What the Privacy Act reforms change

What passed in the Privacy and Other Legislation Amendment Act 2024, what commences on 10 December 2026, and what an Australian practice has to do differently.

Written by the aurii team

The Privacy and Other Legislation Amendment Act 2024 (Cth) added a statutory tort for serious invasions of privacy, in force since 10 June 2025, gave the Information Commissioner mid-tier and low-tier civil penalties, and amended Australian Privacy Principle 11.1 to state that reasonable security steps include technical and organisational measures. From 10 December 2026 a privacy policy must also describe substantially automated decisions that significantly affect a person. The small business exemption in section 6D of the Privacy Act 1988 (Cth) has never covered a business that provides a health service and holds health information.

An empty teal waiting room with two chairs and a potted plant

Changes already in force

The statutory tort for serious invasions of privacy sits in Schedule 2 to the Privacy Act 1988 (Cth), inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth) and commenced on 10 June 2025. It requires the invasion to be intentional or reckless and to be serious, and an individual sues directly, with no complaint to the Information Commissioner first.

Schedule 1 added a mid-tier civil penalty and a low-tier penalty enforceable by infringement notice. For a serious or repeated interference the ceiling, set by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth), is the greater of A$50 million, three times the benefit obtained, or 30 per cent of adjusted turnover.

Australian Privacy Principle 11.1 has required technical and organisational measures since December 2024, on the 2024 Act's amendment.

Erasure and clinical record retention

The Health Records and Information Privacy Act 2002 (NSW) and the Health Records Act 2001 (Vic) require an adult's health record to be kept for seven years from the last service, and a child's until that person turns 25, so a signed note is unlikely to be deletable at a patient's request.

Consultation audio, interim transcripts, unsigned drafts and processing logs sit outside the clinical record and carry no equivalent retention mandate, so an erasure right lands there first. A right to request erasure, agreed in principle in the Government Response of September 2023, needs further legislation.

The automated decisions disclosure

Australian Privacy Principle 1.7, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), commences on 10 December 2026. It requires a privacy policy to set out the kinds of personal information used in those decisions, and the duty runs on the policy alone, with no approval step and no separate register.

A scribe drafts a note that the clinician corrects and signs, so the decision affecting the patient is made by the clinician. The disclosure still reaches triage scoring, recall selection and appointment allocation.

Vendor questions under Australian Privacy Principle 11

APP 11.1 binds the practice for the information it holds, and engaging a vendor does not move that obligation. Put these to any scribe vendor in writing.

  • Where audio, transcripts and drafts are stored, and where the backups are held.
  • How long each artefact is retained, what deletes it, and whether deletion is automatic or run on request.
  • Whether patient content is used beyond the practice's own documentation, including model training.
  • Which encryption, access control, multi-factor authentication and audit logging controls are in place, and who assessed them.
  • What the vendor does during a notifiable data breach, and how fast it tells the practice.

Breach assessment and notification

The Notifiable Data Breaches scheme sits in Part IIIC of the Privacy Act 1988 (Cth). Section 26WH requires all reasonable steps to complete the assessment within 30 days, and that clock starts at the suspicion of an eligible data breach. An eligible data breach is notified to the Information Commissioner and to affected individuals under sections 26WK and 26WL.

aurii and Australian privacy law

The Australian Privacy Principles are mapped principle by principle on the compliance page.

Hosting and backups are in Australian regions. Where the data sits.

This is general information about the Privacy Act. It is not clinical or legal advice.

Start the free trial

Free 30-day trial. Create an account in the iPhone app or at app.aurii.com.au/signup. A card is added at signup on Stripe's checkout page; nothing is charged until the 30 days end.

hello@aurii.com.au