Privacy & data protection in Northern Territory
Privacy Act 1988 obligations including APPs, NDB scheme, the 2024 amendments (statutory tort, enhanced penalties, doxxing offence), the 10 December 2026 commencements (ADM transparency, Children's Online Privacy Code), and the proposed removal of the small-business exemption (a future reform tranche, not yet law).
0
NT-specific obligations
24
Federal obligations
Federal
Notifiable Data Breach (NDB) scheme
Under the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
Automated Decision-Making transparency under Privacy Act (phased)
From a phased commencement, APP entities using ADM must disclose in Privacy Policy.
APP 3 collection of sensitive information
APP 3 bars collecting sensitive information — health, race, religion, sexual orientation and more — without consent. What counts as sensitive, the exceptions and penalties.
Comply with the Spam Act 2003 (consent, identify, unsubscribe)
All commercial electronic messages must have consent, identify the sender, and offer a working unsubscribe.
Provide an APP 5 collection notice at or before collection
APP 5 requires notice of identity, purposes, recipients, consequences of not providing info, and where Privacy Policy lives.
APP 8 cross-border disclosure
Before disclosing personal information overseas, APP 8 requires reasonable steps so the recipient meets the APPs — unless an exception applies. Steps and exceptions.
APP 12 & APP 13 access and correction requests
Individuals can ask to access (APP 12) and correct (APP 13) the personal information you hold — the strict response times, allowable refusals and how to comply.
Comply with credit reporting obligations (Part IIIA Privacy Act)
Credit providers and CRBs must adhere to the CR Code on collection, use, disclosure, hardship and dispute resolution.
Consumer Data Right (CDR) participant accreditation + compliance
Banking, energy and (soon) non-bank lending data sharing — accredited participants must comply with privacy safeguards.
Lodge Payment Times Reports (large business)
Large businesses (>$100M revenue) must report payment times to small business suppliers every 6 months.
Comply with doxxing criminal offence (Criminal Code s 474.17C)
From 11 December 2024, using a carriage service to dox personal data with menace is criminal.
Simplified Debt Restructuring (small business)
Small companies (<$1M liabilities) can use SDR to restructure without full external admin.
Pre-2025 ban on unsolicited credit limit increase invitations
Credit card limit increase offers cannot be sent without prior written consent.
APP 7 direct marketing
APP 7 restricts using or disclosing personal information for direct marketing and requires a simple opt-out — when it applies, the exceptions and penalties.
Prepare for the proposed removal of the small business exemption
Removing the Privacy Act small business exemption (<$3M turnover) is proposed for a future reform tranche — agreed in principle, not yet law.
Privacy Act Reform — information controllers regime (proposed Tranche 2)
Tranche 2 reforms in scoping — information controllers + processors regime.
Publish a Privacy Policy compliant with APP 1
Every APP entity needs a clearly-expressed Privacy Policy covering APP 1.4 requirements.
Automated Decision-Making transparency (Privacy Act 2024 reforms)
APP entities making decisions about individuals using ADM must disclose this in privacy policy from December 2026.
Privacy statutory tort (serious invasions of privacy)
From June 2025 — serious invasion of privacy actionable in tort.
Children's Online Privacy Code 2026
OAIC developing mandatory children's online privacy code (in force December 2026).
CDR Energy sector — phased
Energy retailers + distributors must share data via CDR.
APP 2 — anonymity + pseudonymity for individuals
Where reasonable, individuals must be able to deal with you anonymously or under a pseudonym.
Data Availability and Transparency Act 2022
Commonwealth data sharing regime — accredited users + entities.
Instant Asset Write-Off (annually re-set threshold)
SBE asset write-off threshold reset annually; $20,000 for FY25-26.