🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
AU · run data-protection-2026-07-29 v13-gdpri-1.0.0
content: ai_generated 38 sources retrieved model claude-sonnet-5 ·

Australia

AU schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 57 claims · 38 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
57Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

The Federal Court has ordered Australian Clinical Labs to pay $5.8 million in Australia's first-ever civil-penalty judgment under the Privacy Act, arising from breaches connected to the February 2022 Medlab Pathology breach that affected more than 223,000 individuals. The penalty lands against a backdrop of record regulatory activity: the OAIC received 1,205 data breach notifications in 2025, an 8% increase over 2024's 1,112 and the highest total since the Notifiable Data Breaches scheme began in 2018. The regulator has signalled it intends to continue civil-penalty proceedings against Optus and Medibank through 2026, alongside Commissioner-initiated investigations into rental-technology platforms, connected cars and tracking pixels. Taken together, these developments mark a clear escalation in Australia's enforcement posture under a regime whose maximum civil penalty for serious or repeated interference has stood, since December 2022, at the greater of $50 million, three times the value obtained from the misuse, or 30% of adjusted turnover.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute with an active, well-resourced regulator and a clear (if incrementally reforming) legal basis; amber-leaning only on registration/filing due to absence of DPO/DPIA/ROPA registration analogues.

Primary frameworkPrivacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024
Traffic-light rationale — GreenComprehensive statute with an active, well-resourced regulator and a clear (if incrementally reforming) legal basis; amber-leaning only on registration/filing due to absence of DPO/DPIA/ROPA registration analogues.

Sub-modules (5)

Regulator And AuthorityGreen

The OAIC, established under the Australian Information Commissioner Act 2010, is headed by the Australian Information Commissioner supported by the Privacy Commissioner and the Freedom of Information Commissioner.

Claims: CLM-AU-a1b2c3d4

Act And InstrumentsGreen

Primary instrument is the Privacy Act 1988; the POLA Act 2024 is the most significant recent amending instrument.

Claims: CLM-AU-b2c3d4e5, CLM-AU-c3d4e5f6

Material ScopeGreen

Scope is turnover-based ($3M+) for private-sector organisations, plus most Commonwealth agencies and certain always-covered entities (health service providers, credit reporting bodies).

Claims: CLM-AU-d4e5f6a7

Territorial ScopeGreen

Extraterritorial application turns on the 'Australian link' test, capturing foreign entities carrying on business in Australia online.

Claims: CLM-AU-e5f6a7b8

Regulator Registration And FilingAmber

No GDPR-style controller/processor registration, DPO appointment, or DPIA filing regime exists under the Privacy Act.

Claims: CLM-AU-f6a7b8c9

Category narrative87 words

Australia's data-protection regime is anchored in the Privacy Act 1988 (Cth), a comprehensive omnibus statute containing 13 Australian Privacy Principles (APPs) applied and enforced by the Office of the Australian Information Commissioner (OAIC). The regime was substantially modernised by the Privacy and Other Legislation Amendment Act 2024 (POLA Act), most of whose Information-Commissioner-facing amendments commenced 11 December 2024, with further tranches (ADM transparency, Children's Online Privacy Code) commencing 10 December 2026. The Act applies extraterritorially via the 'Australian link' concept and does not require general controller/processor registration.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedOffice of the Australian Information CommissionerThe Office of the Australian Information Commissioner (OAIC), established under the Australian Information Commissioner Act 2010, is Australia's primary privacy regulator, headed by the Australian Information Commissioner supported by the Privacy Commissioner and Freedom of Information Commissioner.
  2. ConfirmedOffice of the Australian Information CommissionerThe Privacy Act 1988 (Cth), as amended, contains 13 Australian Privacy Principles (APPs) applicable to APP entities comprising some private-sector organisations and most Australian Government agencies.
  3. ConfirmedOffice of the Australian Information CommissionerThe Privacy and Other Legislation Amendment Act 2024 (POLA Act) commenced on 11 December 2024, implementing amendments to the Privacy Act within the Information Commissioner's remit.
  4. ConfirmedOffice of the Australian Information CommissionerThe Privacy Act 1988 applies to Australian Government agencies and organisations with an annual turnover of more than $3 million, plus certain other prescribed organisations regardless of turnover.
  5. ProbableOffice of the Australian Information CommissionerThe Privacy Act's extraterritorial reach extends to entities with an 'Australian link', including foreign entities that carry on business in Australia by collecting personal information via a website from individuals physically located in Australia.
  6. ConfirmedOneTrust DataGuidanceThe Privacy Act does not impose a general controller/processor registration or filing obligation and does not explicitly reference 'data controllers'/'data processors' or mandate DPO appointment or formal DPIA filings.

