Australia
Australia's Privacy Act Reforms 2024-2025: What Changed and What's Still Pending

One amending Act, the Privacy and Other Legislation Amendment Act 2024 (Cth), made two major changes on two different dates: doxxing became a federal crime on 11 December 2024, and a new civil tort for serious invasions of privacy commenced separately on 10 June 2025.
This article addresses what the Privacy and Other Legislation Amendment Act 2024 (Cth) changed in the Privacy Act 1988 (Cth) and the Criminal Code, and separately identifies what remains only a proposal, current as at 19 July 2026, as part of recordinglaw.com's Australia data privacy laws hub. It does not address the day-to-day content of the Australian Privacy Principles themselves, covered in recordinglaw.com's Australian Privacy Principles guide, or the doxxing offences' operative wording in detail, which is a criminal law question outside this article's privacy-law scope.
One Amending Act, Multiple Reforms, Different Commencement Dates
The Privacy and Other Legislation Amendment Act 2024 (Cth), registered on the Federal Register of Legislation as C2024A00128, received Royal Assent on 10 December 2024. It is a single Act, but it does not switch on all at once. Different schedules within it commence on different dates set by the Act itself, so a reform introduced by this Act can already be in force while another reform in the very same Act is still months or years away from taking effect. Treating the Act as a single event with one effective date is the most common source of error when describing these reforms, and this article is organised specifically to avoid that.
The Doxxing Offences: In Force Since 11 December 2024
Schedule 3 of the Act inserted two new offences into the Criminal Code Act 1995 (Cth): section 474.17C, a base offence, and section 474.17D, an aggravated offence. Both commenced on 11 December 2024, the day after Royal Assent. In general terms, section 474.17C targets using a carriage service to make available, publish or otherwise distribute another person's personal information in a way that reasonable persons would regard as menacing or harassing, carrying a maximum penalty of 6 years' imprisonment. Section 474.17D is the aggravated version, applying where the conduct was motivated by the victim's or a targeted group's race, religion, sex, sexual orientation, gender identity, intersex status, disability, nationality, or national or ethnic origin, carrying a maximum penalty of 7 years' imprisonment. These are criminal offences prosecuted under the Criminal Code, separate from any civil action or OAIC complaint; the Attorney-General's Department's public consultation on doxxing and privacy reform, which preceded the Act, also notes that the same doxxing conduct can separately amount to a breach of the Australian Privacy Principles where the entity involved is covered by the Privacy Act. Recordinglaw.com's guide to Australia's doxxing laws covers these offences in more depth.

The Statutory Tort for Serious Invasions of Privacy: In Force Since 10 June 2025
Schedule 2 of the same Act inserted a new statutory tort for serious invasions of privacy into the Privacy Act 1988 (Cth), but this schedule commenced separately, six months after Assent, on 10 June 2025. It gives a plaintiff a cause of action against a defendant who has invaded their privacy either by intruding upon their seclusion, for example by physically intruding into a private space, or by misusing information relating to them, in circumstances where the plaintiff would have had a reasonable expectation of privacy. A plaintiff must also show the invasion was serious, that it was intentional or reckless, and that the public interest in protecting their privacy outweighed any countervailing public interest. Defences include consent and lawful authority, and exemptions apply to bodies including intelligence agencies, law enforcement bodies and, in certain circumstances, journalists. Proceedings generally must start within the earlier of 1 year after the plaintiff became aware of the invasion or 3 years after it occurred, or before the plaintiff's 21st birthday if they were under 18 when it happened. Remedies a court can grant include damages, an injunction, or an order for an apology. The OAIC has stated plainly that it does not have a direct role in administering the tort, since it is a court action, not a regulatory complaint. The tort is not merely theoretical: in Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396, the New South Wales District Court granted urgent interlocutory injunctions in October 2025 after a defendant published a plaintiff's private wedding photographs online during an extortion campaign, finding serious questions to be tried under the statutory tort alongside intimidation and defamation claims. That decision is interlocutory relief, not a final judgment on liability or damages, but it shows the tort operating in a real case within months of commencing. Recordinglaw.com's guide to the statutory tort covers its elements in more depth.
