Australian Privacy Act 1988

InternationalPrivacy1988
ByDecipherU Editorial

The Australian Privacy Act governs cybersecurity and privacy for personal information handled by Australian government agencies and private sector organizations with over $3 million AUD annual turnover. The Notifiable Data Breaches (NDB) scheme (Part IIIC, added 2018) requires organizations to notify the OAIC and affected individuals of eligible data breaches. Major reforms proposed in 2024 would strengthen individual rights.

Quick Reference

Enacted1988; NDB scheme commenced February 22, 2018
Last AmendedPrivacy Legislation Amendment (Enforcement and Other Measures) Act 2022; reforms proposed 2024
Enforcement BodyOffice of the Australian Information Commissioner (OAIC)
PenaltiesUp to 50 million AUD, three times the value of any benefit obtained, or 30% of adjusted turnover, whichever is greatest (2022 amendment)
Applicable ToAustralian government agencies, private sector organizations with >$3M AUD annual turnover, health service providers, and certain small businesses

Key Requirements

Australian Privacy Principle (APP) 11

Entities must take reasonable steps to protect personal information from misuse, interference, loss, unauthorized access, modification, or disclosure

Part IIIC, Section 26WE (Notification of eligible data breaches)

Organizations must notify the OAIC and affected individuals as soon as practicable after becoming aware of an eligible data breach

APP 8 (Cross-border disclosure)

Before disclosing personal information overseas, entities must take reasonable steps to ensure the overseas recipient complies with the APPs

How Does AU Privacy Act Affect Cybersecurity Careers?

Cybersecurity professionals in Australia must understand the Privacy Act and NDB requirements. The 2022 penalty increase (up to 50 million AUD) increased the importance of cybersecurity roles at Australian organizations. Incident responders must understand 'eligible data breach' definitions to trigger proper notification.

How Does AU Privacy Act Affect Cybersecurity Sales?

The 2022 penalty increase to 50 million AUD created urgency for cybersecurity investments among Australian businesses. Breach detection and notification platforms address NDB scheme requirements. Vendors entering the Australian market should understand the turnover threshold and NDB timelines.

Cybersecurity Roles That Work With AU Privacy Act

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of AU Privacy Act at the official source: https://www.legislation.gov.au/C2004A03712/latest/versions

Frequently Asked Questions

The Australian Privacy Act governs cybersecurity and privacy for personal information handled by Australian government agencies and private sector organizations with over $3 million AUD annual turnover. The Notifiable Data Breaches (NDB) scheme (Part IIIC, added 2018) requires organizations to notify the OAIC and affected individuals of eligible data breaches. Major reforms proposed in 2024 would strengthen individual rights.

Cybersecurity professionals in Australia must understand the Privacy Act and NDB requirements. The 2022 penalty increase (up to 50 million AUD) increased the importance of cybersecurity roles at Australian organizations. Incident responders must understand 'eligible data breach' definitions to trigger proper notification.

Up to 50 million AUD, three times the value of any benefit obtained, or 30% of adjusted turnover, whichever is greatest (2022 amendment)

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?