What Is Privacy Act 1988 (Cth) + Australian Privacy Principles?
The Privacy Act 1988 (Cth) is Australia's federal data protection law, governing how Commonwealth agencies and private-sector organizations handle personal information. The law is built around 13 Australian Privacy Principles (APPs), which set baseline standards for collection, use, disclosure, security, access, and correction. The Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 increased the maximum civil penalties for serious or repeated privacy interferences. The Privacy and Other Legislation Amendment Act 2024 made further changes, including a statutory tort for serious invasions of privacy; the OAIC states that the tort commenced on 10 June 2025. Other reforms and commencement dates are provision-specific, so check the current legislation and OAIC guidance for the issue being assessed. The Office of the Australian Information Commissioner (OAIC) supervises compliance, with powers to investigate, issue determinations, apply to the Federal Court for civil penalties, and enter enforceable undertakings. The 2022 Optus and Medibank breaches influenced the reform debate, but the legal effect of any current proceeding or amendment should be checked against the latest official source.
At a glance
- Full name
- Privacy Act 1988 (Cth) + Australian Privacy Principles
- Short code
- Privacy Act 1988
- Jurisdiction
- Australia
- Enacted
- 1988
- Last major update
- Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022; statutory tort commenced 10 June 2025 under the Privacy and Other Legislation Amendment Act 2024
- Regulator
- Office of the Australian Information Commissioner (OAIC)
- Private right of action
- Limited
- Statutory citation
- Privacy Act 1988 (Cth)
Scope, who Privacy Act 1988 covers
Protected data
Data subject rights
Right to know what personal information is collected and how it will be used (APP 1, 5. Privacy Notice)
Right to access personal information held (APP 12)
Right to correct personal information (APP 13)
Right to anonymity and pseudonymity where practicable (APP 2)
Right to opt out of direct marketing (APP 7)
Right to complain to the OAIC
Right to sue under the statutory tort for serious invasions of privacy (2024 amendment; in force since 2025)
Notable features
The 2022 Optus and Medibank breaches influenced the Privacy Act reform debate. The 2024 amendments added a statutory tort for serious invasions of privacy, and Australia also has a Notifiable Data Breaches scheme that has applied since February 2018 with harm thresholds and timing requirements.
Enforcement & penalties
Regulator: Office of the Australian Information Commissioner (OAIC)
Penalties: Maximum civil penalties (2022 amendments) for serious or repeated interferences with privacy: the greatest of AUD 50 million; three times the value of the benefit obtained; or 30% of the entity's adjusted turnover in the relevant period. The OAIC can also issue infringement notices (administrative fines) for less serious contraventions and enter enforceable undertakings.
Private right of action: Historically, Privacy Act complaints went through OAIC determinations with limited individual damages. The Privacy and Other Legislation Amendment Act 2024 introduced a statutory tort for serious invasions of privacy, which commenced on 10 June 2025. It creates a direct cause of action for an individual against a defendant for an intentional or reckless serious invasion, subject to the statutory elements and public-interest balancing. The tort is distinct from an OAIC complaint, so review the current legislation and obtain legal advice for a proposed claim.
Relevance to data brokers
The Privacy Act may apply to data brokers that are APP entities, including organizations covered because they trade in personal information or fall within another statutory category. A broker should assess turnover, activities, exemptions, and the current Act rather than rely on a single threshold. The statutory tort is a separate court route and is not an OAIC complaint or a conclusion that a particular broker is liable.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
What are the 13 Australian Privacy Principles (APPs)?+
The 13 APPs under Schedule 1 of the Privacy Act 1988 govern open and transparent management (APP 1), anonymity (APP 2), collection of solicited data (APP 3), unsolicited data (APP 4), notification of collection (APP 5), use and disclosure (APP 6), direct marketing (APP 7), cross-border disclosure (APP 8), government identifiers (APP 9), quality (APP 10), security (APP 11), access (APP 12), and correction (APP 13).
Do small businesses need to comply with the Privacy Act?+
Most small businesses (annual turnover under AUD 3M) are exempt from the Privacy Act, a significant gap criticized by consumer groups. However, certain small businesses are still covered: health service providers, organizations that trade in personal information (including many data brokers), credit reporting bodies, and contracted service providers to the Commonwealth.
What is the Notifiable Data Breaches scheme?+
Since February 2018, APP entities must notify affected individuals and the OAIC when a data breach is likely to result in serious harm. Notification must happen as soon as practicable after the entity becomes aware of the eligible breach; there is no universal 30-day notification deadline.
How do I file an OAIC complaint?+
Submit online at oaic.gov.au/privacy/privacy-complaints. The OAIC expects you to first complain directly to the APP entity and give them 30 days to respond. If unresolved, you can escalate to the OAIC, which can investigate, issue determinations, and apply to court for civil penalties.
What is the 'right to privacy' tort in the 2024 amendment?+
The Privacy and Other Legislation Amendment Act 2024 created a statutory tort for serious invasions of privacy. The OAIC states that it commenced on 10 June 2025. The tort has statutory elements, including seriousness, intent or recklessness, and public-interest balancing; it is separate from the OAIC complaint process, so check the current Act and obtain legal advice before relying on it.
Official sources & citations
Other international privacy regimes
Privacy Act 1988 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
