Privacy Act 2026

The Privacy Tort and Your Workplace: Employer Liability Risks You Didn't See Coming (Australia)

How Australia's statutory tort for serious invasions of privacy (in force since 10 June 2025) creates new employer exposure — workplace surveillance, monitoring and handling of staff information. Plain English, source-checked.

By Daniel Ebiau, AMLCompliant ·

Most coverage of Australia's new privacy tort focuses on customers. But employers have their own exposure — because workplaces involve monitoring, recording and handling a lot of personal information about staff. Since the statutory tort came into force on 10 June 2025, that exposure is sharper. Here is what employers should understand.

A quick recap of the tort

The statutory tort lets individuals sue for a serious, intentional or reckless invasion of privacy through intrusion upon seclusion or misuse of information, where they had a reasonable expectation of privacy and that interest outweighs competing public interest. It is run by the courts, not the OAIC, and — this is the key point for employers — it can reach businesses the Privacy Act itself does not cover, regardless of turnover. The full mechanics are in the statutory tort explained. (Source: OAIC.)

Where workplace exposure can arise

Common workplace activities can intersect with the tort where a reasonable expectation of privacy exists and conduct is intentional or reckless. Areas to think carefully about include:

  • Surveillance and monitoring — cameras, device and computer monitoring, location

tracking, and covert recording.

  • Excessive or intrusive collection of staff personal information beyond what the

role needs.

  • Mishandling or improper disclosure of sensitive staff information (health,

disciplinary matters).

  • Background and screening activities that go further than is reasonable.

Remember the tort requires a serious invasion that is intentional or reckless — not mere negligence — so the bar is meaningful. But it is a bar employers should be deliberately staying under.

Practical steps for employers

  • Review surveillance and monitoring practices: have a clear, communicated basis,

and avoid covert or excessive monitoring.

  • Be transparent with staff about what you collect and why.
  • Limit collection and retention of staff personal information to what you genuinely

need — the OAIC has flagged excessive collection and retention as a 2025–26 priority.

  • Secure staff data and build a breach-response process; see

the data-breach response plan.

  • Fold this into your broader obligations — see the

2026 compliance checklist.

Note that the interaction between the tort, employee-records handling and existing workplace-surveillance laws is complex and varies by state — this is exactly the kind of area to confirm with a qualified adviser.

Run the free checker to see your wider privacy obligations.

General information only, not legal or compliance advice. Current to June 2026; the interaction with state workplace-surveillance laws varies. Confirm your position at oaic.gov.au or with a qualified adviser. Last verified: 8 June 2026.

Run the free ML/TF risk assessment →

Frequently asked questions

Can an employee sue their employer under the new privacy tort?
The statutory tort lets individuals sue for a serious, intentional or reckless invasion of privacy via intrusion upon seclusion or misuse of information — which can include workplace conduct where a reasonable expectation of privacy existed. It applies regardless of the employer's turnover. Source — OAIC.
Does the small-business exemption protect employers from the tort?
No. The tort is broader than the Privacy Act and can reach non-APP entities, so being a small business does not make you safe from it. Source — OAIC.
Is this legal advice?
No. General information, current to June 2026. Confirm your position with a qualified adviser.
statutory tortemployer liabilityworkplace surveillanceaustraliaprivacy act 1988