OAIC
Office of the Australian Information Commissioner
Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.
18
Obligations enforced
23
Enforcement actions tracked
7
Scope topics
Obligations enforced by OAIC (18)
- criticalCWLTHAutomated decision-making transparency in your privacy policy (APP 1.7–1.9)
From 10 December 2026, APP entities that use computer programs to make or substantially assist decisions that significantly affect individuals must say so in their APP privacy policy.
- criticalCWLTHNotifiable Data Breach (NDB) scheme
Under the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
- criticalCWLTHAPP 3 collection of sensitive information
APP 3 bars collecting sensitive information — health, race, religion, sexual orientation and more — without consent. What counts as sensitive, the exceptions and penalties.
- criticalCWLTHMajor banks must provide CDR Banking + Action Initiation (2026)
CDR Action Initiation lets accredited recipients initiate payments + actions on consumer behalf.
- highCWLTHPublish a Privacy Policy that meets APP 1
Every APP entity needs a clearly-expressed Privacy Policy covering APP 1.4 requirements.
- highCWLTHAPP 12 & APP 13 access and correction requests
Individuals can ask to access (APP 12) and correct (APP 13) the personal information you hold — the strict response times, allowable refusals and how to comply.
- highCWLTHConsumer Data Right (CDR) participant accreditation + compliance
Banking, energy and (soon) non-bank lending data sharing — accredited participants must comply with privacy safeguards.
- highCWLTHProvide an APP 5 collection notice at or before collection
APP 5 requires notice of identity, purposes, recipients, consequences of not providing info, and where Privacy Policy lives.
- highCWLTHComply with CDR Banking (Open Banking) — major + non-major ADIs
Banking data holders must share consumer data with accredited recipients on consumer consent.
- highCWLTHAPP 7 direct marketing: consent, opt-out & when you can't message (2026)
APP 7 restricts using or disclosing personal information for direct marketing and requires a simple opt-out — when it applies, the exceptions and penalties.
- highCWLTHCDR Energy sector — phased
Energy retailers + distributors must share data via CDR.
- highCWLTHChildren's Online Privacy Code 2026
OAIC developing a mandatory children's online privacy code — must be registered by 10 December 2026 (commencement not yet fixed).
- highCWLTHPrivacy Act Reform — information controllers regime (proposed Tranche 2)
Tranche 2 reforms in scoping — information controllers + processors regime.
- highCWLTHRespond to FOI requests within 30 days (Cwlth agencies + ministers)
FOI Act 1982 — Commonwealth agencies + ministers must respond to access requests within 30 days.
- highCWLTHPrepare for the proposed removal of the small business exemption
Removing the Privacy Act small business exemption (<$3M turnover) is proposed for a future reform tranche — agreed in principle, not yet law.
- highCWLTHComply with credit reporting obligations (Part IIIA Privacy Act)
Credit providers and CRBs must adhere to the CR Code on collection, use, disclosure, hardship and dispute resolution.
- highCWLTHAPP 8 cross-border disclosure
Before disclosing personal information overseas, APP 8 requires reasonable steps so the recipient meets the APPs — unless an exception applies. Steps and exceptions.
- mediumCWLTHAPP 2 — anonymity + pseudonymity for individuals
Where reasonable, individuals must be able to deal with you anonymously or under a pseudonym.
Recent OAIC enforcement
- determination2026Australian Privacy Commissioner orders American Express Australia Limited to compensate complainant following interference in privacy
Australian Privacy Commissioner orders American Express Australia Limited to compensate complainant following interference in privacy
- determination2026Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026)
Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026). Finding: breach of APP 3.3; 5.1; 5.2 and 7.1. Remedies: Must not repeat or continue acts and practices found to be an interference with individuals’ privacy — Specified steps to address interference.
- determination2026Commissioner Initiated Investigation into Medmate Australia Pty Ltd (Privacy) [2026] AICmr 41 (11 June 2026)
Commissioner Initiated Investigation into Medmate Australia Pty Ltd (Privacy) [2026] AICmr 41 (11 June 2026). Finding: breach. OAIC's listing gives the legislative provision as APP 11.1, while its catchword summary for the entry lists APP 3.3, 5.1, 5.2 and 7.1 (collection of sensitive information via third-party tracking pixels). Remedies: Must not repeat or continue acts and practices found to be an interference with individuals' privacy — Specified steps to address interference.
