AI Call Recording for Business: What It Captures and What You Can Legally Keep

AI call recording: a call centre agent wearing a headset at her desk

TL;DR

AI call recording is two things stacked: the recording, which has been legal territory for decades, and the AI layer that turns a stored audio file into a searchable transcript.
Recording and keeping have different answers. Federal law governs intercepting a call; the Privacy Act governs what you then do with it afterwards.
Businesses turning over $3 million or less are generally outside the Privacy Act, but the carve-outs catch more ordinary businesses than owners expect, and health service providers are covered regardless of turnover.
Under APP 11, an entity covered by the Act must destroy or de-identify personal information once it is no longer needed. Indefinite retention is a decision, not a default. The OAIC has also published AI privacy guidance worth reading before the sales demo.
The value of the AI layer scales with how many calls you take. The compliance work does not, and that asymmetry is the whole decision for a small team.

A call recording used to be a file nobody opened. It sat on a server, and the only time anyone went looking was after a dispute. AI call recording changes that arrangement completely: the same call becomes a transcript, and the transcript becomes searchable, summarised and available to anyone with a login.

That is genuinely useful, and it is also what turns a dormant archive into a live collection of personal information. This post separates the two questions people ask as one: what the technology actually captures, and what you are allowed to keep. The legal groundwork on recording a call in Australia is already covered in NexGen’s guide to whether call recording legal obligations apply to your business, and this post does not re-argue it.

This is general information, not legal advice. Call recording law in Australia sits across federal and state legislation, and the right answer depends on your state, your industry and what you do with the recording.

What does AI call recording actually capture?

It captures far more than the audio. A modern system produces a stored recording, a machine transcript of the whole conversation, a short summary, and usually a set of derived fields: who spoke, for how long, what the call was about, and sometimes a sentiment or outcome label.

Each is a separate artefact with its own life. The audio might be retained for 30 days while the transcript stays forever in a search index. That distinction rarely appears on a feature list, and it is the single most useful thing to ask about.

What ends up in a transcript, on an ordinary business line:

In the transcript Why it matters
Names, addresses, dates of birth Volunteered by callers confirming their identity
Payment details read aloud Card numbers spoken to a person become text in a database
Health, financial or legal detail Sensitive information attracts stricter handling
Staff performance signals The recording is now also a record about your employees
Inferred labels Sentiment and intent the machine assigned, not what anyone said

That last row is worth pausing on. The OAIC’s guidance is explicit that where an AI product generates or infers information about an identifiable person, that is a collection of personal information and APP 3 applies. A sentiment score is not a neutral byproduct. It is a new fact your business created about a named individual.

What changes when a machine keeps a searchable copy

The recording was always personal information. What changes is how easily it can be found, and by whom. Three shifts follow, and none of them are technical problems.

Access widens. An audio archive was protected by inconvenience: nobody was going to listen to 400 calls. A searchable index removes that friction, so who can search it becomes a real access-control decision rather than a theoretical one.

Purpose creep gets easy. A recording collected to resolve disputes is one thing. The same recording mined for sales coaching, then performance management, then model training, is a series of new purposes. The OAIC’s guidance notes APP 6 limits use to the primary purpose, and that given public concern about AI, establishing that a person would reasonably expect an AI-related secondary use is difficult.

The breach surface changes shape. Losing a structured, searchable transcript store is worse than losing audio, because the data is already organised for whoever finds it. If you are covered by the Privacy Act, the data breaches scheme requires you to notify affected individuals and the OAIC when a breach is likely to result in serious harm, and to assess within 30 calendar days.

Does the Privacy Act apply to your business?

Generally not, if your annual turnover is $3 million or less, but the carve-outs are broad enough that the turnover threshold on its own should not settle the question. The OAIC’s small business guidance sets out the threshold and the exceptions to it.

The exceptions that matter most on a phone system:

Health service providers are covered regardless of turnover. On the OAIC’s guidance turnover is not the test for anyone providing a health service, so a small practice recording patient calls should work on the basis that it is inside the Act and confirm that, rather than the reverse.
Businesses that trade in personal information are covered, which catches some lead-generation models.
Credit reporting bodies, credit providers and CDR-accredited businesses are covered.
Contractors delivering services under a Commonwealth contract are covered for that work.
Any business can opt in voluntarily, and some do because their customers ask.

