The Privacy Rort
- CONTESTEDThe Information Commissioner filed civil penalty proceedings against Medibank on 5 June 2024 and against Optus on 8 August 2025; neither had a published outcome as of 24 September 2026.Nearly five years
- Opened on fileOne penalty
Since 2018, businesses and Commonwealth agencies covered by the Privacy Act have had to report data breaches likely to cause serious harm. In 2025 the privacy regulator received 1,205 notifications, the most since the scheme began. The first civil penalties ever ordered under the Act came on 8 October 2025: $5.8 million against Australian Clinical Labs, which admitted the contraventions and consented to the orders. Up to 24 September 2026 we have found no other. Only a court can order a civil penalty, and the regulator's other outcomes have been findings, declarations, a negotiated payment, or nothing yet: Kmart's scanning of every shopper in 28 stores was found unlawful, a finding the law does not allow to carry a fine and one Kmart has asked the Administrative Review Tribunal to review, further action against Clearview AI was judged not warranted nearly three years after it was found in breach, and the Optus and Medibank penalty cases, filed over 2022 breaches, have no outcome we have found. A joint investigation of Latitude, opened in May 2023, has published none.
Fig. 02 / What happened
Fig. 03 / Who the record names
How we know
The exhibits sit beside the title above, each tied to the article that documented it. How evidence and sources are graded: evidence grade, source tiers.
What else is connected
Named in this case and in others. A count of where the record names them, not a finding about what they did.
From the desk
- Schedule 1, Part 15 of the 2024 Act commencesPromised in 2019 · The Privacy RortPart 15 inserts Australian Privacy Principles 1.7 to 1.9 and adds 1.7 to the low penalty tier
Read the desk note
Schedule 1, Part 15 of the Privacy and Other Legislation Amendment Act 2024, "Automated decisions and privacy policies", commences on 10 December 2026, twenty-four months after Royal Assent. It inserts Australian Privacy Principles 1.7 to 1.9, which require an entity that has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, using personal information about that individual, to set out in its privacy policy the kinds of personal information such programs use and the kinds of decisions they make or help make, and it adds Australian Privacy Principle 1.7 to the list of obligations in the low penalty tier, section 13K. Watch this date for what the OAIC publishes on the new obligation, and for any use of the low tier that follows.
- Record: THE PRIVACY RORT, article 1, “One penalty”, corrected, 10 October 2026One penalty · The Privacy RortOne summary point is corrected: only a court can impose a civil penalty, but the OAIC can also issue infringement notices for administrative breaches
The first point of the summary at the top of this article said: ‘Only a court can fine a breach, on the Commissioner’s application.’ That was wrong. Only a court can impose a civil penalty, on the Commissioner’s application, but since the 2024 amendments to the Privacy Act the OAIC can also issue infringement notices for administrative breaches, without court action, as the paragraph above says…
Read the desk note
CORRECTED 10 October 2026 (case: THE PRIVACY RORT, article 1 of four).
ARTICLE CHANGES. A dated Correction paragraph was added in the section on the penalty regime, and the first point of the summary was changed. The point misdescribed who can penalise a breach. Only a court can impose a civil penalty, but since the 2024 amendments the OAIC can also issue infringement notices for administrative breaches, without court action; the point now says only a court can impose a civil penalty for a breach. The four points of the evidence brief now carry a grade (E1), and the standard block names reference [4] as the primary reference. The update date in the byline moves to 10 October 2026.
STILL OPEN. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. Any response received later will be added as a dated update.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Record: THE PRIVACY RORT, article 1, “One penalty”, corrected and updated after the reply deadline, 8 October 2026One penalty · The Privacy RortNo response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. The penalty maximum for a body corporate is corrected to the statute’s wording
The paragraph above gave the higher maximum as the greater of three figures. Under section 13G(3) of the Privacy Act, as amended in 2022, the maximum for a body corporate is the greater of $50 million and either three times the value of the benefit obtained, where the court can determine that value, or 30 per cent of adjusted turnover, where it cannot.
Read the desk note
UPDATED 8 October 2026 (case: THE PRIVACY RORT, article 1 of four).
ARTICLE CHANGES. A correction to the paragraph on the penalty regime in force from 13 December 2022. Under section 13G(3) of the Privacy Act, as amended in 2022, the maximum for a body corporate is the greater of $50 million and either three times the value of the benefit obtained, where the court can determine that value, or 30 per cent of adjusted turnover, where it cannot; the earlier sentence, from a law firm explainer, gave the maximum as the greater of the three figures. A dated update records the position at the reply deadline. One reference added: the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022.
