Data Privacy

Privacy Act 1988 vs GDPR: What Australian Businesses Must Know

The 13 Australian Privacy Principles against the GDPR's structure: lawful bases, consent, data subject rights, the NDB scheme vs Art. 33/34, OAIC vs EU supervisory authorities, and the reform direction.

An Australian company that has built its privacy programme around the Privacy Act 1988 (Cth) has a real compliance asset, but it maps onto the GDPR less cleanly than it appears. The two regimes share vocabulary and diverge on structure. This page sets out where they align, where they do not, and which gaps you have to close if the GDPR applies to your Australian company under Art. 3(2).

Stated at the outset, because it is the point most often assumed away: Australia holds no EU adequacy decision. Verified against the European Commission’s published list on 30 July 2026. Adequacy is not equivalence, and the absence of a decision is the Commission’s formal position that Australian law does not deliver an essentially equivalent level of protection.

Key takeaways

  • The APPs regulate collection, use and disclosure by reference to purpose and reasonable necessity. The GDPR requires an affirmative lawful basis under Art. 6 for every purpose, and a second condition under Art. 9 for health and other special category data.
  • The AU$3 million small business exemption in s 6D has no GDPR counterpart. Health service providers holding health information are already outside that exemption under Australian law in any event.
  • The Notifiable Data Breaches scheme allows up to 30 days to assess. Art. 33 GDPR requires notification within 72 hours of becoming aware, at a lower harm threshold.
  • Australia has one regulator, the OAIC. The EU has one per member state, and a non-EU controller does not get the one-stop-shop.
  • The 2024 amendments are commencing in stages; the more consequential “tranche two” reforms remain a government commitment, not enacted law, as at 30 July 2026.

Structure: principles versus lawful bases

The Privacy Act operates through 13 Australian Privacy Principles set out in Schedule 1. They are sequenced along the information lifecycle: APP 1 open and transparent management, APP 3 collection of solicited personal information, APP 5 notification at collection, APP 6 use and disclosure, APP 7 direct marketing, APP 8 cross-border disclosure, APP 11 security and destruction, APP 12 access, APP 13 correction.

The GDPR’s spine is different. Art. 5 states six principles, Art. 6 then requires that every processing purpose rest on one of six lawful bases, and Art. 9 prohibits processing special category data unless a further condition applies. There is no general APP equivalent of the Art. 6 lawful basis analysis. Under the Privacy Act, collection is permitted where it is reasonably necessary for one or more of the entity’s functions or activities; under the GDPR, “we need it for our business” is not a basis, and legitimate interest — the closest analogue — requires a documented three-part balancing test that can be produced on request.

The practical consequence is a documentation gap rather than a values gap. An Australian entity migrating to the GDPR usually finds it is doing defensible things for undocumented reasons. Building an Art. 30 record of processing activities with a lawful basis recorded per purpose is normally the largest single piece of work.

Sensitive information versus special categories

APP 3.3 requires consent to collect sensitive information, which s 6(1) defines to include health information, genetic and biometric information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation and criminal record. Art. 9(1) GDPR prohibits processing of a closely similar list unless an Art. 9(2) condition applies.

The lists overlap; the mechanics do not. Under the Privacy Act, consent unlocks collection and the analysis largely stops there. Under the GDPR the Art. 9 condition is cumulative with the Art. 6 basis, explicit consent under Art. 9(2)(a) is a higher standard than ordinary consent, and legitimate interest is not available at all for special category data. For health-sector companies this is the single most consequential divergence: two bases, both documented, plus a data protection impact assessment that Art. 35(3)(b) makes effectively mandatory for large-scale health processing.

The small business exemption — and why it buys you nothing

Section 6D exempts “small business operators” with an annual turnover of AU$3 million or less from the APPs. The exceptions in s 6D(4) already remove much of the health sector: an entity that provides a health service and holds health information is an APP entity regardless of turnover, as are entities that trade in personal information, credit reporting bodies, and Commonwealth contracted service providers.

