Other meanings of Privacy Act
Law
The Privacy Act 1988 is an Australian federal statute that regulates the handling of personal information by Australian government agencies and private sector organisations. Enacted in 1988 and significantly amended in 2000, it established the Australian Privacy Principles (APPs) and created the Office of the Australian Information Commissioner (OAIC) to oversee compliance.
The Privacy Act 1988 applies to Australian government agencies and to private sector organisations with an annual turnover of more than $3 million, as well as to all health service providers and some small businesses that handle personal information. The Act sets out 13 Australian Privacy Principles (APPs) that govern the collection, use, disclosure, storage, access, and correction of personal information. The APPs require entities to have a clearly expressed privacy policy, to collect only what is necessary, and to take reasonable steps to secure the information they hold.
The Act also provides individuals with the right to access and correct their personal information, and it restricts the transfer of data overseas unless the recipient is subject to similar protections. The Office of the Australian Information Commissioner (OAIC) investigates complaints and can seek civil penalties for serious or repeated breaches.
The Privacy Act 1988 was enacted in response to growing concerns about the use of personal data by government agencies, following the recommendations of the Australian Law Reform Commission's 1983 report on privacy. The original Act applied only to the public sector, but in 2000 the Howard government extended it to most private sector organisations, a change that took effect in December 2001.
Subsequent amendments have addressed new technologies and practices. The Privacy Amendment (Notifiable Data Breaches) Act 2017 introduced mandatory data breach notification, requiring entities to notify affected individuals and the OAIC when a data breach is likely to result in serious harm. The Act was also amended in 2014 to strengthen the powers of the OAIC and to increase penalties for non-compliance.
The Office of the Australian Information Commissioner (OAIC) is responsible for enforcing the Privacy Act 1988. It can investigate complaints, conduct own-motion investigations, and make determinations that include compensation for individuals. In serious cases, the OAIC can seek civil penalties in the Federal Court, with maximum penalties currently set at $2.5 million for corporations.
Notable enforcement actions include the 2023 case against Meta Platforms, where the Federal Court found that the company had breached the Act through its use of the Onavo app to collect user data. In 2024, the OAIC also commenced proceedings against the health insurer Medibank for a major data breach that affected millions of customers. These cases highlight the Act's growing importance in the digital age.
Beyond the core provisions, the Privacy Act 1988 contains several lesser-known elements. It exempts certain types of information, such as employee records held by private sector employers, and it does not apply to media organisations acting in a journalistic capacity. The Act also includes specific rules for the handling of tax file numbers and for the use of data matching programs.
Another notable aspect is the Act's application to credit reporting, which is governed by Part IIIA and the Credit Reporting Privacy Code. This regime regulates how credit reporting bodies and credit providers handle consumer credit information. The Act also establishes the role of the Privacy Commissioner, who has the power to conduct assessments of compliance and to issue guidelines on emerging issues such as artificial intelligence and biometric data.
This article focuses on the Australian Privacy Act 1988, not to be confused with the United States Privacy Act of 1974.
Help improve the encyclopedia. Reports go straight to the site manager.