Skip to content

OAIC determinations and privacy enforcement digest for real-estate and small business

Four of the five decisions digested here are OAIC determinations, and each ended in declarations and remedial orders with no civil penalty. A determination cannot impose one: s 52(1) of the Privacy Act 1988 (Cth) sets out what a determination may contain after a complaint and s 52(1A) what it may contain after a Commissioner-initiated investigation, and neither list has a penalty limb. Both do allow a declaration that an individual is entitled to a specified amount by way of compensation for loss or damage, which is money paid to that individual rather than a penalty. A pecuniary penalty is a separate track: under s 80U the Commissioner is an authorised applicant and applies to the Federal Court, or the Federal Circuit and Family Court of Australia (Division 2). For the administrative contraventions in s 13K there is a third route with no court in it, because s 80UB(2)(a) makes the Commissioner an infringement officer who may give an infringement notice. The fifth decision is the court track: a total civil penalty of AUD 5.8 million against Australian Clinical Labs Limited, ordered on 8 October 2025 over a breach affecting more than 223,000 individuals, and the first civil penalty ordered under the Privacy Act. That conduct occurred in 2022, so the maxima applied to it were the historic ones, not the current regime. The two findings that recur across the set are collecting more than is reasonably necessary (APP 3) and being slow to assess and to notify (ss 26WH, 26WK).

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Privaproof is not a law practice.

This page digests published regulator decisions and one Federal Court judgment in our own words, with links to the primary sources. It does not assess your circumstances, and outcomes turn on their own facts. Verify every citation against the primary text before relying on it.

For people running or advising Australian real-estate agencies and other small businesses that handle tenant, buyer and vendor data. Each entry gives the case name and medium-neutral citation, the date, the provisions engaged, a plain-English account of what happened, the outcome, and a short note on why it matters for agencies. We summarise each decision in our own words; where a phrase carries the test, we quote it, with the paragraph pinpoint where we hold one, so every statement here can be checked against the primary text.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Every decision in this digest

#Case and citationDateProvisions engagedOutcome
1Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 241 Apr 2026APP 3.2, APP 3.5Declarations; cease listed fields in 60 days, independent reviewer; no civil penalty. The OAIC APP Guidelines, Chapter 3, updated 13 May 2026, record this determination as under review in the Administrative Review Tribunal
2Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 12248 Oct 2025APP 11.1; ss 26WH(2), 26WK(2); s 13GAUD 5.8 million civil penalty, by consent
3Commissioner Initiated Investigation into 7-Eleven Stores Pty Ltd (Privacy) [2021] AICmr 5029 Sep 2021APP 3.3, APP 5Declarations; destroy faceprints within 90 days; no civil penalty
4Datateks Pty Ltd (Privacy) [2023] AICmr 9724 Oct 2023ss 26WH(2), 26WK(2)Declarations; incident-response plan within 3 months; no civil penalty
5Pacific Lutheran College (Privacy) [2023] AICmr 9824 Oct 2023APP 11.1; ss 26WH(2), 26WK(2)Declarations; incident-response plan and security program within 6 months; no civil penalty

How the penalty provisions are built

Before the cases, one point about the structure of the penalty provisions.

Since the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth), in force 13 December 2022, and as narrowed by the Privacy and Other Legislation Amendment Act 2024 (Cth) from 11 December 2024, section 13G of the Privacy Act 1988 (Cth) applies to a serious interference with privacy. The figures below are the current maxima and apply to conduct on or after 13 December 2022. The Australian Clinical Labs conduct occurred in 2022, before that date, so the maxima the Court applied in that case are historic and are not an application of the current regime. For a body corporate, s 13G(3) sets the maximum at the greatest of:

For a person other than a body corporate the maximum is AUD 2,500,000. Those figures are fixed dollar amounts in the statute rather than penalty units, so they do not index.

