Learnings from 2025 and considering what’s next in 2026
With January 2026 almost in the rearview mirror and in celebration of Data Privacy Week, now is a great time to reflect on the privacy, cyber and related digital law lessons and milestones from 2025 and consider what might be around the corner in 2026. From evolving regulations to the first civil penalty awarded under the Privacy Act 1988 (Cth) (Privacy Act), the past year underscored the critical role privacy, cyber security and digital governance plays in building trust and resilience.
This article recaps the key privacy, cyber and related digital law matters from 2025 and previews the trends, risks, and issues that we expect will define the year ahead.
Top 3 in 2025:
- The first ever civil penalty under the Privacy Act was awarded against Australian Clinical Labs following their 2022 cyber attack – a reminder of the importance of preparedness and accountability.
- The Federal Government introduced its National AI Plan to support AI growth and investment within Australia – confirming its plan to manage AI using existing legislation, rather than introducing AI-specific legislation.
- The new statutory tort for serious invasions of privacy commenced and Australia led the pack with a world-first social media minimum age ban.
In 2026, we will be watching:
- For further enforcement action by the OAIC, ASIC and the ACCC in line with their stated priorities – the OAIC has already kicked 2026 off with its first ever compliance sweep of selected businesses’ privacy policies.
- For further OAIC guidance on the automated decision-making transparency obligations and the draft Children’s Online Privacy Code, which are to take effect by 10 December 2026. Organisations with automated-decision making embedded in their businesses or who operate online services accessed by children should be paying close attention to this space.
- The progress of law reform activities, particularly in relation to workplace surveillance, AI and (potentially) the long-awaited tranche 2 amendments to the Privacy Act.
2025 reflections
Shaped by the changing legal landscape, consumer expectations, and the relentless pace of digital innovation, 2025 was a year in which privacy, cyber and related digital law issues took centre stage.
We set out below some of the key developments and determinations from 2025, with an emphasis on the lessons to be learned from these.
Australian Clinical Labs decision
In October 2025, the Federal Court1 approved the first ever civil penalty under the Privacy Act, ordering Australian Clinical Labs to pay $5.8 million following a 2022 cyber attack that exposed the personal and sensitive health information of approximately 223,000 Australians.
This decision sent a clear message that entities must take proactive and ongoing reasonable steps to secure personal information and respond swiftly to suspected data breaches. Importantly, the Court confirmed that accountability cannot be outsourced: even where a third-party service provider is engaged in the aftermath of an incident, an entity is not absolved of its privacy obligations.
Our key takeaways here? Preparedness and accountability are key. This incident also highlighted the importance of managing cyber risks when undertaking M&A activities.
For a more extensive overview of the decision and its significance, refer to our previous article here.
Australian social media minimum age
In December 2025, Australia introduced a world-first social media minimum age ban. The reform requires age-restricted social media platforms to take reasonable steps to prevent children under 16 from holding accounts, with maximum civil penalties of $49.5 million for body corporates2. So far, eSafety has listed 10 age-restricted social media platforms3; a number which is likely to increase as more platforms are evaluated.
The OAIC also published guidance for platform providers on their privacy obligations in the context of the requirements.
This reform highlights the growing regulatory focus on children’s privacy, online safety, age-assurance technologies and platform accountability, and shows how privacy compliance increasingly intersects with online safety.
Refer to our previous article here, for more details.
Facial recognition decisions
Following on from the 2024 Bunnings Group Limited (Bunnings) decision4, in August 2025, Kmart Australia Limited (Kmart) was similarly stung by the Australian Privacy Commissioner (Commissioner) in respect of its use of FRT in stores between mid-2020 and mid-2022.
While the Commissioner has outlined that these decisions are not intended to impose a ban on the use of FRT, they raise questions as to how organisations can operate FRT in a retail setting in compliance with privacy law. These decisions serve as a reminder for all organisations to assess whether new practices and technologies comply with privacy laws.
With Bunnings’ appeal of the Commissioner’s 2024 decision regarding its use of FRT underway, this will be an area that we will be closely watching in 2026.
AI Action Plan
In December 2025, the Federal Government introduced its National AI Plan, whereby the government will seek to manage AI using existing legislation, rather than introducing new AI-specific legislation – shelving plans to introduce a standalone AI Act in Australia.
An AI Safety Institute has also been announced. Set to commence in 2026, its role will be to advise on AI developments to ensure adequate safety measures and legal frameworks are maintained.
Tort of privacy
The statutory tort for serious invasions of privacy commenced in June 2025. Under this new action, individuals may seek remedies where another person or organisation intentionally or recklessly invades their seclusion or misuses information about them, in circumstances where the invasion of privacy is serious, privacy is reasonably expected, and it is not contrary to the public interest5.
