Home › Law library › Privacy Act / APPs
AU
Privacy Act / APPs
Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024
Sourced. Last verified 9 October 2026
Australia Privacy
- Status
- In force. POLA Act 2024 assented 10 Dec 2024; most changes from 11 Dec 2024; statutory privacy tort from 10 Jun 2025; automated-decision disclosure from 10 Dec 2026; Children's Online Privacy Code due by 10 Dec 2026. Further 'tranche 2' reforms not yet introduced.
- Who it applies to
- Australian Government agencies and private organisations with over A$3m annual turnover (plus listed exceptions). Overseas organisations are covered if they have an 'Australian link', e.g. carrying on business in Australia, even without a physical presence.
- Size thresholds
- Small business exemption: A$3m or less turnover is exempt, unless it is a health provider, trades in personal data, is a Commonwealth contractor, a credit reporting body, or covered by AML/CTF, among others. Firms over A$3m in any year since 2002 stay covered.
- Regulator
- Office of the Australian Information Commissioner (OAIC)
- Breach or incident reporting
- Notifiable Data Breaches scheme: assess a suspected breach within 30 days; if serious harm is likely, notify the OAIC and affected individuals (or publish a statement if direct notice is impractical).
- Deadline to answer personal data requests
- Being verified
- Data protection officer
- No legal requirement for a DPO for private organisations; the OAIC recommends one as good practice.
- Local representative
- No local representative requirement.
- Sending data abroad
- Before disclosing data overseas, take reasonable steps so the recipient complies with the APPs; you usually stay liable for their acts. Exceptions: similar foreign law, informed consent, legal requirement. Since Dec 2024 the government can whitelist countries; none listed yet.
- Cookies and consent
- No specific cookie law; the APPs apply when cookies collect personal information. Sensitive information generally needs consent; direct marketing must offer an opt-out.
- Maximum penalty
- Serious interferences: greater of A$50m, 3x the benefit gained, or 30% of domestic turnover. Lower tier up to A$3.3m; infringement notices for administrative breaches. Individuals can also sue under the statutory tort.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Check whether you are covered: A$3m+ turnover, a listed exception, or an Australian link
- Keep an up-to-date APP privacy policy; from 10 Dec 2026 disclose substantially automated decisions
- Take reasonable technical and organisational steps to secure personal information
- Assess suspected breaches within 30 days and notify the OAIC and individuals if serious harm is likely
- Take reasonable steps so overseas recipients comply with the APPs before disclosing data abroad
- If your online service is likely used by children, prepare for the Children's Online Privacy Code
Recent changes
POLA Act 2024: OAIC infringement and compliance notices and doxxing offence (11 Dec 2024); statutory tort for serious privacy invasions (10 Jun 2025); ADM transparency (10 Dec 2026). Children's code exposure draft released 31 Mar 2026; registration due by 10 Dec 2026.
Sources
- Primary source: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/small-business
- Second source: https://www.minterellison.com/articles/privacy-and-other-legislation-amendment-act-2024-now-in-effect
- Regulator: Office of the Australian Information Commissioner (OAIC)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].