Asia-Pacific Australia

Australia Privacy Act Reform: What Has Changed and What's Next

Australia's Privacy Act 1988 overhaul: AUD 50M penalties, the 2024 amendment act, the statutory privacy tort, doxxing offences, and the tranche-two agenda.

Regulation

Privacy Act 1988 (Cth); Privacy and Other Legislation Amendment Act 2024

Max Penalty

Greater of AUD 50 million, 3x the benefit obtained, or 30% of adjusted turnover in the breach period

Enforcing Authority

Office of the Australian Information Commissioner (OAIC)

Official Source

www.oaic.gov.au

Executive Summary

  • The Privacy Act 1988 and its 13 Australian Privacy Principles govern federal agencies and businesses with annual turnover above AUD 3 million (plus health providers and data traders below it).
  • After the 2022 Optus and Medibank breaches, maximum penalties jumped from AUD 2.22 million to the greater of AUD 50 million, 3x benefit, or 30% of adjusted turnover.
  • The Privacy and Other Legislation Amendment Act 2024 (assented 10 December 2024) added a statutory tort for serious invasions of privacy (available from June 2025), criminal doxxing offences, tiered civil penalties, and automated-decision transparency duties.
  • A Children's Online Privacy Code must be in place by December 2026, and 'tranche two' reforms (fair-and-reasonable test, small-business exemption removal, direct right of action) remain on the government's agenda.
  • The OAIC has moved to litigation-first enforcement, with Federal Court proceedings against Medibank and civil penalty action over the Optus breach.

Australian privacy law changed character in two years. Until 2022 the Privacy Act 1988 was enforced gently against a AUD 2.22 million ceiling; then Optus (September 2022, ~9.8 million people) and Medibank (October 2022, ~9.7 million people) put a third of the country’s population into breach notifications within weeks, and parliament responded with penalties among the world’s highest and the first structural rewrite since the APPs. The 2024 amendment act is instalment one; the more radical proposals are queued behind it.

RegulationPrivacy Act 1988 (Cth) + 2022/2024 amendments
Max penaltyGreater of AUD 50M / 3x benefit / 30% adjusted turnover
Enforcing authorityOAIC
Official textPrivacy Act 1988, Federal Register of Legislation

The current rulebook

The 13 Australian Privacy Principles remain the operative duties: open and transparent management (APP 1), collection limits and notice (APPs 3-5), use and disclosure boundaries (APP 6), direct marketing controls (APP 7), cross-border disclosure accountability (APP 8, which keeps the discloser liable for the overseas recipient’s breaches, Australia’s distinctive transfer model), quality, security and destruction (APP 11), and access and correction (APPs 12-13). The Notifiable Data Breaches scheme adds the incident layer, and the Consumer Data Right runs a parallel portability regime.

What the 2024 act changed

Beyond the tort, doxxing offences (up to 6-7 years imprisonment for malicious release of personal data), penalty tiers, and ADM transparency, the act empowered the OAIC to develop codes, required a Children’s Online Privacy Code by 10 December 2026 (applying to services likely accessed by children), clarified that reasonable security under APP 11 includes technical and organizational measures, and enabled emergency information-sharing declarations after eligible data breaches.

Enforcement posture

The OAIC now litigates: Federal Court civil penalty proceedings against Medibank (filed 2024) allege APP 11 failures across the breach window, with theoretical exposure in the trillions given per-individual contraventions; Optus faces parallel action. Determinations against smaller respondents continue, and the regulator publishes NDB statistics twice yearly, consistently showing health, finance, and government as the most-breached sectors. For boards, the combination of the tort (June 2025), class-action-friendly damages, and turnover-scaled penalties moves Australian privacy risk into the top tier of the region. Baseline your Australian-facing collection with a free scan.

Frequently Asked Questions

Who is covered by the Privacy Act today?

Australian government agencies and 'APP entities': organizations with annual turnover over AUD 3 million, plus smaller businesses that trade in personal information, provide health services, or opt in. The small-business exemption survived the 2024 round but is slated for reconsideration in tranche two, so sub-threshold businesses should not assume permanence.

What does the new privacy tort allow?

From 10 June 2025, individuals can sue for serious invasions of privacy, intrusion upon seclusion or misuse of private information, where they had a reasonable expectation of privacy and the invasion was intentional or reckless. Remedies include damages up to the defamation cap; no proof of actual damage is required. It is Australia's first general privacy cause of action.

How do the new penalty tiers work?

The 2024 act kept the top tier (AUD 50M / 3x benefit / 30% turnover for serious interferences) and added a mid tier (civil penalties up to AUD 3.3 million for interferences without the 'serious' element) and an administrative tier (infringement notices for procedural breaches like defective privacy policies), giving the OAIC graduated tools it previously lacked.

What are the automated-decision transparency duties?

Privacy policies must disclose kinds of personal information used in, and kinds of decisions made by, computer programs that significantly affect individuals' rights or interests. Entities have a 24-month runway (to December 2026) to comply, in effect an inventory-and-disclose mandate for consequential ADM.

What is still coming in tranche two?

The government agreed or agreed in principle to most of the 2023 Privacy Act Review proposals not yet legislated: a 'fair and reasonable' test for processing, removal of the small-business and possibly employee-records exemptions, a direct right of action under the act, stricter consent definitions, and data-minimization duties. Timing depends on the parliamentary cycle; the direction is set.

Regulatory Crosswalk

GDPRAustralian Privacy Principles

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.