One penalty
Businesses and agencies told the privacy regulator of 1,205 notifications of data breaches likely to cause serious harm in 2025, the most since reporting became compulsory. The only court-ordered penalty under the Privacy Act we could fi…
In calendar year 2025 the Office of the Australian Information Commissioner received 1,205 data breach notifications, an 8 per cent increase over the 1,112 notifications received in 2024 and the most since the notifiable data breaches scheme began in 2018 1.
Set that count beside the other side of the ledger. Up to 24 September 2026, from the OAIC’s recent media releases and from searches, this outlet has found one civil penalty order a court has ever made under the Privacy Act: $5.8 million against Australian Clinical Labs, ordered by the Federal Court, by consent, on 8 October 2025 2.
This article sets those two figures side by side, then asks what explains the gap between them: who can fine at all, what caps applied to the cases here, and how each of the four Privacy Act penalty cases this outlet could find has ended, or has not ended yet.
- notifications in calendar 2025, the most since the scheme began
- 1,205
- notifications in 2024
- 1,112
- the Meta case, resolved by a $50 million payment program, not a penalty
- Withdrawn
- Medibank and Optus, filed in June 2024 and August 2025
- No outcome found
Stated in: §01, §02, §06, the opening, §03, §04
01What the law requires
Since 2018 the Privacy Act has required businesses and Commonwealth government agencies it covers to report any data breach that is likely to result in serious harm. Notifications go to the Office of the Australian Information Commissioner, the OAIC, not to the Privacy Commissioner personally.
“Businesses and Commonwealth government agencies covered by the Privacy Act are required to report any data breach that is likely to result in serious harm”
OAIC, Notifiable Data Breaches statistics release, 6 July 2026Health service providers were the sector most often named in those notifications: 225 of them, 19 per cent of the total 1. That describes the sector of the entity that reported.
The OAIC’s release acknowledges a growing number of entities reporting under the scheme 1. This article counts notifications, not breaches.
On a different basis, the 2024-25 financial year, the OAIC separately finalised 1,155 notifications under the scheme, 86 per cent of them within 60 days, and finalised 3,123 privacy complaints 3. That count uses a different period and a different basis to the calendar year count above, and this article does not add the two together or compare them.
Elsewhere in this outlet’s reporting, THE REPORTING RORT’s ‘Nobody has to tell’ sets out whom the notification duty binds, and whom it does not.
02Who can fine
Under the Privacy Act, only a court can impose a civil penalty. The Commissioner may apply to a court for one where an entity is alleged to have engaged in serious or repeated interferences with privacy, but a determination the Commissioner makes alone cannot carry a fine 4.
Every case in this article falls under the caps that applied before 13 December 2022: $2.22 million for each contravention in the ACL, Medibank and Optus cases, and $1.7 million in the Meta case, according to the OAIC 45.
A new regime, in force from 13 December 2022 2, allows the Court to impose much higher penalties on conduct after that date: the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover, according to a law firm explainer 6.
Correction, 8 October 2026. The paragraph above gave the higher maximum as the greater of three figures. Under section 13G(3) of the Privacy Act, as amended in 2022, the maximum for a body corporate is the greater of $50 million and either three times the value of the benefit obtained, where the court can determine that value, or 30 per cent of adjusted turnover, where it cannot 12.
A further amendment in 2024 added two more tiers: a mid-tier civil penalty for interferences with privacy that do not meet the ‘serious’ threshold, and a lower tier of OAIC-issued infringement notices for administrative breaches, without court action, according to law firm explainers 67. How many infringement notices or mid-tier proceedings have been used, if any, is not established on this record.
Correction, 10 October 2026. The first point of the summary at the top of this article said: ‘Only a court can fine a breach, on the Commissioner’s application.’ That was wrong. Only a court can impose a civil penalty, on the Commissioner’s application, but since the 2024 amendments to the Privacy Act the OAIC can also issue infringement notices for administrative breaches, without court action, as the paragraph above says 67. The summary point now reads ‘Only a court can impose a civil penalty for a breach, on the Commissioner’s application.’
03The ledger
Every Privacy Act civil penalty case this outlet could find is set out in the ledger graphic at the head of this article, and below, grouped by outcome, not by the order each was filed.
The first order, and the only one we have found up to 24 September 2026, came against Australian Clinical Labs. On 8 October 2025 the Federal Court ordered ACL to pay $5.8 million in civil penalties over the Medlab Pathology data breach, which affected more than 223,000 people; ACL admitted the contraventions, consented to the orders, and the parties made joint submissions to the Court on liability and penalty 2.
The $5.8 million breaks into three parts: $4.2 million for the security failure itself, under Australian Privacy Principle 11.1; $800,000 for failing to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred; and $800,000 for failing to notify the Commissioner as soon as practicable 2.
