Australia’s privacy laws have changed more in the last two years than in the previous decade. Maximum penalties for serious or repeated breaches now sit at the greater of AUD 50 million, three times the benefit gained from the breach, or 30% of adjusted turnover. That is a jump from the old AUD 2.2 million cap, and it applies to any business that handles personal information above the turnover threshold. For a mid-market brand doing AUD 120 million a year, a single compliance failure can now cost more than most marketing budgets.
Disclosure: Some links on this page are affiliate links. If you make a purchase through them, Britwealth may earn a commission at no extra cost to you. We only include products and services that are relevant to the topic.
This article is general information only and does not constitute professional advice. For your specific situation, consult a qualified professional.
The first wave of reforms is already law. The Privacy and Other Legislation Amendment Bill 2024 passed Parliament in late 2024, implementing 23 proposals from the government’s review. More are coming, with 2026 flagged as a key period for new obligations. The Office of the Australian Information Commissioner (OAIC) has already started flexing its new powers — a proactive compliance sweep in January 2026 reviewed roughly 60 entities. If your business collects customer details, runs email marketing, stores payment information, or uses third-party tools, these changes affect you. Here’s what you actually need to know.
The central concept here is the Australian Privacy Principles (APPs).
What I tend to notice is that most business owners know the APPs exist but have never read them. That gap is where the real exposure sits. The OAIC doesn’t need you to have intended a breach — it needs to show you didn’t take reasonable steps. If you want a practical starting point, understanding how AI tools handle your customer data is a good place to begin, because many of them process information overseas.
What the New Penalty Regime Actually Means for Your Business
The old AUD 2.2 million cap was, for many businesses, a manageable risk. A breach might sting, but it wouldn’t sink the company. The new structure changes that calculation entirely. The penalty is now the greater of AUD 50 million, three times the value of any benefit obtained through the breach, or 30% of the company’s adjusted turnover during the relevant period. For a business turning over AUD 10 million, that 30% figure alone is AUD 3 million — and it scales fast.
The OAIC has already demonstrated it will use these powers. In October 2025, Australian Clinical Labs received an AUD 5.8 million penalty, with AUD 1.6 million of that specifically for failing to comply with Notifiable Data Breach (NDB) notification requirements. The AUD 50 million settlement with Meta Platforms in December 2024 signals that the regulator is targeting the top end of the scale. Ongoing Federal Court proceedings against Optus (9.5 million affected individuals from the 2022 breach) and Medibank (9.7 million affected individuals) show that the enforcement pipeline is full.
For sole traders and partnerships, the risk is personal. Unlike a limited company where the business entity bears the fine, a sole trader’s personal assets are on the line. The distinction matters because the Privacy Act applies to the entity, and if that entity is you personally, so is the penalty. The small business exemption currently protects businesses under AUD 3 million turnover, but that exemption is under active review and expected to be removed.
Common Compliance Gaps That Create Real Exposure
Treating the Privacy Policy as a One-and-Done Document
Many businesses wrote a privacy policy years ago and haven’t touched it since. The OAIC can issue infringement notices of up to AUD 66,000 per contravention for core breaches such as maintaining a non-compliant privacy policy. A policy that doesn’t reflect actual data practices — like undisclosed third-party tracking pixels, marketing automation, or overseas data storage — is worse than no policy at all because it misleads individuals about how their information is handled. The fix requires a full audit of what data you collect, where it goes, and who processes it, then rewriting the policy to match reality.
Ignoring the 30-Day NDB Assessment Clock
Under Part IIIC of the Privacy Act, an entity must assess within 30 days whether unauthorised access, disclosure, or loss of personal information is likely to result in serious harm. If it is, you must notify the OAIC and affected individuals as soon as practicable. The Australian Clinical Labs case shows what happens when you get this wrong — AUD 1.6 million of their penalty came from NDB notification failures alone. The assessment period is not a suggestion; it’s a legal deadline. Miss it and the penalty compounds.
Assuming Overseas Vendors Are Someone Else’s Problem
APP 8 is blunt: if you disclose personal information to an overseas recipient, you must take reasonable steps to ensure they handle it in accordance with the APPs. If they breach, you are treated as having breached. The exceptions are narrow — substantially similar overseas law that individuals can enforce, informed consent after warning that APP 8 protections won’t apply, or a legal requirement to disclose. Most standard cloud service agreements don’t meet these exceptions. What I’d do here is review every third-party tool that touches customer data and document whether the recipient is overseas and what protections are in place.
Not Planning for Erasure Requests
Australia doesn’t yet have a statutory right to erasure, but the direction of reform is clear. The government has agreed in principle to stronger individual rights, including deletion-style requests. Even without a formal right, the OAIC expects businesses to handle access and correction requests under APP 12 and APP 13. If you can’t find and delete a customer’s data within a reasonable timeframe, you have a data mapping problem. Start now by documenting where personal information lives — CRM, email platform, accounting software, cloud storage, paper files — and how you would action a deletion request without breaking tax record-keeping obligations.
