Clym Logo

Australian Privacy Principles: 2026 Guide for Businesses

Published
Updated
AS
AuthorAdam Safar
10 min read

Australian Privacy Principles compliance guide

Covers the 13 Australian Privacy Principles, the 2024-2026 Privacy Act reforms, penalties including the first $5.8M OAIC case, and how to prepare.

Summarize full article with:

If you think Australia's privacy law is a quiet, low-risk cousin of the GDPR, that assumption is now out of date. Since December 2024, the Act carries new criminal offences, new penalty tiers, and a regulator that is actively taking organisations to court.

Australia's privacy regulator received 1,205 data breach notifications in 2025, the highest number since mandatory reporting began in 2018. A few months earlier, in October 2025, a Federal Court judge ordered pathology group Australian Clinical Labs to pay $5.8 million AUD, the first civil penalty ever handed down under the Privacy Act 1988.

This guide breaks down what the Australian Privacy Principles actually require, what changed under the 2024 reforms, what is likely coming next, and the practical steps you can take to align your website and data handling with them.

Key takeaways
  • The Privacy Act 1988 and its 13 Australian Privacy Principles govern how organisations handle personal information in Australia.

  • The Privacy and Other Legislation Amendment Act 2024 added doxxing offences, a new privacy tort, and tougher penalties.

  • Serious breaches can now cost up to $50 million AUD or 30% of adjusted turnover, whichever is greater.

  • The OAIC issued its first ever Privacy Act civil penalty in October 2025: $5.8 million against Australian Clinical Labs.

  • The small business exemption still applies below $3 million AUD turnover, though a future reform is expected to remove it.

  • A new Children's Online Privacy Code is due to be registered by 10 December 2026.

What is the Privacy Act 1988 and who does it apply to?

The Privacy Act 1988 is Australia's principal data protection law. It sets national standards for how government agencies and private-sector organisations collect, use, store, and disclose personal information. It created the Australian Privacy Principles that put those standards into practice.

The Act is overseen by the Office of the Australian Information Commissioner (OAIC), which investigates complaints, issues guidance, and, increasingly, takes organisations to court.

For a fast reference on timelines, exemptions and enforcement, see Clym's Australia Privacy Act 1988 regulation summary.

Which organisations need to comply

  • Australian Government agencies.

  • Private sector and not-for-profit organisations with annual turnover above $3 million AUD.

  • Any business, regardless of size, that handles health information or other sensitive information, or that trades in personal information.

  • Foreign organisations that collect or hold personal information about individuals in Australia.

The small business exemption is likely on borrowed time

Businesses with turnover under $3 million AUD are currently exempt from most of the Privacy Act, unless they handle sensitive information, trade in personal information, or are related to a business that must comply. That threshold has not changed yet. What has changed is the direction of travel: the OAIC supports removing the exemption entirely, and it is one of the items under active discussion in the government's second tranche of privacy reforms. No date has been legislated, so if your business currently relies on this exemption, treat it as a planning risk rather than a permanent shield.

What are the Australian Privacy Principles (APPs)?

The Australian Privacy Principles are the 13 legally binding standards set out in Schedule 1 of the Privacy Act. They cover the entire lifecycle of personal information, from collection through use, storage, access and correction, and they apply in the same way to government agencies and to private sector organisations covered by the Act.

APP

What it requires

  1. Open and transparent management

Maintain a clear, up to date privacy policy that describes how you handle personal information.

  1. Anonymity and pseudonymity

Let individuals interact with you anonymously or under a pseudonym where that is practical.

  1. Collection of solicited information

Only collect personal information that is reasonably necessary for your functions or activities.

  1. Dealing with unsolicited information

Assess unrequested personal information you receive, and destroy or de-identify it if you could not have collected it lawfully.

  1. Notification of collection

Tell individuals what you are collecting, why, and how, at or before the time of collection.

  1. Use or disclosure

Use personal information only for the purpose it was collected, unless an exception applies.

  1. Direct marketing

Give individuals a simple, functioning way to opt out of marketing communications.

  1. Cross-border disclosure

Take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs.

  1. Government related identifiers

Do not adopt a government identifier, such as a Medicare number, as your own customer identifier.

  1. Quality of personal information

Keep the personal information you hold accurate, complete and up to date.

  1. Security of personal information

Protect personal information from misuse, loss and unauthorised access, and destroy or de-identify it once it is no longer needed.

  1. Access

Give individuals access to the personal information you hold about them, on request.

  1. Correction

Correct inaccurate or outdated personal information on request, and notify relevant third parties of the correction.

