Click to start searching

Privacy laws

Privacy laws exist at both state and federal level. We’re here to help you understand them.

Content last updated 29/09/2026

Privacy laws

On this page


Privacy laws

Privacy laws regulate how organisations collect, use, store and disclose personal information.

Not-for-profit organisations often hold personal information about clients, service users, members, donors, employees and volunteers. Some organisations also hold sensitive information, such as health information or information about a person’s racial or ethnic origin, religious beliefs or sexual orientation.

Some not-for-profits must comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. State and territory privacy laws may also apply. Privacy obligations can also arise under government contracts, funding agreements and other laws.

Even if privacy legislation does not apply to your organisation, good privacy practices can help protect the people your organisation works with, maintain community trust and reduce privacy and cyber security risks.


Our privacy law resources

Use our resources to understand legal and practical issues relating to privacy, cyber security and artificial intelligence.

Privacy

Our privacy resources explain:

  • when privacy laws may apply to a not-for-profit organisation
  • what personal, sensitive and health information is
  • the Australian Privacy Principles
  • privacy policies and collection notices
  • collecting, using, disclosing and storing personal information
  • access to and correction of personal information
  • artificial intelligence, automated decision-making and privacy
  • data breaches and the Notifiable Data Breaches scheme, and
  • related issues, including confidentiality, surveillance, direct marketing and freedom of information

For more information, see our privacy webpage.

Cyber security

Cyber security involves protecting information, devices, networks and systems from unauthorised access, loss, disruption and attack.

Our cyber security resources explain common cyber risks, third-party provider risks, practical security measures, cyber incident response planning, obligations under the Cyber Security Act 2024 (Cth), and the relationship between cyber security and privacy law.

For more information, see our cyber security webpage.

Artificial intelligence

Artificial intelligence can help not-for-profits improve their processes and services, but its use can create privacy, confidentiality, cyber security and other legal risks.

Our artificial intelligence resources explain the opportunities and risks associated with AI, including privacy, confidentiality, cyber security and governance considerations for not-for-profit organisations.

For more information, see our artificial intelligence webpage.


Common questions about privacy laws

Does the Privacy Act apply to not-for-profits?

The Privacy Act 1988 (Cth) applies to many not-for-profit organisations with annual turnover of more than $3 million. Annual turnover for this purpose is calculated under the Privacy Act and will generally include income from all sources.

The Privacy Act can also apply to some organisations with annual turnover of $3 million or less. This includes some organisations that:

  • provide a health service and hold health information
  • trade in personal information
  • handle tax file number information
  • provide services under an Australian Government contract, or
  • are related to an organisation covered by the Privacy Act

State or territory privacy laws may also apply, particularly where an organisation provides services under an arrangement with a state or territory government.

Whether privacy laws apply depends on the organisation’s activities, structure, contracts and the information it handles. Even if the Privacy Act does not apply, good privacy practices can protect individuals and help maintain community trust.

For more information, see our privacy webpage.

Does our charity need a privacy policy?

A charity covered by the Australian Privacy Principles must have a clearly expressed and up-to-date privacy policy.

The policy must explain matters including:

  • what kinds of personal information the charity collects and holds
  • how it collects and holds that information
  • why it collects, holds, uses and discloses personal information
  • how a person can access or correct their information
  • how a person can make a privacy complaint and how the charity will respond
  • whether the charity is likely to disclose personal information overseas and, if practicable, the countries involved

A charity that is not covered by the Australian Privacy Principles should still consider having a privacy policy. The policy can help the charity explain its practices, guide its workers and volunteers, and demonstrate responsible handling of personal information.

A privacy policy should accurately reflect what the charity does in practice. The charity should review it when its activities, systems or information-handling practices change.

For more information, see our privacy webpage.

What do we need to do after a data breach?

A data breach occurs when personal information is lost or is accessed or disclosed without authorisation.

Act promptly to:

  • contain the breach and protect affected information
  • assess what happened, including what information is involved and who may be affected
  • reduce the risk of harm
  • consider notification obligations, including under the Notifiable Data Breaches scheme
  • review the incident and improve systems, policies and training

If the Privacy Act covers your organisation, the Notifiable Data Breaches scheme may require it to notify affected individuals and the Office of the Australian Information Commissioner where an eligible data breach is likely to result in serious harm. Other notification duties may arise under state or territory laws, contracts, funding agreements or regulatory requirements.

Seek legal and technical advice where necessary and avoid destroying records or evidence that may be needed to investigate the incident.

For more information, see our privacy webpage and our cyber security webpage.

What should not-for-profits know about using AI?

Artificial intelligence (AI) can help not-for-profit organisations improve efficiency, reduce administrative workloads and enhance service delivery. However, AI can also create privacy, confidentiality, cyber security and governance risks.

Before using an AI tool, organisations should:

  • understand how the tool collects, stores, uses and protects information
  • avoid entering personal, sensitive or confidential information unless the use has been assessed and authorised
  • check the provider's privacy, security and data retention practices
  • consider whether information may be stored or processed overseas
  • provide clear guidance and training for staff and volunteers
  • ensure appropriate human oversight of important decisions and AI-generated outputs

An organisation remains responsible for complying with its privacy, confidentiality and other legal obligations when using an AI tool. Before adopting AI, organisations should understand how information is handled, whether information may be disclosed to third parties, and whether the tool could affect decisions involving individuals.

For more information, see our artificial intelligence webpage.


The content on this webpage was last updated in September 2026 and is not legal advice. See full disclaimer and copyright notice.


Apply for free legal help


0