Australia
Australia Data Privacy Laws: Privacy Act, APPs & 2026 Reforms
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 24 primary sources cited on this page. How we verify our legal content

Australia's Privacy Act 1988 (Cth) governs personal information handling through 13 Australian Privacy Principles in Schedule 1, binding APP entities on collection, use, disclosure, and data security. The OAIC enforces the Act, and a statutory tort for serious invasions of privacy has applied since 10 June 2025.
Australia's Privacy Act 1988 (Cth) has governed the country's information protection framework for more than three decades, but the pace of change since 2022 has been significant. A wave of high-profile data breaches, the Privacy Act Review Report with 116 reform proposals, and the Privacy and Other Legislation Amendment Act 2024 (Cth) have collectively produced the most substantial overhaul of Australian privacy law in the Act's history.
This guide covers the current state of Australian data privacy law as of September 2026, including the 13 Australian Privacy Principles (APPs), the enforcement powers of the Office of the Australian Information Commissioner (OAIC), the Notifiable Data Breaches scheme, landmark enforcement actions through 2025-2026, and the staged reform timeline that will reshape obligations for businesses of all sizes.
This article addresses Australian federal privacy law under the Privacy Act 1988 (Cth) as amended, with notes on state and territory privacy regimes and sector-specific laws. For information on recording consent laws in Australia, including state-by-state wiretapping and surveillance provisions, see Australia Recording Laws.
Quick Answer: What Is Australia's Privacy Law?
Australia's primary privacy law is the Privacy Act 1988 (Cth), which imposes obligations on APP entities through 13 Australian Privacy Principles. The OAIC enforces the Act. As of June 2025, individuals also have a direct right to sue for serious invasions of privacy under a new statutory tort. Maximum penalties for bodies corporate reach AUD 50 million, three times the benefit obtained, or 30% of adjusted domestic turnover. A first wave of reform passed in December 2024. A second wave is at exposure draft stage: the Privacy Amendment (Personal Data Protection) Bill 2026 was released for consultation on 31 August 2026, with submissions closing 18 September 2026.
The Privacy Act 1988: Foundation of Australian Data Protection
The Privacy Act 1988 (Cth) is the principal piece of federal legislation governing how personal information is handled in Australia. Parliament enacted it to implement Australia's obligations under the International Covenant on Civil and Political Rights and has amended it numerous times since, most recently by the Privacy and Other Legislation Amendment Act 2024 (Cth).
The Act regulates the handling of personal information by Australian Government agencies and by private sector organizations that meet certain thresholds. It establishes the role of the Australian Information Commissioner as the primary regulator and sets out the framework for complaints, investigations, and enforcement.

Personal information under the Act is defined broadly. Section 6 of the Privacy Act 1988 (Cth) defines it as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not and whether it is recorded in a material form or not. This definition is wider than many comparable international frameworks.
Sensitive information receives heightened protection. This category includes health information, genetic data, biometric information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and criminal records. Collection of sensitive information generally requires consent and must be reasonably necessary for the entity's functions.
Who Must Comply: APP Entities
The Privacy Act applies to organizations and agencies collectively known as APP entities. These include:
- All Australian Government agencies and departments
- Private sector organizations with annual turnover of more than AUD 3 million
- All private sector health service providers, regardless of turnover
- Credit reporting bodies and credit providers
- Organizations that trade in personal information
- Tax file number recipients
- Entities prescribed by regulations
- Contractors providing services under a Commonwealth contract
A significant gap remains. Small businesses with annual turnover of AUD 3 million or less are generally exempt from the Privacy Act unless they fall within one of the listed exceptions. This exemption covers a large proportion of Australian businesses. As of September 2026, the government has not set a date for a general removal of the small business exemption, and the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 released on 31 August 2026 does not remove it. A targeted expansion through AML/CTF reforms took effect on 1 July 2026, and it reaches only information handled for, or in connection with, AML/CTF obligations (discussed below).
The 13 Australian Privacy Principles (APPs)
The Australian Privacy Principles replaced the National Privacy Principles and Information Privacy Principles on 12 March 2014. They are set out in Schedule 1 of the Privacy Act 1988 (Cth) and apply to all APP entities.
The APPs are principles-based rather than prescriptive. This gives organizations flexibility to tailor their personal information handling practices to their business models, but it also means compliance requires ongoing judgment about what constitutes reasonable steps in particular circumstances.

Part 1: Consideration of Personal Information Privacy
- APP 1: Open and Transparent Management. APP entities must manage personal information in an open and transparent way. This includes maintaining a clearly expressed and up-to-date privacy policy describing what personal information is collected, how it is held, used, and disclosed, and how complaints can be made.
- APP 2: Anonymity and Pseudonymity. Individuals must have the option of not identifying themselves, or using a pseudonym, when dealing with an APP entity, unless it is impractical or required by law.
Part 2: Collection of Personal Information
- APP 3: Collection of Solicited Personal Information. An APP entity must not collect personal information unless it is reasonably necessary for the entity's functions or activities. Collection of sensitive information also requires consent.
- APP 4: Dealing with Unsolicited Personal Information. If an entity receives personal information it did not solicit, it must determine whether it could have collected that information under APP 3. If not, the entity must destroy or de-identify it as soon as practicable.
- APP 5: Notification of Collection. At or before the time of collection, an entity must take reasonable steps to notify the individual of specified matters, including the entity's identity, the purposes of collection, and the individual's right to access and seek correction of the information.
Part 3: Dealing with Personal Information
- APP 6: Use or Disclosure. Personal information may only be used or disclosed for the primary purpose of collection, or for a secondary purpose where the individual would reasonably expect it and the purpose is related to the primary purpose.
- APP 7: Direct Marketing. An organization may only use or disclose personal information for direct marketing if certain conditions are met, including providing a simple opt-out mechanism on every direct marketing communication.
- APP 8: Cross-Border Disclosure. Before disclosing personal information to an overseas recipient, an APP entity must take reasonable steps to ensure the recipient handles the information in accordance with the APPs. The disclosing entity remains accountable for breaches by the overseas recipient.
