The legal framework
The Privacy Act applies to federal agencies and to businesses above a turnover threshold, and is built around thirteen Australian Privacy Principles. The Notifiable Data Breaches scheme requires notification of eligible breaches. Reforms passed in 2024 created a statutory tort for serious invasions of privacy and increased enforcement powers.
Key points
| Access and correction | APP 12 and 13, generally within 30 days |
|---|---|
| Small business exemption | Businesses under the turnover threshold are largely exempt — a long-criticised gap |
| Breach notification | Mandatory for eligible data breaches, to the OAIC and affected individuals |
| Sensitive information | Health, sexual orientation and sexual practices require consent |
| Statutory tort | Serious invasions of privacy actionable following the 2024 reforms |
| Children | A Children's Online Privacy Code is being developed |
| Regulator | Office of the Australian Information Commissioner |
| Notifiable breaches | Must be reported to the regulator and to affected individuals |
| Determinations | The Commissioner can award compensation, including for non-economic loss |
| Credit reporting | A separate, detailed part of the Act with its own complaint route |
In practice
- Write to the organisation first, citing the relevant statutory right; keep proof of the date.
- Set out clearly what you want: a copy of your data, deletion, or an end to marketing.
- If there is no adequate reply within the statutory period, complain to the regulator — it is free.
- For dating, health and fertility apps, ask specifically about third-party sharing and overseas transfers.
- Complain to the organisation and allow 30 days before approaching the Commissioner.
- For credit file errors, use the credit reporting provisions — they have shorter deadlines.
Cost and coverage
Free complaints to the OAIC; the new tort allows damages claims in court.
Recent changes
The 2024 package was the first substantial modernisation of the Privacy Act in decades, and further tranches of reform have been foreshadowed.
Where to go
- Office of the Australian Information Commissioner.
- State privacy commissioners for state agencies.
- IDCARE for identity and cyber support.
Worth knowing
The small business exemption means many everyday services are not covered at all. Check whether the organisation is actually subject to the Act before building a complaint around it. Unlike many regulators, the Australian Commissioner can award compensation directly, including for distress. That makes the complaint route worth using.
Official sources and links
- Federal Register of Legislation — Commonwealth law as made and in force
- Services Australia — government services and payments
