{"id":62214,"date":"2024-01-08T14:14:04","date_gmt":"2024-01-08T03:14:04","guid":{"rendered":"https:\/\/www.salesforce.com\/?p=62214"},"modified":"2025-09-12T16:20:54","modified_gmt":"2025-09-12T06:20:54","slug":"australian-privacy-act-update","status":"publish","type":"post","link":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/","title":{"rendered":"Australian Data Protection Laws in 2025: What Businesses Need to Know"},"content":{"rendered":"\n<p>On 10 December 2024, reforms to Australia\u2019s Privacy Act were passed. Key changes as of 2025 include expanded enforcement capabilities for the Office of the Australian Information Commissioner (OAIC) and the introduction of a new statutory tort allowing Australians to sue for serious invasions of privacy.<\/p>\n\n\n\n<p>When the APA was first passed in 1988, floppy disks were still the norm, and a data breach might have consisted of a handful of people passing one around. Now, things have changed; data loss can occur right under your nose, and sensitive information can be leaked to the world in minutes.&nbsp;<\/p>\n\n\n\n<p>With that in mind, it\u2019s no surprise that <a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">75% of organisations expect their security budgets to increase<\/a> to address evolving threats this year, as per our latest security report.<\/p>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;69ecb4bf38646&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"69ecb4bf38646\" class=\"wp-block-image size-full wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"436\" data-attachment-id=\"67892\" data-permalink=\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/australian-privacy-act-update-1\/\" data-orig-file=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-1.png\" data-orig-size=\"602,436\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"australian-privacy-act-update-1\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-1.png?w=602\" data-large-file=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-1.png?w=602\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-1.png?strip=all&#038;quality=95\" alt=\"\" class=\"wp-image-67892\" srcset=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-1.png 602w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-1.png?w=150&amp;h=109 150w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">State of IT: Security (Fourth Edition)<\/a>, p. 7<\/p>\n\n\n\n<p>The key to navigating <a href=\"\/au\/blog\/data-compliance\/\">compliance<\/a> is being prepared. In this guide, we\u2019re going to walk you through the current legal landscape for businesses, explore what\u2019s changing in the future, and explain what you can do to stay ahead of the curve. Let\u2019s dive in.&nbsp;<\/p>\n\n\n\n<p><em>Much of the data mentioned in this article comes from research conducted by Salesforce in the <a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">State of IT: Security report (Fourth Edition)<\/a>. Read the full report to gain insights from more than 2,000 security, privacy and compliance leaders worldwide.&nbsp;<\/em><\/p>\n\n\n\n<div class=\"layout-one wp-block-salesforce-blog-offer\">\n\t<div class=\"wp-block-offer__wrapper\">\n\n\t\t<div class=\"wp-block-offer__content\">\n\t\t\t<h2 class=\"wp-block-offer__title\">Gartner named Salesforce a Leader in Customer Data Platforms. See why.<\/h2>\n\t\t\t\t\t\t\t<p class=\"wp-block-offer__description\"><\/p>\n\t\t\t\n\t\t\t\n\t\t\t\t\t\t\t<div class=\"wp-block-button\">\n\t\t\t\t\t<a class=\"wp-block-button__link\" target=\"_blank\" href=\"\/au\/form\/marketing\/gartner-cdp-magic-quadrant\/?d=pb\">Read the report<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\n\t\t<div class=\"wp-block-offer__media\">\n\t\t\t\t\t<\/div>\n\t<\/div>\n\n\t\t\t<div class=\"wp-block-offer__graphics wp-block-offer__contour\"><\/div>\n\t\n\t\t\t<!-- Standard Illustration -->\n\t\t<img decoding=\"async\" class=\"wp-block-offer__graphics wp-block-offer__illustration\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/themes\/salesforce-blog\/dist\/images\/offer-block\/offer-illustration-layout-one.png\" alt=\"\">\n\n\t\t<!-- Small Accent Illustration -->\n\t\t\t\t\t<img decoding=\"async\" class=\"wp-block-offer__graphics wp-block-offer__accent\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/themes\/salesforce-blog\/dist\/images\/offer-block\/offer-accent-layout-one.png\" alt=\"\">\n\t\t\n\t\t<!-- Left Side Illustration -->\n\t\t\n\t\t<!-- Cloud Illustration -->\n\t\t\t\t\t<img decoding=\"async\" class=\"wp-block-offer__graphics wp-block-offer__cloud\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/themes\/salesforce-blog\/dist\/images\/offer-block\/offer-cloud-layout-one.png\" alt=\"\">\n\t\t\n\t<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-a-quick-overview-of-data-privacy-in-australia\"><strong>A quick overview of data privacy in Australia<\/strong><\/h2>\n\n\n\n<p>Australia relies on a mixture of Federal, State and Territory <a href=\"\/au\/platform\/data-privacy-compliance\/what-is-data-privacy\/\">data privacy<\/a> laws. The primary federal law is the <a href=\"https:\/\/www.oaic.gov.au\/privacy\/privacy-legislation\/the-privacy-act\" target=\"_blank\" rel=\" noopener\">Privacy Act 1988<\/a>. This contains the 13 Australian Privacy Principles (APPs), which govern the collection, use and disclosure of personal information.&nbsp;<\/p>\n\n\n\n<p>The Privacy Act received a long-overdue update in 2024, largely due to the evolving challenges of keeping data private and secure in the era of automation and AI analytics. Add in the fact that <strong><a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">64% of customers feel companies are being reckless with their data<\/a><\/strong>, and it\u2019s clear to see why the government is so keen to bring the legislation up to modern-day standards.&nbsp;<\/p>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;69ecb4bf38ee7&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"69ecb4bf38ee7\" class=\"wp-block-image size-large wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"300\" data-attachment-id=\"67894\" data-permalink=\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/australian-privacy-act-update-2\/\" data-orig-file=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-2.png\" data-orig-size=\"602,300\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"australian-privacy-act-update-2\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-2.png?w=602\" data-large-file=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-2.png?w=602\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-2.png?w=602\" alt=\"\" class=\"wp-image-67894\" srcset=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-2.png 602w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/australian-privacy-act-update-2.png?w=150&amp;h=75 150w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">State of IT: Security (Fourth Edition)<\/a>, p. 21<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-does-the-australian-privacy-act-apply-to-nbsp\"><strong>Who does the Australian Privacy Act apply to?