“a penalty of $800,000 for ACL’s failure to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred”
OAIC, Australian Clinical Labs release, 9 October 2025Together the assess and notify penalties come to $1.6 million, about 28 per cent of the $5.8 million total: the notification duty itself, not only the security failure behind it, has been penalised. THE REPORTING RORT’s ‘Fourteen days’ set this same $1.6 million inside a wider ledger of reporting duties across the Commonwealth; this article puts it beside every other Privacy Act penalty case instead.
It is the only order this outlet could find, from the OAIC’s recent media releases, up to 24 September 2026. We say only that we have found no other.
04Two open, one traded
The Commissioner’s case against Meta never reached a judgment. Proceedings began in March 2020 over the Cambridge Analytica incident. After court-ordered mediation that ran from February 2024, the OAIC accepted an enforceable undertaking on 17 December 2024: a $50 million payment program for affected Australians, and the Commissioner withdrew the civil penalty proceedings 5.
A civil penalty is paid to the Commonwealth. Meta’s program pays affected people instead.
“Today’s settlement represents the largest ever payment dedicated to addressing concerns about the privacy of individuals in Australia”
OAIC, Meta settlement release, 17 December 2024The resolution meant no court ruled on whether Meta breached the Privacy Act. Separately, in 2024-25 the OAIC also reached an enforceable undertaking with Oxfam Australia over a 2021 data breach 3.
The Commissioner’s case against Medibank has no outcome we have found. The Commissioner filed a civil penalty proceeding on 5 June 2024 alleging Medibank seriously interfered with the privacy of 9.7 million Australians by failing to take reasonable steps to protect their personal information, over conduct alleged between March 2021 and October 2022; the breach was in October 2022 8. Up to 24 September 2026, from OAIC releases and searches, we have found no outcome; the underlying court file has not been checked.
The Commissioner’s case against Optus has no outcome we have found yet either. The Commissioner filed a civil penalty proceeding on 8 August 2025 alleging Optus seriously interfered with the privacy of about 9.5 million Australians, over conduct alleged between 17 October 2019 and 20 September 2022, and the Commissioner alleges one contravention for each of the 9.5 million individuals 4. Both the Medibank and Optus figures are allegations, not findings.
We have found no court document that sets a trial date for the Commissioner’s own case against Optus. A separate class action over the same breach, before the same judge, Justice Beach, is set down for trial from 7 June 2027 9. That date belongs to the class action, not to the Commissioner’s case.
05The regulator’s resources
InnovationAus reported in November 2024 that the OAIC had cut dozens of staff after a 23 per cent budget cut 10. IDM reported that in the 2026-27 Budget the OAIC was allocated $36.576 million, down from $39.753 million in 2025-26 11, a fall of $3.177 million, or about 8 per cent. These are two different windows, reported by two different outlets, and this article does not combine them. What effect, if any, the reductions have had on how many matters the office can pursue is not established on this record.
06Enforced once
Set the two counts beside each other again. In 2025 businesses and agencies told the OAIC of 1,205 notifications of data breaches likely to cause serious harm. Since 2018, this outlet could find only one court-ordered civil penalty order under the Privacy Act, agreed rather than fought at trial, and two more penalty cases, filed in June 2024 and August 2025, with no outcome we have found. The duty to report has been enforced once.
The duty to report has been enforced once, and that order was made by consent, not after a trial.
It is a narrower finding than it might look. Only a court can impose a civil penalty, the cap on every case here was at most $2.22 million a contravention, and we have found no court test of the far higher maximums in force since December 2022.
This case will keep a public tally on this count: if a second court-ordered civil penalty lands under the Privacy Act, the headline above changes.
Another written duty has no fine yet. THE SURVEILLANCE RORT’s ‘The internet asks for ID’ found that, on the public record to July 2026, no fines had been issued under the under-16 social media law.
What the regulator does without a court is the subject of the next article in this case.
Update, 8 October 2026. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026.
If it’s a rort, we cover it.
- Record: THE PRIVACY RORT, article 1, “One penalty”, corrected, 10 October 2026One summary point is corrected: only a court can impose a civil penalty, but the OAIC can also issue infringement notices for administrative breaches
Read the desk note
CORRECTED 10 October 2026 (case: THE PRIVACY RORT, article 1 of four).
ARTICLE CHANGES. A dated Correction paragraph was added in the section on the penalty regime, and the first point of the summary was changed. The point misdescribed who can penalise a breach. Only a court can impose a civil penalty, but since the 2024 amendments the OAIC can also issue infringement notices for administrative breaches, without court action; the point now says only a court can impose a civil penalty for a breach. The four points of the evidence brief now carry a grade (E1), and the standard block names reference [4] as the primary reference. The update date in the byline moves to 10 October 2026.
STILL OPEN. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. Any response received later will be added as a dated update.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Record: THE PRIVACY RORT, article 1, “One penalty”, right-of-reply update, 8 October 2026The right-of-reply question to Optus was sent on 2 October; Optus’s media team replied on 8 October, quoted in article 2
Read the desk note
UPDATED 8 October 2026 (case: THE PRIVACY RORT, article 1 of four).
