privacy compliance

Are your privacy practices up to date with the amended Privacy Act 1988 (Cth)?

HomePrivate: BlogLegal insightsAre your privacy practices up to date with the amended Privacy Act 1988 (Cth)?

by

reviewed by

Malcolm Burrows

Business and government organisations need to prepare for changes to the Privacy Act 1988 (Cth) (Privacy Act) that will take effect on 12 March 2014.

The reforms introduce thirteen (13) new Australian Privacy Principles (APPs) that replace the previous National Privacy Principles and Information Privacy Principles.  Most importantly, Schedule 4 of the Privacy Amendment (Enhancing Privacy Protection) Act 2012[1] establishes a civil penalty regime that allows the Federal Court or the Federal Circuit Court to order significant penalties for non-compliance.

The civil penalty regime includes penalties of:

  • $340,000 for individuals; and
  • $1.7 million for a company in breach of the APPs.

The Privacy Act also provides the Privacy Commissioner with new powers including the power to conduct compliance assessments, make compliant determinations, issue enforceable undertakings and institute its ‘own motion’ investigations.

The reforms require organisations to make changes to their:

  • policy, procedures and organisational practices to comply with the APPs (APP 1.2);
  • the content of privacy policies (APP 1.3-1.6);
  • the collection of solicited and unsolicited personal information (APP 3);
  • notification and disclosure procedures (APP 5-6);
  • direct marketing communication (APP 7.6-7.8);
  • information quality assurance and data security (APP 10-11); and
  • sending of information off-shore (APP 8).

Complying with the reforms

There are several steps organisations should take to ensure their policies and procedures are up-to-date.  This will necessarily depend of the circumstances of the organisation, the practices it adopts and the type of personal information it collects.

Privacy review

Organisations should consider conducting a “privacy review” in the context of their current business practices.  This allows potential issues to be identified and new procedures instigated.

A privacy review requires understanding how the organisation collects, stores and discloses personal information.  Under section 6 of the Privacy Act personal information is:

information or an opinion (including information or an opinion forming part of a database), whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion.

Implementation

The APPs require that a business take reasonable steps to implement policies and procedures that comply with the APPs.  This obligation may require a business to introduce a compliant resolution process; train staff concerning their obligations under the Privacy Act and appoint a ‘Privacy Contact Officer’ or ‘Chief Privacy Officer’.

Privacy policy

Under APP 1 organisations should amend their privacy policy to ensure it includes:

  • a complaints procedure;
  • sufficient detail of the kind of personal information the organisation collects and the purpose for which information is collected;
  • whether the organisation is likely to disclose information to overseas recipients and what countries this may include;
  • information relating to direct marketing; and
  • ensure the privacy policy is available free of charge and presented in an appropriate form.

Compliance tips

The APPs require organisations take active steps to comply with the principles.  Organisations should:

  •  provide individuals with opportunity for anonymity and pseudonymity (APP 2).
  • notify individuals prior to collection of personal information that the privacy policy contains relevant information regarding overseas disclosure, complaint mechanisms and how to access and correct their information (APP 5);
  • where possible provide users with an opt out option for all marketing correspondence (APP 7.6(c);
  • ensure marketing information is only sent to individuals who would reasonable anticipate receiving it and note the source of the personal information (APP 7.6-7.8);
  • ensure overseas recipients of personal information store and use information in accordance with APPs (as organisations can be held vicariously liable for not taking adequate precautions, organisations should seek an indemnity if compliance cannot be met) (APP 8);
  •  keep accurate and complete records of personal information (APP 10-11);
  • provide individuals with the ability to access and correct their information (APP 12-13); and

Links and further references

Office of the Australian Information Commissioner, APP Guidelines

Office of the Australian Information Commissioner, Australian Privacy Principles

Office of the Australian Information Commissioner, Privacy Information Fact Sheet 17: Australian Privacy Principles

Office of the Australian Information Commissioner, Protecting Customers’ Personal Information

Further information

If you need further information about making your business compliant with the Australian Privacy Principles, contact us for a confidential and obligation-free discussion:

[1] Privacy Amendment (Enhancing Privacy Protection) Act 2012 Sch 4 PartVIB section 80W.


