THE RORT · THE PRIVACY RORT · ARTICLE 3 / 3READING
CASE FILE · THE PRIVACY RORTARTICLE 3 / 3By The Rort · October 2026 · therort.com.au

Promised in 2019

In December 2019 the government of the day promised to review the Privacy Act and set itself 2021 to finish. The review reported in February 2023. New penalty tiers have applied since December 2024, and the second round of changes is sti…

Reading time11 min
THE PRIVACY RORTThe reform clockJULY 2019 TO OCTOBER 2026: THE GOVERNMENT'S OWN TIMETABLE, SET BESIDE WHAT HAPPENEDABOVE THE LINE: THE GOVERNMENT'S OWN 2019 TARGETS. BELOW IT: WHAT HAPPENED TO THE LAW.REVIEWCOMMENCES2020REVIEWCOMPLETED202126 JUL 2019ACCC recommendsbroader reform12 DEC 2019The governmentpromises areviewOCT 2020Review issuespaper published13 DEC 2022Higher maximumpenaltiesin forceFEB 2023Review reportreleased10-11 DEC2024Assent, thentiers in force9 DEC 2025First compliancesweep announced31 AUG 2026Second roundexposure draft18 SEP 2026Consultationclosed8 OCT 2026No introductionfound to dateDATA BREACHES BEHIND THE CIVIL PENALTY CASESACL: FEB 2022 · OPTUS: ALLEGED CONDUCT TO SEP 2022 · MEDIBANK: OCT 2022Hollow markers are the government's own 2019 targets. Higher maximum penalties apply only to conductafter 13 December 2022; the 2024 tiers only to conduct after 11 December 2024. Not to scale.SOURCES: ACCC · TREASURY · FEDERAL REGISTER OF LEGISLATION · OAIC · ATTORNEY-GENERAL'S DEPARTMENTTHE PRIVACY RORT · THE REFORM CLOCKTHERORT.COM.AU
Hollow markers are the government's own 2019 targets. Higher maximum penalties apply only to conduct after 13 December 2022; the 2024 tiers only to conduct after 11 December 2024. Not to scale. Sources: ACCC; Treasury; Federal Register of Legislation; OAIC; Attorney-General's Department.

On 26 July 2019 the Australian Competition and Consumer Commission published its Digital Platforms Inquiry final report. Recommendation 17 called for broader reform of Australian privacy law 1. In response to the ACCC's recommendations, on 12 December 2019 the government of the day committed to a review of the Privacy Act, with its own roadmap setting the review to commence in 2020 and to be completed in 2021 23.

The review began on time: it published an Issues Paper in October 2020 16. Its report was released in February 2023, and the government responded on 28 September 2023 15. Nearly seven years after the promise, the second round of changes the review led to is still an exposure draft. This outlet found no record that it has been introduced to Parliament 45.

This article sets that reform clock beside the law's own teeth: a March 2019 promise to raise penalties, the higher caps that took effect in December 2022, the two lower tiers added from December 2024, and the one court-ordered Privacy Act penalty this outlet has found, which fell under none of the new caps or tiers.

01The 2019 promise

The recommendation and the promise are two different dates, more than four months apart. The ACCC's Digital Platforms Inquiry final report is cover-dated June 2019 and was published on 26 July 2019; Recommendation 17 calls for broader reform of Australian privacy law but names no timetable of its own 1.

12 December 2019
The date the government committed to a review of the Privacy Act, in Treasury's Government Response and Implementation Roadmap for the Digital Platforms Inquiry.

“The Government will commence a review of the Privacy Act to ensure it empowers consumers, protects their data and best serves the Australian economy.”

Treasury, Government Response and Implementation Roadmap for the Digital Platforms Inquiry, 12 December 2019

The roadmap set its own deadline. It listed the review under the work planned for 2020 as commencing, and under the work planned for 2021 as completed 2.

2020 to 2021
The government's own targets for the Privacy Act review, from the same roadmap: commencing in 2020, completed in 2021.

That is the clock this article measures the rest of this case against: not a standard of ours, but the government's own.

02A penalty promise before the promise

Before the Privacy Act review was promised, a narrower penalty promise had already been made. In March 2019 the government announced it would increase penalties for serious or repeated interference with privacy under the Privacy Act, in line with the penalties available under the Australian Consumer Law 1.

