Australia
Australia's Privacy Act Reforms 2024-2025: What Changed and What's Still Pending
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 13 primary sources cited on this page. How we verify our legal content

One amending Act, the Privacy and Other Legislation Amendment Act 2024 (Cth), switched on in stages. The bulk of it, Schedule 1 Parts 1 to 14, commenced on 11 December 2024 alongside the new federal doxxing offences, and that package recast the Privacy Act's civil penalties, security and overseas disclosure rules and the regulator's enforcement powers. The civil tort for serious invasions of privacy followed on 10 June 2025, and the automated decision-making transparency rule is still ahead, on 10 December 2026.
This article addresses what the Privacy and Other Legislation Amendment Act 2024 (Cth) changed in the Privacy Act 1988 (Cth) and the Criminal Code, and separately identifies what remains only a proposal, current as at 10 September 2026, as part of recordinglaw.com's Australia data privacy laws hub. It does not address the day-to-day content of the Australian Privacy Principles themselves, covered in recordinglaw.com's Australian Privacy Principles guide, or the doxxing offences' operative wording in detail, which is a criminal law question outside this article's privacy-law scope.
One Amending Act, Multiple Reforms, Different Commencement Dates
The Privacy and Other Legislation Amendment Act 2024 (Cth), registered on the Federal Register of Legislation as C2024A00128, received Royal Assent on 10 December 2024. It is a single Act, but it does not switch on all at once. Different schedules within it commence on different dates set by the Act itself, so a reform introduced by this Act can already be in force while another reform in the very same Act is still months or years away from taking effect. Treating the Act as a single event with one effective date is the most common source of error when describing these reforms, and this article is organised specifically to avoid that.
The Main Privacy Act Package: In Force Since 11 December 2024
The largest part of the Act is the part that got the least attention. Schedule 1 Parts 1 to 14 commenced on 11 December 2024, the day after Royal Assent, and that is the package that changed the Privacy Act 1988 (Cth) itself.
Civil penalties became tiered. Section 13G, the serious interference provision, was recast so that seriousness alone is the test. Repetition is no longer a separate trigger; it is one of the factors a court may weigh under the new section 13G(1B), alongside the kind and sensitivity of the information, the consequences for the individual, how many people were affected, whether a child or a person experiencing vulnerability was involved, and whether the entity failed to put compliance practices in place.
For a body corporate, the section 13G maximum is the greatest of AUD 50 million, three times the benefit obtained from the conduct, or 30% of adjusted turnover during the breach turnover period (section 13G(3)). For a person other than a body corporate it is AUD 2.5 million (section 13G(2)).
Two lower tiers now sit underneath it. Section 13H is contravened by any interference with the privacy of an individual, serious or not. Section 13H(3) sets that penalty at not more than 2,000 penalty units, which is AUD 728,000 for conduct on or after 1 July 2026, when the Commonwealth penalty unit rose to AUD 364.
That figure is not the ceiling for a company. Section 80U(1) makes every civil penalty provision of the Privacy Act enforceable under Part 4 of the Regulatory Powers (Standard Provisions) Act 2014, and section 82(5)(a) of that Act caps a body corporate at five times the amount the civil penalty provision specifies. Section 13G(4) switches that multiplier off for section 13G alone, which is direct proof it applies to the rest. A body corporate therefore faces up to 10,000 penalty units under section 13H, or AUD 3,640,000, against 2,000 units or AUD 728,000 for a person other than a body corporate.
Section 13J lets a court that finds an interference but is not satisfied it was serious make a section 13H penalty order instead of a section 13G one.
Section 13K covers specified breaches: failing to have an APP privacy policy or the required contents in it, denying the option to deal anonymously, failing to give the written notice of certain uses or disclosures required by APP 6.5, the direct marketing opt-out and source-notification requirements, failures in dealing with correction requests under APP 13.5, and a non-compliant eligible data breach statement. Section 13K(1)(b) also lets the regulations prescribe further Australian Privacy Principles, so the list can grow.
Section 13K(4) specifies 200 penalty units. The court maximum is therefore 200 units, AUD 72,800, for a person other than a body corporate, and 1,000 units, AUD 364,000, for a body corporate under the same section 82(5)(a) multiplier. Section 80UC(6) sets the same 200-unit figure for failing to comply with a compliance notice, which is likewise multiplied by five for a body corporate.
