Privacy Act 1988 of Australia
Australia's Privacy Act 1988 is the federal privacy law governing how covered organizations and Australian Government agencies handle personal information.
The Act is built around the 13 Australian Privacy Principles (APPs), which regulate areas including collection, use and disclosure, transparency, direct marketing, overseas disclosures, data quality, security, access, and correction.
The Privacy Act has undergone significant reforms, including measures introduced through the Privacy and Other Legislation Amendment Act 2024. Further obligations concerning automated decision-making will commence on 10 December 2026.
The Australian Privacy Act does not operate as a blanket opt-in consent law.
Consent is important in particular situations, including the collection of sensitive information and certain uses or disclosures. For ordinary non-sensitive personal information, organizations may in some circumstances rely on implied consent or other permitted grounds.
Organizations covered by the Act must instead build a broader privacy framework covering:
Australia
In force since 1988; substantially reformed from 2024, with additional obligations commencing in stages
Asia & Africa
The Privacy Act applies to Australian Government agencies and many private-sector organizations that handle personal information.
As a general rule, organizations with annual turnover of more than AU$3 million are covered.
However, some businesses with turnover of AU$3 million or less can also be covered.
Examples include certain:
Therefore, turnover alone does not determine whether an organization is subject to the Act.
The Privacy Act contains 13 Australian Privacy Principles (APPs).
They cover:
The APPs apply throughout the personal-information lifecycle, from collection through use, disclosure, storage, security, access, correction, and destruction.
The Privacy Act provides substantial penalties for serious or repeated interference with privacy.
For a body corporate, the maximum penalty for serious or repeated interference is the greater of:
Individuals can also face significant penalties for applicable contraventions.
The Privacy and Other Legislation Amendment Act 2024 also strengthened the OAIC's enforcement powers and introduced additional privacy protections and remedies.
Organizations covered by the Privacy Act should maintain controls for:
Consent is not required for every collection, use, or disclosure of personal information.
The requirements depend on the type of information and the processing activity.
For example, organizations generally need express consent before handling sensitive information. For non-sensitive personal information, express consent is not always required, although the organization must have a reasonable basis for any implied consent it relies upon.
Consent should be:
Organizations should avoid unclear or bundled consent requests that prevent individuals from understanding which processing activities they are agreeing to.
The Privacy Act provides additional protection for sensitive information.
Sensitive information includes categories such as:
Organizations generally need the individual's consent to collect sensitive information unless an applicable exception applies.
Because sensitive information carries additional privacy risks, organizations should maintain separate controls for its collection, use, disclosure, retention, and security.
APP 5 requires organizations to take reasonable steps to notify individuals, or ensure they are aware, of specified matters when collecting personal information.
Relevant information can include:
Privacy notices should be clear, accessible, and appropriate for the circumstances.
APP 1 requires covered organizations to maintain a clearly expressed and up-to-date privacy policy.
The policy should explain how the organization manages personal information and provide information such as:
The policy should be available free of charge in an appropriate form, generally through the organization's website.
Organizations should collect personal information only where reasonably necessary for their functions or activities.
They should assess:
Organizations should also avoid using or disclosing information for purposes that are incompatible with the original collection purpose unless the APPs permit the additional use or disclosure.
APP 7 places specific restrictions on using and disclosing personal information for direct marketing.
Generally, an organization must not use or disclose personal information for direct marketing unless an applicable exception applies.
Where direct marketing is permitted, individuals must have an effective way to opt out. Organizations must give effect to valid opt-out requests within a reasonable period. OAIC guidance indicates this would generally be no more than 30 days, although digital communications may allow a faster response.
Organizations should therefore maintain:
Australia's Privacy Act does not create a blanket cookie-consent requirement.
Instead, organizations should assess the information collected by cookies, pixels, SDKs, advertising technologies, analytics tools, and other trackers against the APPs.
Relevant considerations include:
This means a website should not automatically assume that every analytics or advertising cookie requires opt-in consent under the Privacy Act.
APP 6 regulates the use and disclosure of personal information.
As a general principle, organizations should use or disclose personal information only for the primary purpose for which it was collected, unless an exception applies.
Additional requirements can apply where information is used for a secondary purpose.
Organizations should document:
APP 8 establishes rules for cross-border disclosure of personal information.
Before disclosing personal information to an overseas recipient, an APP entity generally must take reasonable steps to ensure that the recipient does not breach the APPs in relation to the information.
The Australian organization can remain accountable for certain acts or practices of the overseas recipient.
Organizations should therefore conduct appropriate due diligence on:
There is an exception under APP 8 where an organization expressly informs the individual about the consequences of consenting to the overseas disclosure and the individual then consents.
The information provided should explain that, if the individual consents and the overseas recipient subsequently mishandles the information, the organization may not be accountable under the Privacy Act for that handling and the individual may not have the same redress under the Act.
Consent used for this purpose should be:
Organizations should not seek unnecessarily broad consent for undefined future transfers.
