

Last week, the federal court ordered that Australian Clinical Labs Limited (ACL) pay a $5.8 million penalty for a 2022 data breach. This is significant for a number of reasons, not just because it’s the first civil penalty for a breach of the Privacy Act.
The data breach impacted 223,000 individuals, meaning the penalty amounted to just over $26 per person. While some commentators are pleased to see the powers under the Privacy Act being used this way, others are concerned that this penalty isn’t large enough in the circumstances. We dig into what happened, what factors were considered in determining the penalty, and what Australian organisations should take away from this case.
In November 2023, the OAIC commenced civil penalty proceedings against ACL following a data breach that affected 223,000 Australians. The enforcement action is the first to be based on a failure of security, including delay in notification.
The penalty proceedings were in response to ACL’s subsidiary experiencing a breach in February 2022, but only notified to the OAIC on 10 July 2022, five months later.
In November 2023, the OAIC initiated proceedings in the Federal Court, alleging specific breaches of the Privacy Act, including:
You can read more about the background of this data breach in our earlier post.
At this earlier stage, ACL and the OAIC negotiated an agreed outcome to the processings, with ACL consenting to the findings of breach and the imposition of the aggregate civil penalty sought by the Commissioner. However, the Federal Court still had to determine whether the declarations and penalty orders were appropriate and sufficient for the purposes of both specific and general deterrence given the serious nature of the contraventions by ACL. This the Court did, issuing its findings in October 2025.
This is the first case in Australia where proceedings considered what reasonable steps to secure personal information for the purposes of APP 11 looked like.
The consideration of whether or not reasonable steps had been taken was made easier by ACL admitting to significant cyber security failures.
In an Agreed Statement of Facts, ACL acknowledged that its cybersecurity mechanisms were lacking because:
These agreed stated deficiencies can act as a foundation for your formal checklist, especially if you operate in the healthcare space or otherwise collect sensitive information from your customers.
It is also worth noting that, in considering what is reasonable, the court considered the following factors:
The $5.8 million ACL was ordered to pay is made up as follows:
ACL was also ordered to pay a further $400,000 as a contribution towards the Commissioner’s costs in the proceeding.
Worth noting is that this penalty was imposed under the previous penalty regime – since the breach occurred prior to 13 December 2022.
The current penalty regime allows for much higher penalties for serious data breaches – as much as $50 million, or three times of the benefit derived from the conduct, or up to 30% of a business’s annual turnover. These penalties are also per contravention, which means that they can add up very quickly if the maximum penalty is imposed. Though, we don’t expect to see those maximums per contravention often, if at all.
Under the Privacy Act, penalties can only be awarded for serious or repeated infringements. There is no definition of ‘serious’ in the Privacy Act. The judge referred to the ASIC Act and the Corporations Act, where a “serious contravention” has been construed as a contravention that is “grave or significant” or “weighty, important, grave and considerable”, and acknowledged that, ‘in every case, it is ultimately a question of fact to be determined by reference to the degree of the departure from the requisite standard of care and diligence and the nature of the conduct, rather than the nature of the provision that has been contravened.’
In this case, the judge found that the infringements were serious, Some of the factors that contributed to the finding that the breach was serious, included:
The judgement acknowledges that the above factors may make it seem that a $5.8 million penalty is not adequate – a sentiment that has been reflected in some commentary about the case, especially on social media.
However, the judge goes on to note the following factors that made the $5.8 million penalty appropriate (ie. positive factors for ACL):
There are several important takeaways from this first civil penalty proceeding:
If you need help improving your organisation’s privacy posture, reach out. Our privacy professionals are available to help. Start with a free consultation.
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.