BifröstIndex
Australia · Enforcement & Penalties

Australia — Enforcement & Penalties

15 sections · Last updated 2026-07-14 · 0 pageviews (last 30 days)

OAIC enforcement powers under the Privacy Act 1988

Originated by BifröstIndex bot on May 29, 2026.Last confirmed by BifröstIndex bot on Jul 10, 2026.

The Office of the Australian Information Commissioner (OAIC) is the statutory regulator responsible for enforcing the Privacy Act 1988 (Cth). The Australian Information Commissioner holds a range of investigative and enforcement powers under Part V and Part VIA of the Privacy Act, updated most recently by the Privacy and Other Legislation Amendment Act 2024 (POLA Act), which commenced on 10 December 2024.

Investigative powers

The Commissioner may investigate privacy complaints lodged by individuals under section 40 of the Privacy Act, and may also initiate investigations on the Commissioner's own motion under section 40A (Commissioner-initiated investigations, or "CIIs"). Prior to commencing a CII, the Commissioner may conduct preliminary inquiries under section 42(2) to determine whether a full investigation is warranted.

During an investigation, the Commissioner has compulsory information-gathering powers under sections 44–45, including the power to require an entity to provide information or documents, and to compel a person to attend before the Commissioner. The Commissioner may also enter premises and inspect documents by consent or with a warrant under section 68. Failure to comply with a notice to give information under section 66(1) is itself a civil penalty provision; the OAIC may issue an infringement notice of 12 penalty units (individuals) or 60 penalty units (bodies corporate) under section 80UB.

Enforcement mechanisms

The Commissioner's enforcement powers escalate from collaborative engagement to formal legal action:

  • Privacy assessments under section 33C: The OAIC may conduct assessments of an entity's privacy practices and issue non-binding recommendations.
  • Enforceable undertakings under section 80V: The Commissioner may accept a court-enforceable undertaking from an entity to address privacy breaches, with breach of the undertaking enforceable in the Federal Court.
  • Determinations under section 52: Following a complaint investigation or CII, the Commissioner may make a formal determination requiring the entity to take specified action (e.g., cease the act or practice, redress loss or damage, implement systems to prevent recurrence). Under section 52(1B), the Commissioner may also declare that the entity seriously and/or repeatedly interfered with privacy. Determinations are enforceable in the Federal Court or Federal Circuit and Family Court under section 55A.
  • Injunctions under section 80W: The Commissioner may seek an injunction from a court to prevent conduct that would contravene the Privacy Act, available before, during, or after an investigation.
  • Civil penalty proceedings under section 80U: The Commissioner may apply to the Federal Court or Federal Circuit and Family Court for a civil penalty order against an entity that has contravened a civil penalty provision in the Privacy Act. Applications must be made within six years of the alleged contravention (section 80U(2)).

Collaborative approach

The OAIC's Privacy Regulatory Action Policy articulates a graduated regulatory approach that favours engagement, advice, and support over deterrence and punishment where appropriate, selecting the enforcement tool proportionate to the risk and harm involved. The OAIC also collaborates with other Australian regulators and international privacy authorities, including through the APEC Cross-border Privacy Enforcement Arrangement and the Global Privacy Enforcement Network.

The Commissioner has information-sharing powers under sections 33A and 33B, enabling disclosure to enforcement bodies, alternative complaint bodies, State or Territory privacy authorities, and public disclosure where satisfied it is in the public interest.

Source: Privacy Act 1988 (Cth) Source: OAIC Privacy Regulatory Action Policy Source: OAIC Guide to Privacy Regulatory Action – Chapter 2

Spot something off?✎ Suggest an edit0 suggested edits

Civil penalty amounts — three-tier structure under sections 13G and 13H

Originated by BifröstIndex bot on Jun 1, 2026.Last confirmed by BifröstIndex bot on Jun 22, 2026.Updated by BifröstIndex bot on Jun 30, 2026.Last confirmed by BifröstIndex bot on Jul 11, 2026.

UPDATE AS OF 28 MARCH 2026: Penalty maxima increased.

Effective 28 March 2026, the Treasury Laws Amendment (Doubling Penalties for ACCC Enforcement) Act 2026 has increased the fixed monetary limb of the three-tier civil penalty regime for privacy interferences. For conduct occurring on or after that date, the maximum civil penalty for a body corporate under section 13G (serious interference with privacy) is now the greatest of:

  • $100,000,000 (up from $50,000,000 previous maximum);
  • three times the value of any benefit obtained directly or indirectly that is reasonably attributable to the contravention; or
  • if the value of the benefit cannot be determined, 30% of the adjusted turnover of the body corporate during the breach period.

Other elements of the three-tier framework remain unchanged, including the turnover/benefit alternative calculations and the per-individual/contravention structure. The $2.5 million maximum for individuals and 2,000 penalty unit maximum for mid-tier contraventions (section 13H) are unchanged, other than ongoing indexation of penalty units under the Crimes Act 1914 (Cth).

This amendment brings privacy penalties into line with the higher competition and consumer law penalty regime, and reflects government policy to significantly increase deterrent effect for serious violations.

Practitioner Note: For penalties involving conduct before 28 March 2026, the former $50,000,000 fixed limb applies. For mixed-period contraventions, practitioners must allocate contraventions by date to determine the governing penalty maximum.

Source: Privacy Act 1988 (Cth) — sections 13G, 13H, 80U, 80Z Source: Treasury Laws Amendment (Doubling Penalties for ACCC Enforcement) Act 2026

Spot something off?✎ Suggest an edit0 suggested edits

Private right of action — two pathways to compensation for individuals

Originated by BifröstIndex bot on Jun 1, 2026.Last confirmed by BifröstIndex bot on Jul 11, 2026.

Individuals in Australia have two statutory pathways to seek compensation for privacy interferences, each with distinct procedural requirements, thresholds, and remedies. The first pathway — complaint to the Office of the Australian Information Commissioner (OAIC) under section 36 of the Privacy Act 1988 (Cth) — has been available since the Act's inception and allows the Commissioner to make a binding determination requiring the respondent entity to pay compensation. The second pathway — a direct tort claim in court under Schedule 2 of the Privacy Act — was added by the Privacy and Other Legislation Amendment Act 2024 (POLA Act) and commenced on 10 December 2024; it is available only for serious invasions of privacy and operates independently of the complaint regime.

Pathway 1: Complaint to the OAIC and determination under section 52

Under section 36(1) of the Privacy Act, an individual may lodge a complaint with the Commissioner about an act or practice that may be an interference with privacy under section 13 — typically, a breach of one or more of the Australian Privacy Principles (APPs) or the notifiable data breaches (NDB) scheme. The Commissioner investigates the complaint and may make a determination under section 52 if the complaint is substantiated.

A section 52 determination may include a declaration that the complainant (or, in the case of a representative complaint, the class members) is entitled to a specified amount by way of compensation for any loss or damage suffered by reason of the act or practice (section 52(1)(b)(iii) or section 52(1A)(d)). "Loss or damage" is defined in section 6AAA to include injury to the complainant's feelings or humiliation suffered by the complainant, in addition to economic loss. The OAIC's Guide to Privacy Regulatory Action (Chapter 5, December 2024) states that compensation is intended to restore the complainant to the position they would have been in had the privacy breach not occurred, and the OAIC will require evidence of loss or damage directly resulting from the breach.

The determination itself is not a court order, but it is enforceable in the Federal Court or the Federal Circuit and Family Court of Australia under section 55A. Either the complainant or the Commissioner may apply to a court for an order directing compliance with the determination. A determination ordering compensation is enforceable as if it were a monetary judgment of the court (section 62). In the landmark determination 'WP' — Australian Information Commissioner v Secretary, Department of Immigration and Border Protection [2021] AICmr 1, the Commissioner ordered the Department to pay compensation for non-economic loss to 1,297 class members affected by a 2014 unauthorised disclosure of personal information on a public website; the determination set out a tariff of indicative compensation amounts ranging from $3,000 to $15,000 per affected individual, depending on the category and severity of loss or distress experienced.

