THE RORT · THE PRIVACY RORT · ARTICLE 1 / 3READING
CASE FILE · THE PRIVACY RORTARTICLE 1 / 3By The Rort · September 2026 · updated 10 October 2026 · therort.com.au

One penalty

Businesses and agencies told the privacy regulator of 1,205 notifications of data breaches likely to cause serious harm in 2025, the most since reporting became compulsory. The only court-ordered penalty under the Privacy Act we could fi…

Reading time9 min
THE RORT STANDARDPublished before 1.0
Every Privacy Act penalty case we foundTHE PRIVACY RORTEvery Privacy Act penalty case we foundFOUR CASES, GROUPED BY OUTCOME, TO 24 SEPTEMBER 2026THE BREACHWHAT THE REGULATOR DIDWHERE IT STANDS, 24 SEP 2026Australian Clinical LabsBreach February 2022, 223,000+ peoplePenalty proceedings; ACL admittedthe contraventions$5.8m ordered, 8 Oct 2025, by consentMetaCambridge Analytica incidentPenalty proceedings fromMarch 2020Withdrawn 17 Dec 2024 for a$50 million payment programMedibankBreach October 2022; 9.7 million allegedPenalty proceedings filed5 June 2024No outcome foundOptusConduct to 20 Sep 2022; about9.5 million allegedPenalty proceedings filed8 Aug 2025No outcome found. Separateclass action trial from7 June 2027So far only one of four Privacy Act penalty cases we found has ended in a penalty, and it was by consent, not at trial.Only a court can impose a civil penalty.FIGURES FOR MEDIBANK AND OPTUS ARE ALLEGATIONS · MAXIMUM PENALTY $2.22M PER CONTRAVENTION, $1.7M FOR META · SOURCES: OAIC RELEASES; SLATER AND GORDONFOUR CASES, ONE PENALTYTHERORT.COM.AU
Four Privacy Act civil penalty cases this outlet could find, and how each has ended, or has not ended, up to 24 September 2026. The Medibank and Optus figures are allegations; only a court can impose a civil penalty.

In calendar year 2025 the Office of the Australian Information Commissioner received 1,205 data breach notifications, an 8 per cent increase over the 1,112 notifications received in 2024 and the most since the notifiable data breaches scheme began in 2018 1.

Set that count beside the other side of the ledger. Up to 24 September 2026, from the OAIC’s recent media releases and from searches, this outlet has found one civil penalty order a court has ever made under the Privacy Act: $5.8 million against Australian Clinical Labs, ordered by the Federal Court, by consent, on 8 October 2025 2.

This article sets those two figures side by side, then asks what explains the gap between them: who can fine at all, what caps applied to the cases here, and how each of the four Privacy Act penalty cases this outlet could find has ended, or has not ended yet.

Fig. 01 / What the regulator is told, and what a court has ordered
Required to report
Businesses and agencies
Covered by the Privacy Act
notifications in calendar 2025, the most since the scheme began
1,205
notifications in 2024
1,112
Notify
Any data breach likely to result in serious harm
Office of the Australian Information Commissioner
Receives the notifications; can apply to a court for a civil penalty, but cannot fine on its own determination.
Apply for a penalty
Only a court can impose a civil penalty
The court
Federal Court
One civil penalty order found under the Privacy Act: Australian Clinical Labs, by consent, 8 October 2025
the Meta case, resolved by a $50 million payment program, not a penalty
Withdrawn
Medibank and Optus, filed in June 2024 and August 2025
No outcome found
  • Total penalty, Australian Clinical Labs$5.8 million
  • For the security failure itself$4.2 million
  • For failing to assess the breach$800,000
  • For failing to notify$800,000
Enforced once
The duty to report has been enforced once, and that order was made by consent, not after a trial.

Stated in: §01, §02, §06, the opening, §03, §04

Fig. 01Source: the article text, each mark cited to its sentenceAs of 2026‑09Hand-curated

01What the law requires

Since 2018 the Privacy Act has required businesses and Commonwealth government agencies it covers to report any data breach that is likely to result in serious harm. Notifications go to the Office of the Australian Information Commissioner, the OAIC, not to the Privacy Commissioner personally.

“Businesses and Commonwealth government agencies covered by the Privacy Act are required to report any data breach that is likely to result in serious harm”

OAIC, Notifiable Data Breaches statistics release, 6 July 2026
1,205
Notifications the OAIC received in calendar 2025, an 8 per cent rise on the 1,112 received in 2024, and the most since the scheme began in 2018.

