

On Thursday 12 September 2024, the Privacy and Other Legislation Amendment Bill 2024 (Bill) was introduced into parliament, marking the first tranche of reforms to the Privacy Act 1988 (Cth). This is the Australian Government’s first legislative response to the long-awaited reforms to Australia’s privacy framework. We’ve discussed the initial tranche of reforms here. In this article, we’ll break down the practical implications of the Bill and what organisations should do to prepare.
The Bill implements 23 legislative proposals that were agreed upon by the Government in its response to the 116 proposals set out in the Privacy Act Review Report. Notably, it introduces a new statutory tort for serious invasions of privacy, a tiered penalty regime, new transparency requirements and a new Children’s Online Privacy Code. Below, we outline these reforms and the concrete steps your organisation should consider.
The Bill introduces a new statutory tort addressing a broader range of privacy invasions, including:
The Australian Information Commissioner (AIC) will develop a Children’s Online Privacy Code within 24 months of the Bill taking effect.
The Bill allows a Minister to declare streamlined information sharing for emergencies or during eligible data breaches to mitigate the impact.
The Bill strengthens the Office of the Australian Information Commissioner (OAIC)’s enforcement powers, introducing a three-tier penalty system for privacy breaches:
1. Serious interferences with the privacy of an individual remain subject to the highest level of civil penalties – for a body corporate, this is the greater of $50m, three times the value of any benefit obtained from the interference, or 30% of annual turnover for the body corporate over a 12-month period. The OAIC must still apply to the Federal Court to impose this penalty.
When determining whether an interference is ‘serious’, the Bill outlines several factors that must be considered:
2. Mid-tier penalties for non-serious breaches, up to ~$3m for body corporates. Again, the OAIC must still apply to the Federal Court to impose this penalty.
3. Lower-tier administrative fines, up to $313,000, for administrative breaches of the Australian Privacy Principles (APPs) like having a deficient privacy policy, failing to provide opt-out controls for direct marketing, not properly dealing with information correct requests, or providing deficient data breach notices.
These fines can be imposed directly by the OAIC through infringement notices. If an organisation wishes to contest the notice, the burden is on the organisation to apply to the Federal Court.
The Bill introduces transparency requirements for organisations using personal information in automated decision-making systems that significantly affect individual rights. Organisations must:
The proposed changes to privacy law signal that now, more than ever, privacy compliance should be a top priority for organisations. Here are the key takeaways:
By taking proactive steps now, organisations can mitigate risks, avoid penalties and ensure compliance with Australia’s evolving privacy laws.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.