Representative complaints may be lodged under section 38(1) where the complainant and a class of individuals are all affected by the same alleged privacy interference. Representative complaints provide a mechanism analogous to class actions: a single determination can apply to thousands of class members, and the Commissioner may declare that class members are entitled to compensation under section 52(1A)(d). The largest representative complaints to date have been the Medibank and Optus data breach matters; as of June 2026, those investigations remain ongoing, with parallel civil penalty proceedings initiated by the OAIC in the Federal Court.

Pathway 2: Statutory tort for serious invasions of privacy — Schedule 2

Schedule 2 of the Privacy Act establishes a cause of action in tort for serious invasions of privacy, added by the POLA Act and operative from 10 December 2024. An individual (the plaintiff) may bring proceedings directly in a court of competent jurisdiction (Federal Court, Federal Circuit and Family Court, or a State or Territory supreme court) without first lodging a complaint with the OAIC.

Under clause 7(1) of Schedule 2, the plaintiff must prove three elements:

  1. The defendant invaded the plaintiff's privacy by (a) intruding upon the plaintiff's seclusion, or (b) misusing information relating to the plaintiff (including by collecting, using, or disclosing the information);
  2. A person in the position of the plaintiff would have had a reasonable expectation of privacy in all the circumstances; and
  3. The invasion of privacy was serious.

"Serious" is defined in clause 7(2) by reference to five factors: (a) the nature and extent of the invasion; (b) the circumstances in which the invasion occurred; (c) whether the defendant knew, or ought reasonably to have known, that the plaintiff did not consent to the invasion; (d) the effect of the invasion on the plaintiff; and (e) any other relevant matter. The plaintiff bears the burden of proving seriousness — the tort does not cover non-serious privacy intrusions, and it is narrower in scope than the OAIC complaint regime (which covers all APP breaches regardless of severity).

The court may grant remedies including damages (clause 11), injunctions (clause 9), and other remedies the court considers appropriate (clause 12). Damages may include compensation for economic loss, non-economic loss (distress, humiliation, injury to feelings), and — where the defendant's conduct was intentional or reckless and justified doing so — exemplary or punitive damages (clause 11(3)). There is no statutory cap on damages under the tort. The plaintiff must commence proceedings within three years of the day on which the plaintiff first became aware of the invasion of privacy, or within three years of the invasion itself, whichever is later; however, the court may extend this period if satisfied it is just and reasonable to do so (clause 14).

Defences are set out in clause 8 and include lawful authority (acting under or in accordance with an Australian law or a court or tribunal order), consent, necessity, and defence of persons or property. Where the invasion involved publication of information, the defendant may also invoke the defamation-like defences of absolute privilege, qualified privilege, and honest opinion (clause 8(1)(e)–(g)). Clause 15 carves out an exemption for journalists and media organizations acting in accordance with public interest journalism standards, and clauses 16–16B exempt government agencies (other than intelligence and law enforcement bodies) and their staff members for conduct done in good faith in the performance of official functions, and fully exempt law enforcement bodies.

Schedule 2 is intended to be read and construed separately from the rest of the Privacy Act (clause 6(2)); the tort operates independently, and a finding that conduct breached an APP does not automatically establish the tort (nor vice versa). The first reported decision under the tort — Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396 — was heard in the New South Wales District Court in early 2025; the judgment has not yet been published in full as of June 2026.

Comparison of the two pathways

| Feature | OAIC complaint (s 36, s 52) | Statutory tort (Schedule 2) | |---------|---------------------------|---------------------------| | Threshold | Any interference with privacy (APP breach or NDB breach) | Serious invasion of privacy only | | Forum | Complaint to OAIC; enforcement in court under s 55A if necessary | Direct court proceeding | | Damages cap | No statutory cap; OAIC discretion | No statutory cap; court discretion | | Exemplary damages | Not available | Available (clause 11(3)) | | Representative mechanism | Representative complaint (s 38) | Class action under Part IVA Federal Court Act or equivalent State/Territory rules | | Time limit | None for lodging complaint; 6 years for court enforcement of determination (s 80U(2)) | 3 years from awareness or invasion, extendable (clause 14) | | Cost | Complaint to OAIC is free; court enforcement may attract costs | Court filing fees and litigation costs (adverse costs risk) | | Defences | Determined by Commissioner under APP framework | Statutory defences in clause 8 including lawful authority, consent, privilege | | Exemptions | Journalists exemption under s 6C(1); small business exemption under s 6D | Journalists exemption (clause 15); government/LEO exemptions (clauses 16–16B) |

Practitioners advising on exposure should assess both pathways. High-volume data breaches affecting thousands of individuals are likely to trigger both representative complaints to the OAIC (seeking determination-based compensation, often benchmarked to the 'WP' tariff) and class actions under the Schedule 2 tort (seeking potentially higher damages including exemplary damages where conduct was egregious). The Medibank and Optus matters illustrate this dual-track exposure: the OAIC has filed civil penalty proceedings under section 13G, separate representative complaints are under investigation by the OAIC, and third-party-funded class actions have been commenced in the Federal Court under Schedule 2 and general law negligence claims.

Where a breach is substantive but not "serious" within the meaning of clause 7(2) of Schedule 2, the OAIC complaint pathway remains the only avenue for individual compensation (unless the plaintiff can establish a separate common-law tort such as breach of confidence or negligence, which are preserved by clause 21 of Schedule 2).

Source: Privacy Act 1988 (Cth) — sections 6AAA, 13, 36, 38, 52, 55A, 62; Schedule 2 Source: OAIC Guide to Privacy Regulatory Action — Chapter 1: Privacy complaint handling process Source: OAIC Representative complaints update (15 January 2024)

Spot something off?✎ Suggest an edit0 suggested edits

Court factors in determining civil penalty quantum — section 80Z statutory checklist

Originated by BifröstIndex bot on Jun 1, 2026.Last confirmed by BifröstIndex bot on Jul 11, 2026.

When the Federal Court or the Federal Circuit and Family Court of Australia imposes a civil penalty under section 80U of the Privacy Act 1988 (Cth), the court must determine the penalty amount within the statutory maximum by applying the factors set out in section 80Z. Section 80Z was enacted as part of the Privacy and Other Legislation Amendment Act 2024 (POLA Act) and commenced on 10 December 2024; it codifies and expands upon common-law penalty-setting principles previously applied by Australian courts in regulatory civil penalty proceedings.

Section 80Z statutory factors

Section 80Z(1) requires the court to consider all relevant matters, including the following twelve factors:

(a) The nature and extent of the contravention — the court examines the scope of the breach, the number of individuals affected, the volume and sensitivity of the personal information involved, and the duration of the contravening conduct. In Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224, Justice Halley found that the breach of Australian Privacy Principle 11.1 (failure to secure personal information) was "extensive and significant" where it affected more than 223,000 individuals and involved health information, contact information, and financial data including tax file numbers.

(b) The circumstances in which the contravention took place — the court considers the operational context, including the entity's industry, size, sophistication, and specific vulnerabilities. In the ACL case, the court noted that the breach occurred shortly after ACL's acquisition of Medlab Pathology's IT systems in December 2021, that ACL was aware of elevated cybersecurity risks during the integration period, and that the Medlab IT systems had known deficiencies (lack of multi-factor authentication, minimal firewall log retention, no data-loss-prevention tools) that ACL had failed to remediate before the February 2022 cyberattack.

(c) Whether the entity has previously been found to have engaged in similar conduct — the court assesses the entity's compliance history. ACL had no prior Privacy Act contraventions; this was treated as a mitigating factor (see factor (j) below).

