Employer Invasion of Privacy

Your employer is not exempt from the statutory tort. The employee records carve-out in the Privacy Act does not apply.

Book a Confidential Assessment ($770)

Max file size: 20MB

Workplace Privacy Rights Under the Statutory Tort

Since 10 June 2025, employees in Australia have had a direct civil right of action against employers who commit a serious invasion of privacy. The statutory tort for serious invasion of privacy, enacted as Schedule 2 of the Privacy Act 1988 (Cth), applies to workplace conduct including covert surveillance, disclosure of medical or personal information to colleagues, invasive monitoring of emails and devices, and disproportionate internal investigations.

This matters because of a gap in the law that existed for decades. The Australian Privacy Principles (Schedule 1 of the Privacy Act) contain an employee records exemption. That exemption allowed employers to handle employee records with almost no regulatory oversight, provided the handling was directly related to the employment relationship. The statutory tort contains no such exemption. An employer who intentionally or recklessly invades an employee's privacy can be sued for damages, regardless of whether the conduct related to an employee record.

If your employer has read your private emails, installed covert cameras, disclosed your medical condition to your team, or tracked your movements without proper notice, you may have a claim. The limitation period is short: one year from the date you became aware of the invasion, or three years from its occurrence, whichever expires first. If you are considering action, do not delay.

The clock is ticking. You may have as little as 12 months to act.

A fixed fee confidential initial assessment is $770. We will tell you where you stand.

Common Workplace Privacy Invasions

The statutory tort covers two pathways: intrusion upon seclusion and misuse of personal information. Both arise frequently in the employment context.

Workplace surveillance camera monitoring employee activities

Covert Workplace Surveillance

<p>Hidden cameras in offices, break rooms, or bathrooms. GPS tracking of company vehicles used outside work hours. Keystroke logging and screen capture software installed without notice. Monitoring of personal phone calls or messages on work devices.</p><p>State surveillance legislation creates criminal offences for some of these acts, but it does not give you a civil remedy. The statutory tort does. If your employer conducted surveillance that was covert, disproportionate, or extended beyond what was reasonably necessary for a legitimate business purpose, you may have a claim for intrusion upon seclusion under Schedule 2.</p><p>The conduct must have been intentional or reckless, and it must meet the seriousness threshold. Routine, disclosed workplace monitoring with a clear business justification is less likely to be actionable. Covert surveillance of personal activities almost certainly is.</p>

Confidential medical information in workplace setting

Disclosure of Medical and Personal Information

<p>Your employer disclosed your mental health diagnosis in a team meeting. A manager told colleagues about your positive drug test. HR shared details of your workers' compensation claim with your direct reports. A supervisor forwarded your medical certificate, which contained diagnostic information, to people who had no need to see it.</p><p>These are potential claims for misuse of personal information under the statutory tort. Health information, financial records, and details of personal circumstances are among the most private categories of information a person holds. Disclosure to colleagues or third parties without consent, and without a genuine and proportionate business need, may constitute a serious invasion of privacy.</p><p>Unlike the APPs, truth is not a defence. It does not matter that the information disclosed was accurate. What matters is that it was private, that the disclosure was intentional or reckless, and that a reasonable person in the plaintiff's position would have expected it to remain confidential.</p>

Internal workplace investigation examining employee information

Invasive Internal Investigations

<p>Internal investigations sometimes cross the line. Searching an employee's personal bag, locker, or phone without consent. Requiring disclosure of private medical records unrelated to the role. Engaging a private investigator to conduct covert surveillance of an employee on sick leave. Accessing personal email accounts or social media without authorisation.</p><p>The statutory tort does not prohibit employers from conducting internal investigations. It requires that the methods used be proportionate to the purpose. An investigation into suspected fraud may justify reviewing work emails. It does not justify installing spyware on a personal device or surveilling an employee's home.</p><p>Where an investigation is disproportionate, covert, or extends to genuinely private matters unconnected to the workplace, the employee may have a claim. The court will weigh the employer's legitimate interest against the employee's reasonable expectation of privacy in the circumstances. This balancing exercise is central to the statutory tort.</p>

The Employee Records Exemption Does Not Apply

Why the Statutory Tort Changes Workplace Privacy Law

For years, the employee records exemption in section 7B(3) of the Privacy Act 1988 has shielded employers from the Australian Privacy Principles when handling employee records in connection with the employment relationship. This exemption is broad. It covers health records, leave records, performance appraisals, disciplinary records, and virtually any personal information collected in the course of employment. The practical effect has been that employees had almost no privacy rights under Commonwealth law against their own employer.

