Department of Health

Privacy at the Department of Health

The department endorses fair information handling practices and uses of information in compliance with its obligations under the Privacy and Data Protection Act 2014 (Vic) and the Health Records Act 2001 (Vic)

The Department of Health is committed to protecting the privacy of personal information which we and our funded service partners handle. Personal information is information that directly or indirectly identifies a person. Health information is personal information about the physical, mental or psychological health or a disability of an individual, or the health services provided to them.

We collect and handle a range of personal information for the purposes of providing services or to carry out our statutory functions. In accordance with our responsibilities, the services and functions provided by the department and our service partners include primary and community health, public hospitals, mental health, disability, public health, ambulance, health promotion and protection, alcohol and drug treatment services and aged care. We also collect some personal information for planning, funding, monitoring and evaluating our services and functions, but where practicable we remove identifying details from information used for these purposes.

We are committed to protecting the privacy of your information and we are bound by Victorian laws, as well as other laws that impose specific obligations in regard to handling information. In Victoria, the Privacy and Data Protection Act 2014 (Vic) and the Health Records Act 2001(Vic) are the primary legislation that regulates the information handling of personal and health information. The department will manage your information in accordance with the Information Privacy Principles and Health Privacy Principles that provide standards for information collection, storage, access, transmission, disclosure, use and disposal as prescribed within these Acts. 

We acknowledge that due to the nature of the services performed by the department and our health service providers, some of the information we manage is particularly delicate and/or sensitive.

Privacy policy

For information on how the department collects, uses and stores personal or health information, you should refer to the our privacy policy.

Privacy incidents

If you have a general complaint or wish to provide feedback, about any service provided by the department or one of its health services, please see Feedback and complaints.

If you wish to report a privacy specific incident or if you believe that the department or one of its funded health service providers has breached your privacy through the collection, use or storage of your personal or health information, please contact the Privacy team.

If you are a member of a health service provider or entity that receives funding from the Department of Health and need to report an incident to the department, please do so through your contract manager through Feedback Management System Introduction page or by emailing the Privacy team.

We will use the information you provide us with to investigate and resolve your reported privacy incident, in accordance with our Privacy Policy. The investigation of the reported privacy incident may involve sharing your personal or health information with other relevant areas within the department to achieve a resolution. If a third party was involved, we may also need to discuss your complaint with them.

We may seek further information from you in relation to the privacy incident you report. If you do not provide us with information about the matter, this may limit our ability to assist you.

Access and correction

You can request access to, or correction of personal and health information held by the department.

For information on making an FOI application, please visit our Freedom of Information page or contact the Freedom of Information Officer:

Mail: Freedom of Information Unit

Department of Health

Postal address: GPO BOX 4057, MELBOURNE, VIC 3001



The Privacy and Legal Compliance team provide the department with advice and tools to support compliance with privacy legislation and promote best practice.

If you wish to know more about how the department manages your information, you can contact the Privacy and Legal Compliance team using the below details:



The promotion of public health of Victorians falls within the functions of the Department of Health, as such the department is at the forefront of the response to the coronavirus (COVID-19) pandemic. Further information about our coronavirus (COVID-19) response including privacy information can be found on the Coronavirus website.

  • The department manages the COVID testing to determine if there is a presence of the COVID virus in your body.

    Privacy collection notice

    The Department of Health (the department) is collecting your personal and health information to communicate the request from the health service taking your COVID-19 swab (which may be the department or another health provider) to a pathology service for testing, and to obtain information to assist the department in managing the COVID-19 virus pandemic. After your test, we will use your mobile number to send you an SMS, providing you with links to further information about COVID-19 on our website.

    Some of the questions you will be asked by staff at the testing site are necessary to enable a valid request to be made for COVID-19 pathology testing. Other questions are not mandatory but will assist in our understanding of COVID-19 and who is undergoing testing. We will let you know which questions are optional.

    We will disclose certain information collected about you to a pathology provider for COVID-19 testing. That pathology provider will report test results to the department, and to the health service who took your swab for testing. You will be notified of your result by the pathology provider, the health service or the department using the contact information we collect from you. We may also provide the health service that took your swab with a copy of the information you provided at the time of your test and your COVID-19 test result, so that they have this information in their health care records.