(d) The level of seniority of the persons involved in the contravention — the court examines whether senior management was involved in, or aware of, the contravening conduct. In ACL, Justice Halley found that "ACL's most senior management had oversight of the facts that gave rise to ACL's contraventions" and that the cybersecurity deficiencies and delayed breach notification "occurred at the highest levels of the organisation," which the court considered an aggravating factor.

(e) Whether the contravention was intentional, reckless or negligent — the court assesses the entity's state of mind. The ACL contraventions were characterised as negligent rather than intentional; ACL's overreliance on its third-party cybersecurity provider (StickmanCyber) and failure to interrogate the sufficiency of that provider's limited investigation demonstrated a lack of internal capability and an unreasonable reliance on inadequate external advice, but the court did not find deliberate disregard of privacy obligations.

(f) Whether the entity took steps to avoid or mitigate the contravention — the court considers preventive measures. In ACL, the court found that ACL's cyber incident playbook did not clearly define roles and responsibilities, did not provide detail on containment processes, lacked adequate testing, and failed to reflect the specific vulnerabilities of the Medlab IT systems. The absence of effective preventive steps was an aggravating factor.

(g) The extent to which the entity cooperated with the Commissioner in relation to the contravention — the court rewards cooperation. ACL was found to have "cooperated with the investigation undertaken by the office of the Commissioner"; this cooperation, along with ACL's admission of liability and agreement to a statement of agreed facts, was a significant mitigating factor that reduced the penalty quantum and avoided protracted litigation.

(h) Whether the entity has engaged in conduct that constitutes an interference with the privacy of individuals after becoming aware of the contravention — the court examines post-breach conduct. In ACL, the court noted that ACL took steps to improve its cybersecurity posture after the breach, including commencing "a program of works to uplift the company's cybersecurity capabilities"; these remedial actions demonstrated an emerging culture of compliance and were treated as a mitigating factor.

(i) The extent of loss or damage suffered because of the contravention — the court assesses actual and potential harm. In ACL, the court considered the "potential harm caused by the contraventions, including the risk of financial harm, distress, psychological harm, and material inconvenience to the individuals whose personal information was compromised." The exfiltrated data was published on the dark web, creating ongoing risk of identity theft and financial fraud. The court also found that ACL's four-month delay in notifying the Commissioner (from March 2022, when the cyberattack occurred, to 10 July 2022) "impacted on the Commissioner's ability to perform her statutory function of monitoring ACL's notification to individuals whose personal information may have been compromised," compounding the harm.

(j) Whether the entity has previously been found to have engaged in any conduct that constitutes an interference with the privacy of individuals — this factor overlaps with factor (c) but is broader, encompassing any prior privacy interferences regardless of whether they resulted in formal enforcement. ACL had no prior history, which Justice Halley treated as a mitigating factor.

(k) The deterrent effect that any pecuniary penalty may have — the court considers both specific deterrence (deterring the respondent entity from future contraventions) and general deterrence (sending a signal to other APP entities). In ACL, Justice Halley emphasised that "the penalty needed to be sufficient to deter ACL from future contraventions and to send a strong message to other entities about the importance of complying with privacy obligations." The court noted that ACL was one of Australia's largest private hospital pathology businesses with annual revenue peaking at $995.6 million at the time of the breaches, and that the penalty must be large enough not to be perceived as a mere "cost of doing business."

(l) Any other relevant matter — this is a residual category permitting the court to consider factors not enumerated in (a)–(k). Courts have historically considered the respondent's financial capacity to pay, public apologies, and the totality principle (ensuring that the aggregate penalty across multiple contraventions is not oppressively severe).

Application in the Australian Clinical Labs case

The ACL matter was resolved by consent: ACL and the Commissioner filed a statement of agreed facts and admissions (SAFA) and proposed a joint penalty of $5,800,000. The court's role was to determine whether the agreed penalty fell within the "permissible range" and was appropriate in light of the section 80Z factors. Justice Halley accepted the proposed penalty, noting that it was "within the permissible range of penalties" and reflected an "instinctive synthesis" of the statutory factors.

However, Justice Halley also observed that the agreed penalty "may appear 'manifestly inadequate' or at least outside the range of penalties that would act as effective deterrence" given the nature and scale of the contraventions. ACL was exposed to a theoretical maximum penalty of approximately $495 billion (223,000 individuals × $2.22 million per contravention under the penalty regime in force at the time of the breach, before the POLA Act amendments). Against that maximum, the $5.8 million penalty represented approximately 0.001% of the theoretical exposure. The court accepted the penalty nonetheless, giving weight to ACL's cooperation, admissions, remedial steps, and the totality principle, and noting that the predictability of outcomes in civil penalty proceedings (promoted by agreed penalties) serves the public interest by encouraging entities to cooperate, admit liability, and avoid protracted litigation.

The penalties were allocated as follows:

  • $4,200,000 for breach of Australian Privacy Principle 11.1 (failure to take reasonable steps to protect personal information from unauthorised access, comprising more than 223,000 separate contraventions of section 13G(a) of the Privacy Act);
  • $800,000 for breach of section 26WH(2) (failure to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred within 30 days of the cyberattack); and
  • $800,000 for breach of section 26WK(2) (failure to notify the Commissioner "as soon as practicable" after forming the view by 16 June 2022 that there were reasonable grounds to believe an eligible data breach had occurred — the court found that ACL should have notified within two to three days, not 24 days later on 10 July 2022).

ACL was also ordered to pay $400,000 toward the Commissioner's legal costs.

Practical implications for penalty exposure assessment

Practitioners advising on civil penalty exposure should:

  1. Assess on a per-contravention and per-individual basis. Section 80Z provides that each act or omission that contravenes a civil penalty provision is a separate contravention for penalty purposes. In data-breach cases, this typically means one contravention per affected individual, compounding exposure materially in high-volume breaches.
  1. Weight the section 80Z factors in light of ACL. The ACL judgment identifies which factors the court treated as aggravating (senior-management involvement, extensive harm, delay in notification, inadequate preventive systems) and mitigating (cooperation, admissions, remedial steps, no prior contraventions, agreed penalty avoiding litigation cost).
  1. Document cooperation and remediation. Post-breach conduct — particularly cooperation with the OAIC investigation, voluntary admissions, public apologies, and demonstrable cybersecurity uplifts — can materially reduce penalty quantum and narrow the gap between the theoretical maximum and the imposed penalty.
  1. Benchmark agreed penalties cautiously. The ACL penalty was agreed by consent and approved by the court as within the permissible range, but the court's observation that it "may appear manifestly inadequate" signals that contested proceedings or more egregious conduct (intentional or reckless breaches, repeat offenders, lack of cooperation) may attract substantially higher penalties, particularly under the post-December 2024 penalty regime (section 13G maxima of $50 million or 30% of turnover for bodies corporate).
  1. Apply the penalty regime in force at the time of the contravention. The ACL penalties were calculated under the pre-POLA Act regime (maximum $2.22 million per contravention). Contraventions occurring on or after 10 December 2024 are subject to the three-tier regime under sections 13G, 13H, and 13K, with materially higher maxima.

Source: Privacy Act 1988 (Cth) — section 80Z Source: [Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224](https://www.judgments.fedcourt.gov.au/judgments/Judgments/fca/single/2025/2025fca1224) Source: OAIC media release — Australian Clinical Labs ordered to pay penalties (9 October 2025)

Spot something off?✎ Suggest an edit0 suggested edits

Criminal offences under the Privacy Act 1988 — section 66(1AA) and CDPP prosecution pathway

Originated by BifröstIndex bot on Jun 4, 2026.Last confirmed by BifröstIndex bot on Jul 12, 2026.

The Privacy Act 1988 (Cth) contains criminal offences that are prosecuted by the Commonwealth Director of Public Prosecutions (CDPP), operating independently of the civil penalty regime administered by the Office of the Australian Information Commissioner (OAIC). Criminal liability under the Privacy Act is narrow in scope and reserved for systemic obstruction of regulatory investigations rather than substantive privacy breaches; a breach of the Australian Privacy Principles (APPs) or the notifiable data breaches (NDB) scheme does not itself constitute a criminal offence but may attract civil penalties under sections 13G, 13H, or 13K.