- APP 9: Government-Related Identifiers. Organizations must not adopt, use, or disclose a government-related identifier such as a tax file number or Medicare number unless a specific exception applies.
Part 4: Integrity of Personal Information
- APP 10: Quality of Personal Information. An entity must take reasonable steps to ensure personal information it collects, uses, or discloses is accurate, up-to-date, complete, and relevant to the purposes for which it is to be used.
- APP 11: Security of Personal Information. An entity must take reasonable steps to protect personal information from misuse, interference, loss, and unauthorized access, modification, or disclosure. When information is no longer needed, the entity must destroy or de-identify it.
Part 5: Access to and Correction of Personal Information
- APP 12: Access to Personal Information. Individuals have the right to request access to personal information held about them by an APP entity. Under APP 12.4 an agency must respond within 30 days, while an organisation must respond within a reasonable period. An agency must not charge for making the request or for giving access (APP 12.7). An organisation may charge for giving access, but the charge must not be excessive and must not apply to the making of the request (APP 12.8).
- APP 13: Correction of Personal Information. Individuals may request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading personal information. If the entity refuses, it must provide written reasons and note the refused correction request alongside the information.
Individual Rights Under the Privacy Act
The APPs confer several rights on individuals directly, through APPs 12 and 13.
Right of Access (APP 12)
An individual may request access to personal information held about them by any APP entity. Under APP 12.4(a), an agency must respond within 30 days, while an organisation must respond within a reasonable period after the request is made. The 30-day figure is the statutory deadline only for agencies; for organisations the OAIC treats 30 days as the benchmark for what is reasonable. Grounds for refusing access are limited and include circumstances where access would unreasonably impact another person's privacy, pose a threat to health or safety, or prejudice ongoing legal proceedings. If access is refused in whole or in part, the entity must provide written reasons.
Right of Correction (APP 13)
Where personal information is inaccurate, out-of-date, incomplete, irrelevant, or misleading, an individual may ask the APP entity to correct it. The entity must take reasonable steps to correct the information. Under APP 13.5, an agency must respond within 30 days and an organisation within a reasonable period, and no entity may charge for making the request or for the correction itself. If the entity declines to correct, it must provide written reasons and, on request, note that the individual sought correction alongside the record.
Complaints Mechanism
Individuals who believe an APP entity has breached the Privacy Act may lodge a complaint directly with the OAIC. The OAIC will attempt conciliation first. If conciliation fails or the complaint raises a systemic issue, the Commissioner may investigate and make a determination. From 2025, the OAIC's complaint-handling approach has shifted to focus resources on systemic matters and repeated breaches, with a faster triage model for routine individual complaints.
No General Right to Erasure (Yet)
Australia does not yet have a statutory right to erasure comparable to Article 17 of the GDPR. APP 11 requires destruction or de-identification of personal information no longer needed for any purpose, but this applies to the entity as a duty, not as an individual right the person can directly enforce. A right to erasure is among the proposals under consideration for the tranche 2 reforms.
The OAIC: Australia's Privacy Regulator
The Office of the Australian Information Commissioner (OAIC) is the independent statutory agency responsible for privacy regulation at the federal level. It administers the Privacy Act and oversees compliance by APP entities.
The OAIC has broad powers. It can conduct investigations on its own initiative (own motion investigations) or in response to complaints. It can accept enforceable undertakings, make determinations, seek injunctions, and pursue civil penalty proceedings in the Federal Court. From December 2024, the OAIC also gained the power to issue infringement notices for the administrative breaches listed in section 13K, such as failing to maintain a compliant privacy policy. Section 80UB(1A) fixes that amount at 200 penalty units where the entity is a listed corporation within the meaning of the Corporations Act 2001, which is AUD 72,800 at the Commonwealth penalty unit of AUD 364 in force since 1 July 2026 (the AUD 66,000 figure the OAIC quoted in January 2026 used the earlier AUD 330 unit). For any other entity the amount falls back to section 104(2) of the Regulatory Powers Act: the lesser of one-fifth of the maximum penalty a court could impose for the contravention, and 12 penalty units for an individual or 60 penalty units for a body corporate. On a section 13K contravention the court maximum for a company is 1,000 penalty units, one-fifth of which is 200, so the 60-penalty-unit limb binds: 12 penalty units for an individual and 60 for a body corporate.

2025-2026 Regulatory Priorities
The OAIC's regulatory priorities for 2025-2026 name four areas of focus:
- Rebalancing power and information asymmetries: The rental and property, credit reporting and data brokerage sectors, advertising technology such as pixel tracking, practices that erode privacy and information access rights in the application of artificial intelligence, and excessive collection and retention of personal information.
- Rights preservation in new and emerging technologies: Facial recognition technology and other biometric scanning, new surveillance technologies such as location tracking in apps, cars and other devices, and government use of artificial intelligence and automated decision-making.
- Strengthening the information governance of the Australian Public Service: Inadequate handling of information across its life cycle, the quality of administrative decision-making, agency use of messaging apps, and integrity risks from poor disclosure practices.
- Ensuring timely access to government information: Complaint investigations and monitoring aimed at agencies with high refusal rates, missed statutory timeframes, and weak disclosure log and information publication scheme compliance.
First-Ever Privacy Compliance Sweep
In January 2026, the OAIC launched its inaugural privacy compliance sweep, reviewing the privacy policies of approximately 60 entities against APP 1.4 across six sectors that collect information in person: rental and property, chemists and pharmacists, licensed venues, car rental companies, car dealerships, and pawnbrokers and second-hand dealers. Entities found with non-compliant privacy policies face compliance notices and infringement notices. The OAIC quoted penalties of up to AUD 66,000 at the time (200 penalty units, now AUD 72,800 at the AUD 364 unit in force since 1 July 2026), which is the listed-corporation amount under section 80UB(1A); most entities in these sectors are not listed corporations and face the lower Regulatory Powers Act default. This sweep represents a deliberate shift toward proactive enforcement rather than waiting for complaints or breach reports.
