Who is covered, and what do the 13 APPs require?
Coverage: Australian Government agencies and 'APP entities' in the private sector, organizations with annual turnover above AUD $3 million, plus, regardless of size, private health service providers, businesses that buy or sell personal information, credit reporting bodies, and a few other categories; the small-business exemption below that threshold is an internationally criticized gap slated for tranche-two reform, as is the employee-records exemption that removes most private-sector HR data from the Act. Extraterritorially, the Act reaches foreign organizations carrying on business in Australia, with the old requirement that they also collect or hold information in Australia removed in 2022, capturing offshore platforms serving Australians. The 13 APPs, grouped functionally: APP 1 (open and transparent management: a clearly expressed, up-to-date privacy policy and practices behind it) and APP 2 (anonymity and pseudonymity options where practicable); collection, APP 3 (collect solicited personal information only where reasonably necessary for functions, sensitive information only with consent absent exceptions, by lawful and fair means), APP 4 (unsolicited information handling), APP 5 (notification of collection: purposes, disclosures, overseas recipients); handling, APP 6 (use and disclosure only for the primary purpose or reasonably expected related secondary purposes, with consent or exceptions otherwise), APP 7 (direct marketing restrictions with opt-outs), APP 8 (cross-border disclosure accountability), APP 9 (government identifiers); quality and security, APP 10 (accuracy), APP 11 (reasonable steps to secure, and to destroy or de-identify when no longer needed, the principle at the center of every major enforcement action); access and correction, APPs 12-13 (individual access within 30 days and correction rights). 'Reasonable steps' is the Act's recurring standard, calibrated by the OAIC's guidance and the enforcement record to the entity's size, sensitivity of holdings, and threat environment.
How does the Notifiable Data Breaches scheme work?
Since February 2018, an 'eligible data breach' triggers mandatory notification: unauthorized access to, disclosure of, or loss of personal information that a reasonable person would conclude is likely to result in serious harm to any affected individual, with 'serious harm' spanning identity theft, financial loss, physical or psychological harm, and serious reputational damage, judged with regard to sensitivity, protections (encryption), and who may have obtained the data. Mechanics: on suspecting an eligible breach, the entity has 30 days to conduct a reasonable and expeditious assessment; on forming the likely-serious-harm view, notify the OAIC (a prescribed statement) and affected individuals as soon as practicable, individually where practicable, otherwise by publishing the statement and publicizing it, with the notification covering the breach's nature, the information involved, and recommended steps. A remedial-action exception applies where prompt action prevents likely serious harm (the strongest argument for rehearsed response); law-enforcement and secrecy carve-outs are narrow. Failing to notify is itself an interference with privacy attracting the penalty regime, and the 2024 reforms added infringement notices for non-compliant statements. Practice notes from OAIC NDB reports (published every six months, consistently 500+ notifications per period, roughly two-thirds from malicious or criminal attacks, with health and finance the leading sectors): the 30-day assessment is a maximum, not an entitlement, the OAIC expects faster movement where harm is apparent; multi-party breaches (processor incidents) require sorting notification responsibility by contract in advance; and the OAIC cross-references NDB statements against later complaints, so understating a breach in the statement compounds exposure. Sector overlays stack: APRA-regulated entities report under CPS 234, critical infrastructure under the SOCI Act, and the consumer data right under its own rules.
What happened with penalties and enforcement after Optus and Medibank?
