Skip to content
GlanceDeskJurisdiction

Home › Law library › Privacy Act / APPs

AU

Privacy Act / APPs

Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024

Sourced. Last verified 9 October 2026

Australia Privacy

Status
In force. POLA Act 2024 assented 10 Dec 2024; most changes from 11 Dec 2024; statutory privacy tort from 10 Jun 2025; automated-decision disclosure from 10 Dec 2026; Children's Online Privacy Code due by 10 Dec 2026. Further 'tranche 2' reforms not yet introduced.
Who it applies to
Australian Government agencies and private organisations with over A$3m annual turnover (plus listed exceptions). Overseas organisations are covered if they have an 'Australian link', e.g. carrying on business in Australia, even without a physical presence.
Size thresholds
Small business exemption: A$3m or less turnover is exempt, unless it is a health provider, trades in personal data, is a Commonwealth contractor, a credit reporting body, or covered by AML/CTF, among others. Firms over A$3m in any year since 2002 stay covered.
Regulator
Office of the Australian Information Commissioner (OAIC)
Breach or incident reporting
Notifiable Data Breaches scheme: assess a suspected breach within 30 days; if serious harm is likely, notify the OAIC and affected individuals (or publish a statement if direct notice is impractical).
Deadline to answer personal data requests
Being verified
Data protection officer
No legal requirement for a DPO for private organisations; the OAIC recommends one as good practice.
Local representative
No local representative requirement.
Sending data abroad
Before disclosing data overseas, take reasonable steps so the recipient complies with the APPs; you usually stay liable for their acts. Exceptions: similar foreign law, informed consent, legal requirement. Since Dec 2024 the government can whitelist countries; none listed yet.
Cookies and consent
No specific cookie law; the APPs apply when cookies collect personal information. Sensitive information generally needs consent; direct marketing must offer an opt-out.
Maximum penalty
Serious interferences: greater of A$50m, 3x the benefit gained, or 30% of domestic turnover. Lower tier up to A$3.3m; infringement notices for administrative breaches. Individuals can also sue under the statutory tort.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

POLA Act 2024: OAIC infringement and compliance notices and doxxing offence (11 Dec 2024); statutory tort for serious privacy invasions (10 Jun 2025); ADM transparency (10 Dec 2026). Children's code exposure draft released 31 Mar 2026; registration due by 10 Dec 2026.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].