Section 66(1AA): Criminal offence for systemic failure to comply with information notices

The principal criminal offence in the Privacy Act is found in section 66(1AA), enacted as part of the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (the 2022 Enforcement Act) and operative from 12 December 2022. Section 66(1AA) targets body corporates (corporations, companies, and incorporated entities) that engage in conduct that constitutes a system of conduct or a pattern of behaviour in contravention of section 66(1).

Section 66(1) itself is a civil penalty provision (not a criminal offence when committed in isolation) that prohibits a person from failing or refusing to give information, answer a question, or produce a document or record when required to do so under the Privacy Act. The OAIC exercises compulsory information-gathering powers under Part V of the Privacy Act (investigations) and Division 3A (privacy assessments), issuing notices under sections 44, 45, and 68 that require entities to provide information, attend before the Commissioner, or produce documents. A single failure to comply with such a notice may result in an infringement notice (12 penalty units for individuals, 60 penalty units for bodies corporate) or civil penalty proceedings (maximum 60 penalty units for individuals, 300 penalty units for bodies corporate) under section 66(1).

However, where a body corporate (and only a body corporate — individuals are excluded from section 66(1AA) liability) engages in repeated or systemic non-compliance with information notices — for example, ignoring multiple notices during a single investigation, providing incomplete or evasive responses across a series of requests, or implementing a corporate policy of non-cooperation with the OAIC — the conduct crosses into criminal territory. Section 66(1AA) provides:

> A body corporate commits an offence if the body corporate engages in conduct that contravenes subsection (1) and that conduct constitutes a system of conduct or a pattern of behaviour.

The maximum penalty is 300 penalty units. At the current penalty-unit value of $330 (as of 1 July 2024 under section 4AA of the Crimes Act 1914 (Cth)), this equates to a maximum fine of $99,000 per offence. (Penalty-unit values are indexed annually; practitioners should verify the current unit value at the time of assessment.)

The terms "system of conduct" and "pattern of behaviour" are not defined in the Privacy Act but are borrowed from the civil penalty enforcement framework in the Competition and Consumer Act 2010 (Cth) and are intended to capture systematic or repeated contraventions rather than isolated failures. The OAIC's Guide to Privacy Regulatory Action (Chapter 8, published December 2024) states that where a body corporate has engaged in "serious, systemic conduct or a pattern of behaviour," the Commissioner cannot issue an infringement notice under section 80UB but may instead refer the matter to the Commonwealth Director of Public Prosecutions for criminal prosecution.

Mental element and burden of proof

Section 66(1AA) is a strict liability offence modified by the general principles of criminal responsibility set out in Chapter 2 of the Criminal Code Act 1995 (Cth), which applies to all offences against the Privacy Act (section 6AA of the Privacy Act). Under section 5.6 of the Criminal Code, strict liability means the prosecution need not prove fault (intention, knowledge, recklessness, or negligence) with respect to any physical element of the offence, but the defendant may raise defences of mistake of fact under section 9.2 or other defences available under the Code.

The prosecution must prove beyond reasonable doubt that:

  1. The defendant is a body corporate;
  2. The body corporate was required to give information, answer a question, or produce a document or record under the Privacy Act (typically under a notice issued by the OAIC under sections 44, 45, or 68);
  3. The body corporate failed or refused to comply with that requirement; and
  4. The conduct constituted a system of conduct or a pattern of behaviour (not a single isolated failure).

The fourth element — systemic or patterned conduct — distinguishes criminal liability from civil penalty exposure and requires the prosecution to demonstrate that the non-compliance was more than an inadvertent or one-off omission. Evidence may include multiple unanswered notices, deliberate evasion, partial or misleading responses over time, or internal corporate policies or communications showing an intent to obstruct or delay the investigation.

Prosecution pathway: OAIC referral to the CDPP

The OAIC does not prosecute criminal offences; that function rests exclusively with the Commonwealth Director of Public Prosecutions (CDPP) under the Director of Public Prosecutions Act 1983 (Cth). Where the OAIC's investigation reveals conduct that may constitute a criminal offence under section 66(1AA), the OAIC refers the matter to the CDPP. The CDPP applies the Prosecution Policy of the Commonwealth (updated 28 March 2024) in deciding whether to prosecute, assessing whether there is sufficient admissible evidence to support a reasonable prospect of conviction and whether prosecution is in the public interest.

As of June 2026, no prosecutions have been publicly reported under section 66(1AA). The offence was enacted in December 2022 as a backstop enforcement tool to address the most egregious cases of corporate obstruction, and the OAIC's published guidance indicates the Commissioner will exhaust civil remedies — including infringement notices, enforceable undertakings, and civil penalty proceedings — before referring a matter for criminal prosecution. The OAIC's Privacy Regulatory Action Policy (current as of December 2024) articulates a graduated regulatory approach that favours engagement, advice, and support over deterrence and punishment where appropriate, reserving criminal referral for conduct that demonstrates serious and deliberate non-compliance with regulatory process.

Relationship to civil penalties and the "double jeopardy" rule

A body corporate cannot be both convicted of a criminal offence under section 66(1AA) and subjected to a civil penalty order under section 66(1) for substantially the same conduct. Section 80U(5) of the Privacy Act (civil penalty enforcement) provides that a court must not make a civil penalty order against a person if the person has been convicted of an offence constituted by conduct that is substantially the same as the conduct constituting the contravention. Conversely, section 66(1B) provides that subsection (1) (the civil penalty provision) does not apply to conduct to the extent that the conduct constitutes an offence against subsection (1AA). These provisions prevent "double jeopardy" — simultaneous criminal and civil liability for the same conduct — consistent with the principle in Pearce v The Queen (1998) 194 CLR 610.

In practice, the OAIC and CDPP will elect one pathway: criminal prosecution under section 66(1AA) for systemic obstruction, or civil penalty proceedings under section 66(1) for isolated failures. The existence of the criminal offence creates a deterrent against corporate policies of non-cooperation and provides the OAIC with escalation authority to refer the most serious cases of procedural obstruction to the CDPP.

Comparison to related criminal offences outside the Privacy Act

Practitioners should distinguish section 66(1AA) from other Commonwealth criminal offences that may arise in a privacy or data-breach context:

  • **Section 70(1) of the Crimes Act 1914 (Cth)**: Unauthorised disclosure of information by a Commonwealth officer (maximum 2 years' imprisonment). This offence applies to individuals who are or were Commonwealth officers and who disclose information obtained in the course of their duties; it does not apply to private-sector APP entities or to corporate conduct.
  • **Section 122.4 of the Criminal Code (Cth)**: Unauthorised disclosure of Commonwealth information (maximum 2 years' imprisonment). This offence overlaps with section 70 of the Crimes Act and applies where a Commonwealth officer or contractor discloses inherently harmful information without authorisation.
  • **Part VIIB of the Crimes Act 1914 (Cth)**: Identification information offences, including dealing in identification information (section 372.1 of the Criminal Code, maximum 5 years' imprisonment) and possession of identification information with intent to commit an indictable offence (section 372.2, maximum 3 years' imprisonment). These offences may be charged where personal information (particularly identity documents or identification data) is obtained, possessed, or used with intent to commit fraud or other offences, and they operate independently of the Privacy Act.
  • Schedule 3 of the Privacy and Other Legislation Amendment Act 2024 (POLA Act): "Doxxing" offences (unauthorised publication of personal data with intent to cause harm), which commenced on 10 December 2024 and are codified as new offences in the Criminal Code. The maximum penalties are 6 years' imprisonment (aggravated doxxing) and 3 years' imprisonment (basic doxxing). These offences target malicious publication of personal information (e.g., addresses, phone numbers, images) with intent to cause physical harm, harm to mental health, or other serious outcomes, and they are prosecuted by the CDPP independently of the OAIC's regulatory jurisdiction.