- determination2026Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026)
Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026). Finding: breach of APP 3.2; 3.5. Remedies: Must not repeat or continue acts and practices found to be an interference with individuals’ privacy — Specified steps to address interference.
- determination2026Commissioner Initiated Investigation into Singtel Optus Pty Ltd (Privacy) [2026] AICmr 22 (20 March 2026)
Commissioner Initiated Investigation into Singtel Optus Pty Ltd (Privacy) [2026] AICmr 22 (20 March 2026). Finding: breach of APP 11.1.
- determination2025Commissioner Initiated Investigation into Vinomofo Pty Ltd (Privacy) [2025] AICmr 175 (17 October 2025)
Commissioner Initiated Investigation into Vinomofo Pty Ltd (Privacy) [2025] AICmr 175 (17 October 2025). Finding: breach of APP 11. Remedies: Must not repeat or continue acts and practices found to be an interference with individuals’ privacy — Specified steps to address interference.
- civil penalty$5.8M2025Australian Information Commissioner v Australian Clinical Labs Limited (No 2)
A Feb 2022 cyberattack on ACL's Medlab Pathology systems led to data on over 223,000 people being exfiltrated. ACL failed to take reasonable security steps, did not assess the suspected eligible data breach quickly enough and was slow to notify the Commissioner. First civil penalties ordered under the Privacy Act; ACL admitted liability and penalty was jointly proposed.
- civil penalty2025OAIC investigation — Optus 2022 data breach
September 2022 Optus breach exposed ~10M customer records. OAIC alleges APP 11 failures + delayed notification.
- investigation2024OAIC enforcement — multiple SMB breach investigations 2024
OAIC investigated multiple SMB-scale breaches in 2024 — including in legal, retail, healthcare. Most resolved without penalty but documented APP 11 reasonable-steps + NDB notification expectations.
- determination2024OAIC + AFP Medibank determination 2024-2025
Class action + OAIC determination on Medibank Oct 2022 data breach affecting ~9.7M customers + their families.
- class action2024Optus class action — 2022 data breach
Class action by ~9.8M Optus customers affected by September 2022 data breach.
- determination2024OAIC determination — Bunnings facial recognition + biometric
Bunnings operated facial recognition in stores for loss prevention without proper notice + consent for sensitive (biometric) information.
- determination2024OAIC determinations on Bunnings and Kmart facial recognition
Both retailers operated in-store facial recognition systems for loss-prevention. OAIC found inadequate notification and unjustified breach of APP 3.3 (sensitive information).
- determination2024OAIC determination — Kmart facial recognition
Kmart operated facial recognition for loss prevention; same proceedings as Bunnings determination 2024.
- civil penalty2024OAIC investigation into Australian Clinical Labs (Medlab)
Following the February 2022 Medlab Pathology breach, OAIC alleges ACL failed to take reasonable steps to protect personal information and failed to properly notify the breach.
- investigation2024OAIC investigation — Latitude Financial 2023 breach
March 2023 Latitude breach exposed personal info of ~14M customers including 7.9M driver licences.
- follow up2024OAIC follow-up enforcement — Clearview AI compliance
Follow-up compliance from 2021 determination + ongoing biometric processing detected.
- civil penalty2024OAIC v Medibank Private Limited
The October 2022 Medibank breach exposed personal information of approximately 9.7 million current and former customers. OAIC alleges Medibank failed to take reasonable steps to protect personal information.
- determination2023OAIC determination — Health Engine
Health Engine forwarded patient data to insurance brokers without proper consent.
- determination2021Commissioner-initiated investigation into Clearview AI Inc
Clearview AI scraped publicly available images from the web and used them to build a facial-recognition tool that was offered to Australian police agencies.
- determination2021Commissioner-initiated investigation into 7-Eleven Stores Pty Ltd
7-Eleven collected facial images and faceprints from customers via in-store tablets as part of a customer feedback program. Consent processes were inadequate.
- determination2021Commissioner v Uber Technologies (cross-border breach)
Uber failed to protect personal information of 1.2M Australian customers/drivers in the 2016 breach, and concealed the breach for over a year by paying the attacker as a 'bug bounty'.
- ndb notification2018PageUp NDB incident (illustrative)
PageUp HR software experienced a security incident potentially exposing recruitment data of major Australian employers (CBA, Telstra, Coles, NAB). Quick public notification.
Scope topics
Parent legislation
Source: regulator's own website. Rules Mate links and summarises — we don't republish full statutory text.