The Privacy Act Changed. Here's What Actually Applies to You Now.

The Privacy Act Changed. Here's What Actually Applies to You Now.

7/30/2026 · Compliance365

If the last time you looked closely at your privacy obligations was before the Privacy Act reforms, your processes are almost certainly out of date. Mandatory breach notification has tightened, there's a new governance requirement over automated decision-making, and the penalties for getting it wrong have gone up sharply.

None of this requires ISO 27701 certification to fix. It requires knowing what changed, and checking a handful of specific things this month rather than finding out during a regulator inquiry.


What actually changed

Three changes matter most for a mid-market Australian business right now:

Breach notification is tighter. The window and threshold for notifying the OAIC and affected individuals after an eligible data breach has narrowed, and the bar for what counts as “eligible” is lower than most businesses assume. If your incident response plan still says “assess, then decide if it’s notifiable” with no defined clock, that’s the first gap to close.

Automated decision-making now needs governance, not just a privacy policy line. If your business uses automated or AI-assisted systems to make decisions that materially affect individuals — credit, employment screening, pricing, eligibility — there are now specific transparency and accountability expectations attached to that. A privacy policy that mentions “we may use automated processing” in one sentence no longer reflects what’s actually expected.

Penalties are materially higher. The regulator’s tolerance for “we didn’t have a formal process” has dropped. Enforcement activity is trending toward treating undocumented or informal privacy practices as an aggravating factor, not a neutral one.


Who this actually affects

This isn’t just for businesses already thinking about ISO 27701 or handling health records. It affects any Australian organisation that:

  • Holds customer or employee personal information (which is almost everyone)
  • Has ever had to think about what happens if a laptop is lost, an account is compromised, or a vendor is breached
  • Uses any automated or algorithmic system to make a decision about a person — even something as simple as automated credit scoring, resume screening, or dynamic pricing

If none of that is currently written down anywhere — no defined breach-response clock, no register of where automated decisions are made — that’s the gap, regardless of whether you’ve ever considered formal privacy certification.


Five things to check this month

  1. Do you have a defined, timed breach-response process? Not a policy document — an actual runbook: who assesses, against what criteria, on what clock, and who has authority to decide it’s notifiable.
  2. Do you know every place your business uses automated decision-making? Most businesses can’t answer this without checking, because it’s often adopted by a single team (marketing, HR, credit) without anyone maintaining a central list.
  3. Is there a person accountable for privacy, by name? Not “the IT team” — a named individual who owns the breach-response decision and the automated-decision register.
  4. Have your vendor contracts been reviewed for breach-notification flow-down? If a vendor is breached and holds your customers’ data, do you find out in time to meet your own notification clock?
  5. Is there a record of any of this? If a regulator asked for evidence tomorrow, could you produce it, or would you be writing it retrospectively?

If more than one of these is a “no,” that’s worth a proper look before it becomes a live incident rather than a planning exercise.


How this relates to ISO 27701

ISO 27701 is the broader, certifiable privacy management framework — ROPAs, DPIAs, consent management, third-party privacy risk, the full system. It’s the right answer if you need a defensible, audit-ready privacy programme end to end, particularly for enterprise procurement or regulated-sector customers.

But you don’t need to be pursuing ISO 27701 to have a breach-notification clock or an automated-decision register. Those are baseline Privacy Act compliance now, not framework extras. Our free ISO 27701 privacy readiness checklist covers both of these areas alongside the full PIMS scope — it’s a fast way to see exactly where the specific reform-driven gaps sit, whether or not certification is on your radar at all.

Worried about the breach-notification or automated-decision changes specifically? A 30-minute call is enough to tell you whether your current process actually meets the reformed obligations, and what the fastest fix looks like if it doesn't.

Take the free privacy readiness checklist first if you want a starting picture, or book a call directly if you already know this is a gap.

Share this article: Share on LinkedIn

Found this useful? Get the ISO/Privacy/AI readiness checklists.

Browse resources

Ready to take the next step?

ISO 27701 Privacy

Privacy Information Management System aligned to the Australian Privacy Act 1988.

Learn more Book a free call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.

Microsoft Teams