Article
Privacy Act Changes 2026: Compliance Checklist
Australia's privacy law changed in December 2024 and more lands in December 2026. What the new tort, automated-decision rules and OAIC powers mean for your business, plus a practical checklist.

For most of its life, the Privacy Act 1988 was a law with a polite bark. Breaches happened, the OAIC investigated, and outcomes tended to arrive years later as determinations most business owners never read.
That has changed. The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024 and has been switching on in stages ever since. The last big piece for this round, transparency about automated decisions, starts on 10 December 2026, which is about ten weeks away as we write this in October 2026.
Here's what changed, what's still coming, and a checklist to work through. It's general information, not legal advice, so talk to a lawyer about how it applies to you.
Change 1: the OAIC got a much bigger toolbox
Before the reform, the OAIC's main penalty option was going to the Federal Court over a "serious" interference with privacy. That's a big, slow, expensive step, so it was reserved for big, slow, expensive cases. The 2024 Act filled in the space underneath it, with effect from December 2024:
- Infringement notices for administrative failures, such as a privacy policy that's missing required information, without going to court.
- Compliance notices requiring a business to fix a specific contravention within a set time.
- A mid-tier civil penalty for interferences with privacy that aren't "serious", of up to 2,000 penalty units for individuals and five times that for companies. At the current penalty unit value that's roughly $3.3 million for a company.
The top tier, for serious interferences, was already raised in 2022 to the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover.
And it's no longer theoretical. In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million in the first civil penalty under the Privacy Act, over a 2022 ransomware attack on systems it had acquired. The court found it hadn't taken reasonable steps to protect the data, and hadn't properly assessed and notified the breach. That second part is worth underlining: getting breached was bad, but mishandling the response made it worse.
Change 2: individuals can now sue for serious invasions of privacy
Since 10 June 2025, Australians have a statutory tort for serious invasions of privacy. In plain terms, a person can take someone to court if that party intruded on their seclusion or misused information about them, and the person had a reasonable expectation of privacy, the invasion was intentional or reckless, and it was serious, with the public interest in privacy outweighing any competing public interest.
Two things make this relevant to ordinary businesses. First, it isn't limited to APP entities, so the small business exemption doesn't shield you from it. Second, it's about conduct, not paperwork. Think of a staff member snooping through a customer's file out of curiosity, or a manager sharing an employee's medical details around the office. Damages are capped at the greater of $478,550 or the maximum for non-economic loss in defamation, and there are exemptions for journalists, law enforcement and people under 18.
Negligence isn't enough for this tort, it has to be intentional or reckless. But "we had no rules about who could look at what" is not a great position to argue from.
Change 3: automated decisions must be explained (from 10 December 2026)
If you use a computer program to make decisions that could reasonably be expected to significantly affect someone's rights or interests, using their personal information, your privacy policy will need to say so. That includes decisions made entirely by the program, and decisions where the program does something substantially and directly related to the decision, such as scoring an application that a person then rubber-stamps.
The policy has to describe the kinds of personal information used and the kinds of decisions involved. It's not limited to AI. A hard-coded rule that automatically declines credit, filters out job applicants or sets a price for an individual can count.
Here's a quick test. List every system that says "yes", "no" or "how much" about a person without a human genuinely weighing it up. Recruitment platforms, credit checks, tenancy screening, insurance quoting, fraud flags. If anything's on the list, your privacy policy needs updating before December.
Change 4: security now explicitly means people, not just technology
APP 11 has always required reasonable steps to protect personal information. The amendment makes clear those steps include technical and organisational measures. Firewalls and encryption on one side; documented procedures, access controls and staff training on the other. If your security plan is entirely a product list, it's half a plan.
What hasn't changed (yet)
The small business exemption is still in place. Businesses with annual turnover of $3 million or less are generally outside the Privacy Act, with exceptions, including health service providers, businesses that trade in personal information, and contracted service providers to the Commonwealth.
