Australian Privacy Act
compliance with RecordPoint
The Australian Privacy Act (Privacy Act) is the principle law governing the handling of personal information about individuals.First passed in 1988, the law initially covered only how Australian government agencies handled the data of their citizens during regular operations. From 2001, it began to cover private organizations as well, and has evolved in the past 20 years to add new controls and coverage throughout Australia. With RecordPoint, organizations can be confident in their compliance with this critical law.
.png)
Easily respond to consumer rights request


Know exactly where sensitive data lives
What is the Australian Privacy Act?
The Privacy Act was passed to put in guardrails around how government agencies and certain private sector companies should manage the personal data of Australia and Norfolk Island citizens. The Act is the principal piece of Australian legislation protecting the handling of personal information about individuals. This includes the collection, use, storage and disclosure of personal information in the federal public sector and in the private sector.
All Australian government agencies need to comply with the act. In terms of businesses, they need to comply with the Privacy Act in general if they have more than A$3 million in annual turnover. Healthcare providers, credit reporting agencies, or companies who trade in personal information need to comply with the Act regardless of annual turnover.
The Act has been revised several times over the years, with the most recent amendments made in November 2024. The Privacy and Other Legislation Amendment Act 2024 revised the Privacy Act in accordance with the review of the Privacy Report completed in 2023.
New additions to the Act as of November, 2024:
- A new statutory tort to address serious invasions of privacy
- Development of a Children's Online Privacy Code to better protect children from a range of online harms, supported by an additional A$3 million over three years to the Office of the Australian Information Commissioner for it to develop this important Code
- Greater transparency for individuals regarding automated decisions that affect them
- Streamlined information sharing in the case of an emergency or eligible data breach, while ensuring that information is appropriately protected
- Stronger enforcement powers for the Australian Information Commissioner
These reforms are meant to improve the control Australians have over their personal data, and also include a new criminal offense related to doxxing. This new criminal charge makes the penalties stronger for maliciously releasing personal information online.
How can businesses comply with the Australian Privacy Act?
The most significant action that business can take to comply with the Privacy Act is to follow the 13 Australian Privacy Principles. These principles, introduced in 2014, outline how the Australian government or covered organization should protect the privacy of Australian citizens. These privacy principles include:
Open and transparent management of personal information
Ensure organizations manage personal information in an open and transparent way, and includes creating a privacy policy. When collecting personal information, you need to be clear with how you're managing and using it.
Anonymity and pseudonymity
Ensure individuals have the ability to be anonymous and not identify themselves when working with your organization, or they have the ability to use a pseudonym. There are exceptions under this principle.
Collection of solicited personal information
This principle outlines when an organization can collect personal information, with higher standards applied to sensitive information such as criminal records or health data.
Dealing with unsolicited personal information
This principle describes how to deal with personal information that a covered entity did not ask for. Unsolicited personal data can sometimes be retained if it would have been collected under APP 3.
Notification of the collection of personal information
Describes when a covered entity has to inform individuals about the collection of personal information and the purpose of the collection. Reasonable steps must be taken to communicate at or before the time of collection.
Use or disclosure of personal information
Compliance with this principle means ensuring you disclose how you intend to use collected personal information. According to the Privacy Act, companies are only able to use personal data for one primary purpose. Ensure that this remains the case.
Direct marketing
In general, personal information can't be used for direct marketing, except where there's a reasonable expectation that this is the intended purpose. Organizations also need to provide a way to opt out of receiving marketing communications.
Cross-border disclosure of personal information
Prior to sending personal information overseas, the covered entity needs to take reasonable steps to protect it. This includes ensuring that the overseas recipient doesn't violate the Australian Privacy Principles.
Adoption, use or disclosure of government related identifiers
This principle restricts the adoption, use, and disclosure of government related identifiers by organizations. Ensure that any data collected doesn't use government identifiers unless it's approved to do so.
Quality of personal information
Covered entities need to take reasonable steps to ensure that the personal information it uses and discloses is accurate, up to date, and complete. It also needs to be relevant data to the intended purpose.
Security of personal information
To comply with this principle, you need to take reasonable steps to ensure that personal information is kept secure. This includes adding data protection, implementing role-based access controls, and generally defending personal data against compromise, misuse, and unauthorized access.
Access to personal information
Individuals need to be provided access to their personal information on request. This can include offering up the ability to know what data the organization has on an Australian citizen via a web request or email form.
Access to personal information
Individuals need to be provided access to their personal information on request. This can include offering up the ability to know what data the organization has on an Australian citizen via a web request or email form.
Correction of personal information
Organizations need to ensure there is a process in place to correct any out-of-date personal information. Part of the inherent rule is that all collected personal data needs to be kept up to date. This principle governs the development of those processes.
Penalties for noncompliance
For serious or repeated privacy breaches under the Australian Privacy Act, individuals can face penalties of up to $2.5 million AUD, while companies can be fined up to $50 million AUD, three times the benefit obtained from the breach, or 30% of their adjusted turnover, whichever is greater.
Frequently asked questions
The Australian Privacy Act covers all personal data, including:
- an individual’s name, signature, address, phone number, or date of birth
- sensitive information such as racial or ethnic origin
- credit information like ratings and data included on a credit report
- employee record information
- photographs
- internet protocol (IP) addresses
- voice print and facial recognition biometrics
- location information from a mobile device
All businesses who have annual turnover of more than $3 million AUD within Australia must comply with the Australian Privacy Act. There are some organizations, such as healthcare providers and credit reporting agencies, that must comply with Australian Privacy Principles regardless of annual turnover.
Explore Australian Privacy Act articles & case studies
Regulatory breakdowns, expert commentary, and real-world case studies - everything you need to decode complex Australian Privacy Act requirements, build a defensible compliance strategy, and learn from global enforcement actions.




.avif)



.avif)