Since 2018, businesses and Commonwealth agencies covered by the Privacy Act have had to report data breaches likely to cause serious harm. In 2025 the privacy regulator received 1,205 notifications, the most since the scheme began. The first civil penalties ever ordered under the Act came on 8 October 2025: $5.8 million against Australian Clinical Labs, which admitted the contraventions and consented to the orders. Up to 24 September 2026 we have found no other. Only a court can order a civil penalty, and the regulator's other outcomes have been findings, declarations, a negotiated payment, or nothing yet: Kmart's scanning of every shopper in 28 stores was found unlawful, a finding the law does not allow to carry a fine and one Kmart has asked the Administrative Review Tribunal to review, further action against Clearview AI was judged not warranted nearly three years after it was found in breach, and the Optus and Medibank penalty cases, filed over 2022 breaches, have no outcome we have found. A joint investigation of Latitude, opened in May 2023, has published none.
ATTENDED 25 September 2026 (case: THE PRIVACY RORT, article 1 of four).
FINDING. In calendar 2025 the OAIC received 1,205 data breach notifications, the most since the notifiable data breaches scheme began in 2018. Set beside that count, up to 24 September 2026 this outlet has found one civil penalty order a court has ever made under the Privacy Act: $5.8 million against Australian Clinical Labs, ordered by consent on 8 October 2025. The Commissioner’s penalty cases against Optus and Medibank have no outcome this outlet has found, and the Commissioner’s case against Meta was withdrawn in December 2024 for a $50 million payment program instead of a court finding.
ARTICLE CHANGES. Article 1, “One penalty”, published, setting the record notification count beside every Privacy Act civil penalty case this outlet could find. Three more articles are planned in this case.
STILL OPEN. Right-of-reply questions to the Office of the Australian Information Commissioner, Singtel Optus and Medibank had not been sent when this article was published. Any answers will be added as dated updates.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
ATTENDED 25 September 2026 (case: THE PRIVACY RORT, article 2 of four).
FINDING. On one basis, months from an investigation’s announcement or a civil penalty proceeding’s filing, to its outcome, or to 24 September 2026 if there is none, the regulator’s largest privacy matters run from about one year to nearly five. The Optus White Pages investigation, announced in August 2021, closed only on 11 June 2026, about 58 months. The Meta case ran about 57 months before an enforceable undertaking ended it. The Latitude joint investigation, the Medibank penalty case and the Optus penalty case have no published outcome, at about 40, 27 and 13 months respectively. The Meta, Medibank and Optus penalty cases each followed an earlier OAIC investigation; this measure starts at the filing, not the investigation. This article lays each matter’s own timeline, and its own stated ending or absence of one, side by side.
ARTICLE CHANGES. Article 2, “Nearly five years”, published, covering the duration of the OAIC’s largest matters and the separate, stated ground each matter that closed without a court was closed on.
STILL OPEN. Questions on these matters will be put to the Office of the Australian Information Commissioner, Singtel Optus, Medibank and Latitude Financial; any answers will be added as dated updates.
NEXT DATE: this case’s article 3, on the retail and scraped facial-recognition findings, remains blocked pending outstanding checks. Two dates lie ahead in the matters in this article: 12 February 2027, the date by which, MLex reports, Justice Beach ordered the parties in the Optus matters to mediation, and 7 June 2027, when the related class action is set down for trial.