Federal Court Tightens Rules on Salary Set-Offs Under Awards

Federal Court Tightens Rules on Salary Set-Offs Under Awards

Home » John Davies

Federal Court Tightens Rules on Salary Set-Offs Under Awards

Author: John Davies

}

4 min read

16 Oct 2025

Share:

  • r
    Key Takeaways
  • The Federal Court has confirmed that set-off clauses cannot operate across multiple pay periods - salary payments must meet Award entitlements within each pay cycle.
  • Broad contractual set-off clauses are not sufficient to offset underpayments under modern awards.
  • Accurate record-keeping of hours, overtime, and penalty rates remains mandatory even where employees are paid salaries.
  • Employers should review contracts, payroll practices, and record-keeping systems to ensure compliance and avoid substantial penalties.

Stay Up-To-Date

Subscribe to receive updates specific to your preferences

Overview

The recent decision of the Federal Court of Australia in Fair Work Ombudsman v Woolworths; Fair Work Ombudsman v Coles; Baker; Pabalan [2025] FCA 1092 has significant implications for employers, particularly those with salaried employees covered by a modern Award. This landmark ruling clarifies how contractual salary arrangements interact with Award obligations and reinforces that employers cannot use broad set-off clauses. Key changes and considerations for employers are discussed below.

Background

The judgment involved four connected proceedings brought by the Fair Work Ombudsman (FWO) and affected employees against Woolworths and Coles, alleging systemic underpayment of employees.

Both Woolworths and Coles paid certain managers annual salaries intended to compensate for all entitlements under the General Retail Industry Award 2010 (Retail Award), including overtime, penalty rates, and public holiday loadings.

The FWO and employee class actions alleged that these salary arrangements resulted in substantial underpayments in circumstances where the salaries did not cover Award entitlements in the pay period in which the entitlement/s were accrued.

The Court examined how key provisions of the Retail Award and the Fair Work Act 2009 (Cth) (FWA), including those dealing with ordinary hours, overtime, and penalty rates, should properly be interpreted to determine whether the employees had been underpaid as alleged.

Set-off Clauses and Annualised Wages

One of the most significant aspects of the decision is the Court’s confirmation that entitlements under the Retail Award accrued in a pay period must be discharged within that same pay period.

The FWA requires that employees are paid in money, in full, and at least monthly. Under the Retail Award, employers are required to pay employees on a weekly or fortnightly basis. The Court found that proper interpretation of these requirements indicates that clauses in employment contracts that purport to “set-off” Award entitlements by payment of a salary must operate only within a single pay period – payments or entitlements cannot be averaged or carried over.

This means under the Retail Award and similar awards:

1. entitlements cannot be pooled and paid across multiple pay periods;

2. set-off cannot be averaged across multiple pay periods;

    3. salary payments must be sufficient to meet Award entitlements for that specific period; and

    4. entitlements including payment for overtime and penalties must be calculated and discharged each pay period.

    Depending on the industry in which they operate, employers may be able to utilise an annualised salary provision within a modern Award, an individual flexibility agreement, or a guarantee of annual earnings. However, as this case demonstrates it is subject to strict requirements and you do not want to make a mistake. We strongly recommend that legal advice is sought beforehand.

    Record-Keeping Obligations

    Another significant aspect of the decision was the Court’s emphasis on the importance of accurate record-keeping.

    Employers are required by the Fair Work Regulations to maintain detailed records of employee entitlements, including:

    • loadings;
    • penalty rates; and
    • overtime hours.

    The Court found that set-off clauses do not relieve employers of these obligations. Accordingly, both Woolworths and Coles were found to be in breach of the Regulations and the Award.

