Australia
Tier 2 Comprehensive law Asia-PacificPrincipal framework: Privacy Act 1988 (major 2024 amendments) (1988). Regulator: OAIC. The December 2024 reforms added a statutory tort for serious invasions of privacy (live June 2025); a second tranche of reform is pending.
At a glance
- Principal law
- Privacy Act 1988 (major 2024 amendments)
- Regulator
- Office of the Australian Information Commissioner (OAIC)
- Breach notification
- Assess within 30 days; notify the OAIC and individuals as soon as practicable (eligible breaches)
- Maximum penalty
- Up to A$50m, 3× the benefit, or 30% of adjusted turnover
- DPO required
- No general mandate
- Digital consent age
- No fixed age; a Children’s Online Privacy Code is due by December 2026
- Extraterritorial reach
- Yes — ‘Australian link’ test
Structure
- Structural pattern
- Pattern 3 — uniform private law, devolved public sector
- Sub-jurisdictions
- 0 (regulator-and-public-sector-only)
- ISO code
- AU
Transfers and adequacy
- EU member
- No
- EEA member
- No
Instruments
Sources
- Regulator Office of the Australian Information Commissioner (OAIC)
- Primary Federal Register of Legislation
- Regulator OAIC — regulator
Never independently verified — seeded from the prototype.