Data Privacy Laws Australia: The 2026 Compliance Guide
A complete guide to data privacy laws in Australia: the Privacy Act 1988, the 13 Australian Privacy Principles, breach reporting, penalties, and 2024 reforms.
If you run a website, an app, or an online store that touches Australian customers, the data privacy laws Australia enforces are narrower than the GDPR in some places and broader in others. The centrepiece is the Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles, backed by penalties that reach AUD 50 million. This guide covers who is caught, what you must publish, how breach reporting works, and what changed under the 2024 reforms, though you should consult an Australian privacy lawyer for advice tailored to your business.
What the Data Privacy Laws in Australia Actually Cover
Australian data privacy law is a federal framework built on one principal statute. The Privacy Act 1988 (Cth) regulates how "APP entities" handle personal information, defined in section 6(1) as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
That definition is deliberately broad. It captures names and email addresses, but the Office of the Australian Information Commissioner (OAIC) also treats device identifiers, IP addresses, and cookie IDs as personal information where the individual behind them is reasonably identifiable in the circumstances.
A subset called sensitive information attracts stricter rules. It includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, biometric templates, and genetic information. Under Australian Privacy Principle 3.3, you generally cannot collect sensitive information without the individual's consent.
The Act itself sits alongside several other regimes:
- Notifiable Data Breaches scheme (Part IIIC of the Privacy Act), in force since 22 February 2018.
- Consumer Data Right (Part IVD of the Competition and Consumer Act 2010), covering banking, energy, and non-bank lending data sharing.
- Spam Act 2003 and the Do Not Call Register Act 2006, enforced by the Australian Communications and Media Authority (ACMA).
- State and territory privacy statutes, which cover public sector agencies and, in two states, private sector health records.
Who Has to Comply With Australia's Data Privacy Law
The Privacy Act applies to "APP entities", a term covering Australian Government agencies and "organisations". An organisation means any individual, body corporate, partnership, trust, or unincorporated association that is not a small business operator.
The AUD 3 million small business exemption
Section 6D exempts a business with an annual turnover of AUD 3 million or less. This exemption is unusual internationally and is the single biggest gap in Australia's privacy regime. It does not apply if your business:
- Provides a health service and holds health information.
- Trades in personal information, meaning you buy or sell it.
- Is a credit reporting body or a credit provider.
- Is a tax file number recipient.
- Is a contracted service provider for a Commonwealth contract.
- Is related to a body corporate that is already an APP entity.
- Has opted in to being covered under section 6EA.
The Australian Government agreed in principle to remove the small business exemption in its 2023 response to the Privacy Act Review Report, subject to an impact analysis and a transition period. Treat the exemption as temporary rather than as a long-term compliance strategy.
Foreign businesses and extraterritorial reach
Section 5B extends the Act to organisations with an "Australian link", which includes any overseas company that carries on business in Australia. The Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 removed the earlier requirement that the entity also collect or hold the information in Australia.
The practical effect is wide. A SaaS company incorporated in Delaware that markets to Australian users, bills them in Australian dollars, and serves them from overseas servers can be an APP entity with full obligations under the Act.
The 13 Australian Privacy Principles Explained
The Australian Privacy Principles sit in Schedule 1 of the Privacy Act and are organised by the lifecycle of personal information. They are principles rather than prescriptive rules, which means compliance is judged against what is "reasonable in the circumstances".
