In force since 10 June 2025Six chapters · sourced

A new way Australians can sue you directly for privacy invasions

A plain-English guide to Australia's statutory tort for serious invasions of privacy, which commenced 10 June 2025. Covers what the tort is, what an individual must prove, who is exposed, the operational controls that reduce exposure, and how the tort interacts with cyber insurance and management liability.

Drawn from OAIC guidance and the Privacy Act 1988 (Cth). Not legal advice. Specific situations should be reviewed with privacy counsel.

Direct cause of action

Individuals sue businesses in court

Four elements, with defences

Public interest and consent preserved

Small business exemption does not apply

Tort applies generally

Editorially reviewed
Last reviewed21 Jun 2026
Sources verified21 Jun 2026
01

What changed on 10 June 2025

Australia has, for the first time, a statutory privacy tort.

Individuals can sue businesses directly for serious privacy invasions.

On 10 June 2025, amendments to the Privacy Act 1988 (Cth) commenced that introduce a new statutory cause of action: a tort for serious invasions of privacy. For the first time in Australian law, individuals have a direct right to sue any person or organisation that seriously invades their privacy, whether through misuse of information or intrusion on seclusion. The cause of action sits in addition to existing Office of the Australian Information Commissioner (OAIC) enforcement, not instead of it.

01

Source legislation

The statutory tort was introduced through the Privacy and Other Legislation Amendment Act 2024 (Cth), commencing 10 June 2025. The cause of action sits within the Privacy Act 1988 (Cth).

Source · Privacy Act 1988 (Cth)
02

Plain-English summary from OAIC

The OAIC publishes plain-English guidance on the statutory tort, explaining what it covers, who it applies to, and how it relates to other privacy rights under Australian law.

Source · Statutory tort for serious invasions of privacy
03

Why it matters

Until 10 June 2025, an Australian individual whose privacy was invaded had limited direct remedies. They could complain to the OAIC, which could investigate and potentially issue a determination. The new tort gives them a direct cause of action in court, including the ability to seek damages, injunctions, and other relief.

04

First claims are already being filed

Law firms commenting publicly through 2025 and 2026 confirm that early claims are being brought under the new tort. Boards and insurers are paying attention because the tort creates a litigation pathway separate from OAIC enforcement.

02

What an individual has to prove

Four elements, with public interest and consent as defences.

The tort is gated, not a floodgate.

The tort is structured to be available where the invasion is genuinely serious, while preserving legitimate journalism, public interest reporting, law enforcement, and contractually consented activity. The four elements an individual must establish, and the defences a business can raise, are summarised below. This is not legal advice. Specific situations should be reviewed with privacy counsel.

01

Element 1 : Invasion of privacy

The defendant must have invaded the plaintiff's privacy either by (a) intruding upon the plaintiff's seclusion, or (b) misusing information that relates to the plaintiff.

02

Element 2 : Reasonable expectation of privacy

The plaintiff must have had a reasonable expectation of privacy in all the circumstances. This is an objective test informed by the context, the nature of the information or intrusion, and how the matter came to be invaded.

03

Element 3 : Seriousness

The invasion must be serious. Trivial breaches, minor administrative errors, and routine handling missteps are unlikely to meet the threshold. Cases involving health information, intimate images, sustained intrusion, or significant harm are the likely test cases.

04

Element 4 : Intentional or reckless

The invasion must have been intentional or reckless. Pure negligence is not enough. This narrows the tort significantly compared to the underlying Privacy Act obligations, where the OAIC can still enforce against negligent handling.

05

Defences : public interest

Public interest weighed against the privacy interest is a defence. This protects legitimate journalism, public interest reporting, and matters of public concern. Courts will assess the public interest test objectively.

06

Defences : consent and lawful authority

Consent of the plaintiff is a defence. So is conduct authorised or required by Australian law (including law enforcement and intelligence functions). Standard contractual data handling done with consent is unlikely to be tortious.

03

Who is exposed

Any Australian business handling personal information.

Including businesses currently outside the Privacy Act small business exemption.

The statutory tort is not limited to entities covered by the Australian Privacy Principles. It applies generally. That means Australian small businesses currently exempt from the Privacy Act under the $3 million turnover rule are still exposed to the tort. The 2026 Privacy Act reforms (removing the small business exemption) and the tort are running on parallel tracks. The tort is already live.