What Has Not Changed: the Small Business and Employee Records Exemptions
Two long-standing exemptions in the Privacy Act 1988 (Cth) are frequently discussed as reform candidates, but neither has actually been removed. Section 6D exempts a business with annual turnover of $3,000,000 or less from most Australian Privacy Principle obligations as a "small business operator," subject to specific carve-outs, for example for health service providers. Section 7B(3) exempts a private-sector employer's acts and practices directly related to a current or former employment relationship and to an employee record it holds, covered in more detail in recordinglaw.com's guide to employee records and privacy in Australia. Both exemptions remain in force as at July 2026. The government has said it supports removing or narrowing them in principle as part of a further tranche of reform, but no Bill addressing either exemption has passed, and no commencement date has been set for any such change.
Automated Decision-Making Transparency: Enacted, Not Yet in Force
The 2024 Act also inserted a new automated decision-making (ADM) transparency obligation into Australian Privacy Principle 1, but gave it its own future commencement date rather than switching it on immediately. From 10 December 2026, an APP entity that has arranged for a computer program to use personal information to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests will need to include specified information in its privacy policy about the kinds of personal information used and the kinds of decisions made this way. This obligation is enacted law, unlike the small business and employee records proposals above, but it is not yet in force. As at July 2026, the OAIC was still developing guidance on the new obligation, having run a public consultation on an issues paper that closed for submissions in mid-June 2026, with guidance expected before the December 2026 commencement date. Do not describe this obligation as currently binding; it becomes binding on 10 December 2026.

The Children's Online Privacy Code: Still Being Developed
The same Act requires the OAIC to develop and register a Children's Online Privacy Code, a mandatory code that will apply to social media services, relevant electronic services and designated internet services (as those terms are defined under the Online Safety Act 2021 (Cth)) that are likely to be accessed by children or primarily concern children's activities, other than health service providers. The Act sets a deadline for this: the final Code must be registered by 10 December 2026. As at mid-2026, the OAIC had released an Exposure Draft and Explanatory Statement for public consultation, running from 31 March to 5 June 2026, following earlier phases of engagement with children, parents, civil society, academia and industry through 2025. The registration deadline is fixed, but the Code's own commencement date and any transition period are not yet settled; the OAIC has been separately seeking feedback on what an appropriate commencement date should be. Once registered and in force, a breach of the Code will be treated as an interference with privacy under the Privacy Act, carrying the same regulatory and penalty framework as other privacy breaches. Until it commences, it imposes no obligations.
What's Proposed but Not Law: the Wider Second-Tranche Reform
Beyond the small business and employee records exemptions, the government has flagged a broader second tranche of Privacy Act reform building on the changes already described in this article, covering areas such as further individual rights and additional uplift measures. As at July 2026, this further reform remains at the policy and consultation stage. No second-tranche Bill had been introduced or passed, and no fixed commencement date existed for any of it. Anything described in commentary as part of a future tranche should be treated as a proposal under active discussion, not as current law, until an actual Bill passes Parliament and a commencement date is fixed.
