

The long-awaited amendments to the Australian Privacy Act were pushed through on 29 November 2024 the final day of parliamentary sittings for 2024. So, what does that mean for Australian organisations?
In this post, we looked at the then-proposed changes including:
Other proposed changes include:
Increased transparency for automated decision-making
Organisations using personal information in automated decision-making systems that significantly affect individual rights must:
Children’s Online Privacy Code
The OAIC will develop a Children’s Online Privacy Code within 24 months of the Bill taking effect.
We reviewed the status of the amendment Bill here, which included reference to changes proposed by the Greens which did not get included in the legislation passed. We also covered the 10 recommended changes made by the Senate Legal and Constitutional Affairs Legislation Committee’s Report, which again were not included in the final legislation.
The Bill when passed included the changes as covered in our review of the draft Bill. However, there were some further amendments:
A new compliance notice regime is introduced, which allows for the OAIC to issue of compliance notices prior to sending an infringement notice. Compliance notices can be issued in regard to certain breaches and will require an entity to either take steps, or refrain from certain conduct to address the relevant privacy breach, or ensure the breach is not repeated or continued. Failure to comply can result in a civil penalty of up to AU$330,000 for corporations.
The proposed statutory tort for breach of privacy was amended by adding new exemptions to liability:
Other changes include:
Most of the provisions of the Bill come into effect immediately after the Bill receives Royal Assent.
However, in some cases there will be a delay.
The amendments to APP1 in relation to automated decisions will only commence 24 months after Royal Assent is given, and Schedule 2 dealing with the statutory tort for serious invasions of privacy will commence at a date to be fixed by proclamation, but no later than six months after Royal Asset, meaning the statutory tort will be in place by mid-2025 at the latest.
We set out recommendations on some of the things organisations should do to prepare for the proposed amendments here.
These include:
To prepare for the new statutory tort of invasion of privacy
To prepare for increased transparency of automated decision-making
To prepare for increased OAIC enforcement powers
To prepare for the new Children’s Online Privacy Code, if your organisation handles children’s data (i.e., data of an individual who has not reached 18 years)
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.