Australian Privacy Act

The Privacy Act 1988,
the 13 APPs and what changed in 2024.

A practical guide to the Australian Privacy Act for SaaS and technology companies: who it covers, what each Australian Privacy Principle asks, how breach notification works and the reform dates you need to plan for. Not legal advice: check the current text with your counsel.

Privacy Act 198813 APPsNDB schemePOLA Act 2024OAIC

Last updated Published by TryTrustableNot legal advice

Short answer

The Australian Privacy Act 1988 is the federal law that governs how Australian Government agencies and most businesses with an annual turnover above $3 million collect, use, disclose and protect personal information. Its core is the 13 Australian Privacy Principles (APPs). It also runs the Notifiable Data Breaches scheme, which requires you to tell the OAIC and affected people about a breach likely to cause serious harm. The Privacy and Other Legislation Amendment Act 2024 added a statutory tort for serious invasions of privacy (from 10 June 2025), new penalty tiers, a Children's Online Privacy Code (due by 10 December 2026) and privacy policy disclosures for automated decisions (from 10 December 2026).

01

What is the Australian Privacy Act?

The Privacy Act 1988 (Cth) is Australia's main privacy law. It regulates how "APP entities" handle personal information: information or an opinion about an identified individual, or an individual who is reasonably identifiable. It is administered by the Office of the Australian Information Commissioner (OAIC). The Act contains the 13 Australian Privacy Principles, credit reporting rules, tax file number rules, the Notifiable Data Breaches scheme and, since June 2025, a separate statutory tort for serious invasions of privacy.

It applies to an organisation outside Australia too if it has an "Australian link", which includes carrying on business in Australia. A SaaS company selling to Australian customers should assume it is in scope unless the small business exemption applies.

02

Who does the Privacy Act apply to? The small business exemption

The APPs bind Australian Government agencies and "organisations". A business with an annual turnover of $3 million or less is generally a small business operator and exempt (section 6D). The exemption does not apply, whatever the turnover, if the business:

  • provides a health service and holds health information (other than in employee records);
  • discloses personal information to anyone else for a benefit, service or advantage, or pays to collect it;
  • is a contracted service provider under a Commonwealth contract;
  • is a credit reporting body; or
  • falls into a category the Act or regulations bring in, such as reporting entities under the AML/CTF Act for those activities.

Removing the exemption was discussed in the Privacy Act Review but was not part of the 2024 Act; as of the June 2026 compilation, section 6D still stands. Enterprise customers often require the APPs by contract anyway.

03

The 13 Australian Privacy Principles

The APPs are principles-based: they set the outcome and leave the method to you.

APPPrincipleWhat it asks in practice
APP 1Open and transparent management of personal informationA clearly expressed, current APP privacy policy and internal practices that make compliance work
APP 2Anonymity and pseudonymityLet people deal with you without identifying themselves where that is practicable
APP 3Collection of solicited personal informationCollect only what is reasonably necessary, by lawful and fair means; sensitive information generally needs consent
APP 4Dealing with unsolicited personal informationDecide whether you could have collected it; if not, destroy or de-identify it
APP 5Notification of collectionTell people who you are, why you collect and who you disclose to, at or near collection
APP 6Use or disclosureUse and disclose for the primary purpose, or a secondary purpose the law permits
APP 7Direct marketingOnly in the permitted cases, always with a simple way to opt out
APP 8Cross-border disclosureTake reasonable steps so an overseas recipient does not breach the APPs; you stay accountable for it
APP 9Government related identifiersDo not adopt a government identifier (such as a tax file number) as your own
APP 10Quality of personal informationKeep it accurate, up to date and complete
APP 11Security of personal informationReasonable steps, including technical and organisational measures, to protect it, and destroy or de-identify it when no longer needed
APP 12AccessGive people access to the personal information you hold about them
APP 13CorrectionCorrect it when it is inaccurate, out of date, incomplete, irrelevant or misleading

A summary of Schedule 1 to the Privacy Act 1988. The principles are short; read the full text with the OAIC's APP guidelines.

