TODAY: 1 NEW BREACH·LAST 30 DAYS: 4·RECORDS THIS YEAR: 5.6M·MOST TARGETED: GOVERNMENT·TOP ORIGIN: France·LARGEST BREACH: MedCore Systems — S3 Bucket Exposure (4.2M)·GLOBAL THREAT LEVEL: NORMAL·TODAY: 1 NEW BREACH·LAST 30 DAYS: 4·RECORDS THIS YEAR: 5.6M·MOST TARGETED: GOVERNMENT·TOP ORIGIN: France·LARGEST BREACH: MedCore Systems — S3 Bucket Exposure (4.2M)·GLOBAL THREAT LEVEL: NORMAL
🇦🇺

Australia Data Privacy Regulations

Privacy Act 1988 (Privacy Act)
High Severity
Enacted: 1988 (Amended: 2022 (Penalty increases))

Overview

The main privacy law in Australia is the Privacy Act 1988, which includes the 13 Australian Privacy Principles (APPs). Recent amendments significantly increased maximum penalties following massive national data breaches.

Scope of Application:

Australian Government agencies, businesses with an annual turnover over $3 million, and specific entities holding health data.

Key Rules & Obligations

Breach Notification

As soon as practicable (Notifiable Data Breaches scheme).

Maximum Penalties

Up to $50 million AUD, or 3x the value of the benefit obtained, or 30% of adjusted turnover in the breach period.

Data Transfers

Entity must take reasonable steps to ensure foreign recipient does not breach the APPs (APP 8).

Individual Rights

  • Right to know why data is collected
  • Right to ask for access
  • Right to correct data
  • Option to remain anonymous

Enforcement Authority

Office of the Australian Information Commissioner (OAIC)

Contact: 1300 363 992

Visit Authority Website

Notable Breaches in Australia

CompanyYearRecords ExposedRegulation Violated
Optus20229,800,000Privacy Act 1988
Medibank20229,700,000Privacy Act 1988

Official Sources

Frequently Asked Questions

Is the Australian Privacy Act equivalent to GDPR?

No. The Privacy Act is generally less stringent and only applies to businesses with over $3M AUD revenue, though the government is currently reviewing proposals to align it closer to GDPR standards.

What happens if a company breaches the Australian Privacy Act?

Following 2022 amendments, maximum fines surged to $50 million AUD or 30% of turnover for serious or repeated interferences with privacy.

How do I report a data breach in Australia?

Organizations must notify the OAIC via an online form when an eligible data breach that is likely to result in serious harm occurs.

Last updated: March 5, 2026

Notice an error? Report a correction