Penalties and Enforcement
The 2022 Penalty Increase
The enforcement landscape changed dramatically in December 2022 when the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth) took effect. Under section 13G, where an interference with privacy is serious, the maximum civil penalty for bodies corporate is the greatest of:
- AUD 50 million
- Three times the value of the benefit obtained from the contravening conduct
- 30% of the body corporate's adjusted domestic turnover during the breach turnover period (minimum 12 months)
For a person other than a body corporate, section 13G(2) caps the penalty at AUD 2.5 million. The previous maximum was AUD 2.22 million. The increase was directly motivated by the Optus and Medibank breaches that exposed millions of Australians' personal information in late 2022.
The Privacy and Other Legislation Amendment Act 2024 (Cth) reshaped this into three tiers with effect from 11 December 2024:
- Section 13G applies where an act or practice is an interference with privacy and that interference is serious. Repetition is no longer part of the trigger. It survives as one factor a court may weigh in assessing seriousness under section 13G(1B)(f).
- Section 13H is a mid-tier provision contravened by any act or practice that is an interference with privacy, serious or not, carrying up to 2,000 penalty units. Under section 13J, a court that is not satisfied an interference was serious may make a section 13H penalty order instead.
- Section 13K covers a short list of administrative breaches, including failing to hold a compliant APP privacy policy, at up to 200 penalty units. It is the provision infringement notices and compliance notices attach to.
Both of those figures are multiplied by five for a body corporate. Section 82(5)(a) of the Regulatory Powers Act caps a company's pecuniary penalty at five times the amount specified in the civil penalty provision, and section 13G(4) of the Privacy Act switches that multiplier off only for section 13G. A company therefore faces up to 10,000 penalty units under section 13H and up to 1,000 penalty units under section 13K.
Landmark Enforcement Actions (2021-2026)
Australian Clinical Labs: AUD 5.8 Million (October 2025)
The Federal Court ordered Australian Clinical Labs to pay AUD 5.8 million in the first-ever civil penalty under the Privacy Act. The penalty followed a 2022 cyberattack on its subsidiary Medlab Pathology that affected 223,000 individuals. The breakdown: AUD 4.2 million for failing to take reasonable steps to protect personal information under APP 11.1, AUD 800,000 for failing to conduct a reasonable and expeditious breach assessment, and AUD 800,000 for failing to notify the OAIC in a timely manner.
Meta Platforms: AUD 50 Million Settlement (December 2024)
The OAIC reached a landmark AUD 50 million settlement with Meta Platforms, Inc. as part of an enforceable undertaking resolving civil penalty proceedings originally filed in March 2020. The proceedings related to Meta's disclosure of Australian Facebook users' personal information to Cambridge Analytica without consent. More than 300,000 Australians were eligible for payments under a program administered independently by KPMG Australia. Registration closed on 31 December 2025 and the claim portal is now shut. The administrator emailed verified claimants in July 2026 asking for bank details by 20 August 2026, and made the first-round payment on 2 September 2026 to everyone who met that date. Those payments show up in bank statements under the reference "FB PP". A second round runs in October 2026 for claimants whose first-round payment failed and for anyone who did not submit the Payment Form by 20 August 2026. The administrator's final deadline for that form is 8 October 2026 at 11.59pm AEST for an Australian bank account and 26 October 2026 at 11.59pm AEST for an international one, and a claimant who misses it receives no payment at all. Neither Meta nor the OAIC administers the scheme. The OAIC has warned that scammers exploit this settlement, so treat any unexpected call, text or link offering help with a payment as a scam and report it to Scamwatch.
Optus: Civil Proceedings (Filed August 2025, Ongoing)
The OAIC filed civil penalty proceedings against Optus in the Federal Court following its September 2022 data breach, which exposed personal information of approximately 9.5 million Australians. The Commissioner alleges Optus failed to take reasonable steps to protect personal information over a three-year period from October 2019 to September 2022. The proceedings remain before the Federal Court and no penalty outcome has been announced.
Medibank: Civil Proceedings (Filed, Ongoing)
The OAIC filed civil penalty proceedings against Medibank Private for its October 2022 breach affecting 9.7 million Australians, including highly sensitive health data. The Commissioner alleges Medibank failed to take reasonable steps to protect personal information from March 2021 to October 2022. The proceedings remain before the Federal Court and no penalty outcome has been announced.
Clearview AI: Determination (2021)
The OAIC determined that Clearview AI breached the Privacy Act by scraping Australians' facial images from the internet and using them in a facial recognition tool without consent. Clearview AI was ordered to cease collecting images from Australian individuals and destroy all collected images within 90 days. The case established that the Privacy Act can apply to overseas entities processing Australians' personal information.
The Notifiable Data Breaches Scheme
The Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth) took effect on 22 February 2018. It requires APP entities to notify affected individuals and the Australian Information Commissioner when a data breach is likely to result in serious harm.
What Triggers the NDB Scheme
An eligible data breach occurs when three conditions are met:
- There is unauthorized access to, or unauthorized disclosure of, personal information held by an entity (or the information is lost in circumstances where unauthorized access or disclosure is likely).
- The breach is likely to result in serious harm to any of the affected individuals.
- The entity has been unable to prevent the likely risk of serious harm through remedial action.
Serious harm is assessed by reference to factors including the sensitivity of the information, the number of individuals affected, the people who have obtained or could obtain access, and the nature of the potential harm (financial, physical, psychological, reputational).
Assessment and Notification Timeline
When an entity suspects a breach may have occurred, it must carry out a reasonable and expeditious assessment. The entity must take all reasonable steps to complete the assessment within 30 days of becoming aware of grounds to suspect a breach.
If the assessment confirms an eligible data breach, the entity must prepare a notification statement and provide it to the OAIC as soon as practicable. The statement must include the entity's identity and contact information, a description of the breach, the kinds of information involved, and recommendations for affected individuals.
The entity must also take reasonable steps to notify each affected individual directly, or, if direct notification is not practicable, publish the statement on its website and take reasonable steps to publicize it.
