PRIVACY ACT · 11 MIN

Privacy Act Reform Australia — Where Tranche 1 Lands, What Tranche 2 Brings

For most Australian organisations the Privacy Act has done more in 24 months than in the prior 20 years. This is the structure CISOs and Privacy Officers are using to keep up.

Run your first mission free

The reform programme in one paragraph

The Privacy and Other Legislation Amendment Act 2024 implemented Tranche 1 of the Government’s response to the Attorney-General’s Privacy Act Review. Tranche 2 — the more disruptive set covering the small-business exemption, employee records, a fair-and-reasonable test and direct rights of action — is the subject of ongoing consultation. CISOs and Privacy Officers should plan controls on a 12–24 month horizon.

What Tranche 1 already requires

  • Statutory tort for serious invasions of privacy (commenced 2025)
  • New OAIC enforcement powers including infringement notices and public-interest determinations
  • Criminal offences for malicious doxxing
  • Automated decision-making transparency in privacy policies (with a transition period)
  • Children’s Online Privacy Code (in development)
  • Information sharing power between OAIC and other regulators

Five actions for CISOs and Privacy Officers

Privacy reform readiness

  • Automated decision-making register. New transparency requirement — maintain an inventory of automated decisions with material effects and publish a plain-English summary.
  • Children's privacy controls. Update consent flows, age-assurance approaches and complaints handling for services likely to be accessed by children.
  • Doxxing response playbook. New criminal offences for malicious doxxing — incident response plans should reflect rapid takedown and law-enforcement engagement.
  • Statutory tort exposure assessment. Map where personal information could be handled in ways a court would consider a serious invasion of privacy; tighten controls and director-level oversight.
  • Small-business / employee-records readiness. Begin scoping APP application as Tranche 2 narrows or removes long-standing exemptions.

FOR PRIVACY LEADERS

Generate a Privacy Act readiness brief for your board.

FORTE/CYBERx produces a tailored readiness brief covering Tranche 1 obligations, Tranche 2 exposure, automated-decision register and OAIC engagement strategy.

Start a free mission

The board conversation

Privacy is now a board topic in its own right, not a footnote in the cyber paper. The questions directors are asking — what would a fair-and-reasonable test mean for our data handling, do we have a defensible position on automated decisions, are we ready for direct rights of action — need answers ready, not promised.

FAQ

What changed with the Privacy and Other Legislation Amendment Act 2024?

Tranche 1, passed in November 2024, introduced a statutory tort for serious invasions of privacy, expanded OAIC enforcement powers, new criminal offences for doxxing, transparency requirements for automated decisions and updated children's privacy provisions. It also enabled an information-sharing power between OAIC and other regulators.

When does Tranche 2 land?

The Government has committed to a second tranche addressing the small-business exemption, the employee-records exemption, a fair-and-reasonable test for personal information handling, and direct rights of action. Timing remains 2026 with consultation through 2025; treat the small-business exemption as living on borrowed time.

What are the new maximum penalties?

The maximum civil penalty for serious or repeated interferences with privacy is the greater of $50 million, three times the benefit derived, or 30% of adjusted turnover for the period of contravention. The OAIC has signalled it will use the new powers.

Does the statutory tort apply to my organisation?

Yes if you are an organisation that intentionally or recklessly invades an individual's privacy in a way a reasonable person would consider serious. The tort is actionable by the individual — no OAIC determination required first.

Related

Privacy reform readiness, on the next board agenda.

Two free missions. No credit card. Built for Australian privacy leaders.