1. Who the Privacy Act applies to
  2. How the penalty regime changed in December 2022
  3. What new enforcement and information-sharing powers the OAIC now holds
    1. Expanded assessment and investigation powers
    2. Information-sharing with other regulators
  4. How the extraterritoriality provisions were updated
  5. Where businesses commonly go wrong
  6. How Artificer Legal can assist
  7. Key takeaways

Australian privacy law has changed substantially since late 2022, and the consequences of getting it wrong are now far more serious than they were a few years ago. The Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth), which commenced on 13 December 2022, transformed the penalty regime under the Privacy Act 1988 (Cth) from one of modest fines to one that can reach into the tens of millions of dollars. The Privacy and Other Legislation Amendment Act 2024 (Cth), which commenced in December 2024, has since added further changes — including a statutory tort for serious invasions of privacy and a Children's Online Privacy Code.

This article explains the core elements of the 2022 enforcement reforms, how the penalty regime now works, what new powers the Office of the Australian Information Commissioner (OAIC) has, and what businesses covered by the Privacy Act need to do in response.

The key topics covered are:

  • Who the Privacy Act applies to
  • How the penalty regime changed in December 2022
  • What new enforcement and information-sharing powers the OAIC now holds
  • How the extraterritoriality provisions were updated
  • Where businesses commonly go wrong
  • How Artificer Legal can assist

Who the Privacy Act applies to

The Privacy Act applies to most Australian Government agencies and to private sector organisations that are "APP entities" — that is, entities that are subject to the Australian Privacy Principles (APPs). In the private sector, an organisation generally becomes an APP entity once its annual turnover exceeds $3 million. The $3 million threshold is not the only route in. Regardless of turnover, an organisation is also covered if it is a health service provider, trades in personal information for a benefit, service or advantage, is a credit reporting body, or is a contractor providing services under a Commonwealth contract.

Small businesses below the $3 million threshold should still check whether a specific category catches them — particularly if they handle health information or have a government contract.

How the penalty regime changed in December 2022

Before 13 December 2022, the maximum civil penalty for a serious or repeated interference with the privacy of an individual by a body corporate was $2.22 million per contravention. For individuals and sole traders, it was $440,000. Those figures gave the Privacy Act a reputation for having teeth that were rarely sharp enough to change corporate behaviour.

The 2022 Act rewrote s 13G of the Privacy Act. The new maximum civil penalty for a body corporate is the greatest of three alternative calculations:

  • $50 million; or
  • three times the value of any benefit obtained directly or indirectly by the body corporate and any related bodies corporate that is reasonably attributable to the conduct constituting the contravention; or
  • 30% of the body corporate's adjusted turnover during the breach turnover period for the contravention (with a minimum period of twelve months applying to the calculation).

For a person other than a body corporate — for example, an individual or sole trader — the maximum civil penalty is now $2.5 million.

These penalties apply to a serious or repeated interference with the privacy of an individual. The Act does not provide a closed definition of what is "serious" — it is an objective test, assessed by reference to what a reasonable person would regard as serious in the circumstances. A breach affecting a large number of individuals, a breach that exposes sensitive information such as health or financial data, or a pattern of repeated non-compliance are the kinds of conduct most likely to attract the higher penalty regime.

The penalty structure mirrors that which applies under the Competition and Consumer Act 2010 (Cth) for cartel conduct and other serious contraventions, signalling that Parliament now treats privacy breaches with the same gravity as anti-competitive behaviour.

What new enforcement and information-sharing powers the OAIC now holds

The 2022 Act substantially expanded the powers available to the OAIC, Australia's privacy regulator.

Expanded assessment and investigation powers

The OAIC can now conduct assessments of an entity's compliance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act — not just its compliance with the APPs generally. This includes assessing whether an entity has adequate processes and procedures in place to identify, assess, and notify eligible data breaches. The Commissioner also has an express power under s 26WU to require an entity to give information, produce documents, or answer questions relating to an actual or suspected eligible data breach.

If an entity fails to comply with an OAIC requirement to give information, produce a document or answer a question, it can face an infringement notice.

Information-sharing with other regulators

The 2022 Act gave the OAIC express power to share information with a range of other bodies, including:

  • enforcement bodies;
  • alternative complaint bodies; and
  • State, Territory and foreign privacy regulators.

The purpose of sharing must be to enable either the OAIC or the receiving authority to perform its functions or exercise its powers. For example, the OAIC can share information with the eSafety Commissioner on matters relating to online safety. To safeguard privacy in the sharing process itself, the OAIC must be satisfied on reasonable grounds that the receiving authority has adequate arrangements in place for maintaining the security of the information before it discloses it.