&nbsp;<\/strong><\/h2>\n\n\n\n<p>The Privacy Act currently applies to Australian Government agencies and most private sector organisations earning over A$3 million annually. Some <a href=\"\/au\/small-business\/what-is-an-smb\/\">small businesses<\/a> with an annual turnover of less than A$3 million, such as those that provide health services or sell\/buy personal information, are also included.<\/p>\n\n\n\n<p><strong>Note that the Australian Government is considering scrapping the exemption for small businesses<\/strong>, which would bring millions of new companies within the scope of the legislation.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Who are the key regulators?<\/strong><\/h3>\n\n\n\n<p>Here\u2019s a quick summary showing the key players in Australia\u2019s privacy overhauls:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\"><strong>Body<\/strong><\/th><th class=\"has-text-align-left\" data-align=\"left\"><strong>What role do they play?<\/strong><\/th><th class=\"has-text-align-left\" data-align=\"left\"><strong>What\u2019s their focus?<\/strong><\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>OAIC<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Main federal regulator for data privacy<\/td><td class=\"has-text-align-left\" data-align=\"left\">Enforces the Privacy Act, handles complaints and oversees data breach notifications<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Information Commissioner<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Head of the OAIC<\/td><td class=\"has-text-align-left\" data-align=\"left\">Takes charge of the OAIC\u2019s strategy and policies<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Privacy Commissioner<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Role that supports the OAIC<\/td><td class=\"has-text-align-left\" data-align=\"left\">Oversees development and enforcement of privacy laws<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>FOI Commissioner<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Role that supports the OAIC<\/td><td class=\"has-text-align-left\" data-align=\"left\">Focuses specifically on freedom of information (FOI) matters<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>State\/territory offices<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Local privacy regulators by state\/territory<\/td><td class=\"has-text-align-left\" data-align=\"left\">Enforces state and territory-specific privacy laws<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What state and territory laws are in play?&nbsp;<\/strong><\/h3>\n\n\n\n<p>All states and territories except for Western Australia and South Australia have their own data privacy and protection laws. Here are the main ones to know:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\"><strong>State or Territory<\/strong><\/th><th class=\"has-text-align-left\" data-align=\"left\"><strong>Australian Law<\/strong><\/th><th class=\"has-text-align-left\" data-align=\"left\"><strong>Who does it apply to?<\/strong><\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Australian Capital Territory (ACT)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Information Privacy Act 2014<\/td><td class=\"has-text-align-left\" data-align=\"left\">ACT public sector agencies and contractors<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>New South Wales (NSW)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Privacy and Personal Information Protection Act 1998<\/td><td class=\"has-text-align-left\" data-align=\"left\">NSW public sector agencies, local councils and universities<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Northern Territory (NT)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Information Act 2002<\/td><td class=\"has-text-align-left\" data-align=\"left\">NT public sector agencies and contracted service providers<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Queensland (QLD)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Information Privacy Act 2009<\/td><td class=\"has-text-align-left\" data-align=\"left\">QLD government departments and agencies<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Tasmania (TAS)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Personal Information Protection Act 2004<\/td><td class=\"has-text-align-left\" data-align=\"left\">TAS public sector agencies and contracted service providers<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Victoria (VIC)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Privacy and Data Protection Act 2014<\/td><td class=\"has-text-align-left\" data-align=\"left\">VIC public sector agencies and organisations handling personal information at the state level<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>These laws don\u2019t replace the APA but rather sit alongside it, covering state and territory public sector agencies and their providers. This means businesses that work on both state and federal levels may need to adhere to multiple privacy regulations.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Key amendments to the Privacy Act in 2025<\/strong><\/h2>\n\n\n\n<p>A lot has changed in the last year. Let\u2019s discuss some of the amendments that have already taken shape and then look at the road ahead.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Statutory tort for serious invasions of privacy<\/strong><\/h3>\n\n\n\n<p>A new statutory tort for serious invasions of privacy came into effect on <strong>10 June 2025<\/strong>. This means Australians now have the right to sue a business that has intentionally or recklessly invaded their privacy, allowing them to recover damages or obtain an injunction. This means you could theoretically have 10 million people taking legal action against you.