ACT Workplace Privacy Act 2011
Part 3: Notified surveillance – ACT Workplace Privacy Act 2011

ACT Workplace Privacy Act 2011 16: s 16 Data surveillance: policy on computer resource use, logging, access and auditing, notified in advance

An employer uses a data surveillance device to conduct surveillance of a worker only in line with an employer policy on data surveillance of workers, notified to the worker before the surveillance so that the worker can reasonably be assumed to know and understand it. The policy states how the employer's computer resources (including internet access and electronic communication applications) may and must not be used, which usage information is recorded in logs and who can see those logs, and the way the employer checks and audits compliance with the policy. Failure is an offence (s 18(3), 20 penalty units).

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • APP-1 APP 1 - Open and transparent management of personal information

ISO 27002:2022 · 1 control

  • 5.10 Acceptable use of information and other associated assets

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 3: Notified surveillance – ACT Workplace Privacy Act 2011

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.