DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Oceania · In force · Hybrid

🇦🇺 Australia Data Privacy Laws

Australia's Privacy Act is old but newly dangerous. The 2022 penalty overhaul raised ceilings to AUD 50M or 30% of turnover, and the December 2024 amendment package added a statutory tort for serious invasions of privacy (live since June 2025), criminal doxxing offenses, and two duties landing on 10 December 2026: privacy policies must disclose automated decisions that significantly affect individuals, and the OAIC must register a Children's Online Privacy Code, released in exposure draft this year. The bigger 'tranche 2' rewrite, including a fair-and-reasonable test and the fate of the small-business exemption, remains pending.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Hybrid
Primary law
Privacy Act 1988 + Australian Privacy Principles, amended 2024
Year
1988
Authority
Office of the Australian Information Commissioner (OAIC)
Marketing consent
Collection runs on notice and fair-collection rules, with consent required for sensitive information. APP 7 lets direct marketing proceed with an opt-out where data came from the individual, opt-in otherwise. The Spam Act makes email and SMS opt-in.
Transfers
APP 8 accountability: the discloser remains liable for overseas recipients unless an exception applies.
Penalties
For serious interferences: the greater of AUD 50M, three times the benefit, or 30% of adjusted turnover; a mid-2020s penalty overhaul with tiers for lesser breaches.

The framework

Australia regulates personal data through the Privacy Act 1988 + Australian Privacy Principles, supervised by the Office of the Australian Information Commissioner.

The posture is hybrid. Notice and purpose limitation govern collection and consent is reserved for sensitive cases, which makes first-party marketing more workable here than in strict opt-in markets.

Key instruments

Privacy Act 1988 + APPs

1988 · In force

Thirteen Australian Privacy Principles: open and transparent management, collection limits, use and disclosure rules, direct marketing (APP 7), cross-border accountability (APP 8), security and access rights. Applies to businesses over AUD 3M turnover plus listed exceptions.

Official source →

Privacy and Other Legislation Amendment Act 2024

2024 · In force (staged)

First tranche of reform: statutory tort for serious invasions of privacy (from June 2025), automated decision transparency in privacy policies (from 10 December 2026), a Children's Online Privacy Code (to be registered by 10 December 2026), doxxing offenses, expanded OAIC powers and penalty tiers.

Official source →

Spam Act 2003

2003 · In force

Opt-in consent (express or inferred) for commercial email and SMS, sender identification and functional unsubscribe; the ACMA fines household brands regularly for unsubscribe failures.

Official source →

Marketing and advertising

Collection runs on notice and fair-collection rules, with consent required for sensitive information. APP 7 lets direct marketing proceed with an opt-out where data came from the individual, opt-in otherwise. The Spam Act makes email and SMS opt-in. Most channel decisions here follow from that consent rule.

Cross-border transfers

APP 8 accountability: the discloser remains liable for overseas recipients unless an exception applies.

Enforcement and penalties

For serious interferences: the greater of AUD 50M, three times the benefit, or 30% of adjusted turnover; a mid-2020s penalty overhaul with tiers for lesser breaches.

Primary sources

Cite this page: "Australia Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/australia.html. Accessed [date].