Privacy & data protection
Privacy Act 1988 obligations including APPs, NDB scheme, the 2024 amendments (statutory tort, enhanced penalties, doxxing offence), the 10 December 2026 milestones (ADM transparency applies; the Children's Online Privacy Code must be registered, commencement not yet fixed), and the proposed removal of the small-business exemption (a future reform tranche, not yet law).
25
Obligations
5
Regulators
20
Recent enforcement
Regulators
Obligations (25)
- criticalCWLTHcurrentAPP 3 collection of sensitive information
APP 3 bars collecting sensitive information — health, race, religion, sexual orientation and more — without consent. What counts as sensitive, the exceptions and penalties.
- criticalCWLTHupcomingAutomated decision-making transparency in your privacy policy (APP 1.7–1.9)
From 10 December 2026, APP entities that use computer programs to make or substantially assist decisions that significantly affect individuals must say so in their APP privacy policy.
- criticalCWLTHcurrentNotifiable Data Breach (NDB) scheme
Under the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
- highCWLTHcurrentAPP 8 cross-border disclosure
Before disclosing personal information overseas, APP 8 requires reasonable steps so the recipient meets the APPs — unless an exception applies. Steps and exceptions.
- highCWLTHcurrentLodge Payment Times Reports (large business)
Large businesses (>$100M revenue) must report payment times to small business suppliers every 6 months.
- highCWLTHcurrentComply with doxxing criminal offence (Criminal Code s 474.17C)
From 11 December 2024, using a carriage service to dox personal data with menace is criminal.
- highCWLTHcurrentPublish a Privacy Policy that meets APP 1
Every APP entity needs a clearly-expressed Privacy Policy covering APP 1.4 requirements.
- highNSWcurrentComply with Workplace Surveillance Act 2005 (NSW)
NSW employers conducting workplace surveillance must give notice + meet specific conditions.
- highACTcurrentComply with Workplace Privacy Act 2011 (ACT)
ACT employers must follow ACT workplace surveillance + privacy framework.
- highCWLTHcurrentAPP 12 & APP 13 access and correction requests
Individuals can ask to access (APP 12) and correct (APP 13) the personal information you hold — the strict response times, allowable refusals and how to comply.
- highCWLTHcurrentConsumer Data Right (CDR) participant accreditation + compliance
Banking, energy and (soon) non-bank lending data sharing — accredited participants must comply with privacy safeguards.
- highCWLTHcurrentSimplified Debt Restructuring (small business)
Small companies (<$1M liabilities) can use SDR to restructure without full external admin.
- highCWLTHcurrentProvide an APP 5 collection notice at or before collection
APP 5 requires notice of identity, purposes, recipients, consequences of not providing info, and where Privacy Policy lives.
- highCWLTHcurrentComply with the Spam Act 2003 (consent, identify, unsubscribe)
All commercial electronic messages must have consent, identify the sender, and offer a working unsubscribe.
- highCWLTHcurrentAPP 7 direct marketing: consent, opt-out & when you can't message (2026)
APP 7 restricts using or disclosing personal information for direct marketing and requires a simple opt-out — when it applies, the exceptions and penalties.
- highCWLTHcurrentCDR Energy sector — phased
Energy retailers + distributors must share data via CDR.
- highCWLTHcurrentPre-2025 ban on unsolicited credit limit increase invitations
Credit card limit increase offers cannot be sent without prior written consent.
- highCWLTHupcomingPrivacy Act Reform — information controllers regime (proposed Tranche 2)
Tranche 2 reforms in scoping — information controllers + processors regime.
- highCWLTHupcomingPrepare for the proposed removal of the small business exemption
Removing the Privacy Act small business exemption (<$3M turnover) is proposed for a future reform tranche — agreed in principle, not yet law.
- highCWLTHcurrentComply with credit reporting obligations (Part IIIA Privacy Act)
Credit providers and CRBs must adhere to the CR Code on collection, use, disclosure, hardship and dispute resolution.
- highCWLTHcurrentPrivacy statutory tort (serious invasions of privacy)
From June 2025 — serious invasion of privacy actionable in tort.
- highCWLTHupcomingChildren's Online Privacy Code 2026
OAIC developing a mandatory children's online privacy code — must be registered by 10 December 2026 (commencement not yet fixed).
- mediumCWLTHcurrentAPP 2 — anonymity + pseudonymity for individuals
Where reasonable, individuals must be able to deal with you anonymously or under a pseudonym.
- mediumCWLTHcurrentInstant Asset Write-Off (annually re-set threshold)
SBE asset write-off threshold reset annually; $20,000 for FY25-26.
- mediumCWLTHcurrentData Availability and Transparency Act 2022
Commonwealth data sharing regime — accredited users + entities.