Health service providers were the sector most often named in those notifications: 225 of them, 19 per cent of the total 1. That describes the sector of the entity that reported.

The OAIC’s release acknowledges a growing number of entities reporting under the scheme 1. This article counts notifications, not breaches.

On a different basis, the 2024-25 financial year, the OAIC separately finalised 1,155 notifications under the scheme, 86 per cent of them within 60 days, and finalised 3,123 privacy complaints 3. That count uses a different period and a different basis to the calendar year count above, and this article does not add the two together or compare them.

Elsewhere in this outlet’s reporting, THE REPORTING RORT’s ‘Nobody has to tell’ sets out whom the notification duty binds, and whom it does not.

02Who can fine

Under the Privacy Act, only a court can impose a civil penalty. The Commissioner may apply to a court for one where an entity is alleged to have engaged in serious or repeated interferences with privacy, but a determination the Commissioner makes alone cannot carry a fine 4.

Every case in this article falls under the caps that applied before 13 December 2022: $2.22 million for each contravention in the ACL, Medibank and Optus cases, and $1.7 million in the Meta case, according to the OAIC 45.

$2.22 million
The maximum civil penalty per contravention that applied to the ACL, Medibank and Optus cases in this article; the Meta case carried a $1.7 million cap. Higher maximums have applied to conduct after 13 December 2022, but none of these cases involve conduct after that date.

A new regime, in force from 13 December 2022 2, allows the Court to impose much higher penalties on conduct after that date: the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover, according to a law firm explainer 6.

Correction, 8 October 2026. The paragraph above gave the higher maximum as the greater of three figures. Under section 13G(3) of the Privacy Act, as amended in 2022, the maximum for a body corporate is the greater of $50 million and either three times the value of the benefit obtained, where the court can determine that value, or 30 per cent of adjusted turnover, where it cannot 12.

A further amendment in 2024 added two more tiers: a mid-tier civil penalty for interferences with privacy that do not meet the ‘serious’ threshold, and a lower tier of OAIC-issued infringement notices for administrative breaches, without court action, according to law firm explainers 67. How many infringement notices or mid-tier proceedings have been used, if any, is not established on this record.

Correction, 10 October 2026. The first point of the summary at the top of this article said: ‘Only a court can fine a breach, on the Commissioner’s application.’ That was wrong. Only a court can impose a civil penalty, on the Commissioner’s application, but since the 2024 amendments to the Privacy Act the OAIC can also issue infringement notices for administrative breaches, without court action, as the paragraph above says 67. The summary point now reads ‘Only a court can impose a civil penalty for a breach, on the Commissioner’s application.’

03The ledger

Every Privacy Act civil penalty case this outlet could find is set out in the ledger graphic at the head of this article, and below, grouped by outcome, not by the order each was filed.

The first order, and the only one we have found up to 24 September 2026, came against Australian Clinical Labs. On 8 October 2025 the Federal Court ordered ACL to pay $5.8 million in civil penalties over the Medlab Pathology data breach, which affected more than 223,000 people; ACL admitted the contraventions, consented to the orders, and the parties made joint submissions to the Court on liability and penalty 2.

$5.8 million
The civil penalty the Federal Court ordered against Australian Clinical Labs on 8 October 2025, the first, and up to 24 September 2026 the only, civil penalty order this outlet could find ever made under the Privacy Act, ordered by consent.

The $5.8 million breaks into three parts: $4.2 million for the security failure itself, under Australian Privacy Principle 11.1; $800,000 for failing to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred; and $800,000 for failing to notify the Commissioner as soon as practicable 2.

“a penalty of $800,000 for ACL’s failure to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred”

OAIC, Australian Clinical Labs release, 9 October 2025

Together the assess and notify penalties come to $1.6 million, about 28 per cent of the $5.8 million total: the notification duty itself, not only the security failure behind it, has been penalised. THE REPORTING RORT’s ‘Fourteen days’ set this same $1.6 million inside a wider ledger of reporting duties across the Commonwealth; this article puts it beside every other Privacy Act penalty case instead.

It is the only order this outlet could find, from the OAIC’s recent media releases, up to 24 September 2026. We say only that we have found no other.

