Privacy Act (AU)
Privacy Act 1988 (Australia)
Australia's privacy law, built on the thirteen Australian Privacy Principles, now in a period of reform.
The law in brief
Australia's Privacy Act 1988 regulates how the federal government and many private organizations handle personal information, through thirteen Australian Privacy Principles (APPs). It includes a mandatory Notifiable Data Breaches scheme, and it is in the middle of a major reform program.
The first tranche of reforms, passed in late 2024, raised penalties and gave the regulator more tools, created a statutory tort for serious invasions of privacy from 10 June 2025, and added automated decision-making transparency from 10 December 2026. A second tranche is now out for consultation.
Who it applies to
- APP entities: Australian Government agencies and organizations with annual turnover above AU$3 million.
- Some smaller businesses regardless of turnover, including health service providers, businesses that trade in personal information, and contracted service providers to the Commonwealth.
- Organizations outside Australia with an Australian link, such as carrying on business in Australia.
- Employee records held by a private employer are largely exempt, as are small businesses not otherwise caught.
What it requires
An open and transparent privacy policy
Manage personal information openly, with practices and systems to comply with the APPs and a clearly expressed, up-to-date privacy policy.
Collection and notice
Collect only personal information reasonably necessary for your functions, by lawful and fair means, and notify individuals of the matters APP 5 lists. Sensitive information needs consent unless an exception applies.
Use, disclosure and overseas disclosure
Use or disclose personal information only for the primary purpose of collection or a permitted secondary purpose, and take reasonable steps so overseas recipients do not breach the APPs.
Security and destruction
Take reasonable technical and organizational steps to protect personal information, and destroy or de-identify it when no longer needed.
Notifiable data breaches
Assess a suspected eligible data breach within 30 days, and notify the OAIC and affected individuals as soon as practicable where serious harm is likely.
People's rights
Individuals can access and correct their personal information (APPs 12 and 13), deal anonymously or pseudonymously where practicable, opt out of direct marketing, complain to the Office of the Australian Information Commissioner, and sue for serious invasions of privacy under the statutory tort.
Enforcement and penalties
For serious interferences with privacy, civil penalties of up to the greater of AU$50 million, three times the benefit obtained, or 30% of adjusted turnover for the relevant period. Since the 2024 reforms, lower tiers and infringement notices also apply, including for failures in privacy policies. The OAIC enforces.
What's changing
Reform in progress. Privacy policies must disclose automated decisions that could significantly affect individuals from 10 December 2026, and a Children's Online Privacy Code is due by the same date. On 31 August 2026 the government released an exposure draft of a second-tranche bill for consultation; it is proposed, not law. Regulatory Watch reports its progress.
What to do first
- Confirm you are an APP entity, including under the exceptions to the small business exemption.
- Update your APP 1 privacy policy, including automated decision disclosures before 10 December 2026.
- Run a data breach response plan that assesses suspected breaches within 30 days.
- Review overseas disclosures under APP 8 and the contracts behind them.
- Check direct marketing against APP 7 and the Spam Act.
- Follow the second-tranche consultation; the small business exemption may change.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.
Sources
- Privacy Act 1988 (Cth) Federal Register of Legislation · Official text or regulator