Skip to content

What are the penalties for a privacy breach for a real estate agency?

The Privacy Act sets three civil penalty tiers and only a court can impose one (s 80U). A serious interference by a company is the top tier: the greatest of A$50 million, three times the benefit, or 30 per cent of adjusted turnover (s 13G(3)). Below it, an interference that is not serious, at 2,000 penalty units (10,000 for a body corporate, s 13H(3)). Below that, administrative breaches such as not having an APP privacy policy, at 200 units (1,000 for a body corporate, s 13K(1)(b)(i), (4)). For a smaller agency the realistic end is an OAIC complaint, an infringement notice (60 penalty units for a body corporate, s 80UB), a compliance notice (s 80UC), an order to compensate affected people, a mandatory data-breach notification, and (often the biggest cost) lost client trust.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

The A$50 million figure gets quoted a lot, and usually as a ceiling. It is not one: s 13G(3) makes it the floor of a greatest-of test, and only for an interference a court finds serious. Which tier you sit in turns on what you can check this week. Does your agency have an APP privacy policy, and has anyone read it since the 2024 amendments?

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

What is the headline maximum penalty?

Since 13 December 2022, a company that commits a serious interference with privacy faces a maximum of the greatest of A$50 million, three times the benefit, or 30 per cent of adjusted turnover (s 13G(3)). Seriousness is decided on the s 13G(1B) factors, one of which is whether the entity failed to put practices and procedures in place. That is the factor an agency controls.

There is one court-ordered Privacy Act penalty to point to. In Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224, the Commissioner's first civil penalty proceeding in the history of the Act [6], an ASX-listed pathology company was ordered on 8 October 2025 to pay A$5.8 million: A$4.2 million for not taking reasonable steps to protect personal information (APP 11.1(b)), A$800,000 for not assessing a suspected breach reasonably and expeditiously (s 26WH(2)), and A$800,000 for not giving the Commissioner a statement as soon as practicable (s 26WK(2)). A ransomware attack had taken the health information of more than 223,000 people and published it on the dark web.

The realistic picture for a small agency

Most likely →→ Least likely, most severe
A complaint to the OAIC → conciliationAn infringement notice for a s 13K contravention (s 80UB) or a compliance notice (s 80UC)A court-imposed civil penalty on the Commissioner's application (ss 13G, 13H, 80U)
An order to compensate affected individuals (s 52(1)(b)(iii))A mandatory data-breach notification (s 26WK)A representative complaint (ss 36(2), 38) or a court class action

The Commissioner cannot fine you. A determination under s 52(1) can declare the conduct an interference, order steps so it is not repeated, and award the complainant compensation; it has no penalty limb. A fine is a separate track, requiring the Commissioner to apply to the Federal Court (ss 13G, 80U). And failing to notify a data breach is itself an interference with privacy (s 13(4A)): in FCA 1224 that limb alone drew A$800,000. Lost trust can still outlast all of it.

What is the new right to sue (statutory tort)?

Since 10 June 2025, individuals can bring a direct court claim for a serious invasion of privacy (Privacy Act Sch 2 cl 7). It is not a Privacy Act penalty and sits outside the OAIC process. The bar is cumulative: a reasonable expectation of privacy, an invasion that was intentional or reckless (cl 7(1)(c)), seriousness, and a public interest in privacy outweighing any countervailing one. Carelessness alone does not qualify. Damages for non-economic loss are capped at the greater of A$478,550 and the defamation cap (cl 11(5)).

Common questions

What is the maximum penalty for a privacy breach?

Since 13 December 2022, a company that commits a serious interference with privacy faces a maximum of the greatest of A$50 million, three times the benefit, or 30 per cent of adjusted turnover (s 13G(3)). It is not a A$50 million cap: that is the floor of the greatest-of test, and in FCA 1224 the Court counted a separate contravention for each of the 223,000 people affected.

The A$50 million figure is not the only tier, and it is not the one a small agency is most likely to meet. The Privacy and Other Legislation Amendment Act 2024 added a mid-tier civil penalty for an interference that does not meet the serious threshold (s 13H) and infringement and compliance notice powers (ss 13K, 80UB, 80UC), all commencing 11 December 2024, the day after Royal Assent. The Act states both maximums in penalty units: 2,000 under s 13H(3) and 200 under s 13K(4), each multiplied by five where a court penalises a body corporate, to 10,000 and 1,000 (Regulatory Powers (Standard Provisions) Act 2014 s 82(5)(a)). An infringement notice the OAIC issues itself is smaller again, capped at 60 penalty units for a body corporate and 12 for an individual (s 80UB; Regulatory Powers Act s 104(2)). A penalty unit is A$364 for conduct on or after 1 July 2026 (Crimes (Amount of a Penalty Unit) Instrument 2026, s 5). Those lower tiers are the realistic end of the range, and the cheapest is triggered by something as ordinary as not having an APP privacy policy (s 13K(1)(b)(i)). Being too small for a A$50 million penalty is not the same as being out of range.

What's the realistic exposure for a small agency?

An OAIC complaint going to conciliation, an infringement notice (s 80UB) or a compliance notice (s 80UC), an order to compensate affected individuals (s 52(1)(b)(iii)), a mandatory data-breach notification, and often the biggest cost, lost client trust.

Can I be penalised for not reporting a data breach?

Yes. Where an entity contravenes s 26WH(2), 26WK(2), 26WL(3) or 26WR(10), s 13(4A) deems it an interference with privacy, so it can be penalised like any other. In FCA 1224 the failure to assess and the failure to notify drew A$800,000 each, on top of A$4.2 million for the security failure.

Can an individual sue my agency directly?

Since 10 June 2025, individuals can bring a direct court claim for a serious invasion of privacy (Sch 2 cl 7). It is not a Privacy Act penalty and sits outside the OAIC process. The invasion must be intentional or reckless (cl 7(1)(c)) as well as serious, so carelessness alone does not qualify, and damages for non-economic loss are capped at the greater of A$478,550 and the defamation cap (cl 11(5)).

See your agency's exposure: free 2-minute self-audit →


General information, not legal advice. Penalty figures are maximums and only a court can impose one. The A$50 million in s 13G(3) is a fixed amount; penalty-unit figures move with the penalty unit, indexed every third 1 July under Crimes Act 1914 s 4AA. Sources: Privacy Act 1988 (Cth) ss 13G, 13H, 13K, 52, 80U, 80UB; Australian Clinical Labs (No 2) [2025] FCA 1224.