A section 13K breach can also be dealt with by an infringement notice (section 80UB) or by a compliance notice requiring the entity to fix the problem (section 80UC), which the entity can ask a court to review. An infringement notice is a separate and much smaller amount than the court maximum: section 80UB(1A) fixes it at 200 penalty units, AUD 72,800, for a single alleged contravention by a listed corporation, and every other entity falls back to the lower default in section 104(2) of the Regulatory Powers Act.
The same package made four further changes that are already binding:
- APP 11.3 now says in terms that the reasonable steps an entity must take to secure personal information include technical and organisational measures.
- APP 8.2(aa) and APP 8.3 add a route for disclosing personal information overseas to a recipient in a prescribed country or a prescribed binding scheme, with the Minister's prerequisites for prescribing one set out in section 100(1A).
- Section 26X lets the Minister make an eligible data breach declaration after a breach, temporarily authorising specified information handling to reduce the risk of harm to the people affected.
- Sections 33E to 33J give the Commissioner public inquiry powers into privacy matters, on the Minister's direction or approval, with the report tabled in Parliament.
None of this is pending. It has been in force since 11 December 2024, which is why describing the 2024 Act as only a doxxing and tort reform understates it substantially.
The Doxxing Offences: In Force Since 11 December 2024
Schedule 3 of the Act inserted two new offences into the Criminal Code Act 1995 (Cth): section 474.17C, a base offence, and section 474.17D, an aggravated offence. Both commenced on 11 December 2024, the day after Royal Assent. In general terms, section 474.17C targets using a carriage service to make available, publish or otherwise distribute another person's personal information in a way that reasonable persons would regard as menacing or harassing, carrying a maximum penalty of 6 years' imprisonment. Section 474.17D is the aggravated version, applying where the conduct was motivated by the victim's or a targeted group's race, religion, sex, sexual orientation, gender identity, intersex status, disability, nationality, or national or ethnic origin, carrying a maximum penalty of 7 years' imprisonment. These are criminal offences prosecuted under the Criminal Code, separate from any civil action or OAIC complaint; the Attorney-General's Department's public consultation on doxxing and privacy reform, which preceded the Act, also notes that the same doxxing conduct can separately amount to a breach of the Australian Privacy Principles where the entity involved is covered by the Privacy Act. Recordinglaw.com's guide to Australia's doxxing laws covers these offences in more depth.

The Statutory Tort for Serious Invasions of Privacy: In Force Since 10 June 2025
Schedule 2 of the same Act inserted a new statutory tort for serious invasions of privacy into the Privacy Act 1988 (Cth), but this schedule commenced separately, six months after Assent, on 10 June 2025. It gives a plaintiff a cause of action against a defendant who has invaded their privacy either by intruding upon their seclusion, for example by physically intruding into a private space, or by misusing information relating to them, in circumstances where the plaintiff would have had a reasonable expectation of privacy. A plaintiff must also show the invasion was serious, that it was intentional or reckless, and that the public interest in protecting their privacy outweighed any countervailing public interest. Defences include consent and lawful authority. Part 3 of Schedule 2 then carves out whole categories of defendant: journalists, their employers and people assisting them, to the extent the invasion involves journalistic material (clause 15); agencies and State and Territory authorities, and their staff members, acting in good faith in performing a function or exercising a power (clauses 16 and 16A); law enforcement bodies (clause 16B); intelligence agencies (clause 17); and any defendant under 18 years of age (clause 18). That last exemption matters here, because this article ties the tort to doxxing and to sharing images without consent, which is conduct minors engage in: the Schedule does not apply at all to an invasion of privacy by a person under 18. Proceedings generally must start within the earlier of 1 year after the plaintiff became aware of the invasion or 3 years after it occurred, or before the plaintiff's 21st birthday if they were under 18 when it happened. Remedies a court can grant include damages, an injunction, an order to apologise, an account of profits, a correction order, an order that material be destroyed or delivered up, and a declaration that the defendant seriously invaded the plaintiff's privacy (clause 12(2)). Damages are limited, though. A court must not award aggravated damages (clause 11(2)), exemplary or punitive damages are available only in exceptional circumstances (clause 11(4)), and the sum of any damages for non-economic loss plus any exemplary or punitive damages must not exceed the greater of AUD 478,550 and the non-economic loss cap that applies in defamation proceedings (clause 11(5)). The OAIC has stated plainly that it does not have a direct role in administering the tort, since it is a court action, not a regulatory complaint. The tort is not merely theoretical: in Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396, the New South Wales District Court granted urgent interlocutory injunctions in October 2025 after a defendant published a plaintiff's private wedding photographs online during an extortion campaign, finding serious questions to be tried under the statutory tort alongside intimidation and defamation claims. That decision is interlocutory relief, not a final judgment on liability or damages, but it shows the tort operating in a real case within months of commencing. Recordinglaw.com's guide to the statutory tort covers its elements in more depth.
