For organisations that incur “severe” or “repeated” privacy breaches, the government has succeeded in securing passage of a substantial increase in civil fines.
The new penalties will take effect one day after the Governor-General has given his or her royal assent.
With only a slight wording change, the law was approved by the senate on Monday, and the lower house later that day.
A number of high-profile privacy violations in Australia, for which the maximum penalties is $2.22
Penalties for more egregious breaches are now up to $50 million, 30 percent of adjusted turnover, or three times any financial benefit derived through data misuse.
Attorney General Mark Dreyfus stated in a statement that “the government has wasted no time in reacting to recent serious data breaches.”
“In a little more than a month, we announced, introduced, and delivered legislation.
Large organisations are clearly informed by these new, more severe fines that they must improve the security of the data they acquire.
Since late last week, when a senate committee recommended that the bill be passed, Senate passage had been anticipated.
Industry opposition to the potential penalty amounts did not result in a reduction of the penalties’ amounts.


