Reflecting on the increased number of data breach notifications in Australia, with 2024 having marked the highest number of notifications since the NDB Scheme commenced in 2018, the Australian Privacy Commissioner (Commissioner) warned businesses against the continuing security challenges perpetuated by unnecessary data collection practices. In the same keynote address held at the 2025 IAPP Privacy event during Privacy Awareness Week last month, Ms Kind reminded corporate entities of its obligations to collect personal information that is reasonably necessary for one or more of its functions (under APP 3.2) and only by lawful and fair means (under APP 3.5). In similar sentiment, ASIC Chair Joe Longo emphasised ASIC’s 2025 enforcement priority of taking action against AFS licensees who fail to have adequate cyber-security protections, as demonstrated in the regulator’s recent civil penalty proceedings against FIIG Securities Limited and Fortnum Private Wealth.
In addition to this timely reminder, we summarise in this alert the key developments in the data and privacy space over the past six months that businesses should be aware of.
The new requirement that business operation in Australia report ransomware payments commenced on 30 May 2025.
The new regime requires “reporting business entities” to give a ransomware payment report to the Australian Signal Directorate (ASD), within 72 hours of making a payment or benefit to an extorting entity (or becoming aware that the ransomware payment has been made).[1]
“Reporting business entity” is defined under s 26(2) of the Cyber Security Act 2024 (Cth) as:
The Reporting Rules[3] specify the information which must be provided with the ransomware payment report, being the following:
Failure to report within the prescribed timeframe may attract a civil penalty of up to AU$19,800.
Helpfully the Australian Government (via Home Affairs) has confirmed that the implementation of the new reporting obligations will occur in two stages, being:
Australia’s new statutory tort for serious invasions of privacy took effect from 10 June 2025.
As covered in our previous alert here, claimants must prove five elements to establish a cause of action under the new tort, including that: the invasion of the claimant’s privacy by intrusion upon seclusion and/or misuse of information had occurred, where the claimant had a reasonable expectation of privacy, and such invasion was intentional or reckless. The invasion of privacy must be serious and the public interest in the claimant’s privacy must outweigh the countervailing public interest.
The Privacy Act explicitly exempts groups of individuals and provides defences. Read our alert here for remedies available under this tort, the strategic defences and exemptions, limitation period, and key considerations for businesses.
As part of its development of the Children’s Online Privacy Code (Code), the Office of the Australian Information Commissioner (OAIC) concluded Phase 1 of its consultation phase with children, parents, teachers and relevant organisations focused on children’s welfare on 30 June 2025. Phase 1 focused on gathering feedback on community expectations and views on children’s online privacy. Phase 2 commenced in April 2025, involving insight from industry, civil society and academia and will conclude on 31July 2025.
The OAIC has confirmed that a draft Code will be released in early 2026 for public consultation (i.e. Phase 3), with a view to have the Code ready and in place by 10 December 2026. The OAIC has confirmed that Phase 3 consultation will last a minimum of 60 days.
Social media services, electronic services or designated internet services accessed by children and/or regularly dealing with the personal information of children and young people are highly encouraged to review its current data collection and handling practices now to be ready to comply with the upcoming Code.
In particular, businesses operating or accessible in Australia should consider data practices such as profiling, direct marketing and targeted advertising, as well as any emerging harms from artificial intelligence (AI) affecting children.
Further updates from our team on developments in this area will be continued to be published here.
For assistance with preparing any submissions during the Phase 3 public consultation (in early 2026), please reach out to any of our team.
Businesses who are considered ‘designed data holders’ under Australia’s Consumer Data Right (CDR) regime[4] are reminded of its APP 1 and APP 11 obligations in consideration of the OAIC’s recent CDR determination which clarified the position of liability for actions of third-party providers.
On 14 May 2025, the OAIC handed down its first CDR determination against Regional Australia Bank (RAB).[5] The OAIC determined that RAB, in its capacity as a data holder had breached APP 1 and APP 11 through the conduct of its third-party service provider, Biza. This determination clarifies the OAIC’s position on liability for businesses where outsourcing is involved.
The Commissioner found that:
The Commissioner declared that RAB review and consider opportunities to strengthen the terms of its contractual agreement with Biza and implement documented processes to ensure that it proactively reviews and monitors its compliance with the Privacy Safeguards and the APPs in circumstances where it continues to outsource CDR functions to a third party.
RAB, because of its remediation efforts, and lack of evidence of loss suffered by affected customers, did not face a fine from the privacy regulator.
By 11 December 2025, certain social media platforms will be required to take reasonable steps to prevent children under the age of 16 from having accounts on its platforms under Australia’s new age-restriction laws. Specifically, “age-restricted social media platforms”, defined to include but not limited to electronic services which has a sole or significant purpose to enable online social interaction between 2 or more end-users, interaction with some or all other end-users, and allows end-users to post material on the services will be captured under the new regime.
There is a delayed effect of the requirement for age-restricted social media platforms to take reasonable steps to prevent age-restricted users having accounts, with civil penalty units for a contravention of this requirement to be taken place on a day specified by the Minister for Communications (to be no later than 11 December 2025). Once effective, the contravention will attract a civil penalty of up to AU$9.9 million (s 63D of the Act). The regime also imposes additional obligations on age-restricted social media platforms relating to data collection and empowers the Commissioner with information gathering powers under Division 4 of the Act for the purpose of compliance with s 63D.
Expressions of interest to be consulted for the development of guidelines as part of the new Online Safety Amendment (Social Media Minimum Age) Act 2024 (the Act) ended on 18 May 2025. The Australian eSafety has confirmed that it will work with the OAIC to ensure that the guidelines interlock with the OAIC’s complementary regulatory guidance, and once the age restrictions come into effect, will be responsible for the monitoring, assessing and enforcing industry’s compliance with them.
As we move through 2025 and beyond, it is clear that the era of reactive compliance is over. The message from regulators is unambiguous - data protection is not a compliance checkbox but a fundamental business imperative that requires ongoing investment, attention, and strategic planning. The Australian Government continues to focus on implementing increased robust cybersecurity measures through legislative changes, demanding proactive attention and oversight by businesses. Our team is here to ensure that businesses are best positioned to navigate the changes in this evolving regulatory environment.
Stay tuned for the next alert covering period July to December 2025.
For any questions to any of the developments above, please do not hesitate to contact our Australia Data Privacy experts.
[1] Cyber Security Act 2024 (Cth), s 27(1).
[2] The turnover threshold is set under the Cyber Security (Ransomware Payment Reporting) Rules 2025 (the Reporting Rules).
[3] For a full list, see rule 7 of the Reporting Rules.
[4] The CDR enables consumers of certain businesses within the banking and energy sectors in Australia to require information relating to themselves to be disclosed to themselves or to other businesses in those sectors. All Australian banks, and energy retailers which operate through the National Electricity Market (NEM) with more than 10,000 customers, are required to participate in the CDR.
[5] Commissioner Initiated Investigation into Regional Australia Bank Limited (Privacy) [2025] AICmr 89 (14 May 2025).