WorldPrivacyAtlasInternational Privacy & Data Protection Law Matcher

Jurisdiction Guide

Australia Privacy & Data Protection Laws

Every regime below can apply to a business handling Australia residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

January 1, 1989 (Act); March 12, 2014 (current Australian Privacy Principles)
Privacy Act 1988 (Cth), incorporating the Australian Privacy Principles
Privacy Act / APPs
Verify details

Australia does not use the established-presence/offering/monitoring model — forcing it into that shape would be imprecise, so it's flagged here. The Act applies only to an 'APP entity' with an 'Australian link' (s5B): Australian citizens/residents, entities formed in Australia, or — for foreign entities — one that 'carries on business in Australia' (real, repeated, profit-directed activity; a mere accessible website is not enough) AND collected/held the information in Australia. Modeled here as an established-presence trigger only. Small business operators (annual turnover ≤ AUD 3 million) are generally exempt under s6D, unless an exception applies (health-service providers holding health information, entities trading in personal information, or Commonwealth-contracted providers) — reform to remove this exemption has been proposed but not yet legislated.

Privacy Act 1988 (Cth), No. 119, 1988, as amended; 'Australian link' test: s5B; small-business exemption: ss 6C-6DRead regulation →