APP 11 requires organizations to take reasonable steps to protect personal information from:
Security measures should be proportionate to factors such as:
OAIC guidance identifies measures such as access controls, audit trails, privacy risk management, employee training, and breach-response procedures as relevant privacy governance controls.
Australia operates a Notifiable Data Breaches (NDB) scheme.
Where an organization has reasonable grounds to suspect an eligible data breach, it must undertake an assessment and, where the breach is an eligible data breach, notify affected individuals and the OAIC as required.
An eligible data breach generally involves unauthorized access to, disclosure of, or loss of personal information where the circumstances are likely to result in serious harm to affected individuals.
Organizations should maintain:
APP 12 provides individuals with a right to request access to personal information held about them, subject to applicable exceptions.
Organizations should provide a clear and accessible process for:
Privacy policies should explain how individuals can request access to their information.
Under APP 13, individuals can request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
Organizations should maintain procedures for:
APP 2 provides individuals with the ability to deal with an organization anonymously or using a pseudonym where practicable, subject to exceptions.
Organizations should therefore consider whether identity is genuinely necessary for a particular interaction before requiring identifying information.
Organizations should not retain personal information indefinitely when it is no longer required.
APP 11 includes obligations concerning the destruction or de-identification of personal information that is no longer needed, subject to applicable exceptions and retention requirements.
Organizations should maintain:
The OAIC recommends that organizations consider conducting a Privacy Impact Assessment (PIA) when introducing projects or changing practices involving personal information.
A PIA can help identify privacy risks before a system, product, technology, or business process is deployed.
Relevant projects can include:
OAIC guidance specifically identifies PIAs as a practice organizations should consider as part of their APP 1 compliance systems.
Australia's Privacy Act reforms introduce new transparency requirements for certain automated decisions.
From 10 December 2026, APP entities that arrange for a computer program to use personal information to make, or substantially contribute to, decisions that could reasonably be expected to significantly affect an individual's rights or interests will have additional privacy-policy obligations.
Privacy policies will need to provide specified information about:
Organizations using AI or automated decision systems should therefore review their privacy policies before the December 2026 commencement date.
A statutory tort for serious invasions of privacy commenced on 10 June 2025.
The new cause of action can provide individuals with a separate avenue for seeking redress for certain serious invasions of privacy, including:
The tort has requirements, defenses, exemptions, and public-interest considerations separate from ordinary APP compliance. Courts can grant remedies including damages, injunctions, or an order requiring an apology.
This means organizations should consider privacy risks more broadly than simply checking whether their practices comply with the APPs.
The Privacy Act contains several exemptions and special regimes.
Organizations should assess whether specific activities fall within exemptions relating to areas such as:
Exemptions can be narrow and fact-specific, so organizations should not assume that an entire business is exempt merely because one processing activity falls within an exemption.
ConsentX can help organizations operationalize website-level privacy and consent controls relevant to the Australian Privacy Act.
Configure consent experiences for processing activities where consent is required.
Create clear consent flows for sensitive-information processing where express consent is required.
Use configurable consent interfaces to provide relevant information about website data collection and processing.
Maintain user choices and opt-out preferences relevant to marketing activities.
Prevent configured non-essential cookies and tracking technologies from activating before the applicable user choice.
Identify website technologies and third-party services that may transfer information overseas and support appropriate privacy disclosures and consent workflows where applicable.
Maintain auditable records showing:
Support workflows for access, correction, deletion, and other privacy requests where applicable.
Use region-specific rules to present an appropriate privacy and consent experience to Australian visitors.
Build a structured website privacy and consent workflow aligned with Australia's Privacy Act and Australian Privacy Principles.
Scan your website, identify cookies and trackers, configure appropriate consent and preference controls, block applicable trackers, and maintain auditable records of user choices.
Run a website scan to identify:
Identify what personal information your website collects and determine:
Determine which activities require express consent and which can rely on other permitted grounds.
Pay particular attention to:
Create a clear consent experience that allows users to understand relevant processing activities and make meaningful choices.
Avoid bundling unrelated consent requests into one mandatory choice.
Use prior-script blocking to prevent configured non-essential tracking technologies from activating before the applicable user preference is recorded.
Maintain auditable consent records containing:
Provide appropriate opt-out controls for direct marketing and maintain suppression preferences.
Use the DSAR workflow to manage applicable requests for access and correction and other privacy-related requests.
Identify analytics, advertising, cloud, CRM, support, and other third-party providers that receive information outside Australia.
If your organization uses personal information in automated decision-making that could significantly affect individuals, review your privacy policy before the 10 December 2026 commencement of the new APP 1 requirements.
This page provides a plain-English overview of Australia's Privacy Act 1988 and Australian Privacy Principles for general informational purposes. It is not legal advice.
The Privacy Act contains exemptions, permitted situations, sector-specific requirements, and additional privacy regimes that may affect an organization's obligations. Organizations should assess their specific activities and obtain qualified Australian legal advice where necessary.
The Privacy Act has also undergone significant reforms, with some provisions already in force and others commencing at later dates. Organizations should verify the applicable commencement date and current OAIC guidance before relying on any particular requirement.