Wollongong · Sydney · Australia
Australia's Watchdog
Independent
No ads. No masters.
THE RORT · THE PRIVACY RORT · ARTICLE 1 / 2READING
CASE FILE · THE PRIVACY RORTARTICLE 1 / 2By The Rort · September 2026 · therort.com.au

One penalty

Businesses and agencies told the privacy regulator of 1,205 notifications of data breaches likely to cause serious harm in 2025, the most since reporting became compulsory. The only court-ordered penalty under the Privacy Act we could fi…

Reading time8 min
Every Privacy Act penalty case we foundTHE PRIVACY RORTEvery Privacy Act penalty case we foundFOUR CASES, GROUPED BY OUTCOME, TO 24 SEPTEMBER 2026THE BREACHWHAT THE REGULATOR DIDWHERE IT STANDS, 24 SEP 2026Australian Clinical LabsBreach February 2022, 223,000+ peoplePenalty proceedings; ACL admittedthe contraventions$5.8m ordered, 8 Oct 2025, by consentMetaCambridge Analytica incidentPenalty proceedings fromMarch 2020Withdrawn 17 Dec 2024 for a$50 million payment programMedibankBreach October 2022; 9.7 million allegedPenalty proceedings filed5 June 2024No outcome foundOptusConduct to 20 Sep 2022; about9.5 million allegedPenalty proceedings filed8 Aug 2025No outcome found. Separateclass action trial from7 June 2027So far only one of four Privacy Act penalty cases we found has ended in a penalty, and it was by consent, not at trial.Only a court can impose a civil penalty.FIGURES FOR MEDIBANK AND OPTUS ARE ALLEGATIONS · MAXIMUM PENALTY $2.22M PER CONTRAVENTION, $1.7M FOR META · SOURCES: OAIC RELEASES; SLATER AND GORDONFOUR CASES, ONE PENALTYTHERORT.COM.AU
Four Privacy Act civil penalty cases this outlet could find, and how each has ended, or has not ended, up to 24 September 2026. The Medibank and Optus figures are allegations; only a court can impose a civil penalty.

In calendar year 2025 the Office of the Australian Information Commissioner received 1,205 data breach notifications, an 8 per cent increase over the 1,112 notifications received in 2024 and the most since the notifiable data breaches scheme began in 2018 1.

Set that count beside the other side of the ledger. Up to 24 September 2026, from the OAIC’s recent media releases and from searches, this outlet has found one civil penalty order a court has ever made under the Privacy Act: $5.8 million against Australian Clinical Labs, ordered by the Federal Court, by consent, on 8 October 2025 2.

This article sets those two figures side by side, then asks what explains the gap between them: who can fine at all, what caps applied to the cases here, and how each of the four Privacy Act penalty cases this outlet could find has ended, or has not ended yet.

01What the law requires

Since 2018 the Privacy Act has required businesses and Commonwealth government agencies it covers to report any data breach that is likely to result in serious harm. Notifications go to the Office of the Australian Information Commissioner, the OAIC, not to the Privacy Commissioner personally.

“Businesses and Commonwealth government agencies covered by the Privacy Act are required to report any data breach that is likely to result in serious harm”

OAIC, Notifiable Data Breaches statistics release, 6 July 2026
1,205
Notifications the OAIC received in calendar 2025, an 8 per cent rise on the 1,112 received in 2024, and the most since the scheme began in 2018.

Health service providers were the sector most often named in those notifications: 225 of them, 19 per cent of the total 1. That describes the sector of the entity that reported.

The OAIC’s release acknowledges a growing number of entities reporting under the scheme 1. This article counts notifications, not breaches.

On a different basis, the 2024-25 financial year, the OAIC separately finalised 1,155 notifications under the scheme, 86 per cent of them within 60 days, and finalised 3,123 privacy complaints 3. That count uses a different period and a different basis to the calendar year count above, and this article does not add the two together or compare them.

Elsewhere in this outlet’s reporting, THE REPORTING RORT’s ‘Nobody has to tell’ sets out whom the notification duty binds, and whom it does not.

02Who can fine

Under the Privacy Act, only a court can impose a civil penalty. The Commissioner may apply to a court for one where an entity is alleged to have engaged in serious or repeated interferences with privacy, but a determination the Commissioner makes alone cannot carry a fine 4.

Every case in this article falls under the caps that applied before 13 December 2022: $2.22 million for each contravention in the ACL, Medibank and Optus cases, and $1.7 million in the Meta case, according to the OAIC 45.