“On 24 March 2019, the Australian Government announced that it would increase penalties for serious or repeated interference with privacy under the Privacy Act in line with penalties available under the ACL.”

ACCC, Digital Platforms Inquiry final report, June 2019

The higher penalty regime commenced on 13 December 2022, and it looks forward only: it applies only to conduct after that date 67. For a body corporate the 2022 Act sets the maximum at the greater of $50 million and either three times the value of the benefit obtained, where the court can determine that value, or 30 per cent of adjusted turnover, where it cannot 7. The law firm Corrs describes it the same way 8.

13 December 2022
The date the higher Privacy Act penalty regime commenced. For a body corporate the maximum is the greater of $50 million and either three times the value of the benefit obtained, where the court can determine it, or 30 per cent of adjusted turnover, where it cannot. It applies only to conduct after that date.

Every data breach behind a Privacy Act civil penalty case we found, including Australian Clinical Labs, Optus and Medibank, falls before that line. As this case's first article, ‘One penalty’, set out, the breach behind the only civil penalty this outlet has found ordered under the Privacy Act, against Australian Clinical Labs, happened in February 2022; Optus's alleged conduct ran to 20 September 2022 and Medibank's breach came in October 2022. All three are older than the higher cap.

“The new penalty regime that came into force on 13 December 2022 allows the Court to impose much higher penalties”

OAIC, Australian Clinical Labs release, 9 October 2025

The $5.8 million ordered against Australian Clinical Labs on 8 October 2025, by consent, is the only civil penalty this outlet has found ever ordered under the Privacy Act 6. It fell under the old cap of $2.22 million per contravention. As ‘One penalty’ also set out, this outlet has found no outcome in the Information Commissioner's civil penalty cases against Optus and Medibank; this outlet has found no decision on the allegations in them.

03Three tiers, prospective only

The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024. The new penalty provisions, and the tiers built on them, commenced the next day, 11 December 2024 9.

11 December 2024
Two new lower penalty tiers commenced, and the top tier was rewritten so that seriousness is an element of the contravention, under the Privacy and Other Legislation Amendment Act 2024, again prospective only.

The top tier's maximum was not raised by the 2024 Act. That figure, the $50 million or turnover-based cap described above, was set by the 2022 Act; the 2024 Act instead made seriousness itself an element a court must find before that tier applies 9. A penalty unit was worth $330 for conduct between 7 November 2024 and 30 June 2026, rising to $364 from 1 July 2026; the figures below are given at both rates 10. They are the maximums for a person, as the Act states them; Corrs reports a higher maximum for a body corporate, which this article does not state 8.

TierWhat it coversMaximum for a personIn force
Top, s13GA serious interference with privacy$2.5 million for a person other than a body corporate; for a body corporate, the 2022 Act maximum described above; not raised by the 2024 Act2022 maximums: conduct after 13 December 2022; seriousness element: conduct after 11 December 2024
Mid, s13HAny interference with privacy, with no seriousness threshold2,000 penalty units: $660,000 to 30 June 2026, $728,000 from 1 July 2026Conduct after 11 December 2024
Low, s13KA short list of specific obligations, including the content of privacy policies, and a non-compliant data breach statement200 penalty units: $66,000 to 30 June 2026, $72,800 from 1 July 2026; also enforced by infringement noticeConduct after 11 December 2024

Neither the mid nor the low tier can reach conduct before 11 December 2024, and the 2024 changes to the top tier apply only to later conduct too 9.

The OAIC announced its first compliance sweep on 9 December 2025, to begin in the first week of January 2026: about 60 entities across six sectors, checked against Australian Privacy Principle 1.4, the content of a privacy policy, which is one of the low tier's listed obligations 11.

“Entities found to have non-compliant privacy policies may face compliance and infringement notices and penalties of up to $66,000.”

OAIC, compliance sweep announcement, 9 December 2025

That figure matches 200 penalty units at the $330 rate that applied until 30 June 2026 10.

