The ‘first tranche’ of reforms to the Privacy Act 1988 (Cth) have finally arrived after years of anticipation. The reform bill however is significantly slimmer than expected, omitting some of the more substantial reforms needed to modernise the outdated Australian privacy regime.
The Albanese Government has introduced the Privacy and Other Legislation Amendment Bill 2024 (the Bill) which, if passed, would enact the first tranche of reforms to the Privacy Act 1988 (Cth) that were agreed by the Government in its Response to the Privacy Act Review of September 2023.
Key Takeaway Points:
- Reforms to the Privacy Act 1988 (Cth) have arrived after years of anticipation, however, the bill stops short of making the substantial reforms needed to update Australia’s outdated privacy regime.
- Abolishing the small business exemption, amendments to the definitions of ‘personal information’ and ‘consent’, and other more significant changes are expected in the ‘second tranche’ of reforms, now postponed until after the 2025 election.
- While the Bill has not delivered on some of the larger reforms anticipated by the Privacy Act Review Response, the Bill presents an opportunity for businesses to review and update their privacy practices.
- Australian businesses should stay focused on their preparations for wider privacy reform ahead of 2025.
What is in the Bill
Statutory tort for serious invasions of privacy
The Bill introduces a statutory tort for serious invasions of privacy (i.e., a civil wrong). The tort would give individuals the ability to sue for serious invasions of their privacy, either by intrusion into their seclusion or by misuse of information. Importantly, the tort only applies where there is a reasonable expectation of privacy, and where the invasion was intentional or reckless. Individuals suffering an invasion of their privacy that has resulted from an accident or negligence will not therefore be able to sue using this tort.
As before, the only avenue for individuals to take action for a breach of the Australian Privacy Principles in relation to their personal information will be to complain to the OAIC (who may take undertake an investigation or make a determination).
Development of a Children’s Online Privacy Code
A process for developing a new Children’s Online Privacy Code (Children’s Code) has been introduced with the aim of better protecting children from a range of online harms. The Children’s Code will be developed by the Privacy Commissioner, however, is not likely to be implemented for a number of years (with the deadline for registering the Children’s Code more than two years away).
Greater transparency around automated decision-making
The Bill introduces an obligation for entities to include information in privacy policies about the kinds of personal information used in, and types of decisions made by, computer programs that use personal information to make automated decisions that could affect the rights or interests of an individual.
Examples of automated decision- making systems could include systems that:
- assess job applications and rank the suitability of those applications;
- analyse inputs to recommend resource allocation;
- monitor and analyse network data to detect threats; and
- analyse employee performance.
Streamlined information sharing, tiered penalties, and stronger enforcement powers
The Bill also introduces several other changes, including:
- streamlined information sharing in the case of an emergency or eligible data breach;
- ‘tiered’ penalties allowing for lower fines for more minor breaches of the Privacy Act; and
- stronger enforcement powers for the Australian Information Commissioner.
What is not in the Bill
Small business exemption
The recommendation to abolish the ‘small business exemption’ (exempting businesses with an annual revenue of less than $3 million from compliance with the Privacy Act) has not been included in the Bill. For the time being, small businesses will not therefore be required to comply with Privacy Act obligations including for example, the need to have privacy policies and collection notices.
Changed definitions of ‘personal information’ and ‘consent’
The Bill has not adopted the recommendation of the Privacy Act Review to broaden the definition of ‘personal information’ to encapsulate technical information such as device IDs and IP addresses.
The Bill also does not reform the definition of ‘consent’, which would have required consent to be ‘voluntary, informed, specific, current and unambiguous’ rather than ‘implied’ as is the current wording under the Privacy Act.
Takeaways
While the Bill has not delivered on some of the larger reforms anticipated by the Privacy Act Review Response, the Bill presents an opportunity for businesses to review and update their privacy practices.
In particular, entities should revise their privacy policies and ensure details about the kinds of personal information used in, and types of decisions made by, computer programs that make automated decisions are clearly set out.
‘Second tranche’ of reforms
The abolition of the small business exemption, amendments to the definitions of ‘personal information’ and ‘consent’, and other more significant changes are expected in the ‘second tranche’ of reforms, now postponed until after the 2025 election.
Australian businesses should stay focused on their preparations for wider privacy reform ahead of 2025 by, for example, reviewing their governance frameworks and controls, establishing clear roles and responsibilities for privacy compliance, and implementing privacy by design practices and procedures.
If you would like advice on your privacy obligations, or our assistance with preparing privacy policies or procedures, please contact our Corporate Advisory and Governance experts.