That exemption is also narrowing quietly. From 1 July 2026, lawyers, conveyancers, accountants and real estate agents brought into the anti-money laundering regime became AML/CTF reporting entities, and they must handle personal information collected for AML/CTF purposes under the Australian Privacy Principles, whatever their size.
A second tranche of reform is on the way. The Attorney-General has released an exposure draft, the Privacy Amendment (Personal Data Protection) Bill 2026, with a "fair and reasonable" test for data handling among other changes. It doesn't remove the small business exemption, and it isn't law yet. Plan for the direction of travel, but comply with what's actually in force.
The checklist
- Work out if you're covered. Turnover over $3 million, a health service, AML/CTF reporting entity, or one of the other exceptions? If you're unsure, assume yes. The statutory tort applies either way.
- Map your personal information. What you collect, why, where it's stored, who can access it and who you share it with. Include the forgotten places: website forms, spreadsheets on someone's laptop, the old CRM nobody switched off.
- Update your privacy policy. Make it specific and current, and add automated-decision information before 10 December 2026 if it applies. An out-of-date policy is now precisely the sort of thing an infringement notice is for.
- Tighten access. Staff should see the personal information their job needs and no more. Log access to sensitive records so snooping is detectable.
- Delete what you don't need. APP 11 requires it, and data you no longer hold can't be stolen. See our guide to building a data retention policy.
- Cover the technical basics. MFA everywhere, patching, encrypted devices, tested backups, and monitoring. The ASD Essential Eight is the sensible yardstick, and a cyber security assessment will tell you where you stand.
- Cover the organisational basics. Written procedures, regular staff training, and records showing both happened.
- Rehearse a breach. Under the Notifiable Data Breaches scheme you have 30 days to assess a suspected breach and must notify the OAIC and affected people if it's likely to cause serious harm. Know who does what before you need to. Our guide on what to do after a breach notice shows the other side of that letter.
- Check your suppliers. Your IT provider, payroll platform and marketing tools all handle personal information on your behalf. Know what they hold and how they protect it. Our third-party app vetting checklist helps.
The short version
For years, privacy compliance for most Australian businesses meant having a privacy policy page on the website. That's no longer enough. The regulator can now issue fines without a court case, individuals can sue, and courts have shown they'll impose real penalties. The upside is that most of what the law asks for — know your data, limit access, secure it, delete what you don't need, respond well when things go wrong — is just good IT practice written down.
Frequently asked questions
What are the new privacy laws in Australia?
The Privacy and Other Legislation Amendment Act 2024 added new OAIC enforcement powers (infringement notices, compliance notices and a mid-tier civil penalty) from December 2024, a statutory tort for serious invasions of privacy from 10 June 2025, and automated decision-making transparency requirements from 10 December 2026.
When do the automated decision-making rules start?
10 December 2026. From then, APP entities that use computer programs to make, or substantially help make, decisions that significantly affect individuals must describe this in their privacy policy, including the kinds of personal information used and the kinds of decisions made.
Does the Privacy Act apply to small businesses?
Generally not if annual turnover is $3 million or less, but there are many exceptions, including health service providers, businesses that trade in personal information, and AML/CTF reporting entities for information handled under that regime. The statutory privacy tort applies regardless of business size.
What is the statutory tort for serious invasions of privacy?
A right, in force since 10 June 2025, for individuals to sue over a serious, intentional or reckless intrusion on their seclusion or misuse of their information, where they had a reasonable expectation of privacy and the public interest in privacy outweighs competing interests.
Local IT and cyber security support across NSW
Chewing IT runs managed IT and cyber security for small and mid-sized businesses from our Wyong and Hornsby offices, covering the Central Coast, Newcastle, Lake Macquarie and Hornsby.
Not sure whether your business is ready for the December changes? Book a privacy and security review — we'll map your data, close the gaps and document what you've done.