    Actions for Employers

    In light of this decision, employers should:

    1. Review employment contracts and awards. Ensure that set-off clauses are legally compliant and do not contravene the Award.
    1. Review record-keeping practices. Employers must maintain detailed records of all employee entitlements and ensure compliance with Awards and the FWA. This includes keeping records of hours worked, rosters, and any variations to them.
    1. Review accounting processes. Ensure accounting processes best support compliance and keep in mind that annualised salaries are not ’set and forget.’ Consider whether hourly pay rates may be easier for ensuring compliance. Regular audits and updates are essential.
    1. Proactively rectify non-compliance. Where underpayments or other non-compliance is identified, act swiftly to remediate and communicate transparently with affected employees.
    1. Seek legal advice. The decision highlights the complexities of Australia’s industrial laws. If you are unsure of your obligations please contact Robert Lamb or John Davies on (07) 3220 1144.

    Disclaimer – Legal Advice
    Liability is limited by a scheme approved under professional standards legislation. The information in this article is general guidance only, correct at the time of publication, and does not constitute legal advice. You should consult your lawyer for advice specific to your circumstances.

    2025–2026 Minimum Wage Increase Announced

    2025–2026 Minimum Wage Increase Announced

    Home » John Davies

    2025–2026 Minimum Wage Increase Announced

    Author: John Davies

    }

    2 min read

    5 Jun 2025

    Share:

    • r
      Key Takeaways
    • 3.5% increase to all Modern Award wages takes effect from 1 July 2025.
    • Employers must act now to review and update pay rates, salaries, and payroll systems.
    • Further changes to award allowances will be confirmed on 1 July 2025.
    • SGC rate increases to 12% on the same date and must be applied to all eligible earnings.

    Stay Up-To-Date

    Subscribe to receive updates specific to your preferences

    On 3 June 2025, the Fair Work Commission handed down its Annual Wage Review 2025–2026 decision, confirming a 3.5% increase to minimum wage rates under all Modern Awards, effective from 1 July 2025.

    This increase, which applies from the first full pay period on or after 1 July 2025, will impact a wide range of employees across all industries. Employers should now review pay rates, adjust payroll systems, and assess how this affects both award-based and salaried staff.

    As part of its legal obligation to maintain minimum wage standards in Australia, the Fair Work Commission conducts this review annually, taking into account a range of economic factors including cost of living, inflation, productivity, and broader economic conditions.

    What’s Changed?

    • All Modern Award minimum wages will increase by 3.5%.
    • The National Minimum Wage (NMW) will also rise, though it applies only to a small number of employees not covered by awards or enterprise agreements.
    • Award allowances are yet to be updated and are expected to be released on 1 July 2025.

    This annual review ensures minimum wages reflect current economic conditions, inflation, and the cost of living.

    What Employers Should Do

    • Review and adjust wages for award-covered employees before 1 July 2025.
    • Ensure employees on salaries remain better off overall than they would be if they were on hourly rates, taking into account penalties, overtime, and allowances.
    • All employers with employees covered by an annualised salary clause in an Award should ensure that they comply with their obligations under that clause.
    • Update payroll systems and employment contracts accordingly.
    • Be prepared to implement further changes once allowance updates are released.

    Failure to comply with minimum wage requirements can result in significant penalties and legal exposure.

    Superannuation Guarantee Contribution (SGC) Rate Increase

    From 1 July 2025, the Superannuation Guarantee Contribution (SGC) rate will also increase from 11.5% to 12%. Employers must ensure this increased contribution is applied to all eligible employee earnings from that date. This change should be implemented alongside wage increases to ensure full compliance with employer obligations.

    Need Assistance?

    If you’re unsure how these changes affect your business or want to ensure your payroll and employment practices are fully compliant, our team is here to help.

    Contact Robert Lamb or John Davies at Hillhouse Legal Partners on 07 3220 1144, or via john@hillhouse.com.au or robert@hillhouse.com.au.

