{
 "jurisdiction_id": "AU",
 "jurisdiction": "Australia",
 "url": "https://dataprotection.gi/jurisdictions/australia/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 57,
  "sub_modules": 57,
  "source_register": 38
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive statute with an active, well-resourced regulator and a clear (if incrementally reforming) legal basis; amber-leaning only on registration/filing due to absence of DPO/DPIA/ROPA registration analogues.",
   "claims": [
    {
     "statement": "The Office of the Australian Information Commissioner (OAIC), established under the Australian Information Commissioner Act 2010, is Australia's primary privacy regulator, headed by the Australian Information Commissioner supported by the Privacy Commissioner and Freedom of Information Commissioner.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-legislation/the-privacy-act/history-of-the-privacy-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act 1988 (Cth), as amended, contains 13 Australian Privacy Principles (APPs) applicable to APP entities comprising some private-sector organisations and most Australian Government agencies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-legislation/the-privacy-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy and Other Legislation Amendment Act 2024 (POLA Act) commenced on 11 December 2024, implementing amendments to the Privacy Act within the Information Commissioner's remit.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-legislation/the-privacy-act/history-of-the-privacy-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act 1988 applies to Australian Government agencies and organisations with an annual turnover of more than $3 million, plus certain other prescribed organisations regardless of turnover.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-legislation",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act's extraterritorial reach extends to entities with an 'Australian link', including foreign entities that carry on business in Australia by collecting personal information via a website from individuals physically located in Australia.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/engage-with-us/submissions/privacy-act-review-issues-paper-submission/part-11-statutory-tort",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act does not impose a general controller/processor registration or filing obligation and does not explicitly reference 'data controllers'/'data processors' or mandate DPO appointment or formal DPIA filings.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/australia",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Functionally equivalent protections exist but are structured differently from GDPR (no unified 'special category' list with Article-9-style enumerated exceptions), producing interoperability friction.",
   "claims": [
    {
     "statement": "Rather than an enumerated 'lawful basis' model, the Privacy Act regulates use and disclosure of personal information through APP 6, permitting secondary use/disclosure only where the individual consents or a listed exception applies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/australian-privacy-principles/read-the-australian-privacy-principles",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consent under the Privacy Act is defined as express or implied consent and, per OAIC guidance, must be adequately informed before it is given.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-8-app-8-cross-border-disclosure-of-personal-information",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Handling of health information without individual consent for research, compilation of statistics, or health service management may occur under Guidelines approved under s95A of the Privacy Act, provided human research ethics committees weigh the public interest in the activity against the public interest in privacy protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-legislation/the-privacy-act/rules-and-guidelines",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In certain instances the Privacy Act requires businesses to de-identify unsolicited personal information they receive if it could not lawfully have been collected.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/overview-of-the-newly-enacted-australian-privacy-principles",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core access/correction/portability rights exist and are enforceable, but erasure and objection/restriction rights are narrower or not yet legislated compared to GDPR.",
   "claims": [
    {
     "statement": "The Privacy Act and APPs provide individuals a general right to access and be informed about personal information held about them by APP entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/australia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Commentators noted the 2024 reform bill 'doesn't touch most of the substantive principles' and that a general right to erasure and improved consent models were expected only in a later legislative tranche not materialising before mid-2025 at the earliest.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/australia-introduces-initial-privacy-act-reforms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "APP 7 requires organisations to provide individuals an easy means to opt out of direct marketing communications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/overview-of-the-newly-enacted-australian-privacy-principles",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Consumer Data Right, introduced via the Treasury Laws Amendment (Consumer Data Right) Bill/Act 2019, provides consumers with the right to data portability to switch between products and services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/australia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act requires organisations to take reasonable steps to conduct a data breach assessment within 30 days of becoming aware of grounds to suspect an eligible data breach, and to notify affected individuals and the OAIC as soon as practicable thereafter.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/media-centre/report-shows-highest-number-of-data-breaches-in-3.5-years",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Strong security and breach-notification enforcement (Medibank, Optus, ACL) offsets the absence of formal DPIA/DPO/ROPA mechanisms.",
   "claims": [
    {
     "statement": "The Privacy Act does not include provisions expressly requiring Data Protection Impact Assessments (DPIAs).",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/australia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "APP 1's declared object is to ensure APP entities manage personal information in an open and transparent way, which functions as the Act's principal accountability mechanism in place of a formal DPIA regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act does not include provisions regarding mandatory Data Protection Officer appointments.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/australia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "An APP entity that discloses personal information to an overseas recipient is accountable for any acts or practices of the overseas recipient that would breach the APPs, under s16C of the Privacy Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-8-app-8-cross-border-disclosure-of-personal-information",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Australian Privacy Principle 11.1 requires an APP entity to take such steps as are reasonable in the circumstances to protect personal information it holds from misuse, interference, loss, and unauthorised access, modification or disclosure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The notifiable data breaches (NDB) provisions of the Privacy Act came into effect on 22 February 2018, requiring mandatory notification of all 'eligible data breaches' to the OAIC and affected individuals.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/australia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy and Other Legislation Amendment Act 2024 enhanced requirements relating to the security of personal information and its destruction when it is no longer needed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/media-centre/oaic-welcomes-reforms-critical-to-australias-privacy-future",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "A functioning accountability-based transfer framework exists but lacks a mutual EU adequacy finding and a fully operative statutory whitelist, and has no general data-localisation mandate.",