The September-October 2022 breaches at Optus (~9.8 million individuals' identity data) and Medibank (~9.7 million individuals' health-linked data, published on the dark web after a ransom refusal) transformed Australian privacy politics. Legislative response within weeks: the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 raised the civil penalty for serious interferences with privacy from AUD $2.22 million to the greater of AUD $50 million, three times the value of the benefit obtained, or 30% of adjusted turnover during the breach period, alongside expanded OAIC information-gathering and the extraterritorial fix. Enforcement response: the OAIC sued Medibank in the Federal Court (2024, alleging APP 11.1 security failures across the affected population, with theoretical per-person penalty stacking making headlines); the Australian Clinical Labs proceedings (filed 2023 over the Medlab breach) produced a landmark outcome in 2025, a court-ordered AUD $5.8 million penalty, the first civil penalty under the Act's security provisions; and the OAIC's determinations stream (Bunnings' facial recognition found to breach the Act in 2024; the AUD $50 million Meta/Cambridge Analytica settlement via enforceable undertaking in 2025, Australia's largest privacy payment) signaled a regulator moving from guidance-first to litigation-ready. The 2024 reform act completed the toolkit with tiers: the AUD $50 million-scale top tier for serious interferences, a mid-tier civil penalty (up to AUD $3.3 million) for interferences without the 'serious' element, and infringement notices (around AUD $66,000 for bodies corporate) for administrative breaches like privacy-policy deficiencies, removing the old all-or-nothing enforcement gap that had protected everyday non-compliance.
What did the 2024 reforms (tranche one) actually change, and what is still coming?
The Privacy and Other Legislation Amendment Act 2024 (assented December 10, 2024) enacted the first tranche of the multi-year reform program that followed the Attorney-General's Privacy Act Review. In force or dated: the statutory tort, from June 10, 2025, individuals can sue for serious invasions of privacy (intrusion upon seclusion or misuse of private information) where privacy was reasonably expected, the invasion was intentional or reckless, and seriousness is met, with a public-interest balancing stage, defenses, and remedies including damages up to the defamation cap, Australia's first general private right of action for privacy; criminal doxxing offenses in the Criminal Code (up to six and seven years for menacing or harassing release of personal data, higher where targeting protected attributes); OAIC powers, the tiered penalties and infringement notices above, plus a Federal Court power to order any remedy after a civil-penalty finding; security clarification, APP 11 now expressly includes technical and organizational measures; overseas flows, a mechanism for prescribing countries with substantially similar protection (an adequacy-style whitelist for APP 8.2(a)); a children's online privacy code, to be developed by the OAIC (backed by AUD $3 million in funding, with a statutory deadline in 2026) applying to services likely accessed by children; and automated-decision transparency, privacy policies must disclose kinds of personal information used in, and kinds of decisions made by, computer programs with legal or similarly significant effect, with a 24-month runway to December 10, 2026. Deferred to tranche two (agreed or agreed-in-principle by government but not yet legislated as of early 2026): the 'fair and reasonable' overarching test for collection and use, narrowing or removing the small-business and employee-records exemptions, consent modernization, a direct right of action under the Act itself, and shortened breach timelines, the items that would move Australia decisively toward GDPR-grade architecture.
How should organizations run cross-border disclosures and a reform-proof compliance program?
APP 8 makes Australia's transfer regime accountability-based rather than mechanism-based: before disclosing personal information to an overseas recipient, take reasonable steps to ensure the recipient does not breach the APPs, and, under s 16C, the discloser remains liable for the overseas recipient's acts as if they were its own, unless an exception applies: the recipient is subject to a law or binding scheme substantially similar to the APPs with accessible enforcement (now supplemented by the 2024 prescribed-countries mechanism), or the individual consents after being expressly informed that APP 8.1 protection will not apply (a deliberately unattractive consent), or narrow situational exceptions. Practical machinery: contract clauses obligating APP-consistent handling, vendor due diligence, and a register of overseas disclosure destinations, which APP 5 collection notices and the privacy policy must disclose (countries of likely overseas recipients being expected content). Program design that survives the reform pipeline: build APP 11 security evidence to enforcement grade (the Medibank, ACL, and NDB record says this is where liability concentrates), a tested breach-assessment workflow against the 30-day clock, privacy-policy and collection-notice accuracy (infringement-notice territory now), automated-decision disclosure work scoped before the December 2026 deadline, children's-code readiness for consumer-facing services, and tranche-two positioning, running a 'fair and reasonable' test over collection practices now, and treating employee data as if the exemption were already gone, because both changes are agreed in principle and retrofitting them later costs more than building them in. The statutory tort adds a litigation lens: surveillance-adjacent practices (tracking, monitoring, biometrics) should pass a reasonable-expectation review, since plaintiffs no longer need the OAIC to act.