Privacy Act Penalties: What Happens If My Business Breaches It?
The exact penalty figures, who can enforce them, and the free tools to check your exposure before a breach happens.
Serious or repeated breaches of the Privacy Act 1988 (Cth) carry civil penalties of up to $50 million, 3 times the benefit obtained, or 30% of adjusted turnover during the breach period — whichever is greatest. Non-serious contraventions carry penalties of up to $66,000 per contravention. A statutory tort for serious invasions of privacy commenced June 2025, and an OAIC enforcement sweep of ~60 entities across 6 sectors commenced January 2026.
Last updated: 2 July 2026
Penalty reference table
| Contravention type | Maximum penalty |
|---|---|
| Serious or repeated interference with privacy | $50 million, 3× benefit obtained, or 30% of adjusted turnover — whichever is greatest |
| Non-serious contravention | Up to $66,000 per contravention |
| Statutory tort for serious invasions of privacy | Damages awarded directly to the individual, in force since June 2025 |
| OAIC enforcement sweep, 2026 | ~60 entities across 6 sectors, commenced January 2026 |
What actually triggers enforcement
Most OAIC action doesn't start with a raid — it starts with a complaint from an individual, a notifiable data breach report, or a proactive sweep like the one that began in January 2026. The businesses most exposed are the ones that can't produce a compliant privacy policy, can't show a documented security safeguard under APP 11, or missed the 30-day deadline on an access or correction request.
The 1 July 2026 removal of the small business exemption brings roughly 100,000 additional Australian businesses into scope at the same time enforcement activity is increasing — meaning the penalty exposure described above now applies to businesses that were never regulated before.
Relevant free tools
Related Privacy Act questions
When penalty exposure is worth checking
- — You've never confirmed whether your business is covered by the Privacy Act
- — You don't have a documented process for handling a data breach
- — Your security safeguards haven't been reviewed against APP 11
- — You're newly covered from 1 July 2026 and haven't assessed your obligations yet
- — Your industry or sector is one the OAIC's 2026 enforcement sweep is targeting
Frequently asked questions
What happens if my business breaches the Privacy Act?
Serious or repeated interferences with privacy carry civil penalties of up to $50 million, 3 times the benefit obtained from the breach, or 30% of adjusted turnover during the breach period — whichever is greatest. Non-serious contraventions carry penalties of up to $66,000 per contravention for a body corporate.
Can individuals sue a business for a privacy breach?
Yes. A statutory tort for serious invasions of privacy commenced in June 2025, allowing individuals to sue directly for damages without needing the OAIC to act first. This sits alongside, not instead of, OAIC enforcement action.
Is the OAIC actively enforcing against small businesses?
Yes. An OAIC enforcement sweep commenced in January 2026, covering approximately 60 entities across 6 sectors. This coincides with the 1 July 2026 removal of the small business exemption, which brings roughly 100,000 additional Australian businesses into scope.
What counts as a serious breach?
A serious interference with privacy typically involves sensitive information, a large number of affected individuals, repeated conduct, or a failure to act on a known risk. The OAIC assesses seriousness based on the sensitivity of the data, the harm caused, and whether the entity had reasonable safeguards in place under APP 11.
Run the free business applicability check to find out exactly which obligations — and which penalties — apply to your business.
Get my coverage verdict →