Under the GDPR, none of this matters. Art. 3 contains no turnover threshold, no headcount threshold and no volume threshold. A two-person Australian consultancy with European clients is subject to the same obligations as a listed company. The only size-sensitive relief in the whole regulation is the Art. 30(5) derogation for organisations under 250 employees, and it is narrower than it looks: it falls away where processing is not occasional, is likely to result in a risk to rights and freedoms, or involves special category data — which describes essentially every business with recurring European customers.

One recent and easily missed change runs the other way. From 1 July 2026, businesses that become reporting entities under the anti-money-laundering regime must handle personal information in accordance with the APPs for AML/CTF purposes even where they would otherwise be small-business exempt. It is a targeted carve-out from s 6D, not a general repeal.

Both regimes recognise express and implied consent. The GDPR narrows it considerably. Art. 7 and Art. 4(11) require consent to be freely given, specific, informed and unambiguous, given by a clear affirmative act, as easy to withdraw as to give, and separable from other terms. Silence, pre-ticked boxes and continued use of a service do not constitute consent. Where consent is a condition of a contract that does not require the processing, Art. 7(4) treats it as not freely given.

Australian guidance on implied consent through continued use is meaningfully more permissive. Bundled consent across a suite of purposes — common in Australian terms of service — will not survive GDPR scrutiny. For direct marketing, APP 7 operates on an opt-out logic with a right to request cessation; the GDPR combines an absolute right to object under Art. 21(2) with the ePrivacy Directive’s prior-consent rule for electronic marketing, which is stricter than the Spam Act 2003 in most configurations.

Individual rights

Right Privacy Act 1988 GDPR
Access APP 12; response generally within 30 days; a non-excessive charge is permitted Art. 15; one month, extendable by two; first copy free
Correction APP 13 Art. 16
Erasure No individual right. APP 11.2 obliges the entity to destroy or de-identify when no longer needed Art. 17, enforceable by the individual
Portability None in force Art. 20
Objection Direct marketing only, APP 7 Art. 21, including profiling
Automated decisions Privacy-policy transparency obligation commencing 10 December 2026 Art. 22, a substantive right not to be subject to solely automated decisions with legal or similarly significant effects

The pattern is consistent: the Privacy Act imposes duties on entities where the GDPR confers rights on individuals. Duties are audited; rights are exercised, at any time, by anyone, with a one-month clock and no fee. That difference reshapes operations more than any drafting change.

Breach notification: 30 days is not 72 hours

The Notifiable Data Breaches scheme in Part IIIC has applied since 22 February 2018. On suspecting an eligible data breach, s 26WH requires a reasonable and expeditious assessment, with all reasonable steps taken to complete it within 30 calendar days. Once there are reasonable grounds to believe an eligible breach has occurred, s 26WK requires notification to the Commissioner and to affected individuals as soon as practicable. An “eligible data breach” requires unauthorised access, disclosure or loss that is likely to result in serious harm, where remedial action has not removed that likelihood.

Art. 33 GDPR runs on a different clock and a different threshold. Notification to the supervisory authority is due within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to rights and freedoms — a lower bar than serious harm. Where the breach is likely to result in a high risk, Art. 34 requires communication to affected individuals without undue delay. There is no assessment window that stops the clock; incomplete notifications are made in phases under Art. 33(4).

An Australian incident response runbook built to the NDB scheme will therefore miss the GDPR deadline by design. The remedy is procedural: a 72-hour track that runs in parallel with the Australian assessment rather than after it.

Regulators

Australia has a single national regulator, the OAIC, exercising the functions of the Australian Information Commissioner and the Privacy Commissioner. Its powers include investigation on complaint or own motion, enforceable undertakings, determinations, and civil penalty proceedings in the Federal Court. Section 13G addresses serious or repeated interferences with privacy; since December 2022 the maximum civil penalty has been the greater of AU$50 million, three times any benefit obtained, or 30% of adjusted turnover in the relevant period, and the 2024 amendments added lower tiers for less serious contraventions.

