Privacy Act guide · general information, not legal advice

The privacy tort and employers: workplace exposure

Workplaces watch, record and hold a lot of information about people. Since 10 June 2025 an individual can sue for a serious invasion of privacy, whatever the employer's turnover. This guide shows where the statutory tort meets everyday employment practice, and what a small employer can do about it.

Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227 (compilation date 4 June 2026)

Sch 2 cl 7 the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law

Why employers should look at the tort

The statutory tort for serious invasions of privacy is in Schedule 2 of the Privacy Act 1988. It commenced on 10 June 2025.1 Any individual can bring a claim: an employee, a former employee, a job applicant, a contractor, a client or a visitor to your office.2

Two features matter most to a small employer:

  • Turnover is irrelevant. Schedule 2 has no $3 million threshold. The OAIC says the tort "is broader in application than the Privacy Act, extending to individuals and other entities that may not necessarily be an Australian Privacy Principle entity".3
  • It is decided by the courts. The OAIC "does not have a direct role in administering the tort".3 A claim is a civil action for damages or other orders, not a complaint to a regulator.

The general guide to the statutory tort covers the defences, remedies, damages cap and time limits in full.

What an employee would have to prove

A claim succeeds only if the plaintiff proves all five elements in clause 7(1):4

  1. the employer intruded upon their seclusion or misused information that relates to them, or both;
  2. a person in their position would have had a reasonable expectation of privacy in all of the circumstances;
  3. the invasion was intentional or reckless;
  4. the invasion was serious; and
  5. the public interest in their privacy outweighed any countervailing public interest.

The plaintiff does not have to prove that they suffered damage.5 Intruding upon seclusion includes "watching, listening to or recording the person's private activities or private affairs". Misusing information includes "collecting, using or disclosing information about the individual".6

The bar is high. A careless mistake is not enough on its own, because the invasion must be intentional or reckless, and it must also be serious. But ordinary workplace practices can meet the first element, so they are worth reviewing.

Where workplace exposure can arise

The table maps common practices to the element of the tort they can touch, and to the matters Schedule 2 lets a court consider. Whether any particular practice invades privacy depends on all the circumstances.

Workplace practices and the statutory tort
Practice Limb it can touch What a court may consider Source
Security cameras, audio recording, covert recording Intrusion upon seclusion The device or technology used, the purpose, and the place where the intrusion happened Sch 2 cl 7(5)(a) Sch 2 cl 7(5)(b) Sch 2 cl 7(5)(e)
Email, computer, phone and location monitoring Intrusion upon seclusion; collection of information The means and the purpose, and whether staff manifested a desire for privacy Sch 2 cl 7(5)(a) Sch 2 cl 7(5)(d)
Health, leave and disciplinary records Misuse of information, especially disclosure The nature of the information, including health or medical matters, and how the employee communicated it Sch 2 cl 7(5)(f)
Background checks and screening Misuse of information, through collection The purpose, and whether the information was already public Sch 2 cl 7(5)(b) Sch 2 cl 7(5)(f)
Comments or posts about a staff member Misuse of information, through disclosure The nature of the information and the likely distress to a person of ordinary sensibilities Sch 2 cl 7(5)(f) Sch 2 cl 7(6)

If you provide AML/CTF designated services, your AML/CTF policies must deal with personnel due diligence (AML/CTF Act s 26F(4)(d)).7 That means collecting information about staff. Collect what the program needs, record why, and keep it secure. The OAIC lists "excessive collection and retention of personal information" among its regulatory action priorities for 2025–26.8

The employee records exemption does not answer the tort

Many employers rely on the employee records exemption. Under s 7B(3) of the Privacy Act, an act or practice of an organisation that is or was an individual's employer is exempt for the purposes of s 7(1)(ee) if it is directly related to the employment relationship and to an employee record the organisation holds about that individual.9 That exemption concerns the Australian Privacy Principles.

Schedule 2 works differently:

  • it is "intended to be read and construed separately from the rest of this Act", and in working out what a clause of Schedule 2 means, the rest of the Act is disregarded;10
  • its defences and exemptions are listed in the Schedule itself (clauses 8 and 15 to 18), and an exemption for employee records is not among them.11

The employee records exemption also reaches only an employer's own employees and former employees. It says nothing about job applicants who were never employed, contractors, clients or visitors.9

Defences that matter at work

Of the defences in clause 8(1), three are most relevant to employers:12

  • Consent. The plaintiff, or a person with lawful authority to act for them, expressly or impliedly consented to the invasion. A written, communicated monitoring policy is evidence of what staff were told. Whether it amounts to consent to a particular act is for a court to decide.
  • Lawful authority. The invasion was required or authorised by or under an Australian law or a court or tribunal order.
  • Defence of persons or property. The invasion was incidental to the exercise of a lawful right of defence of persons or property, and was proportionate, necessary and reasonable. Whether a camera meets that test depends on what it covers and why.