The OAIC has since said, in general terms, what the sweep found. In her prepared keynote address for 4 May 2026, the Privacy Commissioner, Carly Kind, wrote 12:

“Our Privacy Sweep of sixty entities earlier this year found instances of non-compliance in a significant proportion.”

Privacy Commissioner Carly Kind, prepared keynote address to the IAPP Sydney KnowledgeNet Privacy Awareness Week launch, 4 May 2026

The OAIC's June 2026 edition of its Information Matters newsletter said the sweep was being finalised, that notices were anticipated and that a report would follow 13.

“The OAIC is finalising its first ever privacy sweep, which involved a review of the privacy policies of 60 businesses that collect information in person, focussing on compliance with Australian Privacy Principle 1.4. We anticipate issuing notices to entities we have identified as non-compliant. A report highlighting the results of the privacy sweep will be published in the new financial year.”

OAIC, Information Matters newsletter, June 2026

As of 8 October 2026 we found no published sweep report, no result for any named entity, and no public report of an infringement notice or a mid-tier penalty case.

04The second round

The next round of privacy law changes reached exposure draft on 31 August 2026. Consultation closed on 18 September 2026, and as of 8 October 2026 this outlet found no record that the resulting bill, the Privacy Amendment (Personal Data Protection) Bill 2026, has been introduced to Parliament 45.

“The Bill remains subject to further consideration by government.”

Attorney-General's Department, privacy reform consultation page

The Attorney-General spoke about timing at a press conference on the exposure draft on 31 August 2026 14.

“I would be hoping that with the introduction of the Bill this year, that we have the broad support across the Parliament to have this passed sooner than a year. So, I would anticipate that we would be in a position to have these laws in place well before a year's time.”

Attorney-General, press conference, 31 August 2026

Those words give a year, not a date, and the department's page gives no date either.

The exposure draft keeps the notification duty on the entity that was breached 5. THE REPORTING RORT's ‘Nobody has to tell’ sets out whom that duty does not bind.

A further part of the 2024 Act has not yet commenced. Schedule 1, Part 15, ‘Automated decisions and privacy policies’, takes effect on 10 December 2026, twenty-four months after Royal Assent. It inserts Australian Privacy Principles 1.7 to 1.9, which require an entity that has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, using personal information about that individual, to set out in its privacy policy the kinds of personal information such programs use and the kinds of decisions they make or help make, and it adds Australian Privacy Principle 1.7 to the low tier's list of obligations in section 13K 9.

The review that led here did go ahead. The Attorney-General's Department has published a page titled ‘Government response to the Privacy Act Review Report’ 15. It says the department released the Privacy Act Review Report in February 2023 and that the government released its response on 28 September 2023. The department's page on the review says it published an Issues Paper in October 2020 and a Discussion Paper in October 2021 16.

“The Privacy Act Review originated out of recommendations from the Australian Competition and Consumer Commission’s 2019 Digital platforms inquiry”

Attorney-General's Department, Government response to the Privacy Act Review Report

This article measures the law's changes against that 2021 target, not the review's own report.

05Right of reply

THE RORT emailed questions to the Office of the Australian Information Commissioner and the Attorney-General's Department on 2 October 2026, and asked for a reply by 5pm AEDT on Thursday 8 October 2026. The questions to the OAIC included how many civil penalty proceedings it has filed since 2018, and how many infringement notices it has issued and mid-tier civil penalty proceedings it has filed since the 2024 Act commenced. The questions to the Department included when the Privacy Amendment (Personal Data Protection) Bill 2026 will be introduced.

No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026.

No response was received from the Attorney-General's Department by the deadline, 5pm AEDT on Thursday 8 October 2026.

Without a reply from the OAIC, this article cannot say whether any infringement notice has been issued or any mid-tier civil penalty proceeding filed; it says only what this outlet found in public sources. Without a reply from the Department, it cannot say when the Bill will be introduced. Any answer will be added as a dated update.

