The Australian Privacy Act Reforms & Email Marketing: What’s Changing

  • The Privacy and Other Legislation Amendment Act 2024 is the biggest privacy shake-up in decades, and more reform is still on the way.
  • A new statutory tort can reach even businesses exempt from the Act, so no email list is fully out of scope.
  • The small business exemption still stands, but its removal has been proposed, so it pays to plan ahead.
  • For email marketers the fix is familiar, including clear opt-in, less data, and a breach plan.

The Australian Privacy Act reforms are a set of changes to the Privacy Act 1988 that tighten how organisations handle personal information. They were introduced mainly through the Privacy and Other Legislation Amendment Act 2024. The Office of the Australian Information Commissioner (OAIC) oversees the Act and these changes.

Why should a busy email marketer care? The reforms raise the stakes for how you collect, store, and use the contact data behind your campaigns. Get the basics right and you protect both your subscribers and the channel you rely on.

So we’ll keep this practical. We’ll cover what the Australian Privacy Act reforms are, what’s actually changing, and how to prepare your email marketing. Then we’ll look at the guidelines that matter most and the habits that keep you compliant.

What are the Australian Privacy Act reforms?

The Australian Privacy Act reforms are the updates to the Privacy Act 1988 made mainly by the Privacy and Other Legislation Amendment Act 2024. Most provisions started on 10/12/2024, with a few phased in later. That means the core changes are already in force, so this is a now issue, not a wait-and-see one.

These changes build on the existing rules rather than replacing them. There are 13 Australian Privacy Principles (APPs), and they still set the standards for how personal information is collected, used, and disclosed. Think of the reforms as a stronger set of teeth on the same framework.

Here are the key parts worth knowing before you go further:

  • The amending law: The Privacy and Other Legislation Amendment Act 2024 carries most of the first round of changes.
  • The timeline: Most provisions began on 10/12/2024, a new statutory tort started on 10/06/2025, and automated-decision rules start on 10/12/2026.
  • The regulator: The OAIC investigates complaints and can take enforcement action.
  • More to come: The government has signalled further reforms, so the picture keeps moving.
  • Not the Spam Act: The Australian Privacy Act covers personal information, while the Spam Act 2003 covers consent for marketing messages.

That last point trips up a lot of marketers. The Australian Privacy Act is overseen by the OAIC and governs personal information. The Spam Act 2003 is a separate law, enforced by the Australian Communications and Media Authority (ACMA). It governs consent, sender identification, and unsubscribe in every message.

ACMA has issued multimillion-dollar fines for repeat or large-scale breaches, so keep the two regimes straight. If you send campaigns, read up on the SMS marketing laws in Australia.

What’s changing under the reforms?

The reforms touch several areas, but three matter most if you run an email list. Each one raises the cost of getting data handling wrong.

A new statutory tort for serious invasions of privacy

A statutory tort is a right to sue in court, and this one covers serious invasions of privacy. The statutory tort for serious invasions of privacy commenced on 10/06/2025.

This matters because the tort can reach even businesses otherwise exempt from the Act. A person could take action directly, without waiting for the regulator, so exempt or not, careful data handling is now the safe default.

Here are some example items:

  • Misusing a customer’s contact details in a way that causes real harm.
  • Sharing a supporter’s private information without any consent.

Stronger enforcement and penalties

If you store customer data, watch this one closely. The reforms expanded the OAIC’s powers and the penalties it can pursue, so the regulator has more ways to act and more weight behind each one.

For a small operator, the takeaway isn’t any single headline figure. It’s that mishandling data now carries a bigger, more enforceable price, so prevention is far cheaper than the alternative.

Here are some example items:

  • A court-ordered civil penalty for a serious breach.
  • An enforcement notice requiring a business to change its practices.

New transparency duties for automated decisions

Review any automation you use before 10/12/2026. From that date, covered entities will need to be open about significant automated decisions. If software makes a call that materially affects someone, your privacy policy will need to say so.

Most small email programs won’t hit this yet, but it signals where things are heading. If you start using automation that scores or sorts people, note how it works now.

Here are some example items:

  • An automated system that scores customers for offers.
  • A tool that auto-sorts applicants without a human review.

How to prepare your email marketing for the reforms

Preparing for the Australian Privacy Act reforms is manageable for a small team, and most of it lines up with good marketing habits. According to our Q1 2026 Small Business Now report, email marketing is the channel small businesses value most. In fact, 41% expect it to be their most valuable channel this year, so protecting that data protects your best channel.

Step 1: Map the personal information you collect

List what you collect, why you collect it, where it lives, and who can see it. This simple audit shows the data you actually use versus the fields you’re keeping out of habit.

Once you can see it all in one place, you can trim the excess. Tools that let you segment your contact list reward that discipline, because cleaner data makes your campaigns sharper too.

Step 2: Tighten consent at sign-up

Ask people to opt in rather than buying a list or adding contacts who never agreed. Permission-first collection is fairer, and it usually delivers a more engaged audience.

Now for the housekeeping part: Spell out what people are signing up for. Our guide to permission-based email marketing walks through clear opt-in. You can also build sign-up forms that capture consent in minutes.

Step 3: Keep your list clean and current

When your list is full of stale contacts, both your risk and your bounce rate climb. Remove people who’ve gone quiet or asked to leave, and correct details when they change.

Holding less data lowers your exposure under the reforms. Tidy email list management keeps your list lean and your deliverability healthy.

Step 4: Update your privacy policy and collection notice

A short privacy notice beside your email field does more than a wall of legal text. Tell people what you collect and why at the point of sign-up, then keep that policy current.

Your policy should match what you actually do, so review it whenever your practices change. Clear list-building tools make it easy to show that notice right where people join.

Step 5: Get breach-ready

If a laptop goes missing or a spreadsheet leaks, your response plan matters as much as your security. Lock down your data, limit who can access it, and write a short plan for what you’ll do.

Decide now who to contact and how quickly you’d act. That preparation sets you up for the breach rules we’ll cover shortly.

How to check your data practices against the reforms

Every business collects and stores data a little differently, so a self-check should fit your size, not a corporate legal team’s. Use the three quick checks below to test your process in under an hour.

Review what you collect and why

Look at each field you gather and ask whether it maps to a real purpose. If a field hasn’t earned its place, cut it.

Say a salon still asks for a date of birth it never uses; dropping that field lowers risk and speeds up the form. It’s a quick win that pays off every time someone signs up.

Check your consent and unsubscribe trail

Can you show how a person joined your list and how they opted out if they left? Good email records answer that in seconds.

The bit people skip is this: A consent trail is only useful if you can find it later. When you grow your email list through sign-up forms, keep the join date and method attached to each contact.

Test your breach response

Run a quick “what if” scenario so you know who to tell and how fast you’d move. Walk through a lost laptop or a leaked spreadsheet and see where you’d get stuck.

A five-minute drill often surfaces gaps, like an out-of-date contact list for your response team. Fix those now, while the pressure is off.

Key Privacy Act reform guidelines for Australian small businesses

Focus on the guidelines that decide how the Australian Privacy Act reforms affect you. Start with who is covered, then breach duties, then your day-to-day records.

Who the reforms apply to

The OAIC guidance for small business says a small business has an annual turnover of $3 million or less. Most are exempt, though exceptions apply, including health providers and businesses trading in personal information.

The exemption is in force today. Its removal has been proposed but not enacted, and no date has been set. So plan for full compliance rather than betting on the exemption lasting.

The Notifiable Data Breaches (NDB) scheme

Know where your contact data lives before anything goes wrong. Under the Notifiable Data Breaches (NDB) scheme, covered entities must report certain breaches. They must notify the OAIC and affected individuals of an eligible breach likely to cause serious harm.

Say a spreadsheet of subscriber emails leaks: You’d need to tell those people and the OAIC quickly. That’s far easier when you already know what data you hold and where.

What this means for your email records

Could you answer an access request this week? Under the APPs, people can ask to see and correct the personal information you hold, so keep records tidy enough to respond quickly. Log how and when each contact opted in, too.

Say a supporter asks a not-for-profit what it holds on them; a clean record lets you pull the sign-up date and source in minutes. Treat these records as part of running your list, not as extra paperwork.

Australian Privacy Act reform best practices

Here are the everyday habits that keep your data handling clean and your subscribers confident as the rules change.

  • Collect only what you need: Ask for details that serve a real purpose, and leave the rest.
  • Say why you’re collecting it: Explain the purpose in plain words at sign-up.
  • Keep one current privacy policy: Review it yearly and update it when practices change.
  • Make opting out easy: Every email needs a working unsubscribe link.
  • Secure the data and limit access: Only staff who need the information should see it.
  • Clean your list regularly: Remove contacts who’ve gone quiet or asked to leave.
  • Keep consent records: Note how and when each person opted in.
  • Plan for a breach: Know who to tell and how fast, before anything goes wrong.

Common mistakes with the Privacy Act reforms

These slip-ups are common, and most come from good intentions. It stings to slow down when you’re busy, but a few minutes here saves real trouble.

  • The mistake: assuming the reforms don’t touch you because you’re exempt.
  • How to fix it: Remember the new statutory tort can reach exempt businesses, so handle data as if the rules apply.
  • The mistake: treating the Australian Privacy Act and the Spam Act 2003 as the same law.
  • How to fix it: Remember the OAIC oversees personal information, while ACMA oversees marketing consent and unsubscribe.
  • The mistake: keeping every contact and every field forever.
  • How to fix it: Set a routine to delete data you no longer use, so you hold less and risk less.
  • The mistake: buying or renting a contact list to grow faster.
  • How to fix it: Build your list from people who opted in, which is fairer and more engaged.
  • The mistake: having no plan for a data breach.
  • How to fix it: Write a short response plan now that names who to contact and how quickly you’ll act.

Keep customer trust while the rules change

You’ve now got the shape of the Australian Privacy Act reforms. You know what’s changing, who it affects, and the habits that keep your email program steady.

The next step that matters most is getting your consent and data habits right. Good practice protects both your subscribers and the channel you rely on.

When you’re ready to put clean, permission-based habits to work, you can try Constant Contact free for 30 days and start collecting contacts the right way.

FAQs

What are the Australian Privacy Act reforms?

The Australian Privacy Act reforms are changes to the Privacy Act 1988, made mainly by the Privacy and Other Legislation Amendment Act 2024. More reform has been proposed, so the rules will keep evolving.

Do the Privacy Act reforms apply to my small business?

Most small businesses are still exempt based on turnover, but exceptions such as health providers apply. The new statutory tort can also reach you regardless of the exemption.

How do the reforms affect email marketing?

The reforms raise the stakes for consent, data minimisation, and breach readiness. For example, a café might drop an unused birthday field and switch to clear opt-in before its next campaign.

What is the statutory tort for serious invasions of privacy?

It’s a new right, in force from 10/06/2025, that lets individuals sue for serious invasions of privacy. It can apply even to businesses otherwise exempt from the Act.

Share with your network
Avatar photo

Whitney Filloon is a writer, content strategist, and former Vox Media journalist who has worked with enterprise brands like Skype and Microsoft and helped dozens of small businesses figure out their "secret sauce".

Related Articles