The Statutory Tort: Intrusion Upon Seclusion
Under Schedule 2 of the Privacy Act 1988 (Cth), a person commits a serious invasion of privacy by intruding upon the seclusion of another individual. The tort requires the plaintiff to establish that the invasion was intentional or reckless, that the plaintiff had a reasonable expectation of privacy in the circumstances, and that the invasion was serious. The court considers all relevant factors, including the nature and consequences of the invasion, the relationship between the parties, and the purpose of the defendant's conduct.
Accessing another person's email, social media, banking, or cloud storage account without their consent is a classic example of intrusion upon seclusion. The plaintiff's password-protected accounts are, by definition, spaces in which a reasonable expectation of privacy exists. The act of logging in using retained, guessed, or improperly obtained credentials is intentional. And where the access reveals private correspondence, financial records, photographs, or health information, the seriousness threshold is readily met.
Criminal Offences: Commonwealth and State Laws
Unauthorised access to a computer system is also a criminal offence. Under section 478.1 of the Criminal Code Act 1995 (Cth), a person who causes unauthorised access to data held in a computer is guilty of an offence carrying a maximum penalty of 2 years imprisonment. The offence requires that the access was unauthorised and that the defendant knew that fact. Where the access involves a restricted-access system (such as an email or banking platform secured by a password), the prosecution need only prove that the defendant was not entitled to access the data.
State offences may also apply. In Victoria, section 247G of the Crimes Act 1958 prohibits unauthorised access to or modification of restricted data (maximum 2 years). In NSW, section 308H of the Crimes Act 1900 creates an offence of unauthorised access to restricted data held in a computer (maximum 2 years). In Queensland, section 408E of the Criminal Code creates an offence of computer hacking and misuse (maximum 3 years, or 5 years if the access is for the purpose of gaining a benefit or causing a detriment).
A criminal complaint and a civil claim under the statutory tort are not mutually exclusive. You can pursue both. However, the criminal process is controlled by police and prosecutors, not by the complainant. It does not yield compensation. The civil claim is within your control and is directed at obtaining injunctive relief, damages, or both.
What Happens if the Access Occurred During the Relationship
Former partners sometimes argue that they had implied consent to access shared accounts or devices during the relationship. Consent is a defence under the statutory tort, but it is limited. Consent to share a password during a relationship does not extend to accessing the account after the relationship has ended, or after the other party has changed passwords or revoked access. The court will assess consent in context. Where the relationship has ended and the plaintiff has taken steps to restrict access, continued logging in will ordinarily be treated as unauthorised.
What if the Information Has Been Disclosed to Others
If your former partner has disclosed information obtained through unauthorised access, such as sharing your private emails with friends, family, or lawyers, or publishing your financial records, that conduct may give rise to a second limb of the tort: misuse of personal information. It may also amount to doxxing if it involves publication of identifying personal details. Where the disclosure has damaged your reputation, a defamation claim may also be available.
The statutory tort of serious invasion of privacy and the tort of defamation operate independently. Truth is a complete defence to defamation, but it is not a defence to the privacy tort. Information that is true, private, and published without consent is actionable under Schedule 2 regardless of its accuracy.