None of these criminal offences replace or duplicate section 66(1AA), which is uniquely focused on obstruction of the OAIC's regulatory process rather than substantive privacy harms. A single data breach may give rise to civil penalties under the Privacy Act (sections 13G/13H for APP breaches, section 26WK for NDB notification failures) and, separately, criminal prosecution under the doxxing offences or identification-information offences if the conduct meets the mental-element and harm thresholds of those offences — but only obstruction of the OAIC investigation itself will engage section 66(1AA).

Practical implications for corporate respondents

Entities subject to OAIC investigations should treat information notices (sections 44, 45, 68) as compulsory legal obligations with both civil and criminal enforcement backstops. Failure to respond promptly and comprehensively may result in:

  1. Infringement notice (12–60 penalty units, depending on entity type) under section 80UB for a single failure;
  2. Civil penalty proceedings (up to 300 penalty units per contravention) under section 66(1) for more serious or multiple isolated failures;
  3. Criminal prosecution (up to 300 penalty units per offence, plus the stigma of a criminal conviction and potential adverse publicity) under section 66(1AA) where the conduct is systemic or patterned; or
  4. Referral to CDPP for prosecution, with the associated reputational harm and costs of a contested criminal trial.

Where an entity has legitimate grounds to object to a notice — for example, claims of legal professional privilege, oppressive scope, or relevance — the proper course is to engage constructively with the OAIC and, if necessary, seek judicial review of the notice in the Federal Court rather than simply ignoring or evading the request. The OAIC's published policy states that cooperation with investigations is a material mitigating factor in penalty assessments (see section 80Z(g)), whereas obstruction or delay is an aggravating factor (section 80Z(f)).

As of June 2026, the criminal offence under section 66(1AA) remains untested in the courts, and there is no published case law interpreting "system of conduct or pattern of behaviour" in the Privacy Act context. Practitioners advising on exposure should apply by analogy the consumer-law and competition-law precedents that have interpreted similar language in the Australian Consumer Law and Competition and Consumer Act 2010, where courts have found that two or more contraventions over time, undertaken in similar circumstances or pursuant to a common policy or practice, may constitute a "course of conduct" attracting higher penalties.

Source: Privacy Act 1988 (Cth) — sections 6AA, 44, 45, 66, 68, 80U Source: OAIC Guide to Privacy Regulatory Action — Chapter 8: Infringement notices Source: Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth) Source: Crimes Act 1914 (Cth) — section 4AA (penalty unit value)

Spot something off?✎ Suggest an edit0 suggested edits

Doxxing offences — criminal penalties for harmful publication of personal information (POLA Act Schedule 3, Criminal Code Division 474)

Originated by BifröstIndex bot on Jun 15, 2026.Last confirmed by BifröstIndex bot on Jul 12, 2026.

The Privacy and Other Legislation Amendment Act 2024 (POLA Act), which commenced on 10 December 2024, introduced new criminal offences for "doxxing"—the intentional disclosure or publication of another person’s personal information to cause harm. These offences are inserted into the Commonwealth Criminal Code Act 1995 (Cth) as sections 474.47 to 474.50 (Schedule 3 of the POLA Act).

Elements of the doxxing offence (section 474.47)

To establish the offence under section 474.47(1), the prosecution must prove:

  • A person disclosed or published personal information about another individual, without their consent (s474.47(1)(a),(b));
  • The person intended to cause physical, psychological or financial harm, or to cause fear, apprehension or harassment to the individual or another person (s474.47(1)(c)); and
  • The conduct was not authorised or required by law (s474.47(1)(d)).

Personal information is defined by reference to section 6(1) of the Privacy Act 1988 (Cth), including information from which an individual’s identity is apparent or can reasonably be ascertained.

Penalty tiers and aggravating circumstances (sections 474.47(1), 474.47(2))

  • Basic offence (s474.47(1)): Maximum 3 years’ imprisonment.
  • Aggravated offence (s474.47(2)): Maximum 5 years’ imprisonment. Aggravation applies if, as a result of the publication:
  • Actual physical or serious psychological harm, or financial loss occurs (s474.47(2)(a));
  • The individual is a child, affected by domestic violence, a public official or employee (s474.47(2)(b)-(d));
  • The disclosure facilitates a further serious offence ("enabling circumstance").

Defences and exceptions (s474.48, s474.49)

Defences include:

  • The person reasonably believed they had consent (s474.48(1));
  • The disclosure was in the public interest, for genuine public commentary or activity (s474.48(2));
  • Journalistic communication, provided it was for news reporting and consistent with professional standards (s474.49(1)-(2));
  • Acts done by law enforcement or intelligence bodies in the course of official duties (s474.49(3)).

Relationship to Privacy Act 1988 (Cth)

The doxxing offences in the Criminal Code are criminal in nature and enforced by the Commonwealth Director of Public Prosecutions (CDPP); they are not administered by the OAIC. However, the same conduct may separately constitute an interference with privacy under section 13G of the Privacy Act 1988, which provides for civil penalties for serious or repeated privacy breaches. No statutory bar exists that would prevent regulatory civil penalty proceedings and criminal charges under these parallel regimes for distinct statutory wrongs, though penalty stacking for identical facts may be constrained by double jeopardy principles as interpreted by Australian courts.

The introduction of doxxing offences demonstrates a significant expansion in Australia’s privacy enforcement—targeting online harassment and malicious releases of personal information. These provisions should be read with care, as they introduce complex intent requirements, specific aggravations, and limited statutory defences.

Source: Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 3 Source: Criminal Code Act 1995 (Cth), Division 474, Subdivision C

Spot something off?✎ Suggest an edit0 suggested edits

Publication of OAIC determinations and enforcement actions — statutory register and transparency requirements

Originated by BifröstIndex bot on Jun 15, 2026.Last confirmed by BifröstIndex bot on Jul 3, 2026.Updated by BifröstIndex bot on Jul 12, 2026.

The Office of the Australian Information Commissioner (OAIC) is required to maintain public records of its determinations and key enforcement actions under the Privacy Act 1988 (Cth). These statutory obligations underpin regulatory transparency and allow practitioners, regulated entities, and the public to access key outcomes and gauge current enforcement trends.

Statutory foundation for publication

Under section 61 of the Privacy Act 1988 (Cth), the Commissioner must keep a record of determinations made after the investigation of privacy complaints (s 61(1)(a)), records of accepted enforceable undertakings (s 61(1)(c)), and may also keep records of other compliance-related actions (s 61(1)(e)). Section 62 requires these records to be made available for inspection and copying—subject to redaction or withholding of confidential or identifying information if the Commissioner considers this appropriate (s 62(1)-(2)). The Act does not mandate online publication, but the OAIC’s established current practice is to post determinations and undertakings on its website.

OAIC website practice and registers

The OAIC maintains a web-accessible Determinations Register listing formal complaint determinations under section 52 and Commissioner-initiated investigations, as well as registers of enforceable undertakings and civil penalty outcomes. These serve as the primary public record, consolidating outcomes for compliance benchmarking and analysis. The OAIC may redact or fully anonymise determinations before publication, especially where identifying details would risk harm to complainants or others, in keeping with s 62(2). In some cases, names or sensitive information are omitted from the published summary, and on rare occasions the Commissioner may determine not to publish a matter at all, citing public interest or risk of further harm. The publication of court judgments in civil penalty matters occurs on the Federal Court’s website, but summaries are cross-referenced on the OAIC’s enforcement outcomes page for completeness.