| APP | Requirement in plain terms |
|---|---|
| APP 1 | Manage information openly and transparently, and keep a clearly expressed, up to date privacy policy |
| APP 2 | Give individuals the option of dealing with you anonymously or under a pseudonym |
| APP 3 | Only collect personal information reasonably necessary for your functions; sensitive information needs consent |
| APP 4 | Deal with unsolicited personal information, and destroy or de-identify it if you could not have collected it |
| APP 5 | Notify individuals at or before collection about what you collect and why |
| APP 6 | Use or disclose information only for the primary purpose, or a related secondary purpose the person would expect |
| APP 7 | Restrict direct marketing and provide a simple opt out |
| APP 8 | Take reasonable steps before disclosing information overseas |
| APP 9 | Do not adopt or use government related identifiers as your own |
| APP 10 | Keep information accurate, up to date, and complete |
| APP 11 | Protect information with reasonable security steps, and destroy or de-identify it when no longer needed |
| APP 12 | Give individuals access to the information you hold about them |
| APP 13 | Correct information on request |
Two of these carry disproportionate enforcement risk. APP 11 underpins almost every OAIC investigation into a data breach, because inadequate security is the finding regulators reach for after an incident. APP 8 makes you accountable for overseas recipients: under section 16C, if an overseas recipient you disclosed to mishandles the data, you are treated as having breached the APPs yourself.
The 2024 amendments added a mechanism for the Governor-General to prescribe countries and binding schemes with substantially similar protections, creating an adequacy style "white list" that reduces the APP 8 burden for transfers to those destinations. No countries have been prescribed as of mid 2026.
What Australia's Data Privacy Law Requires in Your Privacy Policy
APP 1.3 requires every APP entity to have a clearly expressed and up to date privacy policy about how it manages personal information. APP 1.4 sets out the minimum content, and it is a specific list rather than a vague obligation. Your policy must state:
- The kinds of personal information you collect and hold.
- How you collect and hold that information.
- The purposes for which you collect, hold, use, and disclose it.
- How an individual can access their personal information and seek correction.
- How an individual can complain about a breach of the APPs, and how you will deal with the complaint.
- Whether you are likely to disclose personal information to overseas recipients.
- If so, the countries in which those recipients are likely to be located, where practicable.
That last item trips up most Australian websites. Naming actual destination countries requires you to know where your analytics provider, email platform, CRM, and hosting company store data. A privacy policy generator that asks about your third-party services and produces the overseas disclosure section for you removes most of that guesswork.
APP 1.5 adds that the policy must be available free of charge, in an appropriate form, which in practice means a public URL linked from your site footer with no login required.
The separate APP 5 collection notice
A privacy policy is not the same as a collection notice. APP 5 requires you to take reasonable steps to notify the individual at or before the time you collect their information, covering your identity and contact details, the purposes of collection, the consequences of not providing the data, and the entities you usually disclose to.
In practice this means short, in-context notices next to signup forms, checkout fields, and account creation flows, with a link through to the full policy. For a broader walkthrough of the framework behind these obligations, see the guide on the Australian Privacy Principles.
The Notifiable Data Breach Scheme
Part IIIC of the Privacy Act creates the Notifiable Data Breaches (NDB) scheme. It applies to an eligible data breach, which under section 26WE means unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to any affected individual, where remedial action has not removed that likelihood.
The process runs on strict timing:
- Suspect a breach. If you have reasonable grounds to suspect an eligible data breach, section 26WH requires you to carry out a reasonable and expeditious assessment.
- Assess within 30 days. The assessment must be completed within 30 calendar days of becoming aware of the grounds for suspicion.
- Notify as soon as practicable. If you form a reasonable belief that an eligible data breach has occurred, section 26WK requires a statement to the Australian Information Commissioner, and section 26WL requires you to notify affected individuals.
- Include the required content. The statement must set out your identity, a description of the breach, the kinds of information involved, and the steps individuals should take in response.
Breach volumes keep climbing. The OAIC reported 1,113 notifications in the 2024 calendar year, the highest annual total since the scheme began, with malicious or criminal attacks the leading cause and human error a persistent second. The Privacy and Other Legislation Amendment Act 2024 also added Part VIA, which lets the Minister declare an emergency and permit information sharing to prevent or reduce harm after a major breach.
Penalties and Enforcement Under Australian Data Privacy Law
Enforcement changed dramatically after the 2022 Optus and Medibank incidents. The Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 lifted the maximum civil penalty for serious or repeated interference with privacy under section 13G to the greater of:
- AUD 50 million.
- Three times the value of any benefit obtained from the misuse of information.
- If the value cannot be determined, 30 percent of the entity's adjusted turnover during the breach turnover period.
