Our Expert in Australia
No results available
This article explains the key legal and practical implications of the Australian Government’s ongoing Privacy Act reform program, in particular the anticipated “second tranche” of changes, summarises the proposed measures, sets out short-term compliance steps for businesses, and outlines how organisations can engage with consultation processes.
The Privacy Act reform program marks the most significant overhaul of the Privacy Act 1988 (Cth) in decades. The first tranche of reforms was enacted through the Privacy and Other Legislation Amendment Act 2024 (Cth), and the Australian Government has signalled that further, more structural reforms, commonly described as the “second tranche”, remain under development and consultation. These changes carry consequences for how organisations collect, use and protect personal information. For dispute resolution practitioners and in-house counsel, the reform program signals a meaningful shift in litigation and enforcement risk, particularly through a statutory tort for serious invasions of privacy (introduced in 2024) and further proposed measures such as a broader direct right of action and expanded regulator powers.
Businesses that begin preparing now will be better placed to manage exposure and to shape the final legislation.
The Privacy Act reform program is broad in scope. It re-frames baseline obligations around a positive standard of conduct, opens pathways for individuals to seek redress, and strengthens the enforcement toolkit available to the regulator. Taken together, these measures move privacy from a compliance-and-notification model towards a proactive, accountability-based regime, with real dispute consequences for organisations that fall short.
This analysis is aimed at small and medium businesses assessing whether they may lose the benefit of the current exemption, regulated entities already subject to the Act, and legal counsel advising on litigation, enforcement and contractual risk. Anyone responsible for data governance, board reporting or dispute readiness should treat the reform program as a planning trigger rather than a distant policy debate.
The Privacy Act 1988 (Cth) has been the cornerstone of federal privacy regulation for more than three decades. It established the Australian Privacy Principles and the office of the regulator, but it was drafted for an earlier technological era and has been amended incrementally rather than comprehensively. The current reform program follows the Attorney-General’s Department’s Privacy Act Review Report (released in early 2023) and the Government’s response (released in September 2023), which agreed or agreed-in-principle to a large number of proposals. It also draws on earlier analysis by the Australian Law Reform Commission on serious invasions of privacy in the digital era. The Government has chosen to modernise the Act in stages rather than in a single sweeping Bill.
The Act commenced operation in 1988 (with the private-sector provisions added later) and has been amended repeatedly, most notably to introduce credit reporting reforms, the Notifiable Data Breaches scheme (2018), and successive updates to the Australian Privacy Principles. The Privacy Act Review Report in 2023 set the agenda for the current reforms. The first tranche was enacted as the Privacy and Other Legislation Amendment Act 2024 (Cth). Further reforms addressing more contested structural proposals are expected to follow.
An exposure draft is a draft of proposed legislation released for public consultation before a Bill is formally introduced to Parliament. It gives affected parties an opportunity to test the drafting, identify unintended consequences and propose amendments. Critically, an exposure draft does not change the law. Provisions become binding only if a Bill is introduced, passes both Houses of Parliament and receives Royal Assent. Where the Government releases exposure draft materials or consultation papers for the next stage of reform, the consultation window is the mechanism through which businesses can influence the final shape of the legislation. Organisations should confirm current consultation timeframes directly with the Attorney-General’s Department.
For each major reform item below, it is helpful to understand what the current law provides, what is proposed, and the practical impact. Proposed measures should be read alongside the existing statutory text on the Federal Register of Legislation to appreciate the scope of change.
Under the Privacy Act as it currently stands, many businesses with limited annual turnover fall outside the Act’s core obligations because of the small business exemption. The reform program proposes to review and potentially remove or narrow this carve-out. The practical impact is that organisations previously outside the regime may need to comply with the full suite of privacy obligations, including notice, access, correction and security requirements. For a business that has never maintained a formal privacy program, this would represent a substantial operational and governance uplift.
The current framework relies heavily on notice and consent. The reform proposals contemplate a positive obligation that the collection, use and disclosure of personal information be fair and reasonable in the circumstances. This is significant because it would shift responsibility onto organisations to justify their handling of data proactively, rather than relying on the fact that an individual clicked “agree”. In practice, organisations would need to be able to demonstrate that each material data-handling decision was proportionate and defensible.
Historically, enforcement was largely channelled through the regulator. The Privacy and Other Legislation Amendment Act 2024 (Cth) introduced a statutory tort for serious invasions of privacy, giving individuals a cause of action in certain circumstances (commencing in 2025). Further direct rights of action for interferences with privacy under the Act itself remain under consideration in the reform program. This is among the most consequential changes from a dispute resolution perspective, because it opens the door to individual and potentially grouped claims.
