The Privacy Act Gets Its Teeth: What the 2024 Reforms Mean for Notifiable Data Breaches
The Privacy and Other Legislation Amendment Bill 2024 has passed the Senate and awaits Royal Assent. What it would add, and what to do before it does.
Jump to section
- 01 What the 2024 Privacy Act amendment changes
- 02 What the amendment changes for the Notifiable Data Breaches scheme
- 03 Who can be sued under the new statutory tort
- 04 When does the statutory tort start?
- 05 How an OAIC infringement notice works
- 06 What controls the amended regime expects
- 07 What CCP does on Privacy Act readiness
- 08 Primary sources
The Bill received Royal Assent on 10 December 2024, after this post was published.
This is an IT operator’s view of the Privacy and Other Legislation Amendment Bill 2024. The Bill passed the Senate on 29 November 2024 and is expected to receive Royal Assent shortly. It isn’t legal advice or a privacy-law opinion. Whether a particular handling of personal information satisfies the amended Privacy Act is not our call. It is one for your privacy counsel, or for the Office of the Australian Information Commissioner (OAIC). We implement the technical controls. They sign off on the legal interpretation.
The Privacy Act has been under reform since the 2022 review, and for the first time since 2017 the legislation is about to genuinely move. The Bill passed the Senate late on 29 November and is expected to receive Royal Assent in the next two weeks. Three things in it change the risk for any Australian mid-market business holding personal information. A new mid-tier civil penalty of up to AUD 3.3 million for a body corporate. Infringement-notice powers that let the OAIC act on smaller breaches without going through the Federal Court. And a statutory tort of serious invasion of privacy, commencing mid-2025, that lets individuals sue directly without going through the OAIC at all.
The 2024 reforms are less radical than the 2022 review proposed, but they meaningfully tighten the consequences of mishandling personal information. The mid-tier penalty in particular closes a long-standing enforcement gap. Under the pre-amendment regime, the OAIC had the nuclear option (penalties for “serious or repeated” interferences with privacy) or nothing. It now has a graduated response that matches the severity of most breaches we see in mid-market incident work.
What the 2024 Privacy Act amendment changes
Five things matter for a mid-market business. First, the civil-penalty framework gains a mid-tier for “interference with privacy” that is not serious or repeated. It is capped at 2,000 penalty units for an individual, around AUD 660,000. For a body corporate the cap is 10,000 penalty units, around AUD 3.3 million. Second, the OAIC gains infringement-notice and compliance-notice powers, allowing it to act without Federal Court proceedings. Third, a statutory tort of serious invasion of privacy commences on a date to be proclaimed. That date is no later than six months after commencement, so by around 10 June 2025. Fourth, amendments clarify the OAIC’s investigative powers and extend the breach-notification regime in various technical ways. Fifth, obligations around automated decision-making are introduced with a two-year transition period ending 10 December 2026.
The combination matters more than any single change. The OAIC now has the tools to bring enforcement action proportionate to the actual breach. A mid-market business that would previously have received a stern letter might now receive a civil penalty. And the statutory tort opens a completely new pathway for individuals to recover where a breach has caused them real harm.
What the amendment changes for the Notifiable Data Breaches scheme
The Notifiable Data Breaches (NDB) scheme itself has been in effect since February 2018. The 2024 amendments do not rewrite it. What they change is what happens when an entity handles an NDB event badly.
Under the pre-amendment regime, an entity might fail to notify a breach, notify late, or investigate it poorly after notification. It might then face an OAIC investigation, damage to reputation, and possibly a Federal Court action if the conduct was serious. In practice, most non-catastrophic breaches resulted in OAIC engagement, a remediation requirement, and a published determination. The penalty regime was hard to deploy for merely poor handling.
Under the amended regime, the OAIC can issue an infringement notice without going to Federal Court first. It needs only to form the view that a civil penalty applies. It can issue a compliance notice requiring specific remediation, with penalties if the notice is not complied with. The mid-tier civil penalty is available for interferences with privacy that are not at the top end of seriousness.
So the consequences of mishandling an NDB event have sharpened. A mid-market business could once expect that a genuine mistake, handled responsibly, would attract a remediation conversation. The same facts might now attract an infringement notice with a financial penalty attached. The tolerance for poor preparation has narrowed.
Who has to notify, and has that changed?
No. The core NDB obligations remain the same. Notify the OAIC and the affected individuals of an “eligible data breach”. Do it within 30 days of becoming aware of circumstances that would constitute one. And take reasonable steps to address it. The 2024 amendments do not extend notification obligations to new entity categories. They do not lower the threshold for what counts as an eligible data breach.
The small-business exemption also remains: turnover under AUD 3 million, with carve-outs for health service providers and certain other categories. The government has signalled it is under ongoing review. A business that relies on the small-business exemption today should expect that reliance to become more contentious over time.
Who can be sued under the new statutory tort
The statutory tort applies to any person whose conduct is a serious invasion of another person’s privacy. That means intruding on their seclusion, or misusing information relating to them. It is not limited to entities covered by the Privacy Act; individuals, unincorporated bodies, and small businesses can be sued. Damages are available, as are aggravated damages in appropriate cases.
