Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227 (compilation date 4 June 2026) and the Privacy and Other Legislation Amendment Act 2024 (C2024A00128)
s 26GC(10) the law, read in the authorised textOAIC guidance published guidance, which is not law
The dates at a glance
In this table, "the POLA Act" is the Privacy and Other Legislation Amendment Act 2024. Section numbers on their own are sections of the Privacy Act 1988.
- 10 December 2024
The POLA Act received Royal Assent.
POLA Act s 2 - 11 December 2024
Schedule 1, Parts 1 to 14, and Schedule 3 of the POLA Act commenced. They brought in the mid-tier and low-tier civil penalties, compliance notices, the requirement for a Children's Online Privacy Code and changes to the eligible data breach provisions.
s 13H s 13K s 80UC s 26GC POLA Act s 2 - 10 June 2025
The statutory tort for serious invasions of privacy commenced. It is in Schedule 2 of the Privacy Act.
See the statutory tort.
POLA Act s 2 Sch 2 OAIC - 9 December 2025
The OAIC announced its first privacy compliance sweep. From the first week of January 2026 it would review the privacy policies of approximately 60 entities in 6 sectors, including rental and property, against APP 1.4.
OAIC media release - 31 March 2026
Schedules 1 to 3 of the AML/CTF Amendment Act 2024 commenced, and AUSTRAC enrolment for the new sectors opened. The same day, the OAIC published the exposure draft of the Children's Online Privacy Code; consultation ran to 5 June 2026.
AUSTRAC OAIC - 18 May 2026
The OAIC opened consultation on an Issues Paper to inform its guidance on transparency in automated decision-making. Submissions closed on 15 June 2026.
The OAIC said it intended to release the guidance by September 2026. Check oaic.gov.au for the current version.
OAIC - 1 July 2026
The Commonwealth penalty unit became $364 for contraventions on or after this day. Privacy Act penalties expressed in penalty units use it.
Crimes Act s 4AA F2026N00424 - 1 July 2026
AML/CTF obligations applied to real estate, professional services and dealers in precious metals and stones. A small business that becomes a reporting entity is treated as an organisation under the Privacy Act for its AML/CTF activities, whatever its turnover.
Enrolment with AUSTRAC was due on 29 July 2026 for firms already providing those services. See AML tranche 2 and the Privacy Act.
s 6E(1A) OAIC AML/CTF guidance - 31 August 2026
The Attorney-General's Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, with a consultation paper. Submissions closed on 18 September 2026.
The draft is a proposal, not law. The department says it remains subject to further consideration by government.
AGD consultation page - 10 December 2026
APP 1.7 to 1.9 commence. Privacy policies must describe the kinds of personal information used, and the kinds of decisions made, by computer programs that make, or do things substantially and directly related to making, decisions that could reasonably be expected to significantly affect an individual's rights or interests.
The rules apply to decisions made after they commence on this day. See automated decision-making disclosure.
POLA Act s 2 Sch 1 items 87 to 89 - 10 December 2026
The Information Commissioner must have developed and registered the Children's Online Privacy Code. The OAIC says the Code will be in place by this date.
s 26GC(10) OAIC
What is already in force
The POLA Act received Royal Assent on 10 December 2024, and most of Schedule 1 commenced the next day, 11 December 2024.1 Since then the Privacy Act has had three penalty tiers: serious interference with privacy (s 13G), interference with privacy (s 13H) and the listed breaches in s 13K, which include not having a privacy policy with the contents APP 1.4 requires. For a s 13K breach, an infringement notice or a compliance notice can be issued (s 80UB and s 80UC).2
For conduct on or after 1 July 2026, the s 13K maximum is 200 penalty units, which is $72,800, or 1,000 penalty units for a body corporate, which is $364,000 (Regulatory Powers Act s 82(5)(a)).3 Our penalties guide sets out every tier.