“We are too small for the Privacy Act” is a conclusion to check against that list, not an assumption. And being outside the Act is not the same as having no exposure: your contracts, industry obligations and customers’ expectations do not disappear because a turnover threshold does. Confirm your position with the OAIC or your adviser rather than inferring it.

What can you legally keep, and for how long?

If you are covered by the Privacy Act, you may keep it while you still need it for the purpose you collected it for, and you must then destroy or de-identify it. APP 11 requires an entity to take reasonable steps to protect personal information it holds, and to take reasonable steps to destroy or de-identify it once it is no longer needed for any permitted purpose.

There is no fixed number of days in the principle, which is what makes it awkward. It is a judgement you have to make and be able to defend, so write a retention period down and set the system to enforce it.

01Name the purpose.Dispute resolution, training and compliance are three purposes with three different useful lifespans.
02Set a period per artefact.Audio, transcript and derived fields can and often should expire on different clocks.
03Make the system do it, and record who can search.A policy that relies on someone remembering to delete is not a control, and retention and access need separate answers.
04Consider de-identification instead of deletionwhere the aggregate is genuinely useful. The OAIC’s de-identification guidance is clear that re-identification risk has to be actively assessed and managed, not assumed away.

What should you ask a provider before you switch it on?

Ask where the data lives, who can reach it, how long each artefact is kept, and whether anything is used to train a model. Those four answers tell you almost everything, and a provider who cannot answer them in writing has told you something too.

A shortlist worth taking into a demo:

Where are recordings and transcripts stored, and in which country?
Is any customer audio or transcript used to train or improve a model, and can that be turned off?
What retention periods are available, and can audio and transcript differ?
Who, inside your organisation and the provider’s, can search transcripts?
What happens to the data if you leave? Can you export it, and is it then deleted?

The OAIC publishes a selection checklist for exactly this conversation, and it runs to two pages. Better use of ten minutes than any vendor feature comparison.

Worth separating in your own mind: AI that answers calls and AI that analyses them are different products with different risk profiles. If the answering side is what you are shopping for, the honest assessment sits in whether AI answer calls as well as a person does. If the underlying question is whether hosted infrastructure is safe enough to hold any of this, that is the cloud phone security rundown.

Is AI call recording worth it for a team of ten?

It depends almost entirely on whether anyone will actually read the transcripts, because the compliance work is close to the same whether you take twenty calls a week or two thousand.

That asymmetry is the part a feature demo never surfaces. The value of the AI layer scales with volume: the more calls you take, the more a searchable archive is worth, and the more likely it is that a pattern in it tells you something you did not already know. The obligations do not scale the same way. A retention period still has to be set, a position still has to be established for every state you operate in, and someone still has to own the access list. None of that gets cheaper because the team is small.

NexGen builds phone systems for Australian businesses in the 3 to 20 handset range, and at that size this is a real decision rather than an automatic yes. Two questions settle it more reliably than any feature comparison. Is there a named person whose job it will be to look at this, and is there a recurring question about your calls that you currently cannot answer? If either answer is no, the sensible move is to get the phone system itself right first and revisit the AI layer when the volume justifies the admin around it.

Where this leaves a small Australian team

AI call recording is worth having for a lot of businesses, and for all of them it is worth having deliberately. The businesses that regret it switched it on as a feature and found a retention problem eighteen months later. Three decisions before go-live cover most of it: your legal position on recording in the states you operate in, a retention period per artefact that the system enforces, and a plain statement to callers and staff about what is kept.

NexGen has been building phone systems for Australian businesses for 17 years, with 7,500+ businesses served, an Australian-based support team and ISO 27001 Certified security. Standard onboarding is 7 business days. To see what the call-intelligence layer looks like on a real system before deciding what to enable, start with the AI phone system overview and bring the checklist above with you.

Talk to NexGen about your phone system

See what the call-intelligence layer looks like on a real system before deciding what to enable.