    Legal Alert: PCBUs Now Required to Implement Sexual Harassment Prevention Plan

    Legal Alert: PCBUs Now Required to Implement Sexual Harassment Prevention Plan

    Home » John Davies

    Legal Alert: PCBUs Now Required to Implement Sexual Harassment Prevention Plan

    Authors: John Davies

    }

    2 min read

    12 Mar 2025

    Share:

    • r
      Key Takeaways
    • New Legal Requirement: Starting from 1 March 2025, all Persons Conducting a Business or Undertaking (PCBU) in Queensland must create and implement a Sexual Harassment Prevention Plan to address risks related to sexual harassment and sex/gender-based harassment in the workplace.
    • Consultation and Accessibility: PCBUs are required to consult with employees on the plan, ensure it is written clearly, and accessible. The plan must identify risks, control measures, and include procedures for managing harassment reports.
    • Penalties for Non-Compliance: Failure to comply with the requirements, such as preparing, implementing, and reviewing the Prevention Plan, can result in fines of up to $9,678 for businesses.

    Stay Up-To-Date

    Subscribe to receive updates specific to your preferences

    From 1 March 2025, Persons Conducting a Business or Undertaking (PCBU) must prepare and implement a Prevention Plan to manage the risk of sexual harassment and sex or gender-based harassment in the workplace, as mandated by section 5 of the Work Health and Safety Act 2011 (Qld).

    Before putting a Prevention Plan in place, the PCBU are required to consult with their employees on its terms and process, ensuring compliance with the consultation se out in the Act.

    The Prevention Plan must:

    • be in writing;
    • state each identified risk;
    • identify control measures implemented to manage identified risks;
    • identify considerations required to be made in determining control measures (for example specific vulnerabilities such as age or LGBTQIA+ status of workers, and the workplace environment);
    • describe the consultation process undertaken when devising the Prevention Plan;
    • develop procedures for managing reports of sexual harassment or sex or gender-based harassment; and
    • be set out and expressed in a way that is readily accessible and understandable to workers.

    The PCBU must:

    • take reasonable steps to make workers aware of the Prevention Plan and how to access it; and
    • review the Prevention Plan in the event of:
      • a report of sexual harassment or sex or gender-based harassment; or
      • a request from a health and safety committee or representative; or
      • at least once every three years.

    A fine of up to 60 penalty points, currently equivalent to $9,678, may be imposed on non-compliant PCBUs for failure to:

    • prepare a Prevention Plan;  
    • implement the Prevention Plan;  
    • make workers aware of the Prevention Plan; or
    • review the Prevention Plan when required.

    Queensland businesses should promptly begin the consultation process and prepare a prevention plan if they have not already.

    Workplace Health and Safety Queensland has published useful resources including a guide, template, and example Prevention Plan on its website, which you can access here. Care should be taken when using a precedent plan, as it may not be sufficiently tailored to your business.

    For further guidance on your obligations regarding the Prevention Plan or other employment law matters, please contact John Davies or Robert Lamb on 07 3220 1144.

    New Privacy Law Guidance about AI Highlights the Need for a Cautious Approach

    New Privacy Law Guidance about AI Highlights the Need for a Cautious Approach

    Home » John Davies

    New Privacy Law Guidance about AI Highlights the Need for a Cautious Approach

    }

    10 min read

    14 Nov 2024

    Share:

    • r
      Key Takeaways
    • Recent guidance on Australian privacy laws in the context of AI systems shows that there are many complex issues, and careful controls are necessary to protect businesses from fines and reputational damage.
    • Businesses using AI to make decisions, or as part of important or high-risk work, should be especially careful and should consider blanket prohibitions.
    • Even seemingly innocent uses (e.g., using AI systems to take meeting notes, or as a chatbot to talk to customers) are high risk activities to be done carefully (if at all).

    Stay Up-To-Date

    Subscribe to receive updates specific to your preferences

    Businesses should take careful note of the risks of using artificial intelligence (AI) and should implement controls appropriate to their business to ensure use is careful or prohibited.

    A breach of Australian privacy law (for example, the Privacy Act 1988 (the Act) may result in significant fines or reputational damage. Given the recency of AI commercialisation, businesses should be especially careful about their compliance when using AI systems as enough time has not passed for best practice steps to develop.

    Ensuring sufficient controls (or ensuring prohibition) is especially important where the AI is exposed to personal information, makes decisions for a business (e.g., reviewing and sorting resumes), or is engaging in impactful work (e.g., drafting court material).