How to Build a Privacy Framework That Holds Up Under Scrutiny
Map Your Data Flows Before the Regulator Does
You cannot comply with the APPs if you don’t know what personal information you hold, why you hold it, where it came from, and who has access. A data map is the foundation document. List every system that touches personal data — website contact forms, email marketing platforms, CRMs, payment processors, booking tools, CCTV, HR files, cloud storage. For each, note the type of data collected, the legal basis for collection, retention period, and any overseas recipients. This map becomes the evidence you show the OAIC if they ask. Without it, you cannot demonstrate reasonable steps.
Rewrite Your Privacy Policy to Match Actual Practices
A compliant privacy policy under the APPs must cover what personal information is collected, how it’s used, who it’s disclosed to, how individuals can access and correct it, and how they can complain. If you use tracking pixels, marketing automation, or share data with overseas vendors, those must be disclosed. The policy should be written in plain language and placed prominently on your website. A policy that says “we may share data with third parties” without naming them or explaining why is unlikely to satisfy the OAIC’s expectations post-reform.
Build a Breach Response Plan That Works Under Pressure
The NDB scheme gives you 30 days to assess whether a breach is likely to result in serious harm. That assessment window is not the time to figure out who to call. A breach response plan should name the person responsible for the assessment, outline the criteria for determining serious harm, include templates for OAIC and individual notifications, and list external contacts (legal, forensic IT, PR). Test the plan with a tabletop exercise at least once a year. The difference between a contained breach and a board-level disaster is often how fast you move in the first 48 hours.
Review Vendor Contracts for APP 8 Compliance
Every vendor that processes personal information on your behalf needs a contract that requires them to comply with the APPs or equivalent protections. For overseas vendors, the bar is higher. You need to confirm that the recipient country has substantially similar privacy laws that individuals can enforce, or obtain explicit informed consent from individuals after warning them that APP 8 protections won’t apply. Most SaaS terms of service don’t meet this standard. A practical step is to review your digital transformation tools and identify which ones transfer data across borders.
Prepare for the 2026 Obligations Now
The second tranche of reforms is expected to include removal of the small business exemption, stronger individual rights (including erasure and data portability), and tighter rules around automated decision-making and sensitive information. From 1 July 2026, real estate agents, lawyers, accountants, conveyancers, and precious metals dealers will be brought under the Act through AML/CTF reforms regardless of turnover. If you fall into one of those categories, you have no exemption to rely on. Start your compliance work before the obligations land, not after.
→ Scroll right to see all columns
| Obligation | Current Status (May 2026) | Expected Change |
|---|---|---|
| Small business exemption | Businesses under $3M turnover exempt | Removal agreed in principle; no confirmed date |
| Right to erasure | Not legislated | Proposed for tranche 2 reforms |
| Data portability | Not legislated | Proposed for tranche 2 reforms |
| AML/CTF expansion | Not yet in force | From 1 July 2026 for specified professions |
| Statutory tort for privacy | Commenced 10 June 2025 | In force — individuals can sue |
| Maximum penalty | $50M / 3x benefit / 30% turnover | Already in force |
Frequently Asked Questions About Australian Data Privacy
Does the Privacy Act apply to my business if I earn under $3 million? ▾
What is the difference between the GDPR and Australia’s Privacy Act? ▾
Can an individual sue me directly for a privacy breach? ▾
What happens if I use a cloud service based in the US? ▾
How long do I have to notify the OAIC after a data breach? ▾
Do I need to appoint a Data Protection Officer? ▾
The Privacy Shift Is Structural, Not Temporary
The reforms passing through Parliament are not a one-off adjustment. The 116 proposals from the Privacy Act Review represent a fundamental rewrite of how Australia regulates personal information. The first tranche is law, the second is coming, and the enforcement machinery is already running. Businesses that treat privacy as a compliance checkbox rather than an operational requirement are the ones that will face the test cases. The cost of getting it wrong is no longer a fine you can absorb — it’s a penalty that can reshape your business.
Remember: this article is general information only. For advice on your specific situation, speak to a qualified professional.
If this was useful, you might also want to read The Rise of the Conscious Consumer: Meeting the Demands of Ethical Australians.
Sources and Further Reading
The AI Disruption: Opportunities and Threats for Australian Businesses and Workers — Explores how AI tools intersect with data privacy obligations and what businesses need to watch.
Digital Transformation: Are Australian Businesses Keeping Up? — Covers the technology decisions that create privacy exposure and how to manage vendor risk.
Recording Law (2026). Australia Data Privacy Laws. 🔗
Digital One Agency (2026). Australian Privacy Law Changes 2026: Get Fined $50M or Turn It Into a 7-Figure Revenue Stream. 🔗
Sprintlaw (2026). Upcoming Privacy Changes Australia. 🔗
Hall & Wilcox (2026). Privacy Penalties: The Beginning of a New Era. 🔗