Those powers are no longer theoretical. In Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224, the Federal Court imposed the first civil penalties under the Privacy Act: AU$5.8 million in total, comprising AU$4.2 million for failing to take reasonable steps to protect personal information under APP 11.1 across more than 223,000 individuals, AU$800,000 for failing to assess the breach within 30 days under s 26WH(2), and AU$800,000 for failing to notify as soon as practicable under s 26WK(2), together with a AU$400,000 costs contribution.

The EU has an authority in each member state, coordinated by the European Data Protection Board through the Art. 63 consistency mechanism. Australian companies routinely assume the Art. 56 one-stop-shop will give them a single European counterpart. It will not: the one-stop-shop is available only to controllers with a main establishment in the Union. A controller in scope under Art. 3(2) with no EU establishment can be approached by any supervisory authority in whose territory affected data subjects are located, and the EDPB has said so expressly in its territorial-scope guidelines. Fines follow the two bands of Art. 83: EUR 10 million or 2%, and EUR 20 million or 4%, of worldwide annual turnover.

Reform direction, as at 30 July 2026

The Privacy and Other Legislation Amendment Act 2024 received assent on 10 December 2024 and is commencing in stages. The statutory tort for serious invasions of privacy commenced on 10 June 2025. The obligation to disclose in a privacy policy the use of automated decision-making that significantly affects individuals commences on 10 December 2026 — a transparency duty, not an Art. 22-style right. The OAIC is developing a Children’s Online Privacy Code. New criminal offences targeting doxxing were also introduced.

The larger changes — a “fair and reasonable” test for collection, use and disclosure, a direct right of action for individuals, and removal of the small business exemption — sit in a second tranche that remains a government commitment. No second-tranche Bill had passed as at 30 July 2026 and no commencement date has been fixed. Treat these as direction rather than deadline, and check the current position before relying on any date.

None of it changes the GDPR analysis. Australian reform narrows the gap; it does not close it, and it has no bearing on adequacy, which is a separate Commission process that Australia has not undergone.

FAQ

If we comply with the Privacy Act, how much GDPR work is left?

Typically the gap sits in four places: documented lawful bases per purpose, a complete Art. 30 record, an operational data subject rights process running to a one-month clock at no charge, and a transfer file. Security and breach handling usually transfer across with modest changes to timing.

Does the small business exemption help us with European customers?

No. It is a feature of Australian law only. There is no equivalent threshold anywhere in the GDPR’s territorial scope provisions.

Is APP 8 the same as the GDPR’s transfer rules?

No, and the direction differs. APP 8 governs disclosure out of Australia and holds the discloser accountable under s 16C for the overseas recipient’s acts. The GDPR governs transfers out of the EEA, and requires an Art. 45 adequacy decision or an Art. 46 safeguard such as Standard Contractual Clauses. Since Australia has no adequacy decision, the practical route is set out in our page on Australia–EU data transfers.

Which tooling handles both regimes?

Anything you buy has to keep an Australian APP-facing record and a GDPR Art. 30 record from the same underlying inventory, or you will maintain two. Our buying guide to GDPR compliance software for Australian companies covers the dual-register requirement, and our comparison of the GDPR against the CCPA applies the same method to the US.

Legiscope automates this for you

Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.

Start free trial
TD
Written by
Fondateur de Legiscope et expert RGPD

Docteur en droit de l'Université Panthéon-Assas (Paris II), 23 ans d'expérience en droit du numérique et conformité RGPD. Ancien conseiller de l'administration du Premier ministre sur la mise en œuvre du RGPD. Thiébaut est le fondateur de Legiscope, plateforme de conformité RGPD automatisée par l'IA.

View full author profile →