customerrelationshipmanagement.com.auA file of customer records, read from the person’s side

Record Home · the whole file

Customer relationship management, and the person in the record

A customer relationship management system is a file of records about people. Australian privacy law gives people a general right to access their personal information and a way to ask for it to be corrected, and it gives the business holding the record duties of its own. This guide, published by Dotto, reads those rights from the business’s side of the desk.

General information

This is general information, not legal advice. The Office of the Australian Information Commissioner (OAIC) publishes the official guidance on these duties; its pages are listed at the foot of each page here.

Rows of wooden catalogue drawers with brass handles and card labels marked K, L, P and Q, lit warm from one side.
A catalogue cabinet, one drawer to a letter. Photo by DreamQuest on Pixabay

Fields 1 to 6The record, field by field

Open any customer’s record and each part of it meets a different rule. This card follows them down the screen.

Name, birth date, address

The OAIC’s example of inaccurate information is a wrong name, date of birth, residential address or employment detail. Correcting a record

Opinions in the notes

The OAIC says an opinion about a person given by a third party is not inaccurate just because the person disagrees with it. Keeping records accurate

Contact and purchase history

An organisation must give a person access to the personal information it holds about them when asked, except where the law allows a refusal. When a customer asks to see their record

Scores and automatic flags

From 10 December 2026, a privacy policy must carry extra information where a computer program makes or informs decisions that significantly affect people. Automated decisions and your privacy policy

Copies sent to others

On request, an entity must take reasonable steps to tell another APP entity it gave the information to about a correction, unless that is impracticable or unlawful.

Any of it, misused

The statutory privacy tort has been in force since 10 June 2025. The new privacy tort

APP 12 and APP 13Access and correction, side by side

The two requests at the heart of this file run on parallel rules. For an organisation (a business rather than a government agency), they compare like this.

For organisations; agencies follow the line under the table
QuestionAccess (APP 12)Correction (APP 13)
How the person asksNo formal requirements. A business may suggest a form but cannot require one.The same: a form may be offered, never required.
Time to respondA reasonable period. The OAIC’s general guide is no more than 30 calendar days.A reasonable period, with the same general guide of 30 calendar days.
ChargesNothing for making the request. A charge for giving access must not be excessive.Nothing for the request, the correction or attaching a statement.
If the answer is noA written notice giving the reasons (unless that would be unreasonable) and how to complain.A written notice giving the reasons (unless that would be unreasonable) and how to complain, and the person may ask for a statement to be attached to the information.

Agencies are the exception: they must respond to an access request within 30 days and cannot charge for providing access.

ScopeWhose records these rules cover

The privacy principles bind “APP entities”, and the OAIC sets out which businesses that includes. The tort reaches further: the OAIC says it extends “to individuals and other entities that may not necessarily be an Australian Privacy Principle entity”.

Records 1 to 5The five guides in this file

  1. 01

    When a customer asks to see their record

    Checking who is asking, finding everything held, the ten grounds for refusal and what may be charged.

  2. 02

    Correcting a customer’s record

    The five words that make information wrong, and what happens when the business disagrees.

  3. 03

    Keeping customer records accurate

    APP 10’s reasonable steps, and the OAIC’s examples read as a checklist.

  4. 04

    Automated decisions and your privacy policy

    The new privacy-policy duty that starts on 10 December 2026, and the software it reaches.

  5. 05

    The new privacy tort and the customer record

    Who can sue, for what, the defences and the time limits.

Each guide starts from the same place: a real person, a record about them, and what the Act and the OAIC say that record owes them.