Australia Data Removal Guide (2026)
Australians are protected by the Privacy Act 1988 and its 13 Australian Privacy Principles, with 2024 amendments commencing on different dates. The federal electoral roll is not available for sale, although the current roll can be inspected under the Commonwealth Electoral Act and access is restricted by purpose.
Research status: sources last checked 2026-09-07.
This page is educational orientation, not legal advice. The legal fields below are a research snapshot; eligibility, exemptions, deadlines, penalty rules and broker routes can change. Verify the current statute and regulator guidance before relying on a right or filing a complaint.
At a glance
- Governing law
- Privacy Act 1988
- Response deadline
- 30 days (OAIC benchmark for APP 12 access requests)
- Regulator
- Office of the Australian Information Commissioner (OAIC)
- Private right of action
- Yes: statutory tort for serious invasions of privacy commenced 10 June 2025, subject to elements, exemptions, and time limits
Privacy Act 1988 (Cth) + Australian Privacy Principles (2024 amendments with phased commencement)
The Privacy Act 1988 and the 13 APPs apply to Australian Government agencies and many organisations, subject to statutory coverage rules and exceptions. The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024. Its statutory tort for serious invasions of privacy commenced on 10 June 2025, while other amendments have different commencement dates; for example, the automated-decision provisions are scheduled for 10 December 2026. Civil-penalty amounts and available remedies depend on the provision and current law.
Read the full Privacy Act 1988explainer โScope, penalties, private right of action, enforcement history.
What rights do Australia residents have?
- โRight to access personal information held (APP 12)
- โRight to correct personal information (APP 13)
- โRight to opt out of direct marketing (APP 7)
- โRight to deal anonymously or by pseudonym where practicable (APP 2)
- โRight to complain to the OAIC
- โPossible court action under the statutory tort for serious invasions of privacy (Schedule 2, commenced 2025)
Who holds your data in Australia?
The main data-removal issues may involve credit reporting/identity providers (including Equifax Australia, illion, and Experian), marketing-list providers, company records, and international people-search sites. Whether a particular provider is covered by the Privacy Act depends on the Act's coverage rules, including exceptions and the facts of the business; do not infer coverage from a provider label alone.
Public-record sources brokers scrape
- Commonwealth electoral roll: not available for sale; current copies can be inspected at AEC offices and supplied to authorised recipients for permitted purposes
- ASIC company register: company and officeholder records; residential-address protections and access rules depend on the record and current law
- State land titles registries (NSW LRS, etc.): property ownership, for a fee
- Court and bankruptcy records (AFSA)
How to remove your data in Australia
- 1Register on the national Do Not Call Register (donotcall.gov.au) for telemarketing.
- 2Send APP 12 access + APP 13 correction requests to any organisation holding your data.
- 3Use the APP 7 direct-marketing opt-out; organisations generally must stop using or disclosing your information for direct marketing when the applicable conditions are met.
- 4Place credit-reporting bans/freezes with Equifax/illion/Experian after suspected fraud.
- 5If conduct may satisfy the statutory-tort elements, consider independent legal advice; the OAIC does not administer that tort directly. Use the OAIC complaint route for matters within its jurisdiction.
Generate requests in under 60 seconds
Generate requests for 1,034 US/global broker workflows for $9
What if a company ignores your request?
Consider the Office of the Australian Information Commissioner (OAIC) information or complaint route above if the controller does not respond or the response is unsatisfactory. This guide records the following penalty orientation: Top-tier corporate civil penalty: greater of AUD $50M, 3ร attributable benefit, or 30% adjusted turnover; other penalties vary. The private-action note is: Yes: statutory tort for serious invasions of privacy commenced 10 June 2025, subject to elements, exemptions, and time limits. Neither field is an individual award or a promise of enforcement.
Open the Office of the Australian Information Commissioner (OAIC) information or complaint route โFAQ: Australia data removal
Is the Australian electoral roll public?+
The electoral roll is not available for sale in any format. The current roll can be inspected at AEC offices, and the Commonwealth Electoral Act permits supply to specified recipients for permitted purposes. That is different from a publicly downloadable commercial list.
What did the 2024 Privacy Act reforms change?+
The Act received Royal Assent on 10 December 2024. The statutory tort for serious invasions of privacy commenced on 10 June 2025. Other amendments have different commencement dates, including automated-decision provisions scheduled for 10 December 2026; check the current legislation before describing a provision as operative.
How do I stop direct marketing in Australia?+
Use the APP 7 direct-marketing opt-out with the organisation and register on the national Do Not Call Register for covered telemarketing calls.
Can I sue for a privacy breach in Australia?+
A statutory tort commenced on 10 June 2025. An individual may have a cause of action only if the statutory elements are met, including a reasonable expectation of privacy, intentional or reckless conduct, seriousness, and the required public-interest balance; exemptions and time limits also apply.