Privacy Act 2026
Privacy Act Compliance Checklist 2026: 12 Things to Fix Before the Deadlines Hit (Australia)
A practical 12-point Australian Privacy Act 1988 compliance checklist for 2026: the in-force statutory tort, the 30-day data-breach clock, the 10 December 2026 ADM disclosure, AML Tranche 2's privacy ripple, and your privacy-policy gaps. Plain English, source-checked, free checklist inside.
The Australian Privacy Act 1988 is changing on several fronts in 2026. This is a practical, prioritised checklist — twelve things to work through, ordered so you fix the in-force items first and the dated items in time. You can get the whole thing as a free, editable checklist (link below).
In force right now — do these first
1. Understand the statutory tort. Since 10 June 2025, individuals can sue directly for a serious invasion of privacy. It applies regardless of turnover and is run by the courts, not the OAIC. Tighten how you collect, store and surveil. See the statutory tort explained.
2. Set up your data-breach clock. Under the Notifiable Data Breaches scheme you must assess a suspected eligible breach expeditiously — within 30 days — and notify the OAIC and affected individuals if serious harm is likely. Build the process before you need it: data-breach response plan. (Source: OAIC NDB.)
3. Make sure your privacy policy is actually compliant. A non-compliant policy is an APP 1 breach the OAIC can issue an infringement notice for. The OAIC's early-2026 compliance sweep reviewed about 60 businesses across in-person-collection sectors (real estate, pharmacies, licensed venues, car rental, car dealerships, pawnbrokers). See how to write a compliant privacy policy.
4. Give proper collection notices (APP 5) wherever you collect personal information — website forms, onboarding, employment, and AML/KYC.
Dated obligations — get ahead of them
5. Prepare your ADM disclosure for 10 December 2026. If you use software or AI to make decisions that significantly affect people, your privacy policy must disclose the kinds of information used and decisions made. See ADM disclosure in your privacy policy.
6. Build your ADM inventory. List each tool, the decision it affects and the data it uses — so your disclosure stays accurate.
7. Check the Children's Online Privacy Code (by 10 December 2026). If you run a social media, electronic or internet service likely to be accessed by children, this code will apply. See does the Children's Online Privacy Code apply to you?
If you're heading into AML Tranche 2
8. Treat privacy and AML as one project. From 1 July 2026, becoming a reporting entity brings the personal information you collect for AML/CTF under the Privacy Act regardless of turnover. See AML Tranche 2 and the Privacy Act.
9. Write a KYC collection notice that doubles as a privacy and AML document.
Foundations every business should have
10. Map your personal information. What you collect, where it lives, who can access it, how long you keep it. The OAIC's 2025–26 priorities call out excessive collection and retention.
11. Review overseas disclosure and third parties. Know where your data flows, including to processors and ad-tech.
12. Don't over-react to the proposed exemption removal. The removal of the $3M small-business exemption is proposed, not law, with no confirmed date. Monitor it; spend your effort on the certain items above. See the $3 million exemption explained.
Work it in order
Run the free 2-minute checker to see which of these twelve apply to you, then get the editable checklist to track them.
General information only, not legal or compliance advice. Current to June 2026; confirm your obligations at oaic.gov.au or with a qualified adviser. The exemption removal is proposed and not yet law. Last verified: 8 June 2026.
Run the free ML/TF risk assessment →