You can now be sued for a privacy breach: Australia's new privacy tort, explained
Australians can now sue over serious invasions of privacy. What the statutory tort means for businesses that hold client data, and how to stay out of court.
For the first time, Australians can sue over a serious invasion of privacy — directly, personally, without waiting for a regulator. For businesses that hold client data, the risk calculus just changed shape.
Australia's privacy reforms introduced a statutory tort for serious invasions of privacy, live since June 2025. Until now, privacy enforcement mostly meant the OAIC acting after big breaches. The tort adds something different: an individual — a client, a patient, an ex-employee — with a direct legal claim against whoever invaded their privacy. Through 2026, the first cases are working through the courts, and the pattern of business exposure is becoming clear.
What does the tort actually cover?
The tort covers two kinds of serious invasion: intrusion upon seclusion (watching, listening, recording where a person reasonably expects privacy) and misuse of information relating to a person. The invasion must be serious, intentional or reckless, and the person must have had a reasonable expectation of privacy — with the claim balanced against public-interest considerations. Importantly, a claimant does not need to prove financial loss; distress can ground damages.
How does a normal business end up exposed?
Not by being evil — by being careless. The plausible paths for an ordinary business:
A breach that was foreseeable.
Client files exposed through security failures a court considers reckless — no MFA on a system holding sensitive records, years-old unpatched software, credentials shared in spreadsheets.
Misuse by an insider.
A staff member snooping records or leaking someone's file — with the business's controls (or absence of them) in the frame.
Surveillance overreach.
Monitoring staff or customers beyond what is reasonable and disclosed — a live issue as cameras and tracking tools get smarter.
Sensitive-data industries first.
Legal practices, health clinics and finance firms hold exactly the information whose misuse is most obviously "serious" — matter files, health records, financial affairs.
What's the practical defence?
The tort punishes recklessness, so the defence is demonstrable care. Concretely:
Security that matches the sensitivity
access controls, MFA and monitoring on the systems holding client records, mapped to a recognised baseline like the Essential Eight.
Least-privilege access
staff see the records their role needs, with access logged, so an insider incident is limited and provable.
Honest collection habits
hold what you need, delete what you do not; data you no longer hold cannot be misused.
A rapid, documented response
contained quickly and handled properly, an incident reads as misfortune; ignored, it reads as recklessness.
For legal and health practices this lands on top of existing professional obligations — our law-firm and healthcare security pages cover the sector-specific stack.
Frequently asked questions
Can someone sue us just because we were breached?
Being a victim of crime is not automatically a tort — the question is whether the invasion was intentional or reckless. A business that took reasonable, documented security steps is in a very different position from one that ignored known basics.
Does this replace OAIC penalties?
No — it adds to them. The OAIC's enforcement powers and the Notifiable Data Breaches scheme continue; the tort is a separate, personal avenue for individuals, which is what makes it novel.
Are small businesses exposed even under the $3M threshold?
Yes — this is the detail worth underlining. The tort is not bound by the Privacy Act's small-business exemption, so a business too small for the Act's obligations can still be sued for a serious invasion of privacy.
What single step most reduces this risk?
Lock down access to the systems holding your most sensitive records — MFA, least privilege, logging. Most misuse and most breaches run through exactly that gap.
Check your footing
If you hold sensitive client information and cannot point to the controls protecting it, that is now a legal exposure as well as a security one. A free health check shows you the gaps before someone else's lawyer does.
Related Key IT services
More insights
Automated decisions & your privacy policy
New Privacy Act rules from 10 December 2026 make businesses disclose automated decision-making…
Read article →RansomwareRansomware hits Australian construction
An Australian construction consultancy was listed by a ransomware crew this month. Why project…
Read article →Windows 10Windows 10 ESU: free vs paid
Consumer Windows 10 security updates now run to 2027 — but business terms are unchanged. What's…
Read article →Book your free IT & Cyber Security Review
See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.