The precise causes of action, standing requirements, limitation periods and available remedies should be verified against the legislation and any exposure draft text as reform progresses, but the direction of travel is clear: privacy breaches will increasingly be litigated, not merely investigated.
The reforms strengthen the OAIC’s enforcement posture. The 2024 amendments introduced additional enforcement mechanisms and a tiered civil penalty framework, including lower-tier and mid-tier penalties for interferences with privacy alongside the existing serious or repeated interference penalty. Further enhancements to investigatory and enforcement powers are under consideration. For risk teams, this means that a privacy failure that might once have resulted in an inquiry could now attract significant financial penalties and, in serious cases, court proceedings.
Modern privacy regimes increasingly emphasise individual control and the accountability of organisations that send data offshore. Where reforms strengthen obligations around cross-border transfers, including mechanisms to recognise countries with substantially similar protections, organisations that rely on overseas cloud providers, offshore processing or multinational data flows will need to review their contractual and technical safeguards. Aligning Australian practice more closely with international standards also has implications for businesses that operate across jurisdictions.
The proposed change to the small business exemption is arguably the reform with the widest reach, because it could convert a large population of previously exempt entities into regulated ones. Consultation is the moment for affected businesses to explain the practical cost and effort of compliance.
Businesses that have historically relied on the exemption, including many owner-operated enterprises, franchises and service providers, should assess whether they would be brought within the Act. Entities already handling health or other sensitive information may find that a change simply formalises obligations they should arguably have been meeting, while those with limited data-handling may face a genuinely new compliance burden. A prudent assumption during consultation is that the exemption may narrow, and to prepare accordingly.
Larger organisations frequently contract with small suppliers who currently sit outside the Act. If those suppliers become regulated, contractual data-handling clauses, warranties, indemnities and audit rights will need to be revisited. Procurement teams should begin mapping which vendors would be affected, because gaps in the contractual chain are a common source of downstream disputes when a breach occurs.
A fair and reasonable handling standard is deliberately principles-based, which gives organisations flexibility but also uncertainty. The task for compliance teams is to translate an open-textured legal standard into concrete, evidenced practice.
Organisations should build a defensible record around each significant data-handling activity. Privacy impact assessments, documented balancing exercises, data minimisation decisions and retention limits all help demonstrate that a handling decision was proportionate. Where a business collects more data than it strictly needs, retains it indefinitely, or repurposes it without a clear justification, it exposes itself to an argument that its conduct was neither fair nor reasonable, precisely the kind of allegation that could underpin a complaint or claim.
A recurring theme across the reform is accountability. It is not enough to make good decisions; organisations must be able to show that they did. That means maintaining contemporaneous records of privacy assessments, approvals and the reasoning behind data-handling choices. In any future dispute, the quality of this documentation will often determine whether an organisation can defend its position.
From a dispute resolution standpoint, the expansion of individual rights of action, including the new statutory tort for serious invasions of privacy, is the reform most likely to change day-to-day legal practice. It transforms privacy from a predominantly regulatory matter into a source of private litigation.
Where individuals can bring proceedings directly, the natural consequence is a rise in claims following high-profile data breaches or systemic mishandling. Remedies may include damages, and the aggregation of many similarly affected individuals raises the prospect of class action exposure. Organisations that hold large volumes of personal data should model this risk now, because the financial exposure from grouped claims can rival or exceed a regulatory penalty. The specific remedies and any limits should be confirmed against the legislation and any exposure draft as text is finalised.
The emergence of direct claims makes early dispute management more important than ever. Well-drafted complaints-handling processes, internal escalation procedures and access to mediation can resolve grievances before they harden into litigation. Alternative dispute resolution, including mediation and structured settlement, will be central to managing volume claims cost-effectively. Organisations should also review whether and how contractual dispute resolution mechanisms operate alongside statutory rights, recognising that statutory causes of action may not be readily displaced by private agreement.
The reforms sharpen the regulator’s teeth. Understanding the trajectory of the OAIC’s enforcement powers is essential to accurate risk modelling, because the difference between the previous and current regimes is not marginal.
The typical enforcement pathway moves from complaint or own-motion inquiry, through investigation and determination, and, where warranted, to court proceedings for civil penalties. Enhanced powers mean the regulator can investigate more effectively and escalate more readily. The OAIC also increasingly coordinates with other regulators, so a single incident may attract attention across multiple agencies. Organisations should prepare for the possibility of parallel scrutiny and ensure their incident response contemplates regulatory engagement from the outset.