ARTICLE CHANGES. None to this article’s text. The right-of-reply question to Optus was sent on 2 October 2026. Optus’s media team replied on 8 October, in an email signed Optus Media Team. The reply does not say whether Optus contests the Commissioner’s allegations. Its sentences on Optus’s public position and on matters before the Federal Court are quoted in article 2, “Nearly five years”.
STILL OPEN. The question to Optus, whether it contests the Commissioner’s allegations and expects the Commissioner’s case to be heard with the class action, is not answered by the reply. Questions to the Office of the Australian Information Commissioner remain open; any answers will be added as dated updates.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Record: THE PRIVACY RORT, article 1, “One penalty”, corrected and updated after the reply deadline, 8 October 2026No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. The penalty maximum for a body corporate is corrected to the statute’s wording
Read the desk note
UPDATED 8 October 2026 (case: THE PRIVACY RORT, article 1 of four).
ARTICLE CHANGES. A correction to the paragraph on the penalty regime in force from 13 December 2022. Under section 13G(3) of the Privacy Act, as amended in 2022, the maximum for a body corporate is the greater of $50 million and either three times the value of the benefit obtained, where the court can determine that value, or 30 per cent of adjusted turnover, where it cannot; the earlier sentence, from a law firm explainer, gave the maximum as the greater of the three figures. A dated update records the position at the reply deadline. One reference added: the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022.
STILL OPEN. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. Any response received later will be added as a dated update.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Record: THE PRIVACY RORT, article 1, “One penalty”, right-of-reply update, 6 October 2026The right-of-reply question to Medibank was sent on 2 October; a Medibank spokesperson replied on 6 October, quoted in article 2
Read the desk note
UPDATED 6 October 2026 (case: THE PRIVACY RORT, article 1 of four).
ARTICLE CHANGES. None to this article’s text. The right-of-reply question to Medibank was sent on 2 October 2026. A Medibank spokesperson replied on 6 October: ‘As the matter is before the Court, it would not be appropriate for Medibank to comment.’ The reply is quoted in article 2, “Nearly five years”.
STILL OPEN. Questions to the Office of the Australian Information Commissioner and Singtel Optus remain open; any answers will be added as dated updates.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Record: THE PRIVACY RORT, article 1, “One penalty”, publishedRight-of-reply questions to the OAIC, Singtel Optus and Medibank had not been sent at publication; any answers will be added as dated updates
Read the desk note
ATTENDED 25 September 2026 (case: THE PRIVACY RORT, article 1 of four).
FINDING. In calendar 2025 the OAIC received 1,205 data breach notifications, the most since the notifiable data breaches scheme began in 2018. Set beside that count, up to 24 September 2026 this outlet has found one civil penalty order a court has ever made under the Privacy Act: $5.8 million against Australian Clinical Labs, ordered by consent on 8 October 2025. The Commissioner’s penalty cases against Optus and Medibank have no outcome this outlet has found, and the Commissioner’s case against Meta was withdrawn in December 2024 for a $50 million payment program instead of a court finding.
ARTICLE CHANGES. Article 1, “One penalty”, published, setting the record notification count beside every Privacy Act civil penalty case this outlet could find. Three more articles are planned in this case.
STILL OPEN. Right-of-reply questions to the Office of the Australian Information Commissioner, Singtel Optus and Medibank had not been sent when this article was published. Any answers will be added as dated updates.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Primary
- the document itself: legislation, a court record, a filing, a regulator’s own publication
- Trade
- specialist or trade press
A check appears under a source only where one is on record: a machine test of whether the link loads, and, where the desk has made the call, whether the document exists and whether it carries the claim. Nothing is shown for a check that is not on record. What these checks mean
- Primaryhttps://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025,-new-ndb-stats-show
- Primaryhttps://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act
- Primaryhttps://www.oaic.gov.au/news/media-centre/annual-report-highlights-oaics-work-on-privacy-and-information-access-rights-and-strengthened-regulatory-approach
- Primaryhttps://www.oaic.gov.au/news/media-centre/australian-information-commissioner-takes-civil-penalty-action-against-optus
- Primaryhttps://www.oaic.gov.au/news/media-centre/landmark-settlement-of-$50m-from-meta-for-australian-users-impacted-by-cambridge-analytica-incident
- Tradehttps://www.corrs.com.au/insights/changes-to-australias-privacy-act-bolster-enforcement-and-investigative-powers
- Tradehttps://www.atmosgroup.com.au/resources/the-privacy-commissioner-the-infringement-notice-and-the-low-tier-civil-penalty
- Primaryhttps://www.oaic.gov.au/news/media-centre/oaic-takes-civil-penalty-action-against-medibank
- Tradehttps://www.slatergordon.com.au/class-actions/current-class-actions/optus-data-breach
- Tradehttps://www.innovationaus.com/oaic-slashes-staff-to-meet-11m-budget-crunch/
- Tradehttps://idm.net.au/article/0015590-funding-squeeze-hits-oaic-privacy-reforms-land
- Primaryhttps://www.legislation.gov.au/C2022A00083/asmade/2022-12-12/text/original/pdf