Skip to main content
Privacy Act 1988 · APP 11 · Notifiable Data Breaches

Protect Australian customer data before the regulator asks how.

Australia has tougher privacy penalties, a right to sue for serious invasions and new transparency duties arriving in December 2026. Show the OAIC and your customers that personal information is protected in practice.

Human-led VAPT · NDA first · report in 48h

13
Australian Privacy Principles, with APP 11 covering security of personal information
30 days
the time allowed to assess a suspected eligible data breach
A$50M
or more, the maximum penalty tier for serious or repeated interference with privacy
10 Dec 2026
date automated decision transparency requirements are due to apply
Board and leadership view

Why the Australian Privacy Act matters to your board

The work is technical. The consequences of getting Australia Privacy Act wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Customer and contract access

Australian enterprise and government buyers ask suppliers how personal information is protected. Weak answers slow deals and renewals.

Penalties and litigation

Top penalties reach A$50M, three times benefit or 30% of adjusted turnover. Individuals can also sue for serious invasions of privacy.

Trust after a breach

Notification goes to the regulator and to customers. How quickly and clearly you explain what happened shapes how they judge you.

Deadlines and ownership

Automated decision transparency is due 10 December 2026 and the children’s code is in development. Board-level ownership of privacy and security should be clear.

Fit

Who the Act affects

Businesses over A$3M turnover

Most larger private organisations are covered, along with government agencies.

Health and childcare providers

They are covered regardless of size and hold especially sensitive information.

Overseas companies serving Australians

The Act can apply to foreign entities that carry on business in Australia and collect data there.

Financial and retail brands

High volumes of customer data make them frequent targets and frequent subjects of breach notices.

Scope of work

What Summit delivers for Australia Privacy Act

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

We compare your safeguards with APP 11 and OAIC guidance and rank gaps by the risk to personal information.

Penetration testing

Human-led testing of the applications, APIs, cloud and networks that hold or process personal information.

Control validation

We check that access, encryption, logging and retention controls work as documented.

Evidence pack

Scope, methods, findings and results organised for regulators, insurers and customers who ask.

Remediation support and retest

Practical fix guidance for your engineers and a retest to confirm each finding is closed.

Board-ready report

A clear summary of exposure, progress and decisions for directors and executives.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A practical Privacy Act readiness path

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Map personal information

    Weeks 1 to 3

    List the data you hold, where it sits, who can reach it and which suppliers process it.

  2. 2

    Assess gaps

    Weeks 3 to 6

    Compare your safeguards with APP 11 expectations and the OAIC’s guidance on reasonable steps.

  3. 3

    Test your defences

    Months 2 to 4

    Run penetration testing of systems that hold personal information and validate key controls.

  4. 4

    Prepare for breach

    Months 3 to 6

    Test your breach assessment and notification process with a tabletop exercise.

  5. 5

    Update transparency and retest

    Before 10 Dec 2026

    Close findings and retest, review automated decision use and update privacy policy wording and records.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • Where is our personal information?

    Ask for a current inventory including suppliers and overseas locations.

  • What are the reasonable steps we can show?

    Ask for dated test results and fixes, not just policies.

  • Could we assess a breach in 30 days?

    Ask when the breach process was last rehearsed and who decides.

  • Do we use automated decisions about people?

    Ask for the list before 10 December 2026.

  • Who is accountable to the board?

    Confirm a named executive owns privacy and security reporting.

The detail

What the Australian Privacy Act actually is

The Privacy Act 1988 regulates how Australian Government agencies and many private organisations handle personal information. Its core is the 13 Australian Privacy Principles (APPs). Most businesses with annual turnover above A$3 million are covered, and some smaller ones are too, such as health providers and businesses that trade in personal information. It can also reach overseas organisations that carry on business in Australia.

APP 11 requires you to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, and to destroy or de-identify it when no longer needed. The 2024 reforms made clear that reasonable steps include both technical and organisational measures. The Notifiable Data Breaches (NDB) scheme then requires notification to the OAIC and affected people when a breach is likely to cause serious harm.

The Privacy and Other Legislation Amendment Act 2024 added a statutory tort for serious invasions of privacy, new enforcement tools and penalty tiers, and a Children’s Online Privacy Code. Automated decision transparency rules are scheduled for December 2026. Further reform stages are still being discussed, so treat dates and detail as something to confirm before relying on them.