What Has Not Changed: the Small Business and Employee Records Exemptions
Two long-standing exemptions in the Privacy Act 1988 (Cth) are frequently discussed as reform candidates, but neither has actually been removed. Section 6D exempts a business with annual turnover of $3,000,000 or less from most Australian Privacy Principle obligations as a "small business operator," subject to specific carve-outs, for example for health service providers. Section 7B(3) exempts a private-sector employer's acts and practices directly related to a current or former employment relationship and to an employee record it holds, covered in more detail in recordinglaw.com's guide to employee records and privacy in Australia. Both exemptions remain in force as at 10 September 2026, and the published tranche 2 draft leaves them alone. The government agreed in principle, in its response to the Privacy Act Review, to reform both. That is a separate thing from what the exposure draft released on 31 August 2026 actually does.
The Consultation Paper published with the draft does not address either exemption, and the word employee does not appear in the draft Bill at all, so section 7B(3) is untouched. The draft reaches section 6D only in Schedule 2 Part 1, at items 2 to 6, which redraft the subsection 6D(4) carve-outs dealing with trading in personal information. The $3,000,000 turnover threshold in subsections 6D(1) and (2) stays as it is. On the government's own published draft, then, the position is firmer than wait and see: neither exemption is proposed for removal in this round.
Automated Decision-Making Transparency: Enacted, Not Yet in Force
The 2024 Act also inserted a new automated decision-making (ADM) transparency obligation into Australian Privacy Principle 1, but gave it its own future commencement date rather than switching it on immediately. From 10 December 2026, an APP entity that has arranged for a computer program to use personal information to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests will need to include specified information in its privacy policy about the kinds of personal information used and the kinds of decisions made this way. This obligation is enacted law, unlike the small business and employee records proposals above, but it is not yet in force. The obligation sits in APP 1.7 to 1.9, inserted by Schedule 1 Part 15 of the 2024 Act, the one Part given a delayed commencement. As at 10 September 2026, the OAIC was still developing guidance on it, having run a public consultation on an issues paper that closed for submissions on 15 June 2026, with guidance expected before the December 2026 commencement date. Do not describe this obligation as currently binding; it becomes binding on 10 December 2026.

The Children's Online Privacy Code: Still Being Developed
The same Act requires the OAIC to develop and register a Children's Online Privacy Code, a mandatory code that will apply to social media services, relevant electronic services and designated internet services (as those terms are defined under the Online Safety Act 2021 (Cth)) that are likely to be accessed by children or primarily concern children's activities, other than health service providers. The Act sets a deadline for this: section 26GC(10) requires the Commissioner to develop and register the Code within 24 months of the 10 December 2024 Royal Assent, and the OAIC states that the final Code must be registered by 10 December 2026. The OAIC released an Exposure Draft and Explanatory Statement for public consultation, which ran from 31 March to 5 June 2026, following earlier phases of engagement with children, parents, civil society, academia and industry through 2025. As at 10 September 2026 the Code has still not been registered: a search of the Federal Register of Legislation returns no Code of that name, and the OAIC is working through the 135 written submissions it received and a regulatory impact analysis. The registration deadline is fixed, but the Code's own commencement date and any transition period are not yet settled. Once registered and in force, a breach of the Code will be treated as an interference with privacy under the Privacy Act, carrying the same regulatory and penalty framework as other privacy breaches. Until it commences, it imposes no obligations.
What's Proposed but Not Law: the Wider Second-Tranche Reform
On 31 August 2026 the Attorney-General's Department released an Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026, together with a Consultation Paper. Submissions close on Friday 18 September 2026.