01

Small businesses currently exempt from APPs

The Privacy Act's small business exemption does not exempt a business from the statutory tort. A previously exempt business that seriously invades an individual's privacy is exposed to the tort regardless of turnover.

02

Employees and former employees

Employee records have historically benefitted from a partial Privacy Act exemption. The tort is not bound by that exemption. Employee health information, surveillance footage, and personal communications all sit within the potential scope of the tort.

03

Suppliers, contractors and vendors

Any third party handling personal information on behalf of an Australian business is in scope. Boards are now asking whether vendor due diligence covers the tort exposure. Most contracts written before June 2025 do not.

04

Customers, suppliers and members of the public

Any individual whose privacy is seriously invaded has standing. This includes customers, suppliers, prospective customers, members of the public photographed or recorded without authority, and former staff.

04

Operational controls

The same controls reduce tort exposure and improve Privacy Act posture.

Most of the work is documentation, governance, and access control.

The operational controls that reduce tort exposure overlap heavily with the existing Privacy Act work most Australian businesses are starting in 2026. Building those controls now serves two purposes: it reduces tort exposure today, and it positions the business for the removal of the small business exemption in 2026. The list below is proportionate and assumes a typical SMB or mid-market environment.

01

Personal information inventory

Know what personal information you hold, where it lives, who can access it, and why. A current inventory is the starting point for everything else.

02

Access controls and least privilege

Reduce who can access sensitive personal information. Enforce role-based access in Microsoft 365 and your line-of-business systems. Audit access quarterly. Most tort risk lives in over-broad access, not in malice.

03

Surveillance and recording policies

Document CCTV, call recording, screen monitoring, location tracking, and any other surveillance activity. Notify staff and visitors clearly. Most intentional intrusion claims will turn on whether the activity was reasonable and properly disclosed.

04

Email and messaging governance

Tighten distribution lists, sensitivity labels in Microsoft 365, and the use of personal devices for company communications. Most data leakage is preventable with sensitivity labels, conditional access, and DLP.

05

Vendor due diligence

Update vendor contracts to address the statutory tort. Confirm vendors have current cyber insurance, breach response procedures, and access controls that meet your standard.

06

Incident response with the tort in mind

When a privacy incident occurs, your response needs to address three audiences: the affected individuals (potential plaintiffs), the OAIC (potential investigator), and your insurer. Incident response documentation should reflect this.

05

Insurance and litigation

Cyber and management liability insurance is adapting.

Renewal questionnaires are starting to ask about the tort directly.

Australian cyber insurance and management liability insurance markets are adapting to the new statutory tort. Through late 2025 and into 2026, renewal questionnaires have started asking about tort awareness, surveillance policies, vendor due diligence, and incident response procedures with the tort in mind. Boards are increasingly asking the same questions. Both audiences want operational evidence rather than abstract policy statements.

01

Cyber insurance renewal questions to expect

Have you reviewed your privacy policies in light of the statutory tort? Do your vendor contracts address the tort? What is your incident response process for a serious invasion of privacy claim? Do you have a privacy officer or equivalent function?

02

Management liability is in scope

Directors and officers liability and management liability policies are being reviewed in light of the tort. Boards should ask their broker whether existing cover responds to a tort claim and whether sub-limits apply.

03

Class actions are plausible

Legal commentators expect the tort to give rise to class actions where a single intrusive practice has affected many individuals. Examples being discussed publicly include intrusive workplace surveillance, mass leakage of customer personal information, and inappropriate handling of intimate images.

04

Board reporting should include the tort

Quarterly board reporting should now include a brief privacy section that covers tort awareness, vendor due diligence status, and any incidents that could be tortious. Real Bytes covers this in our board reporting template.

Common questions

Questions Australian leadership teams are asking about the statutory tort.

Yes. The statutory tort applies generally and is not limited to entities covered by the Australian Privacy Principles. A small business currently exempt from the APPs under the $3 million turnover rule is still exposed to the tort.

The tort, Privacy Act 2026, and cyber insurance form one cluster

Operational controls that reduce tort exposure also strengthen Privacy Act posture and insurance renewal.

Real Bytes works with Australian businesses to build proportionate operational controls that address the statutory tort, the removal of the Privacy Act small business exemption in 2026, and the questions Australian cyber insurers and boards are now asking. Most of the work is documentation, access control, vendor due diligence, and incident response. We co-author it with privacy counsel where the matter warrants it.

This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.