Schedule 2 of the Privacy Act, which establishes the statutory tort for serious invasion of privacy, is a separate regime. It is not subject to the employee records exemption. The tort applies to any person, corporation, or government body that commits a serious, intentional or reckless invasion of another individual's privacy. This includes employers of all sizes, from large corporations to small businesses with an annual turnover of $3 million or less (who are generally exempt from the APPs).

How State Surveillance Laws Interact With the Statutory Tort

State and territory surveillance legislation creates criminal offences for certain types of surveillance. These laws do not provide a civil remedy. You cannot sue your employer under the Surveillance Devices Act. However, a breach of state surveillance law may strengthen a claim under the Commonwealth statutory tort by demonstrating that the surveillance was unlawful, covert, or disproportionate.

In Victoria, the Surveillance Devices Act 1999 permits one-party consent recording of conversations. Optical surveillance offences apply only to activities inside a building (not outdoor areas). Tracking devices require consent. Employers who install hidden cameras in offices or record conversations without being a party to them may commit criminal offences under Victorian law, and the same conduct may ground a civil claim under the statutory tort.

In New South Wales, the Workplace Surveillance Act 2005 specifically regulates employer surveillance. It requires 14 days' written notice before commencing camera, computer, or tracking surveillance. Covert surveillance is only permitted with a court order (a covert surveillance authority). An employer who fails to give notice, or who conducts covert surveillance without a court order, breaches NSW law. This breach is strong evidence of an invasion of privacy under the Commonwealth tort.

In Queensland, there is no legislation regulating cameras, tracking devices, or computer surveillance in the civilian context. The Invasion of Privacy Act 1971 covers only listening devices. This means that, until the commencement of the statutory tort on 10 June 2025, an employer in Queensland could install hidden cameras in an office and face no civil or criminal consequence under state law. The Commonwealth tort now fills that gap.

What Employers Should Know

We also act for employers and businesses facing claims under the statutory tort. If you are an employer who has been served with a claim or a pre-action demand, or who is concerned about the legality of existing monitoring practices, the position is not necessarily as adverse as it may appear. Workplace monitoring that is disclosed, proportionate, and conducted for a legitimate business purpose may be defended on grounds of implied consent, lawful authority, or because the employee did not have a reasonable expectation of privacy in the circumstances. The seriousness threshold in clause 7(1)(d) also operates as a filter: minor or incidental invasions are not actionable.

For further information about defending privacy claims, including the procedural advantages of seeking a pre-trial exemption determination, contact us for a confidential initial assessment.

Where workplace privacy conduct also involves damage to reputation (for example, disclosure of false information about an employee's conduct or health), there may be an overlapping defamation claim. Our practice focuses on both privacy and defamation law. See defamationlawyer.au for more information about defamation proceedings.

Need to Understand Your Position?

Whether you are an employee or an employer, a confidential initial assessment ($770 fixed fee) will set out your options clearly.

Why Employees and Employers Instruct Us

Our practice focuses on both privacy and defamation law. The statutory tort borrows heavily from defamation law concepts, and our experience in that field informs every workplace privacy matter we handle.

No Employee Records Exemption

The statutory tort is not subject to the employee records exemption that limits the APPs. Employers of any size can be held liable for serious invasions of employee privacy.

No Proof of Damage Required

The tort is actionable per se. You do not need to prove financial loss, psychiatric injury, or any other form of damage. The invasion itself is the wrong.

Fixed Fee Entry Points

A confidential initial assessment is $770. A pre-action demand letter is $990. You will know the cost before you commit.

State Law Knowledge

Workplace surveillance legislation in Victoria, New South Wales, and Queensland operates differently. A breach of state law can significantly strengthen a Commonwealth tort claim.

Plaintiff and Defendant Representation

We act for employees bringing claims and for employers defending them. This means we understand both sides of any dispute and advise accordingly.

Urgent Injunction Capability

Where surveillance is ongoing or disclosure is imminent, we can seek urgent injunctive relief to stop the conduct before further harm occurs.

Frequently Asked Questions: Employer Invasion of Privacy

Since 10 June 2025, yes. The statutory tort for serious invasion of privacy under Schedule 2 of the Privacy Act 1988 (Cth) allows individuals to bring civil proceedings against any person, corporation, or government body that intentionally or recklessly invades their privacy in a serious manner. This includes employers. The employee records exemption that shields employers under the Australian Privacy Principles does not apply to the statutory tort. Claims can be brought for intrusion upon seclusion (such as covert surveillance or tracking) and for misuse of personal information (such as disclosing medical or financial details without consent). The invasion must meet the seriousness threshold, and the conduct must have been intentional or reckless. Negligent or accidental breaches are not actionable under this tort.

