Data & Privacy ยท Australia
Data protection & privacy law in Australia (2026)
Australia shaded by its data & privacy status
Data protection in Australia: comprehensive law.
FrameworkPrivacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth); enforced by the Office of the Australian Information Commissioner (OAIC), with the 13 Australian Privacy Principles (APPs) forming the core obligations.
Australia has a comprehensive federal privacy regime centred on the Privacy Act 1988 and the 13 Australian Privacy Principles, regulated by the OAIC and covering Commonwealth agencies and most private-sector organisations with annual turnover above AU$3 million (plus certain smaller entities such as health providers). The first tranche of the Privacy Act reform package received Royal Assent on 10 December 2024, introducing a statutory tort for serious invasions of privacy (in force from 10 June 2025), stronger OAIC enforcement powers, and a forthcoming Children's Online Privacy Code. A second, more ambitious tranche of reforms (including likely narrowing of the small-business exemption and a 'fair and reasonable' test) remains proposed rather than enacted as of mid-2026.
Key points
The Privacy Act 1988 (Cth) sets 13 Australian Privacy Principles governing collection, use, disclosure, storage, quality, security, access and correction of personal information by APP entities (Commonwealth agencies and most organisations with turnover > AU$3m).
The Office of the Australian Information Commissioner (OAIC) is the independent regulator; it investigates complaints, conducts own-motion investigations and assessments, issues determinations, and can seek civil penalties for serious or repeated interferences with privacy.
Since 2018, APP entities must notify affected individuals and the OAIC of an 'eligible data breach' likely to result in serious harm; entities generally have up to 30 days to assess a suspected breach.
The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024, adding a statutory tort for serious invasions of privacy (commenced 10 June 2025), expanded OAIC investigative/enforcement powers, transparency rules on automated decision-making, and a mandate to develop a Children's Online Privacy Code.
More consequential proposals from the 2023 Privacy Act Review response โ including narrowing/removing the small-business exemption, introducing a 'fair and reasonable' handling test, and broader individual rights โ remain a Government commitment; no second-tranche Bill has been passed as of mid-2026.
From 1 July 2026, AML/CTF 'tranche 2' reforms bring designated non-financial businesses and professions (lawyers, accountants, conveyancers, real estate agents, precious metals dealers) within scope of the Privacy Act regardless of turnover, materially widening the Act's coverage.
Timeline - major decisions & events
The Federal Court ordered Australian Clinical Labs to pay AUD 5.8 million over the 2022 Medlab Pathology breach affecting 223,000 people, the first-ever civil penalty under the Privacy Act, establishing how courts assess 'reasonable steps' and breach-notification failures.
OAIC โThe Australian Information Commissioner filed civil penalty proceedings in the Federal Court against Optus, alleging it seriously interfered with the privacy of about 9.5 million Australians by failing to protect their personal information between 2019 and 2022.
OAIC โSchedule 2 of the Privacy Act took effect, giving individuals for the first time a direct cause of action to sue for serious invasions of privacy (intrusion on seclusion or misuse of information), with remedies including damages and injunctions.
OAIC โFirst tranche of post-review reforms became law, implementing 23 government-agreed proposals, including the statutory tort, new transparency rules for automated decision-making, a children's online privacy code, and tiered civil penalties.
OAIC โThe Commissioner began Federal Court proceedings alleging Medibank failed to take reasonable steps to protect the personal information of 9.7 million Australians between 2021 and 2022, breaching the Privacy Act after its major 2022 breach.
OAIC โThe Government agreed (in full or in principle) to 106 of 116 review proposals, committing to the biggest overhaul of the Act since 2014, including removing the small-business exemption and creating a statutory privacy tort.
Attorney-General's Department โThe Attorney-General's Department published its review of the Privacy Act with 116 reform proposals to modernise Australia's privacy framework for the digital age, setting the agenda for current and pending reforms.
Attorney-General's Department โSpurred by the Optus and Medibank breaches, Parliament raised the maximum penalty for serious or repeated privacy breaches to the greater of A$50 million, three times the benefit obtained, or 30% of relevant turnover, and boosted OAIC's enforcement powers.
OAIC โA breach of an exposed Optus API exposed the personal data of up to 9.5-10 million current and former customers (including passport and licence numbers), triggering an OAIC investigation and becoming a catalyst for privacy law reform.
OAIC โMandatory breach notification took effect, requiring entities to notify affected individuals and the OAIC of any breach likely to result in serious harm, a foundational pillar of Australia's modern data-protection regime.
OAIC โAustralia - other topics
Data & Privacy in other countries
Last verified 7/23/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