#

Functionally equivalent protections exist but are structured differently from GDPR (no unified 'special category' list with Article-9-style enumerated exceptions), producing interoperability friction.

Primary frameworkPrivacy Act 1988 (Cth) — Australian Privacy Principles 3, 6 and 7
Traffic-light rationale — AmberFunctionally equivalent protections exist but are structured differently from GDPR (no unified 'special category' list with Article-9-style enumerated exceptions), producing interoperability friction.

Sub-modules (4)

Lawful BasesAmber

APP 6 governs secondary use/disclosure via consent or listed exceptions rather than an Art 6-style basis list.

Claims: CLM-AU-a7b8c9d0

Special CategoriesGreen

Sensitive/health information research without consent is permitted only under s95A ethics-committee-approved Guidelines.

Claims: CLM-AU-c9d0e1f2

Pseudonymisation And AnonymisationAmber

De-identification is mandated in specific unsolicited-information scenarios.

Claims: CLM-AU-d0e1f2a3

Category narrative50 words

The Privacy Act does not use a GDPR-style enumerated 'lawful basis' model; instead APP 6 governs permissible use/disclosure by reference to primary/secondary purpose and consent. Consent must be informed, voluntary, current and specific. Special handling exists for health information research via s95/s95A Guidelines, and de-identification obligations apply in defined circumstances.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedOffice of the Australian Information CommissionerRather than an enumerated 'lawful basis' model, the Privacy Act regulates use and disclosure of personal information through APP 6, permitting secondary use/disclosure only where the individual consents or a listed exception applies.
  2. ConfirmedOffice of the Australian Information CommissionerConsent under the Privacy Act is defined as express or implied consent and, per OAIC guidance, must be adequately informed before it is given.
  3. ConfirmedOffice of the Australian Information CommissionerHandling of health information without individual consent for research, compilation of statistics, or health service management may occur under Guidelines approved under s95A of the Privacy Act, provided human research ethics committees weigh the public interest in the activity against the public interest in privacy protection.
  4. ProbableInternational Association of Privacy ProfessionalsIn certain instances the Privacy Act requires businesses to de-identify unsolicited personal information they receive if it could not lawfully have been collected.

#

Core access/correction/portability rights exist and are enforceable, but erasure and objection/restriction rights are narrower or not yet legislated compared to GDPR.

Primary frameworkPrivacy Act 1988 (Cth) APPs 12–13; Treasury Laws Amendment (Consumer Data Right) Act 2019
Traffic-light rationale — AmberCore access/correction/portability rights exist and are enforceable, but erasure and objection/restriction rights are narrower or not yet legislated compared to GDPR.

Sub-modules (5)

Access RightGreen

General right to access and be informed about held personal information.

Claims: CLM-AU-e1f2a3b4

Rectification And ErasureAmber

Correction right exists; general erasure right not yet enacted (flagged for future tranche).

Claims: CLM-AU-f2a3b4c5

Restriction And ObjectionAmber

Objection right limited mainly to direct-marketing opt-out under APP 7.

Claims: CLM-AU-a3b4c5d6

Data PortabilityGreen

Portability delivered via the sectoral Consumer Data Right rather than a general Privacy Act right.

Claims: CLM-AU-b4c5d6e7

Deadlines And Response WindowsGreen

NDB scheme imposes a 30-day reasonable assessment window plus 'as soon as practicable' notification.

