What Privacy Act actually requires
Australia's federal privacy law, structured around 13 Australian Privacy Principles (APPs). Cookies that identify or could reasonably identify an individual are treated as personal information. The OAIC (Office of the Australian Information Commissioner) enforces the law, and a substantial reform package is currently advancing through Parliament.
Key requirements
- Be open about how you handle personal information through a clear privacy policy
- Collect only personal information that is reasonably necessary
- Notify individuals at or before the time of collection
- Allow access and correction of personal information you hold
- Take reasonable steps to secure personal information from misuse
- Notify the OAIC and affected individuals of eligible data breaches
At a glance
Full name
Privacy Act 1988 (Australia)
Region
Australia
Status
In force since 1988, reform in progress
Who it affects
Australian Government agencies and private-sector organisations with annual turnover above AUD 3 million, plus all health service providers and some other categories regardless of size.
Penalties
Up to AUD 50 million, 3× the benefit obtained from the breach, or 30% of adjusted turnover for the period — whichever is highest. Penalties were sharply increased in late 2022.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
