Don’t do SECURITY. Do business SECURELY.

Australia passes major Privacy Act reforms

The Privacy and Other Legislation Amendment Act 2024 adds a statutory privacy tort, new OAIC powers and automated decision-making transparency.

The Privacy and Other Legislation Amendment Act 2024 receives Royal Assent today, delivering the first tranche of reforms to Australia’s Privacy Act 1988.

Key points

  • A new statutory tort for serious invasions of privacy.
  • Clarification that APP 11 reasonable steps include technical and organisational measures.
  • New tiered civil penalties and infringement notice powers for the OAIC.
  • Privacy policies must disclose certain automated decisions that significantly affect individuals.
  • A framework for a Children’s Online Privacy Code and a whitelist mechanism for overseas transfers.

The Privacy Act applies to overseas organisations carrying on business in Australia. UK organisations with Australian customers or staff should review security measures, breach readiness and automated decision-making disclosures.

Source: Privacy and Other Legislation Amendment Act 2024 (Federal Register of Legislation)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights