A new privacy right is here. What does it mean for business?
A high-profile court case in New South Wales may provide guidance on Australia's new privacy laws.
Maurice Terzini, founder of Bondi Icebergs Dining Room, has reportedly taken legal action against his former wife, Emma Addams, and the Nine Network, alleging private information was disclosed and published without his consent. The information is said to include personal text messages, financial information and details relating to their relationship.
While the case is yet to be decided, it could provide important guidance on how Australia's new statutory tort for serious invasions of privacy will be applied.
The new tort came into effect nationally on June 10, 2025 under amendments to the Privacy Act 1988 (Cth). It gives individuals a direct right to take legal action when their privacy has been seriously invaded.
What is a serious invasion of privacy?
The new law covers two types of conduct:
- intruding on a person's private life, and
- misusing their personal information.
For most businesses, the second category is likely to be the biggest concern.
The tort applies when personal information is collected, used, shared or handled in a way that seriously infringes an individual's privacy. Importantly, not every privacy mistake will lead to liability. The conduct must be serious, and the person must have had a reasonable expectation that the information would remain private.
This expectation is more likely to exist where information is sensitive in nature, such as:
- health information;
- financial records;
- private communications;
- employment records; or
- personal or intimate information.
The law also requires the conduct to be intentional or reckless. Genuine mistakes or simple negligence will not usually be enough.
Why should businesses pay attention?
The new tort creates legal risks that extend beyond traditional privacy obligations.
Businesses could face:
- urgent court orders requiring content to be removed;
- demands to return or destroy information;
- compensation claims; and
- reputational damage arising from privacy complaints or disputes.
Importantly, an individual does not necessarily need to prove they suffered financial loss before making a claim.
Business Law WA's Commercial Legal team is offering a free Red Flag Review of existing privacy policies to help identify potential gaps and compliance risks.
Get in touch today. Email [email protected] or call 08 9365 7560.
Where are the biggest risks?
For many businesses, privacy risks arise in day-to-day operations rather than major data breaches.
Common risk areas include:
- disclosing customer information in disputes, online responses or social media posts;
- accessing or disclosing HR, disciplinary or investigation records;
- using customer information for purposes people did not expect;
- sharing CCTV footage, recorded calls or security records without proper authority; and
- circulating sensitive information internally without a legitimate business need.
As businesses increasingly rely on customer data, workplace monitoring tools and digital communication platforms, it is important to ensure personal information is only being used for appropriate and clearly communicated purposes.
What remedies are available?
Courts have broad powers under the new legislation.
Depending on the circumstances, businesses could be ordered to:
- pay compensation for financial and non-financial loss, including distress;
- remove published material;
- issue corrections or apologies; or
- return, destroy or delete private information.
The maximum amount of damages available under the legislation is currently $478,550.
Practical tools to help you comply
Business Law WA has prepared practical privacy templates to help businesses review and update their privacy documentation.
The templates are written in plain English, customisable and designed to help businesses meet their privacy obligations with confidence.
What should businesses do now?
Businesses should review how they collect, store, access and share personal information.
Key documents such as privacy policies, collection notices, employee policies and customer complaint procedures should be updated to ensure they reflect current practices and clearly explain how information will be handled.
Managers and employees should also understand what constitutes sensitive information and when additional care is required before sharing it internally or externally.
How can Business Law WA assist?
Business Law WA (BLWA) can help businesses understand their obligations and reduce the risk of privacy-related claims.
Our team can assist with:
- privacy risk reviews;
- updating privacy policies and collection notices;
- employee and workplace privacy issues;
- customer complaints and social media responses;
- information-sharing and data governance processes;
- privacy incident response and remediation; and
- staff training and privacy compliance resources.
BLWA also offers privacy and collection notice templates through CCIWA's Legal Guides and Toolkits.
To discuss your business's privacy obligations, contact [email protected] or call 08 9365 7560.
Cass Wright – Legal Director, Business Law WA
Cass has practiced as a lawyer for more than 20 years. She has assisted a large number of SMEs and businesses to put in place protections against cyber attacks and make sure businesses better protect their data assets.
Cass is well known for her easy-to-talk-to nature, proactive advice and clarity.
Make a time to chat to her and discuss your needs: [email protected] or call 08 9365 7746.
This article is authorised by Business Law WA, an incorporated legal practice and wholly owned subsidiary of CCIWA. The content of this article is general in nature and is not legal or professional advice and should not be relied upon as such.