NDB Statistics
The OAIC publishes half-yearly NDB statistics and, since November 2025, an interactive Notifiable Data Breach statistics dashboard covering every period since the scheme began. The OAIC received 1,205 notifications in the 2025 calendar year, the highest annual total since the scheme commenced and an 8% rise on the 1,112 reported in 2024. Malicious or criminal activity accounted for 716 of them, and health service providers were the most affected sector at 19% (225 notifications), ahead of financial services, the Australian Government, business and professional associations, education, and legal, accounting and management services. Health information is consistently the most frequently reported category of sensitive information involved in eligible data breaches.
Consequences of Non-Compliance
Failing to comply with the NDB scheme is itself an interference with privacy and can result in the full range of enforcement actions, including civil penalties. The Australian Clinical Labs penalty of AUD 5.8 million included AUD 1.6 million specifically for NDB failures.
The Privacy and Other Legislation Amendment Act 2024 (Cth)
The Privacy and Other Legislation Amendment Act 2024 (Cth) (Act No. 128 of 2024) passed both Houses of Parliament on 29 November 2024 and received Royal Assent on 10 December 2024. It advanced 23 of the 116 proposals from the Privacy Act Review Report and introduced changes at staged commencement dates.
Statutory Tort for Serious Invasions of Privacy (Commenced 10 June 2025)
The most significant change for individuals is a new cause of action in Schedule 2 of the Privacy Act 1988 (Cth), which commenced on 10 June 2025. Under the statutory tort, an individual has a cause of action against any person (not only APP entities) who invaded their privacy by:
- Intrusion upon seclusion: Physically intruding into a private space, watching or surveilling a private act, or intercepting private communications.
- Misuse of personal information: Collecting, using, or disclosing personal information in a way that violates a reasonable expectation of privacy.
To succeed, the plaintiff must establish all five elements in Schedule 2 clause 7(1): that the defendant invaded their privacy by intruding upon their seclusion or misusing information relating to them; that a person in the plaintiff's position would have had a reasonable expectation of privacy in all the circumstances; that the invasion was intentional or reckless, with reckless taking its Criminal Code meaning; that the invasion was serious; and that the public interest in the plaintiff's privacy outweighed any countervailing public interest.
The fault element matters. A negligent or accidental invasion of privacy is not actionable under this tort. Clause 7(3) lists the countervailing public interests a court may weigh, including freedom of expression, freedom of the media, the proper administration of government, open justice, public health and safety, national security, and the prevention and detection of crime and fraud.
Damages are capped. Under clause 11, a court must not award aggravated damages and may award exemplary or punitive damages only in exceptional circumstances. The sum of any damages for non-economic loss plus any exemplary or punitive damages must not exceed the greater of AUD 478,550 and the maximum non-economic-loss award available in defamation proceedings under an Australian law. Damages for emotional distress are available within that cap.
Clause 12 is separate and unconstrained. The court may grant whatever other remedies it thinks most appropriate, including an account of profits, an injunction, an order requiring an apology, a correction order, an order that material obtained through the invasion be destroyed or delivered up, and a declaration that the defendant seriously invaded the plaintiff's privacy. The tort is actionable without proof of damage, meaning a plaintiff does not need to demonstrate financial loss to bring a claim.
Time limits: For adults, proceedings must commence within 1 year after the plaintiff became aware of the invasion, or within 3 years of the date of invasion (whichever is earlier). For individuals under 18 at the time of the invasion, proceedings must commence before their 21st birthday. Clause 14(2) to (4) lets a plaintiff apply for an order extending that period where it was not reasonable in the circumstances to have commenced in time, with a hard outer limit of 6 years after the invasion. Clause 19 adds a single publication rule, so republishing substantially the same material in a materially similar manner does not restart the clock.
Defences under clause 8(1) include that the invasion was required or authorised by an Australian law or court order, that the plaintiff consented, that the defendant reasonably believed the invasion was necessary to prevent or lessen a serious threat to the life, health or safety of a person, and that the invasion was incidental to a lawful right of defence of persons or property and was proportionate, necessary and reasonable. Where the invasion involved publication, clause 8(2) and (3) add three defamation-derived defences: absolute privilege, publication of public documents, and fair report of proceedings of public concern.
The breadth of this tort is notable. Unlike complaints to the OAIC (which are limited to APP entities), the statutory tort reaches individuals, private companies outside the APP threshold, and conduct that occurred before or outside a formal APP entity relationship. It applies to any person who is not exempt under Part 3 of Schedule 2.
Who Cannot Be Sued: The Part 3 Exemptions
Part 3 sets out hard exemptions, not factors a court balances. If an exemption applies, the Schedule does not apply at all.
- Journalists. Clause 15 excludes a journalist, a journalist's employer or engager, and a person assisting a journalist, to the extent the invasion involves collecting, preparing for publication or publishing journalistic material. Clause 15(4) makes it immaterial whether the journalist breached the standards or code of practice they are subject to.
- Agencies and State or Territory authorities. Clauses 16 and 16A exclude those bodies and their staff members acting in good faith in the performance or purported performance of a function, or the exercise or purported exercise of a power.
- Law enforcement bodies. Clause 16B excludes law enforcement bodies, their staff members acting in that capacity, disclosures made to such a body, and information a law enforcement body disclosed.
- Intelligence agencies. Clause 17 applies the same carve-out to intelligence agencies, their staff and ASIO affiliates.
- Persons under 18. Clause 18 excludes any invasion of privacy by a person under 18 years of age.
- Deceased persons. Clause 20 bars any action in respect of an invasion of the privacy of a deceased person, or against a defendant who has died.
Under clause 8A, a court may determine whether a Part 3 exemption applies at any stage of the proceedings, and is to do so before trial where a party applies early.
Automated Decision-Making Transparency (Commencing December 2026)
APP entities that use computer programs to make decisions using personal information that could reasonably be expected to significantly affect individuals' rights or interests must include additional disclosures in their privacy policies. These disclosures cover the kinds of personal information used and the types of decisions made by automated means. This requirement commences in December 2026.