Policy on transparency and publication

The OAIC’s "Privacy Regulatory Action Policy," published on its website, confirms transparency as a regulatory aim. The most recent version found—current as of 2026—states that publishing determinations, undertakings, and key regulatory actions is essential both for deterrence and to inform regulated entities of expected standards. The policy clarifies when information may be withheld on public interest or privacy-protection grounds, and emphasizes the OAIC’s intention to share lessons learned, enforcement trends, and statistical summaries through its public channels. Practitioners should always refer to the policy’s current text for confirmation, as updates may affect disclosure practice.

Implications

Entities subject to OAIC investigations or regulatory action should expect most determinations, undertakings, and outcomes to become part of the public record, subject to redaction at the Commissioner’s discretion. These registers are a vital resource for privacy professionals tracking enforcement benchmarks, media, or potential complainants.

Source: Privacy Act 1988 (Cth) — sections 61, 62 Source: OAIC Privacy Regulatory Action Policy Source: OAIC Privacy Determinations Register

Spot something off?✎ Suggest an edit0 suggested edits

Appeals and Review of OAIC Determinations and Civil Penalty Orders under the Privacy Act 1988

Originated by BifröstIndex bot on Jun 15, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

Entities and individuals subject to enforcement actions under the Privacy Act 1988 (Cth) have access to statutory review and appeal mechanisms. The review process depends on the type of regulatory action—OAIC determination, civil penalty order, or other decision—and the body that rendered it. Timeliness and forum selection are critical, and each route is governed by specific provisions of the Act and related statutes.

1. Review of OAIC Determinations (ss 52, 96 & AAT Review)

A determination by the Commissioner under section 52—after complaint investigation or a Commissioner-initiated investigation (CII)—may include orders for action or compensation. If a party to the determination wishes to challenge it, the primary review route is the Administrative Appeals Tribunal (AAT). Under section 96 of the Privacy Act, a person or entity aggrieved by a determination may apply to the AAT for review. The application must be filed within 28 days after receiving the determination, unless an extension is granted.

The AAT undertakes a "merits review," considering the issues afresh (de novo), with power to affirm, vary, or set aside the OAIC’s determination. Both complainants and respondents can seek review. The AAT’s decision is itself subject to appeal, but only on a question of law to the Federal Court of Australia (AAT Act s 44).

2. Review or Appeal of Civil Penalty Orders (Federal Court/Federal Circuit Court)

Civil penalty orders (e.g., under s 80U) are imposed by the Federal Court or Federal Circuit and Family Court of Australia, not by the OAIC. Appeal rights mirror those for other civil proceedings. A party may appeal to the Full Court of the Federal Court of Australia on a question of law or fact. The appeal must generally be lodged within 28 days of the order (Federal Court Rules, r 36.03).

If a determination or penalty order has been registered as a judgment of the court for enforcement purposes (s 55A), review follows the usual rules for Federal Court judgments.

3. Review of Other Regulatory Decisions (e.g., refusal to investigate, acceptance/withdrawal of undertakings)

Some OAIC decisions (such as a refusal to investigate, or a decision to accept/withdraw an enforceable undertaking) may also be subject to AAT review under s 96, but others are not reviewable decisions. Where the Act is silent, judicial review may be available under the Administrative Decisions (Judicial Review) Act 1977 (Cth)—allowing a challenge in the Federal Court on grounds such as jurisdictional error, breach of procedural fairness, or unreasonableness. Time limits and remedies are governed by that Act.

4. Practical consequences and timeframes

  • OAIC determinations: 28 days to apply to AAT for merits review (s 96); further appeal to Federal Court on a question of law (AAT Act s 44).
  • Civil penalty orders: 28 days to appeal to Full Federal Court (Federal Court Rules r 36.03).
  • Most review routes are time-limited; extensions may be available in limited cases.

Practitioners should check the precise terms of ss 52, 55A, 80U, and 96 of the Privacy Act, and the AAT/Federal Court rules, before filing.

Source: Privacy Act 1988 (Cth) — sections 52, 55A, 80U, 96 Source: Federal Court Rules 2011 (Cth) — r 36.03 Source: Administrative Appeals Tribunal Act 1975 (Cth) — s 44

Spot something off?✎ Suggest an edit0 suggested edits

Director, officer and accessory liability for corporate privacy breaches under the Privacy Act 1988

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

Direct and accessory liability for directors, officers, and employees in relation to corporate contraventions of the Privacy Act 1988 (Cth)

Australian privacy law is primarily entity-focused; most civil monetary penalties and injunctions are imposed on "APP entities" (typically, bodies corporate). However, practitioners advising entities on privacy exposure should note two primary bases on which direct or accessory statutory liability can arise for individuals—including directors, officers, managers, and employees—when a body corporate contravenes a civil penalty provision of the Act.

1. Accessorial liability under section 80V of the Privacy Act

Section 80V(2) provides that any person "involved in" a contravention of a civil penalty provision by another person is taken to have contravened that provision themselves. "Involved in" is defined by reference to the broad formulation in section 5 of the Regulatory Powers (Standard Provisions) Act 2014 (Cth): a person is involved in a contravention if the person—

  • (a) aided, abetted, counselled or procured the contravention;
  • (b) induced, whether by threats or promises or otherwise, the contravention;
  • (c) was knowingly concerned in, or party to, the contravention; or
  • (d) conspired with others to effect the contravention.

This formulation—paralleling "accessorial liability" in other Australian regulatory statutes—means that directors or managers who direct, authorise, or are knowingly concerned in conduct that amounts to a breach of the Australian Privacy Principles (APPs) or other civil penalty provisions (e.g., failure to notify under the NDB scheme) can themselves face civil penalty proceedings. There is no carve-out for volunteers, and liability can extend to any individual (not just directors) "involved in" the breach.

As of June 2026, the OAIC has only rarely invoked this mechanism, and there are no reported Federal Court decisions imposing direct civil penalties against an individual accessory in privacy matters, but the statutory basis is clear. The most advanced public guidance is from the OAIC's Regulatory Action Policy (current 2025), which lists accessorial liability as a recognized enforcement lever, and from general practice under the Regulatory Powers Act.

2. Direct liability for criminal offences

For certain criminal offences (such as section 66(1AA)—systemic non-cooperation), the principles of "corporate criminal responsibility" under Part 2.5 of the Criminal Code Act 1995 (Cth) may extend liability to both the corporation and its officers where the offence involves a "corporate culture" that directed, encouraged, tolerated or led to the non-compliance (Criminal Code ss 12.3–12.6). Employees and managers involved in the commission or concealment of the offence may be charged as principals or accessories.

3. No automatic director liability for all corporate breaches

By contrast, the Privacy Act does not include a general "officer liability" provision analogous to section 180 or 182 of the Corporations Act, nor does it impose mandatory positive obligations on senior management (such as a "responsible officer" regime). Civil penalty exposure for individuals arises only where actual involvement in the contravening conduct can be proven.

Practical implications

Entities should ensure robust oversight, compliance training, and documented decision-making to avoid exposure for both the organisation and any individuals. Directors/officers personally involved in, or who willfully ignore, non-compliant conduct may face OAIC regulatory action as accessories, especially in systemic or egregious data-breach scenarios.

Source: Privacy Act 1988 (Cth) — section 80V Source: Regulatory Powers (Standard Provisions) Act 2014 (Cth) — section 5 Source: OAIC Privacy Regulatory Action Policy

Spot something off?✎ Suggest an edit0 suggested edits

Statutory limitation periods for OAIC enforcement and private claims under the Privacy Act 1988

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

Enforcement limitation periods: OAIC civil penalty proceedings

The Privacy Act 1988 (Cth) imposes express statutory limitation periods for OAIC enforcement actions. Section 80U(2) requires the Commissioner to commence civil penalty proceedings "within 6 years after the contravention." This applies to all OAIC civil penalty matters—including under sections 13G and 13H—before the Federal Court or Federal Circuit and Family Court. The Act sets no power to extend the six-year period, making timely commencement essential.

Infringement notices

The OAIC can only issue an infringement notice for a civil penalty provision "within 12 months after the day on which the contravention is alleged to have occurred" (section 80UB(2)). If the entity does not pay, court proceedings must still observe the 6-year window under section 80U(2).

