Data Protection Atlas

Australia

Tier 2 Comprehensive law Asia-Pacific

Principal framework: Privacy Act 1988 (major 2024 amendments) (1988). Regulator: OAIC. The December 2024 reforms added a statutory tort for serious invasions of privacy (live June 2025); a second tranche of reform is pending.

At a glance

Principal law
Privacy Act 1988 (major 2024 amendments)
Regulator
Office of the Australian Information Commissioner (OAIC)
Breach notification
Assess within 30 days; notify the OAIC and individuals as soon as practicable (eligible breaches)
Maximum penalty
Up to A$50m, 3× the benefit, or 30% of adjusted turnover
DPO required
No general mandate
Digital consent age
No fixed age; a Children’s Online Privacy Code is due by December 2026
Extraterritorial reach
Yes — ‘Australian link’ test

Structure

Structural pattern
Pattern 3 — uniform private law, devolved public sector
Sub-jurisdictions
0 (regulator-and-public-sector-only)
ISO code
AU

Transfers and adequacy

EU member
No
EEA member
No

Instruments

Sources

Never independently verified — seeded from the prototype.