Children's Online Privacy Code
Section 26GC(10) of the Privacy Act requires the Information Commissioner to develop and register the Children's Online Privacy Code within 24 months of the Privacy and Other Legislation Amendment Act 2024 receiving Royal Assent. Royal Assent was 10 December 2024, so the Code must be registered by 10 December 2026.
The Code will bind providers of social media services, relevant electronic services and designated internet services as defined in the Online Safety Act 2021 where the service is likely to be accessed by children, other than entities providing a health service. The OAIC released the exposure draft Code on 31 March 2026 and closed its Phase 3 consultation on 5 June 2026, receiving 135 written submissions, 425 responses from children, young people, parents and carers, and feedback from 374 stakeholders across 14 roundtables. A Regulatory Impact Analysis is now under way ahead of registration. No commencement or compliance date for the Code itself has been set.
Enhanced OAIC Powers
The Act gave the OAIC new enforcement tools from December 2024, including:
- Infringement notices under section 80UB for the section 13K administrative breaches, such as failing to hold a compliant privacy policy (200 penalty units, AUD 72,800 since 1 July 2026, applies to listed corporations; other entities face the lower default under Part 5 of the Regulatory Powers Act)
- Strengthened investigative powers
- Clearer powers to share information with overseas privacy regulators
Cross-Border Data Transfers (APP 8)
Australia's rules on international data transfers are governed by APP 8. Before disclosing personal information to an overseas recipient, an APP entity must take reasonable steps to ensure the recipient handles the information in accordance with the APPs.
The critical feature of APP 8 is accountability transfer. If an overseas recipient breaches the APPs in handling the disclosed information, the disclosing Australian entity is treated as having breached the APPs itself. The Australian entity faces enforcement action for the overseas recipient's failures.
Exceptions to APP 8
The accountability obligation does not apply where:
- The APP entity reasonably believes the overseas recipient is subject to a law or binding scheme that is substantially similar to the APPs, and the individual can enforce that law or scheme.
- APP 8.3 applies: the recipient is subject to the laws of a country prescribed by the regulations, or is a participant in a binding scheme prescribed by the regulations, and any conditions attached to that prescription are satisfied. No country or scheme has been prescribed yet.
- The individual consents to the cross-border disclosure after being informed that APP 8's accountability protection will not apply to them.
- The disclosure is required or authorized by Australian law or a court order.
No EU Adequacy Decision
Australia does not currently have an EU adequacy decision under the GDPR. Transfers of personal data from the EU/EEA to Australia require appropriate safeguards such as Standard Contractual Clauses. The small business exemption has been cited as a barrier to obtaining adequacy, which adds urgency to the tranche 2 reform work.
The Prescribed Country and Binding Scheme Pathway (APP 8.3)
The whitelist mechanism is already law. The Privacy and Other Legislation Amendment Act 2024 inserted APP 8.2(aa) and APP 8.3, which switch off the APP 8.1 accountability obligation where the overseas recipient is subject to the laws of a country prescribed by the regulations, or is a participant in a binding scheme prescribed by the regulations, and any conditions attached to that prescription are met.
Section 100(1A) sets the prerequisites. Before the Governor-General prescribes a country or scheme, the Minister must be satisfied that its protection is at least substantially similar overall to the protection the APPs give, and that the individual can access mechanisms to enforce it. Section 100(1B) lets a prescription be made subject to conditions attached to specified entities or to specified kinds of personal information.
What is still outstanding is the prescribing. The Privacy Regulations 2025 contain no APP 8.3 prescription, so as of September 2026 no country and no binding scheme has been approved and the pathway cannot yet be used in practice.
Pending Reforms: Tranche 2 and Beyond
On 31 August 2026 the Attorney-General's Department released an exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 together with a consultation paper. Submissions close on 18 September 2026. The Bill is not law, remains subject to further consideration by government, and carries no settled commencement date.
The draft would modernise the core definitions (personal information, sensitive information, de-identified, collects, consent and disclosure), replace several existing obligations with a single fair and reasonable test for the collection, use and disclosure of personal information, refine consent and notification requirements, clarify the direct marketing rules, strengthen data security, minimisation and breach response, introduce a right to erasure against large digital platforms, and reduce obligations on processors. The consultation also seeks views on further measures still under development covering OAIC administration and enforcement, wearable surveillance technologies such as smart glasses and ear buds, and connected vehicles.
Two points matter for readers watching the exemptions: the draft Bill does not remove the small business exemption, and it does not remove the employee records exemption. The tranche 2 items below set out where each proposal now stands.
Small Business Exemption
The OAIC supports full removal of the small business exemption. The government agreed in principle to the proposal in its 2023 response to the Review Report. As of September 2026, no commencement date for a general removal has been legislated, and the 31 August 2026 exposure draft Bill does not remove the exemption.
What actually changed in 2026: AML/CTF reform brought two waves of small businesses into the Privacy Act. Existing tranche 1 reporting entities were affected from 31 March 2026. From 1 July 2026, tranche 2 professions (real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious stones, metals and products) became reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
Section 6E(1A) of the Privacy Act is the operative provision, and its scope is narrower than it is often described. A small business operator that is a reporting entity, or an authorised agent of one, is treated as an organisation only in relation to activities carried on for the purposes of, or in connection with, the AML/CTF Act and the AML/CTF Rules. Customer due diligence and the records that support it are covered. The rest of the business stays outside the Privacy Act unless another exception applies.
Employee Records Exemption
The employee records exemption (section 7B(3) of the Privacy Act 1988 (Cth)) exempts acts and practices by private sector employers directly related to an employee relationship. Removal or reduction of this exemption is under active consultation.
Right to Erasure
Australia does not yet have a statutory right to erasure. The 31 August 2026 exposure draft Bill would introduce one, but only against a large digital platform: an organisation providing a social media service, relevant electronic service or designated internet service under the Online Safety Act 2021 whose business group had at least AUD 500 million in gross revenue in the previous financial year, or that averaged 2.5 million monthly Australian end users, or that is prescribed by regulation. The draft right is subject to exceptions, including where compliance is technically impossible or infeasible. It is narrower than the general qualified right the Privacy Act Review Report recommended, and it is not law.