   "claims": [
    {
     "statement": "APP 8 and s16C create an accountability-based cross-border transfer framework requiring an APP entity, before disclosing personal information to an overseas recipient, to take reasonable steps ensuring the recipient does not breach the APPs, with the disclosing entity remaining accountable for the overseas recipient's mishandling.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-8-app-8-cross-border-disclosure-of-personal-information",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Australia has not obtained a formal EU adequacy decision; the OAIC's submissions note that a formal EU Adequacy Decision would alleviate the need for Australian and EU entities to conduct further Article 46 GDPR transfer-tool assessments.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/engage-with-us/submissions/privacy-act-review-issues-paper-submission/part-11-statutory-tort",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act reforms establish a new mechanism to prescribe a 'white list' of countries and binding schemes with adequate privacy protections to facilitate cross-border data transfers.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/media-centre/pasing-of-bill-a-significant-step-for-australias-privacy-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "An APP entity may satisfy its APP 8.1 'reasonable steps' obligation through contractual arrangements with the overseas recipient requiring APP compliance, flow-down obligations to sub-contractors, and a data-breach response mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-8-app-8-cross-border-disclosure-of-personal-information",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act does not mandate a formal Transfer Impact Assessment process; OAIC guidance instead suggests entities could consider notifying individuals that an overseas recipient may be required to disclose their information under a foreign law such as the USA PATRIOT Act.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/__data/assets/pdf_file/0015/1239/chapter-8-app-guidelines-v1.1.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The National Health (Privacy) Rules 2021 prohibit Australian Government agencies from storing Medicare Benefits Program and Pharmaceutical Benefits Program claims information obtained under those programs on the same database.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-legislation/the-privacy-act/rules-and-guidelines",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial, health and telecoms/online-safety overlays are well documented and actively enforced; employment and education sector-specific DP rules are an evidentiary gap.",
   "claims": [
    {
     "statement": "Part IIIA of the Privacy Act (credit reporting) establishes a distinct set of civil penalty provisions of 500, 1000 or 2000 penalty units, separate from the general s13G serious-interference penalty.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/guide-to-privacy-regulatory-action/chapter-7-privacy-assessments",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under s79 of the My Health Records Act, the Information Commissioner may apply to a court for an order that a person who has contravened a civil penalty provision in that Act pay the Commonwealth a civil penalty, constituting a distinct health-sector enforcement track from the general Privacy Act regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/guide-to-privacy-regulatory-action/chapter-7-privacy-assessments",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Part 4A of the Online Safety Act 2021, introduced in November 2024, establishes the Social Media Minimum Age scheme, which operates alongside the Privacy Act, with the OAIC overseeing privacy-related compliance under s63F and eSafety overseeing broader compliance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/your-privacy-rights/social-media-minimum-age",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy (Credit Related Research) Rule 2024, a legislative instrument made under s20M of the Privacy Act applying from 12 July 2024, permits credit reporting bodies to use or disclose de-identified information for credit-related research subject to compliance with the Rule.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-legislation/the-privacy-act/rules-and-guidelines",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OAIC alleged Medibank failed to take reasonable steps to protect personal information given its size, resources, and the nature and volume of the sensitive and personal information it handled, illustrating heightened security expectations for health insurers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/media-centre/oaic-takes-civil-penalty-action-against-medibank",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct marketing and tracking-technology oversight exist and are being actively enforced, but dark-pattern-specific rules, recognised opt-out signals, clean-room rules and cross-context-advertising concepts (as distinct legal categories) were not evidenced.",
   "claims": [
    {
     "statement": "The OAIC has inspected the use of tracking pixels by 50 healthcare providers as part of its regulatory focus on online tracking technologies in the health sector.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "APP 7 requires an organisation to provide the individual with an easy means to opt out of direct marketing communications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/overview-of-the-newly-enacted-australian-privacy-principles",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ACMA fined Latitude Finance AUD 3.96 million for sending marketing messages without accurate contact information and a working unsubscribe function, illustrating adjacent (non-OAIC) enforcement of direct-marketing rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/australia",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Meaningful ADM transparency reform is enacted but not yet in force, and biometric governance currently relies on case-by-case enforcement rather than a dedicated statute.",
   "claims": [
    {