Related insights about privacy compliance

  • Bill to allow victims of AI deepfakes to sue for emotional damages

    Bill to allow victims of AI deepfakes to sue for emotional damages

    On 24 November 2025, Senator David Pocock introduced a private Senator’s bill, the Online Safety and Other Legislation Amendment (My Face, My Rights) Bill 2025 (Cth) (Bill) to amend the Online Safety Act 2021 (Cth) (Online Safety Act) and the Privacy Act 1988 (Cth) (Privacy Act). 

    Read more …

  • Malcolm Burrows on ABC’s “Legal Eagles” segment – Deepfakes

    Malcolm Burrows on ABC’s “Legal Eagles” segment – Deepfakes

    On 3 December 2025, Malcolm Burrows appeared live on Katherine Feeney’s ABC Radio program, “Legal Eagles” as the Technology and Intellectual Property Lawyer to discuss the proposed amendments to the Online Safety Act 2021 (Cth) through the introduction of the Online Safety and other legislation Amendment (My Face Rights) Bill (Cth) 2025 (My Face Rights…

    Read more …

  • OAIC publishes new guidance for under-16s social media ban

    OAIC publishes new guidance for under-16s social media ban

    On 10 October 2025, the Office of the Australian Information Commissioner (OAIC), led by Privacy Commissioner, Ms Carly Kind, released a twenty-nine (29) page Privacy Guidance on Part 4A (Social Media Minimum Age) of the Online Safety Act 2021 (New Guidance).  This New Guidance details the privacy obligations for Age-Restricted Social Media Platforms (Restricted Platforms)…

    Read more …

  • Aust Clinical Labs fined $5.8mil for failing to report data breach

    Aust Clinical Labs fined $5.8mil for failing to report data breach

    On 8 October 2025, the Federal Court published the judgement of Justice Halley in the case of Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224 (AIC v ACL).  Australian Clinical Labs Limited (ACL) was ordered to pay $5.8 million in civil penalties in relation to a 2022 data breach.  This…

    Read more …

  • Federal Government releases report into age verification trials

    Federal Government releases report into age verification trials

    On 31 August 2025, the Australian Government published the Final Report (Report) on the Age Assurance Technology Trial (Trial).  Conducted by the independent Age Check Certification Scheme (ACCS), the Trial offers insights into the technical feasibility, privacy implications, and operational deployment capabilities of various age assurance technologies.  While the Report explicitly states it is neutral…

    Read more …

  • What is the US Take It Down Act?

    What is the US Take It Down Act?

    The Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (Take It Down Act ) is a United States (US) federal law enacted on 19 May 2025. The Take It Down Act amends 47 U.S. Code § 223 (Code) of the Communications Act 1934 (US) (Communications Act) by establishing new…

    Read more …

  • Federal parliament enacts cyber security legislation

    Federal parliament enacts cyber security legislation

    On 25 November 2024, the Australian Parliament passed a suite of legislation, collectively referred to by the Australian Government as the Cyber Security Legislative Package 2024.  The purported impetus for this legislation was a series of high-profile data breaches in 2022 and 2023.

    Read more …

  • Privacy Act amended to increase penalties to a max of $50 million

    Privacy Act amended to increase penalties to a max of $50 million

    The Privacy Legislation Amendment (Enforcement and Other Measures) Bill 2022 (Bill) was passed by both Houses of Parliament on the 28 November 2022 and now awaits Royal Assent.  The Bill was passed with virtually no amendment.

    Read more …

  • What should APP Entities include in data destruction policies?

    What should APP Entities include in data destruction policies?

    This article summarises the Australian Privacy Principles (APPs) and the importance of having a data destruction policy (DDP) in place. It outlines the steps to take when destroying or deidentifying personal and sensitive information, and the consequences of not doing so.

    Read more …


Posted

in

,
Send this to a friend