Privacy Act 2026
The Privacy Tort and Your Workplace: Employer Liability Risks You Didn't See Coming (Australia)
How Australia's statutory tort for serious invasions of privacy (in force since 10 June 2025) creates new employer exposure — workplace surveillance, monitoring and handling of staff information. Plain English, source-checked.
Most coverage of Australia's new privacy tort focuses on customers. But employers have their own exposure — because workplaces involve monitoring, recording and handling a lot of personal information about staff. Since the statutory tort came into force on 10 June 2025, that exposure is sharper. Here is what employers should understand.
A quick recap of the tort
The statutory tort lets individuals sue for a serious, intentional or reckless invasion of privacy through intrusion upon seclusion or misuse of information, where they had a reasonable expectation of privacy and that interest outweighs competing public interest. It is run by the courts, not the OAIC, and — this is the key point for employers — it can reach businesses the Privacy Act itself does not cover, regardless of turnover. The full mechanics are in the statutory tort explained. (Source: OAIC.)
Where workplace exposure can arise
Common workplace activities can intersect with the tort where a reasonable expectation of privacy exists and conduct is intentional or reckless. Areas to think carefully about include:
- Surveillance and monitoring — cameras, device and computer monitoring, location
tracking, and covert recording.
- Excessive or intrusive collection of staff personal information beyond what the
role needs.
- Mishandling or improper disclosure of sensitive staff information (health,
disciplinary matters).
- Background and screening activities that go further than is reasonable.
Remember the tort requires a serious invasion that is intentional or reckless — not mere negligence — so the bar is meaningful. But it is a bar employers should be deliberately staying under.
Practical steps for employers
- Review surveillance and monitoring practices: have a clear, communicated basis,
and avoid covert or excessive monitoring.
- Be transparent with staff about what you collect and why.
- Limit collection and retention of staff personal information to what you genuinely
need — the OAIC has flagged excessive collection and retention as a 2025–26 priority.
- Secure staff data and build a breach-response process; see
the data-breach response plan.
- Fold this into your broader obligations — see the
Note that the interaction between the tort, employee-records handling and existing workplace-surveillance laws is complex and varies by state — this is exactly the kind of area to confirm with a qualified adviser.
Run the free checker to see your wider privacy obligations.
General information only, not legal or compliance advice. Current to June 2026; the interaction with state workplace-surveillance laws varies. Confirm your position at oaic.gov.au or with a qualified adviser. Last verified: 8 June 2026.
Run the free ML/TF risk assessment →