Treat this strictly as a proposal. It is a draft released for public comment, not a Bill introduced in Parliament, its own commencement table is blank, and the department says the Bill remains subject to further consideration by government. Nothing in it binds anyone today.
The Consultation Paper describes a package of roughly 40 proposals, most of them carried over from the Privacy Act Review. The draft Bill is arranged in six schedules:
- Schedule 1 modernises core definitions, including personal information and reasonably identifiable, sensitive information, de-identified, collects, consent and disclosure.
- Schedule 2 replaces several existing handling obligations with a single fair and reasonable test for the collection, use and disclosure of personal information, tightens consent (including for sensitive information and for trading personal information), reworks the permitted general situations, simplifies notification, and clarifies the direct marketing rules.
- Schedule 3 changes data security and the notifiable data breach scheme.
- Schedule 4 adds a right to request erasure of personal information held by large digital platforms, with an exception where compliance is technically impossible or infeasible.
- Schedule 5 simplifies the research exceptions and supports ethically approved human research.
- Schedule 6 reduces the obligations that fall on processors handling personal information for someone else.
The Consultation Paper also seeks feedback on two measures that are not yet drafted: more efficient administration and enforcement by the OAIC, and privacy issues arising from wearable surveillance technology such as smart glasses and ear buds, and from connected vehicles.
Until a Bill passes Parliament and a commencement date is fixed, anything in this package should be described as a proposal, not as current law.
Quick Timeline
| Date | What happened | Status as at 10 September 2026 |
|---|---|---|
| 10 December 2024 | Privacy and Other Legislation Amendment Act 2024 (Cth) receives Royal Assent | Done |
| 11 December 2024 | Schedule 1 Parts 1 to 14 commence: tiered civil penalties (ss 13G, 13H, 13J, 13K), infringement and compliance notices (ss 80UB, 80UC), APP 11.3, APP 8.2(aa) and 8.3, eligible data breach declarations (s 26X), Commissioner's public inquiry powers (ss 33E to 33J) | In force |
| 11 December 2024 | Doxxing offences (Criminal Code ss 474.17C, 474.17D) commence | In force |
| 10 June 2025 | Statutory tort for serious invasions of privacy commences (Privacy Act sch 2) | In force |
| 7 October 2025 | First published application of the statutory tort, Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396 (interlocutory injunctions) | Decided (interlocutory) |
| 31 March to 5 June 2026 | Public consultation on the Children's Online Privacy Code Exposure Draft | Consultation closed; Code not yet registered |
| Closed 15 June 2026 | OAIC consultation on guidance for the automated decision-making transparency obligation | Guidance in development |
| 31 August 2026 | Attorney-General's Department releases the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 and Consultation Paper | Draft only; submissions close 18 September 2026 |
| 10 December 2026 | Automated decision-making transparency obligation (APP 1.7 to 1.9) commences; deadline for the OAIC to register the Children's Online Privacy Code | Not yet in force |
| No date set | Removal of the small business operator exemption (s 6D) | Exemption still in force; the 31 August 2026 exposure draft does not touch the $3,000,000 threshold |
| No date set | Reform of the employee records exemption (s 7B(3)) | Exemption still in force; the 31 August 2026 exposure draft does not amend s 7B(3) |

This article provides general legal information about reforms to the Privacy Act 1988 (Cth) and related Commonwealth legislation under the Privacy and Other Legislation Amendment Act 2024 (Cth), current as at 10 September 2026. It is not legal advice and does not account for your individual circumstances. For advice about a specific privacy matter, consult a legal practitioner admitted in the relevant Australian state or territory.
Frequently Asked Questions
Did doxxing and the privacy tort become law on the same date?
No. Both came from the same amending Act, but the doxxing offences commenced 11 December 2024, while the statutory tort for serious invasions of privacy commenced separately on 10 June 2025, six months later.
What else changed on 11 December 2024?
