Privacy enforcement in Australia: the OAIC is not waiting for Tranche 2 and neither should you

As Privacy Awareness Week 2025 wrapped last week, the message was clear; Australia’s federal privacy regulator has a new enforcement toolkit and a clear-eyed vision about how to deploy it in a strategic and proportionate way. The regulator is aiming to address privacy harms, clarify the current law and deter some of the privacy invasive practices that Australians experience daily.

With privacy enforcement heating up and a new statutory tort for serious invasions of privacy coming into effect this month, the time to level up your privacy practices and make privacy your business is now.
This article will look at some recent developments in privacy enforcement in Australia, what issues we expect to be in the cross hairs in the near term and the steps that all organisations should be taking now.

What has changed?

The need for Australia’s privacy laws and regulatory enforcement to adapt to meet the requirements of the digital era are well-understood by government, the community and corporate Australia. This need is only being exacerbated by the speed and widespread adoption of recent technological advances. Just look at explosion of AI and how quickly it is being embedded in the products and services we interact with daily.

After a multi-year review of the Privacy Act 1988 (Cth) (Privacy Act), the first tranche of reforms to the Privacy Act became law in December last year. While the first tranche of reforms may have been a scaled down package, they included (amongst other changes – which you can read about here) a significantly expanded range of regulatory powers and civil penalties that the Privacy Commissioner may call on when investigating potential privacy violations and enforcing the Privacy Act.

This expanded enforcement toolkit now includes:

  • new civil penalty tiers for interferences with privacy that do not meet the threshold of ‘serious’ under section 13G, significantly lowering the bar for holding entities accountable for breaches of the Privacy Act (including the Australian Privacy Principles (APPs)) through civil penalty proceedings in Australia;
  • new compliance and infringement notices (including civil penalties) that can be issued without going to court for certain less serious breaches of the Privacy Act and APPs, giving the Privacy Commissioner a lower cost enforcement option that shifts the burden to the entity receiving the notice to decide whether to accept or challenge the notice;
  • bolstered monitoring and investigation powers, including entry, search and seizure powers to improve regulatory enforcement outcomes;
  • the ability to issue a greater scope of determinations following investigations and require a respondent entity to take steps to prevent or reduce any reasonably foreseeable loss or damage;
  • new powers to conduct public inquiries on the direction or approval of the Minister, which may enable the Privacy Commissioner to investigate a specific industry or market practice; and
  • new powers for the courts to make orders, including compensation orders, where the court determines that an entity has contravened a civil penalty provision and the individual has suffered, or is likely to suffer, loss or damage as a result of the contravention

While we wait to see how the much anticipated second tranche of privacy reforms will proceed following the recent federal election, in her opening address for Privacy Awareness Week 2025, Privacy Commissioner Carly Kind made it clear that the Office of the Australian Information Commissioner (OAIC) does not intend to wait. The Privacy Commissioner intends to maximise her regulatory impact through:

  • clear education, guidance and tools for government and business to enable compliance and safe innovation; and
  • strategic, targeted and proportionate enforcement of the current law using the range of enforcement tools now at her disposal to achieve clarity in the law and general deterrence.

We discuss what this may look like below.

What have we seen so far?

While many of these cases and developments pre-date the recent reforms, they demonstrate the shift toward increased privacy enforcement and litigation in Australia and provide some clues in relation to what we should expect in the near term.

Cyber related litigation

With data breaches, particularly those caused by malicious actors, remaining stubbornly common, it is of no surprise that we continue to see enforcement action and litigation flowing from these events.

Notably, the OAIC continues to prosecute civil penalty proceedings against Medibank and Australian Clinical Labs alleging serious interferences with the privacy of individuals in connection with their respective large scale data breaches. In March this year, ASIC also brought an action against an Australian financial services licensee for alleged failures to implement adequate cybersecurity measures, exposing itself and its clients to unreasonable cyber risk. This action follows ASIC’s previous litigation against RI Advice Group, in which the Federal Court found that the company had breached its obligations as an Australian financial services (AFS) licensee by failing to have adequate risk management systems to manage cybersecurity risks.

These significant regulatory enforcement actions send a clear message to corporate Australia about their accountability for managing cyber risk and, if these current proceedings go the distance, will provide additional clarity in relation to the security measures and resources organisations should have in place and the calculation of civil penalties under the Privacy Act.

Separate to these regulatory actions, class actions against Medibank and Optus continue to progress, with both proceedings shining a light on the complexities of establishing and maintaining legal professional privilege over reports procured in the aftermath of a cyber event.

Strategic OAIC determinations

In the last 12 months, we have seen several investigations and determinations targeting key areas of priority for the OAIC, including:

  • In October last year, the Privacy Commissioner issued an adverse determination against Bunnings Group Limited in relation to its use of facial recognition technology (FRT) in at least 62 Bunnings stores in Victoria and New South Wales between 2018 and 2021. The determination followed an investigation initiated by the Commissioner in which it was determined that Bunnings breached:
    • APP 3.3 by collecting biometric data (a form of sensitive information) without consent;
    • APP 5.1 by failing to provide adequate notice to customers entering the stores;
    • APP 1.2(a) by failing to implement practices, procedures and systems to ensure it complied with the APPs; and
    • APP 1.3 by failing to include required information in its privacy policy.

