Australia flag

Australia

Australia Data Privacy Laws: Privacy Act, APPs & 2026 Reforms

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 24 primary sources cited on this page. How we verify our legal content

Australia Data Privacy Laws: Privacy Act, APPs & 2026 Reforms

Frequently Asked Questions

Does the Australian Privacy Act apply to small businesses?

Businesses with annual turnover of AUD 3 million or less are generally exempt from the Privacy Act 1988 (Cth) unless they handle health information, trade in personal information, are a credit reporting body, or are a contractor under a Commonwealth contract. This exemption is under review: the OAIC supports its removal, and the government agreed in principle in its 2023 Privacy Act Review response. As of September 2026 no date for a general removal has been legislated, and the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 released on 31 August 2026 does not remove the exemption. A targeted expansion did take effect: tranche 1 AML/CTF reporting entities were captured on 31 March 2026 and tranche 2 professions (real estate agents, lawyers, accountants, conveyancers, and dealers in precious stones and metals) on 1 July 2026. Section 6E(1A) applies the Privacy Act to those small businesses only for personal information handled for, or in connection with, their AML/CTF obligations, not to the rest of the business.

What is the new statutory tort for serious invasions of privacy?

The statutory tort commenced on 10 June 2025 under Schedule 2 of the Privacy Act 1988 (Cth) as inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth). It gives an individual the right to sue another person who is not exempt under Part 3 of Schedule 2 (not only APP entities) for a serious invasion of privacy through either intrusion upon seclusion or misuse of information relating to them. To succeed the plaintiff must establish all five elements in clause 7(1), including that a person in their position would have had a reasonable expectation of privacy and that the invasion was intentional or reckless. A negligent or accidental invasion is not actionable. Part 3 exempts journalists handling journalistic material, agencies and their staff acting in good faith, law enforcement bodies, intelligence agencies, and anyone under 18. Remedies include damages, injunctions and apology orders, but clause 11 bars aggravated damages and caps non-economic loss plus any exemplary or punitive damages at the greater of AUD 478,550 and the defamation non-economic-loss cap. For adults, proceedings must start within 1 year of becoming aware of the invasion or within 3 years of the invasion itself, whichever is earlier, subject to a court-ordered extension of up to 6 years.

What should a business do if it suffers a data breach in Australia?

Under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), the entity must first assess whether there has been unauthorized access to, disclosure of, or loss of personal information that is likely to result in serious harm. All reasonable steps must be taken to complete this assessment within 30 days. If the breach qualifies as an eligible data breach, the entity must notify the OAIC and affected individuals as soon as practicable, providing the entity's identity, a description of the breach, the types of information involved, and steps individuals should take to protect themselves. Failure to comply can result in significant civil penalties, as demonstrated by the AUD 1.6 million NDB component of the AUD 5.8 million Australian Clinical Labs penalty.

Can Australian businesses transfer personal data overseas?

Yes, but APP 8 of the Privacy Act 1988 (Cth) imposes strict accountability requirements. Before disclosing personal information to an overseas recipient, an APP entity must take reasonable steps to ensure the recipient handles the information in accordance with the APPs. If the overseas recipient breaches the APPs, the Australian disclosing entity is treated as having breached the APPs itself and faces enforcement action. Exceptions include where the recipient is subject to a substantially similar law the individual can enforce, where the individual consents after being informed that APP 8 protections will not apply, where Australian law requires the disclosure, or (under APP 8.2(aa) and APP 8.3, added in 2024) where the recipient is in a country or bound by a scheme prescribed by regulation, although no country or scheme has been prescribed yet.

How does Australia's Privacy Act compare to the GDPR?

The two frameworks share core principles around data minimization, purpose limitation, and individual rights, but differ in key areas. The GDPR applies to all organizations processing EU residents' data regardless of turnover; the Privacy Act currently has a small business exemption. The GDPR requires 72-hour breach notification to authorities; Australia's NDB scheme allows a 30-day assessment window. The GDPR includes established rights to erasure and data portability; Australia has neither, though the exposure draft Bill released on 31 August 2026 proposes a right to erasure limited to large digital platforms. Australia does not have EU adequacy status. The reform program is gradually bringing Australia's framework closer to GDPR standards.

What were the biggest enforcement actions under the Privacy Act?

Three major enforcement actions define the current era. First, Australian Clinical Labs received the first-ever civil penalty under the Privacy Act, AUD 5.8 million in October 2025, for failing to protect 223,000 individuals' health information in a 2022 cyberattack. Second, Meta Platforms settled for AUD 50 million in December 2024 over the Cambridge Analytica data breach affecting more than 300,000 Australians. Third, the OAIC filed civil penalty proceedings against both Optus (9.5 million affected individuals, breach in 2022) and Medibank (9.7 million affected individuals, health data breach in 2022), which remain before the Federal Court with no penalty outcome announced.

Who is the OAIC and what powers does it have?

