IronSights

Privacy Act 1988 · Reform tracker

Privacy Act reforms: law now, coming, or still proposed.

A lot of privacy reform commentary blurs three different things: what is already binding, what has a commencement date in the future, and what remains a government commitment. Sorted, with dates, so you know what to act on.

General guidance for Australian businesses, current as at August 2026. It is not legal advice; the law changes and your circumstances matter, so take your own advice before acting.

In force

Already binding. Act on these.

The first tranche is legislated and progressively in effect. The statutory tort is the change most likely to alter how a breach plays out for an ordinary business.

In force 10 June 2025

A statutory tort for serious invasions of privacy

Individuals can sue for serious invasions of privacy: intrusion upon seclusion, or misuse of information. It is actionable without proof of damage, which makes it a materially different risk from an OAIC complaint. Practically, a breach that exposes sensitive information now has a private-litigation tail as well as a regulatory one.

Assent 10 December 2024

Expanded penalties and enforcement

On top of the existing maximum for serious or repeated interferences (the greater of $50 million, three times the benefit, or 30 per cent of adjusted turnover), the amendments added mid-tier penalties and infringement notices so the regulator can act on smaller failures without running a full case.

In force 11 December 2024

Criminal offences for doxxing

Menacing or harassing release of personal data is now a criminal offence, with a higher penalty where the targeting is based on a protected attribute. Relevant to businesses mostly when employee data is dumped after an extortion incident.

Enacted, being implemented

Clearer overseas disclosure and a white list mechanism

Amendments to APP 8 and a mechanism to prescribe countries with substantially similar protections, which over time makes cross-border disclosure assessments simpler rather than harder.

Dated, and coming

Two obligations with December 2026 on them.

These are legislated with a deferred start, so the date is real. Both need work that starts well before the deadline.

From 10 December 2026

Automated decision-making transparency

If you use automated decision-making that significantly affects an individual's rights or interests, your privacy policy has to say so: what kinds of decisions, and what personal information is used. Twelve months' lead time was deliberate. If you have deployed AI or scoring into a customer-facing decision, this is the clause that will need writing, and the inventory behind it takes longer than the paragraph.

To be registered by 10 December 2026

The Children's Online Privacy Code

The OAIC is developing a binding code for online services likely to be accessed by children. If your product or site reaches under-18s, this will set specific expectations rather than leaving it to general APP obligations.

Proposed only

Signalled, not law. Plan for the direction.

The second tranche has been agreed in principle in large part, but nothing here binds you today, and no commencement dates are fixed. Anyone selling you compliance against these is selling you a forecast.

Government commitment, not law

Removing the small business exemption

The long-signalled second tranche would bring businesses under $3 million turnover into the Privacy Act, likely with a transition period. Nothing has passed. The exceptions that already catch small businesses (health service providers, traders in personal information, TFN recipients) apply regardless.

Proposed

A fair and reasonable test, and direct rights

Proposals include a requirement that collection, use and disclosure be fair and reasonable in the circumstances, plus stronger individual rights such as erasure. These would be the most consequential changes for ordinary businesses if enacted, and they are the least settled.

Proposed

Employee records and political exemptions

Narrowing or removing long-standing exemptions has been recommended and agreed in principle. Treat as a signal of direction, not a compliance deadline.

What to do now

The work is the same whichever way the second tranche lands.

Every proposal in the pipeline assumes you know what personal information you hold, that you protect it with reasonable steps, and that you can respond to a breach quickly. Those are already obligations under APP 11 and the NDB scheme, and they are what an OAIC determination or a statutory-tort claim will be argued about.

So the sensible sequence is: inventory, controls, breach readiness, then policy language. Not the other way round.

Four things worth doing this quarter

  • Inventory the personal information you hold, where it lives and who can reach it. Everything else depends on this.
  • Check APP 11 reasonable steps against reality: MFA, access reviews, encryption, retention and deletion.
  • List every automated decision that affects customers, ready for the December 2026 disclosure.
  • Rehearse a breach assessment: can you say what was accessed, by whom and when, within days rather than weeks?

An audit and assurance engagement covers the first two; incident response readiness covers the last.

Common questions

Asked and answered.

  1. What has actually changed in the Privacy Act?

    The Privacy and Other Legislation Amendment Act 2024 received assent on 10 December 2024. From it: a statutory tort for serious invasions of privacy commenced 10 June 2025, criminal doxxing offences commenced 11 December 2024, penalty tiers and enforcement powers were expanded, and overseas disclosure rules were clarified. Automated decision-making transparency obligations start 10 December 2026, and a Children's Online Privacy Code is to be registered by the same date.

  2. Has the small business exemption been removed?

    Not as at August 2026. Removing it is a government commitment associated with the second tranche of reforms, and no second-tranche Bill has passed. Businesses under $3 million turnover remain generally exempt, with the standing exceptions: private-sector health service providers, businesses trading in personal information, credit providers and reporting bodies, TFN recipients, and Commonwealth contracted service providers.

  3. What is the statutory tort, and does it affect my business?

    It lets an individual sue for a serious invasion of privacy, either intrusion upon seclusion or misuse of information, and it is actionable without proof of damage. For a business it means a data breach involving sensitive information can now produce private claims alongside any OAIC action, so the quality of your controls and your response is relevant to more than the regulator.

  4. We use AI in customer decisions. What do we need by December 2026?

    From 10 December 2026 your privacy policy must disclose the use of automated decision-making that significantly affects individuals' rights or interests, including the kinds of decisions and the personal information used. The writing is quick; knowing every place a model or rules engine touches a customer decision is not. Start with the inventory.

  5. Is the second tranche coming, and when?

    It has been repeatedly signalled and partly agreed in principle, but as at August 2026 it is not law and no commencement date is fixed for its major proposals (the fair and reasonable test, direct rights such as erasure, and the small business exemption). Plan for the direction, not for a specific date.

  6. What should we do now?

    Three things that are useful regardless of what passes: know what personal information you hold and where (an asset and data inventory), be able to show reasonable steps to protect it under APP 11 (which is already law and already enforced), and have a breach response that can complete an assessment in days. The reforms mostly raise the price of not doing those, rather than changing what good looks like.

Incident now, or preparing for one?

Know what you hold, before someone asks.

A data and controls review tells you what personal information you hold, whether APP 11 reasonable steps are actually in place, and how fast you could assess a breach today.