AUSTRALIA HUBPrivacy

OAIC

Office of the Australian Information Commissioner

Privacy Act 1988 · 13 APPs · NDB scheme

Who it applies to

Australian Government agencies and private organisations with turnover above $3m (plus exceptions).

Key instruments

  • 0113 Australian Privacy Principles — collection through to security & access
  • 02Notifiable Data Breaches — assess within 30 days, notify without delay
  • 03APP 11 security of personal information — reasonable steps
  • 04Privacy Act Review — statutory tort, fair-and-reasonable test incoming

Compliance calendar

  • NDB assessment — 30 days from suspicion
  • Notification to OAIC + individuals — as soon as practicable

Penalty framework

Greater of $50m, 3× benefit obtained, or 30% of adjusted turnover for serious interference with privacy.

Need the full control catalogue?

Templates, applicability matrices and board-paper skeletons for OAIC.

Talk to us