Privacy Ready
Penalties · Privacy Act 1988

Privacy Act Penalties: What Happens If My Business Breaches It?

The exact penalty figures, who can enforce them, and the free tools to check your exposure before a breach happens.

Serious or repeated breaches of the Privacy Act 1988 (Cth) carry civil penalties of up to $50 million, 3 times the benefit obtained, or 30% of adjusted turnover during the breach period — whichever is greatest. Non-serious contraventions carry penalties of up to $66,000 per contravention. A statutory tort for serious invasions of privacy commenced June 2025, and an OAIC enforcement sweep of ~60 entities across 6 sectors commenced January 2026.

Last updated: 2 July 2026

Penalty reference table

Contravention type Maximum penalty
Serious or repeated interference with privacy $50 million, 3× benefit obtained, or 30% of adjusted turnover — whichever is greatest
Non-serious contravention Up to $66,000 per contravention
Statutory tort for serious invasions of privacy Damages awarded directly to the individual, in force since June 2025
OAIC enforcement sweep, 2026 ~60 entities across 6 sectors, commenced January 2026

What actually triggers enforcement

Most OAIC action doesn't start with a raid — it starts with a complaint from an individual, a notifiable data breach report, or a proactive sweep like the one that began in January 2026. The businesses most exposed are the ones that can't produce a compliant privacy policy, can't show a documented security safeguard under APP 11, or missed the 30-day deadline on an access or correction request.

The 1 July 2026 removal of the small business exemption brings roughly 100,000 additional Australian businesses into scope at the same time enforcement activity is increasing — meaning the penalty exposure described above now applies to businesses that were never regulated before.

Free diagnostic tools

Relevant free tools

Related Privacy Act questions

When penalty exposure is worth checking

  • You've never confirmed whether your business is covered by the Privacy Act
  • You don't have a documented process for handling a data breach
  • Your security safeguards haven't been reviewed against APP 11
  • You're newly covered from 1 July 2026 and haven't assessed your obligations yet
  • Your industry or sector is one the OAIC's 2026 enforcement sweep is targeting

Frequently asked questions

What happens if my business breaches the Privacy Act?

Serious or repeated interferences with privacy carry civil penalties of up to $50 million, 3 times the benefit obtained from the breach, or 30% of adjusted turnover during the breach period — whichever is greatest. Non-serious contraventions carry penalties of up to $66,000 per contravention for a body corporate.

Can individuals sue a business for a privacy breach?

Yes. A statutory tort for serious invasions of privacy commenced in June 2025, allowing individuals to sue directly for damages without needing the OAIC to act first. This sits alongside, not instead of, OAIC enforcement action.

Is the OAIC actively enforcing against small businesses?

Yes. An OAIC enforcement sweep commenced in January 2026, covering approximately 60 entities across 6 sectors. This coincides with the 1 July 2026 removal of the small business exemption, which brings roughly 100,000 additional Australian businesses into scope.

What counts as a serious breach?

A serious interference with privacy typically involves sensitive information, a large number of affected individuals, repeated conduct, or a failure to act on a known risk. The OAIC assesses seriousness based on the sensitivity of the data, the harm caused, and whether the entity had reasonable safeguards in place under APP 11.

Run the free business applicability check to find out exactly which obligations — and which penalties — apply to your business.

Get my coverage verdict →