What this guide covers
This guide explains how the Privacy Act 1988 (Cth) applies to Australian organisations, what your obligations are under the Australian Privacy Principles (APPs), and how to manage risk under the Notifiable Data Breaches (NDB) scheme.
It is designed for:
- Executives responsible for governance, risk and compliance
- CIOs, CTOs and IT leaders responsible for implementation
What is the Privacy Act 1988?
The Privacy Act 1988 (Cth) is the Australian law that regulates how organisations collect, use, store and disclose personal information.
Personal information includes:
- Names and contact details
- Financial or health data
- Employee and customer records
- Any data that can reasonably identify an individual
Why Privacy Act compliance matters
Privacy Act compliance is not just a legal requirement. It directly impacts:
- Regulatory exposure
- Customer trust
- Operational resilience
- Board-level accountability
Failure to comply can result in:
- Investigation by the Office of the Australian Information Commissioner (OAIC)
- Significant financial penalties
- Mandatory public disclosure of breaches
- Reputational damage
Who must comply with the Privacy Act in Australia?
Organisations must comply if they:
- Have annual revenue above $3 million
- Provide health services
- Trade in personal information
- Are contracted to government
Even where not strictly required, many organisations adopt compliance due to:
- Supply chain requirements
- Cyber insurance conditions
- Customer and partner expectations
The 13 Australian Privacy Principles (APPs)
The Australian Privacy Principles (APPs) define how personal information must be managed across its entire lifecycle.
Summary of the APPs
| Principle | Requirement |
| APP 1 | Maintain transparent privacy policies |
| APP 2 | Allow anonymity where appropriate |
| APP 3–5 | Collect data lawfully and notify individuals |
| APP 6–7 | Restrict use, disclosure and marketing |
| APP 8 | Manage cross-border data risks |
| APP 9 | Limit use of government identifiers |
| APP 10 | Ensure data accuracy and quality |
| APP 11 | Secure personal information |
| APP 12–13 | Provide access and correction rights |
Executive takeaway
The APPs represent a continuous governance framework, not a checklist.
If controls are not embedded into systems, people and processes, compliance does not exist in practice.
Notifiable Data Breaches (NDB) Scheme
The Notifiable Data Breaches scheme requires organisations to report serious data breaches to regulators and affected individuals.
What is a notifiable data breach?
A notifiable data breach occurs when:
- Personal information is accessed, disclosed or lost without authorisation
- The breach is likely to result in serious harm
- The risk cannot be mitigated quickly
What organisations must do
When a breach occurs:
- Assess the incident promptly
- Contain and remediate the breach
- Notify the OAIC
- Inform affected individuals
Why this matters
Under the NDB scheme, cyber incidents become:
- Public events
- Regulatory obligations
- Board-level risks
Your ability to respond is as important as preventing the breach itself.
OAIC Enforcement and Penalties
The Office of the Australian Information Commissioner (OAIC) enforces the Privacy Act.
What enforcement includes
- Investigations into data handling practices
- Enforceable undertakings
- Mandatory remediation actions
- Public determinations
Privacy Act penalties
Serious or repeated breaches can lead to:
- Significant financial penalties
- Court-enforced compliance measures
- Public disclosure of non-compliance
Key insight
Regulators increasingly expect organisations to demonstrate:
- Active control over data
- Ongoing risk management
- Operational capability, not just policy documentation
Privacy Act Compliance Checklist
This checklist provides a practical baseline for assessing your organisation.
Governance
- Documented privacy policy aligned to APPs
- Defined ownership at executive level
- Clear accountability across departments
Data visibility
- Clear understanding of where personal data is stored
- Mapping of systems, applications and vendors
- Awareness of cross-border data exposure
Security controls (APP 11 alignment)
- Identity and access management
- Multi-factor authentication
- Endpoint and network protection
- Monitoring and detection
Breach response (NDB readiness)
- Documented incident response plan
- Defined escalation process
- Tested breach scenarios
Data lifecycle management
- Controlled collection practices
- Secure storage and retention
- Defined data disposal processes
Workforce awareness
- Ongoing privacy and cyber training
- Clear reporting pathways for incidents
Common Privacy Compliance Gaps
Most organisations are not non-compliant due to lack of awareness.
They are exposed due to lack of execution.
The most common gaps
- Limited visibility over personal data locations
- Inconsistent enforcement of access controls
- Legacy infrastructure not meeting current requirements
- Absence of a tested breach response capability
- Misalignment between policy and operational reality
What this creates
These gaps increase:
- Cyber risk exposure
- Regulatory scrutiny
- Business disruption during incidents
Data Protection Best Practices
To move beyond compliance into capability, organisations should:
- Align governance and technology
Compliance controls must be enforced through systems, not just documented.
- Apply risk-based security
Security should reflect the sensitivity and impact of the data being handled.
- Maintaincontinuous visibility
You cannot protect what you cannot see. Data mapping is critical.
- Integrate compliance into operations
Privacy should be embedded into everyday workflows, not treated as a separate function.
- Build breach readiness
Your ability to respond quickly is a defining factor under the NDB scheme.
How prepared is your organisation?
Consider:
- Do you know where all personal information is stored?
- Could you respond to a breach within required timeframes?
- Are your controls aligned to the Australian Privacy Principles?
If the answer is unclear, the organisation is exposed.
Frequently Asked Questions
What is the Privacy Act 1988?
The Privacy Act 1988 is the Australian law that governs how organisations collect, use, store and protect personal information.
Who must comply with the Privacy Act?
Most organisations with revenue above $3 million, and those handling sensitive personal data, must comply.
What are the Australian Privacy Principles?
The Australian Privacy Principles are 13 rules that define how personal information must be managed across its lifecycle.
What is a notifiable data breach?
A notifiable data breach is a breach likely to result in serious harm that must be reported to the OAIC and affected individuals.
What happens if an organisation does not comply?
Non-compliance can result in regulatory investigation, financial penalties, and reputational damage.
Next Step for Executives and IT Leaders
Privacy compliance is not a one-off exercise.
It is an ongoing capability across:
- governance
- cyber security
- technology
- operational processes
Organisations that take this approach achieve:
- reduced regulatory risk
- faster incident response
-
- stronger trust with customers and partners