The Office of the Australian Information Commissioner (OAIC) is the independent statutory agency that administers the Privacy Act 1988 (Cth). It investigates complaints and can initiate its own investigations. Following the 2022 penalty increase and 2024 reforms, the OAIC can pursue civil penalties of up to AUD 50 million for a serious interference under section 13G and up to 2,000 penalty units for any interference under section 13H (10,000 penalty units where the entity is a body corporate, under section 82(5)(a) of the Regulatory Powers Act), issue infringement notices for the section 13K administrative breaches such as holding a non-compliant privacy policy (200 penalty units, AUD 72,800 since 1 July 2026, for a listed corporation, materially less for everyone else), accept enforceable undertakings, and seek injunctions. The OAIC can also conduct proactive compliance sweeps, as demonstrated by its January 2026 review of approximately 60 entities.

Does Australia have state-level privacy laws?

Yes. New South Wales (Privacy and Personal Information Protection Act 1998), Victoria (Privacy and Data Protection Act 2014), Queensland (Information Privacy Act 2009), the ACT (Information Privacy Act 2014), and Tasmania (Personal Information Protection Act 2004) all have state-level privacy legislation. These laws primarily apply to their respective state and territory government agencies. Western Australia's Privacy and Responsible Information Sharing Act 2024 commenced on 1 July 2026, covering WA public sector entities, with serious data breach reporting obligations from 1 January 2027. South Australia is now the only jurisdiction with no privacy statute; it relies on administrative Information Privacy Principles for state agencies. Private sector entities may face dual federal and state obligations if they handle health information in states with state-level health privacy regimes that operate alongside the federal Privacy Act.

What is the Consumer Data Right and how does it relate to privacy?

The Consumer Data Right (CDR) gives Australians the ability to direct businesses to share their data with accredited third parties. It is active in banking and energy, and non-bank lenders started sharing product data on 13 July 2026, with consumer data sharing phased in from 9 November 2026. The OAIC regulates the privacy and confidentiality aspects of the CDR framework, including handling complaints and eligible data breach notifications under CDR rules. The CDR operates alongside the Privacy Act rather than replacing it, and CDR-related personal information handling must also comply with the APPs.

What does the automated decision-making reform require?

From December 2026, APP entities that use computer programs to make decisions using personal information that could reasonably be expected to significantly affect an individual's rights or interests must include new disclosures in their privacy policies. The policy must describe the kinds of personal information used in automated decision-making and the types of decisions made. This requirement was introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth) and is designed to address concerns about algorithmic transparency in areas such as credit decisions, insurance assessments, and employment screening.

Updates

Third-round corrections: penalty-unit amounts restated at the AUD 364 unit in force since 1 July 2026 (200 units = AUD 72,800), the infringement-notice working shown, and the APP 8.3 prescribed-country pathway added to the transfer FAQ.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Expanded to cover statutory tort commencement (10 June 2025), Meta $50M Cambridge Analytica settlement, AML/CTF tranche 2 expansion (1 July 2026), tranche 2 reform status update, individual rights section, and business compliance section. Word count increased from 3,250 to approximately 6,200 words.

Reviewed and approved by an editor

Initial publication covering Privacy Act 1988, 13 APPs, OAIC, NDB scheme, 2024 reform Act, enforcement, cross-border disclosure, and state regimes.

Sources and References

  1. Privacy Act 1988 (Cth) — Federal Register of Legislation(legislation.gov.au).gov
  2. Privacy and Other Legislation Amendment Act 2024 (Cth) No. 128(legislation.gov.au).gov
  3. Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022(legislation.gov.au).gov
  4. My Health Records Act 2012 (Cth), in-force text - Federal Register of Legislation(legislation.gov.au).gov
  5. Australian Privacy Principles — OAIC(oaic.gov.au).gov
  6. Australian Privacy Principles Guidelines — OAIC(oaic.gov.au).gov
  7. About the Notifiable Data Breaches Scheme — OAIC(oaic.gov.au).gov
  8. Data breach notifications increase to all-time high in 2025, new NDB stats show - OAIC (6 July 2026)(oaic.gov.au).gov
  9. Statutory Tort for Serious Invasions of Privacy — OAIC(oaic.gov.au).gov
  10. Privacy Act 1988 (Cth) Schedule 2, Statutory Tort for Serious Invasions of Privacy - Federal Register of Legislation(legislation.gov.au).gov
  11. OAIC Regulatory Priorities 2025-26(oaic.gov.au).gov
  12. Privacy Compliance Sweep — OAIC(oaic.gov.au).gov
  13. Australian Clinical Labs Ordered to Pay Penalties — OAIC(oaic.gov.au).gov
  14. Landmark Settlement $50M from Meta — OAIC(oaic.gov.au).gov
  15. Civil Penalty Action Against Optus — OAIC(oaic.gov.au).gov
  16. Civil Penalty Action Against Medibank — OAIC(oaic.gov.au).gov
  17. Clearview AI Breached Australians Privacy — OAIC(oaic.gov.au).gov
  18. APP 8 Cross-Border Disclosure — OAIC(oaic.gov.au).gov
  19. State and Territory Privacy Legislation — OAIC(oaic.gov.au).gov
  20. Privacy Guidance for AML/CTF Reporting Entities — OAIC(oaic.gov.au).gov
  21. Privacy Act Review Report — Attorney-General Department(ag.gov.au).gov
  22. Government Response to Privacy Act Review Report — Attorney-General Department(ag.gov.au).gov
  23. Privacy — Attorney-General Department(ag.gov.au).gov
  24. Consumer Data Right — Australian Government(cdr.gov.au).gov
Share: