Jurisdiction Guides / Asia-Pacific
Australia Privacy & Data Protection Laws
Every regime below can apply to a business handling Australia residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Australia does not use the established-presence/offering/monitoring model — forcing it into that shape would be imprecise, so it's flagged here. The Act applies only to an 'APP entity' with an 'Australian link' (s5B): Australian citizens/residents, entities formed in Australia, or — for foreign entities — one that 'carries on business in Australia' (real, repeated, profit-directed activity; a mere accessible website is not enough). Modeled here as an established-presence trigger only. Small business operators (annual turnover up to AUD 3 million) remain generally exempt under s6D, unless an exception applies (health-service providers holding health information, entities trading in personal information, or Commonwealth-contracted providers) — removing this exemption has been recommended and remains government policy, but as of this writing it has not been legislated, so do not plan on it having lapsed. Three changes from the Privacy and Other Legislation Amendment Act 2024 do bite now or shortly: a statutory tort for serious invasions of privacy applies to conduct on or after June 10, 2025 and is available against any defendant, including entities the Privacy Act itself exempts; APP 1 transparency obligations for substantially automated decision-making that significantly affects individuals must be reflected in privacy policies by December 10, 2026; and 'tranche 2' AML/CTF reporting entities (real estate agents, dealers in precious metals and stones, lawyers, conveyancers, accountants, trust and company service providers) come within the Privacy Act for their AML/CTF activities from July 1, 2026.
Sector-Specific Law · 2
SOCI covers eleven sectors — including health care and medical, financial services and markets, data storage or processing, communications, energy, transport and higher education and research — and imposes register, risk-management and incident-notification duties on responsible entities for covered assets, with cyber incidents notifiable on short statutory timeframes and a critical infrastructure risk management program required and annually attested. The change that matters most for a data business came with the 2024 amendments: a DATA STORAGE SYSTEM can now form part of the primary critical infrastructure asset where the responsible entity owns or operates it, it is used in connection with the asset, it holds or processes business-critical data, and a hazard affecting it could have a relevant impact on the asset. That pulls storage and processing environments inside a regime many operators assumed applied only to the physical asset. Regulators also gained power to direct an entity to vary a risk management program with serious deficiencies.
The CDR is an open-banking-style data portability right, and its privacy dimension is the part businesses under-read: thirteen legally binding Privacy Safeguards in Part IVD apply to CDR data INSTEAD of the Australian Privacy Principles, not alongside them, so an organization can be subject to two different privacy regimes depending on which data is in issue. The Safeguards are generally stricter than the APPs — notably a near-prohibition on sending CDR data overseas except in strictly limited circumstances, which contrasts sharply with APP 8's accountability model, and a positive duty to delete or de-identify CDR data when it is no longer needed or when the consumer asks. Participation is compulsory for designated data holders (banks, and energy retailers in the National Electricity Market above a customer threshold) and voluntary but accreditation-gated for data recipients, who must pass an ACCC accreditation process. Enforced jointly by the ACCC and the OAIC.
Children & Minors Protections · 1
The first law of its kind: age-restricted social media platforms must take reasonable steps to prevent Australians under 16 from holding an account, for existing accounts as well as new ones. It is a platform obligation, not a parental-consent regime — there is no consent route that lets an under-16 on — and it is enforced against the provider by the eSafety Commissioner, with civil penalties up to 150,000 penalty units for a breach of the minimum-age obligation. Which services are age-restricted is set by the Minister working with the eSafety Commissioner rather than fixed in the statute, so scope is a live question a provider must track. The Act also requires the age-assurance steps taken to be reasonable, privacy-preserving, and proportionate, which puts it in direct tension with maximal identity verification and makes the eSafety Commissioner's regulatory guidance the operative document.
Cross-Border Data Transfer · 1
Australia does not restrict WHERE you send data; it makes you answer for what happens to it there. APP 8.1 requires taking reasonable steps to ensure an overseas recipient does not breach the APPs, and s. 16C then deems any such breach by the recipient to be a breach BY YOU — the accountability does not transfer with the data, and no contractual allocation of risk changes that as against the regulator. The practical consequences are that vendor due diligence and contractual APP flow-downs are the compliance artefact, and that a SOC 2 report or similar assurance is evidence toward reasonable steps rather than a substitute for them. APP 8.2 carves out exceptions, including where the recipient is subject to a substantially similar law the individual can enforce, or where the individual consents after being expressly told that APP 8.1 will not apply.
Data Security & Breach Notification · 1
Australia's scheme turns on an 'eligible data breach': unauthorised access, disclosure, or loss of personal information that a reasonable person would conclude is likely to result in serious harm. There is no fixed notification deadline — s. 26WK requires the statement to the Australian Information Commissioner as soon as practicable after the entity becomes aware there are reasonable grounds to believe an eligible data breach has occurred — but there IS a fixed assessment deadline, which is where most of the compliance risk sits: where an entity only suspects an eligible breach, it must take all reasonable steps to complete a reasonable and expeditious assessment within 30 days. Individuals at risk are notified with the same statement. Note the entity-level scope limit: the Privacy Act's small-business exemption (turnover of AUD 3 million or less, subject to exceptions) means some businesses fall outside the scheme entirely — an unusual carve-out among the regimes here, and one under active reform pressure.
Other Asia-Pacific jurisdictions