Schedule 1 Parts 1 to 14, which is the main Privacy Act package. Civil penalties became tiered: section 13G now turns on seriousness alone, with a maximum for a body corporate of the greatest of AUD 50 million, three times the benefit obtained, or 30% of adjusted turnover, and AUD 2.5 million for a person other than a body corporate. Section 13H covers any interference with privacy, at up to 2,000 penalty units (AUD 728,000) for a person other than a body corporate and 10,000 penalty units (AUD 3,640,000) for a body corporate, because section 82(5)(a) of the Regulatory Powers Act multiplies the specified figure by five and section 13G(4) switches that multiplier off for section 13G alone. Section 13K covers specified breaches such as the APP privacy policy, anonymity, the APP 6.5 written notice, direct marketing and correction request failures, at up to 200 penalty units (AUD 72,800) for a person and 1,000 penalty units (AUD 364,000) for a body corporate, and it is the tier infringement notices and compliance notices attach to. An infringement notice for a single contravention by a listed corporation is fixed separately at 200 penalty units, AUD 72,800, by section 80UB(1A). The same day, APP 11.3 gained the words technical and organisational measures, APP 8.2(aa) and 8.3 added a prescribed-country route for overseas disclosure, section 26X gave the Minister an eligible data breach declaration power, and sections 33E to 33J gave the Commissioner public inquiry powers.
Is the small business exemption gone?
No. The $3,000,000 annual turnover small business operator exemption at section 6D of the Privacy Act 1988 (Cth) remains fully in force. The tranche 2 exposure draft released on 31 August 2026 does not propose to remove it: the draft amends section 6D only at the subsection 6D(4) carve-outs about trading in personal information, and leaves the turnover threshold as it is.
Is the employee records exemption gone?
No. Section 7B(3) remains in force, and the tranche 2 exposure draft released on 31 August 2026 does not amend it. Neither the draft Bill nor the Consultation Paper published with it addresses employee records. The government has agreed in principle to reform the exemption, but nothing in the published draft does so.
Is the automated decision-making transparency rule already in effect?
No. It was enacted by the 2024 Act but only commences on 10 December 2026. Until that date it does not bind an APP entity's privacy policy.
What is the Children's Online Privacy Code and is it in force?
It is a mandatory OAIC code for social media, messaging and similar services likely to be accessed by children. The OAIC must register it by 10 December 2026. As at 10 September 2026 it has not been registered: the exposure draft consultation closed on 5 June 2026, the OAIC is considering submissions, and the Code has no commencement date or transition period yet. Until it is registered and commences it imposes no obligations.
Can the OAIC help me bring a claim under the statutory tort?
No. The OAIC has stated it does not have a direct role in administering the tort, since it is a civil court action rather than a regulatory complaint. Someone considering the tort should seek independent legal advice.
Has the statutory tort actually been used in a real case?
Yes. In Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396, decided 7 October 2025, the NSW District Court granted urgent interlocutory injunctions after private wedding photographs were published online during an extortion campaign. That decision is interlocutory relief, not a final ruling on liability or damages.
What is the maximum penalty for a doxxing offence?
The base offence at Criminal Code section 474.17C carries a maximum penalty of 6 years' imprisonment; the aggravated offence at section 474.17D, where the conduct was motivated by characteristics such as race, religion or sexual orientation, carries a maximum of 7 years.
Is there a further round of Privacy Act reform coming?
A draft exists. On 31 August 2026 the Attorney-General's Department released an Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 with a Consultation Paper, and submissions close on 18 September 2026. It proposes modernised core definitions, a fair and reasonable test for handling personal information, tighter consent and notice rules, changes to data security and notifiable data breaches, a right to erasure on large digital platforms, a research exception and relief for processors. It is a consultation draft, not a Bill before Parliament, it fixes no commencement date, and it does not propose removing the small business or employee records exemptions.
