The first tranche of Privacy Act reform introduced a statutory tort for serious invasions of privacy. Risk teams should stop treating privacy as a compliance checklist and start modelling it as class-action exposure.
The Privacy and Other Legislation Amendment Act 2024 delivered the first tranche of reform — including a statutory tort for serious invasions of privacy that commenced in June 2025.
For risk managers, the shift is from regulator-only exposure to plaintiff-driven exposure. Serious invasions — intrusion upon seclusion or misuse of information — can now ground direct claims without proving actual damage in the traditional sense.
Practical moves: refresh privacy impact assessments for high-volume data products, quantify class-action scenarios in the operational risk model, and align NDB response playbooks with litigation-hold discipline.
The second tranche — a fair-and-reasonable test and erosion of the small business exemption — remains on the horizon. Entities that build to the incoming state rather than the current floor will spend less twice.
Disclaimer
General information only — not legal, financial or professional advice. Verify obligations against the current instruments and your entity's circumstances.