Sections 13G, 13H and 13K are three civil-penalty provisions that overlap, rather than three rungs of a ladder. Section 13G(1) requires the interference to be serious. Section 13H(1) has no seriousness element at all: an entity contravenes it "if the entity does an act, or engages in a practice, that is an interference with the privacy of an individual", and s 13H(3) sets the penalty at not more than 2,000 penalty units. Section 13J provides that in proceedings for a contravention of s 13G, a court that is satisfied there was an interference but is not satisfied it was serious may make a pecuniary penalty order under s 13H instead.

Section 13K is headed "Civil penalty provision for which infringement notices or compliance notices can be issued". Section 13K(1)(b) lists the principles whose breach contravenes it, and the first two it names, in the Act's own bracketed words, are "Australian Privacy Principle 1.3 (requirement to have APP privacy policy)" and "Australian Privacy Principle 1.4 (contents of APP privacy policy)". Section 13K(4) sets the penalty at not more than 200 penalty units. The notice powers sit elsewhere: s 80UB(1)(a) makes s 13K(1) and (2) subject to an infringement notice under Part 5 of the Regulatory Powers (Standard Provisions) Act 2014 (Cth), s 80UB(2)(a) makes the Commissioner an infringement officer, and s 80UC(1) allows the Commissioner to give a compliance notice. Under s 103(1) of that Act an infringement officer who "believes on reasonable grounds" that a person has contravened the provision "may give" the notice, and s 103(2) requires it to be given within 12 months of the alleged contravention. These provisions commenced on 11 December 2024.

Two provisions stop the tiers stacking. The note to s 13K(1) says "Conduct that contravenes this section may also contravene section 13G or 13H", and s 84(2) of the Regulatory Powers Act says a person "is not liable to more than one pecuniary penalty under this Part in relation to the same conduct". Contravening a civil-penalty provision is also not the same as being penalised: under s 82(1) and (2) only an authorised applicant may apply, within 6 years, and under s 82(3) the court "may order the person to pay to the Commonwealth such pecuniary penalty for the contravention as the court determines to be appropriate".

The 2,000 and 200 unit figures are what the Privacy Act specifies. Section 82(5)(a) of the Regulatory Powers Act then provides that where the person is a body corporate the penalty "must not be more than ... 5 times the pecuniary penalty specified for the civil penalty provision", so for an incorporated entity the maxima are 10,000 penalty units under s 13H and 1,000 under s 13K. Section 13G(4) expressly disapplies that multiplier for s 13G, which is why the AUD 50,000,000 figure above is not multiplied.

These are statutory maximums, not automatic penalties, infringement-notice amounts or standard fines. The applicable enforcement pathway and amount depend on the relevant provision, the conduct and the circumstances.

Penalty-unit values are indexed under s 4AA of the Crimes Act 1914 (Cth), and the indexed amount is published by the Minister as a notifiable instrument under s 4AA(1A) rather than reprinted in the Act. The instrument in force is the Crimes (Amount of a Penalty Unit) Instrument 2026 (Cth), F2026N00424, registered 16 June 2026, which sets the unit at AUD 364 from 1 July 2026. The value that applies is the one in force at the time of the conduct.

The amount that can be stated in an infringement notice is a different figure again. It is set by s 104 of the Regulatory Powers Act as a fraction of what a court could impose, and s 80UB(1A) of the Privacy Act overrides that fraction for a listed corporation. This page does not state a notice amount: the court maximum under s 13K and the amount payable under a notice are not the same number.

A determination sits outside all of that, and it has no penalty limb. Section 52(1) governs a determination made after investigating a complaint, and s 52(1A) a determination made after an act or practice investigated on the Commissioner's own initiative under s 40(2). Each sets out what a determination may include: a declaration that the conduct was an interference with privacy and must not be repeated or continued, a declaration requiring specified steps within a specified period, a declaration to perform a reasonable act to redress loss or damage, a declaration to prepare and publish a statement, and a declaration that an individual is entitled to a specified amount by way of compensation for loss or damage. Section 52(1AB) provides that the loss or damage includes "injury to the feelings" of the individual and "humiliation suffered". So a determination can direct money to an affected individual, as compensation. What it cannot do is impose a pecuniary penalty payable to the Commonwealth. The IRE declarations below were made under s 52(1A), expressly at [2] and [3] of that determination.