For a mid-market Australian business, the exposure has three sources. A data breach that exposes personal information in a way that causes real harm to affected individuals. Employment-related data handling that goes badly wrong (surveillance disputes, improperly accessed records, misuse of information about former employees). And deliberate or reckless use of personal information in a way a reasonable person would find offensive or distressing.
The tort does not require proof of financial loss. Distress, humiliation, or interference with private life can ground damages. That is a different kind of exposure to a traditional breach-of-contract claim, and insurance policies are only beginning to respond to it.
When does the statutory tort start?
On a date to be proclaimed, and no later than six months after commencement. Given the Bill is expected to receive Royal Assent in December 2024, the tort will commence no later than around 10 June 2025. Businesses should treat first-half 2025 as the transition window.
What to do in the six months before it starts
Three things. Review the personal information the business actually holds, with a focus on information that would cause real harm if exposed or misused. Update the incident-response plan so it covers the tort-law side of a breach as well as the regulatory notification side. That includes early legal advice on whether an incident creates tort exposure. And tighten day-to-day practice on employee data handling and internal monitoring. Short of a headline breach, that is the conduct most likely to ground a tort claim.
Technical controls (access management, logging, encryption, breach detection) continue to do most of the work on the regulatory side. The tort is mainly a governance and legal problem. But the technical controls reduce how often an event becomes a legal problem at all.
How an OAIC infringement notice works
Infringement notices under the amended Act are a new enforcement tool for the OAIC. They work like the infringement notices the Australian Competition and Consumer Commission (ACCC) already issues. The OAIC forms the view that a civil penalty applies and issues a notice specifying the amount. The recipient either pays or disputes the notice in proceedings. Paying the notice is not an admission of liability but does close the matter.
For a mid-market business, the OAIC will probably resolve many mid-severity matters by infringement notice rather than Federal Court action. That is more efficient for the regulator, and arguably more proportionate for the respondent. But it also means more cases end with a financial penalty where previously none would have applied.
So the quality of an entity’s breach response now matters more. A breach handled responsibly, with credible technical evidence of preparation, may still draw OAIC engagement. It is less likely to draw a penalty. A poorly-handled breach with thin evidence of preparation is a natural candidate for an infringement notice.
What controls the amended regime expects
The regime does not prescribe controls. It requires entities to take reasonable steps to protect personal information and to respond appropriately to breaches. What counts as reasonable moves with the state of the art and the sensitivity of the information.
For a mid-market business handling personal information, the baseline is broadly familiar. Identity and access controls that enforce least privilege. Logging sufficient to reconstruct what happened in a breach. Encryption of personal information both in transit and at rest. Backup and recovery that can restore operations without paying a ransom. Patching and vulnerability management on a documented schedule. An incident-response plan that has been tested. Vendor management for third parties handling personal information on the entity’s behalf.
For most mid-market businesses we work with, the gap is not in knowing what to do. It is in having documented evidence that the controls were actually operating when the breach occurred. The amended regime’s enforcement tools will increasingly rely on that evidence gap.
Do the amendments change how long you keep data?
Indirectly. The amendments do not change retention obligations. They do sharpen the consequences of over-retention. Under the amended regime, personal information held past the point of legitimate business need is an uncompensated liability in a way it was not before. The statutory tort in particular exposes a long-retention habit. Information held for years after it ceased to be needed can still cause harm if it is exposed.
Through 2024, well-advised privacy programs have been reducing the volume of personal information held, not increasing it. The 2024 amendments are consistent with that trend.
What CCP does on Privacy Act readiness
We don’t give privacy advice. We set up the IT environment a business needs to operate under the amended Privacy Act credibly, and we keep it running.
For a mid-market client preparing for the amended regime, we cover three areas. The controls environment: access management, encryption, logging, endpoint security, backup, vulnerability management, the Essential Eight baseline that does most of the technical work. Breach response: detection, investigation, and evidence preservation. That work joins up with legal and executive response, which is what keeps an incident from becoming a crisis. And retention and minimisation: personal information held because there is a legitimate reason, not because nobody ever built a retention process.
The privacy-law interpretation and the notification decisions stay with the business’s privacy counsel and executive leadership. So does the legal response to an OAIC enquiry or a tort-law claim. Our boundary is explicit. We run the machinery. They run the interpretation.
If you want to check your current controls before the amended regime takes full effect, start with our Essential Eight self-assessment. It is not a privacy-specific tool. The controls it assesses support the technical obligations the amended Privacy Act will enforce more sharply through 2025.
Primary sources
- Privacy and Other Legislation Amendment Bill 2024, Parliament of Australia Bill page. Accessed 28 November 2024.
- Office of the Australian Information Commissioner, OAIC’s regulator site for current guidance and notifiable data breach resources. Accessed 28 November 2024.
- Privacy Act 1988 (Cth), as amended, available via Federal Register of Legislation.