Claims: CLM-AU-c5d6e7f8

Category narrative59 words

Individuals have access and correction rights under the APPs, a portability right via the Consumer Data Right (CDR), and an opt-out right for direct marketing. A general 'right to be forgotten'/erasure was not introduced by the 2024 reform tranche and remains a proposed future reform. Response deadlines are anchored in the Notifiable Data Breaches (NDB) scheme's 30-day assessment window.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceThe Privacy Act and APPs provide individuals a general right to access and be informed about personal information held about them by APP entities.
  2. ProbableInternational Association of Privacy ProfessionalsCommentators noted the 2024 reform bill 'doesn't touch most of the substantive principles' and that a general right to erasure and improved consent models were expected only in a later legislative tranche not materialising before mid-2025 at the earliest.
  3. ConfirmedInternational Association of Privacy ProfessionalsAPP 7 requires organisations to provide individuals an easy means to opt out of direct marketing communications.
  4. ConfirmedOneTrust DataGuidanceThe Consumer Data Right, introduced via the Treasury Laws Amendment (Consumer Data Right) Bill/Act 2019, provides consumers with the right to data portability to switch between products and services.
  5. ConfirmedOffice of the Australian Information CommissionerThe Privacy Act requires organisations to take reasonable steps to conduct a data breach assessment within 30 days of becoming aware of grounds to suspect an eligible data breach, and to notify affected individuals and the OAIC as soon as practicable thereafter.

#

Strong security and breach-notification enforcement (Medibank, Optus, ACL) offsets the absence of formal DPIA/DPO/ROPA mechanisms.

Primary frameworkPrivacy Act 1988 (Cth) APPs 1, 11; Notifiable Data Breaches scheme (Part IIIC)
Traffic-light rationale — AmberStrong security and breach-notification enforcement (Medibank, Optus, ACL) offsets the absence of formal DPIA/DPO/ROPA mechanisms.

Sub-modules (7)

Accountability And DpiaAmber

No explicit statutory DPIA requirement; accountability flows from APP 1 privacy-policy/open-management obligations.

Claims: CLM-AU-d6e7f8a9, CLM-AU-f8a9b0c1

Dpo RequirementsAmber

No mandatory DPO appointment requirement.

Claims: CLM-AU-e7f8a9b0

Ropa RequirementsAmber

No formal Records of Processing Activities filing obligation equivalent to GDPR Art 30.

Joint Controller ArrangementsAmber

No controller/processor terminology; accountability instead attaches to the APP entity and flows to related bodies corporate and overseas recipients under s16C.

Claims: CLM-AU-a9b0c1d2

Security MeasuresGreen

APP 11.1 requires reasonable steps to protect personal information, heavily litigated in recent enforcement actions.

Claims: CLM-AU-b0c1d2e3

Breach NotificationGreen

Mandatory NDB scheme in force since 22 February 2018.

Claims: CLM-AU-c1d2e3f4

Retention And DisposalGreen

POLA Act 2024 enhanced retention/destruction requirements.

Claims: CLM-AU-d2e3f4a5

Category narrative64 words

The Privacy Act does not use a controller/processor construct, does not mandate DPOs, and has no formal DPIA or ROPA filing regime; instead accountability is achieved via the APP 1 'open and transparent management' obligation, APP 11.1 security-of-processing duty, and s16C accountability for overseas recipients. The Notifiable Data Breaches (NDB) scheme has operated since February 2018, and the POLA Act 2024 strengthened retention/disposal expectations.

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceThe Privacy Act does not include provisions expressly requiring Data Protection Impact Assessments (DPIAs).
  2. ConfirmedOffice of the Australian Information CommissionerAPP 1's declared object is to ensure APP entities manage personal information in an open and transparent way, which functions as the Act's principal accountability mechanism in place of a formal DPIA regime.
  3. ConfirmedOneTrust DataGuidanceThe Privacy Act does not include provisions regarding mandatory Data Protection Officer appointments.
  4. ConfirmedOffice of the Australian Information CommissionerAn APP entity that discloses personal information to an overseas recipient is accountable for any acts or practices of the overseas recipient that would breach the APPs, under s16C of the Privacy Act.
  5. ConfirmedOffice of the Australian Information CommissionerAustralian Privacy Principle 11.1 requires an APP entity to take such steps as are reasonable in the circumstances to protect personal information it holds from misuse, interference, loss, and unauthorised access, modification or disclosure.
  6. ConfirmedOneTrust DataGuidanceThe notifiable data breaches (NDB) provisions of the Privacy Act came into effect on 22 February 2018, requiring mandatory notification of all 'eligible data breaches' to the OAIC and affected individuals.
  7. ConfirmedOffice of the Australian Information CommissionerThe Privacy and Other Legislation Amendment Act 2024 enhanced requirements relating to the security of personal information and its destruction when it is no longer needed.