Recent enforcement
- oaicdetermination2026Australian Privacy Commissioner orders American Express Australia Limited to compensate complainant following interference in privacy
Australian Privacy Commissioner orders American Express Australia Limited to compensate complainant following interference in privacy
- oaicdetermination2026Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026)
Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026). Finding: breach of APP 3.3; 5.1; 5.2 and 7.1. Remedies: Must not repeat or continue acts and practices found to be an interference with individuals’ privacy — Specified steps to address interference.
- oaicdetermination2026Commissioner Initiated Investigation into Medmate Australia Pty Ltd (Privacy) [2026] AICmr 41 (11 June 2026)
Commissioner Initiated Investigation into Medmate Australia Pty Ltd (Privacy) [2026] AICmr 41 (11 June 2026). Finding: breach. OAIC's listing gives the legislative provision as APP 11.1, while its catchword summary for the entry lists APP 3.3, 5.1, 5.2 and 7.1 (collection of sensitive information via third-party tracking pixels). Remedies: Must not repeat or continue acts and practices found to be an interference with individuals' privacy — Specified steps to address interference.
- oaicdetermination2026Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026)
Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026). Finding: breach of APP 3.2; 3.5. Remedies: Must not repeat or continue acts and practices found to be an interference with individuals’ privacy — Specified steps to address interference.
- oaicdetermination2026Commissioner Initiated Investigation into Singtel Optus Pty Ltd (Privacy) [2026] AICmr 22 (20 March 2026)
Commissioner Initiated Investigation into Singtel Optus Pty Ltd (Privacy) [2026] AICmr 22 (20 March 2026). Finding: breach of APP 11.1.
- oaicdetermination2025Commissioner Initiated Investigation into Vinomofo Pty Ltd (Privacy) [2025] AICmr 175 (17 October 2025)
Commissioner Initiated Investigation into Vinomofo Pty Ltd (Privacy) [2025] AICmr 175 (17 October 2025). Finding: breach of APP 11. Remedies: Must not repeat or continue acts and practices found to be an interference with individuals’ privacy — Specified steps to address interference.
- oaiccivil penalty$5.8M2025Australian Information Commissioner v Australian Clinical Labs Limited (No 2)
A Feb 2022 cyberattack on ACL's Medlab Pathology systems led to data on over 223,000 people being exfiltrated. ACL failed to take reasonable security steps, did not assess the suspected eligible data breach quickly enough and was slow to notify the Commissioner. First civil penalties ordered under the Privacy Act; ACL admitted liability and penalty was jointly proposed.
- accccivil penalty2025ACCC CDR enforcement progressing 2024-2025
ACCC + OAIC CDR enforcement progressed in 2024-2025 — first civil penalty proceedings + significant infringement notices.
- oaiccivil penalty2025OAIC investigation — Optus 2022 data breach
September 2022 Optus breach exposed ~10M customer records. OAIC alleges APP 11 failures + delayed notification.
- oaicinvestigation2024OAIC enforcement — multiple SMB breach investigations 2024
OAIC investigated multiple SMB-scale breaches in 2024 — including in legal, retail, healthcare. Most resolved without penalty but documented APP 11 reasonable-steps + NDB notification expectations.
- oaicdetermination2024OAIC + AFP Medibank determination 2024-2025
Class action + OAIC determination on Medibank Oct 2022 data breach affecting ~9.7M customers + their families.
- oaicclass action2024Optus class action — 2022 data breach
Class action by ~9.8M Optus customers affected by September 2022 data breach.
- oaicdetermination2024OAIC determination — Bunnings facial recognition + biometric
Bunnings operated facial recognition in stores for loss prevention without proper notice + consent for sensitive (biometric) information.
- oaicdetermination2024OAIC determinations on Bunnings and Kmart facial recognition
Both retailers operated in-store facial recognition systems for loss-prevention. OAIC found inadequate notification and unjustified breach of APP 3.3 (sensitive information).
- oaicdetermination2024OAIC determination — Kmart facial recognition
Kmart operated facial recognition for loss prevention; same proceedings as Bunnings determination 2024.
- ipc-nswreview2024IPC NSW privacy investigations — government breaches
Multiple NSW government agency privacy reviews including data breaches + PPIPA failures.
- oaiccivil penalty2024OAIC investigation into Australian Clinical Labs (Medlab)
Following the February 2022 Medlab Pathology breach, OAIC alleges ACL failed to take reasonable steps to protect personal information and failed to properly notify the breach.
- acccreview2024ACCC CDR Banking compliance reviews 2024
Periodic ACCC + OAIC compliance reviews of CDR Banking data holders + accredited recipients.
- oaicinvestigation2024OAIC investigation — Latitude Financial 2023 breach
March 2023 Latitude breach exposed personal info of ~14M customers including 7.9M driver licences.
- oaicfollow up2024OAIC follow-up enforcement — Clearview AI compliance
Follow-up compliance from 2021 determination + ongoing biometric processing detected.