Data Protection Matters
← All privacy laws

Australia

Privacy Act 1988

Privacy Act 1988 (Cth)

Keywords

Privacy Act 1988AustraliaCthAustralian Privacy PrinciplesAPPsOAICNotifiable Data BreachesNDB schemeeligible data breachAPP entitysmall business exemptioncredit reportingtax file numberstatutory tort
Plain-English overview, not the law. This is a general summary we wrote to help you get oriented. It is not legal advice, it is not binding, and it may simplify, omit, or get things wrong. We also cannot guarantee that the source we link to is the correct, current, or official text; we may have linked or labelled it wrong. For anything that matters, find and read the law itself and seek advice for your situation.

What it is

The Privacy Act 1988 is Australia's principal federal privacy law. It regulates how Australian Government agencies and many private-sector organizations handle personal information, mainly through the thirteen Australian Privacy Principles (APPs) set out in Schedule 1. The Act also contains specific rules for credit reporting, tax file numbers and the notification of data breaches. It has been amended repeatedly, most significantly in 2022 and 2024.

Who it applies to

The APPs bind "APP entities", which are Australian Government agencies and organizations, including companies, trusts and individuals acting in business. Most small businesses with annual turnover of 3 million Australian dollars or less are exempt, though not if they, for example, provide health services, trade in personal information or are related to a larger business. Employee records held by private employers, and registered political parties in certain activities, are also exempt. The Act applies to overseas organizations that carry on business in Australia and collect personal information there.

Core principles

The APPs cover the full information lifecycle: open and transparent management, anonymity and pseudonymity, collection, dealing with unsolicited information, notification of collection, use and disclosure, direct marketing, cross-border disclosure, government identifiers, quality, security, and access and correction. Entities must take reasonable steps to implement practices that ensure compliance. Stricter rules apply to sensitive information, such as health, biometric and racial or ethnic origin data.

Individual rights

Individuals can ask to access the personal information an entity holds about them (APP 12) and to have it corrected if it is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13). They can also opt out of direct marketing and complain to the entity, and then to the regulator. The Act does not contain a general right to erasure or data portability. The 2024 amendments added a statutory tort that allows individuals to sue for serious invasions of privacy, which began operating in 2025.

Key obligations

Entities must collect only what is reasonably necessary, tell individuals about the collection, use personal information only for the purpose it was collected or a permitted related purpose, and keep it secure, destroying or de-identifying it when it is no longer needed. When disclosing information overseas, an entity generally remains accountable for the recipient's handling of it (APP 8). The 2024 amendments also introduced a Children's Online Privacy Code and new transparency requirements for automated decisions that significantly affect individuals.

Data breaches

Under the Notifiable Data Breaches scheme in Part IIIC, in force since February 2018, an entity must notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when an eligible data breach occurs. A breach is eligible when there is unauthorised access to or disclosure of personal information, or a loss of it, that is likely to result in serious harm. If an entity only suspects a breach, it must complete a reasonable and expeditious assessment, generally within 30 days.

Enforcement and penalties

The OAIC investigates complaints, conducts assessments and can seek enforcement through the Federal Court. Following reforms in 2022, the maximum civil penalty for a serious or repeated interference with privacy is the greatest of 50 million Australian dollars, three times the benefit obtained from the conduct, or 30% of the entity's adjusted turnover during the breach period. The OAIC can also issue infringement notices and make determinations that include compensation.

The official text

The authoritative version is the Privacy Act 1988 as published on the Federal Register of Legislation at legislation.gov.au. Use that text, not this summary, for anything that matters.

Below is the source we understand to be the official text (English, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:

Go to the source →