Australian privacy law changed character in two years. Until 2022 the Privacy Act 1988 was enforced gently against a AUD 2.22 million ceiling; then Optus (September 2022, ~9.8 million people) and Medibank (October 2022, ~9.7 million people) put a third of the country’s population into breach notifications within weeks, and parliament responded with penalties among the world’s highest and the first structural rewrite since the APPs. The 2024 amendment act is instalment one; the more radical proposals are queued behind it.
| Regulation | Privacy Act 1988 (Cth) + 2022/2024 amendments |
|---|---|
| Max penalty | Greater of AUD 50M / 3x benefit / 30% adjusted turnover |
| Enforcing authority | OAIC |
| Official text | Privacy Act 1988, Federal Register of Legislation |
The current rulebook
The 13 Australian Privacy Principles remain the operative duties: open and transparent management (APP 1), collection limits and notice (APPs 3-5), use and disclosure boundaries (APP 6), direct marketing controls (APP 7), cross-border disclosure accountability (APP 8, which keeps the discloser liable for the overseas recipient’s breaches, Australia’s distinctive transfer model), quality, security and destruction (APP 11), and access and correction (APPs 12-13). The Notifiable Data Breaches scheme adds the incident layer, and the Consumer Data Right runs a parallel portability regime.
What the 2024 act changed
Beyond the tort, doxxing offences (up to 6-7 years imprisonment for malicious release of personal data), penalty tiers, and ADM transparency, the act empowered the OAIC to develop codes, required a Children’s Online Privacy Code by 10 December 2026 (applying to services likely accessed by children), clarified that reasonable security under APP 11 includes technical and organizational measures, and enabled emergency information-sharing declarations after eligible data breaches.
Enforcement posture
The OAIC now litigates: Federal Court civil penalty proceedings against Medibank (filed 2024) allege APP 11 failures across the breach window, with theoretical exposure in the trillions given per-individual contraventions; Optus faces parallel action. Determinations against smaller respondents continue, and the regulator publishes NDB statistics twice yearly, consistently showing health, finance, and government as the most-breached sectors. For boards, the combination of the tort (June 2025), class-action-friendly damages, and turnover-scaled penalties moves Australian privacy risk into the top tier of the region. Baseline your Australian-facing collection with a free scan.