04Two open, one traded

The Commissioner’s case against Meta never reached a judgment. Proceedings began in March 2020 over the Cambridge Analytica incident. After court-ordered mediation that ran from February 2024, the OAIC accepted an enforceable undertaking on 17 December 2024: a $50 million payment program for affected Australians, and the Commissioner withdrew the civil penalty proceedings 5.

$50 million
The payment program Meta agreed to in December 2024; as part of the resolution the Commissioner withdrew the civil penalty case. It is not a civil penalty; the program pays affected people.

A civil penalty is paid to the Commonwealth. Meta’s program pays affected people instead.

“Today’s settlement represents the largest ever payment dedicated to addressing concerns about the privacy of individuals in Australia”

OAIC, Meta settlement release, 17 December 2024

The resolution meant no court ruled on whether Meta breached the Privacy Act. Separately, in 2024-25 the OAIC also reached an enforceable undertaking with Oxfam Australia over a 2021 data breach 3.

The Commissioner’s case against Medibank has no outcome we have found. The Commissioner filed a civil penalty proceeding on 5 June 2024 alleging Medibank seriously interfered with the privacy of 9.7 million Australians by failing to take reasonable steps to protect their personal information, over conduct alleged between March 2021 and October 2022; the breach was in October 2022 8. Up to 24 September 2026, from OAIC releases and searches, we have found no outcome; the underlying court file has not been checked.

The Commissioner’s case against Optus has no outcome we have found yet either. The Commissioner filed a civil penalty proceeding on 8 August 2025 alleging Optus seriously interfered with the privacy of about 9.5 million Australians, over conduct alleged between 17 October 2019 and 20 September 2022, and the Commissioner alleges one contravention for each of the 9.5 million individuals 4. Both the Medibank and Optus figures are allegations, not findings.

We have found no court document that sets a trial date for the Commissioner’s own case against Optus. A separate class action over the same breach, before the same judge, Justice Beach, is set down for trial from 7 June 2027 9. That date belongs to the class action, not to the Commissioner’s case.

05The regulator’s resources

InnovationAus reported in November 2024 that the OAIC had cut dozens of staff after a 23 per cent budget cut 10. IDM reported that in the 2026-27 Budget the OAIC was allocated $36.576 million, down from $39.753 million in 2025-26 11, a fall of $3.177 million, or about 8 per cent. These are two different windows, reported by two different outlets, and this article does not combine them. What effect, if any, the reductions have had on how many matters the office can pursue is not established on this record.

06Enforced once

Set the two counts beside each other again. In 2025 businesses and agencies told the OAIC of 1,205 notifications of data breaches likely to cause serious harm. Since 2018, this outlet could find only one court-ordered civil penalty order under the Privacy Act, agreed rather than fought at trial, and two more penalty cases, filed in June 2024 and August 2025, with no outcome we have found. The duty to report has been enforced once.

The duty to report has been enforced once, and that order was made by consent, not after a trial.

It is a narrower finding than it might look. Only a court can impose a civil penalty, the cap on every case here was at most $2.22 million a contravention, and we have found no court test of the far higher maximums in force since December 2022.

This case will keep a public tally on this count: if a second court-ordered civil penalty lands under the Privacy Act, the headline above changes.

Another written duty has no fine yet. THE SURVEILLANCE RORT’s ‘The internet asks for ID’ found that, on the public record to July 2026, no fines had been issued under the under-16 social media law.

What the regulator does without a court is the subject of the next article in this case.

Update, 8 October 2026. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026.

If it’s a rort, we cover it.
Next in this rort · Article 2 / 3
Nearly five years
The whole case
All 3 articles in The Privacy Rort →
From the desk
  • 10 October 2026Record
    Record: THE PRIVACY RORT, article 1, “One penalty”, corrected, 10 October 2026
    One summary point is corrected: only a court can impose a civil penalty, but the OAIC can also issue infringement notices for administrative breaches
    Read the desk note

    CORRECTED 10 October 2026 (case: THE PRIVACY RORT, article 1 of four).

    ARTICLE CHANGES. A dated Correction paragraph was added in the section on the penalty regime, and the first point of the summary was changed. The point misdescribed who can penalise a breach. Only a court can impose a civil penalty, but since the 2024 amendments the OAIC can also issue infringement notices for administrative breaches, without court action; the point now says only a court can impose a civil penalty for a breach. The four points of the evidence brief now carry a grade (E1), and the standard block names reference [4] as the primary reference. The update date in the byline moves to 10 October 2026.