Personal information vs. sensitive information

Personal information is any information about an identified or reasonably identifiable individual, such as a name, email address, IP address, or purchase history. Sensitive information is a narrower, higher-protection category that includes health information, genetic and biometric data, racial or ethnic origin, religious beliefs, sexual orientation, and criminal record. Sensitive information generally needs express, opt-in consent before you collect it.

How Australia's Privacy Act compares to the GDPR and CCPA

The Privacy Act shares goals with the EU's GDPR and California's CCPA, transparency, purpose limitation, and individual rights, but the details differ enough to catch multinational teams out.

Feature

Australia (Privacy Act / APPs)

EU (GDPR)

US (CCPA/CPRA)

Regulator

OAIC

National supervisory authorities

California Privacy Protection Agency

Default consent model

Notice-based for general use; express opt-in for sensitive information

Opt-in required for most processing

Opt-out model

Maximum penalty

$50M AUD or 30% of adjusted turnover

€20M or 4% of global turnover

Roughly $8,000 per intentional violation (adjusted periodically)

Individual right to sue

Yes, new statutory tort since June 2025

Indirect, via supervisory authority complaints and some member state rights

Limited, mainly for specific data breaches

If your business already handles GDPR or CCPA compliance, you have a head start, most of the operational muscle (privacy policies, consent records, breach response) carries over. For a side by side breakdown of running all three at once, see Clym's guide on managing GDPR, CCPA, and other global privacy regulations at the same time. Australian companies with customers in California should also review Clym's guide on what Australian companies need to know to comply with CCPA.

What changed under the Privacy and Other Legislation Amendment Act 2024

Australia passed its first major privacy reform in over a decade in December 2024. Here is what actually changed.

The Privacy and Other Legislation Amendment Act 2024 received royal assent on 10 December 2024, and most of its provisions took effect the following day.

  • Doxxing is now a criminal offence, punishable by up to 6 years in prison, or 7 years where the offence is motivated by race, religion, sex, or gender identity.

  • A new statutory tort for serious invasions of privacy took effect in June 2025, letting individuals sue directly for intrusion into their seclusion or misuse of their personal information.

  • The OAIC gained a mid-tier civil penalty option alongside the existing serious-breach tier: up to $660,000 AUD for individuals and $3.3 million AUD for companies, plus new infringement and compliance notice powers.

A "whitelist" mechanism was introduced, allowing the government to designate countries with adequate privacy protections for cross-border data transfers, though no countries had been whitelisted as of mid-2026.

The OAIC must register a Children's Online Privacy Code by 10 December 2026, covering apps, games, and online platforms used by children and teenagers, not just social media.

What is likely in the next round of reforms (tranche 2)

The government confirmed in February 2026 that a second tranche of reforms is being progressed, though no timetable has been set. Items understood to be in scope include removing the $3 million small business exemption entirely, introducing a "fair and reasonable" test that would apply regardless of consent, and reworking or removing the exemption for employee records. None of this is law yet, but it signals where compliance obligations are heading.

What happens if you do not comply: enforcement and penalties

Non-compliance is no longer a theoretical risk in Australia.

The Australian Clinical Labs penalty was the first of its kind, but it will not be the last. The Federal Court's ruling followed a data breach that exposed the health information of more than 223,000 people, and the delay in reporting it to the OAIC was central to the case.

Two larger cases remain before the courts. Civil penalty proceedings against Medibank and against Optus, following breaches that affected roughly 9.7 million and 9.5 million Australians respectively, were both continuing as of mid-2026.

Most breaches, though, never reach a courtroom, they get reported under the Notifiable Data Breaches scheme. Organisations covered by the Privacy Act must notify the OAIC and affected individuals when a data breach is likely to result in serious harm. Health service providers accounted for 19% of the 1,205 notifications received in 2025, the largest single sector, followed by finance and government agencies.

Penalties now scale with severity. Less serious interferences with privacy can attract civil penalties of up to $660,000 AUD for individuals and $3.3 million AUD for companies. Serious or repeated interferences can reach $50 million AUD or 30% of adjusted turnover, whichever is greater.

Consent under the Australian Privacy Principles: express vs. implied

The APPs recognise two forms of consent. Express consent is a clear, unambiguous action: ticking a box, clicking "I agree", or answering a direct question. Implied consent exists when it is reasonable to infer agreement from someone's conduct and the surrounding circumstances, though regulators read this narrowly.

Sensitive information almost always needs express, opt-in consent. For a full breakdown of consent models across different regulations, see Clym's guide to different types of consent.