It may be. Disclosure of medical information, including diagnoses, treatment details, drug test results, or mental health conditions, to persons who had no genuine need to know is a potential claim for misuse of personal information under the statutory tort. The disclosure must have been intentional or reckless and must meet the seriousness threshold. Truth is not a defence: it does not matter that the medical information was accurate. The court will consider whether you had a reasonable expectation of privacy in the information, whether the employer had a legitimate purpose for the disclosure, and whether the disclosure was proportionate to that purpose. A confidential initial assessment will help you determine whether your circumstances support a claim.

It depends on the type of monitoring, the state or territory, and whether notice was given. In New South Wales, the Workplace Surveillance Act 2005 requires employers to provide at least 14 days' written notice before commencing camera, computer, or tracking surveillance. Covert surveillance requires a court order. In Victoria, the Surveillance Devices Act 1999 restricts listening and tracking devices but does not regulate optical surveillance of outdoor areas. In Queensland, there is no legislation regulating workplace cameras, tracking, or computer monitoring. Even where monitoring is lawful under state legislation, it may still be actionable under the Commonwealth statutory tort if it is covert, disproportionate, or extends beyond what is reasonably necessary. The tort requires an assessment of the employee's reasonable expectation of privacy in all the circumstances.

They are separate regimes with different scope, forums, and remedies. The OAIC complaint pathway deals with breaches of the Australian Privacy Principles by APP entities (generally, organisations with annual turnover above $3 million and certain other bodies). It does not cover small businesses, individuals acting in a personal capacity, or employee records. It is free, does not require a lawyer, and is handled by the Office of the Australian Information Commissioner. The statutory tort under Schedule 2 is a court-based civil action. It covers any defendant, including small businesses and individuals. It is not limited to APP entities. Damages are capped at approximately $478,550 for non-economic loss, and exemplary damages may be available in exceptional cases. For a more detailed comparison, see our page on OAIC complaints versus the statutory tort.

Yes. Several defences are available under Part 2 of Schedule 2. Implied consent may apply where the monitoring was clearly disclosed in an employment contract or policy and the employee continued to use the monitored systems. Lawful authority may apply where the monitoring was authorised by law (for example, under a covert surveillance authority in NSW). The necessity defence may apply where the employer reasonably believed the invasion was necessary to prevent a serious threat to health or safety. Beyond formal defences, the public interest balancing test in clause 7(1)(e) requires the court to weigh the employee's privacy interest against countervailing interests, including the employer's legitimate interest in investigating misconduct or protecting its property. Proportionate, disclosed monitoring conducted for a genuine business purpose is far less likely to be found actionable.

The court may award damages for non-economic loss (capped at approximately $478,550, indexed annually), which covers emotional distress, humiliation, anxiety, and loss of dignity. No proof of financial loss is required. The court may also award exemplary damages in exceptional cases where the defendant's conduct was particularly egregious. An account of profits is available where the defendant profited from the invasion. An apology by the defendant does not constitute an admission of fault or liability, but the court may take it into account when assessing damages. For more detail on compensation, see our page on compensation and damages claims.

The limitation period is one year from the date you became aware (or ought reasonably to have become aware) of the invasion, or three years from the date the invasion occurred, whichever expires first. The court has discretion to extend the period to a maximum of six years in certain circumstances. These timeframes are strict. If you suspect your employer has invaded your privacy, obtain legal advice promptly. For further detail, see our page on privacy tort time limits.

Yes. We act for employers, businesses, and other defendants facing claims under the statutory tort. Defence options include raising statutory defences (consent, lawful authority, necessity, proportionate defence of property), challenging the seriousness threshold, and seeking pre-trial determination of exemptions under Part 3 of Schedule 2. An early pre-trial exemption application, if successful, can resolve the matter before trial and avoid the cost of full proceedings. We also advise employers on the legality of existing monitoring practices and assist with implementing lawful, disclosed, and proportionate surveillance policies. Contact us for a confidential initial assessment.

Workplace Privacy Is Now Enforceable. Act Promptly.

The limitation period may be as short as 12 months. A confidential initial assessment is $770 fixed fee.

The content of this article is intended to provide general information and does not constitute specific legal advice. You should seek professional advice before acting on any information provided.

Call