Terms Of Use

Your access to the Nexgen website at https://www.nexgen.com.au is your acceptance of these Terms and Conditions and your access and use of the website is subject to these Terms and Conditions. If you do not accept these Terms and Conditions, you must refrain from using the Website. In these Terms and Conditions, capitalised words have special meanings. These special meanings are set out in the “General” section of this document.

Disclaimer of Liability – General Disclaimer

We are not liable to you or anyone else for any Loss in connection with use of this Website or a Linked Website or the failure to provide this Website.

This general disclaimer is not restricted or modified by any of the following specific warnings and disclaimers.

Disclaimer of Liability – Specific Warnings and Disclaimers

We are not liable to you or anyone else if interference with or damage to your computer systems occurs in connection with use of this Website or a Linked Website. You must take your own precautions to ensure that whatever you select for your use from this Website is free of viruses or anything else (such as worms or trojan horses) that may interfere with or damage the operations of your computer systems.

We may, from time to time, change or add to this Website (including these Terms and Conditions and privacy policy) or information, products or services without notice and your continued use of the Website will constitute acceptance of the variation. However, we do not undertake to keep this Website or these Terms and Conditions updated. We are not liable to you or anyone else if errors occur in the information on this Website or if that information is not up-to-date.

To the extent permitted by applicable law, all representations, warranties and other terms are excluded. You must ensure that your access to this Website is not illegal or prohibited by laws which apply to you or in your location.

To the extent permitted by applicable law, our liability for negligence, breach of contract or contravention of any law as a result of our failure to provide the Website, is limited to providing access to the Website.

You may not use the Website to collect or harvest Personal Information, including Internet addresses, about other users. You must comply with our Acceptable Use Policy available on the Website.

You must abide by any Terms and Conditions posted on the Website. You indemnify us from and against all actions, claims, suits, demands, liabilities, costs or expenses arising out of, or in any way connected to, the use of the Website by you.

Charges

You are responsible for the costs of all Internet access and telecommunications charges incurred when using the Website and accept that your use of the Website is your responsibility and is at your own risk entirely.

Nexgen operates secure servers to minimise the risk of unauthorised use of credit card information but unauthorised credit card use is at your risk.

Copyright

This Website, including without limitation, documents, information, programs and designs is our copyright property.

You are provided with access to it only for your personal and non-commercial use.

Other than for the purposes of and subject to the conditions prescribed under the Copyright Act 1968 (Commonwealth of Australia) and similar statutes that apply in your location, you may not, in any form or by any means:

1. adapt, reproduce, store, distribute, transmit, print, display, perform, publish or create derivative works from any part of this Website; or

2. commercialise any information, products or services obtained from any part of this Website, without our written permission.

Google Online Advertising

Nexgen use the Google AdWords Remarketing service which advertises across the internet to previous visitors to our website.

Google AdWords Remarketing displays relevant advertising content based on which sections of the Nexgen website you have visited. This is done by placing a cookie on your machine. A cookie is a small file sent to your browser from a web server to be stored on your computer. Cookies do not allow access to your computer or any data / files contained in your computer. It will not identify you in any way. Google Adwords Remarketing allow us to tailor our advertising and marketing content so it is relevant and suits your needs.

Any data collected as part of our use of Google Adwords Remarketing will be in accordance with Arrow’s privacy policy and Google’s privacy policy.

If you do not wish to be a part of our Google AdWords Remarketing, you can opt out by visiting Google Ads Preference Manager:

https://www.google.com/settings/ads

Then go to the “opt-out settings” where you can opt out of all interest based ads on Google and across the web.

Trade Marks

Intellectual Property in all materials, documents, information, data, images, logos and trade marks that we provide you or which are contained on the Website are owned or licensed to us and all rights are reserved.

Other product and company names mentioned in this Website may be the trade marks of other people or entities.

If you use any of our trade marks to refer to our activities, products or services, you must include a statement attributing that trade mark to us. You must not use any of our trade marks:

Linked Websites

This Website may contain links to Linked Websites. Those links are provided for convenience only and may not remain current or be maintained. We do not make any representation as to the accuracy or sustainability of any of the information contained on those other sites, and do not accept any responsibility or liability for the conduct or content of those other sites.

