Praeferre/Frameworks/Privacy Act 1988
Privacy & Data Protection · Australia

Privacy Act 1988 & Australian Privacy Principles (APPs)

Australia's principal privacy law, built around 13 Australian Privacy Principles covering collection, use, disclosure and security of personal information. Recent reforms have significantly increased penalties and introduced new enforcement powers.

REGULATOROffice of the Australian Information Commissioner (OAIC) REGIONAustralia EFFECTIVE1988, with major reform amendments from 2022 onward

Who it applies to

  • Australian and certain overseas organisations with an Australian link
  • Commonwealth government agencies
  • Businesses with annual turnover above the statutory threshold, plus specific sectors regardless of size

Key requirements

  • Compliance with the 13 Australian Privacy Principles
  • An up-to-date, accessible privacy policy
  • Notifiable Data Breaches scheme reporting to the OAIC and affected individuals
  • Reasonable steps to secure personal information
  • Cross-border disclosure accountability

Maximum penaltyUp to the greater of AUD $50 million, three times the benefit obtained, or 30% of adjusted turnover for serious or repeated breaches

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates Privacy Act 1988 compliance

Continuous monitoring, evidence and reporting for Privacy Act 1988 — alongside every other framework you need to satisfy.