The Privacy and Other Legislation Amendment Act 2024 filled the gap below that ceiling. It created a mid-tier civil penalty for an interference with privacy that is not serious, with a maximum of 2,000 penalty units, and a low-tier penalty of up to 200 penalty units for specific administrative failures such as an inadequate privacy policy or failure to respond to an access request. Bodies corporate face five times those amounts under the Regulatory Powers (Standard Provisions) Act 2014.
The OAIC also gained infringement notice powers and the ability to conduct public inquiries. It has filed civil penalty proceedings in the Federal Court against Australian Clinical Labs over its 2022 breach and against Medibank Private in June 2024, the first cases to test section 13G at scale.
Separately, the Criminal Code was amended in December 2024 to create doxxing offences, carrying up to six years imprisonment, or seven years where the targeting is based on race, religion, sex, sexual orientation, gender identity, intersex status, disability, nationality, or national or ethnic origin.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowWhat the 2024 Reforms Changed
The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024 and represents the first tranche of reform following the 2023 Privacy Act Review Report. Three changes matter most for ordinary businesses.
A statutory tort for serious invasions of privacy. Commenced in June 2025, this new cause of action lets an individual sue directly for intrusion upon seclusion or misuse of information where the invasion was serious, intentional or reckless, and there was a reasonable expectation of privacy. Damages are capped at AUD 478,550 or the cap for non-economic loss in defamation, whichever is greater. This is the first time Australians can sue over privacy without going through the regulator.
Automated decision-making transparency. From December 2026, privacy policies must disclose the kinds of personal information used in computer programs that make, or substantially and directly assist in making, decisions that could reasonably be expected to significantly affect an individual's rights or interests. If you use automated credit scoring, algorithmic pricing, or AI-assisted eligibility checks, your policy needs a new section.
A Children's Online Privacy Code. The OAIC must develop a code applying to social media and other services likely to be accessed by children, with a statutory deadline of December 2026. Services aimed at under 18s should plan for higher default protections.
Further tranches remain on the agenda, including a "fair and reasonable" test for collection, a direct right of action for individuals, and removal of the small business exemption. None of those are law yet.
State, Territory, and Sector-Specific Privacy Laws
The Privacy Act is federal and mostly covers Commonwealth agencies and private organisations. Each state and territory runs its own regime for its public sector:
- New South Wales: Privacy and Personal Information Protection Act 1998 and Health Records and Information Privacy Act 2002.
- Victoria: Privacy and Data Protection Act 2014 and Health Records Act 2001.
- Queensland: Information Privacy Act 2009.
- Tasmania: Personal Information Protection Act 2004.
- Northern Territory: Information Act 2002.
- Australian Capital Territory: Information Privacy Act 2014.
- Western Australia: Privacy and Responsible Information Sharing Act 2024, being introduced in stages.
- South Australia: administrative instructions rather than legislation.
Two of these reach private businesses. The NSW and Victorian health records statutes apply to private sector health service providers in those states, so a private clinic in Sydney answers to both the Privacy Act and the NSW health privacy regime. Sector rules add further layers, including the My Health Records Act 2012, Part IIIA of the Privacy Act for credit reporting, and the Security of Critical Infrastructure Act 2018 for designated critical assets.
How Australia's Data Privacy Law Compares to GDPR and CCPA
If you already comply with European rules, most of the work carries across, but the gaps run in both directions.