    As a general comment, it should also be understood that AI systems are often wrong and that their output should be thoroughly factchecked to confirm accuracy.

    Best practice will be to not input personal information (especially not sensitive information) into publicly available AI tools, or indeed any AI system unless appropriate safeguards and restrictions are in place.

    OAIC Guidance

    The Office of the Australian Information Commissioner (OAIC) has issued guidance regarding the deployment of AI systems within an organisation subject to the Privacy Act (APP Entity) to provide a product or service, particularly in the context of generative AI (OAIC AI Guidance).

    This guidance is crucial as AI systems are highly complicated and carry numerous complex privacy risks.

    We urge all businesses contemplating the use of AI in their business to read the OAIC’s AI Guidance in detail and particularly note the included checklists before undertaking any use of an AI System.

    This article does not propose to summarise or repeat the OAIC’s AI Guidance in detail, however a number of key takeaways should be emphasised.

    Due Diligence

    Prior to use of any AI system, due diligence will be critical, you must understand:

    1. the terms and conditions for the use of the AI system;
    2. how the AI system has been trained and what information it was trained on;
    3. how the AI system will treat the information included in prompts (e.g., is it used to train the AI in future, is it saved locally or remotely);
    4. whether any information included in a prompt will be accessible by publisher of the system (if so, use of the AI system may constitute a disclosure of personal information which is subject to further rules than a use of personal information);
    5. how the AI system is protected from data breaches; and
    6. whether there have been previous data breaches.

    You should regularly check and confirm whether any changes occur in respect of the above during the use of the AI system.

    Use of Personal and Sensitive Information in AI Systems

    Your privacy policy must clearly state how your business uses AI. In some circumstances e.g., where an AI is used to take meeting notes, this will likely be insufficient on its own and the meeting participants should be given an opportunity to opt out.

    APP Entities are required by Australian Privacy Principal 6 to only use or disclose personal information for a particular purpose if the information was obtained for that purpose. There are exceptions that permit a use or disclosure for a secondary purpose (e.g., if consent from the individual was obtained). One such exception is where the individual would reasonably expect the APP Entity to use or disclose the information for that secondary purpose if that purpose is related to the primary purpose (or directly related if the information is sensitive information).

    The OAIC Guidance relevantly provides that “[i]f your organisation cannot clearly establish that a secondary use for an AI-related purpose was within reasonable expectations and related to the primary purpose, to avoid regulatory risk you should seek consent for that use and/or offer individuals a meaningful and informed ability to opt-out. Importantly, you should only use or disclose the minimum amount of personal information sufficient for the secondary purpose.”

    Controls

    Prior to using an AI system, a business should consider the worst case scenario, as some AI systems are black boxes and their “reasoning” cannot be extracted and examined. E.g., the OAIC AI Guidance notes that using AI in recruitment could discriminate against candidates based on perceived biases. For this reason, any commercial use of an AI System should include sufficient controls to analyse and manage risks associated with the black box nature of the software.

    These controls are discussed in further detail below in our commentary on a recent report by the OVIC.

    Businesses which permit the internal use of AI should perform a privacy impact assessment, implement an AI policy containing express requirements for the use of AI systems, and undertake regular staff training on the use of AI.

    Generation of personal Information

    You should consider that AI systems are trained on a wide range of information, which means they are capable of generating personal information. The OAIC AI Guidance references an example where workplace psychosocial hazard training was partially created with AI and the AI generated a real situation using the real names of the persons involved (who were involved in an ongoing court matter at the time). This event may be considered collecting personal information under the Act and the information collected would need to be treated accordingly as unsolicited personal information.

    Meeting minute making

    While seemingly innocuous, the risks of using an AI system to record a meeting are substantial – meetings can veer off topic, in which case any personal and sensitive information discussed may well be information the business is not permitted to collect. In that case, that information should be erased or deidentified. Without proper systems in place, this can be easily overlooked from time to time.

    AI and images

    You also need to be aware that any images generated by an AI may copy part (or all) of an image it was trained on. Such generated images may reproduce personal or sensitive information and may breach copyright laws.