#

A functioning accountability-based transfer framework exists but lacks a mutual EU adequacy finding and a fully operative statutory whitelist, and has no general data-localisation mandate.

Primary frameworkPrivacy Act 1988 (Cth) — Australian Privacy Principle 8 and s16C
Traffic-light rationale — AmberA functioning accountability-based transfer framework exists but lacks a mutual EU adequacy finding and a fully operative statutory whitelist, and has no general data-localisation mandate.

Sub-modules (6)

Transfer MechanismsGreen

Accountability-based framework requiring reasonable steps before overseas disclosure.

Claims: CLM-AU-e3f4a5b6

Adequacy ReceivedAmber

No formal EU adequacy decision for Australia identified.

Claims: CLM-AU-f4a5b6c7

Adequacy GrantedAmber

POLA Act 2024 creates a future white-list prescription mechanism, not yet operative.

Claims: CLM-AU-a5b6c7d8

Sccs And BcrsGreen

Contractual arrangements are the principal APP 8.1 'reasonable steps' compliance tool.

Claims: CLM-AU-b6c7d8e9

Transfer Impact AssessmentAmber

No formal mandated TIA process; informal foreign-law-risk disclosure is recommended practice only.

Claims: CLM-AU-c7d8e9f0

Data LocalisationAmber

Only sector-specific localisation rules identified (health claims data).

Claims: CLM-AU-d8e9f0a1

Category narrative85 words

APP 8 and s16C create an accountability-based (not adequacy-list-based) cross-border transfer regime: an APP entity must take reasonable steps to ensure an overseas recipient will not breach the APPs and remains liable if it does, subject to exceptions (substantially-similar-law belief, informed consent, legal requirement, international agreements, enforcement-body disclosures). Australia has not received a formal EU adequacy decision. The POLA Act 2024 introduces a future 'white list' mechanism to prescribe adequate countries/schemes, not yet operative. Data localisation is sectoral (e.g., health claims data) rather than general.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedOffice of the Australian Information CommissionerAPP 8 and s16C create an accountability-based cross-border transfer framework requiring an APP entity, before disclosing personal information to an overseas recipient, to take reasonable steps ensuring the recipient does not breach the APPs, with the disclosing entity remaining accountable for the overseas recipient's mishandling.
  2. ProbableOffice of the Australian Information CommissionerAustralia has not obtained a formal EU adequacy decision; the OAIC's submissions note that a formal EU Adequacy Decision would alleviate the need for Australian and EU entities to conduct further Article 46 GDPR transfer-tool assessments.
  3. ConfirmedOffice of the Australian Information CommissionerThe Privacy Act reforms establish a new mechanism to prescribe a 'white list' of countries and binding schemes with adequate privacy protections to facilitate cross-border data transfers.
  4. ConfirmedOffice of the Australian Information CommissionerAn APP entity may satisfy its APP 8.1 'reasonable steps' obligation through contractual arrangements with the overseas recipient requiring APP compliance, flow-down obligations to sub-contractors, and a data-breach response mechanism.
  5. ProbableOffice of the Australian Information CommissionerThe Privacy Act does not mandate a formal Transfer Impact Assessment process; OAIC guidance instead suggests entities could consider notifying individuals that an overseas recipient may be required to disclose their information under a foreign law such as the USA PATRIOT Act.
  6. ConfirmedOffice of the Australian Information CommissionerThe National Health (Privacy) Rules 2021 prohibit Australian Government agencies from storing Medicare Benefits Program and Pharmaceutical Benefits Program claims information obtained under those programs on the same database.

#

Financial, health and telecoms/online-safety overlays are well documented and actively enforced; employment and education sector-specific DP rules are an evidentiary gap.

Primary frameworkPrivacy Act 1988 (Cth) Part IIIA; My Health Records Act 2012 (Cth); Online Safety Act 2021 (Cth) Part 4A
Traffic-light rationale — AmberFinancial, health and telecoms/online-safety overlays are well documented and actively enforced; employment and education sector-specific DP rules are an evidentiary gap.

Sub-modules (7)

Financial Sector OverlayGreen

Part IIIA credit reporting regime carries distinct, lower civil penalty caps than s13G.

Claims: CLM-AU-e9f0a1b2

Health Sector OverlayGreen

My Health Records Act 2012 provides a separate civil-penalty enforcement track administered by the Information Commissioner.