    STILL OPEN. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. Any response received later will be added as a dated update.

    NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.

  • 8 October 2026Record
    Record: THE PRIVACY RORT, article 1, “One penalty”, right-of-reply update, 8 October 2026
    The right-of-reply question to Optus was sent on 2 October; Optus’s media team replied on 8 October, quoted in article 2
    Read the desk note

    UPDATED 8 October 2026 (case: THE PRIVACY RORT, article 1 of four).

    ARTICLE CHANGES. None to this article’s text. The right-of-reply question to Optus was sent on 2 October 2026. Optus’s media team replied on 8 October, in an email signed Optus Media Team. The reply does not say whether Optus contests the Commissioner’s allegations. Its sentences on Optus’s public position and on matters before the Federal Court are quoted in article 2, “Nearly five years”.

    STILL OPEN. The question to Optus, whether it contests the Commissioner’s allegations and expects the Commissioner’s case to be heard with the class action, is not answered by the reply. Questions to the Office of the Australian Information Commissioner remain open; any answers will be added as dated updates.

    NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.

  • 8 October 2026Record
    Record: THE PRIVACY RORT, article 1, “One penalty”, corrected and updated after the reply deadline, 8 October 2026
    No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. The penalty maximum for a body corporate is corrected to the statute’s wording
    Read the desk note

    UPDATED 8 October 2026 (case: THE PRIVACY RORT, article 1 of four).

    ARTICLE CHANGES. A correction to the paragraph on the penalty regime in force from 13 December 2022. Under section 13G(3) of the Privacy Act, as amended in 2022, the maximum for a body corporate is the greater of $50 million and either three times the value of the benefit obtained, where the court can determine that value, or 30 per cent of adjusted turnover, where it cannot; the earlier sentence, from a law firm explainer, gave the maximum as the greater of the three figures. A dated update records the position at the reply deadline. One reference added: the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022.

    STILL OPEN. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. Any response received later will be added as a dated update.

    NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.

  • 6 October 2026Record
    Record: THE PRIVACY RORT, article 1, “One penalty”, right-of-reply update, 6 October 2026
    The right-of-reply question to Medibank was sent on 2 October; a Medibank spokesperson replied on 6 October, quoted in article 2
    Read the desk note

    UPDATED 6 October 2026 (case: THE PRIVACY RORT, article 1 of four).

    ARTICLE CHANGES. None to this article’s text. The right-of-reply question to Medibank was sent on 2 October 2026. A Medibank spokesperson replied on 6 October: ‘As the matter is before the Court, it would not be appropriate for Medibank to comment.’ The reply is quoted in article 2, “Nearly five years”.

    STILL OPEN. Questions to the Office of the Australian Information Commissioner and Singtel Optus remain open; any answers will be added as dated updates.

    NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.

  • 25 September 2026Record
    Record: THE PRIVACY RORT, article 1, “One penalty”, published
    Right-of-reply questions to the OAIC, Singtel Optus and Medibank had not been sent at publication; any answers will be added as dated updates
    Read the desk note

    ATTENDED 25 September 2026 (case: THE PRIVACY RORT, article 1 of four).

    FINDING. In calendar 2025 the OAIC received 1,205 data breach notifications, the most since the notifiable data breaches scheme began in 2018. Set beside that count, up to 24 September 2026 this outlet has found one civil penalty order a court has ever made under the Privacy Act: $5.8 million against Australian Clinical Labs, ordered by consent on 8 October 2025. The Commissioner’s penalty cases against Optus and Medibank have no outcome this outlet has found, and the Commissioner’s case against Meta was withdrawn in December 2024 for a $50 million payment program instead of a court finding.

    ARTICLE CHANGES. Article 1, “One penalty”, published, setting the record notification count beside every Privacy Act civil penalty case this outlet could find. Three more articles are planned in this case.

    STILL OPEN. Right-of-reply questions to the Office of the Australian Information Commissioner, Singtel Optus and Medibank had not been sent when this article was published. Any answers will be added as dated updates.

    NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.