STILL OPEN. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. Any response received later will be added as a dated update.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Record: THE PRIVACY RORT, article 1, “One penalty”, right-of-reply update, 8 October 2026One penalty · The Privacy RortThe right-of-reply question to Optus was sent on 2 October; Optus’s media team replied on 8 October, quoted in article 2
Read the desk note
UPDATED 8 October 2026 (case: THE PRIVACY RORT, article 1 of four).
ARTICLE CHANGES. None to this article’s text. The right-of-reply question to Optus was sent on 2 October 2026. Optus’s media team replied on 8 October, in an email signed Optus Media Team. The reply does not say whether Optus contests the Commissioner’s allegations. Its sentences on Optus’s public position and on matters before the Federal Court are quoted in article 2, “Nearly five years”.
STILL OPEN. The question to Optus, whether it contests the Commissioner’s allegations and expects the Commissioner’s case to be heard with the class action, is not answered by the reply. Questions to the Office of the Australian Information Commissioner remain open; any answers will be added as dated updates.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Record: THE PRIVACY RORT, article 2, "Nearly five years", updated after the reply deadline, 8 October 2026Nearly five years · The Privacy RortNo response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. No response was received from Latitude Financial Services by the deadline, 5pm AEDT on Thursday 8 October 2026. Medibank’s reply of 6 October was its only one
Read the desk note
UPDATED 8 October 2026 (case: THE PRIVACY RORT, article 2 of four).
ARTICLE CHANGES. A dated update records the position at the reply deadline, 5pm AEDT on Thursday 8 October 2026: Medibank’s reply of 6 October, quoted in the article, is the only reply received from Medibank, and the two absence lines below.
STILL OPEN. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. No response was received from Latitude Financial Services by the deadline, 5pm AEDT on Thursday 8 October 2026. The question to Optus stands as recorded earlier on 8 October 2026. Any response received later will be added as a dated update.
NEXT DATE: 12 February 2027, the date by which, MLex reports, Justice Beach ordered the parties in the Optus matters to mediation; then 7 June 2027, when the related class action is set down for trial.
- Record: THE PRIVACY RORT, article 2, "Nearly five years", updated, 8 October 2026Nearly five years · The Privacy RortOptus’s media team replied on 8 October to the question about its penalty case; the reply is quoted
THE RORT asked Optus on 2 October whether it contests the Commissioner’s allegations in this case, and whether it expects the Commissioner’s case to be heard with the class action. Optus’s media team replied by email on 8 October. The email is signed Optus Media Team and carries no request that it be kept off the record. It says: ‘Optus’s position on these matters is on the public record…
Read the desk note
UPDATED 8 October 2026 (case: THE PRIVACY RORT, article 2 of four).
ARTICLE CHANGES. Optus’s media team replied on 8 October to the question sent on 2 October, in an email signed Optus Media Team. The article now quotes two sentences of the reply, one on Optus’s public position and one on matters before the Federal Court, in a dated update after the paragraph on the Optus penalty case, which is unchanged. The reply does not say whether Optus contests the Commissioner’s allegations, and its Federal Court sentence names no matter; the article does not say which matter it refers to. One reference added: the release that Optus dated 21 September 2026 and the reply links, which concerns the September 2025 Triple Zero outage.
STILL OPEN. The question to Optus, whether it contests the Commissioner’s allegations and expects the Commissioner’s case to be heard with the class action, is not answered by the reply. Questions to the OAIC and Latitude Financial remain open, and the question to Medibank stands as recorded on 6 October 2026; any answers will be added as dated updates.
NEXT DATE: 12 February 2027, the date by which, MLex reports, Justice Beach ordered the parties in the Optus matters to mediation; then 7 June 2027, when the related class action is set down for trial. The reply date given to the OAIC, Latitude Financial and Medibank was 5pm AEDT, Thursday 8 October 2026.
- Record: THE PRIVACY RORT, article 4, "Promised in 2019", publishedPromised in 2019 · The Privacy RortRight-of-reply questions were sent to the OAIC and the Attorney-General's Department on 2 October. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. No response was received from the Attorney-General's Department by the deadline, 5pm AEDT on Thursday 8 October 2026.