    Uploading of images to AI systems should generally be avoided even where no personal or sensitive information is apparent, as the image may contain metadata or sufficient information to identify a location or other personal information may be present to identify a location.

    Chatbots

    Our view is that any business seeking to use an AI chatbot should seek legal advice beforehand as such activity may result in collection of improper personal and sensitive information. Chatbots also raise particular risks regarding Australian Privacy Principal 10 (ensuring the accuracy of personal information collected) and Australian Privacy Principal 3 which requires that unless unreasonable or impractical to do so, personal information must be collected from the individual directly.

    OVIC decision

    A deputy Commissioner of the OVIC recently performed an investigation into the use by a child protection worker (the Worker) employed in the Victorian Department of Families, Fairness and Housing (DFFH).

    This example is an illustrative example of what controls may or may not be sufficient to guard against the risks of using AI systems.

    Conduct

    In this example, the Worker used ChatGPT to assist in the drafting of a protection application report, which is submitted to the Children’s Court to assist the court in deciding whether a child needs protection.

    The use by ChatGPT of the Worker was plainly inappropriate and dangerous as “the Protection Application Report mistakenly described a child’s doll, that was used by the child’s father for sexual purposes, as a mitigating factor, in that the parents had provided the child with “age appropriate toys””.[1]

    Of some interest is the 9 factors identified by the DFFH in their investigation which indicated ChatGPT involvement:[2]

    1. sophisticated language;
    2. overly positive descriptors;
    3. inaccurate information;
    4. unusual content;
    5. unusual terminology;
    6. unusual reference to legal intervention;
    7. unusual Child Protection intervention;
    8. nonsensical references; and
    9. American spelling and/or phrasing.

    Any business that, as part of its AI controls, audits work for evidence of AI use, should take note of these examples.

    Breach

    It was determined that this conduct constituted a breach of Information Privacy Principals 3.1 and 4.1.

    Information Privacy Principal 3.1

    An organisation must take reasonable steps to make sure that the personal information it collects, uses or discloses is accurate, complete and up to date.

    Information Privacy Principal 4.1

    An organisation must take reasonable steps to protect the personal information it holds from misuse and loss and from unauthorised access, modification or disclosure.

    Controls

    The DFFH had the following controls in place at the time of the conduct:

    1. “an acceptable Use of Technology Policy;
    2. eLearning modules on privacy awareness and security awareness;
    3. the DFFH values;
    4. the VPS code of conduct;
    5. Human Rights legislation and associated eLearning module;
    6. communications to leadership and management by way of three education sessions in May 2023 that referred to data security, privacy and other risks associated with GenAI.”[3]

    The OVIC decided that these controls were insufficient and there was a need to train all employees, not only management staff.[4]

    Since the conduct took place the DFFH created specific “Generative Artificial Intelligence Guidance” (which was circulated on several instances to all DFFH staff), which included two “critical rules”:

    1. “Employees should be able to explain, justify and take ownership of their advice and decisions;”[5] and
    • “Employees should assume that any information they input into public GenAI tools could become public. They must not input anything that could reveal classified, personal or otherwise sensitive information.”[6]

    However, the report noted that:

    1. “DFFH has almost no visibility on how GenAI tools are being used by staff. It has no way of ascertaining whether personal information is being entered into GenAI tools and how GenAI-generated content is being applied. Further, as is always the case with policy and guidance, there is no way of guaranteeing that all staff will properly read, understand, and apply these.” [7]
    • “The risks of harm from using GenAI tools are too great to be managed by policy and guidance alone. At present, there are insufficient controls in place regarding staff access to GenAI tools coupled with a lack of assurance capabilities to verify that such use is appropriate. In other words, these controls are insufficient to prevent a re-occurrence of incidents like the PA Report incident.”[8]

    Decision

    The OVIC decided to issue a compliance notice, with 6 specified actions required (some of which DFFH can apply to amend), including:

