Privacy breach penalty calculator
Answer three plain-English questions to see which Privacy Act civil-penalty tier a breach at your agency could fall into, under the maximums introduced by the 2022 and 2024 reforms.
General information, not legal advice. Privaproof is not a law practice. This tool gives a general, illustrative indication of the maximum penalty tiers under the Privacy Act 1988. It does not assess your actual liability, which depends on your circumstances and is decided by the courts and the regulator. Get advice from a qualified lawyer before you rely on it.
Worked out entirely in your browser. Your answers never leave your device. Nothing is sent to us or to any server.
What kind of privacy failure are you weighing up?
Pick the closest match. This is the main driver of which penalty tier applies.
Roughly how many people were (or could be) affected?
Scale doesn't set the tier on its own, but a large-scale breach is far more likely to be judged "serious".
What best describes your agency?
Business size affects whether the Privacy Act even applies to you, and how the top-tier maximum is calculated.
Figures are current Commonwealth maximums for a body corporate unless noted. This tool covers Privacy Act civil penalties only, not the Spam Act, the Do Not Call Register, AUSTRAC/AML penalties, or state law.
Not sure where your gaps are?
The cheapest penalty is the one you never trigger. Take the free 2-minute self-audit to see which of the 8 privacy areas your agency still needs to close.
Start the free 2-min audit →