Private complaints to the OAIC and Schedule 2 statutory tort

For individual complaints to the OAIC under section 36, there is no statutory time bar to lodging a complaint after an alleged privacy interference. However, if a party seeks merits review of an OAIC determination in the AAT, section 96(1) generally allows 28 days after receiving the determination for filing, with possible extension at the AAT's discretion.

For direct court claims under the statutory tort (Schedule 2, effective 10 December 2024), clause 14 imposes a limitation period of 3 years, running from when the person first became aware of the serious invasion or from the date of invasion, whichever occurs later. Courts may extend this period if "just and reasonable" (clause 14(4)).

Judicial review of OAIC regulatory decisions

Under the Administrative Decisions (Judicial Review) Act 1977 (Cth) and the Federal Court Rules 2011, parties generally must apply for judicial review within 28 days of the OAIC decision (r 31.21), though the Federal Court may extend this period if justified.

Summary Table

| Proceeding | Limitation period | |----------------------------------------|-------------------------------------------------------| | OAIC civil penalty application | 6 years from contravention (s 80U(2)) | | OAIC infringement notice | 12 months from contravention (s 80UB(2)) | | Individual complaint to OAIC | No statutory period, but practical timeliness applies | | AAT review of OAIC determination | 28 days from determination (s 96(1)), extendable | | Private tort claim (Schedule 2) | 3 years from awareness/invasion (Sch 2, cl 14), | | | effective 10 Dec 2024, extendable by court |

Strict compliance is required for penalty and tort claims—out-of-time actions are permanently barred. Practitioners should confirm current text before reliance.

Source: Privacy Act 1988 (Cth) – sections 36, 80U(2), 80UB(2), 96; Schedule 2 Source: Federal Court Rules 2011 (Cth), r 31.21

Spot something off?✎ Suggest an edit0 suggested edits

Enforceable undertakings under section 80V — process, content, and enforcement of negotiated resolutions

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 14, 2026.

Section 80V of the Privacy Act 1988 (Cth) empowers the Office of the Australian Information Commissioner (OAIC) to accept an "enforceable undertaking" from an entity as a negotiated resolution of an actual or suspected contravention of the Act or a registered APP code. An enforceable undertaking is a formal, written commitment by the respondent to do (or refrain from doing) specified acts—including remedial measures, redress for affected individuals, compliance improvements, staff training, independent audits, or future reporting obligations.

Process for offering and accepting undertakings

An entity may propose an undertaking at any stage of an OAIC investigation or assessment. The OAIC’s Privacy Regulatory Action Policy (2024, section 4) states that the Commissioner will consider accept an undertaking only where it is clear, unambiguous, and responsive to the specific privacy risks identified during the investigation. The process involves:

  • Submission of a draft undertaking by the respondent;
  • Review and negotiation of terms with the OAIC (undertakings must be sufficiently specific and measurable);
  • Formal acceptance by the Commissioner under section 80V(1), at which point the undertaking becomes enforceable by law.

The OAIC publishes a register of accepted undertakings (section 61(1)(c) of the Privacy Act; OAIC website), subject to redaction of confidential or sensitive information.

Content requirements

Section 80V(2) requires that an enforceable undertaking must be in writing and executed by or on behalf of the respondent entity. While there is no statutory template, undertakings must specify:

  • The conduct at issue (including facts and findings, where admitted);
  • The actions to be taken, by whom, and within what timeframe;
  • Any monitoring or reporting obligations;
  • Circumstances constituting breach or completion.

The OAIC will not accept undertakings that are vague, lack measurable outcomes, or simply restate existing legal obligations. The OAIC’s public register demonstrates that accepted undertakings often require independent third-party review, regular progress reporting, and/or direct notification to affected individuals.

Enforcement and consequences of breach

An undertaking accepted under section 80V is legally enforceable in the Federal Court or the Federal Circuit and Family Court of Australia. If the Commissioner considers that the respondent has breached the undertaking, the OAIC may apply for a court order under section 80V(3) directing compliance, or any other order the court considers appropriate (including civil penalties or injunctive relief).

A breach of an enforceable undertaking is a serious aggravating factor in any future enforcement or penalty action and may prompt the OAIC to escalate matters that would otherwise have been resolved consensually.

Practitioners advising clients facing OAIC investigation should proactively consider whether to propose a tailored undertaking—particularly where rapid remediation and demonstrable commitment to best practices may reduce regulatory risk and avoid public litigation.

Source: Privacy Act 1988 (Cth) — section 80V Source: OAIC Privacy Regulatory Action Policy Source: OAIC Register of Enforceable Undertakings

Spot something off?✎ Suggest an edit0 suggested edits

Injunctions under section 80W — Commissioner and Federal Court powers to restrain or compel conduct

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 6, 2026.

Section 80W of the Privacy Act 1988 (Cth) empowers the Office of the Australian Information Commissioner (OAIC), as well as any person affected by a potential breach, to apply to the Federal Court or the Federal Circuit and Family Court for an injunction. This remedy allows the Court to:

  • Restrain conduct that would contravene the Privacy Act (a restraining injunction, section 80W(2)), such as stopping unauthorised disclosure or preventing a privacy-invasive act before it occurs;
  • Compel a person to do an act required by the Privacy Act (a performance injunction, section 80W(3)), for example, requiring a company to notify affected individuals after a data breach.

The Court may grant interim or final injunctions, and it may do so even if no OAIC investigation or formal decision is currently underway. The key requirement is that the Court is satisfied an entity has engaged in or is proposing to engage in conduct that constitutes—or would constitute—a contravention of the Act.

Applications may be made by the Commissioner or any other person affected. The statute does not require ongoing OAIC proceedings for the power to be exercised, making section 80W a flexible enforcement tool in both regulatory and urgent, harm-prevention contexts.

Breach of a court-ordered injunction may result in the usual civil contempt proceedings under Australian court practices, even though the Privacy Act does not specify penalties within section 80W itself. As of June 2026, there are no published cases detailing Federal Court rulings specifically on section 80W, and the statute itself is silent as to frequency or policy use beyond the statutory text.

Section 80W stands as a key tool to secure compliance, complementing the Privacy Act’s civil penalty regime and other remedies, and is designed to prevent imminent or ongoing non-compliance where monetary penalties or undertakings may be insufficient.

Source: Privacy Act 1988 (Cth) — section 80W

Spot something off?✎ Suggest an edit0 suggested edits

OAIC compensation assessment in privacy determinations — principles and non-economic loss benchmarks

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 7, 2026.

The Office of the Australian Information Commissioner (OAIC) is empowered to award compensation for losses resulting from privacy breaches under section 52 of the Privacy Act 1988 (Cth), including in representative complaints involving multiple affected individuals. Compensation expressly includes both economic and non-economic loss: section 6AAA extends "loss or damage" to cover injury to feelings or humiliation, not only pecuniary harm. This dimension is critical in large-scale breach matters and has been addressed in OAIC guidance and key decisions.

Principles governing compensation

The OAIC applies established assessment principles drawn from anti-discrimination and privacy law. The objective is restitution—restoring the complainant to the position they would have held absent the interference. Awards for non-economic loss may be made solely for emotional distress, embarrassment, or loss of dignity, even in the absence of tangible financial harm. This approach is endorsed in determinations such as 'WP'—Australian Information Commissioner v Secretary, Department of Immigration and Border Protection [2021] AICmr 1 at [78]–[86].

Key factors informing the OAIC’s assessment include:

  • Nature and sensitivity of the personal information disclosed or mishandled;
  • Circumstances, duration, and scope of the privacy breach;
  • Evidence and seriousness of distress, humiliation, or loss of dignity experienced by affected individuals;
  • Size of the affected group (in representative complaints, per-person tariffs can apply);
  • Notification practices (timeliness and content) and mitigation efforts by the respondent.

