Who Can Be Sued
The statutory tort allows individuals to bring claims against any person, corporation, or government body. In a deepfake context, potential defendants include the person who created the synthetic media, any person who distributed or published it, the operator of a platform that hosted it (where the platform's conduct was intentional or reckless, not merely negligent), and any person who commissioned or procured its creation. The tort requires the defendant's conduct to have been intentional or reckless. Negligent hosting or accidental sharing is not sufficient.
Evidence and Preservation
Deepfake claims require careful evidence preservation. Synthetic media can be deleted, re-uploaded, or altered quickly. Before contacting the person responsible, you should take steps to capture and preserve evidence. This includes screenshots with visible URLs and timestamps, screen recordings of video content, archived versions of web pages, metadata from image files where accessible, and records of any communications from or about the person who created or shared the material. Do not rely on the content remaining available online. Platforms may remove it (which is helpful) but the evidentiary record must be secured first.
Overlap with Intimate Image Offences and Defamation
Deepfakes depicting a person in a sexual context may also engage Commonwealth criminal offences relating to non-consensual sharing of intimate images under the Criminal Code Act 1995 (Cth), as well as equivalent state offences. A criminal complaint and a civil claim under the statutory tort are not mutually exclusive. They serve different purposes: the criminal offence punishes the offender, while the civil claim compensates the victim and can restrain further distribution.
Where a deepfake places a person in a false and damaging context, there may also be a defamation claim. A fabricated video showing a person engaging in criminal conduct, for example, is both a misuse of personal information and a publication of defamatory matter. The two causes of action have different elements, different defences, and different damages frameworks. In some cases, it will be appropriate to pursue both. For more on the intersection of privacy and defamation, see our page on invasion of privacy vs defamation or visit defamationlawyer.au.
Remedies Available
Under the statutory tort, the court may award general damages for non-economic loss (capped at approximately $478,550 for non-economic loss, with no requirement to prove financial loss), injunctions restraining further creation or distribution of the material, orders for delivery up or destruction of the deepfake, and exemplary damages in exceptional cases where the defendant's conduct was particularly egregious. The court must not award aggravated damages. An apology by a defendant does not constitute an admission of fault or liability under clause 13 of Schedule 2, but the court may take it into account when determining damages. This creates scope for negotiated outcomes that include both removal and a formal acknowledgement.
The OAIC Complaint Pathway
A complaint to the Office of the Australian Information Commissioner (OAIC) is a free, lawyer-free alternative for resolving privacy disputes. However, the OAIC pathway has significant limitations regarding resolution speed and the inability to award punitive damages. Furthermore, the OAIC generally only has jurisdiction over entities subject to the Australian Privacy Principles (APP entities). For serious deepfake invasions, the statutory tort often represents a more effective avenue for relief.
Overseas Jurisprudence
Judicial consideration of deepfake claims under the statutory tort remains limited in Australia. However, the UK, New Zealand, and Canada have each developed privacy tort jurisprudence that Australian courts are likely to consider as persuasive authority. The English courts in particular have addressed misuse of private information in the context of manipulated and fabricated imagery. While these decisions are not binding, they provide a framework for how the seriousness threshold and reasonable expectation of privacy may be assessed in this context.
The Journalist Exemption Does Not Protect Most Deepfake Creators
The journalist exemption under Part 3 of Schedule 2 is narrow. It applies only to professional journalists subject to a code of practice, and their employers and assistants, in relation to the collection, preparation, or publication of journalistic material. Social media users, influencers, content creators, and anonymous online accounts do not qualify. The vast majority of deepfake creators and distributors will not be able to rely on this exemption.
Disclaimer: The content of this page provides general information only and does not constitute specific legal advice. You should seek independent legal advice regarding your particular circumstances.