Fair and Reasonable Test
A proposed overarching requirement that collection, use, and disclosure of personal information be fair and reasonable in the circumstances would add an objective test beyond the existing APPs. This would bring Australian law closer to EU standards.
Controller/Processor Distinction
This is no longer speculative. Schedule 6 of the 31 August 2026 exposure draft Bill defines controller and processor and provides that a processor does not breach an Australian Privacy Principle or a registered APP code where it acts on a controller's written, documented instructions for purposes the controller specified, with responsibility flowing back to the controller. The concepts are analogous to the GDPR framework, though the drafting is framed as an exception for information processors rather than a full allocation-of-responsibility regime.
Sector-Specific Privacy Laws
My Health Records Act 2012
The My Health Records Act 2012 (Cth) governs the national digital health record system. It establishes strict rules about who may access health information in the My Health Record system and imposes criminal penalties for unauthorized collection, use, or disclosure. The Australian Digital Health Agency operates the system, and the OAIC oversees privacy compliance.
The Act mandates separate data breach notification to both the OAIC and the System Operator for breaches involving My Health Record data, supplementing the general NDB scheme obligations.
Consumer Data Right
The Consumer Data Right (CDR) gives Australians greater control over their data by allowing them to direct businesses to share their data with accredited third parties. The CDR is active in banking (since July 2020) and energy (since November 2022). Non-bank lenders began sharing product data such as interest rates, fees, charges and eligibility criteria on 13 July 2026, and consumer data sharing for that sector is being phased in from 9 November 2026 according to provider size.
The OAIC regulates privacy and confidentiality aspects of the CDR, handling complaints and eligible data breach notifications within the CDR framework.
State and Territory Laws
State and territory governments have their own privacy legislation primarily covering their own public sectors:
| Jurisdiction | Legislation |
|---|---|
| New South Wales | Privacy and Personal Information Protection Act 1998 (PPIPA) |
| Victoria | Privacy and Data Protection Act 2014 (PDP Act) |
| Queensland | Information Privacy Act 2009 (IPA) |
| Australian Capital Territory | Information Privacy Act 2014 (ACT) |
| Tasmania | Personal Information Protection Act 2004 |
| Northern Territory | Information Act 2002 (privacy-related provisions) |
| Western Australia | Privacy and Responsible Information Sharing Act 2024 (in force 1 July 2026) |
| South Australia | No comprehensive state privacy legislation |
Western Australia is the most recent addition. The Privacy and Responsible Information Sharing Act 2024 (WA) commenced on 1 July 2026, setting principles and standards for how WA public sector entities collect, use, store and share personal information. It covers departments, local governments, non-SES organisations, government trading enterprises and public universities, plus contracted providers where the contract says so, and Ministers and Parliamentary Secretaries in their executive capacity. A WA Information Commissioner and a Chief Data Officer oversee it, and agencies must start reporting serious data breaches to the Commissioner and to affected people from 1 January 2027.
South Australia is now the only jurisdiction with no privacy statute. A state privacy committee handles complaints about state agencies against a set of administrative Information Privacy Principles.
State and territory laws primarily apply to their respective public sectors. Private sector entities handling health information in New South Wales, Victoria, and the ACT may need to comply with both federal and applicable state privacy obligations.
Australia vs. GDPR: Key Comparisons
| Feature | Australia (Privacy Act 1988) | EU (GDPR) |
|---|---|---|
| Scope | APP entities (turnover threshold, with targeted expansions) | All organizations processing EU residents' data |
| Legal basis for processing | Reasonably necessary; consent for sensitive data | Six legal bases including consent, contract, legitimate interest |
| Right to erasure | Not enacted; the 2026 exposure draft proposes one limited to large digital platforms | Yes, Article 17 |
| Data breach notification | 30-day assessment; notify "as soon as practicable" | 72 hours to supervisory authority |
| Maximum penalties | AUD 50M / 3x benefit / 30% turnover | EUR 20M / 4% global turnover |
| Private right of action | Statutory tort (from 10 June 2025) | Yes, Article 82 |
| Data Protection Officer | Not required (may change in tranche 2) | Required in certain circumstances |
| Adequacy status | No EU adequacy decision | N/A |
| Cross-border accountability | APP 8: disclosing entity remains liable | Adequacy decisions, SCCs, BCRs |
Business Compliance: Practical Steps for APP Entities
Any private sector organization operating in Australia with annual turnover above AUD 3 million (or within a covered category regardless of turnover) should maintain the following baseline:
-
Maintain a current privacy policy covering what information is collected, how it is used and disclosed, how individuals can access and correct their information, and how to complain. Non-compliant policies are the primary target of the OAIC's 2026 compliance sweep.
-
Map your data flows. Know what personal information you collect, where it is stored, who it is shared with (including overseas recipients), and how long it is retained. APP 4 requires you to assess and destroy unsolicited personal information.
-
Implement an APP 11 security program. Take reasonable steps appropriate to the size and nature of your organization to protect personal information from unauthorized access, modification, disclosure, misuse, and loss.
-
Establish a data breach response plan. Your plan must enable you to identify, contain, and assess a potential breach within the 30-day NDB assessment window. Designate who triggers the NDB assessment process and who notifies the OAIC.
-
Review overseas vendor contracts. Under APP 8, you remain accountable for your overseas recipients' handling of personal information. Contracts with overseas processors should require APPs-equivalent handling and include breach notification obligations to you.
-
Prepare for the statutory tort. Since 10 June 2025, any person who is not exempt under Part 3 of Schedule 2 can be sued for a serious invasion of privacy, and that includes employees, contractors, and small businesses previously outside the Privacy Act's scope. Review your surveillance, monitoring, and data practices against the new tort standard. Remember that the claim requires an intentional or reckless invasion, and that journalists handling journalistic material, agencies acting in good faith, law enforcement bodies, intelligence agencies, and people under 18 are exempt.