04

How does the Notifiable Data Breaches scheme work?

An eligible data breach happens when there is unauthorised access to, or disclosure or loss of, personal information you hold, and a reasonable person would conclude it is likely to result in serious harm to any of the people it relates to (Part IIIC of the Act). If you take remedial action in time so serious harm is no longer likely, it is not notifiable.

  1. Assess. If you suspect an eligible breach, carry out a reasonable and expeditious assessment and take all reasonable steps to finish it within 30 days (section 26WH).
  2. Notify the OAIC. Once you have reasonable grounds to believe there has been an eligible breach, prepare a statement and give it to the Commissioner as soon as practicable (section 26WK). It must set out your identity and contact details, a description of the breach, the kinds of information involved, and the steps people should take.
  3. Notify individuals as soon as practicable after that: everyone affected, or everyone at risk, or if neither is practicable, publish the statement on your website and publicise it (section 26WL).

There is no fixed hour count as under the GDPR, but the 30-day assessment limit is real and the OAIC expects speed. Since 11 December 2024 a breach statement that is missing the required content can attract an infringement notice. Our incident management page covers the response workflow.

05

The 2024 amendments and their commencement dates

The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024. It is one part of the government's response to the Privacy Act Review. Its parts start on different dates:

Change (Privacy and Other Legislation Amendment Act 2024)In force
Most of Schedule 1: new penalty tiers, infringement and compliance notices, APP 11.3 (technical and organisational measures), prescribed countries for APP 8, eligible data breach declarations, OAIC public inquiries and investigation powers11 December 2024
Doxxing offences in the Criminal Code (Schedule 3)11 December 2024
Statutory tort for serious invasions of privacy (Schedule 2)10 June 2025
Children's Online Privacy Code: the OAIC must develop and register itBy 10 December 2026 (draft consulted on 31 March to 5 June 2026)
Automated decisions: APP privacy policy disclosures (APP 1.7 to 1.9)10 December 2026

Dates from the Act's commencement table (section 2) and the OAIC. Royal Assent was 10 December 2024.

Statutory tort for serious invasions of privacy

Since 10 June 2025 an individual can sue for a serious invasion of privacy by intrusion upon seclusion or misuse of information, where they had a reasonable expectation of privacy, the invasion was intentional or reckless, it was serious, and the public interest in privacy outweighs any countervailing public interest. No proof of damage is needed. Damages for non-economic loss plus any exemplary damages are capped at the greater of $478,550 and the defamation cap. Proceedings must generally start within one year of becoming aware and three years of the invasion. Journalists, intelligence and law enforcement bodies and people under 18 are exempt in the circumstances the Schedule sets out.

Children's Online Privacy Code

The OAIC must develop and register a Children's Online Privacy Code by 10 December 2026. It will set out how the APPs apply to social media services, relevant electronic services and designated internet services that are likely to be accessed by children (people under 18). The draft was consulted on from 31 March to 5 June 2026. Check the registered Code for when its obligations start.

Automated decisions transparency

From 10 December 2026, if a computer program uses personal information to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect someone's rights or interests, your APP privacy policy must say what kinds of personal information are used and which kinds of decisions are made solely by the program or with its substantial help. A failure is an infringement notice matter under section 13K. If you run AI features, see our AI governance guide.

06

Privacy Act penalties and OAIC enforcement

The 2024 Act turned a single penalty for serious or repeated interferences into three tiers, and gave the OAIC faster tools for the lower ones.

TierProvisionMaximum
Serious interference with privacys 13GBody corporate: the greatest of $50 million, three times the benefit obtained, or (if the benefit cannot be determined) 30% of adjusted turnover in the breach turnover period. Others: $2.5 million
Interference with privacy (not serious)s 13H2,000 penalty units, with the usual multiplier for a body corporate under the Regulatory Powers Act
Administrative breaches (for example a missing or deficient privacy policy, or a non-compliant breach statement)s 13K200 penalty units per contravention; the OAIC can issue infringement notices and compliance notices

Penalty units are set by the Crimes Act 1914 and were due for indexation on 1 July 2026, so check the current dollar value.

