Privacy statutory tort (serious invasions of privacy)
From June 2025 — serious invasion of privacy actionable in tort.
Who must comply
All individuals + entities. Not limited to APP entities.
What triggers it
Alleged serious invasion of privacy (intrusion or misuse of info).
When due
1-year limitation period (extensions possible).
Evidence required
Plaintiff: evidence of seriousness + harm + defendant's conduct.
Max penalty
—
Effective from
10 June 2025
Who must comply with this? The applicability test by industry, business structure and size.
Summary
Privacy and Other Legislation Amendment Act 2024 introduced statutory tort for serious invasions of privacy from 10 June 2025. Defences include defamation, statutory authority, public interest. Federal Court + state courts hear.
Source legislation
Topics
Related
- CWLTHNotifiable Data Breach (NDB) schemeUnder the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
- CWLTHAPP 3 collection of sensitive informationAPP 3 bars collecting sensitive information — health, race, religion, sexual orientation and more — without consent. What counts as sensitive, the exceptions and penalties.
- CWLTHAutomated decision-making transparency in your privacy policy (APP 1.7–1.9)From 10 December 2026, APP entities that use computer programs to make or substantially assist decisions that significantly affect individuals must say so in their APP privacy policy.
- CWLTHPrepare for the proposed removal of the small business exemptionRemoving the Privacy Act small business exemption (<$3M turnover) is proposed for a future reform tranche — agreed in principle, not yet law.
- CWLTHComply with credit reporting obligations (Part IIIA Privacy Act)Credit providers and CRBs must adhere to the CR Code on collection, use, disclosure, hardship and dispute resolution.
- CWLTHAPP 8 cross-border disclosureBefore disclosing personal information overseas, APP 8 requires reasonable steps so the recipient meets the APPs — unless an exception applies. Steps and exceptions.
Frequently asked questions
- Who must comply with Privacy statutory tort (serious invasions of privacy)?
- All individuals + entities. Not limited to APP entities.
- What triggers Privacy statutory tort (serious invasions of privacy)?
- Alleged serious invasion of privacy (intrusion or misuse of info).
- When is Privacy statutory tort (serious invasions of privacy) due?
- 1-year limitation period (extensions possible).
- What evidence is required for Privacy statutory tort (serious invasions of privacy)?
- Plaintiff: evidence of seriousness + harm + defendant's conduct.
Source: https://www.oaic.gov.au/privacy/privacy-legislation/the-privacy-act. Rules Mate is not a law firm. Always verify against the live regulator source before acting.