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Criminal offence for doxxing<\/strong><\/h3>\n\n\n\n<p>Publishing personal data in a menacing or harassing way is now a criminal offence, bringing penalties of up to six years imprisonment or seven years if motivated by discrimination. This law came into effect in <strong>December 2024<\/strong>.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>New powers for the OAIC<\/strong><\/h3>\n\n\n\n<p>The OAIC now has more power to conduct public inquiries, issue compliance notices and thoroughly investigate offending businesses.<\/p>\n\n\n\n<p>They can also issue administrative fines for minor breaches without a court order (civil penalties up to A$66,600 for individuals and A$330,000 for businesses) or seek court orders to issue penalties up to A$50 million, 30% of the company\u2019s adjusted turnover in the relevant period, or three times whatever benefit the company gained from the interference (whichever is greater) for more serious offences.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Automated process privacy notices<\/strong><\/h3>\n\n\n\n<p>Organisations that use automated processes (such as AI data processing or screening) to make decisions that impact the rights or interests of individuals will now need to include details about this process in their privacy policy. This requirement comes into effect on <strong>10 December 2026<\/strong>.<strong>&nbsp;<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Children\u2019s Online Privacy Code framework<\/strong><\/h3>\n\n\n\n<p>The amended Privacy Act also introduced a framework for developing a Children\u2019s Online Privacy Code (COPC), which will add new guidelines surrounding the collection of children\u2019s personal data. The code will be written and enforced by <strong>10 December 2026<\/strong>.<strong>&nbsp;<\/strong><\/p>\n\n\n\n<div class=\"layout-one wp-block-salesforce-blog-offer\">\n\t<div class=\"wp-block-offer__wrapper\">\n\n\t\t<div class=\"wp-block-offer__content\">\n\t\t\t<h2 class=\"wp-block-offer__title\">Say hello to Data Cloud.<\/h2>\n\t\t\t\t\t\t\t<p class=\"wp-block-offer__description\">Data Cloud, the only data platform native to Salesforce, unifies data from any system with built-in trust, security, and compliance. Get real-time customer insights while protecting privacy and staying compliant.<\/p>\n\t\t\t\n\t\t\t\n\t\t\t\t\t\t\t<div class=\"wp-block-button\">\n\t\t\t\t\t<a class=\"wp-block-button__link\" target=\"_self\" href=\"\/au\/data\/\">Explore Data Cloud<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\n\t\t<div class=\"wp-block-offer__media\">\n\t\t\t\t\t<\/div>\n\t<\/div>\n\n\t\t\t<div class=\"wp-block-offer__graphics wp-block-offer__contour\"><\/div>\n\t\n\t\t\t<!-- Standard Illustration -->\n\t\t<img decoding=\"async\" class=\"wp-block-offer__graphics wp-block-offer__illustration\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/themes\/salesforce-blog\/dist\/images\/offer-block\/offer-illustration-layout-one.png\" alt=\"\">\n\n\t\t<!-- Small Accent Illustration -->\n\t\t\t\t\t<img decoding=\"async\" class=\"wp-block-offer__graphics wp-block-offer__accent\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/themes\/salesforce-blog\/dist\/images\/offer-block\/offer-accent-layout-one.png\" alt=\"\">\n\t\t\n\t\t<!-- Left Side Illustration -->\n\t\t\n\t\t<!-- Cloud Illustration -->\n\t\t\t\t\t<img decoding=\"async\" class=\"wp-block-offer__graphics wp-block-offer__cloud\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/themes\/salesforce-blog\/dist\/images\/offer-block\/offer-cloud-layout-one.png\" alt=\"\">\n\t\t\n\t<\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What\u2019s still to come: future privacy act reforms<\/strong><\/h2>\n\n\n\n<p>Understanding the new laws is a great start, but there are still more changes to come. The 2022 Australian Privacy Act Review Report laid out 116 proposals for modernising the Privacy Act, and only a fraction of them have come into play.&nbsp;<\/p>\n\n\n\n<p>The upcoming \u2018tranche two\u2019 reforms are expected to be more extensive and prescriptive, meaning businesses will need to be on their toes and plan ahead. Some of the anticipated changes include:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A redefinition of key terms like \u2018personal information\u2019<\/li>\n\n\n\n<li>Clarity around requirements for obtaining consent&nbsp;<\/li>\n\n\n\n<li>Removal of small business exemptions<\/li>\n\n\n\n<li>The right to be forgotten (known as the right to erasure)<\/li>\n\n\n\n<li>Mandatory privacy assessments for high-risk data processing<\/li>\n<\/ul>\n\n\n\n<p>The end goal here is to bring the Privacy Act in line with more comprehensive data protection legislation worldwide, such as Europe\u2019s GDPR.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How will the government handle AI?&nbsp;<\/strong><\/h3>\n\n\n\n<p>A defining moment will be the Australian government\u2019s response to <a href=\"\/au\/artificial-intelligence\/what-is-ai\/\">artificial intelligence (AI)<\/a>. So far, we\u2019ve only seen the change associated with privacy notices for automated processes, but there\u2019s almost certainly more on the horizon.&nbsp;<\/p>\n\n\n\n<p>In late 2024, the Department of Industry, Science and Resources (DISR) issued the <a href=\"https:\/\/consult.industry.gov.au\/ai-mandatory-guardrails\" target=\"_blank\" rel=\" noopener\">Safe and Responsible AI in Australia<\/a> proposals paper, outlining 10 proposed guardrails for high-risk AI, covering accountability, transparency, human oversight, recordkeeping and risk management.&nbsp;<\/p>\n\n\n\n<p>Our <a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">State of IT: Security report (Fourth Edition)<\/a> reveals that <strong>43% of security leaders feel unprepared for AI-related security regulations<\/strong>, so the best time to start <a href=\"\/au\/artificial-intelligence\/responsible-ai\/\">reviewing your procedures<\/a> is now. It\u2019s much easier (and less risky) to plan ahead for the likely outcome than to retrofit compliance once the laws are in force.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Sector-specific privacy and data security laws in Australia<\/strong><\/h2>\n\n\n\n<p>Next, let\u2019s touch on some of the sector-specific laws that operate alongside the Privacy Act. These laws add additional privacy and security requirements for certain industries like finance and national security.