← All guides
Australia Privacy14 min read22 July 2026

Australia Privacy Act 2024 Amendments: Statutory Tort, NDB Scheme Updates & OAIC Enforcement (2026)

Complete guide to the Privacy and Other Legislation Amendment Act 2024 (Australia) — statutory tort for serious invasions of privacy, enhanced OAIC enforcement powers (up to AUD $50M), NDB scheme updates, doxxing offences, Children's Online Privacy Code framework, and practical compliance steps for Australian entities and multinationals.

Australia's Privacy Act reforms: what changed in 2024?

On 29 November 2024, Australia's Privacy and Other Legislation Amendment Act 2024 received Royal Assent, implementing the most significant reforms to the Privacy Act 1988 (Cth) in a generation. The reforms follow years of review — including the Australian Law Reform Commission's 2008 recommendations and the Attorney-General's Department's 2022 Privacy Act Review Report — and were accelerated by high-profile data breaches at Optus (2022) and Medibank (2022), which exposed millions of Australians' personal and health data.

The 2024 Act does not replace the Privacy Act 1988 or the Australian Privacy Principles (APPs). Instead, it layers significant new obligations on top of the existing framework. For organisations already compliant with the APPs and the Notifiable Data Breach (NDB) scheme, the 2024 reforms require updates in three main areas: privacy tort risk management, enforcement readiness, and children's data handling.

The Privacy Act 1988 and Australian Privacy Principles — the foundation

Before covering the 2024 amendments, it is worth understanding the baseline framework. The Privacy Act 1988 (Cth) governs how Australian Government agencies and private sector organisations handle personal information. The 13 Australian Privacy Principles (APPs) — introduced by the Privacy Amendment (Enhancing Privacy Protection) Act 2012 — set out the rules for collection, use, disclosure, security, retention, and individual rights. Key principles include:

  • APP 1: Open and transparent management — privacy policy in clear, up-to-date form; Privacy Management Framework documented and implemented.
  • APP 3: Collection of solicited personal information — only collect information reasonably necessary for functions or activities; sensitive information requires consent.
  • APP 5: Notice of collection — inform individuals at or before collection of purposes, recipients, overseas disclosures, and rights.
  • APP 6: Use and disclosure — only use or disclose for the primary purpose of collection or with consent (or a listed exception).
  • APP 7: Direct marketing — provide opt-out; no sensitive information for direct marketing without consent.
  • APP 8: Cross-border disclosure — take reasonable steps to ensure overseas recipients comply with the APPs; accountability for overseas handling.
  • APP 11: Security of personal information — reasonable steps to protect from misuse, interference, loss, unauthorised access, modification, or disclosure; destroy or de-identify when no longer needed.
  • APPs 12 and 13: Access and correction — 30-day response; no excessive fee for making a request; refused correction must be notated.

The Privacy Act exempts small businesses with an annual turnover below AUD $3 million from most obligations — though important carve-outs exist (health service providers, credit reporting, government-contracted businesses, businesses that opt in voluntarily, and those that trade in personal information are all subject to the Act regardless of turnover).

Statutory tort for serious invasions of privacy

The most far-reaching 2024 reform is the introduction of a statutory cause of action for serious invasions of privacy. For the first time, individuals in Australia have a direct right of legal action against entities — including private companies — that seriously invade their privacy, without needing to rely on a patchwork of common law and equitable doctrines.

The tort covers two categories:

  • Intrusion upon seclusion: An intentional or reckless intrusion into the claimant's private affairs or physical space. Examples include surveillance, tracking location without consent, or accessing private accounts.
  • Misuse of private information: Obtaining, using, or disclosing the claimant's private information without consent where a reasonable person in the claimant's position would have had a reasonable expectation of privacy.

For a claim to succeed, the invasion must be serious — not every technical breach will suffice. The claimant must show: an intentional or reckless act by the defendant; a reasonable expectation of privacy in the circumstances; and that the invasion was serious in its nature and effect. Courts will weigh countervailing public interest factors, including freedom of expression, freedom of the press, and the right to information.

Remedies available include: damages (including non-economic loss for distress and humiliation); injunctions; account of profits; and declarations. Importantly, aggravated and exemplary damages are available in serious cases. For organisations, the tort creates liability for employees who act in the course of employment, under standard vicarious liability principles.

Practical implications: Organisations should audit their data collection, monitoring, and employee privacy practices. Employee monitoring (keystroke logging, location tracking, email monitoring) needs to be proportionate and disclosed. Data leakage to third parties — including poorly secured cloud vendors — could give rise to tort claims if the leak involves sensitive personal information. The tort is not retrospective, but claims based on conduct after Royal Assent (November 2024) are now actionable.

Enhanced OAIC enforcement powers

The 2024 Act significantly strengthens the Office of the Australian Information Commissioner's (OAIC) enforcement toolkit. Previously, the OAIC's primary remedy was a determination requiring compensation (often limited in practice) or an enforceable undertaking. The 2024 reforms introduce:

  • Civil penalty proceedings: The OAIC can apply to the Federal Court for civil penalties of up to AUD $50 million (body corporate) or AUD $2.5 million (individual) for serious or repeated interferences with privacy. This brings Australia broadly in line with GDPR-level enforcement potential.
  • Infringement notices: The OAIC can issue infringement notices for NDB scheme failures — specifically, for failing to notify the OAIC of an eligible data breach — without going to court. Fixed penalties apply per notice.
  • Compliance notices: The OAIC can issue compliance notices requiring organisations to take specific action to remedy privacy breaches within a stated timeframe.
  • Public interest determinations: Enhanced powers to make public interest determinations that bind organisations.