Claims: CLM-AU-f0a1b2c3

Telecoms And EprivacyGreen

Online Safety Act 2021 Part 4A SMMA scheme operates alongside the Privacy Act, co-regulated by OAIC and eSafety.

Claims: CLM-AU-a1b2c3e4

Employment DataRed

No dedicated employment-data privacy statute or code identified in this research pass.

Credit And ScoringGreen

Privacy (Credit Related Research) Rule 2024 permits de-identified credit-research data use by credit reporting bodies.

Claims: CLM-AU-b2c3e4f5

EducationRed

No education-sector-specific privacy statute identified in this research pass.

InsuranceAmber

Health insurers handling sensitive information face heightened APP 11.1 scrutiny, illustrated by the Medibank enforcement action.

Claims: CLM-AU-c3e4f5a6

Category narrative54 words

Sector overlays exist for credit reporting (Part IIIA with its own penalty scale), health records (My Health Records Act with its own enforcement regime), and telecommunications/online-safety (Online Safety Act 2021 Part 4A Social Media Minimum Age scheme, co-regulated by OAIC and eSafety). No dedicated employment-privacy or education-sector statutes were identified in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedOffice of the Australian Information CommissionerPart IIIA of the Privacy Act (credit reporting) establishes a distinct set of civil penalty provisions of 500, 1000 or 2000 penalty units, separate from the general s13G serious-interference penalty.
  2. ConfirmedOffice of the Australian Information CommissionerUnder s79 of the My Health Records Act, the Information Commissioner may apply to a court for an order that a person who has contravened a civil penalty provision in that Act pay the Commonwealth a civil penalty, constituting a distinct health-sector enforcement track from the general Privacy Act regime.
  3. ConfirmedOffice of the Australian Information CommissionerPart 4A of the Online Safety Act 2021, introduced in November 2024, establishes the Social Media Minimum Age scheme, which operates alongside the Privacy Act, with the OAIC overseeing privacy-related compliance under s63F and eSafety overseeing broader compliance.
  4. ConfirmedOffice of the Australian Information CommissionerThe Privacy (Credit Related Research) Rule 2024, a legislative instrument made under s20M of the Privacy Act applying from 12 July 2024, permits credit reporting bodies to use or disclose de-identified information for credit-related research subject to compliance with the Rule.
  5. ConfirmedOffice of the Australian Information CommissionerThe OAIC alleged Medibank failed to take reasonable steps to protect personal information given its size, resources, and the nature and volume of the sensitive and personal information it handled, illustrating heightened security expectations for health insurers.

#

Direct marketing and tracking-technology oversight exist and are being actively enforced, but dark-pattern-specific rules, recognised opt-out signals, clean-room rules and cross-context-advertising concepts (as distinct legal categories) were not evidenced.

Primary frameworkPrivacy Act 1988 (Cth) APP 7; Spam Act 2003 (Cth) (adjacent, ACMA-administered)
Traffic-light rationale — AmberDirect marketing and tracking-technology oversight exist and are being actively enforced, but dark-pattern-specific rules, recognised opt-out signals, clean-room rules and cross-context-advertising concepts (as distinct legal categories) were not evidenced.

Sub-modules (6)

Cookies And TrackersAmber

OAIC has actively inspected tracking-pixel use in the healthcare sector.

Claims: CLM-AU-d4e5f6b7

Dark PatternsRed

No dedicated dark-pattern prohibition identified in this research pass.

Opt Out SignalsRed

No GPC/DAA-equivalent recognised opt-out signal regime identified.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific rules identified.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' construct identified in the Privacy Act.

Direct MarketingGreen

APP 7 mandates an easy opt-out; adjacent ACMA enforcement addresses unlawful marketing practices.

Claims: CLM-AU-e5f6b7c8, CLM-AU-f6b7c8d9

Category narrative48 words

Australia lacks a dedicated ePrivacy/cookie-consent statute or CPRA-style 'sale'/'share' construct; commercial privacy protection instead flows from general APP obligations (notably APP 7 direct-marketing opt-out) plus targeted regulatory activity such as the OAIC's inspection of tracking-pixel use by healthcare providers and ACMA's separate Spam Act enforcement against unlawful marketing.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedOffice of the Australian Information CommissionerThe OAIC has inspected the use of tracking pixels by 50 healthcare providers as part of its regulatory focus on online tracking technologies in the health sector.
  2. ConfirmedInternational Association of Privacy ProfessionalsAPP 7 requires an organisation to provide the individual with an easy means to opt out of direct marketing communications.
  3. ConfirmedOneTrust DataGuidanceACMA fined Latitude Finance AUD 3.96 million for sending marketing messages without accurate contact information and a working unsubscribe function, illustrating adjacent (non-OAIC) enforcement of direct-marketing rules.

