If your business sits under the Privacy Act’s $3 million turnover threshold, you have probably been told you are exempt from the Privacy Act. You are, from most of it. You are not exempt from the tort that commenced on 10 June 2025, and neither is anyone else in Australia, individual, business, or government body, regardless of size or Privacy Act coverage.

Four months after it commenced, a District Court judge used it to shut down a campaign of harassment against a Sydney property developer, over leaked wedding photographs, not a data breach. That case is worth understanding before assuming this doesn’t apply to you.

What Changed on 10 June 2025

The Privacy and Other Legislation Amendment Act 2024 (Cth) received royal assent in December 2024 and inserted a new statutory tort for serious invasions of privacy as Schedule 2 to the Privacy Act 1988. It commenced six months later, on 10 June 2025.

A plaintiff has to prove five elements: that the defendant invaded their privacy, either by intruding on their seclusion or misusing information about them; that a reasonable person in their position would have expected privacy in the circumstances; that the invasion was intentional or reckless, negligence isn’t enough; that the invasion was serious; and that the public interest in protecting their privacy outweighs any competing public interest, such as freedom of the press. Proving actual damage isn’t required at all, only individuals can bring a claim, but the pool of people or organisations they can sue is broad.

Why “We’re Exempt from the Privacy Act” Doesn’t Help You Here

This is the part most Australian SMEs get wrong, understandably, since Coastal Cyber spends a fair amount of time explaining the small business exemption in other contexts.

The new tort was deliberately drafted to sit outside the Privacy Act’s regulatory framework. Courts are directed to interpret it independently of how terms are defined elsewhere in the Act. The practical result: you don’t need to be an APP entity, and the $3 million turnover exemption that shields most small businesses from the rest of the Privacy Act does nothing here. Any individual or organisation, including one currently exempt from everything else in the Act, can be sued if the five elements are met.

There’s a second exposure worth knowing about if you employ staff. Businesses can face vicarious liability for an employee’s or agent’s conduct if the invasion happened in the course of their work, using a work phone to record someone, sharing information gained on the job, an insider leaking data. The employer doesn’t need to have done anything wrong directly.

The First Case: A Property Dispute, Not a Data Breach

On 7 October 2025, Justice Gibson of the NSW District Court handed down the first published decision applying the new tort, in Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396.

The background has nothing to do with cyber security. A Sydney developer lodged a redevelopment application. A tenant on the affected site demanded $50,000 to withdraw his objection, and when refused, ran what the court called a “campaign of extortion”: a hostile website, a one-star review, hostile submissions to the planning committee, and the second plaintiff’s private wedding photographs, published in a way intended to suggest impropriety rather than what they actually showed. The court found there was a serious question to be tried under the privacy tort, alongside claims in defamation and intimidation, and granted urgent injunctions requiring the material to come down within two days.

The lesson for a GRC-minded business owner isn’t about hacking or data breaches. It’s that a workplace dispute, a difficult client, or a soured business relationship can now turn into a privacy claim the moment private material gets published to make a point.

What This Costs, in Practice

Courts can order injunctions, apologies, corrections, and destruction of material, alongside damages. Non-economic loss, including any exemplary or punitive damages a court decides to award, is capped at $478,550 or the equivalent defamation cap, whichever is higher. There’s no cap at all on damages for proven financial loss. Aggravated damages aren’t available, but exemplary and punitive damages are, in exceptional circumstances.

A plaintiff generally has to start proceedings within one year of becoming aware of the invasion, or three years of it occurring, whichever comes first. That’s a short window by most civil litigation standards, and it cuts both ways: it also means a threat can surface and resolve faster than businesses are used to.

Best Practice - This is the way

  1. Stop treating the small business exemption as blanket cover. It protects you from most of the Privacy Act. It does not protect you from this tort.
  2. Extend your review beyond IT controls to how staff handle personal information about people in disputes. Former employees, difficult clients, tenants, neighbours, anyone your business is in conflict with. That’s where this tort is actually being tested.
  3. Build a documented process for disputes before they escalate. The Kurraba case turned on conduct that built up over months. A clear internal process for handling a hostile client or ex-employee, before anything gets published, is cheaper than defending an injunction application.
  4. Get advice early once personal information becomes part of a dispute. Not after something’s already online.

Daniel Johns is a CRISC-certified virtual CISO and GRC advisor, Founder of Coastal Cyber, and a former member of the ISACA Global Advisory Council and CompTIA Executive Council ANZ. He works with healthcare providers, education, financial services, technology businesses, and MSPs across Southeast Queensland on privacy, cyber security, and governance.

If your privacy and cyber posture needs a clear-eyed assessment, book a 20-minute conversation.

Sources

  • MinterEllison, “Statutory tort for serious invasions of privacy comes into force,” 11 June 2025 (commencement date, elements, remedies, damages cap, exemptions). minterellison.com
  • Corrs Chambers Westgarth, “The new statutory tort for serious invasions of privacy and its implications for business” (elements, defences, limitation periods, vicarious liability for employers). corrs.com.au
  • Colin Biggers & Paisley, “Putting the privacy tort to the test: First application for relief under the statutory tort for serious invasions of privacy,” 5 November 2025 (Kurraba v Williams case detail). cbp.com.au
  • Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396 (7 October 2025, Gibson DCJ)