    Our public health unit and other researchers are undertaking important analysis of available COVID-19 data to improve our understanding of the virus and assist in our response. Information that we collect may be used for these purposes by the department or disclosed to other researchers where that is authorised by law.

    If your test is positive for COVID-19, the department may share your information with Victoria Police to ensure that the Chief Health Officer's Directions are being complied with.

    Your test result may be loaded to My Health Record unless you tell us that you do not want this to happen.

    You can apply for access to information the department holds about you. The department’s Freedom of Information Unit may be contacted on email:

    If you have feedback or a complaint about COVID testing, then please submit your complaint or feedback online using the Make a complaint eform or by mail: Health Feedback, GPO Box 4057, Melbourne Victoria 3000.

  • The department is managing the vaccination rollout to immunise Victorians against the COVID virus. You can access the department’s booking portal.

    Privacy collection notice

    The Department of Health (the department) is collecting your personal and health information to complete your registration in the Victorian COVID-19 Vaccination Management Solution (CVMS), create a record of your vaccination(s) and obtain your feedback after your vaccination.

    If you choose to register with CVMS, the department will use your information to book your COVID-19 vaccination, provide you with a reminder about your bookings, provide you with a reminder about when your next dose of COVID-19 vaccination is due, and send you a survey in which you can record your post COVID-19 vaccination outcomes.

    If you do not provide complete information in the registration process or in response to the survey, we may not be able to assess your suitability for the vaccine and/or identify any adverse reactions. This may pose a risk to your health.

    The department will provide access to CVMS to registered vaccination providers (i.e. health care workers who are providing COVID-19 vaccinations) so that they can record details of your vaccination in your CVMS record and provide you with healthcare and vaccination services. The department will also permit call centre staff to access your personal information in CVMS to respond to requests for assistance from vaccination providers or you.

    The department will use the CVMS database, including your information, to retrieve your vaccination history from the Australian Immunisation Register, to facilitate your COVID-19 vaccination, manage the COVID-19 vaccination process in Victoria including analysis of data collected, monitor use of the CVMS database, perform required system maintenance and any other uses or disclosures authorised or required by law.  Your health service provider may also use your information to manage your health. 

    The department will disclose your personal and health information that is specific to your COVID-19 vaccination to:

    the Australian Immunisation Register held by the Commonwealth Department of Health (which may be viewed on your My Health Record, subject to your settings);

    SAEFVIC (identifiable information) and AusVaxSafety (de-identified information only) in the event that you have an adverse reaction, so that the safety of vaccines can be monitored; and your employer where this disclosure is necessary to lessen or prevent the serious risk to public health posed by COVID-19 in the workplace (e.g. hospitals, health service providers, aged care facilities, other high risk industries).

    You can apply for access to information the department holds about you. The department’s Freedom of Information Unit may be contacted on email:

    If you have feedback or a complaint about COVID testing, then please submit your complaint or feedback online using the Make a complaint eform or by mail: Health Feedback, GPO Box 4057, Melbourne Victoria 3000.

Information sharing laws to improve healthcare quality and safety

From 27 August 2020, new laws to help keep patients safe in health care commenced in Victoria under the Health Legislation Amendment and Repeal Act 2019 (Vic), which amended the existing Health Services Act 1988 (Vic). The laws make it easier for some health services and parts of the government, including the Department of Health, to share confidential information and work together to make Victorian health care safer and better for patients.

Frequently asked questions about the new laws for patients and for health services are available:

Website privacy statement

See the Website privacy statement for information about how any personal information about you will be treated as you access and interact with this website.

Relevant legislation

The Victorian Legislation website provides free access to all relevant Acts and Regulations.

Search for the following:

  • Freedom of Information Act 1982 (Vic)
  • Ombudsman Act 1973 (Vic)
  • Privacy and Data Protection Act 2014 (Vic)
  • Health Records Act 2001 (Vic)
  • Public Interest Disclosures Act 2012 (Vic)
  • Financial Management Act 1994 (Vic)
  • Charter of Human Rights and Responsibilities Act 2006 (Vic)
  • Disability Act 2006 (Vic)

Reviewed 15 November 2021


Contact details

For further information on how the department manages privacy please use these contact details. Postal address: GPO Box 4057, Melbourne, Victoria 3001.

Department of Health Senior Privacy Advisor

Was this page helpful?