Skip to content

What are the penalties for a privacy breach for a real estate agency?

For a serious breach, the Privacy Act sets the maximum for a company at the greatest of A$50 million, three times the benefit obtained, or 30 per cent of adjusted turnover, so A$50 million is a floor on that maximum rather than a cap. The largest penalties are reserved by the courts for major organisations and serious failures. For a smaller agency, the realistic exposure is an OAIC complaint or compliance notice, an order to compensate affected people, a mandatory data-breach notification, and (often the biggest cost) lost client trust.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

The A$50 million figure gets quoted a lot. It's real, but it's a ceiling built for the country's biggest data failures, not the going rate for a suburban agency. What a breach actually costs a smaller agency looks very different, and it usually starts long before any penalty does.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

What is the headline maximum penalty?

Since December 2022, a company that commits a serious interference with privacy can face civil penalties of up to the greater of A$50 million, three times the benefit, or 30% of adjusted turnover. This is a maximum reserved for large, serious or systemic breaches; the only Privacy Act civil penalty imposed by a court to date (about A$5.8m) was against a large listed company, not a small business.

The realistic picture for a small agency

Most likely →→ Least likely, most severe
A complaint to the OAIC → conciliationAn infringement notice (s 13K) or a compliance noticeA court-imposed civil penalty (s 13G, reserved for large/serious cases)
An order to compensate affected individualsA mandatory data-breach notification (NDB)A class action (mass breaches)

Lost trust is often the real cost for an agency that lives on referrals. Note too that failing to notify a data breach under the NDB scheme is itself an interference with privacy that can attract penalties.

What is the new right to sue (statutory tort)?

Since June 2025, individuals can bring a direct court claim for a serious invasion of privacy. This is not a Privacy Act penalty and sits outside the OAIC process; it's a private lawsuit, with a high bar (the conduct must be intentional or reckless and serious; ordinary accidents don't qualify). It's a genuinely new exposure worth understanding, separate from anything above.

Common questions

What is the maximum penalty for a privacy breach?

Since December 2022, a company that commits a serious interference with privacy can face civil penalties of up to the greater of A$50 million, three times the benefit, or 30% of adjusted turnover.

The $50 million figure is not the only tier, and it is not the one a small agency is most likely to meet. The Privacy and Other Legislation Amendment Act 2024 added a mid-tier civil penalty for an interference with privacy that does not meet the "serious" threshold (s 13H), and infringement notice powers for specified contraventions (s 13K), both commencing 10 December 2024. Those lower tiers, not the headline ceiling, are the realistic end of the range for a suburban agency, and they are why "we are too small to be worth a $50 million penalty" is the wrong thing to take comfort from. We have deliberately not published penalty-unit figures for s 13H and s 13K here: we could not pin them to a primary source we could read, and a wrong penalty figure is worse than no figure. It's a maximum reserved for large, serious or systemic breaches; the only Privacy Act civil penalty imposed by a court to date (about A$5.8m) was against a large listed company.

What's the realistic exposure for a small agency?

An OAIC complaint going to conciliation, an infringement or compliance-sweep notice, an order to compensate affected individuals, a mandatory data-breach notification, and often the biggest cost, lost client trust.

Can I be penalised for not reporting a data breach?

Yes. Failing to notify a data breach under the Notifiable Data Breaches scheme is itself an interference with privacy that can attract penalties.

Can an individual sue my agency directly?

Since June 2025, individuals can bring a direct court claim for a serious invasion of privacy. It's not a Privacy Act penalty and sits outside the OAIC process, a private lawsuit with a high bar: the conduct must be intentional or reckless and serious.

See your agency's exposure: free 2-minute self-audit →


General information, not legal advice. Penalty figures are maximums and indexed over time. Sources: OAIC (oaic.gov.au); Privacy Act 1988 (Cth).