The Optus and Medibank data breaches — both in 2022 — are widely understood to have driven these enforcement reforms. The OAIC has already commenced civil penalty proceedings against Medibank in relation to the 2022 breach. Expect the OAIC to use these new powers actively in 2025-2026.

Notifiable Data Breach (NDB) scheme — updates and enforcement

The NDB scheme, introduced in February 2018 under Part IIIC of the Privacy Act, requires organisations to notify the OAIC and affected individuals when an eligible data breach occurs. An eligible data breach is: unauthorised access to, or disclosure of, personal information (or loss of information in circumstances likely to lead to unauthorised access or disclosure) that is likely to result in serious harm to any individual whose information is involved.

The 2024 Act updates the NDB scheme in several ways:

  • The OAIC's new infringement notice power creates a direct financial consequence for NDB notification failures — previously, enforcement required a lengthy investigation and determination process.
  • The serious harm threshold remains, but the OAIC has published updated guidance clarifying that the test is objective — whether a reasonable person in the same circumstances would conclude serious harm is likely — not whether harm has already materialised.
  • The 30-day assessment obligation (to complete a reasonable and expeditious assessment of whether a breach is eligible) is reinforced; organisations that fail to assess within 30 days face enforcement risk.

NDB process in practice:

  1. Detect and contain the incident.
  2. Assess within 30 days whether it is an eligible data breach (likelihood of serious harm test).
  3. If eligible: notify OAIC via Statement of Eligible Data Breach (SEDB) as soon as practicable.
  4. Notify affected individuals directly (or by public substitution notice where direct notification is not practicable).
  5. Complete post-incident review and document lessons learned.

Doxxing offences

The 2024 Act introduces criminal offences for malicious disclosure of personal information — commonly called doxxing. Two offences are created in the Criminal Code (Cth):

  • Disclosing personal data about a person to the public where the disclosure is motivated by malice and causes or is likely to cause the victim to fear for their safety.
  • Disclosing personal data about a group of people based on a protected characteristic (race, sex, sexual orientation, etc.) where the disclosure is calculated to cause harm.

For organisations, the doxxing offences are primarily relevant to the conduct of employees or users on platforms. Content moderation policies, data handling practices, and employee codes of conduct should be reviewed to ensure no organisational activity could contribute to or enable doxxing conduct.

Children's Online Privacy Code

The 2024 Act creates a framework for the OAIC to register a Children's Online Privacy Code — a privacy code specifically targeting online services directed at or likely to be used by children (under 16 years). The Code, when finalised and registered, will impose age-appropriate design requirements, including:

  • No dark patterns that manipulate children into providing more personal information than necessary.
  • No behavioural profiling of children for commercial purposes without verifiable parental consent.
  • No targeted advertising to children without explicit parental consent.
  • Default high privacy settings for accounts created by children.
  • Data minimisation requirements beyond the general APPs.

As of mid-2026, the Code is being consulted on by the OAIC. Organisations with services likely to be used by children should begin age-appropriate design reviews now in anticipation of the Code's registration.

Cross-border disclosures (APP 8)

APP 8 remains the governing framework for cross-border transfers. Before disclosing personal information to an overseas recipient, Australian entities must take reasonable steps to ensure the recipient does not breach the APPs in relation to the information — and are then accountable as if they had handled the information themselves. The APP 8.2 exception — where the individual consents after being informed that the Australian entity will no longer be accountable — must be used carefully and not as a default mechanism to avoid accountability.

The 2024 reforms did not introduce a new adequacy framework, but the statutory tort and enhanced penalties mean that getting cross-border accountability wrong carries higher stakes. Organisations transferring personal information to overseas cloud providers, SaaS vendors, or group entities should review their Data Processing Agreements and consider transfer impact assessments for high-risk destinations.

Assess your Australia Privacy Act 2024 compliance

The Australia Privacy Act 2024 Amendments Checker covers 42 key obligations across six categories: APP governance and collection (privacy policy, Privacy Management Framework, anonymity, collection notice, sensitive information consent, use and disclosure, direct marketing), data quality, security and retention (APP 10 data quality, APP 11 security safeguards, destruction and de-identification, retention schedule, security testing), individual rights (access within 30 days, access exceptions, no excessive request fee, correction right, refused correction notation, complaints handling, OAIC complaint referral), cross-border disclosure and 2024 reforms (APP 8 accountability, transfer exceptions, statutory tort risk, Children's Online Privacy Code readiness, doxxing offences review, NDB enhancements, AUD $50M penalty risk), notifiable data breach scheme (eligible data breach definition, 30-day assessment, OAIC SEDB notification, individual notification, breach procedure, breach register, annual simulation), and governance and OAIC enforcement (Privacy Management Framework, Privacy Officer, PIAs, 2024 enforcement powers readiness, health information compliance, staff training, privacy code applicability).

Related tools

See also: Singapore PDPA Compliance Checker, India DPDP Act Compliance Checklist, APRA CPS 230 Operational Risk, GDPR Compliance Audit, DPIA Generator.