Early consideration of the tort has already resulted in the District Court granting an interlocutory injunction to restrain an individual’s misuse of private photographs not intended for public release6.
ACMA enforcement action: spam
In 2025, the ACMA enforced substantial penalties and undertakings against businesses for unsolicited communications and spam law breaches.
Notably, the ACMA issued a penalty of $4,003,270 for sending marketing messages without a functional unsubscribe mechanism or recipient consent, in one of the larger fines we have seen in this space in recent years7.
The ACMA also consulted on a mandatory SMS Sender ID Register to help tackle impersonation scams. The ACMA plans to launch this register in mid-2026.
Civil proceedings against Optus
In August 2025, civil penalty proceedings were commenced by the Commissioner in the Federal Court against Singtel Optus Pty Limited and Optus Systems Pty Limited for serious interferences with privacy, following the headline-making 2022 data breach that affected approximately 9.5 million Australians.
Refreshed priorities
The OAIC has published refreshed and streamlined regulatory enforcement priorities for 2025-26 (available here), reaffirming the OAIC’s focus on rebalancing power and information asymmetries (particularly in areas that involve power and information imbalances) and preserving privacy rights in the context of new and emerging technologies.
The Australian Signals Directorate and the Australian Institute of Company Directors have also provided guidance on cyber security governance, with particular consideration given to the ever-evolving cyber threat environment. Informed by the annual cyber threat report 2024-25 (available here), 4 priority areas have been identified, including event logging and threat detection, management of legacy IT assets, cyber supply chain controls, and preparation for a post quantum cryptography environment.
ASIC enforcement
Finally, 2025 saw continued ASIC enforcement in relation to cybersecurity risk management. In July 2025, ASIC commenced civil proceedings in the NSW Supreme Court against Fortnum Private Wealth Limited (Fortnum)8. ASIC alleged that Fortnum failed to comply with its general obligations as a financial services licensee under the Corporations Act 2001 (Cth) by failing to properly manage and mitigate cybersecurity risks. ASIC’s claims focused on the inadequacy of Fortnum’s policies, systems and employee education to address and manage cybersecurity risks, presenting that this exposed the company and its clients to an unacceptable level of risk of a cyber attack.
Fortnum and similar actions brought by ASIC highlight a recurring theme; namely, it is paramount that organisations proactively and adequately understand and manage their cybersecurity and privacy risks.
What we will be following closely in 2026
Sustained enforcement focus
The Australian Privacy Commissioner has repeatedly indicated that the OAIC will adopt an increased enforcement posture. We expect to see more enforcement action and use of new tranche 1 regulatory tools to address non-compliance, including in respect of non-compliance with the Privacy Act that does not reach the threshold of ‘serious and repeated interference’.
Notably, in December 2025, the OAIC announced it would undertake its first-ever compliance sweep. The sweeps are focused on auditing selected businesses’ privacy policies to ensure compliance, with a further focus on in-person collection of personal information. These sweeps have now begun.
We also expect other regulators to continue prioritising enforcement in this space in 2026, including ASIC continuing its focus on cyber security risk management as a central compliance obligation, and the ACCC continuing its focus on unfair business practices following its commencement of proceedings against HelloFresh and YouFoodz for unfair subscription practices9.
The message is clear: now is the time to ensure your house is in order.
Tranche 2 reforms?
While the tranche 1 reforms to the Privacy Act have commenced, there remains uncertainty regarding when the tranche 2 reforms will arrive and what they will include.
The tranche 2 reforms were expected to potentially remove the employee records and small business exceptions, incorporate a new ‘fair and reasonable’ test in respect of the handling of personal information, and expand individual rights.
While there has been no confirmation regarding when exactly tranche 2 will be announced, we may see these reforms progressed sometime in 2026.
Commencement of automated decision-making transparency obligations
Introduced as part of the first tranche of reforms to the Privacy Act, from 10 December 2026, organisations who use automated decision-making systems in particular ways will need to ensure their privacy policies reflect certain matters. In particular, where an organisation uses a computer program to “make, or do a thing that is substantially and directly related to a decision”, specific content must be included in the organisation’s privacy policy10.
While the OAIC made high level updates to the APP Guidelines to address these new requirements in late 2025, more detailed guidance is expected in the coming months.
Children’s online privacy code
The OAIC is in the process of developing the Children’s Online Privacy Code (Code), with the aim of better protecting the privacy of children within Australia. The Code will outline how online services accessed by children must comply with the APPs and has the potential to significantly impact the privacy compliance obligations of in-scope services. The OAIC has announced that consultation on the draft Code will occur during 2026, with the Code expected to be in effect by 10 December 202611.
AI, FRT and surveillance
We may see clarifications to existing legislative frameworks in respect of AI regulation. We also are interested to see how the new AI Safety Institute will balance AI risk and the benefits of AI efficiency.