Read the desk note
ATTENDED 8 October 2026 (case: THE PRIVACY RORT, article 4 of four).
FINDING. The government's own timetable set the Privacy Act review, promised on 12 December 2019, to commence in 2020 and to be completed in 2021. The review published an Issues Paper in October 2020. The review's report was released in February 2023 and the government responded on 28 September 2023. Nearly seven years after that promise, the second round of changes the review led to is still an exposure draft, and this outlet found no record that it has been introduced to Parliament. The two lower penalty tiers added by the 2024 Act, and its changes to the top tier, apply only to conduct after 11 December 2024, almost exactly five years after the promise itself. The only civil penalty this outlet has found ordered under the Privacy Act, against Australian Clinical Labs, was ordered under the cap that applied before any of these changes. The Privacy Commissioner's prepared keynote address for 4 May 2026 says the OAIC's first compliance sweep found instances of non-compliance in a significant proportion of the 60 entities it reviewed; the OAIC said in June 2026 that a report would be published in the new financial year; this outlet has found none yet.
ARTICLE CHANGES. Article 4, "Promised in 2019", published, setting the government's own reform clock beside the Privacy Act's enforcement record. Right of reply: THE RORT emailed questions to the Office of the Australian Information Commissioner and the Attorney-General's Department on 2 October 2026, with a reply date of 5pm AEDT on Thursday 8 October 2026. No response was received from the Office of the Australian Information Commissioner by the deadline, 5pm AEDT on Thursday 8 October 2026. No response was received from the Attorney-General's Department by the deadline, 5pm AEDT on Thursday 8 October 2026. The article records both under "Right of reply". Optus's media team replied on 8 October 2026 to the email that put the question about the Commissioner's case against it, together with questions for THE TRIPLE ZERO RORT; the article prints the reply and says what it does not answer. A Medibank spokesperson replied on 6 October 2026 to a separate question, about Medibank's own court application; that reply is quoted in article 2, "Nearly five years", and is not repeated here.
STILL OPEN. The questions to the OAIC, on the civil penalty proceedings it has filed since 2018 and on the infringement notices it has issued and mid-tier proceedings it has filed since the 2024 Act commenced, are unanswered, so the article says only what this outlet found in public sources. The question to the Attorney-General's Department, on when the Privacy Amendment (Personal Data Protection) Bill 2026 will be introduced, is unanswered. Optus's reply does not say whether Optus contests the Commissioner's allegations or whether it expects the Commissioner's case to be heard with the separate Optus data breach class action. In June 2026 the OAIC said it anticipated issuing notices to entities it identified as non-compliant in the sweep and that a report on the results would be published in the new financial year; this outlet has found neither yet. Any answer will be added as a dated update.
NEXT DATE: 10 December 2026, when Schedule 1, Part 15 of the 2024 Act commences.
- Record: THE PRIVACY RORT, article 1, “One penalty”, right-of-reply update, 6 October 2026One penalty · The Privacy RortThe right-of-reply question to Medibank was sent on 2 October; a Medibank spokesperson replied on 6 October, quoted in article 2
Read the desk note
UPDATED 6 October 2026 (case: THE PRIVACY RORT, article 1 of four).
ARTICLE CHANGES. None to this article’s text. The right-of-reply question to Medibank was sent on 2 October 2026. A Medibank spokesperson replied on 6 October: ‘As the matter is before the Court, it would not be appropriate for Medibank to comment.’ The reply is quoted in article 2, “Nearly five years”.
STILL OPEN. Questions to the Office of the Australian Information Commissioner and Singtel Optus remain open; any answers will be added as dated updates.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Record: THE PRIVACY RORT, article 2, "Nearly five years", updated, 6 October 2026Nearly five years · The Privacy RortA Medibank spokesperson replied on 6 October to the question about its 2023 application; the reply is quoted
THE RORT asked Medibank on 2 October why it brought its 2023 application to restrain the Commissioner from investigating and deciding the representative complaint, and whether any other proceeding about the representative complaint is on foot. A Medibank spokesperson said: ‘As the matter is before the Court, it would not be appropriate for Medibank to comment.’ The statement does not say which…
Read the desk note
UPDATED 6 October 2026 (case: THE PRIVACY RORT, article 2 of four).