$2.22 million
The maximum civil penalty per contravention that applied to the ACL, Medibank and Optus cases in this article; the Meta case carried a $1.7 million cap. Higher maximums have applied to conduct after 13 December 2022, but none of these cases involve conduct after that date.

A new regime, in force from 13 December 2022 2, allows the Court to impose much higher penalties on conduct after that date: the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover, according to a law firm explainer 6.

A further amendment in 2024 added two more tiers: a mid-tier civil penalty for interferences with privacy that do not meet the ‘serious’ threshold, and a lower tier of OAIC-issued infringement notices for administrative breaches, without court action, according to law firm explainers 67. How many infringement notices or mid-tier proceedings have been used, if any, is not established on this record.

03The ledger

Every Privacy Act civil penalty case this outlet could find is set out in the graphic above, and below, grouped by outcome, not by the order each was filed.

The first order, and the only one we have found up to 24 September 2026, came against Australian Clinical Labs. On 8 October 2025 the Federal Court ordered ACL to pay $5.8 million in civil penalties over the Medlab Pathology data breach, which affected more than 223,000 people; ACL admitted the contraventions, consented to the orders, and the parties made joint submissions to the Court on liability and penalty 2.

$5.8 million
The civil penalty the Federal Court ordered against Australian Clinical Labs on 8 October 2025, the first, and up to 24 September 2026 the only, civil penalty order this outlet could find ever made under the Privacy Act, ordered by consent.

The $5.8 million breaks into three parts: $4.2 million for the security failure itself, under Australian Privacy Principle 11.1; $800,000 for failing to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred; and $800,000 for failing to notify the Commissioner as soon as practicable 2.

“a penalty of $800,000 for ACL’s failure to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred”

OAIC, Australian Clinical Labs release, 9 October 2025

Together the assess and notify penalties come to $1.6 million, about 28 per cent of the $5.8 million total: the notification duty itself, not only the security failure behind it, has been penalised. THE REPORTING RORT’s ‘Fourteen days’ set this same $1.6 million inside a wider ledger of reporting duties across the Commonwealth; this article puts it beside every other Privacy Act penalty case instead.

It is the only order this outlet could find, from the OAIC’s recent media releases, up to 24 September 2026. We say only that we have found no other.

04Two open, one traded

The Commissioner’s case against Meta never reached a judgment. Proceedings began in March 2020 over the Cambridge Analytica incident. After court-ordered mediation that ran from February 2024, the OAIC accepted an enforceable undertaking on 17 December 2024: a $50 million payment program for affected Australians, and the Commissioner withdrew the civil penalty proceedings 5.

$50 million
The payment program Meta agreed to in December 2024; as part of the resolution the Commissioner withdrew the civil penalty case. It is not a civil penalty; the program pays affected people.

A civil penalty is paid to the Commonwealth. Meta’s program pays affected people instead.

“Today’s settlement represents the largest ever payment dedicated to addressing concerns about the privacy of individuals in Australia”

OAIC, Meta settlement release, 17 December 2024

The resolution meant no court ruled on whether Meta breached the Privacy Act. Separately, in 2024-25 the OAIC also reached an enforceable undertaking with Oxfam Australia over a 2021 data breach 3.

The Commissioner’s case against Medibank has no outcome we have found. The Commissioner filed a civil penalty proceeding on 5 June 2024 alleging Medibank seriously interfered with the privacy of 9.7 million Australians by failing to take reasonable steps to protect their personal information, over conduct alleged between March 2021 and October 2022; the breach was in October 2022 8. Up to 24 September 2026, from OAIC releases and searches, we have found no outcome; the underlying court file has not been checked.

The Commissioner’s case against Optus has no outcome we have found yet either. The Commissioner filed a civil penalty proceeding on 8 August 2025 alleging Optus seriously interfered with the privacy of about 9.5 million Australians, over conduct alleged between 17 October 2019 and 20 September 2022, and the Commissioner alleges one contravention for each of the 9.5 million individuals 4. Both the Medibank and Optus figures are allegations, not findings.

We have found no court document that sets a trial date for the Commissioner’s own case against Optus. A separate class action over the same breach, before the same judge, Justice Beach, is set down for trial from 7 June 2027 9. That date belongs to the class action, not to the Commissioner’s case.

05The regulator’s resources

InnovationAus reported in November 2024 that the OAIC had cut dozens of staff after a 23 per cent budget cut 10. IDM reported that in the 2026-27 Budget the OAIC was allocated $36.576 million, down from $39.753 million in 2025-26 11, a fall of $3.177 million, or about 8 per cent. These are two different windows, reported by two different outlets, and this article does not combine them. What effect, if any, the reductions have had on how many matters the office can pursue is not established on this record.

