Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227 (compilation date 4 June 2026)
Sch 2 cl 7 the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law
Why employers should look at the tort
The statutory tort for serious invasions of privacy is in Schedule 2 of the Privacy Act 1988. It commenced on 10 June 2025.1 Any individual can bring a claim: an employee, a former employee, a job applicant, a contractor, a client or a visitor to your office.2
Two features matter most to a small employer:
- Turnover is irrelevant. Schedule 2 has no $3 million threshold. The OAIC says the tort "is broader in application than the Privacy Act, extending to individuals and other entities that may not necessarily be an Australian Privacy Principle entity".3
- It is decided by the courts. The OAIC "does not have a direct role in administering the tort".3 A claim is a civil action for damages or other orders, not a complaint to a regulator.
The general guide to the statutory tort covers the defences, remedies, damages cap and time limits in full.
What an employee would have to prove
A claim succeeds only if the plaintiff proves all five elements in clause 7(1):4
- the employer intruded upon their seclusion or misused information that relates to them, or both;
- a person in their position would have had a reasonable expectation of privacy in all of the circumstances;
- the invasion was intentional or reckless;
- the invasion was serious; and
- the public interest in their privacy outweighed any countervailing public interest.
The plaintiff does not have to prove that they suffered damage.5 Intruding upon seclusion includes "watching, listening to or recording the person's private activities or private affairs". Misusing information includes "collecting, using or disclosing information about the individual".6
The bar is high. A careless mistake is not enough on its own, because the invasion must be intentional or reckless, and it must also be serious. But ordinary workplace practices can meet the first element, so they are worth reviewing.
Where workplace exposure can arise
The table maps common practices to the element of the tort they can touch, and to the matters Schedule 2 lets a court consider. Whether any particular practice invades privacy depends on all the circumstances.
| Practice | Limb it can touch | What a court may consider | Source |
|---|---|---|---|
| Security cameras, audio recording, covert recording | Intrusion upon seclusion | The device or technology used, the purpose, and the place where the intrusion happened | Sch 2 cl 7(5)(a) Sch 2 cl 7(5)(b) Sch 2 cl 7(5)(e) |
| Email, computer, phone and location monitoring | Intrusion upon seclusion; collection of information | The means and the purpose, and whether staff manifested a desire for privacy | Sch 2 cl 7(5)(a) Sch 2 cl 7(5)(d) |
| Health, leave and disciplinary records | Misuse of information, especially disclosure | The nature of the information, including health or medical matters, and how the employee communicated it | Sch 2 cl 7(5)(f) |
| Background checks and screening | Misuse of information, through collection | The purpose, and whether the information was already public | Sch 2 cl 7(5)(b) Sch 2 cl 7(5)(f) |
| Comments or posts about a staff member | Misuse of information, through disclosure | The nature of the information and the likely distress to a person of ordinary sensibilities | Sch 2 cl 7(5)(f) Sch 2 cl 7(6) |
If you provide AML/CTF designated services, your AML/CTF policies must deal with personnel due diligence (AML/CTF Act s 26F(4)(d)).7 That means collecting information about staff. Collect what the program needs, record why, and keep it secure. The OAIC lists "excessive collection and retention of personal information" among its regulatory action priorities for 2025–26.8
The employee records exemption does not answer the tort
Many employers rely on the employee records exemption. Under s 7B(3) of the Privacy Act, an act or practice of an organisation that is or was an individual's employer is exempt for the purposes of s 7(1)(ee) if it is directly related to the employment relationship and to an employee record the organisation holds about that individual.9 That exemption concerns the Australian Privacy Principles.
Schedule 2 works differently:
- it is "intended to be read and construed separately from the rest of this Act", and in working out what a clause of Schedule 2 means, the rest of the Act is disregarded;10
- its defences and exemptions are listed in the Schedule itself (clauses 8 and 15 to 18), and an exemption for employee records is not among them.11
The employee records exemption also reaches only an employer's own employees and former employees. It says nothing about job applicants who were never employed, contractors, clients or visitors.9
Defences that matter at work
Of the defences in clause 8(1), three are most relevant to employers:12
- Consent. The plaintiff, or a person with lawful authority to act for them, expressly or impliedly consented to the invasion. A written, communicated monitoring policy is evidence of what staff were told. Whether it amounts to consent to a particular act is for a court to decide.
- Lawful authority. The invasion was required or authorised by or under an Australian law or a court or tribunal order.
- Defence of persons or property. The invasion was incidental to the exercise of a lawful right of defence of persons or property, and was proportionate, necessary and reasonable. Whether a camera meets that test depends on what it covers and why.
Schedule 2 does not say when a business is liable for an invasion of privacy committed by one of its employees. If that question arises, get legal advice. State and Territory laws continue to operate alongside Schedule 2, including any surveillance or listening-device laws where you operate.13
Practical steps for employers
Write a monitoring policy
Say what you monitor (cameras, email, devices, location), why, where, who can see the results and how long you keep them. Review it when you add a new tool.
Tell staff before you start
Give the policy to staff, and to new starters before their first day. Record that you did. Avoid covert monitoring unless a lawyer has advised that it is lawful where you operate.
Collect the minimum
Collect only what the role, the law or your AML/CTF program requires, and delete it when it is no longer needed.
Restrict access to staff files
Keep health, leave and disciplinary information in a restricted file. Share it only with people who need it, and never in a group email or chat.
Plan for a breach
Decide in advance who does what if staff information is lost or wrongly disclosed. Whether the Notifiable Data Breaches scheme applies depends on whether you are an APP entity and on the information involved; our data breach response plan explains the test.
Deal with complaints early
An apology is not an admission of liability for the purposes of Schedule 2, and a court may take an apology into account in setting damages. Sch 2 cl 13 Sch 2 cl 11(6)
Where to go next
- The tort in full: the statutory tort for serious invasions of privacy.
- The rest of the Privacy Act: the Privacy Act section covers the small business test, privacy policies, data breaches and the dates coming up.
- Every source we use is listed on our sources page.
AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, the Attorney-General's Department or any other government body. This guide is general information, not legal or employment advice.
Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.
Sources
Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC pages are guidance, not law.
-
Privacy Act 1988, compilation No. 104 (C2026C00227), Schedule 2 and endnote 3: "sch 2: 10 June 2025". legislation.gov.au/C2004A03712/latest/text
-
Privacy Act 1988, Schedule 2, clause 7(1): "An individual (the plaintiff) has a cause of action in tort against another person".
-
OAIC, "Statutory tort for serious invasions of privacy". Guidance, not law. oaic.gov.au
-
Privacy Act 1988, Schedule 2, clause 7(1).
-
Privacy Act 1988, Schedule 2, clause 7(2): the invasion "is actionable without proof of damage".
-
Privacy Act 1988, Schedule 2, clause 6(1), definitions of "intruding upon the seclusion of an individual" and "misusing information that relates to an individual".
-
Anti-Money Laundering and Counter-Terrorism Financing Act 2006, compilation C2026C00274, s 26F(4)(d). legislation.gov.au/C2006A00169/latest/text
-
OAIC, "OAIC releases regulatory action priorities for 2025-26". Guidance, not law. oaic.gov.au
-
Privacy Act 1988, s 7B(3); s 6(1), definition of "employee record".
-
Privacy Act 1988, Schedule 2, clause 2 and clause 6(3).
-
Privacy Act 1988, Schedule 2, clauses 8, 15, 16, 16A, 16B, 17 and 18.
-
Privacy Act 1988, Schedule 2, clause 8(1)(a), (b) and (d).
-
Privacy Act 1988, Schedule 2, clause 21.