#

Meaningful ADM transparency reform is enacted but not yet in force, and biometric governance currently relies on case-by-case enforcement rather than a dedicated statute.

Primary frameworkPrivacy Act 1988 (Cth) APP 1.7–1.9 (from 10 December 2026)
Traffic-light rationale — AmberMeaningful ADM transparency reform is enacted but not yet in force, and biometric governance currently relies on case-by-case enforcement rather than a dedicated statute.

Sub-modules (6)

Profiling RestrictionsRed

No direct analogue to Art 22 profiling restrictions identified; searched OAIC ADM consultation materials and APP guidelines.

Absence provenance: not recorded. Searched: OAIC ADM Transparency consultation page, OAIC APP 1 guidelines chapter.

Automated Decision Making TransparencyAmber

New APP 1.7–1.9 ADM transparency duty enacted, commencing 10 December 2026.

Claims: CLM-AU-a7b8c9e0

Ai Risk AssessmentsAmber

No standalone AI-risk-assessment mandate; OAIC preparing ADM guidance ahead of December 2026 commencement.

Claims: CLM-AU-b8c9e0f1

Biometric RegimeAmber

Facial recognition addressed via landmark OAIC determinations (Bunnings, Kmart) rather than a dedicated biometric statute.

Claims: CLM-AU-c9e0f1a2

Genetic DataRed

No genetic-data-specific regime identified in this research pass.

Absence provenance: not recorded. Searched: OAIC APP guidelines special categories, OAIC Privacy Act review submissions.

State Surveillance CarveoutsAmber

APP 8.2 enforcement-body exception permits cross-border disclosure without standard reasonable-steps obligation.

Claims: CLM-AU-d0f1a2b3

Category narrative63 words

Australia has no direct analogue to GDPR Art 22 restricting solely-automated decisions, but the POLA Act 2024 introduces a new APP 1 automated-decision-making (ADM) transparency obligation commencing 10 December 2026. The OAIC has separately used its existing enforcement powers to address facial-recognition biometric use (Bunnings, Kmart) and provides enforcement-body exceptions for cross-border law-enforcement data sharing. No standalone AI-risk-assessment or genetic-data-specific regime was evidenced.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedOffice of the Australian Information CommissionerFrom 10 December 2026, APP entities that arrange for a computer program to use personal information to make decisions reasonably expected to significantly affect an individual's rights or interests must include specified information about the kinds of personal information used and decisions made in their APP Privacy Policies (APP 1.7–1.9).
  2. ConfirmedOffice of the Australian Information CommissionerThe OAIC intends to release guidance on the ADM Transparency Obligation by September 2026, ahead of the 10 December 2026 commencement date, following a consultation that closed 15 June 2026; Australia does not yet impose a standalone AI-specific risk-assessment mandate akin to the EU AI Act.
  3. ConfirmedOffice of the Australian Information CommissionerThe OAIC has issued landmark determinations addressing facial recognition technology use by retailers, including the Bunnings and Kmart decisions, updating the application of the Privacy Act to biometric technologies.
  4. ConfirmedOffice of the Australian Information CommissionerAPP 8.2 provides an exception permitting cross-border disclosure without the standard reasonable-steps requirement where an agency reasonably believes disclosure is necessary for enforcement-related activities and the overseas recipient performs functions similar to an Australian enforcement body.

#

Binding, in-force age-verification law plus a legislatively mandated forthcoming Children's Code represent strong and active regulatory attention to children's privacy.

Primary frameworkOnline Safety Act 2021 (Cth) Part 4A; Privacy Act 1988 (Cth) (Children's Online Privacy Code, pending)
Traffic-light rationale — GreenBinding, in-force age-verification law plus a legislatively mandated forthcoming Children's Code represent strong and active regulatory attention to children's privacy.

