Zavior
For Schools

What changed in Australia's Privacy Act reforms, and what's coming?

Australia's first privacy reform tranche is live: a statutory tort, doxxing offences, and duties landing by December 2026. Tranche two is still ahead.

By Glenn Tan · CEO at Zavior.ai

6 min readNews
What changed in Australia's Privacy Act reforms, and what's coming?

The Privacy and Other Legislation Amendment Act 2024 delivered the first reform tranche: a statutory tort for serious invasions of privacy (actionable from June 2025), criminal doxxing offences, a Children's Online Privacy Code due to take effect from 10 December 2026, and automated-decision transparency requirements from the same date. A second tranche, including the small-business exemption, is still ahead.

What is the new privacy tort?

Since 10 June 2025, individuals can sue directly for a serious invasion of privacy. That is new in a structural way. Australian privacy law previously ran almost entirely through the regulator; an aggrieved individual complained to the OAIC and waited. The tort opens a second front. A plaintiff no longer needs the regulator's attention or its timetable, and the defendant no longer gets to treat privacy exposure as a single-regulator problem.

The word doing the work is "serious". The tort was built with a threshold and with defences, and that boundary is where the early case law will be made. It requires an invasion of privacy through intrusion upon seclusion or misuse of information, weighed against a seriousness threshold, with defences covering lawful authority, consent, necessity and privileged reporting of matters of public concern.

For businesses the planning consequence is simple. Every practice that would embarrass you in front of the regulator can now also put you in front of a judge, with a named plaintiff and discovery. Direct causes of action also change how liability gets priced. Privacy exposure that once ended at a regulator's determination now includes damages and legal costs, which is exactly the kind of change that starts appearing in insurance renewal questionnaires.

The complaint queue is no longer the only door.

What are the ADM transparency rules?

From 10 December 2026, privacy policies must disclose the use of automated decision-making that involves personal information. This is a transparency duty, so what it demands is honesty in your privacy policy rather than a ban on automation. As this page is updated, that deadline is about five months away.

The hard part is not the drafting. It is finding every automated decision you actually make. Credit scoring is obvious; the CV-screening feature your recruitment platform switched on last year is not, and neither is the fraud filter inside your payment provider's dashboard. The disclosure obligation quietly forces an inventory, because you cannot honestly describe automation you have not found.

Two questions sort most tools quickly. Does it use personal information, and does its output decide or materially shape something about a person? A demand-forecasting model fails the first test and drops out of scope; a tenant-screening score passes both and belongs in your policy.

Start the inventory before the policy rewrite. Every organisation we have watched attempt the reverse order has had to do the inventory anyway, later and faster.

What's in the Children's Online Privacy Code?

The OAIC is developing a Children's Online Privacy Code aimed at online services likely to be accessed by children. Note the phrasing. "Likely to be accessed by children" is a much wider net than "designed for children". A general social app and a game with no age gate are both plausibly inside, whatever their terms of service claim about minimum ages.

The code is still in development, so the binding detail is not settled. The OAIC consulted on its Exposure Draft from 31 March to 5 June 2026 and the Code is due to take effect on 10 December 2026, the same date as the ADM transparency deadline. If children can plausibly reach your service, the cheap move now is to follow the OAIC's consultation and check how your age assumptions would survive scrutiny. What codes of this kind tend to fix is defaults. If your onboarding assumes every user is an adult because the sign-up form said so, that assumption is the one to stress-test while changing it is still a product decision rather than a compliance deadline.

What should you prepare for tranche two?

Two items on the table dwarf the rest: a right to erasure, and the small-business exemption. Neither has a committed date, and both would change who is regulated and what they owe. An erasure right would force organisations to be able to find and delete an individual's data on request, which is an engineering capability, not a policy paragraph. Narrowing the small-business exemption would bring businesses under A$3 million turnover into the Act for the first time.

Prepare on substance, not on dates. Deletion capability takes longest to build, so it is the one to start while tranche two remains a discussion paper. Reform programmes are slow until they are sudden. Tranche one is the evidence: it arrived with commencement dates already attached, and it left months rather than years between passage and the tort becoming actionable. Businesses that waited for certainty got certainty and no runway.

The timeline so far, with what is ahead. This page is a living document; we update it as instruments commence.

DateChangeStatus
2024Privacy and Other Legislation Amendment Act 2024 passed; criminal doxxing offences createdLaw
10 June 2025Statutory tort for serious invasions of privacy becomes actionableIn force
10 December 2026Children's Online Privacy Code, developed by the OAIC (Exposure Draft consulted 31 Mar to 5 Jun 2026)Due to take effect
10 December 2026Automated-decision transparency required in privacy policiesDeadline ahead
Not scheduledTranche two, including a possible erasure right and changes to the small-business exemptionAwaiting legislation

The gaps between rows are the message. Each change so far has landed with a fixed date and a short runway, and there is no reason to expect tranche two to behave differently.

Zavior clients hold each commencement date as a register deadline with an owner attached, so 10 December 2026 arrives as a task list rather than a surprise.

Frequently asked questions

Can individuals sue for privacy invasions now?

Yes. The statutory tort has been actionable since 10 June 2025 for serious invasions of privacy, giving individuals a direct route to court rather than only a complaint to the OAIC. The seriousness threshold means not every grievance will qualify.

Does ADM transparency cover AI tools?

Yes, where the tool makes automated decisions involving personal information. The requirement is about the decision-making, so a hand-coded rules engine and an AI model that decide the same thing are treated alike. Vendor-supplied AI features count even though you did not build them.

When is tranche two expected?

No date has been committed. The Attorney-General confirmed in February 2026 Senate estimates that a Tranche 2 Bill is being progressed, with no timetable announced; the erasure right and small-business exemption remain the items to watch.

This is general information, not legal advice.

Sources: Privacy and Other Legislation Amendment Act 2024; OAIC; Attorney-General's Department.

Glenn Tan

Written by

Glenn Tan

CEO at Zavior.ai

Build Trust Through Certifications | Cyber Security | AI Governance | Data Protection

Share

Let us be your Zavior.

Zavior helps Australian businesses build cyber resilience aligned to the ACSC Essential Eight, the Privacy Act, and ISO 27001.

Continue reading