-
On this page
What is a compliance notice?
The OAIC may issue a compliance notice where it believes an entity has contravened certain provisions of the Privacy Act 1988 (Privacy Act). Compliance notices can be issued to ‘APP entities’ – that is, entities regulated by the Privacy Act, including the Australian Privacy Principles (APPs)[1].
A compliance notice sets out the details of the contravention and states the actions the APP entity must take (or refrain from taking) to address the contravention.
Compliance notices are issued under s 80UC of the Privacy Act. They provide an alternative to litigation and encourage timely resolution of contraventions of the Privacy Act.
When can the OAIC issue a compliance notice?
The OAIC can issue a compliance notice when an APP entity contravenes the Privacy Act by doing an act, or engaging in a practice, that breaches certain APPs.[2] In particular, the OAIC may issue a compliance notice when an APP entity does not meet the following requirements:
- to have a clearly expressed and up-to-date APP Privacy Policy about how it manages personal information (APP 1.3)
- to include certain information in its APP Privacy Policy (APP 1.4)
- to enable individuals interacting with the APP entity not to identify themselves or use a pseudonym (APP 2.1)
- to make a written note when it uses or discloses personal information for enforcement-related activities (APP 6.5)
- to provide a simple means for individual to opt out of direct marketing communications (APP 7.2(c) or 7.3(c))
- to draw attention to ability to opt out of direct marketing communications (APP 7.3(d))
- to give effect to an opt out request within a reasonable period (APP 7.7(a))
- to notify individual of the source of personal information used or disclosed for direct marketing (APP 7.7(b))
- to respond to correction requests within a certain period and to not charge to deal with these requests (APP 13.5).
The OAIC may also issue a compliance notice when an APP entity fails to submit a statement regarding an eligible data breach, as soon as practicable after becoming aware that one has occurred (s 26WK(3) of the Privacy Act).
Issuing a notice
The OAIC may issue a compliance notice if it reasonably believes that the APP entity has contravened a relevant provision under the Privacy Act. This only applies to contraventions after 11 December 2024.[3]
The compliance notice will detail the nature of the alleged contravention and the actions that must be taken by the entity to comply with the notice.
When taking regulatory action such as issuing a compliance notice, the OAIC considers a range of factors, that are set out in our Guide to Privacy Regulatory Action and Regulatory Action Policy.
What action is required in response to a compliance notice?
The compliance notice will explain what the entity needs to do, or refrain from doing, to comply with privacy legislation.
What happens if the entity complies with the notice?
When an entity complies with a compliance notice within the timeframe requested, the OAIC will take no further action in relation to the compliance notice.
Complying with a compliance notice does not mean the entity has admitted to contravening the Privacy Act.
What happens if the entity does not comply with the notice?
When an entity does not comply with a compliance notice, for example if the entity does not respond to the compliance notice, or if the entity does not take the action requested in the notice by the date specified in the notice, the OAIC may:
- issue an infringement notice under s 80UB(1)(c) of the Privacy Act, or
- apply for civil penalties (up to 200 penalty units).
See our factsheet about infringements notices for more information about these notices.
What if the entity disagrees with the notice?
If an entity disagrees with a compliance notice, or believes information contained in the compliance notice is wrong, the entity may ask the OAIC to vary or revoke the notice.
A request that the OAIC vary or revoke a compliance notice and should be made before the timeframe for compliance specified in the notice has expired. The notice should outline the reasons why the entity considers the compliance notice should be varied or revoked and should provide any relevant information the entity wishes the OAIC to consider.
If any entity disagrees with a compliance notice, the APP entity may apply to the Federal Court or Federal Circuit Court for a review on either or both of the following grounds:
- it did not commit the contravention set out in the compliance notice; or
- the compliance notice does not comply with the requirements set out in ss 80UC(2) of the Privacy Act.
The compliance notice will include information on the pathways available to entities should they wish to challenge it.
Footnotes
[1] An ‘APP entity’ is an agency or organisation which is subject to the Privacy Act. See Chapter B: Key concepts of the Australian Privacy Principles guidelines for more information.
[2] See s 80UC(1) and s 13K(1) and (2) of the Privacy Act
[3] Infringement and compliance notices can only be issued for conduct occurring after the introduction of the Privacy and Other Legislation Amendment Act 2024