The OAIC also now has express power to publish its final determinations following privacy investigations, and information about final assessment reports, on its publicly accessible website. This means that the reputational consequences of an OAIC finding are now more direct — the regulator can name and publish.

The 2022 Act also amended the Australian Communications and Media Authority Act 2005 (Cth) to permit the ACMA to share information with any non-corporate Commonwealth entity responsible for enforcing a Commonwealth law where the information will help that entity perform its functions.

How the extraterritoriality provisions were updated

Before 13 December 2022, a foreign organisation had an "Australian link" — and was therefore potentially bound by the Privacy Act — only if it both (a) carried on business in Australia and (b) had collected or held the relevant personal information in Australia before or at the time of the act. That second element created a gap: a global technology company that processed data about Australians entirely outside Australia could argue it fell outside the Act's reach.

The 2022 Act removed the second element. Under the current s 5B, a foreign organisation has an Australian link if it carries on business in Australia — full stop. It no longer matters whether the personal information was collected or held in Australia. A company that markets its services to Australian customers, receives payment from them, or otherwise conducts commercial activity directed at Australia can be subject to the Privacy Act even if all its data processing occurs offshore.

This change aligns the Privacy Act's extraterritoriality provisions with those in the Competition and Consumer Act 2010 (Cth) and reflects the cloud-based, cross-border reality of how personal information is now handled.

Where businesses commonly go wrong

Even with the new penalty regime in place since December 2022, businesses often find compliance harder in practice than it appears in theory. Common problem areas include:

  • Treating privacy as a documentation exercise. A privacy policy on a website is not sufficient. The APPs impose ongoing obligations around collection, use, disclosure, security, access and correction. A policy that was drafted when the business launched and never reviewed is likely to be out of date and potentially misleading.

  • Not knowing when the NDB scheme applies. The NDB scheme requires APP entities to notify the OAIC and affected individuals when an eligible data breach occurs. Many businesses either do not recognise a breach when it happens, or are unsure whether the threshold for "likely to result in serious harm" has been met. Delay in notification is itself a potential compliance failure.

  • Assuming size is a shield. Businesses close to the $3 million turnover threshold, or that are growing quickly, should check their status regularly. A business that was below the threshold last year may be covered now.

  • Overlooking third-party data flows. APP entities remain responsible for how personal information they have collected is handled by their service providers and offshore processors. A contract that requires a service provider to handle information in accordance with the APPs is a baseline requirement, not a complete answer.

  • Ignoring overseas data transfers. The 2024 Act introduced a new mechanism for cross-border data transfers, including a future whitelist of countries and binding schemes with adequate protections. APP 8 already imposes obligations on entities that disclose personal information to an overseas recipient, and those obligations apply now.

Navigating Privacy Act compliance is not a one-off task. A privacy lawyer will typically assist a business by:

  1. Assessing whether the business is an APP entity and what obligations apply given its size, sector, and data flows.
  2. Reviewing or drafting a privacy policy that accurately describes how personal information is collected, used, stored, disclosed and deleted.
  3. Preparing or reviewing a data breach response plan so the business has a process in place before an incident occurs, rather than working out what to do in the middle of one.
  4. Reviewing contracts with third-party suppliers and cloud service providers to ensure privacy obligations flow down appropriately.
  5. Advising on whether a specific incident meets the NDB notification threshold, and assisting with notification if required.
  6. Providing ongoing advice as the law continues to develop — the 2024 Act introduced a statutory tort for serious invasions of privacy and is directing the OAIC to develop a Children's Online Privacy Code by December 2026, both of which will affect businesses interacting with consumers online.

If you have questions about how the Privacy Act applies to your business, or you need help updating your privacy documents or preparing a data breach response plan, contact Artificer Legal to speak with one of our privacy lawyers.

Key takeaways

Australia's privacy enforcement framework has been materially strengthened. The essentials for any APP entity to keep in mind are:

  • The Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth) commenced on 13 December 2022 and is in force.
  • For a body corporate, a serious or repeated privacy breach can now attract a civil penalty of up to $50 million (or a turnover-based amount if greater).
  • For individuals, the maximum civil penalty is $2.5 million.
  • The OAIC has broader powers to investigate, assess, issue notices, and share information with other regulators.
  • A foreign organisation that carries on business in Australia is subject to the Privacy Act regardless of where it processes personal information.
  • Further reforms under the 2024 Act are already in effect, with more to come by December 2026.

Businesses that handle personal information should treat privacy compliance as a continuous obligation rather than a box-ticking exercise. The penalty regime now gives the regulator tools that are proportionate to the scale of data breaches that have become a regular feature of the Australian business landscape.