-
Comply with the AML/CTF expansion (in force since 1 July 2026). If you are a real estate professional, lawyer, accountant, conveyancer, trust or company service provider, or a dealer in precious stones and metals, the Privacy Act has applied to you since 1 July 2026 regardless of turnover, but only for personal information you handle for, or in connection with, your AML/CTF obligations. Existing tranche 1 reporting entities were affected from 31 March 2026. Get advice on where that line falls in your business.
-
Prepare for automated decision-making disclosures (December 2026). If your organization uses algorithms or computer programs to make decisions significantly affecting individuals, update your privacy policy to include the new APP disclosures before December 2026.
This article presents general legal information about Australian federal privacy law as verified in September 2026. It does not constitute legal advice. The law continues to evolve through ongoing legislative reform and OAIC enforcement action. Consult a lawyer admitted in the relevant Australian jurisdiction for advice on your specific situation.
Related Australian Data Privacy Guides
- The 13 Australian Privacy Principles
- How to Complain to the OAIC
- The Notifiable Data Breaches Scheme
- Deepfake and Intimate Image Laws in Australia
- The Social Media Minimum Age Law: Who Is Covered, Penalties and the High Court Challenges
- Doxxing Laws in Australia
- Identity Theft Laws in Australia: Criminal Penalties by State
- Identity Theft Victims' Certificates: Commonwealth, NSW, WA, QLD and NT
- Bank Liability for Identity Theft: The ePayments Code
- The Spam Act 2003: Marketing Emails and SMS, Penalties and How to Report Spam
- The Do Not Call Register: Who Can Register, Exemptions and Penalties
- Telemarketing Rules: Calling Hours, Caller ID and the Fax Standard
- The Statutory Tort for Serious Invasions of Privacy
- Freedom of Information: Requesting Government Records in Every State
This guide is part of our Australia law guides.
Frequently Asked Questions
Does the Australian Privacy Act apply to small businesses?
Businesses with annual turnover of AUD 3 million or less are generally exempt from the Privacy Act 1988 (Cth) unless they handle health information, trade in personal information, are a credit reporting body, or are a contractor under a Commonwealth contract. This exemption is under review: the OAIC supports its removal, and the government agreed in principle in its 2023 Privacy Act Review response. As of September 2026 no date for a general removal has been legislated, and the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 released on 31 August 2026 does not remove the exemption. A targeted expansion did take effect: tranche 1 AML/CTF reporting entities were captured on 31 March 2026 and tranche 2 professions (real estate agents, lawyers, accountants, conveyancers, and dealers in precious stones and metals) on 1 July 2026. Section 6E(1A) applies the Privacy Act to those small businesses only for personal information handled for, or in connection with, their AML/CTF obligations, not to the rest of the business.
What is the new statutory tort for serious invasions of privacy?
The statutory tort commenced on 10 June 2025 under Schedule 2 of the Privacy Act 1988 (Cth) as inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth). It gives an individual the right to sue another person who is not exempt under Part 3 of Schedule 2 (not only APP entities) for a serious invasion of privacy through either intrusion upon seclusion or misuse of information relating to them. To succeed the plaintiff must establish all five elements in clause 7(1), including that a person in their position would have had a reasonable expectation of privacy and that the invasion was intentional or reckless. A negligent or accidental invasion is not actionable. Part 3 exempts journalists handling journalistic material, agencies and their staff acting in good faith, law enforcement bodies, intelligence agencies, and anyone under 18. Remedies include damages, injunctions and apology orders, but clause 11 bars aggravated damages and caps non-economic loss plus any exemplary or punitive damages at the greater of AUD 478,550 and the defamation non-economic-loss cap. For adults, proceedings must start within 1 year of becoming aware of the invasion or within 3 years of the invasion itself, whichever is earlier, subject to a court-ordered extension of up to 6 years.
What should a business do if it suffers a data breach in Australia?
Under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), the entity must first assess whether there has been unauthorized access to, disclosure of, or loss of personal information that is likely to result in serious harm. All reasonable steps must be taken to complete this assessment within 30 days. If the breach qualifies as an eligible data breach, the entity must notify the OAIC and affected individuals as soon as practicable, providing the entity's identity, a description of the breach, the types of information involved, and steps individuals should take to protect themselves. Failure to comply can result in significant civil penalties, as demonstrated by the AUD 1.6 million NDB component of the AUD 5.8 million Australian Clinical Labs penalty.
Can Australian businesses transfer personal data overseas?
Yes, but APP 8 of the Privacy Act 1988 (Cth) imposes strict accountability requirements. Before disclosing personal information to an overseas recipient, an APP entity must take reasonable steps to ensure the recipient handles the information in accordance with the APPs. If the overseas recipient breaches the APPs, the Australian disclosing entity is treated as having breached the APPs itself and faces enforcement action. Exceptions include where the recipient is subject to a substantially similar law the individual can enforce, where the individual consents after being informed that APP 8 protections will not apply, where Australian law requires the disclosure, or (under APP 8.2(aa) and APP 8.3, added in 2024) where the recipient is in a country or bound by a scheme prescribed by regulation, although no country or scheme has been prescribed yet.
How does Australia's Privacy Act compare to the GDPR?
The two frameworks share core principles around data minimization, purpose limitation, and individual rights, but differ in key areas. The GDPR applies to all organizations processing EU residents' data regardless of turnover; the Privacy Act currently has a small business exemption. The GDPR requires 72-hour breach notification to authorities; Australia's NDB scheme allows a 30-day assessment window. The GDPR includes established rights to erasure and data portability; Australia has neither, though the exposure draft Bill released on 31 August 2026 proposes a right to erasure limited to large digital platforms. Australia does not have EU adequacy status. The reform program is gradually bringing Australia's framework closer to GDPR standards.
What were the biggest enforcement actions under the Privacy Act?