Key terms in plain English

Personal information
Information or an opinion about an identified or reasonably identifiable person.
Eligible data breach
Unauthorised access or disclosure likely to cause serious harm, which triggers notification.
OAIC
The Office of the Australian Information Commissioner, the privacy regulator.
Statutory tort
A right for individuals to sue for serious invasions of privacy, in force since June 2025.
Requirements

The parts of the Act that shape security work

Not every principle is about security, but several decide what regulators ask after an incident. These are the ones that matter most to boards and security teams.

1

APP 11: security of personal information

Take reasonable steps to protect personal information and to destroy or de-identify it when no longer needed. The OAIC’s guidance expects steps that fit the sensitivity and volume of the data, covering governance, access, systems, testing and supplier controls.

What it looks like in practice

  • A data inventory and retention rules
  • Access control, encryption and logging
  • Regular testing and remediation of weaknesses
2

Notifiable Data Breaches scheme

If you suspect an eligible breach, complete an assessment within 30 days. If it is confirmed, notify the OAIC and affected individuals as soon as practicable. Your ability to answer what happened rests on logs and tested response plans.

What it looks like in practice

  • A breach response plan with roles
  • Decision criteria for serious harm
  • Forensic readiness and log retention
3

Overseas disclosure and supplier control

APP 8 makes you accountable in many cases when you send personal information overseas, such as to a cloud provider. The reforms also add a mechanism to recognise countries with comparable protections.

What it looks like in practice

  • A list of suppliers and data locations
  • Contracts with security obligations
  • Assurance evidence from key suppliers
4

Automated decisions and privacy policies

Organisations that use automated decision-making that significantly affects individuals’ rights or interests must describe it in their privacy policy. The requirement is due to start on 10 December 2026. The OAIC can now issue infringement notices for some policy failures.

What it looks like in practice

  • A register of automated decisions that affect people
  • Updated, accurate privacy policy wording
  • Review of how decisions are explained
5

Children’s code and the statutory tort

The OAIC is developing a Children’s Online Privacy Code for services likely to be accessed by children. Separately, individuals have been able to sue for serious invasions of privacy since June 2025, which adds litigation risk after a breach.

What it looks like in practice

  • Age-appropriate design review where relevant
  • Monitoring of the code’s final text and start date
  • Legal review of intrusion and misuse scenarios
Where testing fits

How penetration testing supports Australia Privacy Act

The Act does not name penetration testing, but APP 11 asks for reasonable steps. After a breach, regulators and courts look for proof that you tested and fixed known weaknesses.

APP 11.1

Reasonable steps

Testing evidence shows you looked for weaknesses in systems holding personal information and acted on them.

NDB scheme

Knowing what was exposed

Prior testing and clear system documentation make breach assessment faster and more accurate.

APP 8

Supplier risk

Test results and retest letters help show that the systems you rely on, or hand data to, were checked.

Governance

Board assurance

Reports translate technical results into a record that directors have asked the right questions.

Avoid these

Common Australia Privacy Act mistakes, and how to avoid them

!

Treating the A$3M threshold as a safe harbour

Health providers, data traders and others are covered at any size, and customers will ask regardless.

!

Keeping data forever

APP 11 includes destruction and de-identification. Old data is old risk.

!

No tested breach process

A 30 day assessment window is short when no one knows who decides.

!

Ignoring December 2026

Automated decision wording and records take time to compile across business units.

FAQ

Australia Privacy Act questions, answered

Does the Privacy Act apply to my business?

Probably, if you have annual turnover above A$3 million, handle health information, trade in personal information or are a government agency. It can also apply to overseas entities carrying on business in Australia.

What does APP 11 require?

Reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, and to destroy or de-identify it when it is no longer needed. Reasonable steps include technical and organisational measures.

When must I notify a data breach?

If you suspect an eligible breach, assess it within 30 days. If likely to cause serious harm, notify the OAIC and affected individuals as soon as practicable.

What changed in the 2024 reforms?

A statutory tort for serious invasions of privacy, new penalty tiers and infringement notices, a Children’s Online Privacy Code, a mechanism for comparable overseas privacy regimes, and automated decision transparency duties.

What are the penalties?

For serious or repeated interference with privacy, the maximum is the greater of A$50M, three times the benefit obtained or 30% of adjusted turnover. Lower tiers and infringement notices apply to less serious failures.

When do the automated decision rules start?

They are due to apply from 10 December 2026. Check the latest OAIC guidance as that date approaches.

Is this legal advice?

No. It is general education. Confirm obligations with qualified Australian counsel.

Ready to get Australia Privacy Act sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →