Skip to content
World Watch/Australia/Data & Privacy

Data & Privacy ยท Australia

Data protection & privacy law in Australia (2026)

Comprehensive lawCountry index 84 ยท A

Australia shaded by its data & privacy status

Data protection in Australia: comprehensive law.

FrameworkPrivacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth); enforced by the Office of the Australian Information Commissioner (OAIC), with the 13 Australian Privacy Principles (APPs) forming the core obligations.

Australia has a comprehensive federal privacy regime centred on the Privacy Act 1988 and the 13 Australian Privacy Principles, regulated by the OAIC and covering Commonwealth agencies and most private-sector organisations with annual turnover above AU$3 million (plus certain smaller entities such as health providers). The first tranche of the Privacy Act reform package received Royal Assent on 10 December 2024, introducing a statutory tort for serious invasions of privacy (in force from 10 June 2025), stronger OAIC enforcement powers, and a forthcoming Children's Online Privacy Code. A second, more ambitious tranche of reforms (including likely narrowing of the small-business exemption and a 'fair and reasonable' test) remains proposed rather than enacted as of mid-2026.

Key points

Primary law and principles

The Privacy Act 1988 (Cth) sets 13 Australian Privacy Principles governing collection, use, disclosure, storage, quality, security, access and correction of personal information by APP entities (Commonwealth agencies and most organisations with turnover > AU$3m).

Supervisory authority

The Office of the Australian Information Commissioner (OAIC) is the independent regulator; it investigates complaints, conducts own-motion investigations and assessments, issues determinations, and can seek civil penalties for serious or repeated interferences with privacy.

Notifiable Data Breaches scheme

Since 2018, APP entities must notify affected individuals and the OAIC of an 'eligible data breach' likely to result in serious harm; entities generally have up to 30 days to assess a suspected breach.

First-tranche reforms (2024โ€“2025)

The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024, adding a statutory tort for serious invasions of privacy (commenced 10 June 2025), expanded OAIC investigative/enforcement powers, transparency rules on automated decision-making, and a mandate to develop a Children's Online Privacy Code.

Second tranche still pending

More consequential proposals from the 2023 Privacy Act Review response โ€” including narrowing/removing the small-business exemption, introducing a 'fair and reasonable' handling test, and broader individual rights โ€” remain a Government commitment; no second-tranche Bill has been passed as of mid-2026.

Scope expansion via AML/CTF reforms

From 1 July 2026, AML/CTF 'tranche 2' reforms bring designated non-financial businesses and professions (lawyers, accountants, conveyancers, real estate agents, precious metals dealers) within scope of the Privacy Act regardless of turnover, materially widening the Act's coverage.

Timeline - major decisions & events

Oct 8, 2025enforcementofficial
Australia's first civil penalty under the Privacy Act ($5.8M, Australian Clinical Labs)

The Federal Court ordered Australian Clinical Labs to pay AUD 5.8 million over the 2022 Medlab Pathology breach affecting 223,000 people, the first-ever civil penalty under the Privacy Act, establishing how courts assess 'reasonable steps' and breach-notification failures.

OAIC โ†—
Aug 8, 2025enforcementofficial
Information Commissioner sues Optus over 2022 breach

The Australian Information Commissioner filed civil penalty proceedings in the Federal Court against Optus, alleging it seriously interfered with the privacy of about 9.5 million Australians by failing to protect their personal information between 2019 and 2022.

OAIC โ†—
Jun 10, 2025lawofficial
Statutory tort for serious invasions of privacy commences

Schedule 2 of the Privacy Act took effect, giving individuals for the first time a direct cause of action to sue for serious invasions of privacy (intrusion on seclusion or misuse of information), with remedies including damages and injunctions.

OAIC โ†—
Dec 10, 2024lawofficial
Privacy and Other Legislation Amendment Act 2024 receives Royal Assent

First tranche of post-review reforms became law, implementing 23 government-agreed proposals, including the statutory tort, new transparency rules for automated decision-making, a children's online privacy code, and tiered civil penalties.

OAIC โ†—
Jun 5, 2024enforcementofficial
OAIC commences civil penalty action against Medibank

The Commissioner began Federal Court proceedings alleging Medibank failed to take reasonable steps to protect the personal information of 9.7 million Australians between 2021 and 2022, breaching the Privacy Act after its major 2022 breach.

OAIC โ†—
Sep 28, 2023guidanceofficial
Government response to the Privacy Act Review Report

The Government agreed (in full or in principle) to 106 of 116 review proposals, committing to the biggest overhaul of the Act since 2014, including removing the small-business exemption and creating a statutory privacy tort.

Attorney-General's Department โ†—
Feb 16, 2023guidanceofficial
Privacy Act Review Report released

The Attorney-General's Department published its review of the Privacy Act with 116 reform proposals to modernise Australia's privacy framework for the digital age, setting the agenda for current and pending reforms.

Attorney-General's Department โ†—
Dec 13, 2022lawofficial
Enforcement and Other Measures Act sharply increases penalties

Spurred by the Optus and Medibank breaches, Parliament raised the maximum penalty for serious or repeated privacy breaches to the greater of A$50 million, three times the benefit obtained, or 30% of relevant turnover, and boosted OAIC's enforcement powers.

OAIC โ†—
Sep 22, 2022incidentofficial
Optus data breach

A breach of an exposed Optus API exposed the personal data of up to 9.5-10 million current and former customers (including passport and licence numbers), triggering an OAIC investigation and becoming a catalyst for privacy law reform.

OAIC โ†—
Feb 22, 2018lawofficial
Notifiable Data Breaches scheme commences

Mandatory breach notification took effect, requiring entities to notify affected individuals and the OAIC of any breach likely to result in serious harm, a foundational pillar of Australia's modern data-protection regime.

OAIC โ†—

Australia - other topics

Data & Privacy in other countries

Last verified 7/23/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ†’