Quick Timeline
| Date | What happened | Status as at July 2026 |
|---|---|---|
| 10 December 2024 | Privacy and Other Legislation Amendment Act 2024 (Cth) receives Royal Assent | Done |
| 11 December 2024 | Doxxing offences (Criminal Code ss 474.17C, 474.17D) commence | In force |
| 10 June 2025 | Statutory tort for serious invasions of privacy commences (Privacy Act sch 2) | In force |
| 7 October 2025 | First published application of the statutory tort, Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396 (interlocutory injunctions) | Decided (interlocutory) |
| 31 March to 5 June 2026 | Public consultation on the Children's Online Privacy Code Exposure Draft | Consultation closed; Code not yet registered |
| Closed 15 June 2026 | OAIC consultation on guidance for the automated decision-making transparency obligation | Guidance in development |
| 10 December 2026 | Automated decision-making transparency obligation (APP 1.7) commences; deadline for the OAIC to register the Children's Online Privacy Code | Not yet in force |
| Not fixed | Removal of the small business operator exemption (s 6D) | Proposed only, no Bill passed |
| Not fixed | Reform of the employee records exemption (s 7B(3)) | Proposed only, no Bill passed |

This article provides general legal information about reforms to the Privacy Act 1988 (Cth) and related Commonwealth legislation under the Privacy and Other Legislation Amendment Act 2024 (Cth), current as at 19 July 2026. It is not legal advice and does not account for your individual circumstances. For advice about a specific privacy matter, consult a legal practitioner admitted in the relevant Australian state or territory.
Frequently Asked Questions
Did doxxing and the privacy tort become law on the same date?
No. Both came from the same amending Act, but the doxxing offences commenced 11 December 2024, while the statutory tort for serious invasions of privacy commenced separately on 10 June 2025, six months later.
Is the small business exemption gone?
No. The $3 million annual turnover small business operator exemption at section 6D of the Privacy Act 1988 (Cth) remains fully in force as at July 2026. Removing it is a proposed further reform that has not been enacted.
Is the employee records exemption gone?
No. Section 7B(3) remains in force. Reforming or removing it has been raised as part of a further tranche of reform, but no Bill has passed as at July 2026.
Is the automated decision-making transparency rule already in effect?
No. It was enacted by the 2024 Act but only commences on 10 December 2026. Until that date it does not bind an APP entity's privacy policy.
What is the Children's Online Privacy Code and is it in force?
It is a mandatory OAIC code for social media, messaging and similar services likely to be accessed by children. The OAIC must register it by 10 December 2026, but as at mid-2026 it was still in public consultation and its commencement date and transition period had not been fixed.
Can the OAIC help me bring a claim under the statutory tort?
No. The OAIC has stated it does not have a direct role in administering the tort, since it is a civil court action rather than a regulatory complaint. Someone considering the tort should seek independent legal advice.
Has the statutory tort actually been used in a real case?
Yes. In Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396, decided 7 October 2025, the NSW District Court granted urgent interlocutory injunctions after private wedding photographs were published online during an extortion campaign. That decision is interlocutory relief, not a final ruling on liability or damages.
What is the maximum penalty for a doxxing offence?
The base offence at Criminal Code section 474.17C carries a maximum penalty of 6 years' imprisonment; the aggravated offence at section 474.17D, where the conduct was motivated by characteristics such as race, religion or sexual orientation, carries a maximum of 7 years.
Is there a further round of Privacy Act reform coming?
The government has indicated it supports further reform in principle, including to the small business and employee records exemptions, but as at July 2026 no further Bill has been introduced or passed and no commencement date has been fixed for any of it.
Sources and References
- OAIC, Statutory tort for serious invasions of privacy(oaic.gov.au).gov
- Privacy and Other Legislation Amendment Act 2024 (Cth) No. 128, 2024, Federal Register of Legislation version history (Royal Assent 10 December 2024)(legislation.gov.au).gov
- Attorney-General's Department, Doxxing and privacy reforms consultation(consultations.ag.gov.au).gov
- Privacy Act 1988 (Cth) s 6D, small business and small business operators ($3,000,000 annual turnover threshold)(austlii.edu.au)
- OAIC, Employee records exemption(oaic.gov.au).gov
- OAIC, Consultation on Guidance for Transparency in Automated Decision Making (ADM obligation commencing 10 December 2026)(oaic.gov.au).gov
- OAIC, Children's Online Privacy Code(oaic.gov.au).gov
- NSW Crown Solicitor's Office, Key legal decision: Australia's first privacy tort judgment (Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396)(cso.nsw.gov.au).gov