THE RORT also asked Optus on 2 October 2026 whether it contests the Commissioner's allegations in the civil penalty case this article mentions, and whether it expects that case to be heard with the separate Optus data breach class action. Optus's media team replied by email on 8 October, in an email signed Optus Media Team that carries no request that it be kept off the record. The same email from THE RORT also put questions for THE TRIPLE ZERO RORT, and the reply answers the email as a whole. It says:

“Thanks for your enquiry. Optus’s position on these matters is on the public record, including our submission to the Senate Environment and Communications Committee following the September 2025 Triple Zero outage. Our response following the release of the Senate inquiry report, including an update on the changes Optus has made since the outage, is available here: https://www.optus.com.au/about/media-centre/media-releases/2026/09/building-stronger-optus Matters currently before the Federal Court will be addressed through the appropriate legal process.”

Optus Media Team, email of 8 October 2026

The reply does not say whether Optus contests the allegations or whether it expects the Commissioner's case to be heard with the separate Optus data breach class action. Its sentence on the Federal Court names no matter, so this article does not say which matter it refers to. This outlet has found no decision on the allegations in the Commissioner's case. The release the reply links, which Optus dated 21 September 2026, concerns the September 2025 Triple Zero outage.

A Medibank spokesperson replied on 6 October 2026 to a separate question, about Medibank's 2023 application to restrain the Commissioner. That reply is quoted in ‘Nearly five years’.

06Newer than every data breach

Set the clock against the record. From the ACCC's report to 8 October 2026 is more than seven years. From the government's own promise, on 12 December 2019, to 8 October 2026 is nearly seven years. The review was to be completed in 2021 and reported in February 2023; this outlet found no record that the second round of changes it led to has reached Parliament.

From that promise to the penalty tiers commencing, on 11 December 2024, is almost exactly five years. The gap this article measures is that wait, not the fact that new penalties apply to later conduct.

The higher cap of 2022 and the penalty tiers of 2024 are both newer than every data breach behind a Privacy Act civil penalty case we found.

Every data breach behind a Privacy Act civil penalty case we found is older than both penalty changes this article measures: older than the higher cap of December 2022, older than the tiers of December 2024, and penalised, in the one penalty ordered, under the cap that applied before either.

If it’s a rort, we cover it.
Previous in this rort · Article 2 / 3
Nearly five years
The whole case
All 3 articles in The Privacy Rort →
From the desk
  • 10 December 2026Watch
    Schedule 1, Part 15 of the 2024 Act commences
    Part 15 inserts Australian Privacy Principles 1.7 to 1.9 and adds 1.7 to the low penalty tier
    Read the desk note

    Schedule 1, Part 15 of the Privacy and Other Legislation Amendment Act 2024, "Automated decisions and privacy policies", commences on 10 December 2026, twenty-four months after Royal Assent. It inserts Australian Privacy Principles 1.7 to 1.9, which require an entity that has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, using personal information about that individual, to set out in its privacy policy the kinds of personal information such programs use and the kinds of decisions they make or help make, and it adds Australian Privacy Principle 1.7 to the list of obligations in the low penalty tier, section 13K. Watch this date for what the OAIC publishes on the new obligation, and for any use of the low tier that follows.

  • 8 October 2026Record
    Record: THE PRIVACY RORT, article 4, "Promised in 2019", published
    Right-of-reply questions were sent to the OAIC and the Attorney-General's Department on 2 October. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. No response was received from the Attorney-General's Department by the deadline, 5pm AEDT on Thursday 8 October 2026.
    Read the desk note

    ATTENDED 8 October 2026 (case: THE PRIVACY RORT, article 4 of four).

    FINDING. The government's own timetable set the Privacy Act review, promised on 12 December 2019, to commence in 2020 and to be completed in 2021. The review published an Issues Paper in October 2020. The review's report was released in February 2023 and the government responded on 28 September 2023. Nearly seven years after that promise, the second round of changes the review led to is still an exposure draft, and this outlet found no record that it has been introduced to Parliament. The two lower penalty tiers added by the 2024 Act, and its changes to the top tier, apply only to conduct after 11 December 2024, almost exactly five years after the promise itself. The only civil penalty this outlet has found ordered under the Privacy Act, against Australian Clinical Labs, was ordered under the cap that applied before any of these changes. The Privacy Commissioner's prepared keynote address for 4 May 2026 says the OAIC's first compliance sweep found instances of non-compliance in a significant proportion of the 60 entities it reviewed; the OAIC said in June 2026 that a report would be published in the new financial year; this outlet has found none yet.