Links to those Linked Websites should not be construed as any endorsement, approval, recommendation, or preference by us of the owners or operators of the Sites, or for any information, products or services referred to on those Other Websites.

Unless stated otherwise on this Website, we have:

1. no relationship with the owners or operators of those Linked Websites; and

2. no control over or rights in those Linked Websites.

Personal Information

When transacting with you we may ask you for personal details such as your name, address and email address so that we can accurately identify who is using our services. By accessing the Website you consent to us sending you commercial electronic messages. If you do not want us to send you commercial electronic messages you may ask us not to by sending a blank email to [email protected]

Cookies

“Cookies” are a standard for storing small pieces of data on a web client (ie. the web browser on your computer). Any Web server (including this one) may:

1. store one or more cookies in your browser; or

2. request your browser to transmit the data to the Web server.

This Website may store cookies on your Web client in order to better serve you upon your subsequent visits to this Website.

By using cookies, Websites can track information about visitors’ usage of the site, provide customised content, or even the use of password protection. Note that some browsers can be configured to allow cookies to be accessed by servers other than the originating server.

Please note that most Web browsers can also be configured to notify the user when a cookie is received, allowing you to either accept or reject it. Please refer to the documentation and help screens for your web browser.

Security of Information

Unfortunately, no data transmission over the Internet can be guaranteed as totally secure. Whilst we strive to protect such information, we do not warrant and cannot ensure the security of any information or content which you transmit to us. Accordingly, any information which you transmit to us is transmitted at your own risk. Nevertheless, once we receive your transmission, we will take reasonable steps to preserve the security of such information.

Termination of Access

Access to this Website may be terminated at any time by us without notice. Our disclaimer will nevertheless survive any such termination.

General

In these Terms and Conditions:

1. “Intellectual Property” means any and all intellectual and industrial property rights throughout the world including but not limited to any copyright, trade mark, domain name, business name, design, patent, circuit layout, semi-conductor or other similar proprietary rights and licenses and sub-licenses of such rights (irrespective of whether or not such rights are registered, or formal or informal); trade secrets, technical or non-technical data, knowledge, information or documentation; secret or confidential operations or information; business systems, business methods or business plans (whether registered, formal, informal or otherwise); customer lists, supplier lists and other proprietary lists, names, addresses or information not generally known; techniques, diagrams, data, proofs, prints, particulars, inventions and prototypes.

2. “Linked Websites” means Websites of people other than NexGen which are hyperlinked from this Website.

3. “Loss” means any loss or damage, however caused (including through negligence) which may be directly or indirectly suffered.

4. “Personal Information” means any information from which your identity is apparent or can be reasonably ascertained as defined in the Privacy Act 1988 (Cth).

5. This “Website” means the whole or any part of the web pages located at https://www.nexgen.com.au (including the layout of this Website; individual elements of the Website design; underlying code elements of this Website; or text, sounds, graphics, animated elements or any other content of this Website).

6. “We” and “us” refer to Nexgen Australia Group Pty Ltd trading Nexgen Australiaas and “our” has a similar meaning.

These Terms and Conditions are governed by the laws in force in New South Wales, Australia and you submit to the non-exclusive jurisdiction of the courts of New South Wales, Australia and any courts which may hear appeals from those courts in respect of any proceedings in connection with these Terms and Conditions or this Website.

Nothing contained in these Terms and Conditions derogates from Nexgen’s right to comply with law enforcement requests or requirements relating to your use of this Website or information provided to or gathered by Nexgen with respect to that use.

Nexgen Master Security License Certificate Number is 410 295 251, ID Number 108 216 452 Nexgen is a member of ASIAL.