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Assistance and Access Act (2018)&nbsp;<\/strong><\/h3>\n\n\n\n<p>The Assistance and Access Act gives a law enforcement agency the power to request help from tech companies to access encrypted data. They can issue notices that require a company to help using the tools they already have or make tech companies build new capabilities to enable future access.<\/p>\n\n\n\n<p>This legislation applies to a broad range of tech companies, including device manufacturers and software developers working in Australia.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Security of Critical Infrastructure Act (SOCI Act)&nbsp;<\/strong><\/h3>\n\n\n\n<p>The SOCI Act looks to safeguard Australia\u2019s core services from both internal and external threats. It covers the security of personal information and applies to all sectors deemed \u2018critical infrastructure\u2019, such as energy, communications, ports and data hosting\/storage providers. Obligations include:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Mandatory risk management programs that cover cyber and physical security&nbsp;<\/li>\n\n\n\n<li>Mandatory cyber incident reporting within 12 hours of becoming aware of the issue&nbsp;<\/li>\n\n\n\n<li>Government intervention for severe cyber threats or attacks<\/li>\n\n\n\n<li>Regular critical infrastructure risk assessments&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Consumer Data Right (CDR)<\/strong><\/h3>\n\n\n\n<p>The CDR gives consumers the right to access and share their own data with third parties. It currently applies to the banking (specifically open banking) and energy sectors, though there are plans to expand this legislation into additional industries, such as telecommunications.&nbsp;<\/p>\n\n\n\n<p>Businesses that fall under the CDR umbrella need to ensure that they have clear consent and data sharing mechanisms and that they\u2019re compliant with the <a href=\"https:\/\/www.accc.gov.au\/by-industry\/banking-and-finance\/the-consumer-data-right\" target=\"_blank\" rel=\" noopener\">privacy and security rules<\/a> outlined by the ACCC and OAIC.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Cyber Security Act 2024<\/strong><\/h3>\n\n\n\n<p>The Cyber Security Act is the government\u2019s response to the evolving sophistication of cyber threats. It requires any business that handles personal data to meet some essential obligations:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Mandatory reporting of eligible data breaches and cyber incidents within 72 hours<\/li>\n\n\n\n<li>A Cyber Incident Review Board (CIRB) to provide guidance and support during cyber incidents<\/li>\n\n\n\n<li>New security standards for smart devices sold in Australia&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>This legislation is part of the government&#8217;s attempt to get a handle on artificial intelligence. While AI has countless benefits (including upholding security), it also introduces challenges, especially when cyber criminals can leverage it for their own purposes.&nbsp;<\/p>\n\n\n\n<p>Of the security leaders we surveyed, <strong><a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">79% believed AI agents will introduce new security and compliance challenges<\/a><\/strong>. The Cyber Security Act is just one of the ways the government intends to \u2018walk the tightrope\u2019 between the benefits and risks AI brings.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What these laws mean for businesses in 2025<\/strong><\/h2>\n\n\n\n<p>There\u2019s a lot to unpack in the current privacy and protection landscape, so let\u2019s translate it into core obligations for businesses. Here are the five core things you need to do:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Strengthen data management:<\/strong> Learn where your personal data is stored and processed, especially high-risk records like children\u2019s data or health information.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Prepare for breaches:<\/strong> Prepare to detect, report and respond to breaches within 72 hours of learning of a breach.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Update your privacy policies: <\/strong>Adapt your privacy policies to reflect the APA changes to automated process privacy notices and the right to consent.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Protect children\u2019s data:<\/strong> Understand the rules around children\u2019s data and update your procedures to ensure increased transparency during handling.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Review your AI policies:<\/strong> Start auditing, documenting and reviewing your AI practices to prepare for future AI governance regulations.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Artificial intelligence, in particular, is going to be the <a href=\"\/au\/news\/stories\/ai-cyber-attack-prevention\/\">double-edged sword<\/a> of this change. While the security risks are no secret (the idea of cyber criminals using AI to automate attacks is concerning), according to our survey, <strong>80% of security leaders also believe AI will bring new security opportunities.&nbsp;<\/strong><\/p>\n\n\n\n<p>The businesses that best cope with the legislative changes will be the ones that can toe the line between using <a href=\"\/au\/artificial-intelligence\/ai-use-cases\/\">AI for its benefits<\/a> and <a href=\"\/au\/artificial-intelligence\/ai-security\/\">maintaining security and oversight<\/a> at every stage.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How to stay compliant (and build customer trust)<\/strong><\/h2>\n\n\n\n<p>By making targeted changes to your processes and procedures, you can stay ahead of evolving compliance, build trust with consumers and gain an edge over your competitors. Here are the steps to take:&nbsp;&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Part 1: Compliance<\/strong><\/h3>\n\n\n\n<p>Compliance has always been a moving target, but the goalposts have rarely moved this fast. It\u2019s having an impact, as <a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">68% of security leaders<\/a> say compliance is becoming more difficult amid evolving regulations.&nbsp;<\/p>\n\n\n\n<p>As mentioned, the key is always preparation. Here\u2019s what you can do to adapt to the current landscape and prepare for the future:&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-1-conduct-a-privacy-impact-assessment-pia\">1. <strong>Conduct a privacy impact assessment (PIA)<\/strong><\/h4>\n\n\n\n<p>The first step is to understand your current privacy practices. How does your business collect, store, use and share its personal information? Conduct a risk assessment and map out your data flow to identify potential compliance gaps.