The Privacy and Other Legislation Amendment Bill 2024 (Cth) has been passed by both Houses of Parliament.
Key takeouts:
- The Privacy and Other Legislation Amendment Bill 2024 (Cth) has been passed by both Houses of Parliament. The Bill now awaits the Royal Assent.
- The Bill implements 23 of the 25 proposals directed at legislative change to the Privacy Act 1988 (Cth) that were ‘agreed’ to by the Government in its 2023 response to the Attorney-General’s Privacy Act Review Report.
- Key changes to the Bill since it was first introduced include changes to the tort for serious invasions of privacy, and the introduction of new OAIC powers to issue compliance notices.
The Privacy and Other Legislation Amendment Bill 2024 (Cth) (Bill) was passed by both Houses of Parliament on 29 November 2024. It is the first tranche of long-awaited reforms to the Privacy Act 1988 (Cth) (Privacy Act) following the Attorney-General’s Privacy Act Review Report of February 2023 (Report) and the Government’s response to that Report of September 2023 (Response).
In the Government’s Response, it ‘agreed’ to 38 of the 116 proposals, with a further 68 ‘agreed in-principle’. The Bill implements 23 of the 25 ‘agreed’ proposals that were specifically directed at legislative change. Key reforms which have been passed include:
- a new cause of action in tort for serious invasions of privacy;
- a new criminal offence of ‘doxxing’ – that is, releasing personal data using a carriage service in a manner that would reasonably be regarded as menacing or harassing;
- a requirement for the OAIC to develop a Children’s Online Privacy Code addressing online privacy for children;
- new civil penalty provisions for interfering with the privacy of individuals and new OAIC powers to issue infringement notices and compliance notices;
- new Ministerial powers to ‘white list’ countries that provide substantially similar privacy protections, in order to assist entities disclosing personal information overseas;
- a new requirement for privacy policies to include information about automated decision-making; and
- clarifying that taking ‘reasonable steps’ to protect the security of personal information includes implementing ‘technical and organisational measures’.
There have been some changes to the Bill since it was first introduced, in particular, to the tort for serious invasion of privacy, and the introduction of new OAIC powers to issue compliance notices, which we explore below.
Key amendments:
The key amendments commence the day after the Bill receives the Royal Assent, except for:
- updating privacy policies to include automated decision-making – which will commence 24 months after the Royal Assent; and
- the provisions relating to the tort of serious invasions of privacy – which will commence on a day to be fixed, but within 6 months after the Royal Assent.
Feb 2025