Cybersecurity Policy Report, Privacy Sweep to Focus on Australian Businesses’ Data Collection, (Dec 10, 2025)
By Tony Foley
The Office of the Australian Privacy Commissioner (OAIC) will launch its first-ever compliance sweep in 2026, conducting a targeted review of businesses’ privacy policies to ensure they are compliant with legal requirements.
The sweep will begin in the first week of January, according to an OAIC press release yesterday. It will scrutinize the privacy policies of businesses that collect personal information in person, like real estate agencies asking for phone numbers at open houses or car rental agencies presenting customers with lengthy forms. Entities found to have non-compliant policies may face compliance and infringement notices and penalties of up to $66,000 Australian (US$44,075). The failure to adopt compliant privacy policies is one of the areas in which the possible regulatory consequences for infringements were expanded by amendatory changes to the Privacy Act in 2024.
OAIC chose to focus on in-person collections of personal information after identifying that such practices often involve power and information asymmetries. “When confronted with in-person requests for their personal information from retailers, licensed venues, car hire companies or real estate agents, consumers often don’t have access to all the information they might need to make an informed decision,” said Privacy Commissioner Carly Kind. “This makes them vulnerable to overcollection of personal information and creates risks to their security and privacy. In conducting a compliance sweep, the OAIC intends to ensure that entities are meeting their obligations to be transparent with consumers and customers about how they’re using the personal information they collect in-person.”
News: InternationalLegislation DataPrivacy