The statutory tort has been in force since 10 June 2025.4 It has no turnover threshold, so it reaches small businesses that the Australian Privacy Principles do not. The Notifiable Data Breaches scheme also applies now: an APP entity that suspects an eligible data breach must take all reasonable steps to complete an assessment within 30 days (s 26WH).5
For tranche 2 firms, s 6E(1A) matters most. If a small business operator is a reporting entity under the AML/CTF Act, the Privacy Act applies to its AML/CTF activities as if it were an organisation.6 The OAIC says: "From 1 July 2026, the Privacy Act will also apply to tranche 2 entities once they become reporting entities under the AML/CTF Act."7
What is dated for 10 December 2026
| Change | What it requires | Source |
|---|---|---|
| Automated decisions in privacy policies (APP 1.7 to 1.9) | If you have arranged for a computer program to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, and personal information about the individual is used in the program, your privacy policy must describe the kinds of personal information used and the kinds of decisions involved. It applies to decisions made after the rules commence on 10 December 2026. | POLA Act s 2 Sch 1 items 88 to 89 |
| APP 1.7 becomes a s 13K matter | From the same day, a breach of APP 1.7 is added to the low-tier provisions in s 13K(1)(b). | Sch 1 item 87 |
| Children's Online Privacy Code | The Commissioner must develop and register the Code within 24 months of Royal Assent. It will bind APP entities that provide social media services, relevant electronic services or designated internet services likely to be accessed by children (other than entities providing a health service), and any other APP entities the Code specifies. The Code can also exclude specified entities. | s 26GC(5) s 26GC(7) s 26GC(10) OAIC |
The automated-decision rules commence on 10 December 2026 because s 2 of the POLA Act starts Part 15 of Schedule 1 on "the day after the end of the period of 24 months beginning on the day this Act receives the Royal Assent".8 They are not yet in the text of the Privacy Act compilation, so we cite them from the POLA Act.
Proposed, not law
Two items often appear on privacy timelines without a date. Neither is law.
Keep these off your deadline list
The small business exemption. A business with an annual turnover of $3 million or less is generally a small business operator, outside the Australian Privacy Principles, unless one of the cases in s 6D(4) applies (for example, it provides a health service and holds health information, or it trades in personal information).9 Removing the exemption is not law. The exposure draft released on 31 August 2026 re-words the s 6D(4) carve-outs for trading in personal information, but it keeps the exemption.10
A 72-hour breach notification. The same exposure draft would require an entity to notify the Commissioner within 72 hours of having reasonable grounds to believe an eligible data breach has occurred. It is a proposal. The law today is the 30-day assessment in s 26WH and notification as soon as practicable (s 26WK and s 26WL).10
Where to go next
- The Privacy Act section: the Privacy Act guides cover the small business test, privacy policies, data breaches and the statutory tort.
- Your AML/CTF dates: see our tranche 2 key dates.
- Every source we use is listed on our sources page.
AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, the Attorney-General's Department, AUSTRAC or any other government body. This guide is general information, not legal advice.
Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.
Sources
Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC, AUSTRAC and Attorney-General's Department pages are guidance, not law. An exposure draft Bill is a proposal, not law.
-
Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024; C2024A00128), front page ("Assented to 10 December 2024") and s 2(1), table items 1 to 6 and 9. legislation.gov.au/C2024A00128/latest/text
-
Privacy Act 1988, compilation No. 104 (C2026C00227), ss 13G, 13H, 13K, 80UB and 80UC. The mid and low tiers and compliance notices were added by the POLA Act; the s 13G maxima come from the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022. legislation.gov.au/C2004A03712/latest/text
-
Privacy Act 1988, s 13K(4): 200 penalty units. Regulatory Powers (Standard Provisions) Act 2014, s 82(5)(a): 5 times for a body corporate. Crimes Act 1914, s 4AA, and the Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424): a penalty unit is $364 for contraventions on or after 1 July 2026. 200 × $364 = $72,800; 1,000 × $364 = $364,000. legislation.gov.au/F2026N00424/latest/text
-
Privacy Act 1988, compilation No. 104, endnote 3: "sch 2: 10 June 2025"; POLA Act s 2(1), table item 8.
-
Privacy Act 1988, s 26WH(2).
-
Privacy Act 1988, s 6E(1A).
-
OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026. Guidance, not law. oaic.gov.au
-
POLA Act s 2(1), table item 7; Schedule 1, items 87 to 89.
-
Privacy Act 1988, s 6D(1) and (4).
-
Attorney-General's Department, "Privacy Reform: Consultation on Exposure Draft legislation", and the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026. A proposal, not law. consultations.ag.gov.au