Note how a court-imposed maximum is built, because it is not a single headline figure. In Australian Clinical Labs the Court treated the conduct as a separate contravention in respect of each affected individual: at [60], "ACL engaged in a separate contravention of s 13G(a) in respect of each of the more than 223,000 individuals". At [120] the Court recorded that "during the Relevant Period s 13G(a) of the Act attracted a maximum civil penalty of 2,000 penalty units", the figure that applied before 13 December 2022. Because each affected individual was a separate contravention, the aggregate maximum the Court recorded at [121] was very large. The penalty ordered was AUD 5.8 million, on admitted contraventions and a joint submission on liability and penalty. A consent proposal does not fix the amount: under s 82(3) of the Regulatory Powers (Standard Provisions) Act 2014 (Cth) the court orders "such pecuniary penalty for the contravention as the court determines to be appropriate", and s 82(6) sets out the matters it must take into account.

What these decisions have in common

Read together, these decisions point in one direction:


1. Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24: over-collection on a rental-application platform

Citation and date: Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026). At [36] the Commissioner commenced the investigation on her own initiative under s 40(2) on 18 March 2025, not on a complaint, and the declarations at [2] and [3] were made under s 52(1A).

Status note: the OAIC's own APP Guidelines, Chapter 3, updated 13 May 2026, record that this determination is under review in the Administrative Review Tribunal, and that positions drawn from it are for that reason "not settled"; the guidance says it "will be updated should the outcome of the review change this position". The OAIC has nonetheless written those positions into the Guidelines. Section 96(1)(c) of the Privacy Act allows an application to the Tribunal for review of a decision under s 52(1) or (1A) to make a determination. This entry describes the determination as published on 1 April 2026 and does not state the outcome of that review.

Relevant period: at [1] the finding is that the respondent interfered with the privacy of individuals whose personal information was collected via 2Apply "between March 2020 and 18 March 2025". At [36] the Commissioner records the period as running from March 2020, "the general release of 2Apply", to the commencement of the investigation.

Provisions engaged: Australian Privacy Principle 3.2 (only collect personal information reasonably necessary for the entity's functions or activities) and APP 3.5 (collect only by lawful and fair means).

What happened (plain English): The respondent was IRE Pty Ltd, trading as InspectRealEstate, the operator of the 2Apply rental-application platform used by real-estate agencies to take and process tenancy applications. It was not a case against the agencies that used the platform. The Commissioner found the platform collected applicant details that were not reasonably necessary for processing a rental application. At [94] the Commissioner found the respondent could undertake its functions or activities without collecting ten categories: "gender"; "details of dependants, specifically names and ages"; "student status"; "bankruptcy status"; "retirement status"; "details of previous living history"; "current or intended ownership of their principal place of residence or investment property"; "current applications for other properties"; "bond and rent assistance application status"; and "citizenship status and visa expiry". At [95] the Commissioner found it could carry on those functions collecting a lesser amount in relation to emergency contact, vehicle details, identification documents, proof of income documents and employment details. There was a separate finding on the way the form asked, engaging APP 3.5; at [7] the Commissioner said the determination "also considers, for the first time, an entity's Online Choice Architecture in an assessment of whether the collection was fair", and at [111] added that this was the first time she had done so in the context of APP 3.5.

Outcome / remedy: Declarations that the conduct was an interference with privacy and must not be repeated or continued, together with orders to cease collecting the listed fields within 60 days, to engage an independent reviewer at IRE's own expense across APP 3.2, the online choice architecture under APP 3.5 and retention under APP 11.2, and to report back to the OAIC. No civil penalty was imposed, and a determination cannot impose one. The orders were declarations and remedial steps.