Privacy Policy

  • 1. About this Document
    • 1.1 This document (“Privacy Policy”) sets out the policy of Nexgen Investment Group Pty Ltd Trading As Nexgen Australia – ABN 88 606 251 503 in respect of the treatment of your Personal Information or your affairs or personal particulars.
  • 2. Interaction with Telecommunications Act 1997 (Cth)
    • 2.1 Nexgen is a Carriage Service Provider and is subject to obligations set out in the Telecommunications Act 1997 (Cth)
    • 2.2 To the extent that any of your Personal Information is also information of the kind referred to section 276 of the Telecommunications Act 1997 (Cth) (in particular, information that relates to your affairs or personal particulars) Nexgen will not use or disclose that information unless permitted by the Telecommunications Act 1997 (Cth) and the Privacy Act 1988 (Cth).
  • 3. Dictionary
    • 3.1 To assist in the understanding of this Privacy Policy, the following capitalized words in this Privacy Policy have the following meanings:
      Carriage Services has the meaning given to that term in the Telecommunications Act 1997 (Cth).
      Carriage Service Provider has the meaning given to that term in the Telecommunications Act 1997 (Cth).
      Personal Information has the meaning given to that term in the Privacy Act 1988 (Cth).
      Related Body Corporate has the meaning given to that term in the Privacy Act 1988 (Cth).
      Sensitive Information has the meaning given to that term in the Privacy Act 1988 (Cth).
      and includes information as to race, political opinion, religious believes, sexual preferences and membership of a professional or trade association.
  • 4. Collection
    • 4.1 1 Nexgen will collect Personal Information from you if that Personal Information is necessary for one or more of Nexgen’s functions or activities.
    • 4.2 Personal Information is predominantly collected so that Nexgen can supply Carriage Services to you (or contact you in respect of a proposed supply of Carriage Services) and perform ancillary and incidental functions. This includes:
      • customer service;
      • complaints handling;
      • billing; and
      • promoting our special offers as well as offers from our Related Bodies Corporate, suppliers and/or affiliated third parties.
    • 4.3 Nexgen may collect Personal Information using several different methods. For example, Personal Information may be collected by Nexgen:
      • directly from you by telephone, email or by completing a form (e.g. Nexgen may be provided with Personal Information on a customer application form, during contractual negotiations, during voice verification etc.); or
      • from third parties such as our Related Bodies Corporate, credit reporting agencies or your representatives; or
      • from information in the public domain – however if it is reasonable and practicable to do so, we will only collected Personal Information about you directly from you.
    • 4.4 Nexgen will take reasonable steps to ensure that you are aware at the time of collection (if practicable):
      • that Nexgen is collecting the Personal Information and as to how to contact Nexgen (if this is not obvious to you);
      • that you may gain access to the Personal Information (see paragraph 9 below);
      • the purpose for which the Personal Information is collected (this may be referring you to this Privacy Policy); done by
      • of the organisations (or types of organisations) to which Nexgen usually discloses Personal Information (this may be done by referring you to this Privacy Policy);
      • of any law that requires the Personal Information to be collected (for example, for compliance with the laws relating to the Integrated Public Number Database); and
      • of the consequences (if any) of Nexgen not collecting the Personal Information (typically, this will be an inability to supply Carriage Services to you).
    • 4.5 If it is not practicable for Nexgen to take reasonable steps to ma e you aware of the matters set out in paragraph 4.4 at the time of collection, Nexgen will do so as soon as practicable after collection.
  • 5. Use and Disclosure
    • 5.1 Nexgen will generally only use Personal Information for the primary purpose for which it was collected (for example, Personal Information set out in a customer application form is collected for Nexgen). the primary purpose of facilitating the supply of Carriage Services by
    • 5.2 However, Nexgen may use or disclose Personal Information for a secondary purpose in the following circumstances:
      Reasonable Expectation
    • 5.3 Nexgen may use or disclose Personal Information for a secondary purpose if:
      • the secondary purpose is related to (or if the Personal Information is Information, directly related to) the primary purpose of collection; and Sensitive
      • you would reasonably expect Nexgen use or disclose the Personal Information for that purpose.
    • 5.4 For example, Nexgen considers that if you are a customer, you would reasonably expect Nexgen to disclose or use your Personal Information to:
