Australian privacy requirements and regulatory expectations continue to develop. Some changes are already operating, some have confirmed future commencement dates and others remain under development.
Statutory tort for serious invasions of privacy
In effect · 10 June 2025Individuals now have an additional pathway to seek redress through the courts for serious invasions of privacy where the legal requirements are met. Organisations should be able to explain and support their information-handling decisions, not merely point to a policy document.
Practical review: Check collection practices, access controls, disclosures, surveillance, sensitive information and complaint escalation.
Source: Office of the Australian Information Commissioner →Expanded regulatory and enforcement framework
In effectRecent reforms expanded the privacy regulator’s investigation and enforcement options, including additional civil-penalty and compliance mechanisms. Policies, notices and operating practices should be current, supportable and capable of being implemented in practice.
Practical review: Check whether documented practices match what staff, systems and suppliers actually do.
Source: Office of the Australian Information Commissioner →Automated-decision transparency
Confirmed commencement · 10 December 2026Certain organisations covered by the Australian Privacy Principles will need to include additional information in their privacy policies where personal information is used in automated decisions that may significantly affect a person’s rights or interests.
Practical review: Identify where computer programs use personal information to make or materially support significant decisions. Record the information used, the kinds of decisions made and what affected people are told.
Source: Office of the Australian Information Commissioner →Children’s Online Privacy Code
Under development · Target 10 December 2026A Children’s Online Privacy Code is being developed for online services likely to be accessed by children. This may affect websites, apps, platforms, games, education services and online communities used by children, even where children are not the sole intended audience.
Practical review: Consider whether children are likely to access the service, what information is collected, whether the design is appropriate and how notices and consent operate.
Source: Office of the Australian Information Commissioner →Privacy-policy scrutiny
Current regulatory focusThe privacy regulator has undertaken targeted reviews of privacy policies and has publicly emphasised that policies should be clear, current and compliant with Australian Privacy Principle requirements.
Practical review: Confirm the policy explains what is collected, why, how it is used, who receives it, overseas disclosure, access and correction, complaints, retention and automated decision-making where required.
Source: Office of the Australian Information Commissioner →This information is general and does not constitute legal advice. The obligations applying to an organisation depend on its circumstances, activities and legal status.
Last reviewed against OAIC sources: August 2026.