Who must comply with Privacy statutory tort (serious invasions of privacy)?
The applicability test for Privacy statutory tort (serious invasions of privacy), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Every business
Applies when the business has personal information.
What the obligation is
From June 2025 — serious invasion of privacy actionable in tort.
Privacy and Other Legislation Amendment Act 2024 introduced statutory tort for serious invasions of privacy from 10 June 2025. Defences include defamation, statutory authority, public interest. Federal Court + state courts hear.
The applicability test
Applies when the business has personal information.
How the regulator frames it: All individuals + entities. Not limited to APP entities.
What triggers it: Alleged serious invasion of privacy (intrusion or misuse of info).
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: yes).
The answer is the same in every industry: yes. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "yes".
Size does not change the answer across all industries: at every size band the answer is "yes".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: applies. Holds personal information — the statutory privacy tort applies to everyone, not only APP entities.
What you must do, and when
- When due
- 1-year limitation period (extensions possible).
- Frequency
- When a triggering event occurs
- Evidence to keep
- Plaintiff: evidence of seriousness + harm + defendant's conduct.
- In force from
- 10 June 2025
- Status
- Current
- Priority
- High
Penalty for not complying
No maximum penalty is recorded for this obligation in the Rules Mate corpus; check the regulator source below.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Where it sits in the corpus
Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated high priority, and is triggered by events.
Regulator, legislation and tools
Privacy Act 1988: Federal privacy Act.
Free tools that help with this obligation:
Questions
- Who must comply with Privacy statutory tort (serious invasions of privacy)?
- Applies when the business has personal information.
- Does Privacy statutory tort (serious invasions of privacy) apply to sole traders?
- Yes. Across every industry and every size band, the engine's answer for a sole trader is: yes.
- Does Privacy statutory tort (serious invasions of privacy) apply to businesses with 1–5 employees?
- Yes (1–5 employees, turnover $100K–$1M).
- When is "Privacy statutory tort (serious invasions of privacy)" due?
- 1-year limitation period (extensions possible).
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.