      • its printing and mailing house to print and dispatch correspondence and communications to you or
      • notify the customer of special offers or promotions from Nexgen, its Related Bodies Corporate, suppliers and/or affiliated third parties; or
      • ask you to participate in a customer satisfaction survey; or
      • to its dealers, sub-contractors and agents to enable them to perform certain functions on behalf of Nexgen.
  • Consent
    • 5.5 5 Nexgen may use or disclose Personal Information for a secondary purpose if you provide your express consent or consent can be implied.
    • 5.6 Nexgen may seek your consent on an application form for services, during the voice contracting stage of your application or in some other way.
  • Direct Marketing
    • 5.7 Nexgen may use or disclose Personal Information for the secondary purpose of direct marketing.
    • 5.8 Unless paragraphs 5.3 to 5.6 allow Nexgen to otherwise use Personal Information for direct marketing, Nexgen will only use Personal Information for direct marketing to you if:
      • it is not Sensitive Information;
      • it is impracticable for Nexgen to seek your consent before that particular use;
      • Nexgen will not charge you for giving effect to a request by you to not receive direct marketing communications;
      • you have not made a request to Nexgen not to receive direct marketing communications;
      • in each direct marketing communication with you, Nexgen draws to your attention, or prominently displays a notice, that you may express a wish not to receive any further direct marketing communications; and
      • each written direct marketing communication by Nexgen with you sets out Nexgen’s business address and telephone number and, if the communication is made by fax, telex or other electronic means, a number or address at which Nexgen can be directly contacted electronically.
    • 5.9 To avoid doubt, Nexgen will also comply with the Spam Act 2001 (Cth) and Do Not Call Register Act 2006 (Cth) in circumstances of direct marketing to you.
  • Life, Health and Safety
    • 5.10 Nexgen may use or disclose Personal Information if Nexgen reasonably believes that it is necessary to lessen or prevent:
      • a serious and imminent threat to an individual’s life, health or safety; or
      • a serious threat to public health or public safety.
  • Unlawful Activity
    • 5.11 Nexgen may use or disclose Personal Information if Nexgen has reason to suspect that unlawful activity has been, is being, or may be engaged in. However, Nexgen’s use or disclosure will be limited to that which is a necessary part of Nexgen’s investigation into the matter or in reporting Nexgen’s concerns to relevant persons or authorities.
  • Permitted by Law
    • 5.12 Nexgen may use or disclose Personal Information if Nexgen is permitted by law to do so. For example, Nexgen may disclose your Personal Information pursuant to:
      • a law enforcement request;
      • ccourt order or subpoena; or
      • its interception obligations.
  • Disclosure to Enforcement Body
    • 5.13 Nexgen may use or disclose Personal Information if Nexgen is permitted by law to do so. For example, Nexgen may disclose your Personal Information pursuant to an enforcement body (for example, the Australian Federal Police, ASIC, ACCC, police force etc.) if Nexgen believes that it is reasonably necessary for:
      • the prevention, detection, investigation, prosecution or punishment of criminal offences, breaches of a law imposing a penalty or sanction or breaches of a prescribed law;
      • the enforcement of laws relating to the confiscation of the proceeds of crime;
      • the protection of the public revenue;
      • the prevention, detection, investigation or remedying of seriously improper conduct or prescribed conduct; or
      • the preparation for, or conduct of, proceedings before any court or tribunal, or implementation of the orders of a court or tribunal.
  • 6. Data Quality
    • 6.1 Nexgen will review, on a regular and ongoing basis, its collection and storage practices to ascertain how improvements to accuracy can be achieved.
    • 6.2 Nexgen will also take reasonable steps to make sure that the Personal Information collected, used or disclosed is accurate, complete and current.
  • 7. Data Security
    • 7.1 Nexgen will take reasonable steps to protect the Personal Information it holds from misuse and loss and from unauthorised access, modification or disclosure. It will generally do so by:
      • restricting or limiting the access to Personal Information to those of its employees, agents or contractors who have a ‘need to know’;
      • removing access from employees, agents or contractors who no longer work for or with Nexgen or no longer have a ‘need to know’;
      • reviewing and resetting passwords which provide access to Personal Information with reasonable frequency; and
      • implement enhanced security access features to prevent unauthorised access, use or disclosure.
    • 7.2 Nexgen will take reasonable steps to destroy or permanently de-identify Personal Information if it is no longer needed for any purpose for which the Personal Information may be used or disclosed.