     "statement": "From 10 December 2026, APP entities that arrange for a computer program to use personal information to make decisions reasonably expected to significantly affect an individual's rights or interests must include specified information about the kinds of personal information used and decisions made in their APP Privacy Policies (APP 1.7–1.9).",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OAIC intends to release guidance on the ADM Transparency Obligation by September 2026, ahead of the 10 December 2026 commencement date, following a consultation that closed 15 June 2026; Australia does not yet impose a standalone AI-specific risk-assessment mandate akin to the EU AI Act.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/__data/assets/pdf_file/0027/263925/ADM-Issues-Paper.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OAIC has issued landmark determinations addressing facial recognition technology use by retailers, including the Bunnings and Kmart decisions, updating the application of the Privacy Act to biometric technologies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/blog/handling-privacy-complaints-a-new-approach-for-a-new-era",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "APP 8.2 provides an exception permitting cross-border disclosure without the standard reasonable-steps requirement where an agency reasonably believes disclosure is necessary for enforcement-related activities and the overseas recipient performs functions similar to an Australian enforcement body.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/australian-privacy-principles/read-the-australian-privacy-principles",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "green",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Binding, in-force age-verification law plus a legislatively mandated forthcoming Children's Code represent strong and active regulatory attention to children's privacy.",
   "claims": [
    {
     "statement": "From 10 December 2025, providers of age-restricted social media platforms must take reasonable steps to prevent Australians under the age of 16 from creating or keeping an account, under the co-regulated Social Media Minimum Age scheme overseen by the OAIC for privacy compliance and eSafety for broader compliance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/your-privacy-rights/social-media-minimum-age",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Once the SMMA obligation took effect, parents lost the ability to consent to allow children under 16 to hold accounts on affected social media platforms such as Facebook, Snapchat, Instagram and TikTok.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/social-media-safety-privacy-literacy-and-gentle-parenting",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OAIC is developing a Children's Online Privacy Code, a legislative instrument under the Privacy Act mandated by the POLA Act 2024, which must be registered by 10 December 2026 and will apply to APP entities providing social media services, relevant electronic services, or designated internet services likely to be accessed by children.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The draft Children's Online Privacy Code's applicability extends to designated internet services likely to be accessed by children or primarily concerning children's activities, which may capture certain education-adjacent online services, though the OAIC has not yet finalised sector-specific carve-outs.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Speculative",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/australia/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Well-resourced, increasingly assertive enforcement with escalating penalties, multiple concurrent major proceedings, and new private/collective redress avenues, tempered by acknowledged case-backlog capacity constraints.",
   "claims": [
    {
     "statement": "Since amendments effective December 2022, the maximum civil penalty for a body corporate's serious or repeated interference with privacy under s13G is the greater of $50 million, three times the value of the benefit obtained, or 30% of the entity's adjusted turnover during the breach period.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy and Other Legislation Amendment Act 2024 introduced a new mid-tier civil penalty under s13H for interferences with privacy that do not meet the 'serious' threshold, capped at 2,000 penalty units (AUD 660,000).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In its first civil-penalty judgment under the Privacy Act, the Federal Court ordered Australian Clinical Labs to pay $5.8 million for privacy breaches connected to its February 2022 Medlab Pathology data breach affecting over 223,000 individuals.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OAIC received a record 1,205 data breach notifications in the 2025 calendar year, an 8% increase over 2024's 1,112 notifications and the highest annual total since the NDB scheme commenced in 2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025,-new-ndb-stats-show",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of early 2026 the OAIC intended to continue civil-penalty proceedings against Optus and Medibank through the year, alongside Commissioner-initiated investigations into rental-technology platforms, connected cars and tracking pixels.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/blog/handling-privacy-complaints-a-new-approach-for-a-new-era",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OAIC was allocated AUD 3 million in funding over three years to fully develop the Children's Online Privacy Code.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/australia-introduces-initial-privacy-act-reforms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As at February 2026, the OAIC reported a significant backlog of individual privacy complaints, with new validly lodged complaints unlikely to be substantially progressed for 6 to 12 months absent exceptional circumstances.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news/blog/handling-privacy-complaints-a-new-approach-for-a-new-era",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Representative complaints under s36 of the Privacy Act allow the Information Commissioner to investigate on behalf of a class and, if substantiated, declare that class members are entitled to compensation for loss or damage including injury to feelings or humiliation, as pursued in the Medibank and Optus representative complaints.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/newsroom/representative-complaints",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Separate from the OAIC's representative complaint process, affected individuals have pursued parallel Federal Court class actions, such as Zoe Lee McClure v Medibank Private Limited, arising from the same 2022 data breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/privacy-complaints/medibank-representative-complaint-notice",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A statutory tort for serious invasions of privacy, inserted into Schedule 2 of the Privacy Act, commenced on 10 June 2025, giving individuals a direct court-based avenue for redress independent of the OAIC and applicable to entities beyond APP entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/privacy/your-privacy-rights/more-privacy-rights/statutory-tort-for-serious-invasions-of-privacy",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OAIC published a report of its preliminary inquiries into the 2025 Qantas Airways data breach, released 16 July 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Commissioner found that providers Medmate Australia Pty Ltd and Monash IVF Pty Ltd interfered with the privacy of individuals, per a determination reported on the OAIC's website in 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/news",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OAIC opened a consultation (Issues Paper) on guidance for the ADM Transparency Obligation, with submissions closing 15 June 2026 ahead of guidance expected by September 2026.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}