Beyond penalties, the OAIC can investigate complaints and on its own initiative, make determinations (including orders to pay compensation), accept enforceable undertakings, run assessments, use monitoring and investigation powers under the Regulatory Powers Act, conduct public inquiries, and apply to the Federal Court for civil penalty orders. The Federal Court can also order an entity to compensate people or publish a statement about the contravention.

07

Australian Privacy Act vs GDPR

Teams that already work to the GDPR have most of the building blocks, but the two laws are not interchangeable:

  • Lawful basis. The APPs do not require a lawful basis for every processing activity; they control collection, use and disclosure by purpose, with consent required mainly for sensitive information.
  • Exemptions. The small business and employee records exemptions have no GDPR equivalent.
  • Transfers. APP 8 makes you accountable for an overseas recipient rather than requiring a transfer mechanism; the 2024 Act allows countries to be prescribed, but check whether any have been.
  • Breach timing. "As soon as practicable" after a 30-day assessment window, rather than 72 hours.
  • Data subject rights. Access and correction only; there is no general right to erasure or portability under the APPs.
  • Cookies. No ePrivacy-style cookie rule, but identifying tracking data is personal information. The free cookie scanner shows what your site collects.
08

How TryTrustable helps with the Australian Privacy Act

The Australian Privacy Act is one of the frameworks modelled in the platform. Each APP is a requirement mapped to controls in a shared library, so the work you do for SOC 2, ISO 27001 or GDPR counts here too, and readiness comes from control results rather than a checkbox.

Australian requirementWhat TryTrustable does
APP 1 privacy policy, APP 5 collection noticeA privacy policy generator, notice versions recorded in the consent ledger, and the 13 APPs modelled as requirements mapped to your controls
APP 3, APP 7 consent and opt-outA consent banner that blocks trackers until the visitor chooses, records each choice in a tamper-evident ledger and relays withdrawals to your processors
APP 8 cross-border disclosureA vendor and processor register with contract status and destination country for each recipient
APP 11 securitySecurity controls with evidence collected from GitHub, AWS and GCP, shared with SOC 2 and ISO 27001
APP 12 and 13 access and correctionA rights-request queue with a deadline on every request, fed by a link on the banner or your own form
NDB schemeIncident tracking from detection to post-mortem with real timestamps, so you can show when the assessment started and finished

Readiness is derived from control results. The platform supports your programme; it does not make you compliant by itself. Data is hosted in Google Cloud Mumbai today, which is itself an overseas disclosure to account for under APP 8.

Questions

The things people ask us

Does the Australian Privacy Act apply to small businesses?

Generally not if annual turnover is $3 million or less, but the exemption is lost if the business provides a health service, trades in personal information, is a Commonwealth contracted service provider or a credit reporting body, among other cases in section 6D(4).

How long do I have to report a data breach in Australia?

You must take all reasonable steps to finish assessing a suspected breach within 30 days, then notify the OAIC and affected individuals as soon as practicable once you believe it is an eligible data breach.

What are the maximum penalties under the Privacy Act?

For a serious interference with privacy, a body corporate faces up to the greatest of $50 million, three times the benefit obtained, or 30% of adjusted turnover. Lower tiers apply to interferences that are not serious and to administrative breaches.

When does the Children's Online Privacy Code start?

The OAIC must register it by 10 December 2026. The registered Code will set out when its obligations start, so check the OAIC's page for the final version.

Do I need a data protection officer in Australia?

The Privacy Act does not require private sector organisations to appoint a DPO, unlike the GDPR. APP 1 does require practices and procedures that ensure compliance, which in practice means a named privacy owner.

Book a walkthrough

See the 13 APPs mapped to your controls.

Thirty minutes on the Australian Privacy Act alongside the frameworks you already answer to: SOC 2, ISO 27001 or GDPR.