Updates
Corrected the page's account of the Privacy and Other Legislation Amendment Act 2024: alongside the doxxing offences, the whole of Schedule 1 Parts 1 to 14 commenced on 11 December 2024, so the page now covers the tiered civil penalties (sections 13G, 13H and 13K), infringement and compliance notices, APP 11.3, the APP 8.2(aa) and 8.3 overseas disclosure route, eligible data breach declarations and the Commissioner's public inquiry powers; updated the second-tranche section for the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 released on 31 August 2026, with submissions closing 18 September 2026, and stated that the draft leaves the small business and employee records exemptions in place; added the statutory tort's exemption for defendants under 18 and the limits on damages; and refreshed every currency stamp to 10 September 2026. Corrected the civil penalty maximums that apply to a company: section 13H carries up to 2,000 penalty units (AUD 728,000) for a person but 10,000 penalty units (AUD 3,640,000) for a body corporate, and section 13K up to 200 penalty units (AUD 72,800) for a person but 1,000 penalty units (AUD 364,000) for a body corporate, because section 82(5)(a) of the Regulatory Powers Act multiplies the stated figure by five and only section 13G is carved out. The AUD 72,800 infringement notice amount for a listed corporation is now shown separately from the court maximum. Also added APP 6.5 and the regulation-making limb to the section 13K breach list, corrected APP 13.5 from access requests to correction requests, attributed the 10 December 2026 Children's Online Privacy Code deadline to the OAIC alongside the statutory 24-month rule, and removed an unsourced claim that the OAIC was seeking feedback on the Code's commencement date.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Privacy Act 1988
s 6DSmall business and small business operatorsIn force
What is a small business? (1) A business is a small business at a time (the test time) in a financial year (the current year) if its annual turnover for the previous financial year is $3,000,000 or less. Test for new business (2) However, if there was no time in the previous financial year when the business was carried on, the business is a small business at the test time only if its annual turnover for the current year is $3,000,000 or less. What is a small business operator? (3) A small business operator is an individual, body corporate, partnership, unincorporated association or trust that: (a) carries on one or more small businesses; and (b) does not carry on a business that is not a small business.
Official text (excerpt) · last checked 2026-08-14 · Read the full text in our law library · Verify at legislation.gov.au
Cited in 6 court opinions in our collectionLatest citing opinion in our collection: 2023
Opinions citing this section in our collection:
- [2013] NSWCA 473 (NSW Court of Appeal 2013, [2013] NSWCA 473)
- Zhang v Australian Information Commissioner (Federal Court of Australia 2023, [2023] FCA 132)
- Australian Information Commission v Facebook Inc (Federal Court of Australia 2020, [2020] FCA 531)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- OAIC, Statutory tort for serious invasions of privacy(oaic.gov.au).gov
- Privacy and Other Legislation Amendment Act 2024 (Cth) No. 128, 2024, Federal Register of Legislation version history (Royal Assent 10 December 2024)(legislation.gov.au).gov
- Attorney-General's Department, Doxxing and privacy reforms consultation(consultations.ag.gov.au).gov
- Privacy Act 1988 (Cth) ss 6D (small business operator, $3,000,000 annual turnover threshold), 7B(3), 13G, 13H, 13K, 26X, 33E-33J, 80UB, 80UC and Schedule 2, current authorised compilation (Compilation No. 104, compilation date 4 June 2026)(legislation.gov.au).gov
- OAIC, Employee records exemption(oaic.gov.au).gov
- OAIC, Consultation on Guidance for Transparency in Automated Decision Making (ADM obligation commencing 10 December 2026)(oaic.gov.au).gov
- OAIC, Children's Online Privacy Code(oaic.gov.au).gov
- NSW Crown Solicitor's Office, Key legal decision: Australia's first privacy tort judgment (Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396)(cso.nsw.gov.au).gov
- Attorney-General's Department, Privacy Reform: Consultation on Exposure Draft legislation (Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 and Consultation Paper, opened 31 August 2026, submissions close 18 September 2026)(consultations.ag.gov.au).gov
- Privacy and Other Legislation Amendment Act 2024 (Cth) No. 128, 2024, as made, section 2 commencement table (Schedule 1 Parts 1-14 and Schedule 3 commence 11 December 2024, Schedule 2 on 10 June 2025, Schedule 1 Part 15 on 10 December 2026)(legislation.gov.au).gov
- Crimes (Amount of a Penalty Unit) Instrument 2026 (Cth) s 5, penalty unit of $364 from 1 July 2026(legislation.gov.au).gov
- Regulatory Powers (Standard Provisions) Act 2014 (Cth) s 82(5) (a body corporate's pecuniary penalty is 5 times the penalty specified for the civil penalty provision) and s 104(2) (default infringement notice amounts), authorised compilation No. 4, compilation date 20 March 2024(legislation.gov.au).gov
- Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396 (Gibson DCJ, decision date 7 October 2025), NSW Caselaw(caselaw.nsw.gov.au).gov