  • 8. Openness
    • 8.1 The Nexgen website will contain a prominently displayed link to this Privacy Statement.
    • 8.2 Nexgen will refer any person to this Privacy Statement if that person requests information on Nexgen’s policy on the management of Personal Information.
    • 8.3 On request by a person, Nexgen will take reasonable steps to let the person know, in general terms, what sort of Personal Information is held and the reasons for which that Personal Information is generally collected. Nexgen will also provide information, in general terms, in respect of how Nexgen holds, uses and discloses that Personal Information.
  • 9. Access and Correction
    • 9.1 1 If Nexgen holds your Personal Information, Nexgen will provide you with access on request to that Personal Information, in particular, so that you can verify the Personal Information is accurate, complete and current. If the Personal Information is not accurate, complete or current, Nexgen will take reasonable steps to remedy the inaccurate, incomplete or outdated Personal Information.
    • 9.2 However, Nexgen will not provide you with access to the extent that:
      • providing access would pose a serious and imminent threat to the life or health of any person; or
      • providing access would have an unreasonable impact upon the privacy of any other person; or
      • the request for access is frivolous or vexatious; or
      • the Personal Information relates to existing or anticipated legal proceedings between Nexgen and yourself, and the Personal Information would not be accessible by the process of discovery in those proceedings; or
      • providing access would reveal Nexgen’s intentions in relation to negotiations with you in such a way as to prejudice those negotiations; or
      • providing access would be unlawful; or
      • denying access is required or authorised by or under law; or
      • providing access activity; or would be likely to prejudice an investigation of possible unlawful
      • providing access would be likely to prejudice:
        • the prevention, detection, investigation, prosecution or punishment of criminal offences, breaches of a law imposing a penalty or sanction or breaches of a prescribed law; or
        • the enforcement of laws relating to the confiscation of the proceeds of crime; or a prescribed law; or
        • the protection of the public revenue; or
        • the prevention, detection, investigation or remedying of seriously improper conduct or prescribed conduct; or
        • the preparation for, or conduct of, proceedings before any court or tribunal, or implementation of its orders; by or on behalf of an enforcement body; or
      • an enforcement body performing a lawful security function asks Nexgen not to provide access to the information on the basis that providing access would be likely to cause damage to the security of Australia.
    • 9.3 Additionally, if providing access would reveal evaluative information generated within Nexgen in connection with a commercially sensitive decision-making process, Nexgen may give you an explanation for the commercially sensitive decision rather than direct access to the information.
    • 9.4 Nexgen reserves the right to charge a fee for searching for and providing access to your Personal Information (except if any other law prohibits Nexgen from charging a fee). In any event,
  • 10. Anonymous Transactions
    • 10.1 Nexgen will allow its customers to transact with it anonymously wherever that is reasonable and practicable.
  • 11. Transferring Personal Information Overseas11.1 Nexgen may transfer Personal Information outside of Australia where Nexgen considers that it is necessary or desirable to do so. However, Nexgen will not transfer your Personal Information outside of Australia unless any of the following circumstances exist:
    • Nexgen reasonably believes that the recipient of the Personal Information is subject to a law, binding scheme or contract which effectively upholds principles for fair handling of the information that are substantially similar to the National Privacy Principles contained in the Privacy Act 1988 (Cth); or
    • you consent to the transfer; or
    • the transfer is necessary for the performance of a contract between Nexgen and yourself, or for the implementation of pre-contractual measures taken in response to the your request; or
    • the transfer is necessary for the conclusion or performance of a contract concluded in your interest between the Nexgen and a third party; or
    • all of the following apply:
      • the transfer is for your benefit;
      • it is impracticable to obtain your consent to that transfer;
      • if it were practicable to obtain your consent, you would be likely to give it; or
    • Nexgen has taken reasonable steps to ensure that the information which it has transferred will not be held, used or disclosed by the recipient of the information inconsistently with the National Privacy Principles contained in the Privacy Act 1988 (Cth).