Sub-modules (5)

Age VerificationGreen

SMMA scheme requires reasonable steps to prevent under-16 accounts from 10 December 2025.

Claims: CLM-AU-e1f2a3c4

Minor Profiling BansAmber

Children's Online Privacy Code (pending, must register by 10 December 2026) will impose child-specific privacy obligations on covered online services.

Claims: CLM-AU-a3c4d5e6

Education SettingsAmber

Draft Code's scope may capture some education-adjacent services but sector-specific carve-outs are not yet finalised.

Claims: CLM-AU-b4d5e6f7

Dependent AdultsRed

No dependent-adults-specific privacy protections identified in this research pass.

Absence provenance: not recorded. Searched: OAIC privacy rights pages, OAIC Privacy Act Review submissions.

Category narrative79 words

Australia has implemented one of the world's most prominent children's online protection regimes: the Social Media Minimum Age (SMMA) scheme (in force from 10 December 2025) prevents under-16s from holding accounts on age-restricted social media platforms, co-regulated by OAIC and eSafety, and removes parental override of the age floor. Separately, the OAIC is developing a Children's Online Privacy Code (mandated by the POLA Act 2024) which must be registered by 10 December 2026. No dependent-adults-specific privacy protections were evidenced.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedOffice of the Australian Information CommissionerFrom 10 December 2025, providers of age-restricted social media platforms must take reasonable steps to prevent Australians under the age of 16 from creating or keeping an account, under the co-regulated Social Media Minimum Age scheme overseen by the OAIC for privacy compliance and eSafety for broader compliance.
  2. ConfirmedInternational Association of Privacy ProfessionalsOnce the SMMA obligation took effect, parents lost the ability to consent to allow children under 16 to hold accounts on affected social media platforms such as Facebook, Snapchat, Instagram and TikTok.
  3. ConfirmedOffice of the Australian Information CommissionerThe OAIC is developing a Children's Online Privacy Code, a legislative instrument under the Privacy Act mandated by the POLA Act 2024, which must be registered by 10 December 2026 and will apply to APP entities providing social media services, relevant electronic services, or designated internet services likely to be accessed by children.
  4. SpeculativeOffice of the Australian Information CommissionerThe draft Children's Online Privacy Code's applicability extends to designated internet services likely to be accessed by children or primarily concerning children's activities, which may capture certain education-adjacent online services, though the OAIC has not yet finalised sector-specific carve-outs.

#

Well-resourced, increasingly assertive enforcement with escalating penalties, multiple concurrent major proceedings, and new private/collective redress avenues, tempered by acknowledged case-backlog capacity constraints.

Primary frameworkPrivacy Act 1988 (Cth) Part IIIC / ss 13G–13K, 80U–80W; Schedule 2 (statutory tort)
Traffic-light rationale — GreenWell-resourced, increasingly assertive enforcement with escalating penalties, multiple concurrent major proceedings, and new private/collective redress avenues, tempered by acknowledged case-backlog capacity constraints.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Tiered civil penalty regime: up to $50M (s13G, serious/repeated) and up to $660,000 (s13H, new mid-tier).

Claims: CLM-AU-c5e6f7a8, CLM-AU-d6e7f8b9

Enforcement Activity IndexGreen

Record 2025 NDB notifications; first civil penalty (ACL); ongoing Optus/Medibank proceedings; new CIIs into rentaltech, connected cars, tracking pixels.

Claims: CLM-AU-e7f8b9c0, CLM-AU-f8b9c0d1, CLM-AU-a9c0d1e2

Regulator Funding And CapacityAmber

Dedicated Children's Code funding (AUD3M/3yrs) but acknowledged general complaint-handling backlog in 2026.

Claims: CLM-AU-b0d1e2f3, CLM-AU-c1e2f3a4

Collective Redress And Class ActionsGreen

Representative complaints (s36) and parallel Federal Court class actions both operate as collective redress routes.

Claims: CLM-AU-d2f3a4b5, CLM-AU-e3a4b5c6

Private Right Of ActionGreen

Statutory tort for serious invasions of privacy in force since 10 June 2025.

Claims: CLM-AU-f4b5c6d7

Recent Developments 180DGreen

Qantas preliminary inquiry report (16 July 2026), Medmate/Monash IVF determination, and ADM consultation closing 15 June 2026 are the most salient developments inside the 180-day window.

