Navigating Australian Privacy Reform:
Your guide to the changes ahead
Key Takeaways
|
In 2014, the Australian Law Reform Commission released the ‘Serious Invasions of Privacy in the Digital Era’ Report (ALRC Report), recognising that Australia’s privacy protections were unable to keep pace with the complex challenges created by emerging technologies such as mobile phones, surveillance devices, drones and online platforms. The ALRC Report recommended the introduction of a statutory cause of action for serious invasions of privacy for physical intrusions into a person’s private space by watching, listening to, or recording a person’s private affairs, and for the misuse of a person’s private information.
Over 10 years later, Parliament has answered this call through the introduction of the statutory tort. This means that for the first time, Australian’s have a personal cause of action to sue another who invades their privacy by intruding on their seclusion or misusing information relating to them.
The new statutory tort strengthens privacy protections by creating a new cause of action for serious invasions of privacy. It empowers the Court to grant a range of remedies, including, importantly, damages for non-economic loss. This may increase your business’ risk of litigation (including class action litigation) for privacy breaches, and may have flow on effects for insurance premiums and other compliance costs.
The tort does not require a breach of the APPs or other Privacy Act provisions to be triggered, or for the impacted interference with privacy to be personal information as otherwise defined in the Privacy Act. A separate proposal for a direct right of action for Privacy Act breaches has been deferred for further consideration as part of the Tranche Two Reforms.
What is needed to make out the Statutory Privacy Tort?
Claimants need to show that:
|
Under the tort of misuse of private information in the UK, “misuse” requires a positive action (albeit it may be unintentional) and not merely a failure to have in place adequate systems for storing and protecting data. Courts in that jurisdiction have found that circumstances where a company failed to keep data secure when it suffered a cyber-attack or failed to wipe data from a smart device before on-selling it were not misuse of information due to the lack of a positive act.2 Having said that, the UK tort was developed out of a need to give effect to Article 8 of the European Convention on Human Rights, and the meaning of “misuse” has been interpreted in light of the use of “interference” in that article. |
Importantly, no proof of damage is required for a claim to succeed, although the extent of damage may be relevant to establishing the seriousness of the conduct.
The limitation period for these claims is short. In all cases where the claimant is an adult when the invasion of privacy occurred, proceedings must be commenced before the earlier of: (a) 1 year after the day the plaintiff became aware of the invasion of privacy; or (b) 3 years after the invasion of privacy occurred
Remedies
The remedies for breach include damages (including for non-economic loss and emotional distress, although capped), an account of profits, an injunction, an apology, a declaration that the defendant has seriously invaded their privacy, and destruction or delivery up of material. Aggravated damages are not available, but the Court may award exemplary or punitive damages in exceptional circumstances.
Any non-economic damages award is capped at the maximum amount of a non-economic damages award for defamation proceedings, which is presently $478,5503.
Defences and Exemptions
Defences / exemptions to the invasion of privacy which apply include where:
What sort of conduct would be captured?
Examples of conduct included in the Explanatory Memorandum (EM) which may amount to misuse of information are:
The EM also outlines examples where information handling is unlikely to give rise to an issue under the tort:
Developing common law tort?
Separate to the statutory tort above, last year, the Victorian County Court recognised a common law tort for the invasion of privacy in Waller (A Pseudonym) v Barrett (A Pseudonym) [2024] VCC 962. The plaintiff claimed against her estranged father for discussing her personal and intimate details with the media without her consent. While the factual matrix is not directly applicable to a commercial context and the decision is from a lower court, it underscores the growing judicial willingness to protect individuals’ privacy rights and is notable for awarding damages for non-economic loss on that basis.
The County Court recognised that an action for invasion of privacy forms part of the common law of Australia, developing under the umbrella of an action for breach of confidence, but emerging as a separate and distinct category of cases. Rather than protecting specific information (as was the basis for actions for breach of confidence), the underlying principle in the developing class of privacy cases was the protection of human dignity that is associated with the maintenance of privacy.
Notably:
This judgment arose prior to the statutory tort coming into effect. It remains to be seen whether courts will develop a common law cause of action further, or more clearly distinguish it from the statutory tort. Claimants may elect to run both causes of action, including because the common law cause of action is not subject to damages caps or the threshold requirements for intention and seriousness (although it is still not widely recognised, and we would expect any elements to become more precisely defined over time if it were).
Ultimately, businesses may be exposed to both statutory and common law causes of action for serious invasions of privacy. The compliance suggestions above should be undertaken to minimise risks of breaches and non-compliance.
AI and automated decision-making
Other changes enacted under the first tranche of privacy law reforms include the regulation of automated decision-making, affecting AI platforms and systems. This will take effect from 10 December 2026.
The reforms will require APP entities to include certain disclosures in their privacy policies if they use personal information in computer programs to make automated decisions on matters which are reasonably expected to significantly affect the rights or interests of the individual, and where that personal information is substantially and directly related to making that decision. Relevant decisions may include the refusal to grant a benefit to an individual, an individual’s rights under a contract, and decisions that affect an individual’s right to access a significant service or support.
Policies will need to include disclosures about the kinds of:
These transparency requirements demonstrate the growing intersection of AI and privacy, as lawmakers and regulators seek to catch up to technological developments and introduce safeguards for individuals’ rights in that context.
Privacy Act: Tranche Two Reforms
Tranche Two Reforms of the Privacy Act are not expected to land until at least late 2025 (the new Attorney General has declined to provide a timeline so far). However, this second wave of reform will likely include consent reforms, new fair and reasonableness requirements, individual rights, removal of the employee and small business exemptions, and assessing privacy impacts of high-risk activities. Further changes may include the right to be forgotten, stricter regulation of biometric data, greater consent requirements and the right to data portability.
Footnotes
Other changes implemented as part of these reforms include new doxxing offences with an ancillary penalty of 6 years imprisonment (which came into effect earlier on 11 December 2024) (Doxxing Reform). The Doxxing Reform prohibits people from using a carriage service (ie an email account or social media account) to publish, make available or distribute personal data of another individual (which would allow the individual to be identified, contacted or located) and engaging in what a reasonable person would consider menacing or harassing conduct towards the individual. A similar doxxing offence was also introduced in respect of doxxing offences against one or more members of certain groups distinguished by race, religion, sex, sexual orientation, gender, disability, nationality or ethnic origin (among others). The Doxxing Reform provides an example of conduct that would be captured, being where the name, image and telephone number of an individual is published on a website and others are encouraged to repeatedly contact the individual with violent or threatening messages.
Warren v DSG Retail Ltd [2021] EWHC 2168 and Stadler v Currys [2022] EWHC 160N.
Since 1 July 2024, maximum damages for non-economic loss in defamation proceedings is $478,500. This amount is indexed annually.
See clause 1 of Schedule 1 of the Privacy Bill.
Your guide to the changes ahead
Partner, Sydney
Partner, Melbourne
Special Counsel, Melbourne
Partner, Head of TMT, Asia, Singapore
Solicitor, Sydney
The contents of this publication are for reference purposes only and may not be current as at the date of accessing this publication. They do not constitute legal advice and should not be relied upon as such. Specific legal advice about your specific circumstances should always be sought separately before taking any action based on this publication.
© Herbert Smith Freehills Kramer 2026
Receive timely insights and briefings from HSF Kramer, tailored to keep you informed and ahead