What is the Privacy Act?

Claudia AinsleyWritten byClaudia Ainsley
Reviewed byMatt Leeburn
Updated 26 Aug 2026

The Privacy Act 1988 is the Australian law that sets out how government agencies and many organisations must collect, use, disclose and correct personal information, including credit reporting data.

Also known as: Privacy Act 1988, Commonwealth Privacy Act

Key points

  • The Act's backbone is the 13 Australian Privacy Principles (APPs), covering collection, notice, use, direct marketing, security, access and correction.
  • It applies to government agencies and to organisations above an annual turnover threshold, plus smaller ones handling credit reporting, health or other sensitive information.
  • The Notifiable Data Breaches scheme requires organisations to assess breaches and notify the OAIC and affected people when serious harm is likely.
  • Lenders and brokers handle identity documents, bank statements and credit files, so the Act sets duties on every application they touch.

Who the Privacy Act applies to

The Australian Privacy Principles

Data breaches and enforcement

Example

Not to be confused with

Data protection
data protection is the broader practice of securing information; the Privacy Act is the specific law that sets Australian obligations
OAIC
the OAIC is the regulator that enforces the Privacy Act, not the law itself
Comprehensive credit reporting (CCR)
CCR is the credit data-sharing regime that operates under the Privacy Act's credit reporting provisions

Frequently asked questions

Does the Privacy Act apply to small businesses?

Possibly. Most small businesses under the annual turnover threshold are exempt, but the exemption falls away if the business handles health information, engages in credit reporting or meets other specified criteria. Check your turnover, the kinds of data you hold and whether you collect information from the public; the OAIC publishes detailed coverage guidance.

What are the Australian Privacy Principles?

The APPs are the 13 principles at the heart of the Privacy Act. They cover open management and privacy policies, anonymity, collecting and notifying, use and disclosure, direct marketing, cross-border disclosure, government identifiers, data quality, security, and an individual's right to access and correct their information. Each one sets a specific obligation for regulated entities.

When do I have to notify the OAIC about a data breach?

When the breach is an eligible data breach: personal information has been accessed, disclosed or lost without authorisation, and a reasonable person would conclude it is likely to cause serious harm to someone. If you suspect one, finish the assessment within 30 days of becoming aware, then notify the OAIC and the affected individuals as soon as practicable, keeping records of your assessment and response.

How do I make a privacy complaint?

Raise it with the organisation first and give them a chance to fix it. If that does not resolve the issue, lodge a complaint with the OAIC, which can investigate and make determinations requiring correction, deletion or other remedial steps. The OAIC website sets out the steps and timelines.

Can a business send my personal information overseas?

Yes, but under APP 8 it must first take reasonable steps to make sure the overseas recipient will handle the information in line with the APPs, typically through contract clauses and due diligence checks. Those steps should be documented, often in a privacy impact assessment, so the business can show what it did.

Go deeper

Sources

This article is general information only and is not financial advice.