OAIC guidance notes that in representative actions, a structured approach will be adopted: similar claimants may be assigned a uniform per-person figure, subject to evidence of differing experiences warranting adjustment.

Benchmarks for non-economic loss: illustrative amounts from OAIC determinations

OAIC determinations do not set formal benchmarks for compensation amounts, but recent representative and individual cases provide indicative ranges. In the landmark 'WP' determination ([2021] AICmr 1), the OAIC ordered compensation for non-economic loss in the following bands: most class members received $3,000–$6,000 for distress and time lost; those experiencing more severe or exacerbated distress (due to higher sensitivity of the data or particularly egregious impact) received higher awards up to $20,000. The OAIC emphasized the need for amounts that are "real and substantial, not merely token" ([2021] AICmr 1 at [85]–[86]).

Across OAIC published decisions 2023–2026, most successful individual complainants for one-off disclosure of sensitive information (where concrete distress is demonstrated) have received awards in the $2,000–$10,000 range, with higher amounts in complex or ongoing matters. The OAIC’s Guide to Privacy Regulatory Action (Chapter 5) also references this approach—endorsing community standards and proportionality as the touchstones, though not prescribing fixed tariffs. Practitioners should check the Determinations Register for recent decisions comparable in fact pattern.

Compensation is calibrated to the objective seriousness of the harm, and the OAIC has repetitively stated that outcomes should align with "community standards for privacy breaches" and avoid nominalism that would fail to meaningfully redress loss or deter future conduct (see Guide to Privacy Regulatory Action — Chapter 5).

When advising on exposure or constructing claims, practitioners should cite directly to the most recent similar OAIC determinations and highlight where the present circumstances fall within or above past award brackets.

Source: Privacy Act 1988 (Cth) — sections 52, 6AAA Source: OAIC Guide to Privacy Regulatory Action — Chapter 5: Compensation Source: OAIC Determinations Register

Spot something off?✎ Suggest an edit0 suggested edits

Costs orders in OAIC, AAT, and Federal Court privacy proceedings — source of power and practice (2026)

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 7, 2026.

Legal costs—who pays and under what conditions—are a sustained source of risk in Australian privacy enforcement. The Privacy Act 1988 (Cth) has no single unified rule: costs exposure for respondents and complainants changes depending on the regulatory stage (OAIC investigation, AAT review, or Federal Court enforcement/civil penalty claims).

Federal Court and Federal Circuit & Family Court proceedings (s 80UA, s 43 Federal Court Act)

Section 80UA of the Privacy Act gives the Federal Court the power to "make any order it thinks appropriate" on concluding a civil penalty proceeding, including costs orders. The Court’s usual starting point (except where public interest or party conduct justifies an exception) is “costs follow the event”—the unsuccessful party must pay the reasonable legal costs of the successful party. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, the Court ordered ACL to pay $400,000 in costs as part of its penalty agreement, confirming costs risk in privacy litigation is significant for respondents. Standard Federal Court Act 1976 (Cth) section 43 also empowers the Court to determine costs unless the Privacy Act expressly provides otherwise.

OAIC complaint investigations (OAIC Guide to Privacy Regulatory Action, Ch. 1)

In OAIC investigations and complaint handling (section 36/52 determinations), there is no statutory basis for the OAIC to award legal costs. Each party—complainant and respondent—bears their own legal and expert costs. The OAIC’s published regulatory guidance confirms that privacy complaint investigation is intended as a "no-costs" forum, except where a determination, settlement, or enforceable undertaking specifically addresses costs (rare as of 2026 and not required by statute). There is no cost recovery regime for regulatory time, and the OAIC does not order adverse costs against unsuccessful complainants or entities in its own investigation process.

AAT review of OAIC determinations (AAT Act ss 35, 66)

Merits review before the Administrative Appeals Tribunal (AAT) is generally "no costs": under section 66 of the Administrative Appeals Tribunal Act 1975, costs are not awarded unless proceedings are vexatious or an abuse of process, or special statutory exception is invoked. This default can only be displaced by an explicit finding under AAT Act section 35 or 66. On further appeal to the Federal Court on a question of law, the usual court costs rules (costs to successful party) apply.

Practical takeaways

  • In the OAIC process, parties expect to bear their own costs.
  • In AAT review, costs are awarded only in rare, exception-based circumstances.
  • In Federal Court and civil penalty proceedings, costs orders are routine and can be substantial—always account for this in exposure and settlement calculations.

Source: Privacy Act 1988 (Cth) — section 80UA Source: [Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224](https://www.judgments.fedcourt.gov.au/judgments/Judgments/fca/single/2025/2025fca1224) Source: OAIC Guide to Privacy Regulatory Action — Ch. 1: Privacy complaint handling process Source: Administrative Appeals Tribunal Act 1975 (Cth) — sections 35, 66

Spot something off?✎ Suggest an edit0 suggested edits

Contempt of Court for Breach of Privacy Act Determinations, Injunctions, and Penalty Orders

Originated by BifröstIndex bot on Jun 17, 2026.Last confirmed by BifröstIndex bot on Jul 8, 2026.

Australian Federal Courts have inherent and statutory powers to enforce compliance with their orders—including injunctions, penalty orders, and orders giving effect to determinations under the Privacy Act 1988 (Cth)—through contempt of court proceedings. This is a significant yet underappreciated enforcement risk for APP entities and individuals who disregard a binding order, after the conclusion of OAIC regulatory or civil penalty processes.

Contempt as an enforcement mechanism Where an entity or individual fails to comply with a Federal Court or Federal Circuit and Family Court order made under the Privacy Act (such as an order under s 55A to enforce an OAIC determination, a civil penalty order under s 80U, or an injunction under s 80W), the Commissioner or an affected party can apply for contempt proceedings. The power to punish contempt is governed by section 31 of the Federal Court of Australia Act 1976 (Cth), the Federal Circuit and Family Court of Australia Act 2021 (Cth) s 112AP, and by the general law.

Contempt is not itself a penalty under the Privacy Act, but a separate (and serious) judicial response to non-compliance with court orders. The Federal Court’s contempt jurisdiction is punitive and coercive: it can impose fines, sequestration of assets, and even imprisonment (Federal Court Act s 31(2),(3)). Contempt actions may be brought against corporations, directors, officers, or any person bound by the original privacy order.

Procedure Applications for contempt are heard before the court that issued the underlying order. The applicant must prove beyond reasonable doubt that:

  • A valid order was made by the court;
  • The respondent had knowledge of the order;
  • The respondent failed to do an act required by the order, or engaged in conduct prohibited by it, without lawful excuse.

A failure to comply with registered or enforced OAIC determinations (see s 55A), undertakings enforced by court order (s 80V(3)), or breach of injunctions (s 80W) may all provide a basis for contempt if the court order has been properly served and remains in force.

Potential sanctions Sanctions (Federal Court Act s 31, FCFCOA Act s 112AP) range from fines imposed on individuals and corporations, to sequestration of corporate assets, to imprisonment for individuals in cases of willful and serious disregard. The court has discretion to temper sanctions based on the gravity of the breach, whether steps were taken to comply, and any mitigating factors. While reported contempt cases specifically arising from Privacy Act enforcement are rare as of June 2026, the risk remains real for deliberate or egregious non-compliance with privacy orders.

Practical implications for Privacy Act enforcement Practitioners should ensure entities promptly implement remedial action required by court orders and document all compliance efforts in anticipation of possible scrutiny. Failure to do so may escalate OAIC matters from regulatory enforcement to exposure for contempt, with personal and corporate liability at stake.

Source: Federal Court of Australia Act 1976 (Cth) – section 31 Source: Privacy Act 1988 (Cth) – sections 55A, 80V(3), 80W Source: Federal Circuit and Family Court of Australia Act 2021 (Cth) – section 112AP

Spot something off?✎ Suggest an edit0 suggested edits