\u00a0<\/p>\n\n\n\n<p>This is especially important if you handle sensitive data, work with the data of children or operate in a heavily regulated industry.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-2-appoint-a-data-protection-officer\">2. <strong>Appoint a data protection officer<\/strong><\/h4>\n\n\n\n<p>If you haven\u2019t done so already, assign the responsibility of your data privacy and protection compliance to one or more individuals. It\u2019s helpful to have a dedicated specialist who can stay up to date with the new compliance standards as they evolve.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-3-revise-your-policies-and-procedures\">3. <strong>Revise your policies and procedures<\/strong><\/h4>\n\n\n\n<p>Now, you\u2019re ready to update your privacy policy to reflect the new changes. Here are some things to consider:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Include privacy disclosures if your business uses AI or automation for decision-making<\/li>\n\n\n\n<li>Create a plan for rapid cyber incident reporting and disaster recovery<\/li>\n\n\n\n<li>Develop processes for data consent and the right to erasure<\/li>\n\n\n\n<li>Start documenting your AI activities for upcoming mandatory privacy assessments<\/li>\n<\/ul>\n\n\n\n<p>You should also prepare for sector-specific requirements, such as SOCI Act reporting and CDR data sharing rules (based on your industry).&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-4-tighten-your-security-measures\">4. <strong>Tighten your security measures<\/strong><\/h4>\n\n\n\n<p>You should also implement security measures to comply with the new rules. This could include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Investing in technical safeguards like <a href=\"\/au\/data\/what-is-data-encryption\/\">encryption<\/a><\/li>\n\n\n\n<li>Creating internal playbooks to detect data breaches early<\/li>\n\n\n\n<li>Segmenting high-risk data (such as children\u2019s data)<\/li>\n\n\n\n<li>Adding measures to meet industry-specific standards like CPS 234 for financial services<\/li>\n<\/ul>\n\n\n\n<p>If you develop your own AI applications, you may also consider implementing DevSecOps to embed Secure by Design into every stage of the development lifecycle. It\u2019s a proactive approach that can help organisations maintain compliance as regulations change.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-5-train-your-teams\">5. <strong>Train your teams<\/strong><\/h4>\n\n\n\n<p>Your new policies are only as strong as the buy-in of your teams. Make sure every employee who handles personal data understands what\u2019s required of them, and provide ongoing education to keep everyone up to date, especially when new laws are established.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Part 2: Trust<\/strong><\/h3>\n\n\n\n<p>With<strong> <a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">71% of customers<\/a> reporting that their trust in companies is decreasing<\/strong>, <a href=\"\/au\/blog\/regulatory-compliance\/\">regulatory compliance<\/a> alone isn\u2019t enough to heal the wound. Businesses need to embed trust into their business through action.&nbsp;<\/p>\n\n\n\n<p>Here are some ideas:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Be transparent with your customers about how you\u2019re using AI and why it matters<\/li>\n\n\n\n<li>Inform users that they have control over their data and what this means<\/li>\n\n\n\n<li>Offer clear opt-ins and opt-outs, and make these options easy to find<\/li>\n\n\n\n<li>Remove the jargon from your privacy policy to explain things in simple terms<\/li>\n\n\n\n<li>Demonstrate accountability if things go wrong<\/li>\n<\/ul>\n\n\n\n<p>Need support meeting the new regulations? <a href=\"\/au\/products\/platform\/products\/privacy-center\/\">Salesforce Privacy Center<\/a> can help you minimise your risk. With just a few clicks, Privacy Center simplifies data privacy compliance and builds trust with customers. It\u2019s a simpler, more secure future for businesses and their customers.&nbsp;<\/p>\n\n\n\n<div class=\"layout-one wp-block-salesforce-blog-offer\">\n\t<div class=\"wp-block-offer__wrapper\">\n\n\t\t<div class=\"wp-block-offer__content\">\n\t\t\t<h2 class=\"wp-block-offer__title\">Get expert Data Cloud guidance from Salesforce Professional Services.<\/h2>\n\t\t\t\t\t\t\t<p class=\"wp-block-offer__description\">With 1.3K+ certified Data Cloud consultants and 240+ implementations globally, we&#8217;ll help you realise value quickly. Check out our guide to learn how.<\/p>\n\t\t\t\n\t\t\t\n\t\t\t\t\t\t\t<div class=\"wp-block-button\">\n\t\t\t\t\t<a class=\"wp-block-button__link\" target=\"_blank\" href=\"\/au\/resources\/guides\/professional-services-and-data-cloud\/?d=pb\">Get the guide<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\n\t\t<div class=\"wp-block-offer__media\">\n\t\t\t\t\t<\/div>\n\t<\/div>\n\n\t\t\t<div class=\"wp-block-offer__graphics wp-block-offer__contour\"><\/div>\n\t\n\t\t\t<!-- Standard Illustration -->\n\t\t<img decoding=\"async\" class=\"wp-block-offer__graphics wp-block-offer__illustration\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/themes\/salesforce-blog\/dist\/images\/offer-block\/offer-illustration-layout-one.png\" alt=\"\">\n\n\t\t<!-- Small Accent Illustration -->\n\t\t\t\t\t<img decoding=\"async\" class=\"wp-block-offer__graphics wp-block-offer__accent\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/themes\/salesforce-blog\/dist\/images\/offer-block\/offer-accent-layout-one.png\" alt=\"\">\n\t\t\n\t\t<!-- Left Side Illustration -->\n\t\t\n\t\t<!-- Cloud Illustration -->\n\t\t\t\t\t<img decoding=\"async\" class=\"wp-block-offer__graphics wp-block-offer__cloud\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/themes\/salesforce-blog\/dist\/images\/offer-block\/offer-cloud-layout-one.png\" alt=\"\">\n\t\t\n\t<\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Final thoughts&nbsp;<\/strong><\/h2>\n\n\n\n<p>Australia\u2019s data privacy landscape is evolving faster than ever, and it shows no signs of slowing down. Only a small fraction of the proposals from the Privacy Act Review Report have currently been implemented, and more guardrails are sure to follow soon.&nbsp;<\/p>\n\n\n\n<p>The best way to stay ahead is to make privacy a priority, monitor legal changes and focus on watertight <a href=\"\/au\/platform\/data-security\/what-is-data-security\/\">data security<\/a>. This is even more important in the age of artificial intelligence, with <strong><a href=\"\/au\/resources\/research-reports\/state-of-the-connected-customer\/?d=pb\" target=\"_blank\" rel=\" noopener\">61% of customers<\/a> saying AI makes it more important than ever for customers to protect their data.<\/strong><\/p>\n\n\n\n<p>Fortunately, technology can also fight on the other side of the battle to keep your data secure.&nbsp;<\/p>\n\n\n\n<p>Take <a href=\"\/au\/data\/\">Salesforce Data Cloud<\/a>, for instance. Our solution will help you unify, manage and secure all your data at scale across the entire Salesforce ecosystem, with built-in features for governance and role-based access controls (RBAC). And with robust encryption and granular data policies, you can be confident your customer data is protected at every layer.&nbsp;<\/p>\n\n\n\n<p><a href=\"\/au\/form\/signup\/sales-ee\/?d=pb\" target=\"_blank\" rel=\" noopener\">Try Data Cloud for free<\/a> to see how Salesforce can help you stay ahead of evolving compliance standards.&nbsp;<\/p>\n\n\n\n<p>Ready to learn more about the current security landscape in 2025? Read our <a href=\"\/au\/form\/platform\/4th-state-of-it-security\/?d=pb\" target=\"_blank\" rel=\" noopener\">State of IT: Security report<\/a> to gain insights from more than 2,000 security leaders and compliance experts worldwide.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Are there any other industry-specific updates I should be aware of?<\/strong><\/h3>\n\n\n\n<p>Yes. The Privacy (Credit Reporting) Code 2025 was updated on <strong>25 March 2025<\/strong>. Among other changes, \u2018Buy Now, Pay Later\u2019 businesses will need to report and manage their credit data under stricter rules. Financial institutions are now under increased APRA CPS 234 scrutiny.&nbsp;<\/p>\n\n\n\n<p>My Health Record was also updated recently, mandating that pathology labs and diagnostic imaging providers automatically upload patient test results to the platform.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How does the Privacy Act 1988 differ from the GDPR?<\/strong><\/h3>\n\n\n\n<p>Currently, the GDPR is much more prescriptive and strict than the Privacy Act. It has several additional data subject rights, such as the right to be forgotten and the right to portability, explicit consent standards and mandatory data protection legislation for organisations. The upcoming reforms will look to bring Australia\u2019s laws closer to those of the GDPR.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What is considered a serious invasion of privacy under the new tort?&nbsp;<\/strong><\/h3>\n\n\n\n<p>In general, a serious invasion of privacy involves an intentional or reckless act that causes loss, distress or humiliation to an individual. This could include disclosing personal information or surveilling an individual. It can also include data being exposed during a data breach.&nbsp;<\/p>\n\n\n\n<div class=\"alignnormal is-style-row wp-block-salesforce-blog-curated-articles\">\n\t<ul class=\"sp-top-latest sp-top-latest--row\">\n\t\t\n<li class=\"card card--row\">\n\t<article class=\"card__article\">\n\t\t<div class=\"card__contents\">\n\t\t\t<div class=\"card__meta\">\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t<span class=\"card__meta__readtime\">\n\t\t\t\t\t\t6 min\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t\t<a href=\"https:\/\/www.salesforce.com\/au\/blog\/building-brands-on-customer-loyalty\/\" target=\"_self\" class=\"card__link\">\n\t\t\t\t<h2 class=\"card__title h6\">\n\t\t\t\t\tHow Customer Loyalty Turns SMEs Into Brands That Last\t\t\t\t<\/h2>\n\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t<div class=\"card__thumbnail\">\n\t\t\t\t<span class=\"img-object-fit\"><img decoding=\"async\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/11\/AdobeStock_643833602.jpeg?w=128&#038;h=96&#038;crop=1&#038;quality=75\" sizes=\"768px\" srcset=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/11\/AdobeStock_643833602.jpeg 7008w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/11\/AdobeStock_643833602.jpeg?w=750&amp;h=500 750w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/11\/AdobeStock_643833602.jpeg?w=768&amp;h=512 768w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/11\/AdobeStock_643833602.jpeg?w=1536&amp;h=1024 1536w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/11\/AdobeStock_643833602.jpeg?w=2048&amp;h=1365 2048w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/11\/AdobeStock_643833602.jpeg?w=150&amp;h=100 150w\" alt=\"\" loading=\"lazy\" \/><\/span>\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/article>\n<\/li>\n\n<li class=\"card card--row\">\n\t<article class=\"card__article\">\n\t\t<div class=\"card__contents\">\n\t\t\t<div class=\"card__meta\">\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t<span class=\"card__meta__readtime\">\n\t\t\t\t\t\t5 min\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t\t<a href=\"https:\/\/www.salesforce.com\/au\/blog\/questions-about-ai\/\" target=\"_self\" class=\"card__link\">\n\t\t\t\t<h2 class=\"card__title h6\">\n\t\t\t\t\t5 Questions About AI Your Business Should Ask Before Diving In\t\t\t\t<\/h2>\n\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t<div class=\"card__thumbnail\">\n\t\t\t\t<span class=\"img-object-fit\"><img decoding=\"async\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/07\/lisa-image.png?w=128&#038;h=96&#038;crop=1&#038;quality=75\" sizes=\"768px\" srcset=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/07\/lisa-image.png 1500w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/07\/lisa-image.png?w=889&amp;h=500 889w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/07\/lisa-image.png?w=768&amp;h=432 768w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/07\/lisa-image.png?w=150&amp;h=84 150w\" alt=\"\" loading=\"lazy\" \/><\/span>\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/article>\n<\/li>\n\n<li class=\"card card--row\">\n\t<article class=\"card__article\">\n\t\t<div class=\"card__contents\">\n\t\t\t<div class=\"card__meta\">\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t<span class=\"card__meta__readtime\">\n\t\t\t\t\t\t2 min\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t\t<a