Privacy Act Implications: How Long Should You Retain Drug Test Records?

Compliance & Legal
Corporate boardroom with safety documents and hard hat on the table

Drug and alcohol test results are among the most sensitive categories of personal information that an employer can hold. They are health information, they carry significant consequences for the individuals concerned, and their mishandling can result in both legal liability and reputational damage. Yet many Australian organisations have no clear policy on how long these records should be retained — or when and how they should be destroyed.

This article examines the legislative framework governing the retention of drug test records in Australia, the competing obligations that employers must balance, and practical guidance for establishing a defensible retention policy.

The Privacy Act 1988: Core Principles

The Privacy Act 1988 (Cth) establishes the Australian Privacy Principles (APPs), which regulate the collection, use, storage, and destruction of personal information by organisations with an annual turnover exceeding $3 million (and certain other entities regardless of turnover).

Relevant Principles

  • APP 3 — Collection — personal information (including health information) must only be collected where it is reasonably necessary for the organisation’s functions or activities.
  • APP 6 — Use and disclosure — health information collected for one purpose must not be used or disclosed for another purpose without consent or a permitted exception.
  • APP 11 — Security — organisations must take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.
  • APP 11.2 — Destruction or de-identification — if an organisation no longer needs personal information for any purpose for which it may be used or disclosed under the APPs, and the information is not required to be retained by law, the organisation must take reasonable steps to destroy or de-identify it.

The critical implication of APP 11.2 is that retaining drug test records indefinitely is not merely unnecessary — it may be unlawful. Once there is no longer a legitimate purpose for retention and no legal requirement to retain, the records must be destroyed or de-identified.

State and Territory Health Records Legislation

In addition to the Commonwealth Privacy Act, several states and territories have their own health records legislation that may apply to drug test results:

  • Victoria — the Health Records Act 2001 (Vic) applies to health information held by organisations in Victoria, including employers. It contains health privacy principles that are broadly similar to the APPs but include specific provisions regarding health information.
  • New South Wales — the Health Records and Information Privacy Act 2002 (NSW) governs health information held by NSW organisations.
  • Australian Capital Territory — the Health Records (Privacy and Access) Act 1997 (ACT) applies to health records in the ACT.

Organisations operating across multiple jurisdictions must comply with the most stringent applicable requirements. In practice, this means adopting a retention policy that satisfies the obligations of every jurisdiction in which you operate.

WHS Record-Keeping Obligations

Work health and safety legislation imposes its own record-keeping requirements that intersect with drug test record retention. Under the Work Health and Safety Act 2011 and its associated regulations, PCBUs must keep records relating to workplace health and safety for defined periods.

  • Health monitoring records — where drug testing is conducted as part of a health monitoring program (as may be the case in certain industries), records must typically be retained for at least 30 years after the last entry.
  • Incident records — if a drug test is conducted in connection with a workplace incident, the test record forms part of the incident documentation, which has its own retention requirements.
  • General WHS records — regulators may require access to testing records as part of compliance audits or investigations. Records that have been prematurely destroyed may constitute a breach of record-keeping obligations.

Recommended Retention Periods

Given the overlapping and sometimes conflicting obligations, the following retention periods represent a defensible approach for most Australian organisations:

Standard Test Records (Random, Pre-Employment)

A minimum retention period of seven years from the date of the test is generally appropriate. This period accommodates:

  • The six-year limitation period for most civil claims.
  • The general WHS record-keeping obligations in most jurisdictions.
  • The practical need to demonstrate program compliance over a reasonable historical period.

Records Related to Disciplinary Action

Where a test result has led to disciplinary action, including termination, the records should be retained for a minimum of seven years from the date of the final outcome — not the date of the test. This accounts for potential unfair dismissal claims (which have a 21-day filing deadline but may involve retrospective discovery of records), general protections claims (which have a longer limitation period), and any appeal or review processes.

Records Related to Workplace Incidents

Drug test records associated with a notifiable incident should be retained for a minimum of 30 years, consistent with the WHS health monitoring record requirements and the extended limitation periods that apply to personal injury claims in most jurisdictions.

Health Monitoring Records

Where testing is conducted as part of a formal health monitoring program, records must be retained for at least 30 years after the last entry, as required by WHS regulations.

Secure Destruction

When records reach the end of their retention period, they must be securely destroyed. The method of destruction must ensure that the information cannot be reconstructed or recovered.

  • Paper records — cross-cut shredding or professional document destruction services. Standard strip-cut shredding is not sufficient for sensitive health information.
  • Digital records — secure deletion using methods that render the data irrecoverable. Simple file deletion does not meet this standard; overwriting, degaussing, or physical destruction of storage media may be required.
  • Documentation — maintain a record of what was destroyed, when, by whom, and the method used. This destruction log should itself be retained permanently as evidence of compliance.

Practical Implementation

Establishing a defensible record retention policy requires the following steps:

  • Classify your records — not all test records warrant the same retention period. Classify records by type (routine, disciplinary, incident-related, health monitoring) and assign the appropriate retention period to each.
  • Implement a retention schedule — document the retention period for each record category and the destruction method to be used. This schedule should be reviewed annually.
  • Automate where possible — digital record-keeping systems can flag records that have reached their retention expiry and prompt the appropriate destruction workflow. Manual retention management is error-prone and unsustainable at scale.
  • Train your staff — ensure that all personnel who handle test records understand the retention policy and their obligations under it.
  • Seek legal advice — the intersection of privacy, WHS, and employment law is complex. Organisations should have their retention policy reviewed by a lawyer with expertise in all three areas.

Need a testing management system that handles record retention and access control from day one? Start a free trial of FairTest — with secure digital records, role-based access, and complete audit trails that support your privacy and compliance obligations.