Regulations

Knowledge Base | Regulations | What is Australia’s Privacy Act, and which businesses does it cover?

What is Australia’s Privacy Act, and which businesses does it cover?

Australia’s Privacy Act 1988 is the principal federal law regulating how covered organisations and Australian Government agencies handle personal information. It governs matters such as collection, use, disclosure, security and individual access rights.

The Act commenced in 1989. Its 13 Australian Privacy Principles, or APPs, took effect on 12 March 2014 and remain central to the framework, as amended.

Coverage generally includes:

  • Australian Government agencies covered by the Act.

  • Organisations with annual turnover exceeding A$3 million.

  • Certain smaller organisations, including private health service providers and some businesses that trade in personal information.

The small-business exemption has exceptions, so turnover alone does not settle whether an organisation is covered.

The OAIC’s Privacy Act overview explains the framework and links to the legislation.

For covered website operators, data minimisation, clear collection notices and appropriate security are important. Information collected through tracking technologies must be assessed against the applicable APPs.

Australia’s framework should not be treated as an identical version of EU cookie law. Australian website privacy compliance depends on the organisation, information and processing involved.