The desk record →
THE RORT STANDARD 1.0: published before 1.0, not yet reviewed
This piece was published before the standard took effect on 8 Oct 2026 and has not been reviewed against it. What follows is what its own data records, not a finding that it meets the standard.
RS-1 7 of 12 references are primary documents (Tier 1). Enforced on new pieces by the release gate (RS-1.1) and the desk record.
RS-2 12 references: resolves checked 0, exists confirmed 0, supports confirmed 0, the rest unchecked. Enforced on new pieces by the release gate (RS-2.1) and the desk record.
RS-3 No counter. Enforced by the release gate (RS-3.1 to RS-3.4) and the desk record.
RS-4 Weakest headline finding: E1. Enforced on new pieces by the release gate (RS-4.1 to RS-4.2) and the desk record.
RS-5 Medibank · questions sent 2 Oct 2026 · declined 6 Oct 2026.
RS-5 Singtel Optus · questions sent 2 Oct 2026 · responded 8 Oct 2026, printed in full below.
RS-5 Office of the Australian Information Commissioner (OAIC) · questions sent 2 Oct 2026 · reply asked by 8 Oct 2026 · no response 8 Oct 2026. Enforced on new pieces by the release gate (RS-5.1 to RS-5.8) and the desk record.
RS-6 Unnamed sources not yet declared (published before 1.0). Enforced on new pieces by the release gate (RS-6.1 to RS-6.2) and the desk record.
RS-7 Corrections: 8 Oct 2026, 10 Oct 2026. Enforced by the release gate (RS-7.1 to RS-7.2) and the desk record.
RS-8 None declared. Enforced by the release gate (RS-8.1) and the desk record.
RS-10 No desk sign-off: published before 1.0. Enforced on new pieces by the release gate (RS-10.1) and the desk record.
RS-11 Complaints: desk@therort.com.au. Factual errors: corrections@therort.com.au. Acknowledged within five business days. Enforced by the release gate (RS-11.1 to RS-11.4) and the desk record.
Register B-0008 (RS-5.2, closed); B-0041 (RS-7.1, closed by B-0043); B-0043 (RS-7.1, closes B-0041); B-0044 (RS-6.2, closed by B-0064); B-0064 (RS-6.2, closes B-0044); B-0075 (RS-2, closed). The breach register
Reply from Singtel Optus, received 8 Oct 2026, printed in full
Optus’s position on these matters is on the public record, including our submission to the Senate Environment and Communications Committee following the September 2025 Triple Zero outage. Matters currently before the Federal Court will be addressed through the appropriate legal process.
References & Sources12 sources · all linked
Evidence strength
  • Primary 7
  • Trade 5
Primary
the document itself: legislation, a court record, a filing, a regulator’s own publication
Trade
specialist or trade press
How sources are graded

A check appears under a source only where one is on record: a machine test of whether the link loads, and, where the desk has made the call, whether the document exists and whether it carries the claim. Nothing is shown for a check that is not on record. What these checks mean

  1. Primaryhttps://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025,-new-ndb-stats-show
  2. Primaryhttps://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act
  3. Primaryhttps://www.oaic.gov.au/news/media-centre/annual-report-highlights-oaics-work-on-privacy-and-information-access-rights-and-strengthened-regulatory-approach
  4. Primaryhttps://www.oaic.gov.au/news/media-centre/australian-information-commissioner-takes-civil-penalty-action-against-optus
  5. Primaryhttps://www.oaic.gov.au/news/media-centre/landmark-settlement-of-$50m-from-meta-for-australian-users-impacted-by-cambridge-analytica-incident
  6. Tradehttps://www.corrs.com.au/insights/changes-to-australias-privacy-act-bolster-enforcement-and-investigative-powers
  7. Tradehttps://www.atmosgroup.com.au/resources/the-privacy-commissioner-the-infringement-notice-and-the-low-tier-civil-penalty
  8. Primaryhttps://www.oaic.gov.au/news/media-centre/oaic-takes-civil-penalty-action-against-medibank
  9. Tradehttps://www.slatergordon.com.au/class-actions/current-class-actions/optus-data-breach
  10. Tradehttps://www.innovationaus.com/oaic-slashes-staff-to-meet-11m-budget-crunch/
  11. Tradehttps://idm.net.au/article/0015590-funding-squeeze-hits-oaic-privacy-reforms-land
  12. Primaryhttps://www.legislation.gov.au/C2022A00083/asmade/2022-12-12/text/original/pdf
This piece is one node in the model. Every entity it names has a dossier that assembles itself from every article mentioning it. Follow the names, and the case, through the record.
← THE PRIVACY RORT