← New search

Other meanings of Privacy Act

Law

Privacy Act 1988

The Privacy Act 1988 is an Australian federal statute that regulates the handling of personal information by Australian government agencies and private sector organisations. Enacted in 1988 and significantly amended in 2000, it established the Australian Privacy Principles (APPs) and created the Office of the Australian Information Commissioner (OAIC) to oversee compliance.

1988
Year enacted
Year the Act was passed by the Australian Parliament
13
Australian Privacy Principles
Number of APPs that set out the standards for handling personal information
2000
Private sector extension
Year the Act was extended to cover most private sector organisations
OAIC
Regulator
Office of the Australian Information Commissioner, the independent body that oversees the Act
1

Scope and key principles

The Privacy Act 1988 applies to Australian government agencies and to private sector organisations with an annual turnover of more than $3 million, as well as to all health service providers and some small businesses that handle personal information. The Act sets out 13 Australian Privacy Principles (APPs) that govern the collection, use, disclosure, storage, access, and correction of personal information. The APPs require entities to have a clearly expressed privacy policy, to collect only what is necessary, and to take reasonable steps to secure the information they hold.

The Act also provides individuals with the right to access and correct their personal information, and it restricts the transfer of data overseas unless the recipient is subject to similar protections. The Office of the Australian Information Commissioner (OAIC) investigates complaints and can seek civil penalties for serious or repeated breaches.

2

Historical context and amendments

The Privacy Act 1988 was enacted in response to growing concerns about the use of personal data by government agencies, following the recommendations of the Australian Law Reform Commission's 1983 report on privacy. The original Act applied only to the public sector, but in 2000 the Howard government extended it to most private sector organisations, a change that took effect in December 2001.

Subsequent amendments have addressed new technologies and practices. The Privacy Amendment (Notifiable Data Breaches) Act 2017 introduced mandatory data breach notification, requiring entities to notify affected individuals and the OAIC when a data breach is likely to result in serious harm. The Act was also amended in 2014 to strengthen the powers of the OAIC and to increase penalties for non-compliance.

3

Enforcement and notable cases

The Office of the Australian Information Commissioner (OAIC) is responsible for enforcing the Privacy Act 1988. It can investigate complaints, conduct own-motion investigations, and make determinations that include compensation for individuals. In serious cases, the OAIC can seek civil penalties in the Federal Court, with maximum penalties currently set at $2.5 million for corporations.

Notable enforcement actions include the 2023 case against Meta Platforms, where the Federal Court found that the company had breached the Act through its use of the Onavo app to collect user data. In 2024, the OAIC also commenced proceedings against the health insurer Medibank for a major data breach that affected millions of customers. These cases highlight the Act's growing importance in the digital age.

4

Lesser-known aspects

Beyond the core provisions, the Privacy Act 1988 contains several lesser-known elements. It exempts certain types of information, such as employee records held by private sector employers, and it does not apply to media organisations acting in a journalistic capacity. The Act also includes specific rules for the handling of tax file numbers and for the use of data matching programs.

Another notable aspect is the Act's application to credit reporting, which is governed by Part IIIA and the Credit Reporting Privacy Code. This regime regulates how credit reporting bodies and credit providers handle consumer credit information. The Act also establishes the role of the Privacy Commissioner, who has the power to conduct assessments of compliance and to issue guidelines on emerging issues such as artificial intelligence and biometric data.

Glossary

Australian Privacy Principles (APPs)
A set of 13 principles that govern the handling of personal information by entities covered by the Privacy Act 1988.
Office of the Australian Information Commissioner (OAIC)
The independent Australian government agency responsible for overseeing the Privacy Act 1988 and the Freedom of Information Act 1982.
Notifiable Data Breaches
A scheme introduced in 2018 that requires entities to notify affected individuals and the OAIC of data breaches likely to result in serious harm.

This article focuses on the Australian Privacy Act 1988, not to be confused with the United States Privacy Act of 1974.