Even where the APPs do not strictly require a cookie banner, using one is widely considered good practice for demonstrating notice and consent, especially given the OAIC's increased enforcement appetite.

7 steps to align your website with the Australian Privacy Principles

1. Publish or update your APP privacy policy. It needs to disclose what you collect, why, how people can access or correct it, and whether data goes overseas. Clym's policy management solution can help you generate and version privacy and cookie policies across jurisdictions.

2. Map every cookie and tracker on your site. Analytics tools, ad pixels, and session recording software typically collect personal information and fall within the APPs.

3. Give visitors real consent choices, not just a policy. A consent banner should let people accept, reject, or customise their preferences, and apply the right notification format automatically based on where the visitor is located.

4. Set up a documented process for data subject requests, including access, correction and, where applicable, deletion. Clym's data subject request management tool centralises intake and tracking so requests do not fall through the cracks.

5. Review your cross-border data flows. Know which vendors and cloud providers process Australian personal information overseas, and check whether adequate protections are in place.

6. Build or refresh your data breach response plan. You need to be able to assess, contain, and where necessary notify the OAIC and affected individuals promptly, delays were central to the Australian Clinical Labs case.

7. Watch out for the Children's Online Privacy Code. If children or teenagers are likely to use your service, start reviewing your data practices against the draft code now rather than waiting for the December 2026 deadline.

Common mistakes businesses make with Australian privacy compliance

  • Treating the Privacy Act as "GDPR lite" and skipping Australia-specific requirements like notifiable data breach obligations and doxxing risk.

  • Assuming the small business exemption applies without checking whether they handle sensitive information or trade in personal information, both of which remove the exemption.

  • Publishing a generic privacy policy that does not reflect actual data practices.

  • Treating consent as a one-time checkbox instead of an ongoing, documented record.

  • Having no tested plan for reporting an eligible data breach within a reasonable timeframe.

How Clym supports Australian Privacy Principles compliance

Managing privacy requirements under the APPs can involve several parts of a website, from cookie and tracking disclosures to consent preferences, privacy policies, and individual privacy requests. Clym brings these workflows into a single platform rather than relying on several disconnected tools.

RealtimeCompliance™ scans your website for cookies and trackers, while ReadyCompliance® helps configure consent experiences based on applicable regional requirements. Clym’s policy and data subject request tools can also help teams manage privacy documentation and requests from one place.

Clym does not replace legal advice or guarantee compliance outcomes, but it can reduce the manual work involved in managing website privacy requirements as Australia’s privacy framework evolves.

Conclusion

Australia's privacy landscape looks very different from the one this article originally described in 2020. The Privacy Act 1988 and its 13 Australian Privacy Principles are still the foundation, but the 2024 reforms added criminal doxxing offences, a new privacy tort, and a mid-tier penalty option, and the OAIC has shown with Australian Clinical Labs that it is willing to use its enforcement powers. More change is coming: a Children's Online Privacy Code is due by December 2026, and a second reform tranche could remove the small business exemption altogether.

None of this needs to be overwhelming if you treat it as an ongoing programme rather than a one-off checklist: a current privacy policy, real consent choices, a documented request process, and a tested breach response plan cover most of what the APPs require. The businesses that get caught out are usually the ones that set a policy once and never revisit it.

Frequently asked questions

The 13 Australian Privacy Principles set out in the Privacy Act 1988 cover how organisations manage personal information, from collection and consent through storage, security, access and correction. They range from transparency requirements (APP 1) to cross-border disclosure rules (APP 8) and individual rights to access and correct their data (APPs 12 and 13).

Most small businesses with annual turnover under $3 million AUD are exempt, but the exemption does not apply if you handle health or other sensitive information, trade in personal information, or are related to a business that must comply. A future reform is expected to remove this exemption altogether.

Penalties depend on severity. Less serious interferences can attract civil penalties of up to $660,000 AUD for individuals and $3.3 million AUD for companies. Serious or repeated interferences can reach $50 million AUD or 30% of adjusted turnover, whichever is greater.

They share similar goals, transparency, purpose limitation, and individual rights, but differ in the details. The GDPR generally requires opt-in consent for most processing and carries fines of up to 4% of global turnover, while the Privacy Act uses a narrower consent trigger and a higher maximum penalty of 30% of turnover for serious breaches.

The Notifiable Data Breaches scheme requires organisations covered by the Privacy Act to notify the OAIC and affected individuals when a data breach is likely to result in serious harm. The OAIC received a record 1,205 notifications in 2025, the highest since the scheme began in 2018.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam