Skip to main content
  • On this page

Published:  

What is an infringement notice?

The OAIC may issue an infringement notice where an entity has contravened certain provisions under the Privacy Act 1988 (Privacy Act). Infringement notices can be issued to ‘APP entities’ – that is, entities regulated by the Privacy Act, including the Australian Privacy Principles (APPs)[1].

An infringement notice sets out a monetary penalty for contravention of the Privacy Act. Infringement notices provide an alternative to potential litigation of a matter and encourage timely resolution of contraventions of the Privacy Act.

When can the OAIC issue an infringement notice?

The OAIC can issue an infringement notice when an entity contravenes the Privacy Act by doing an act, or engaging in a practice, that breaches certain APPs.[2] In particular, the OAIC may issue an infringement notice when an APP entity does not meet the following requirements (APP infringement notice provisions):

  • to have a clearly expressed and up-to-date APP Privacy Policy about how it manages personal information (APP 1.3)
  • to include certain information in its APP Privacy Policy (APP 1.4)
  • to enable individuals interacting with the APP entity not to identify themselves or use a pseudonym (APP 2.1)
  • to make a written note when it uses or discloses personal information for enforcement-related activities (APP 6.5)
  • to provide a simple means for individual to opt out of direct marketing communications (APP 7.2(c) or 7.3(c))
  • to draw attention to ability to opt out of direct marketing communications (APP 7.3(d))
  • to give effect to an opt out request within a reasonable period (APP 7.7(a))
  • to notify individual of the source of personal information used or disclosed for direct marketing (APP 7.7(b))
  • to respond to correction requests within a certain period and to not charge to deal with these requests (APP 13.5).

The OAIC may also issue an infringement notice when:

  • an APP entity fails to submit a statement regarding an eligible data breach, as soon as practicable after becoming aware that one has occurred (s 26WK(3) of the Privacy Act)
  • an APP entity is given a compliance notice under s 80UC(1) of the Privacy Act and the entity fails to comply with the notice (s 80UC(4) and s 80UB(1)(c) of the Privacy Act)
  • a person fails or refuses to give information, answer a question or produce a document (s 66(1) of the Privacy Act)
  • an entity fails to destroy or de-identify information as required under s 136 of the Digital ID Act or contravenes the Digital ID privacy safeguards.[3]

Issuing a notice

The OAIC may issue an infringement notice against an APP entity if it believes on reasonable grounds that the entity has contravened a relevant provision of the Privacy Act. This only applies after 11 December 2024[4] and the notice must be issued within 12 months of the day of the alleged contravention.[5]

The infringement notice will detail the nature of the alleged contravention among other information.

When taking regulatory action such as issuing an infringement notice, the OAIC considers a range of factors, that are set out in our Guide to Privacy Regulatory Action and Regulatory Action Policy.

What are the infringement notice penalties?

The financial penalty varies according to the number of contraventions, the type of contravention and the type of entity involved. Penalties are calculated by reference to penalty units, which are contained in s 4AA of the Crimes Act 1914 (Cth)and increase over time.

A single contravention of an infringement notice provision may result in a penalty of up to 12 penalty units where the person is an individual (currently $4,368) and up to 60 penalty units for a body corporate (currently $21,840).[6] A single contravention of s 13K(1) or (2) or s 80UC(4) of the Privacy Act by a listed corporation attracts a penalty of 200 penalty units (currently $72,800).

What happens when an entity pays an infringement notice?

Paying an infringement notice does not mean an entity has admitted to contravening the Privacy Act. Paying the infringement notice discharges the entity’s liability for the alleged contravention and means the entity will not be subject to further regulatory action in relation to the alleged contravention.

Information on how to pay the penalty will be contained within the infringement notice. Payment should be made within 28 days.

Can the entity seek additional time to pay?

If an entity needs additional time to pay the notice, it can request that the due date for payment be extended. An application for an extension of time to pay must be made before the due date for payment.

Information about how to apply for an extension of time will be provided in the infringement notice.

If the extension of time request is refused, the due date for payment will be the last day of the period specified in the infringement notice, or the 7th day after notice of the decision not to grant an extension of time (whichever is later).

What happens if the entity does not comply with the notice?

If an entity does not pay an infringement notice, or if the entity pays the infringement notice after the due date for payment has passed, the OAIC may apply for civil penalties for contravention of the infringement notice provisions the entity is alleged to have contravened.[7]

What if the entity disagrees with the notice?

If an entity disagrees with an infringement notice, it may ask the OAIC to withdraw the notice.

To avoid further regulatory action, entities should consider making a withdrawal request before the due date for payment. The request should include any information the entity considers relevant to the request. If the withdrawal request is granted, the OAIC may consider further regulatory action, such as applying for a civil penalty.

If an entity requests withdrawal of an infringement notice, the due date for payment remains the same (i.e. the date specified in the infringement notice). To avoid liability for the alleged contravention, entities should consider paying the notice by the date specified. If the infringement notice is withdrawn, the amount paid will be refunded to the entity.

Footnotes

[1] An ‘APP entity’ is an agency or organisation which is subject to the Privacy Act. See Chapter B: Key concepts of the Australian Privacy Principles guidelines for more information.

[2] See s 80UC(1) and s 13K(1) and (2) of the Privacy Act

[3] See Part 2 Division 2 of the Digital ID Act 2024

[4] Infringement and compliance notices can only be issued for conduct occurring after the introduction of the Privacy and Other Legislation Amendment Act 2024

[5] See s 103(2) of the Regulatory Powers (Standard Provisions) Act

[6] Based on a penalty unit value of $364 as at July 2026.

[7] The civil penalty payable will vary according to the contravention. Under section 82(5) of the Regulatory Powers Act, the penalty for bodies corporate (if it is not specified in the civil penalty provision) must not be more than 5 times the penalty specified in the civil penalty provision).