href=\"https:\/\/www.salesforce.com\/au\/blog\/salesforce-to-launch-data-cloud-and-marketing-cloud-on-hyperforce-in-australia\/\" target=\"_self\" class=\"card__link\">\n\t\t\t\t<h2 class=\"card__title h6\">\n\t\t\t\t\tSalesforce Launch Data Cloud and Marketing Cloud on Hyperforce in Australia\t\t\t\t<\/h2>\n\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t<div class=\"card__thumbnail\">\n\t\t\t\t<span class=\"img-object-fit\"><img decoding=\"async\" src=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/10\/Hyperforce-Blog-500x281-ANZ.png?w=128&#038;h=96&#038;crop=1&#038;quality=75\" sizes=\"768px\" srcset=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/10\/Hyperforce-Blog-500x281-ANZ.png 500w, https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2023\/10\/Hyperforce-Blog-500x281-ANZ.png?w=150&amp;h=84 150w\" alt=\"\" loading=\"lazy\" \/><\/span>\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/article>\n<\/li>\n\t<\/ul>\n<\/div>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data protection regulations are always evolving. Discover important changes to Australian data protection laws, and learn ways to keep your business compliant.<\/p>\n","protected":false},"author":28,"featured_media":62220,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"sf_justforyou_enable_alt":true,"optimizely_content_id":"68c385e043a2266099049dc9","post_meta_title":"","ai_synopsis":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"sf_topic":[2485,2467,2858,3268],"sf_content_type":[3154],"coauthors":[2454],"class_list":["post-62214","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","sf_topic-data-culture","sf_topic-future-of-work","sf_topic-artificial-intelligence","sf_topic-data-cloud","sf_content_type-blog"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Australian Data Protection Laws: A Guide for 2025<\/title>\n<meta name=\"description\" content=\"Data protection regulations are always evolving. Discover important changes to Australian data protection laws, and learn ways to keep your business compliant.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Australian Data Protection Laws in 2025: What Businesses Need to Know\" \/>\n<meta property=\"og:description\" content=\"Data protection regulations are always evolving. Discover important changes to Australian data protection laws, and learn ways to keep your business compliant.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/\" \/>\n<meta property=\"og:site_name\" content=\"Salesforce\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/salesforce\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-08T03:14:04+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-12T06:20:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"4514\" \/>\n\t<meta property=\"og:image:height\" content=\"3323\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Salesforce\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@salesforce\" \/>\n<meta name=\"twitter:site\" content=\"@salesforce\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Salesforce\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/\"},\"author\":[{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/person\/image\/3116597fb93569a20b61fd4fe1a932b8\"}],\"headline\":\"Australian Data Protection Laws in 2025: What Businesses Need to Know\",\"datePublished\":\"2024-01-08T03:14:04+00:00\",\"dateModified\":\"2025-09-12T06:20:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/\"},\"wordCount\":2983,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg\",\"inLanguage\":\"en-AU\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/\",\"url\":\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/\",\"name\":\"Australian Data Protection Laws: A Guide for 2025\",\"isPartOf\":{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg\",\"datePublished\":\"2024-01-08T03:14:04+00:00\",\"dateModified\":\"2025-09-12T06:20:54+00:00\",\"description\":\"Data protection regulations are always evolving. Discover important changes to Australian data protection laws, and learn ways to keep your business compliant.\",\"inLanguage\":\"en-AU\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-AU\",\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#primaryimage\",\"url\":\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg\",\"contentUrl\":\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg\",\"width\":4514,\"height\":3323},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#website\",\"url\":\"https:\/\/www.salesforce.com\/au\/blog\/\",\"name\":\"Salesforce\",\"description\":\"Learn how to get ahead of trends and supercharge professional relationships\",\"publisher\":{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.salesforce.com\/au\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-AU\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#organization\",\"name\":\"Salesforce\",\"url\":\"https:\/\/www.salesforce.com\/au\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-AU\",\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/logo\/image\/\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Salesforce\"},\"image\":{\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/salesforce\",\"https:\/\/x.com\/salesforce\",\"https:\/\/instagram.com\/salesforce\",\"http:\/\/www.linkedin.com\/company\/salesforce\",\"http:\/\/www.youtube.com\/Salesforce\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/person\/image\/3116597fb93569a20b61fd4fe1a932b8\",\"name\":\"Salesforce\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-AU\",\"@id\":\"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/person\/image\/5c0ee1996ec3a82ffd225f681265d95d\",\"url\":\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2022\/10\/salesforce-avatar-e1666571807979.png?w=128&h=96&crop=1\",\"contentUrl\":\"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2022\/10\/salesforce-avatar-e1666571807979.png?w=128&h=96&crop=1\",\"width\":128,\"height\":96,\"caption\":\"Salesforce\"},\"description\":\"The 360 Blog from Salesforce teaches readers how to improve work outcomes and professional relationships. Our content explores the mindset shifts, organisational hurdles, and people behind business evolution. We also cover the tactics, ethics, products, and thought leadership that make growth a meaningful and positive experience.\",\"url\":\"https:\/\/www.salesforce.com\/au\/blog\/author\/salesforce\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Australian Data Protection Laws: A Guide for 2025","description":"Data protection regulations are always evolving. Discover important changes to Australian data protection laws, and learn ways to keep your business compliant.