Higher civil penalties change the calculus for boards. Privacy risk can no longer be treated as a minor operational matter; it belongs in enterprise risk registers alongside other material exposures. Insurance cover should be reviewed to confirm whether privacy penalties and defence costs are addressed (noting that civil penalties are commonly uninsurable as a matter of public policy), and boards should receive regular reporting on the organisation’s privacy posture.
Consultation timeframes on Privacy Act reform can be compressed, so organisations should be ready to engage promptly when exposure draft or consultation materials are released. A focused, evidence-based submission carries far more weight than a general expression of concern. Submissions are administered through the Attorney-General’s Department; organisations should verify current consultation dates on the Department’s website.
Clear asks travel furthest. A submission that isolates a small number of high-priority issues, articulates the problem, sets out the practical impact and proposes a workable alternative is more likely to influence the final Bill than a lengthy document covering every provision. The Law Council of Australia and other peak bodies also publish submissions, and reviewing the concerns raised by professional bodies can help sharpen your own contribution.
Waiting for further reforms to pass before acting would leave many organisations exposed, particularly given the measures already legislated in 2024. Because the direction of reform is now visible, sensible preparation can begin immediately and will reduce both enforcement and litigation risk.
The controls that reduce regulatory exposure are largely the same as those that defend against private claims: documented decision-making, proportionate data handling, robust security, and a demonstrable culture of accountability. Building this evidence base now means that if a dispute arises, the organisation can point to a contemporaneous record of responsible conduct.
A dispute resolution lens helps organisations anticipate how the reforms could translate into real conflict, and how to mitigate it. The following two scenarios illustrate the practical stakes.
A small services business that previously relied on the exemption suffers a breach after a reform narrowing the exemption commences. It has no privacy program, no breach-response plan and limited records of its data-handling decisions. It faces regulatory scrutiny and complaints from affected individuals, and its larger clients invoke contractual warranties. Early preparation, a privacy policy, a documented breach-response process and clean vendor contracts, would have substantially reduced both the regulatory and contractual exposure.
Following a systemic mishandling of personal information, an individual brings a direct claim, and others in a similar position consider joining. The organisation’s ability to defend itself turns on the records it can produce: did it assess the risks, minimise the data, and act proportionately? Where those records exist, early mediation may resolve the matter efficiently. Where they do not, the organisation faces a costly and public dispute. This scenario underscores why demonstrable compliance is the most effective litigation shield.
| Topic | Privacy Act 1988 (pre-2024 position) | Reform direction (legislated 2024 and/or proposed) | Practical impact |
|---|---|---|---|
| Small business exemption | Many small businesses excluded from core obligations | Proposed for review, potential narrowing or removal | More organisations may be brought into the regime; governance uplift required |
| Standard of handling | Reliance on notice and consent | Proposed positive “fair and reasonable” handling obligation | Organisations would need to justify handling proactively and keep records |
| Rights of individuals | Enforcement largely regulator-led | Statutory tort for serious invasions of privacy legislated (2024); broader direct rights under consideration | Increased litigation and potential class action exposure |
| Regulator (OAIC) powers | Existing investigatory and enforcement powers | Enhanced powers legislated in 2024; further powers under consideration | Greater likelihood of investigation and escalation |
| Penalties | Serious or repeated interference penalty framework | Tiered civil penalty regime introduced in 2024 | Higher financial stakes; board-level risk management needed |
| Commencement | In force | 2024 measures commencing progressively; further measures subject to enactment | Timing and phasing will shape compliance planning |
The Attorney-General’s Department continues to develop the next stage of reforms informed by consultation. Where exposure draft or consultation materials are released, the Department considers feedback and finalises drafting before a Bill is introduced to Parliament. The usual legislative process then applies: debate, potential committee scrutiny, amendment and passage through both Houses before Royal Assent. Industry observers expect that the substance of any broader direct right of action, the small business exemption and the penalty framework will attract significant attention. Organisations should monitor the Parliament of Australia website for introduced legislation and the OAIC and Attorney-General’s Department websites for guidance and consultation updates, and track any transitional provisions closely, as commencement timing will drive compliance deadlines.
As the Privacy Act reform program advances, organisations face a narrowing window to influence future reforms and a longer road to compliance with measures already legislated. Global Law Experts can assist with tailored consultation submissions, dispute resolution planning, litigation readiness assessments and practical privacy compliance uplift. For guidance from a Dispute Resolution expert, contact the Global Law Experts team to discuss how the reforms affect your organisation and what to prioritise now.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jim Harrowell at Hunt & Hunt Lawyers, a member of the Global Law Experts network.
posted 34 minutes ago
posted 58 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message