| Issue | Privacy Act 1988 (Australia) | GDPR (EU) |
|---|---|---|
| Legal basis | Collection permitted where reasonably necessary for your functions | Specific Article 6 lawful basis required for every activity |
| Consent | Required mainly for sensitive information under APP 3.3 | Required whenever consent is the chosen lawful basis, and must be opt in |
| Right to erasure | No general right; APP 11.2 requires destruction when no longer needed | Article 17 gives an explicit right to erasure |
| Data portability | Limited to Consumer Data Right sectors | Article 20 applies across the board |
| Breach reporting | Assess in 30 days, notify if serious harm is likely | Notify supervisory authority within 72 hours |
| Small business | Under AUD 3 million turnover generally exempt | No turnover exemption |
| Maximum penalty | Greater of AUD 50 million, three times benefit, or 30 percent of adjusted turnover | Greater of 20 million EUR or 4 percent of global annual turnover |
The most common mistake is assuming that a GDPR-shaped policy satisfies APP 1.4. It usually will not, because the GDPR does not require you to list the countries where overseas recipients are located, and Australian regulators expect that detail. If you serve both markets, build one policy with distinct sections for each regime rather than hoping the stricter law covers everything. The GDPR vs CCPA comparison covers the equivalent split between European and Californian rules.
A Practical Compliance Checklist for Australian Businesses
Working through these steps in order gets most small and mid-sized businesses to a defensible position:
- Confirm whether you are covered. Check your annual turnover against the AUD 3 million threshold, then check whether any section 6D carve-out applies to you anyway.
- Map what you collect. Build an inventory of every form, cookie, SDK, and third-party script that touches personal information, and record where each destination stores data.
- Publish an APP 1.4 compliant privacy policy. Cover all seven required elements, including the overseas recipient countries, and link it from every page.
- Add APP 5 collection notices. Short notices at the point of collection, not just a link to the policy.
- Review your APP 8 disclosures. Check the contractual terms with overseas processors, since section 16C makes their failures your liability.
- Write a data breach response plan. Assign an assessment owner, document the 30-day clock, and prepare the notification statement template in advance.
- Set a retention schedule. APP 11.2 requires destruction or de-identification once information is no longer needed for a permitted purpose.
- Re-audit quarterly. New marketing tags and analytics tools change your disclosure obligations without anyone updating the policy.
Step two is where most teams lose accuracy, because marketing adds tags that nobody records. Automated scanners such as TermsBox detect the cookies, trackers, and third-party services actually running on your site, which gives you the evidence base for both the policy and your APP 5 notices. For deeper background on the statute itself, see the overview of privacy laws in Australia and the detail on the Australian Privacy Act 1988.
Frequently Asked Questions
Does Australian privacy law apply to overseas businesses?
Yes. Section 5B of the Privacy Act 1988 extends the Act to foreign organisations that carry on business in Australia. Since the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022, you no longer need to collect or hold the data in Australia for the Act to apply, so an overseas online store selling to Australian customers can be covered.
What is the small business exemption in the Privacy Act?
Section 6D exempts most businesses with an annual turnover of AUD 3 million or less from the Privacy Act. The exemption does not apply to health service providers, businesses that trade in personal information, credit reporting bodies, tax file number recipients, or Commonwealth contracted service providers, and the government has agreed in principle to remove it in a future reform tranche.
Do I need cookie consent banners in Australia?
Australia has no direct equivalent of the EU ePrivacy Directive, so there is no standalone cookie consent law. However, the OAIC treats online identifiers as personal information where an individual is reasonably identifiable, which means APP 5 collection notices apply and most Australian sites with EU or UK visitors deploy a consent banner anyway.
What are the penalties for breaching data privacy laws in Australia?
For serious or repeated interferences with privacy, the maximum penalty for a body corporate is the greater of AUD 50 million, three times the benefit obtained from the misuse, or 30 percent of adjusted turnover during the breach period. The Privacy and Other Legislation Amendment Act 2024 added mid-tier and low-tier civil penalties of up to 2,000 and 200 penalty units for less serious contraventions.
How quickly must an Australian data breach be reported?
Under Part IIIC of the Privacy Act, you must complete an assessment of a suspected eligible data breach within 30 days. If the breach is likely to result in serious harm, you must notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable after forming that belief.
Is the Privacy Act 1988 the same as the GDPR?
No. The Privacy Act is principles-based and generally allows collection where it is reasonably necessary for your functions, while the General Data Protection Regulation requires a specific lawful basis under Article 6 for every processing activity. Australian law also lacks a general right to erasure and applies consent mainly to sensitive information under APP 3.3.