people reach for to refuse access is the framework that authorises the access.

But "you must disclose" is not "anyone can have anything"

Holding the other side of the tension is just as important, and getting it wrong is where covered managers create risk. A lawful right of access has limits, and outside those limits the ordinary privacy duties come back into force.

If you are covered, APP 6 and APP 11 still bind the same data

Whether the Privacy Act reaches your business at all depends on your turnover and structure. Many smaller independent managers under A$3 million, and not part of a larger group, genuinely fall within the small-business exemption. But if you are covered (because you turn over more than A$3 million, or you are a related body corporate of a larger covered group), two obligations sit over the roll at all times, alongside the duty to disclose it:

Even if your business is inside the exemption and the APPs do not bind you, none of this makes the data less sensitive, and state strata law still compels disclosure to entitled people. The exemption is a reason the federal Act may not reach you, not a reason to disclose loosely or to lock records away from people entitled to see them.

How to hold both sides in practice

1. Start from the statutory right. When a request comes in, first ask whether the person is an entitled person making a proper request under your state's strata Act. If they are, the default is to provide access, and privacy is not a valid refusal. 2. Check scope and redaction. Provide the records the Act prescribes, apply any state-specific redaction practice for contact details, and take the prescribed fee where one applies . 3. Refuse only the unentitled. Where the requester has no statutory entitlement, that is where a covered manager's APP 6 duty does the work: you decline because the disclosure is not authorised, not because "it is private". 4. Secure the same data. Behind the counter, APP 11 still governs. Access controls, secure storage, and a retention-and-destruction schedule are the other half of doing this right.

Getting this line right is the hardest single question in strata privacy, and it is the exact gap generic website-policy templates leave open.

Common questions

Can a strata manager refuse a records request on privacy grounds?

Generally no. State strata legislation requires the roll and records to be made available to entitled persons on a proper request, and the Privacy Act permits a disclosure that is required or authorised by law. So privacy is not a lawful ground to refuse a proper inspection. You can decline a requester who has no statutory entitlement, but that is because the request is unauthorised, not because the data is "private".

Does the Privacy Act override state strata law here?

No, and it is not meant to. The two work together. Strata law compels disclosure to entitled people; the Privacy Act's "required or authorised by law" exception makes that disclosure a permitted one. The Privacy Act's role is to govern how you secure the data and stop it being reused or leaked outside those lawful channels.

If I am covered by the Privacy Act, am I breaching it by handing over the roll?

Not when you are handing it to an entitled person under strata law, because that disclosure is authorised by law and permitted under APP 6. You would risk a breach if you disclosed the roll to someone with no statutory entitlement, or reused it for your own purposes, or failed to keep it secure under APP 11.

Do owners' contact details have to be handed over in full?

Not necessarily. Commentary describes a common practice of redacting phone numbers and email addresses before releasing the roll, but the exact position and the prescribed inspection fee are state-specific and change over time, so confirm your own state's current requirements before you release records .

We are a small manager under $3 million. Does any of this apply to us?

The Privacy Act's APP 6 and APP 11 duties may not bind you if you are genuinely within the small-business exemption. But your state strata law still compels you to keep and disclose the roll to entitled people, and your management agreement and state surveillance law apply regardless of turnover. So the "must disclose to entitled people" half applies to you either way; the "must secure under the APPs" half depends on whether you are covered.

Keep reading


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's strata documents are self-authored and are not independently reviewed by a solicitor. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover and structure; state strata legislation on record access and state surveillance-devices law apply separately and vary by jurisdiction. Section numbers and prescribed fees change with amendments, so confirm your own state's current requirements. For advice on your specific circumstances, consult a qualified Australian legal practitioner.