In terms of new tools to be used in business, the Bunnings and Kmart FRT decisions evidence how, at times, new technologies do not easily squeeze into the existing legislative frameworks. We will be waiting to see the outcome of Bunnings’ appeal of the Commissioner’s finding in respect of its use of FRT. In the meantime, we expect the Commissioner will not look kindly on businesses who seek to introduce new technologies without properly assessing privacy risks and complying with the requirements under APP 1.2 (which requires organisations to proactively review the adequacy of their practices, procedures and systems).
Moreover, given the National AI Plan hinted at a need to protect employees in the workplace from AI surveillance, we may see some focus on this space. While specific workplace surveillance legislation currently exists in New South Wales and the ACT, outside of the workplace, surveillance in Australia is governed by a patchwork of various state and territory legislation. With organisations implementing new tools that go to monitoring individuals (particularly employees), we expect to see surveillance as an area of increased scrutiny (particularly if the employee records exception is abolished as proposed by the tranche 2 privacy reforms).
Notably, we have already seen developments in this space as follows:
- in November 2025, the Victorian government published its Response12 to the Final Report (Report) of the Legislative Assembly Economy and Infrastructure Committee’s Inquiry into workplace surveillance (Response). In the Response, the government indicated its support in principle for 15 of the 18 recommendations proposed in the Report; and
- the Work Health and Safety Amendment (Digital Works System) Bill 2025 has been introduced in New South Wales. The Bill is concerned with business’ use of algorithms, AI, automation, online platforms (referred to in the Bill as ‘digital work systems’) in the workplace. Notably, the Bill introduces obligations on persons conducting a business or undertaking to ensure, so far as reasonably practicable, that the health or safety of a worker is not put at risk from the allocation of work by a digital work system used by the business13. It is anticipated that the Bill will be passed sometime in 2026.
Tort of privacy
We expect more opportunities for judicial consideration of the new statutory tort for serious invasions of privacy.
Spam enforcement
The ACMA has reaffirmed its enduring priority to combat unwanted spam and telemarketing, outlining that it will escalate its approach to businesses that do not respond to early warnings14.
If your business is sending direct marketing, this is a reminder to review your compliance with applicable direct marketing laws and ensure you have effective measures in place to ensure compliance.
Need advice?
For advice on further understanding upcoming regulations in the emerging technology and AI space, contact Alex Hutchens, Partner and Head of Technology, Media and Telecommunications, at ahutchens@mccullough.com.au or here.
[1] Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224.
[2] See Online Safety Act 2021 (Cth) s 63D; Regulatory Powers (Standard Provisions) Act 2014 (Cth) s 82(5)(a).
[3] eSafety Commissioner, ‘Which platforms are age-restricted?’, About social media age restrictions (web page), <https://www.esafety.gov.au/about-us/industry-regulation/social-media-age-restrictions/which-platforms-are-age-restricted>.
[4] Commissioner Initiated Investigation into Bunnings Group Ltd (Privacy) [2024] AICmr 230.
[5] See Privacy Act 1988 (Cth) sch2, s 7.
[6] See Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396.
[7] See the ACMA, ‘Investigations into spam and telemarketing’, Telemarketing and spam compliance and investigations (web page) <https://www.acma.gov.au/investigations-spam-and-telemarketing#outcomes-for-2025
[8] See ASIC, ‘ASIC sues Fortnum Private Wealth for allegedly failing to adequately manage cybersecurity risks’, Media release (web page) 22 July 2025 <https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2025-releases/25-143mr-asic-sues-fortnum-private-wealth-for-allegedly-failing-to-adequately-manage-cybersecurity-risks/>.
[9] See ACCC, ‘HelloFresh and Youfoodz in court over alleged subscription traps’, Media release (web page) 16 December 2025 <https://www.accc.gov.au/media-release/hellofresh-and-youfoodz-in-court-over-alleged-subscription-traps>.
[10] See new APPs 1.7 and 1.8 to be inserted under the Privacy Act.
[11] See OAIC, ‘Children’s online privacy code’, Privacy Codes (web page) 19 February 2025 <https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code>.
[12] See Victorian Government, ‘Government Response to Inquiry into workplace surveillance’, Private sector industrial relations (web page) <https://www.vic.gov.au/workplace-surveillance>.
[13] See new section 21A(1) of the Workplace Health And Safety Act 2011 (NSW), as proposed to be amended by the Work Health and Safety Amendment (Digital Work Systems) Bill 2025 (NSW).y-code>.
[14] See the ACMA, ‘Action on scams, spam and telemarketing: July to September 2025’, Publications (web page) last updated 15 December 2025 <https://www.acma.gov.au/publications/2025-12/report/action-scams-spam-and-telemarketing-july-september-2025>.