06Enforced once

Set the two counts beside each other again. In 2025 businesses and agencies told the OAIC of 1,205 notifications of data breaches likely to cause serious harm. Since 2018, this outlet could find only one court-ordered civil penalty order under the Privacy Act, agreed rather than fought at trial, and two more penalty cases, filed in June 2024 and August 2025, with no outcome we have found. The duty to report has been enforced once.

The duty to report has been enforced once, and that order was made by consent, not after a trial.

It is a narrower finding than it might look. Only a court can impose a civil penalty, the cap on every case here was at most $2.22 million a contravention, and we have found no court test of the far higher maximums in force since December 2022.

This case will keep a public tally on this count: if a second court-ordered civil penalty lands under the Privacy Act, the headline above changes.

Another written duty has no fine yet. THE SURVEILLANCE RORT’s ‘The internet asks for ID’ found that, on the public record to July 2026, no fines had been issued under the under-16 social media law.

What the regulator does without a court is the subject of the next article in this case.

If it’s a rort, we cover it.
Next in this rort · Article 2 / 2
Nearly five years
The whole case
All 2 investigations in The Privacy Rort →
From the desk
  • 25 September 2026Record
    Record: THE PRIVACY RORT, article 1, “One penalty”, published
    Right-of-reply questions to the OAIC, Singtel Optus and Medibank had not been sent at publication; any answers will be added as dated updates
    Read the desk note

    ATTENDED 25 September 2026 (case: THE PRIVACY RORT, article 1 of four).

    FINDING. In calendar 2025 the OAIC received 1,205 data breach notifications, the most since the notifiable data breaches scheme began in 2018. Set beside that count, up to 24 September 2026 this outlet has found one civil penalty order a court has ever made under the Privacy Act: $5.8 million against Australian Clinical Labs, ordered by consent on 8 October 2025. The Commissioner’s penalty cases against Optus and Medibank have no outcome this outlet has found, and the Commissioner’s case against Meta was withdrawn in December 2024 for a $50 million payment program instead of a court finding.

    ARTICLE CHANGES. Article 1, “One penalty”, published, setting the record notification count beside every Privacy Act civil penalty case this outlet could find. Three more articles are planned in this case.

    STILL OPEN. Right-of-reply questions to the Office of the Australian Information Commissioner, Singtel Optus and Medibank had not been sent when this article was published. Any answers will be added as dated updates.

    NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.

The desk record →
Corrections policy
Correction Policy: If you believe any claim in this article is factually incorrect, contact us at corrections@therort.com.au with your evidence and a source. We will review and publish corrections prominently.
References & Sources11 sources · all linked
  1. https://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025,-new-ndb-stats-show
  2. https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act
  3. https://www.oaic.gov.au/news/media-centre/annual-report-highlights-oaics-work-on-privacy-and-information-access-rights-and-strengthened-regulatory-approach
  4. https://www.oaic.gov.au/news/media-centre/australian-information-commissioner-takes-civil-penalty-action-against-optus
  5. https://www.oaic.gov.au/news/media-centre/landmark-settlement-of-$50m-from-meta-for-australian-users-impacted-by-cambridge-analytica-incident
  6. https://www.corrs.com.au/insights/changes-to-australias-privacy-act-bolster-enforcement-and-investigative-powers
  7. https://www.atmosgroup.com.au/resources/the-privacy-commissioner-the-infringement-notice-and-the-low-tier-civil-penalty
  8. https://www.oaic.gov.au/news/media-centre/oaic-takes-civil-penalty-action-against-medibank
  9. https://www.slatergordon.com.au/class-actions/current-class-actions/optus-data-breach
  10. https://www.innovationaus.com/oaic-slashes-staff-to-meet-11m-budget-crunch/
  11. https://idm.net.au/article/0015590-funding-squeeze-hits-oaic-privacy-reforms-land
This piece is one node in the model. Every entity it names has a dossier that assembled itself from every investigation mentioning it, and this article now deepens each of them. Follow the power: from the price you pay, to the company that takes it, to the regulator that waved it through.
← THE PRIVACY RORT
Independent · No ads · No masters · If it's a rort, we cover it
Submit a Tip →
Engine DΛREΛKT_Contract site.therort 1.0.0Core 94216cc946eeBuild 2026-09-26T11:59:16Z