ID management, a 'human problem' says privacy group

13.03.2006

For IT managers considering biometrics as part of an identity management project, Johnston recommends familiarizing themselves with the regulatory environment first.

"There are health privacy laws in NSW [so] if you are considering using a biometric or conducting drug testing you are collecting health information," she said, adding health information includes a person's donor status on their driver's licence.

"You need to comply with the specialist compliance laws in addition to the national laws. If your ID management includes RFID (radio frequency identification), you'll need to check compliance as well."

Johnston believes there is little understanding about privacy law, because it is "very complex" in Australia and a growing area.

"There is less awareness of state laws," she said. "Unfortunately in NSW the government hasn't put any money into education programs. So there are not many free, publicly available resources for businesses to get their head around the laws, let alone comply with them."