Schedule 2 does not say when a business is liable for an invasion of privacy committed by one of its employees. If that question arises, get legal advice. State and Territory laws continue to operate alongside Schedule 2, including any surveillance or listening-device laws where you operate.13

Practical steps for employers

  1. Write a monitoring policy

    Say what you monitor (cameras, email, devices, location), why, where, who can see the results and how long you keep them. Review it when you add a new tool.

  2. Tell staff before you start

    Give the policy to staff, and to new starters before their first day. Record that you did. Avoid covert monitoring unless a lawyer has advised that it is lawful where you operate.

  3. Collect the minimum

    Collect only what the role, the law or your AML/CTF program requires, and delete it when it is no longer needed.

  4. Restrict access to staff files

    Keep health, leave and disciplinary information in a restricted file. Share it only with people who need it, and never in a group email or chat.

  5. Plan for a breach

    Decide in advance who does what if staff information is lost or wrongly disclosed. Whether the Notifiable Data Breaches scheme applies depends on whether you are an APP entity and on the information involved; our data breach response plan explains the test.

  6. Deal with complaints early

    An apology is not an admission of liability for the purposes of Schedule 2, and a court may take an apology into account in setting damages. Sch 2 cl 13 Sch 2 cl 11(6)

Where to go next

AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, the Attorney-General's Department or any other government body. This guide is general information, not legal or employment advice.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC pages are guidance, not law.

  1. Privacy Act 1988, compilation No. 104 (C2026C00227), Schedule 2 and endnote 3: "sch 2: 10 June 2025". legislation.gov.au/C2004A03712/latest/text

  2. Privacy Act 1988, Schedule 2, clause 7(1): "An individual (the plaintiff) has a cause of action in tort against another person".

  3. OAIC, "Statutory tort for serious invasions of privacy". Guidance, not law. oaic.gov.au

  4. Privacy Act 1988, Schedule 2, clause 7(1).

  5. Privacy Act 1988, Schedule 2, clause 7(2): the invasion "is actionable without proof of damage".

  6. Privacy Act 1988, Schedule 2, clause 6(1), definitions of "intruding upon the seclusion of an individual" and "misusing information that relates to an individual".

  7. Anti-Money Laundering and Counter-Terrorism Financing Act 2006, compilation C2026C00274, s 26F(4)(d). legislation.gov.au/C2006A00169/latest/text

  8. OAIC, "OAIC releases regulatory action priorities for 2025-26". Guidance, not law. oaic.gov.au

  9. Privacy Act 1988, s 7B(3); s 6(1), definition of "employee record".

  10. Privacy Act 1988, Schedule 2, clause 2 and clause 6(3).

  11. Privacy Act 1988, Schedule 2, clauses 8, 15, 16, 16A, 16B, 17 and 18.

  12. Privacy Act 1988, Schedule 2, clause 8(1)(a), (b) and (d).

  13. Privacy Act 1988, Schedule 2, clause 21.

Questions

Does the employee records exemption help?

Not against the tort. The employee records exemption in s 7B(3) of the Privacy Act exempts certain acts of an employer for the purposes of the Australian Privacy Principles. Schedule 2 is a separate cause of action, read separately from the rest of the Act, with its own defences and exemptions, and an employee records exemption is not among them. Get advice on the surveillance and workplace laws of your State or Territory as well.

What is a serious invasion?

The employee must prove five things: an intrusion upon their seclusion or a misuse of information about them; a reasonable expectation of privacy in all the circumstances; that the invasion was intentional or reckless; that it was serious; and that the public interest in their privacy outweighed any countervailing public interest (Sch 2 cl 7(1)). In judging seriousness a court may consider the likely offence, distress or harm to dignity, what the employer knew or ought to have known, and any malice (cl 7(6)).

What should we do?

Write down what you monitor and why, tell staff before you start, collect the minimum, restrict access to staff files, and plan how you would respond if staff information were lost or wrongly disclosed. The steps are set out in the section on practical steps above.