Australia's privacy law just changed. The data you hold is in scope
If you caught any news about Australia’s privacy law changing at the end of 2024, it was probably about doxxing. The Privacy and Other Legislation Amendment Act 2024 made the malicious release of someone’s personal details a criminal offence, with serious jail time attached, and that’s the part that got the headlines.
The headline isn’t the part most businesses should care about, though. Underneath it sits a broader shift that affects anyone who holds personal information about customers, clients or staff, which is to say nearly everyone. It’s the first instalment of a bigger overhaul, and the direction is clear: more obligations, stronger enforcement, and less tolerance for holding people’s data carelessly.
Here’s what changed, in plain terms, and what it means for a normal business.
A new right to sue over privacy
The Act introduced a statutory tort for serious invasions of privacy, which commenced in June 2025. In plain English, individuals can now take legal action when their privacy is seriously invaded, whether by someone intruding on them or by misusing their information. Australia spent years without a clear right like this. Now it has one.
For a business, the takeaway isn’t that you’re about to be sued. It’s that mishandling someone’s personal information now carries a sharper legal edge than it used to, on top of the regulator’s own powers, which the same reforms strengthened.
Disclosure coming for automated decisions
There’s a change on the horizon worth flagging now, because it has a long lead time. From December 2026, businesses that use computer programs to make decisions that significantly affect people will have to say so in their privacy policy. If software, including AI tools, plays a substantial part in a decision about someone’s rights or interests, that has to be disclosed.
If you’re starting to use automated or AI tools in how you deal with customers, this is the moment to keep track of where they sit in your decisions, so the disclosure is straightforward when it’s due rather than a scramble.
Why this matters more if you’re a law firm
Every business holds some personal information. A law firm holds an extraordinary amount of it, and the most sensitive kind: financial details, family matters, health, disputes, the lot. That makes a firm both a bigger target and a bigger liability if the data isn’t looked after. The reforms raise the stakes on exactly the kind of information a practice lives on.
None of this is legal advice on your specific obligations. The point is simpler: the law now expects more of anyone holding personal data, and it’s worth getting ahead of rather than reacting to.
What to actually do about it
The good news is that meeting the spirit of these changes is mostly good practice you’d want anyway:
- Know what you hold and why. You can’t protect or justify data you’ve forgotten you have. Map out what personal information you keep and the reason for it.
- Don’t keep what you don’t need. The safest data is the data you never collected or have properly deleted. Less held means less to lose and less to answer for.
- Secure it properly. The obligation to protect personal information has real teeth now. The fundamentals (access control, multi-factor authentication, encryption, tested backups) are how you meet it.
- Get your privacy policy current, and start tracking any automated or AI-assisted decisions ahead of the 2026 disclosure rules.
- Have a breach plan. If personal information is exposed, the Notifiable Data Breaches scheme already sets out what you must do. Knowing the steps in advance turns a panic into a procedure.
The takeaway
The doxxing headlines will fade. The shift underneath them won’t. Holding people’s personal information is now more of a responsibility, and more of a risk, than it was a year ago. The businesses that handle this well aren’t the ones with the most lawyers. They’re the ones who know what data they hold and actually protect it. That’s a manageable goal, and a good one to aim at whatever the law does next.
Hold a lot of personal information?
Book a free, no-obligation security review. We'll look at how the personal data you hold is protected, so a privacy duty doesn't become a privacy problem.