MarketplacePrivacyPrivacy Act 1988
PrivacyLaw

Privacy Act 1988

Privacy Act 1988

The Privacy Act 1988 is an Australian law that regulates the handling of personal information by businesses, government agencies, and other entities. It includes provisions for the Australian Privacy Principles, credit reporting, and notification of data breaches.

Overview

The Privacy Act 1988 establishes a comprehensive framework for managing personal information to protect individuals' privacy in Australia. It outlines the Australian Privacy Principles (APPs), which provide guidelines for handling personal information, including collection, use, storage, and disclosure. The Act also includes specific provisions for credit reporting, mandates for the notification of eligible data breaches, and mechanisms for individuals to lodge complaints about privacy breaches. Administered by the Attorney-General's Department and the Department of the Treasury, the Act applies to organisations, agencies, and entities operating in Australia with specific provisions extending to certain overseas entities.

Related in Privacy

PrivacyLaw

PRIS Act — Privacy and Responsible Information Sharing Act 2024

The Privacy and Responsible Information Sharing Act 2024 (PRIS Act) establishes a privacy framework for the Western Australian public sector. It introduces Information Privacy Principles (IPPs) and provisions for privacy complaints, privacy impact assessments, and a notifiable information breach scheme.

Government of Western Australia • Western Australia

View details
PrivacyControl set

NIST SP 800-53 Rev. 5.2 — Security and Privacy Controls for Information Systems and Organizations

NIST Special Publication 800-53 Rev. 5 provides a comprehensive catalog of security and privacy controls designed to safeguard organizational operations, assets, and individuals from a broad spectrum of risks including cyberattacks, human mistakes, and natural disasters. It is widely used for implementing security measures as part of risk management frameworks.

NIST (National Institute of Standards and Technology) • United States • v5.2.0

View details
PrivacyRegulation

India - (DPDP) Rules — India - Digital Personal Data Protection (DPDP) Rules

The Digital Personal Data Protection Rules, 2025 operationalize India’s Digital Personal Data Protection Act, 2023 by establishing detailed requirements for the collection, processing, storage, and protection of digital personal data. The Rules define obligations for organizations handling personal data, including consent management, breach notifications, data retention, and protections for children and vulnerable individuals. They also establish governance mechanisms such as the Data Protection Board and provide a phased implementation timeline for compliance.

Government of India • India • v2025

View details
PrivacyLaw

India - PDPD Act — India - Digital Personal Data Protection (PDPD) Act (Act No. 22 of 2023)

The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) establishes India’s legal framework for processing digital personal data while balancing individuals’ privacy rights with lawful data use. The Act defines obligations for organizations handling personal data, grants rights and duties to individuals, and introduces requirements for consent, data protection, and breach accountability. It also establishes the Data Protection Board of India to oversee compliance, adjudication, and enforcement of penalties for violations.

Government of India • India • v2023

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call