The Aged Care Act 2024 has absorbed most of the compliance energy in the residential aged care sector over the past two years. The Strengthened Quality Standards raised the bar significantly on governance, safety, and person-centred care. What is getting considerably less attention is the Privacy Act.

Operators have spent considerable time and money getting their quality governance in order, and the pressure from the ACQSC is real and enforced. The 2024 reforms to the Privacy Act, however, apply to approved aged care providers independently of the Aged Care Act and are enforced by a completely separate regulator.

These are not one compliance programme running on parallel tracks. They are two compliance programmes with different obligations, different enforcement bodies, and different consequences for failure. Providers who have embedded privacy inside their quality management framework — treating it as a dimension of quality rather than a standalone legal obligation — have a structural gap. Most will not discover it until it surfaces as an incident.

What aged care providers are holding

Aged care providers collect and hold some of the most sensitive personal information in existence. Health records. Cognitive and functional assessments. Medication histories. Financial affairs, including income, assets, and estate planning. Family relationships, including estrangement and conflict. Advance care directives and end-of-life preferences.

That information does not sit in a locked filing cabinet. It moves. In the course of a normal week, a single resident’s information might be accessed by care staff across multiple shifts, disclosed to a general practitioner, shared with an allied health provider, discussed with a pharmacist, and referenced by administrative staff processing a fee assessment. Family members request updates. Subcontractors are on site.

Every one of those access and disclosure events is in scope under the Australian Privacy Principles. The 2024 reforms did not change that underlying framework. Quite the opposite — they tightened it and added teeth.

What the Privacy Act reforms changed for aged care

Three changes from the Privacy and Other Legislation Amendment Act 2024 are directly relevant to how aged care providers operate.

APP 11.3 now explicitly requires both technical and organisational security measures. A modern electronic records system run by staff who have never been trained on what constitutes a disclosure risk, or what to do when something goes wrong, is not a compliant posture. Both the technical environment and the information governance environment are in scope and both will be assessed if the OAIC examines a complaint or breach.
The statutory tort for serious invasion of privacy creates direct civil litigation exposure. A reckless disclosure of a resident’s health information to an unauthorised family member — something that occurs in care settings with more regularity than providers would like to acknowledge — could now result in direct legal action from the affected individual. Not a complaint to a regulator. A claim. The test is whether the conduct was intentional or reckless, and whether a reasonable person would regard the privacy invasion as serious. In a care context, health and financial information meets that threshold.
The NDB scheme’s 30-day notification clock applies in full, and the clock starts early. Under the Notifiable Data Breach scheme, an organisation must notify the OAIC and affected individuals within 30 days of becoming aware of information likely to constitute an eligible data breach. Healthcare is consistently the highest-reporting sector for notifiable data breaches in Australia. Aged care sits within that sector. In a care environment with multiple shifts, distributed teams, and high staff turnover, awareness and escalation of a potential breach can fragment quickly. A breach response programme not designed for that operational reality will not meet the 30-day threshold reliably.

Two regulators, running on different clocks

The Aged Care Quality and Safety Commission audits compliance with the Strengthened Quality Standards. The Office of the Australian Information Commissioner assesses compliance with the Australian Privacy Principles and the NDB scheme. These bodies have different legislative mandates, different investigation powers, and different consequences for non-compliance.

A successful ACQSC audit outcome does not indicate Privacy Act compliance. The ACQSC is not assessing APP 11.3. It is not assessing how consent is managed when information is shared with allied health providers. It is not assessing whether your breach response programme meets the NDB notification threshold. Producing a clean quality report and treating that as a complete compliance picture is a category error — one that leaves the organisation exposed on a separate regulatory front.

This is not a technical observation. It is a governance one. If your compliance programme does not have a dedicated privacy workstream sitting alongside your ACQSC quality programme — with its own framework, its own training obligations, and its own incident response pathway — it is structurally incomplete.

Best practice: what a compliant posture requires

Privacy compliance in aged care is a governance programme, not a policy document. Several elements need to be in place and functioning, not just documented.

A Privacy Management Framework under APP 1. This maps what information is collected, from whom, for what purpose, and who can access or disclose it. In a care setting, that mapping is complex. It needs to reflect the operational reality of the environment: the shift structure, the contractor relationships, the allied health network. Not an idealised version of how information should flow.
Privacy-specific staff training. Training that goes beyond general information handling awareness. Care staff need to understand what a disclosure risk looks like in their working environment, what they are and are not authorised to share, who can make requests for information and under what circumstances, and what to do when something appears to have gone wrong.
Technical controls and operational governance working together. APP 11.3 makes the combined requirement explicit. A well-configured records system with weak governance around access and disclosure is not sufficient. Neither is strong governance operating on an inadequately secured technical platform. Both sides are assessed.
A breach response programme built for care environments. Specifically designed to work across shifts, account for staff at varying levels of awareness, and produce a reportable outcome within 30 days. A general-purpose incident response policy with “healthcare” written at the top will not achieve this.

The gap that most aged care providers carry is not a technology gap. It is a governance gap: privacy embedded inside quality, rather than running alongside it as a distinct obligation.

Daniel Johns is a CRISC-certified virtual CISO and GRC advisor, and Founder of Coastal Cyber. He works with healthcare providers, independent schools, financial services firms, and technology businesses across Southeast Queensland on privacy, cyber security, and governance.

If your privacy and compliance posture needs a clear-eyed assessment, book a 15-minute conversation.