Why it matters for agencies: The Commissioner framed it as a signal to the sector, announcing it in an OAIC media release of 22 April 2026 headed "RentTech platforms must stop unfair and excessive personal information collection, says Privacy Commissioner". The regulator went after the platform operator that shaped what agencies collected, but the finding is that the fields themselves were excessive for a rental application. APP 3.2 attaches to the entity doing the collecting, and this determination decided that question about the platform only. At [53] the Commissioner found the respondent "has operational involvement in the development and maintenance of the default list of questions for the 2Apply form and also engages in the collection of personal information in its own right", so it was "not merely collecting personal information on behalf of real estate agents". At [6] the Commissioner said the operators of RentTech and other online platforms "may bear their own obligations under the Privacy Act", and at [10] encouraged "RentTech providers and real estate agents" to keep collection fair and limited to what is reasonably necessary. No finding was made against any agency, and whether a given agency is an APP entity at all is a separate question under s 6D.

Primary source: Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 on AustLII, the OAIC determination (PDF), and the OAIC media release.


2. Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224: the first civil penalty under the Privacy Act

Citation and date: Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224 (Federal Court, orders made 8 October 2025, Halley J).

Provisions engaged: APP 11.1 (reasonable steps to protect personal information), s 26WH(2) (reasonable and expeditious assessment of a suspected eligible data breach) and s 26WK(2) (give the Commissioner a statement as soon as practicable) of the Privacy Act, with the penalty imposed under s 13G, which at the time of the conduct applied to a serious or repeated interference with privacy.

What happened (plain English): Australian Clinical Labs (ACL), a large ASX-listed pathology company, had acquired Medlab Pathology. In February 2022 an attacker accessed and exfiltrated the personal and health information of more than 223,000 individuals from Medlab's systems. The Court, imposing penalties by consent, found ACL had failed to take reasonable steps to secure the information, had not assessed the suspected breach expeditiously, and had not notified the regulator as soon as practicable. At [48] the Court noted that APP 11.1(b) "has not been the subject of any previous judicial consideration".

Outcome / remedy: A total civil penalty of AUD 5.8 million, the first civil penalty ordered under the Privacy Act, ordered in exact terms: AUD 4,200,000 for the APP 11.1 security failure, AUD 800,000 for the assessment failure (s 26WH(2)) and AUD 800,000 for the notification failure (s 26WK(2)), payable to the Commonwealth within 30 days.

Why it matters for agencies: It shows how the court track works, and how a maximum is built. The Court found three separate failures and penalised each separately: the security failure under APP 11.1, the assessment failure under s 26WH(2), and the notification failure under s 26WK(2). It also shows the maximum is calculated per affected individual rather than as one headline number, which is why the aggregate maximum the Court recorded at [121] as applicable to the APP 11.1 contraventions was orders of magnitude above the AUD 5.8 million ordered by consent.

Primary source: OAIC media release and Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224 on AustLII.


3. Commissioner Initiated Investigation into 7-Eleven Stores Pty Ltd (Privacy) [2021] AICmr 50: faceprints collected without consent

Citation and date: Commissioner Initiated Investigation into 7-Eleven Stores Pty Ltd (Privacy) [2021] AICmr 50 (29 September 2021; corrigendum 12 October 2021). Shortened elsewhere on this page to 7-Eleven Stores Pty Ltd (Privacy).

Provisions engaged: APP 3.3 (do not collect sensitive information without consent, and only where reasonably necessary) and APP 5 (notify individuals of the collection and its circumstances). At [12] the Commissioner said: "I have made findings in relation to APPs 3.3 and 5. I have not made a finding in relation to APP 3.5."