ARTICLE CHANGES. Medibank replied on 6 October to the question sent on 2 October about its 2023 application to restrain the Commissioner. The article now quotes the reply, which Medibank offered for attribution to a Medibank spokesperson: ‘As the matter is before the Court, it would not be appropriate for Medibank to comment.’ The reply does not say which matter it refers to and does not address the 22 February 2024 dismissal reported in the article's correction; that paragraph is unchanged.
STILL OPEN. The question to Medibank, why it brought the 2023 application and whether any other proceeding about the representative complaint is on foot, has no answer beyond the quoted sentence; the deadline given was 5pm AEDT, Thursday 8 October 2026. Questions to the OAIC, Singtel Optus and Latitude Financial remain open; any answers will be added as dated updates.
NEXT DATE: 5pm AEDT, Thursday 8 October 2026, the deadline given to Medibank. Two dates lie ahead in the matters in this article: 12 February 2027, the date by which, MLex reports, Justice Beach ordered the parties in the Optus matters to mediation, and 7 June 2027, when the related class action is set down for trial.
- Correction publishedNearly five years · The Privacy Rort
The paragraph above did not say that Medibank’s application was dismissed in February 2024, before this article was published. In Medibank Private Limited v Australian Information Commissioner, decided in February 2024, Justice Beach refused the injunction and ordered the application dismissed, with Medibank to pay the Commissioner’s costs; AAP reported it on 22 February 2024. The OAIC’s own…
- Record: THE PRIVACY RORT, article 1, “One penalty”, publishedOne penalty · The Privacy RortRight-of-reply questions to the OAIC, Singtel Optus and Medibank had not been sent at publication; any answers will be added as dated updates
Read the desk note
ATTENDED 25 September 2026 (case: THE PRIVACY RORT, article 1 of four).
FINDING. In calendar 2025 the OAIC received 1,205 data breach notifications, the most since the notifiable data breaches scheme began in 2018. Set beside that count, up to 24 September 2026 this outlet has found one civil penalty order a court has ever made under the Privacy Act: $5.8 million against Australian Clinical Labs, ordered by consent on 8 October 2025. The Commissioner’s penalty cases against Optus and Medibank have no outcome this outlet has found, and the Commissioner’s case against Meta was withdrawn in December 2024 for a $50 million payment program instead of a court finding.
ARTICLE CHANGES. Article 1, “One penalty”, published, setting the record notification count beside every Privacy Act civil penalty case this outlet could find. Three more articles are planned in this case.
STILL OPEN. Right-of-reply questions to the Office of the Australian Information Commissioner, Singtel Optus and Medibank had not been sent when this article was published. Any answers will be added as dated updates.
NEXT DATE: 7 June 2027, when the separate Optus data breach class action, not the Commissioner’s own civil penalty case, is set down for trial.
- Record: THE PRIVACY RORT, article 2, "Nearly five years", publishedNearly five years · The Privacy RortQuestions on these matters will be put to the OAIC, Optus, Medibank and Latitude Financial; any answers will be added as dated updates
Read the desk note
ATTENDED 25 September 2026 (case: THE PRIVACY RORT, article 2 of four).
FINDING. On one basis, months from an investigation’s announcement or a civil penalty proceeding’s filing, to its outcome, or to 24 September 2026 if there is none, the regulator’s largest privacy matters run from about one year to nearly five. The Optus White Pages investigation, announced in August 2021, closed only on 11 June 2026, about 58 months. The Meta case ran about 57 months before an enforceable undertaking ended it. The Latitude joint investigation, the Medibank penalty case and the Optus penalty case have no published outcome, at about 40, 27 and 13 months respectively. The Meta, Medibank and Optus penalty cases each followed an earlier OAIC investigation; this measure starts at the filing, not the investigation. This article lays each matter’s own timeline, and its own stated ending or absence of one, side by side.
ARTICLE CHANGES. Article 2, “Nearly five years”, published, covering the duration of the OAIC’s largest matters and the separate, stated ground each matter that closed without a court was closed on.
STILL OPEN. Questions on these matters will be put to the Office of the Australian Information Commissioner, Singtel Optus, Medibank and Latitude Financial; any answers will be added as dated updates.
NEXT DATE: this case’s article 3, on the retail and scraped facial-recognition findings, remains blocked pending outstanding checks. Two dates lie ahead in the matters in this article: 12 February 2027, the date by which, MLex reports, Justice Beach ordered the parties in the Optus matters to mediation, and 7 June 2027, when the related class action is set down for trial.