    1. DFFH must direct child protection staff to not use any generative AI tools as part of their duties;
    2. DFFH must block access to 15 specified generative AI tools between 5 November 2024 and 5 November 2026;
    3. DFFH must between 5 November 2024 and 5 November 2026 “implement and maintain a program to regularly scan for web-based or external” generative AI tools similar to those directed to be blocked; and
    4. “DFFH must implement and maintain controls to prevent Child Protection staff from using Microsoft365 Copilot” between 5 November 2024 and 5 November 2026.[9]

    Takeaway

    Businesses which handle important or high risk personal information should be on notice they may not be able to implement sufficient controls around AI systems to prevent breaches of Australian privacy laws and should consider blanket prohibitions to avoid fines or reputational damage.

    Hillhouse Legal Partners can assist if you have any questions about treatment of personal or sensitive information, you require the preparation of a privacy policy, or you have experienced a data breach. Feel free to reach out to John Davies, Lawyer or Craig Hong, Director to discuss.


    [1] Office of the Victorian Information Commissioner, Investigation into the use of ChatGPT by a Child Protection Worker, available: https://ovic.vic.gov.au/wp-content/uploads/2024/09/DFFH-ChatGPT-investigation-report-20240924.pdf p5.

    [2] Ibid p21.

    [3] Ibid p23.

    [4] Ibid p24 – 25.

    [5] Ibid p26.

    [6] Ibid p26.

    [7] Ibid p28.

    [8] Ibid p28.

    [9] Ibid p29-30.

    Privacy Awareness Week (6-12 May 2024) – What You Need To Consider

    Privacy Awareness Week (6-12 May 2024) – What You Need To Consider

    Home » John Davies

    Privacy Awareness Week (6-12 May 2024) – What You Need To Consider

    Author: John Davies

    }

    3 min read

    8 May 2024

    Share:

    • r
      Key Takeaways
    • Audit your business privacy practices.
    • Be aware that non-compliance with the Privacy Act carries significant reputation and financial risks.
    • Consider whether your businesses treats your client’s and/or customer’s personal information in a transparent, accountable, and secure way.

    Stay Up-To-Date

    Subscribe to receive updates specific to your preferences

    It’s Privacy Awareness Week (6-12 May 2024), which makes NOW a great time for businesses to review their privacy practices. 

    The theme for PAW 2024 is “Power Up Your Privacy”. 

    In line with this theme, the Office of the Australian Information Commissioner (OAIC), is urging businesses to:

    1. be transparent about how they handle personal information;
    2. be accountable for how they treat personal information; and
    3. securely hold personal information. 

    The Australian Privacy Commissioner, Carly Kind has said “while individuals can all do our bit by having sound personal data practices, the biggest onus is on businesses and other organisations that hold data to make the right decisions to adequately protect and respect it, and not collect or keep what is not needed.” 

    What happens if you don’t comply?

    It is critically important that businesses covered by Privacy Act 1988 (Cth) (the Act) comply with the Act including all Australian Privacy Principles. Breach of the Act can incur significant financial penalties (potentially $50 million or more in fines) and reputational loss. 

    If your business is covered by the Act (for example if it provides health services, or has an annual turnover of more than $3 million), PAW is a great opportunity to consider whether you are complying with best principle privacy practices. 

    What should businesses consider?

    Key privacy awareness action items to consider include:

    • Seek informed consent before collecting personal information;
    • Have an up to date and accurate privacy policy;
    • Ensure good housekeeping measures are in place to ensure unnecessary personal data is not being collected or stored;
    • Have a plan in place in the event of a data breach, including a plan to report that breach to the OAIC if required;
    • Staff trained appropriately on cybersecurity and privacy issues;
    • Systems in place to guard against bad actors and human error; and
    • Ensure outsourced handling of personal information to third parties is handled with care. 

    Businesses can visit https://paw.gov.au/ to learn more about Privacy Awareness Week and access OAIC resources. 

    Hillhouse Legal Partners can help you with questions relating to the treatment of personal or sensitive information, the preparation of a privacy policy, or if you have experienced a data breach how to manage this. 

    Contact Craig Hong or John Davies to discuss your situation further.