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/","og_type":"article","og_title":"Australian Data Protection Laws in 2025: What Businesses Need to Know","og_description":"Data protection regulations are always evolving. Discover important changes to Australian data protection laws, and learn ways to keep your business compliant.","og_url":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/","og_site_name":"Salesforce","article_publisher":"https:\/\/www.facebook.com\/salesforce","article_published_time":"2024-01-08T03:14:04+00:00","article_modified_time":"2025-09-12T06:20:54+00:00","og_image":[{"width":4514,"height":3323,"url":"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg","type":"image\/jpeg"}],"author":"Salesforce","twitter_card":"summary_large_image","twitter_creator":"@salesforce","twitter_site":"@salesforce","twitter_misc":{"Written by":"Salesforce","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#article","isPartOf":{"@id":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/"},"author":[{"@id":"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/person\/image\/3116597fb93569a20b61fd4fe1a932b8"}],"headline":"Australian Data Protection Laws in 2025: What Businesses Need to Know","datePublished":"2024-01-08T03:14:04+00:00","dateModified":"2025-09-12T06:20:54+00:00","mainEntityOfPage":{"@id":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/"},"wordCount":2983,"commentCount":0,"publisher":{"@id":"https:\/\/www.salesforce.com\/au\/blog\/#organization"},"image":{"@id":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#primaryimage"},"thumbnailUrl":"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg","inLanguage":"en-AU","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/","url":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/","name":"Australian Data Protection Laws: A Guide for 2025","isPartOf":{"@id":"https:\/\/www.salesforce.com\/au\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#primaryimage"},"image":{"@id":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#primaryimage"},"thumbnailUrl":"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg","datePublished":"2024-01-08T03:14:04+00:00","dateModified":"2025-09-12T06:20:54+00:00","description":"Data protection regulations are always evolving. Discover important changes to Australian data protection laws, and learn ways to keep your business compliant.","inLanguage":"en-AU","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/"]}]},{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.salesforce.com\/au\/blog\/australian-privacy-act-update\/#primaryimage","url":"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg","contentUrl":"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg","width":4514,"height":3323},{"@type":"WebSite","@id":"https:\/\/www.salesforce.com\/au\/blog\/#website","url":"https:\/\/www.salesforce.com\/au\/blog\/","name":"Salesforce","description":"Learn how to get ahead of trends and supercharge professional relationships","publisher":{"@id":"https:\/\/www.salesforce.com\/au\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.salesforce.com\/au\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-AU"},{"@type":"Organization","@id":"https:\/\/www.salesforce.com\/au\/blog\/#organization","name":"Salesforce","url":"https:\/\/www.salesforce.com\/au\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/logo\/image\/","url":"","contentUrl":"","caption":"Salesforce"},"image":{"@id":"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/salesforce","https:\/\/x.com\/salesforce","https:\/\/instagram.com\/salesforce","http:\/\/www.linkedin.com\/company\/salesforce","http:\/\/www.youtube.com\/Salesforce"]},{"@type":"Person","@id":"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/person\/image\/3116597fb93569a20b61fd4fe1a932b8","name":"Salesforce","image":{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.salesforce.com\/au\/blog\/#\/schema\/person\/image\/5c0ee1996ec3a82ffd225f681265d95d","url":"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2022\/10\/salesforce-avatar-e1666571807979.png?w=128&h=96&crop=1","contentUrl":"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2022\/10\/salesforce-avatar-e1666571807979.png?w=128&h=96&crop=1","width":128,"height":96,"caption":"Salesforce"},"description":"The 360 Blog from Salesforce teaches readers how to improve work outcomes and professional relationships. Our content explores the mindset shifts, organisational hurdles, and people behind business evolution. We also cover the tactics, ethics, products, and thought leadership that make growth a meaningful and positive experience.","url":"https:\/\/www.salesforce.com\/au\/blog\/author\/salesforce\/"}]}},"jetpack_featured_media_url":"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Salesforce","distributor_original_site_url":"https:\/\/www.salesforce.com\/au\/blog","push-errors":false,"primary_topic":{"term_id":2485,"name":"Data","slug":"data-culture","term_group":0,"term_taxonomy_id":2485,"taxonomy":"sf_topic","description":"Global data will double every 12 hours by 2025. You need the right tech and training for data-driven decisions at every level.","parent":0,"count":59,"filter":"raw"},"featured_image_url":"https:\/\/www.salesforce.com\/au\/blog\/wp-content\/uploads\/sites\/4\/2024\/01\/AdobeStock_570547190.jpeg?w=4514","_links":{"self":[{"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/posts\/62214","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/comments?post=62214"}],"version-history":[{"count":12,"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/posts\/62214\/revisions"}],"predecessor-version":[{"id":67901,"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/posts\/62214\/revisions\/67901"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/media\/62220"}],"wp:attachment":[{"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/media?parent=62214"}],"wp:term":[{"taxonomy":"sf_topic","embeddable":true,"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/sf_topic?post=62214"},{"taxonomy":"sf_content_type","embeddable":true,"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/sf_content_type?post=62214"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.salesforce.com\/au\/blog\/wp-json\/wp\/v2\/coauthors?post=62214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}