The framework
Australia regulates personal data through the Privacy Act 1988 + Australian Privacy Principles, supervised by the Office of the Australian Information Commissioner.
The posture is hybrid. Notice and purpose limitation govern collection and consent is reserved for sensitive cases, which makes first-party marketing more workable here than in strict opt-in markets.
Key instruments
Privacy Act 1988 + APPs
Thirteen Australian Privacy Principles: open and transparent management, collection limits, use and disclosure rules, direct marketing (APP 7), cross-border accountability (APP 8), security and access rights. Applies to businesses over AUD 3M turnover plus listed exceptions.
Privacy and Other Legislation Amendment Act 2024
First tranche of reform: statutory tort for serious invasions of privacy (from June 2025), automated decision transparency in privacy policies (from 10 December 2026), a Children's Online Privacy Code (to be registered by 10 December 2026), doxxing offenses, expanded OAIC powers and penalty tiers.
Spam Act 2003
Opt-in consent (express or inferred) for commercial email and SMS, sender identification and functional unsubscribe; the ACMA fines household brands regularly for unsubscribe failures.
Marketing and advertising
Collection runs on notice and fair-collection rules, with consent required for sensitive information. APP 7 lets direct marketing proceed with an opt-out where data came from the individual, opt-in otherwise. The Spam Act makes email and SMS opt-in. Most channel decisions here follow from that consent rule.
Cross-border transfers
APP 8 accountability: the discloser remains liable for overseas recipients unless an exception applies.
Enforcement and penalties
For serious interferences: the greater of AUD 50M, three times the benefit, or 30% of adjusted turnover; a mid-2020s penalty overhaul with tiers for lesser breaches.