Australiaregulation

Australian Privacy Act (APPs)

Civil penalties up to AUD 50 million or 30% of adjusted turnover make privacy breaches an existential financial risk requiring direct board oversight.

Mapped to Microsoft controls
Effective Date21 December 1988 (Notifiable Data Breaches: 22 February 2018)
Enforcement BodyOffice of the Australian Information Commissioner (OAIC)
Penalty FrameworkCivil penalties of up to AUD 50 million, three times the benefit obtained from the contravention, or 30% of adjusted turnover (whichever is greatest) for serious or repeated interferences with privacy. The OAIC can accept enforceable undertakings, make determinations, and seek civil penalty orders through the Federal Court.

The Australian Privacy Act 1988 is Australia's principal privacy legislation, establishing 13 Australian Privacy Principles (APPs) that govern the handling of personal information by Australian Government agencies and private sector organisations. The Act is administered by the Office of the Australian Information Commissioner (OAIC).

The Notifiable Data Breaches (NDB) scheme, introduced in 2018, requires entities to notify the OAIC and affected individuals of eligible data breaches likely to result in serious harm. The 2024 Privacy Act Review is set to introduce significant reforms including a statutory tort for serious privacy invasions, a children's privacy code, and enhanced enforcement powers.

For Microsoft 365 environments, compliance requires Defender XDR for threat detection and breach identification, Purview DLP for preventing data loss, Intune for endpoint security, and Conditional Access for access management. StremarControl engineers and operates the Microsoft-native controls required for Australian Privacy Act mandates, translating obligations into enforceable Microsoft-native controls, structured evidence, and ongoing assurance discipline for OAIC compliance reporting and NDB scheme obligations.

Why This Matters Now

The Australian Privacy Act 1988 and its 13 Australian Privacy Principles (APPs) form the backbone of data protection in Australia. The Notifiable Data Breaches (NDB) scheme mandates reporting of eligible data breaches to the OAIC and affected individuals. APP 11 specifically requires entities to take reasonable steps to protect personal information - for M365 this means Defender XDR for threat protection, Purview DLP for data loss prevention, Intune for endpoint security, and Conditional Access for access control. Major reforms proposed in 2024 will further strengthen the framework.

Scope & Applicability

Applies to Australian Government agencies, private sector organisations with annual turnover exceeding AUD 3 million, health service providers, and certain small businesses handling personal information. Also applies to overseas organisations with an 'Australian link.' M365 tenants used by Australian operations must implement APP-compliant controls.

Core Obligations

01
Australian Privacy Principle 11

APP 11 - Security of Personal Information

Take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.

02
Part IIIC

Notifiable Data Breaches

Notify the OAIC and affected individuals of eligible data breaches that are likely to result in serious harm, as soon as practicable.

03
Australian Privacy Principle 6

APP 6 - Use and Disclosure

Use or disclose personal information only for the purpose for which it was collected, unless an exception applies.

04
Australian Privacy Principle 8

APP 8 - Cross-Border Disclosure

Before disclosing personal information overseas, take reasonable steps to ensure the recipient complies with the APPs.

Microsoft 365 Control Mapping

How each obligation maps to enforceable Microsoft 365 controls and the evidence they produce.

Obligation

APP 11 - Security

M365 Control

Conditional Access with MFA and device compliance. Intune endpoint security baselines. Defender XDR for advanced threat protection. Purview sensitivity labels for data classification.

Evidence

Conditional Access evaluation logs, Intune compliance reports, Defender threat analytics, label usage reports.

Obligation

Notifiable Data Breaches

M365 Control

Defender XDR incident detection with Sentinel playbooks for NDB assessment. Automated breach scope analysis and OAIC notification workflows.

Evidence

Incident timeline reports, breach assessment documentation, OAIC notification records.

Obligation

APP 8 - Cross-Border Disclosure

M365 Control

Purview DLP policies with geo-fencing rules. Conditional Access named locations restricting data access by geography. Data residency controls.

Evidence

DLP cross-border incident logs, Conditional Access geo-restriction reports, data residency configuration exports.

Implementation Timeline

December 1988
Privacy Act 1988 enacted
March 2014
Australian Privacy Principles (APPs) replace former Information Privacy Principles and National Privacy Principles
February 2018
Notifiable Data Breaches scheme commences
February 2024
Government response to Privacy Act Review - major reforms announced
2025–2026
Phased implementation of Privacy Act reforms including a statutory tort for serious privacy invasions

Related Frameworks

Ready to get Australia Privacy Act-ready?

Start with a fixed-scope sprint. We assess your Microsoft 365 controls against Australia Privacy Act requirements, close gaps, and produce audit-ready evidence.