Privacy and Other Legislation Amendment Act 2024 (Australia)
Amends the Privacy Act 1988 (Cth) and Criminal Code Act 1995 (Cth). Royal Assent 10 December 2024. Introduces a statutory tort for serious invasion of privacy, criminal doxxing offences, a Children's Online Privacy Code, automated decision-making transparency, and enhanced OAIC enforcement powers.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
ADM Transparency
| Code | Title |
|---|---|
| AUPA24-2 | Automated Decision Making Transparency Notice |
Automated Decision-Making Transparency
Commences 10 December 2026 — Transparency requirements for automated decisions
| Code | Title |
|---|---|
| POLA24-ADM-1 | Privacy Policy Disclosure |
| POLA24-ADM-2 | Computer-Only Decision Disclosure |
Breach Notification
| Code | Title |
|---|---|
| AUPA24-9 | Eligible Data Breach Statement Disclosures |
Children Privacy
| Code | Title |
|---|---|
| AUPA24-3 | Children's Online Privacy Code Compliance |
Children's Online Privacy Code
Schedule 1, Part 4 — OAIC must develop a Children's Online Privacy Code by 10 December 2026
| Code | Title |
|---|---|
| POLA24-CHILD-1 | Code Development Requirement |
| POLA24-CHILD-2 | Services Covered |
| POLA24-CHILD-3 | Enforcement |
| POLA24-CHILD-4 | Consultation Requirements |
Civil Liability
| Code | Title |
|---|---|
| AUPA24-1 | Statutory Tort for Serious Invasions of Privacy |
Criminal Compliance
| Code | Title |
|---|---|
| AUPA24-4 | Doxxing Offence Prevention Controls |
Cross Border Transfer
| Code | Title |
|---|---|
| AUPA24-8 | Overseas Data Disclosure Country Designation |
Data Governance
| Code | Title |
|---|---|
| AUPA24-13 | Personal Information Inventory Maintenance |
Direct Marketing
| Code | Title |
|---|---|
| AUPA24-14 | Direct Marketing Opt Out Mechanisms |
Doxxing Offences
Criminal Code amendments — Commences 10 December 2024 (immediate effect)
| Code | Title |
|---|---|
| POLA24-DOX-1 | Standard Doxxing Offence (s 474.17C) |
| POLA24-DOX-2 | Aggravated Doxxing Offence (s 474.17D) |
Enhanced OAIC Enforcement Powers
Tiered civil penalty system — Commences 10 December 2024 (immediate effect)
| Code | Title |
|---|---|
| POLA24-ENF-1 | Infringement Notices |
| POLA24-ENF-2 | Mid-Level Civil Penalties |
| POLA24-ENF-3 | Serious Interference (s 13G Amended) |
| POLA24-ENF-4 | Compliance Notices |
| POLA24-ENF-5 | APP 11 Technical Measures |
| POLA24-ENF-6 | APP 8 Country Whitelisting |
Individual Rights
| Code | Title |
|---|---|
| AUPA24-16 | Privacy Complaints Handling |
Information Security
| Code | Title |
|---|---|
| AUPA24-11 | Technical and Organisational Security Measures |
International Cooperation
| Code | Title |
|---|---|
| AUPA24-10 | Information Sharing with Foreign Regulators |
People
| Code | Title |
|---|---|
| AUPA24-15 | Privacy Training and Awareness |
Privacy by Design
| Code | Title |
|---|---|
| AUPA24-12 | Privacy Impact Assessment Threshold Triggers |
Regulatory Cooperation
| Code | Title |
|---|---|
| AUPA24-7 | Information Commissioner Public Inquiries |
Regulatory Enforcement
| Code | Title |
|---|---|
| AUPA24-5 | Enhanced OAIC Enforcement Tier Framework |
Regulatory Engagement
| Code | Title |
|---|---|
| AUPA24-6 | OAIC Compliance Notice Response Capability |
Sensitive Data
| Code | Title |
|---|---|
| AUPA24-18 | Sensitive Information Additional Protections |
Statutory Tort for Serious Invasion of Privacy
Schedule 2 — Commences 10 June 2025. Creates a cause of action for serious privacy invasions.
| Code | Title |
|---|---|
| POLA24-TORT-1 | Intrusion Upon Seclusion |
| POLA24-TORT-2 | Reasonable Expectation of Privacy |
| POLA24-TORT-3 | Intentional or Reckless Invasion |
| POLA24-TORT-4 | Seriousness Requirement |
| POLA24-TORT-5 | Public Interest Balancing |
| POLA24-TORT-6 | Remedies and Damages Cap |
Vendor Risk
| Code | Title |
|---|---|
| AUPA24-17 | Third Party Processor Privacy Obligations |
Your Compliance Coverage
If you comply with Privacy and Other Legislation Amendment Act 2024 (Australia), you already cover:
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
8%
3 controls mapped
Compare →ISO/IEC 27400:2022
8%
3 controls mapped
Compare →Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011)
8%
3 controls mapped
Compare →+ 317 more: Angola Personal Data Protection Law (Law No. 22/11) (8%), CSA CCM v4 (8%)
See all 320 mapped frameworks ↓Maps to 320 other frameworks
Frequently Asked Questions
What is Privacy and Other Legislation Amendment Act 2024 (Australia)?
Privacy and Other Legislation Amendment Act 2024 (Australia) is a compliance framework from Australia with 23 domains and 38 controls. Amends the Privacy Act 1988 (Cth) and Criminal Code Act 1995 (Cth). Royal Assent 10 December 2024. Introduces a statutory tort for serious invasion of privacy, criminal doxxing offences, a Children's Online Privacy Code, automated decision-making transparency, and enhanced OAIC enforcement powers. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Privacy and Other Legislation Amendment Act 2024 (Australia) have?
Privacy and Other Legislation Amendment Act 2024 (Australia) has 38 controls organised across 23 domains. The largest domains are Enhanced OAIC Enforcement Powers (6 controls), Statutory Tort for Serious Invasion of Privacy (6 controls), Children's Online Privacy Code (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Privacy and Other Legislation Amendment Act 2024 (Australia) map to?
Privacy and Other Legislation Amendment Act 2024 (Australia) maps to 320 other compliance frameworks. The top mapping partners are Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) (8% coverage), ISO/IEC 27400:2022 (8% coverage), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Privacy and Other Legislation Amendment Act 2024 (Australia) compliance?
Start your Privacy and Other Legislation Amendment Act 2024 (Australia) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Privacy and Other Legislation Amendment Act 2024 (Australia) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 702 frameworks.
Get Started Free →Free forever — no credit card required