What happened (plain English): Between mid-2020 and August 2021, 7-Eleven ran an in-store customer-feedback survey on tablets that quietly captured facial images and generated "faceprints". At [84] the Commissioner found "both the facial images and faceprints are sensitive information within the meaning of s 6(1)". The stated purpose was narrow: to detect whether the same person was submitting multiple survey responses on the same tablet within a 20-hour period. At [105] the Commissioner found that "at most, it may have been helpful or convenient to collect this kind of information", and that customers were not adequately told it was happening.

Outcome / remedy: Declarations that the conduct was an interference with privacy and must not be repeated, and an order to destroy all faceprints within 90 days. The company had already ceased the collection, so at [131] the Commissioner said she did "not need to make a declaration to cease the conduct". No civil penalty was imposed, and a determination cannot impose one. The orders were declarations and remedial steps.

Why it matters for agencies: This is the clearest statement that convenience does not equal necessity, and the APP 5 reasoning travels beyond biometrics. At [121] the Commissioner said a privacy policy "is a transparency mechanism... It is not generally a way of providing notice under APP 5", and that it "is not reasonable to assume that customers will have searched for the respondent's Privacy Policy online and read through it before entering the store and completing the survey". Read across to an open-home sign-in sheet or an online enquiry form: the notice has to sit at the point of collection, before the collection happens. Note the limit before reading the rest across: the necessity finding was made inside APP 3.3, the sensitive-information limb, which carries its own necessity test, so it is not an APP 3.2 authority.

Primary source: Commissioner Initiated Investigation into 7-Eleven Stores Pty Ltd (Privacy) [2021] AICmr 50 on AustLII.


4. Datateks Pty Ltd (Privacy) [2023] AICmr 97: slow to assess, slow to notify

Citation and date: Datateks Pty Ltd (Privacy) [2023] AICmr 97 (24 October 2023).

Provisions engaged: Section 26WH(2) (carry out a reasonable and expeditious assessment, taking all reasonable steps to complete it within 30 days) and s 26WK(2) (give the Commissioner a statement as soon as practicable) of the Notifiable Data Breaches scheme.

What happened (plain English): In June 2020, three of Datateks' email accounts were accessed by an attacker and used to run a phishing campaign. At [54] the preliminary investigation report recorded that the password on the compromised account was "Password1". At [34] the categories of personal information the respondent held were date of birth, credit card details, bank account details, superannuation details, driver licence, birth certificate, working with children check, Medicare number and tax file number. At [35] the general email account contained that information, other than the working with children check, stored in the "sent" folder and, in the determination's words, "retained and not deleted for audit trail purposes". Datateks was aware of the incident on the day it happened, 26 June 2020 ([7], [31]), but did not formally engage a cyber-security expert until 23 July 2020, 27 days later ([60]). The statement to the Commissioner was completed on 8 December 2020 ([95]) and not given until 18 January 2021, 41 days later ([96]). The Commissioner held that co-ordinating the statement with notifying individuals was not a reason for the delay, and that preparing it "should have taken no more than a day or two" ([98]). On the outsourced part of the work, at [61] the Commissioner said: "While this report was undertaken by the respondent's IT provider, not by the respondent itself, I consider the respondent could have taken steps to ensure it was completed expeditiously by communicating to the IT provider the need for the report to be finalised promptly."

Outcome / remedy: Declarations of contravention and an order to prepare an incident-response plan meeting specified minimum content within three months and provide it to the Commissioner. No civil penalty was imposed, and a determination cannot impose one. The orders were declarations and remedial steps.

Why it matters for agencies: This is a small-business, email-compromise fact pattern: one general email account, weak credentials, and personal information left sitting in the mailbox. The failure was not just the hack; it was the delay in assessing and reporting. Section 26WH(2) requires an entity to carry out a reasonable and expeditious assessment and to take all reasonable steps to complete it within 30 days after becoming aware of reasonable grounds to suspect an eligible data breach, and s 26WK(2) requires the statement to the Commissioner as soon as practicable. (Note the related remedial-action exception in s 26WF: where remedial action is taken before any serious harm results, and a reasonable person would then conclude the breach is not likely to result in serious harm, the breach is taken never to have been an eligible data breach.) An incident-response plan written in advance is what makes the 30-day assessment achievable.

