Privacy Act 1988 (Australia)
Tier 2 In forceAustralia’s principal privacy statute: thirteen Australian Privacy Principles in Schedule 1 bind federal agencies and private organisations above A$3m turnover (with carve-outs). The December 2024 reforms began the largest modernisation in its history, with a second tranche still to come.
Identity
- Citation
- Privacy Act 1988 (Cth), No. 119 of 1988, as amended by the Privacy and Other Legislation Amendment Act 2024 (No. 128 of 2024)
- Jurisdiction
- Australia
- Type
- comprehensive
Assented 1988; APPs from 2014; breach scheme 2018
Amended by: Privacy and Other Legislation Amendment Act 2024 (tranche one)
Structure
What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.
Parts I–II — Scope and definitions
Who and what the Act reaches.
- s 6 Personal information — information ‘about’ an identified or reasonably identifiable individual.
- s 6D The small-business exemption (under A$3m turnover) — targeted for removal in tranche two.
- s 5B Extraterritorial reach via the ‘Australian link’ test.
Part III + Schedule 1 — The 13 APPs
Open and transparent management (APP 1), anonymity (2), collection (3–5), use and disclosure (6), direct marketing (7), cross-border disclosure (8), identifiers (9), quality and security (10–11), access and correction (12–13).
- APP 8 + s 16C Cross-border accountability — the discloser generally remains liable for overseas recipients’ breaches.
- APP 11 Security of personal information; the 2024 Act confirms this includes technical and organisational measures.
Part IIIA — Credit reporting
A dense parallel regime for credit providers and bureaus, with its own notification and correction machinery.
Part IIIC — Notifiable data breaches (ss 26WA–26WT)
The NDB scheme, in force since 2018.
- s 26WH Assess suspected eligible breaches within 30 days.
- ss 26WK–26WL Notify the OAIC and affected individuals as soon as practicable once an eligible breach is found.
Parts IV–VIB — Commissioner, investigations, penalties
The OAIC’s toolkit, sharpened in 2022 and 2024.
- s 13G Serious interference with privacy: civil penalties to the greater of A$50m, three times the benefit, or 30% of adjusted turnover.
- 2024 tiers New mid- and low-tier civil penalties and infringement notices for administrative breaches.
The 2024 reforms and Schedule 2 tort
Tranche one of the post-review reform.
- Sch 2 A statutory tort for serious invasions of privacy — intrusion or misuse — actionable from June 2025.
- Children’s code The OAIC must register a Children’s Online Privacy Code by December 2026.
- Doxxing New Criminal Code offences for menacing release of personal data.
Regulatory enforcement
Interactions and conflicts
Sits above state and territory privacy acts (public sectors and health records), the Spam Act 2003 and the Do Not Call Register for marketing, and tax-file-number and My Health Records rules. Tranche two — a ‘fair and reasonable’ processing test and removal of the small-business exemption — remains pending, so the structural gap with the GDPR persists for multinationals.
Sources
Never independently verified — seeded from the prototype.