The Privacy Act 1988 (Cth) has long been one of the oldest national data protection statutes in the world. Despite its name, it has been more concerned with regulating how personal data is handled than with granting individuals a stand-alone right to privacy they can enforce in court.
That changed in June 2025. Australians now have access to a statutory cause of action, or tort, built into the Act for serious invasions of their privacy. The elements have been widely discussed, but the practical consequences for employers are now being tested.
What the Tort Requires
The cause of action arises in the following circumstances:
- An individual suffers an invasion of their privacy, either by an intrusion into their seclusion, a misuse of their information, or both. The Act contemplates that a person may claim for both elements, for example where material produced by an intrusion into seclusion is then published by the defendant.
- A person in the individual's position would have had a reasonable expectation of privacy.
- The invasion of privacy was intentional or reckless.
- The invasion of privacy was serious.
- The public interest in the plaintiff's privacy outweighs any countervailing public interest.
Two features of this cause of action matter to employers. First, negligence is not enough. Accidental or careless handling of employee information will not support a claim under this tort, though it may still attract scrutiny through other pathways, including an OAIC privacy complaint. Second, the plaintiff does not need to prove damage. The tort is actionable per se, and truth is not a defence.
Why the Employee Records Exemption Does Not Apply
The Australian Privacy Principles contain an exemption for employee records. The statutory tort does not. This means that workplace privacy rights in Australia now extend to the handling of employee records in a way the APPs never did. Employers who have relied on the exemption to justify their approach to monitoring, internal investigations, or the storage and disclosure of staff information should review that assumption.
The Act expressly separates the tort from the rest of the Privacy Act. The APPs, the OAIC's enforcement powers, and the tort are different regimes with different elements, defendants, and forums. A business that is compliant with the APPs is not, by that fact alone, protected from a claim under the tort.
Where Employers Face Exposure
Three areas carry the most immediate risk.
Workplace monitoring. Email reading, device tracking, and covert surveillance can all amount to an intrusion into seclusion or a misuse of information. Monitoring that is disclosed, proportionate, and conducted for a legitimate business purpose may be defensible on grounds of implied consent, lawful authority, or because the employee did not have a reasonable expectation of privacy in the circumstances. Monitoring that is covert, disproportionate, or unexplained is harder to defend. The Fair Work Ombudsman's guidance on workplace privacy is a useful starting point for assessing whether current practices meet community expectations.
Internal investigations. Investigations often involve collecting and sharing employee information with third parties, including external advisers and other staff. Each disclosure is a potential misuse of information. The seriousness threshold and the public interest balancing test will do some work here, but the way an investigation is scoped and conducted matters.
Data handling. Unauthorised disclosure of personal data, including health records, financial information, and identifying details, can ground a claim. The defendant pool is broad: individuals can sue any person or entity, regardless of whether the defendant is an APP entity. Small businesses that fall outside the APPs are not outside the tort.
Victorian work on workplace privacy issues has already identified the tension between legitimate management needs and employee expectations of privacy. That tension now has a civil remedy attached to it.
Defences and Exemptions
Defences under Part 2 of Schedule 2 include lawful authority, consent, necessity, defence of persons or property, and certain defamation-related defences where the invasion involved publication. Exemptions under Part 3 operate differently. They can be determined before trial on application by the defendant, which may resolve the matter without the defendant going to trial at all. Defences are raised and determined at trial. That procedural distinction is significant for strategy, particularly in matters where an exemption is available.
Employers should also note that an apology does not constitute an admission of fault or liability, but the court may consider it when determining damages. The public interest balancing test requires the court to weigh the plaintiff's privacy interest against countervailing public interests, including freedom of expression and the prevention and detection of crime and fraud. Where a business can lead evidence on those interests, it should.
For matters involving publication of private information that also damages reputation, see defamationlawyer.au.
Time Limits and Urgent Applications
Limitation periods are strict: one year from awareness, or three years from occurrence, whichever is earlier, with a maximum extension to six years. Where an injunction is sought to restrain an ongoing invasion or to prevent publication, the court must have particular regard to the public interest in publication. Businesses served with an urgent injunction application should seek advice immediately.
Time limits are strict. You may have as little as 12 months to act.
Sutton Laurence King Lawyers acts for both plaintiffs and defendants under the statutory tort. If you are an employer reviewing your monitoring or data practices, or you have been served with a claim, we offer a confidential initial assessment. Enquire through our contact form or call our office to discuss your position.
This article provides general information only and is not legal advice. You should obtain advice about your own circumstances before acting.