Primary source: Datateks Pty Ltd (Privacy) [2023] AICmr 97 on AustLII.


5. Pacific Lutheran College (Privacy) [2023] AICmr 98: security and response failures together

Citation and date: Pacific Lutheran College (Privacy) [2023] AICmr 98 (24 October 2023).

Provisions engaged: APP 11.1 (reasonable steps to protect personal information) together with s 26WH(2) (expeditious assessment) and s 26WK(2) (timely notification).

What happened (plain English): In May 2020, an attacker compromised the email account of a College manager. Personal information of parents, guardians, students and staff was sitting in the mailbox rather than in secure storage. At [6] the account was used to send 8,332 phishing emails to its contacts, and the College became aware the following day, 29 May 2020. At [8], and again at [116], the assessment concluded on 14 October 2020 that 367 individuals' information was likely at risk of serious harm. At [169] the determination records that the College had implemented multi-factor authentication on expert advice, on 4 December 2019, and that it was in place at the time, and that the attacker bypassed it using IMAP because legacy authentication had never been disabled and cannot enforce MFA. The Commissioner found the College had not taken reasonable steps to secure the information, had not assessed the suspected breach expeditiously, and had not notified the regulator as soon as practicable, holding at [173] that "while I appreciate that the respondent relied upon external expertise, under the Privacy Act the obligation to implement reasonable security steps rests with the respondent who holds the personal information".

Outcome / remedy: Declarations of contravention, with orders to prepare and implement an incident-response plan and an information security program within six months, to obtain an independent expert review at 12 months, and to implement its recommendations. No civil penalty was imposed, and a determination cannot impose one. The orders were declarations and remedial steps.

Why it matters for agencies: Decided alongside Datateks, this pairs the security obligation (APP 11) with the assessment and notification obligations in one decision. At [174], in the Finding, the Commissioner set out the steps the College ought to have taken: a member of staff designated as responsible for personal information security; privacy training provided for all staff; documented practices, procedures and systems, particularly for removing personal information from email accounts; adequate password security, including complexity and expiration; and multifactor authentication effectively implemented. Note the limit before reading it across: the College held children's information and the Commissioner expressly weighted that in assessing seriousness, so the transferable part is the reasoning about reasonable steps for a small organisation, not the outcome.

Primary source: Pacific Lutheran College (Privacy) [2023] AICmr 98 on AustLII.


The collection discipline these decisions turn on is a document problem: what an application form asks for, and what the collection notice says at the point of collection. Our privacy kit is the template set for that.

This page is general information, not legal advice, and does not take account of your circumstances. It summarises published decisions in our own words for reference only; the outcome of any matter depends on its own facts and on the primary text of the determination or judgment. Always read the primary source and obtain advice before acting. Sources: Office of the Australian Information Commissioner (oaic.gov.au), including the OAIC APP Guidelines Chapter 3 as updated 13 May 2026; AustLII (austlii.edu.au); Privacy Act 1988 (Cth), Compilation No. 104 (compilation date 4 June 2026), including APPs 3, 5 and 11 and ss 13G, 13H, 13J, 13K, 26WF, 26WH, 26WK, 40, 52, 80U, 80UB, 80UC and 96, at legislation.gov.au C2026C00227; Regulatory Powers (Standard Provisions) Act 2014 (Cth) ss 82, 84, 103 and 104, at legislation.gov.au C2014A00093; Crimes Act 1914 (Cth) s 4AA, at legislation.gov.au C1914A00012, and the Crimes (Amount of a Penalty Unit) Instrument 2026 (Cth), F2026N00424. Written by Privaproof.