Claims: CLM-AU-a5c6d7e8, CLM-AU-b6d7e8f9, CLM-AU-c7e8f9a0

Category narrative100 words

The OAIC's enforcement toolkit was substantially strengthened by the December 2022 penalty increase (up to $50M/3x benefit/30% turnover for serious/repeated interferences) and the POLA Act 2024's new mid-tier civil penalty and infringement/compliance notice powers. 2025 saw record NDB notifications and the OAIC's first-ever court-ordered civil penalty (Australian Clinical Labs, $5.8M), with Optus and Medibank civil-penalty proceedings continuing into 2026 alongside a $50M Meta enforceable undertaking. A statutory tort for serious invasions of privacy (in force since 10 June 2025) and representative-complaint mechanisms provide collective and private redress routes, though the OAIC reported a significant individual-complaint backlog as of February 2026.

No periodic updates recorded against this sub-brief.

Sources and claims (13)
  1. ConfirmedOffice of the Australian Information CommissionerSince amendments effective December 2022, the maximum civil penalty for a body corporate's serious or repeated interference with privacy under s13G is the greater of $50 million, three times the value of the benefit obtained, or 30% of the entity's adjusted turnover during the breach period.
  2. ConfirmedOffice of the Australian Information CommissionerThe Privacy and Other Legislation Amendment Act 2024 introduced a new mid-tier civil penalty under s13H for interferences with privacy that do not meet the 'serious' threshold, capped at 2,000 penalty units (AUD 660,000).
  3. ConfirmedOffice of the Australian Information CommissionerIn its first civil-penalty judgment under the Privacy Act, the Federal Court ordered Australian Clinical Labs to pay $5.8 million for privacy breaches connected to its February 2022 Medlab Pathology data breach affecting over 223,000 individuals.
  4. ConfirmedOffice of the Australian Information CommissionerThe OAIC received a record 1,205 data breach notifications in the 2025 calendar year, an 8% increase over 2024's 1,112 notifications and the highest annual total since the NDB scheme commenced in 2018.
  5. ConfirmedOffice of the Australian Information CommissionerAs of early 2026 the OAIC intended to continue civil-penalty proceedings against Optus and Medibank through the year, alongside Commissioner-initiated investigations into rental-technology platforms, connected cars and tracking pixels.
  6. ConfirmedInternational Association of Privacy ProfessionalsThe OAIC was allocated AUD 3 million in funding over three years to fully develop the Children's Online Privacy Code.
  7. ConfirmedOffice of the Australian Information CommissionerAs at February 2026, the OAIC reported a significant backlog of individual privacy complaints, with new validly lodged complaints unlikely to be substantially progressed for 6 to 12 months absent exceptional circumstances.
  8. ConfirmedOffice of the Australian Information CommissionerRepresentative complaints under s36 of the Privacy Act allow the Information Commissioner to investigate on behalf of a class and, if substantiated, declare that class members are entitled to compensation for loss or damage including injury to feelings or humiliation, as pursued in the Medibank and Optus representative complaints.
  9. ConfirmedOffice of the Australian Information CommissionerSeparate from the OAIC's representative complaint process, affected individuals have pursued parallel Federal Court class actions, such as Zoe Lee McClure v Medibank Private Limited, arising from the same 2022 data breach.
  10. ConfirmedOffice of the Australian Information CommissionerA statutory tort for serious invasions of privacy, inserted into Schedule 2 of the Privacy Act, commenced on 10 June 2025, giving individuals a direct court-based avenue for redress independent of the OAIC and applicable to entities beyond APP entities.
  11. ConfirmedOffice of the Australian Information CommissionerThe OAIC published a report of its preliminary inquiries into the 2025 Qantas Airways data breach, released 16 July 2026.
  12. ConfirmedOffice of the Australian Information CommissionerThe Privacy Commissioner found that providers Medmate Australia Pty Ltd and Monash IVF Pty Ltd interfered with the privacy of individuals, per a determination reported on the OAIC's website in 2026.
  13. ConfirmedOffice of the Australian Information CommissionerThe OAIC opened a consultation (Issues Paper) on guidance for the ADM Transparency Obligation, with submissions closing 15 June 2026 ahead of guidance expected by September 2026.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Australia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 57 claim(s), 38 source(s) in the cumulative register.