    ARTICLE CHANGES. Article 4, "Promised in 2019", published, setting the government's own reform clock beside the Privacy Act's enforcement record. Right of reply: THE RORT emailed questions to the Office of the Australian Information Commissioner and the Attorney-General's Department on 2 October 2026, with a reply date of 5pm AEDT on Thursday 8 October 2026. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. No response was received from the Attorney-General's Department by the deadline, 5pm AEDT on Thursday 8 October 2026. The article records both under "Right of reply". Optus's media team replied on 8 October 2026 to the email that put the question about the Commissioner's case against it, together with questions for THE TRIPLE ZERO RORT; the article prints the reply and says what it does not answer. A Medibank spokesperson replied on 6 October 2026 to a separate question, about Medibank's own court application; that reply is quoted in article 2, "Nearly five years", and is not repeated here.

    STILL OPEN. The questions to the OAIC, on the civil penalty proceedings it has filed since 2018 and on the infringement notices it has issued and mid-tier proceedings it has filed since the 2024 Act commenced, are unanswered, so the article says only what this outlet found in public sources. The question to the Attorney-General's Department, on when the Privacy Amendment (Personal Data Protection) Bill 2026 will be introduced, is unanswered. Optus's reply does not say whether Optus contests the Commissioner's allegations or whether it expects the Commissioner's case to be heard with the separate Optus data breach class action. In June 2026 the OAIC said it anticipated issuing notices to entities it identified as non-compliant in the sweep and that a report on the results would be published in the new financial year; this outlet has found neither yet. Any answer will be added as a dated update.

    NEXT DATE: 10 December 2026, when Schedule 1, Part 15 of the 2024 Act commences.

The desk record →
Corrections policy
Correction Policy: If you believe any claim in this article is factually incorrect, contact us at corrections@therort.com.au with your evidence and a source. We will review and publish corrections prominently. How corrections work
References & Sources16 sources · all linked
Evidence strength
  • Primary 2
  • Trade 1
  • 13 not yet graded
Primary
the document itself: legislation, a court record, a filing, a regulator’s own publication
Trade
specialist or trade press
How sources are graded

A check appears under a source only where one is on record: a machine test of whether the link loads, and, where the desk has made the call, whether the document exists and whether it carries the claim. Nothing is shown for a check that is not on record. What these checks mean

  1. https://www.accc.gov.au/system/files/Digital%20platforms%20inquiry%20-%20final%20report.pdf
  2. https://treasury.gov.au/sites/default/files/2019-12/Government-Response-p2019-41708.pdf
  3. https://treasury.gov.au/publication/p2019-41708
  4. https://consultations.ag.gov.au/rights-and-protections/privacy-reform/
  5. Primaryhttps://consultations.ag.gov.au/rights-and-protections/privacy-reform/user_uploads/exposure-draft-bill-2026.pdf
  6. Primaryhttps://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act
  7. https://www.legislation.gov.au/C2022A00083/asmade/2022-12-12/text/original/pdf
  8. Tradehttps://www.corrs.com.au/insights/changes-to-australias-privacy-act-bolster-enforcement-and-investigative-powers
  9. https://www.legislation.gov.au/C2024A00128/asmade/2024-12-10/text/original/pdf
  10. https://www.afsa.gov.au/professionals/resource-hub/penalty-units
  11. https://www.oaic.gov.au/news/media-centre/privacy-compliance-sweep-to-put-privacy-policies-under-the-spotlight
  12. https://www.oaic.gov.au/news/speeches/paw-2026-iapp-keynote
  13. https://oaic.writemsg.com/em/message/email/view.php?id=1698085&a=57903&k=pJxprds124aaDM1lzMY8aN7-pAxQJW4IiJp1DiDZz5g
  14. https://ministers.ag.gov.au/media-centre/transcripts/press-conference-blue-room-31-08-2026
  15. https://www.ag.gov.au/rights-and-protections/publications/government-response-privacy-act-review-report
  16. https://www.ag.gov.au/rights-and-protections/privacy/review-privacy-act-1988
This piece is one node in the model. Every entity it names has a dossier that assembles itself from every article mentioning it. Follow the names, and the case, through the record.
← THE PRIVACY RORT