      This decision is particularly interesting, as the Privacy Commissioner applied a proportionality test when weighing up whether the collection was ‘necessary’. This test gave careful consideration to whether the FRT system achieved its stated purpose, whether the purpose could be met through less privacy intrusive means and whether the benefit outweighed the significant privacy intrusion. Bunnings is currently appealing the determination.
  • In November last year, the Privacy Commissioner issued adverse determinations against Master Wealth Control Pty Ltd t/a DG Institute and Property Lovers Pty Ltd. That company collected and used publicly available information from daily court listings across Australia and published death or funeral notices to create lead lists for property investors of potentially distressed properties where the owner may be willing to sell below fair market value due to their personal circumstances. The determinations followed investigations initiated by the Commissioner in which it was determined that the entities had breached:
    • o APP 3.5 by failing to collect personal information by fair means;
    • APP 5.1 by failing to provide notice to the individuals to whom the information related; and
    • APP 10.2 by failing to take reasonable steps to ensure the personal information they made available in their lead lists was accurate, up-to-date, complete and relevant.

This decision follows the OAIC’s focus on data scraping and misuse of publicly available information.

What’s next?

The Privacy Commissioner has indicated that the OAIC will publish refreshed regulatory enforcement priorities in the coming months. However, in the meantime, we have a few clues in relation to what we might see from the OAIC in the short term which includes:

  • continued regulatory enforcement action by the OAIC where organisations fail to adequately manage cyber risk. With cyber threats not going anywhere, real life harms occurring in the community and many organisations still failing to get the basics right, organisations are expected to implement reasonable technical and organisational measures to protect personal information, only collect the personal information that is necessary, and implement effective data retention and destruction practices;
  • increased enforcement of the APPs through public determinations and use of the lower tier civil penalties, with a focus on whether business practices are proportionate and within the reasonable expectation of individuals. In particular, we expect a continued focus on collection practices (APPs 3, 5 and 1) and an increased focus on secondary uses of personal information (APP 6). Civil penalties are more likely where the violation is consistent, systemic, particularly egregious or manifesting in real life harm;
  • investigation of practices publicly identified by the Privacy Commissioner, including the use of tracking pixels on websites and use of existing datasets to train AI models. We may see some determinations and civil penalty enforcement in this space soon which would supplement the guidance published by the OAIC on these topics last year;
  • use of compliance and infringement notices to achieve more streamlined regulatory enforcement outcomes. These notices may be used to address individual complaints or following a more proactive market scan to address low hanging fruit, such as failing to have an APP compliant privacy policy or give access to personal information;
  • a strategic focus on areas where there are significant power asymmetries, such as credit reporting, data broking and emerging technologies (including AI, biometric enabled technology, connected cars and apps); and
  • new and refreshed regulatory guidance. In the last year we have seen guidance published on a range of topics, including tracking pixels, AI and facial recognition technologies.

In addition to these matters, we also anticipate that:

  • ASIC will continue to take regulatory enforcement action where organisations experience a cyber-security incident, as ASIC has indicated that this is one of its enforcement priorities for 2025;
  • as regulatory action in this area becomes more frequent, there will be a consequent increase in class actions; and
  • the first claims under the new statutory tort for serious invasions of privacy will find their way into the courts. This statutory cause of action can be brought against all persons and organisations (regardless of size) and includes invasions of information privacy but also an individual’s physical privacy. This significantly expands the ability for individuals to seek redress for violations of their privacy.

What should organisations be doing now?

In the face of these developments, organisations and their leadership should focus their attention on the following matters:

Ensure your house is in order
  • revisit your privacy compliance framework, assess your level of compliance and privacy risk, and ensure you have effective and embedded policies, practices, procedures and systems in place to comply with the Privacy Act and the APPs; and
  • keep an eye out for new and refreshed OAIC guidance, determinations and any court and tribunal decisions, and review your practices if needed.
Focus on data governance and security
  • only collect the personal information you need, and ensure you have embedded effective data retention and destruction practices;
  • invest in data governance to ensure your management and use of personal information complies with the APPs. In addition to the compliance and risk benefits, this will be an important enabler of safe innovation and adoption of AI;
  • consider whether your cyber security risk management framework and resources are adequate to manage cyber risks and respond to potential weaknesses in your organisation’s technical and organisational security measures; and
  • have up-to-date and tested incident response plans which details the steps your organisation will take in the event of a cyber incident (including immediately and until the matter is resolved), which may include swift engagement with relevant regulators.
Undertake privacy impact assessments on high risk or privacy invasive technologies and practices
  • assess the privacy risks and impacts associated with any high-risk practices or privacy invasive technology (including AI and biometric enabled technology) and carefully weigh the benefits against the privacy impacts; and
  • ensure safeguards are implemented and appropriate ongoing assurance is in place.
Ensure you are prepared for regulatory engagement
  • expect to be required to show, not tell. Regulators will expect to see relevant policies and procedures as well as evidence of their ongoing implementation; and
  • in the event of a cyber security breach, regulators will want to see that you have acted promptly to contain the breach and minimise risk of harm to individuals, and that you understand the root cause and have fully remediated the root cause to prevent reoccurrence.

If you need help, please reach out to our team. From privacy compliance and data governance to cyber risk, commercial contracting, incident response, regulatory engagement and litigation, McCullough Robertson offers the full service of expert privacy guidance for you and your organisation and can deliver practical solutions and assist our clients stay ahead of and respond to the evolving regulatory landscape.