Three major enforcement actions define the current era. First, Australian Clinical Labs received the first-ever civil penalty under the Privacy Act, AUD 5.8 million in October 2025, for failing to protect 223,000 individuals' health information in a 2022 cyberattack. Second, Meta Platforms settled for AUD 50 million in December 2024 over the Cambridge Analytica data breach affecting more than 300,000 Australians. Third, the OAIC filed civil penalty proceedings against both Optus (9.5 million affected individuals, breach in 2022) and Medibank (9.7 million affected individuals, health data breach in 2022), which remain before the Federal Court with no penalty outcome announced.
Who is the OAIC and what powers does it have?
The Office of the Australian Information Commissioner (OAIC) is the independent statutory agency that administers the Privacy Act 1988 (Cth). It investigates complaints and can initiate its own investigations. Following the 2022 penalty increase and 2024 reforms, the OAIC can pursue civil penalties of up to AUD 50 million for a serious interference under section 13G and up to 2,000 penalty units for any interference under section 13H (10,000 penalty units where the entity is a body corporate, under section 82(5)(a) of the Regulatory Powers Act), issue infringement notices for the section 13K administrative breaches such as holding a non-compliant privacy policy (200 penalty units, AUD 72,800 since 1 July 2026, for a listed corporation, materially less for everyone else), accept enforceable undertakings, and seek injunctions. The OAIC can also conduct proactive compliance sweeps, as demonstrated by its January 2026 review of approximately 60 entities.
Does Australia have state-level privacy laws?
Yes. New South Wales (Privacy and Personal Information Protection Act 1998), Victoria (Privacy and Data Protection Act 2014), Queensland (Information Privacy Act 2009), the ACT (Information Privacy Act 2014), and Tasmania (Personal Information Protection Act 2004) all have state-level privacy legislation. These laws primarily apply to their respective state and territory government agencies. Western Australia's Privacy and Responsible Information Sharing Act 2024 commenced on 1 July 2026, covering WA public sector entities, with serious data breach reporting obligations from 1 January 2027. South Australia is now the only jurisdiction with no privacy statute; it relies on administrative Information Privacy Principles for state agencies. Private sector entities may face dual federal and state obligations if they handle health information in states with state-level health privacy regimes that operate alongside the federal Privacy Act.
What is the Consumer Data Right and how does it relate to privacy?
The Consumer Data Right (CDR) gives Australians the ability to direct businesses to share their data with accredited third parties. It is active in banking and energy, and non-bank lenders started sharing product data on 13 July 2026, with consumer data sharing phased in from 9 November 2026. The OAIC regulates the privacy and confidentiality aspects of the CDR framework, including handling complaints and eligible data breach notifications under CDR rules. The CDR operates alongside the Privacy Act rather than replacing it, and CDR-related personal information handling must also comply with the APPs.
What does the automated decision-making reform require?
From December 2026, APP entities that use computer programs to make decisions using personal information that could reasonably be expected to significantly affect an individual's rights or interests must include new disclosures in their privacy policies. The policy must describe the kinds of personal information used in automated decision-making and the types of decisions made. This requirement was introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth) and is designed to address concerns about algorithmic transparency in areas such as credit decisions, insurance assessments, and employment screening.
Updates
Third-round corrections: penalty-unit amounts restated at the AUD 364 unit in force since 1 July 2026 (200 units = AUD 72,800), the infringement-notice working shown, and the APP 8.3 prescribed-country pathway added to the transfer FAQ.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Expanded to cover statutory tort commencement (10 June 2025), Meta $50M Cambridge Analytica settlement, AML/CTF tranche 2 expansion (1 July 2026), tranche 2 reform status update, individual rights section, and business compliance section. Word count increased from 3,250 to approximately 6,200 words.
Reviewed and approved by an editor
Initial publication covering Privacy Act 1988, 13 APPs, OAIC, NDB scheme, 2024 reform Act, enforcement, cross-border disclosure, and state regimes.
Sources and References
- Privacy Act 1988 (Cth) — Federal Register of Legislation(legislation.gov.au).gov
- Privacy and Other Legislation Amendment Act 2024 (Cth) No. 128(legislation.gov.au).gov
- Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022(legislation.gov.au).gov
- My Health Records Act 2012 (Cth), in-force text - Federal Register of Legislation(legislation.gov.au).gov
- Australian Privacy Principles — OAIC(oaic.gov.au).gov
- Australian Privacy Principles Guidelines — OAIC(oaic.gov.au).gov
- About the Notifiable Data Breaches Scheme — OAIC(oaic.gov.au).gov
- Data breach notifications increase to all-time high in 2025, new NDB stats show - OAIC (6 July 2026)(oaic.gov.au).gov
- Statutory Tort for Serious Invasions of Privacy — OAIC(oaic.gov.au).gov
- Privacy Act 1988 (Cth) Schedule 2, Statutory Tort for Serious Invasions of Privacy - Federal Register of Legislation(legislation.gov.au).gov
- OAIC Regulatory Priorities 2025-26(oaic.gov.au).gov
- Privacy Compliance Sweep — OAIC(oaic.gov.au).gov
- Australian Clinical Labs Ordered to Pay Penalties — OAIC(oaic.gov.au).gov
- Landmark Settlement $50M from Meta — OAIC(oaic.gov.au).gov
- Civil Penalty Action Against Optus — OAIC(oaic.gov.au).gov
- Civil Penalty Action Against Medibank — OAIC(oaic.gov.au).gov
- Clearview AI Breached Australians Privacy — OAIC(oaic.gov.au).gov
- APP 8 Cross-Border Disclosure — OAIC(oaic.gov.au).gov
- State and Territory Privacy Legislation — OAIC(oaic.gov.au).gov
- Privacy Guidance for AML/CTF Reporting Entities — OAIC(oaic.gov.au).gov
- Privacy Act Review Report — Attorney-General Department(ag.gov.au).gov
- Government Response to Privacy Act Review Report — Attorney-General Department(ag.gov.au).gov
- Privacy — Attorney-General Department(ag.gov.au).gov
- Consumer Data Right — Australian Government(cdr.gov.au).gov