AUSTRALIA HUBPrivacy
OAIC
Office of the Australian Information Commissioner
Privacy Act 1988 · 13 APPs · NDB scheme
Who it applies to
Australian Government agencies and private organisations with turnover above $3m (plus exceptions).
Key instruments
- 0113 Australian Privacy Principles — collection through to security & access
- 02Notifiable Data Breaches — assess within 30 days, notify without delay
- 03APP 11 security of personal information — reasonable steps
- 04Privacy Act Review — statutory tort, fair-and-reasonable test incoming
Compliance calendar
- NDB assessment — 30 days from suspicion
- Notification to OAIC + individuals — as soon as practicable
Penalty framework
Greater of $50m, 3× benefit obtained, or 30% of adjusted turnover for serious interference with privacy.
Need the full control catalogue?
Templates, applicability matrices and board-paper skeletons for OAIC.