Serious Invasion of Privacy Tort Lands in Australia: What It Means for Your Business

Australia’s First Serious Invasion of Privacy Tort Has Landed (And It’s About to Get Messy)

On 10 June 2025, Australia quietly flipped the switch on a major new legal right: individuals can now sue under a serious invasion of privacy tort. It’s a landmark change in a country that, until now, didn’t give people a clear way to fight back when their private lives were mishandled, filmed, leaked, or sold.

For businesses, this is not a drill. From customer emails to CCTV footage, and everything in between, the new serious invasion of privacy tort puts privacy in the courtroom, and most companies aren’t ready.

So, What Just Happened?

Australia has officially created a national, statutory tort (read: civil wrong) for serious invasions of privacy. While privacy breaches have long attracted regulator attention or made headlines, they rarely led to real consequences for the companies responsible unless, perhaps, it involved a giant telco.

Now, that’s changed. A single employee mistake, an overlooked system, or even a “helpful” AI tool can land your business in court, and you don’t need to be a tech giant to get caught out.

How the Serious Invasion of Privacy Tort Can Be Breached

This new tort comes in two flavours:

1. Intrusion upon seclusion

Basically: spying. Think hidden cameras, sneaky phone recordings, or apps that track users without warning. This covers any intentional or reckless act that seriously invades someone’s private space or moments.

2. Misuse of private information

This one is all about what you do with the data you collect. Leaking customer info, exposing sensitive medical records, sharing private details without consent, it’s now a legal landmine.

The catch? You don’t even need to cause financial loss. Emotional distress alone is enough to trigger a claim. And yes, courts can order damages (up to $478,000), takedowns, public apologies, and even the destruction of offending material.

Why the Serious Invasion of Privacy Tort Is a Wake-Up Call for Business

This law doesn’t just target bad actors or data breaches. It hits ordinary mistakes made by ordinary businesses, the marketing email sent to the wrong person, the team member who screenshotted a customer chat, or the outdated consent form that no one updated after a rebrand.

And while the tort applies to individuals, businesses are on the hook when their employees are involved. That means if someone on your team slips up while “just doing their job,” it’s your name on the claim.

Expect Litigation Under the Serious Invasion of Privacy Tort

This tort is new, but the problems it covers aren’t. Expect an initial wave of litigation in areas like:

  • Retail and hospitality: Surveillance-heavy environments, loyalty programs, and tracking tech.
  • Health and fitness: Personal data, body images, sensitive scans, and AI health assessments.
  • Tech platforms: Data scraping, AI-generated content, or app permissions that go too far.
  • Education: Webcam monitoring and facial recognition in online exams.
  • Property and building management: Smart locks and motion sensors that collect occupant behaviour.

The first lawsuits will likely be straightforward clear invasions with big emotional impact. But as awareness grows, so will the complexity. And the stakes.

The Privacy Culture Shift

Most businesses say they care about privacy. Few know how to show it.

This new tort will push privacy beyond legal compliance and into company culture. Ticking a privacy policy box is no longer enough; what matters is what you actually do when no one’s watching (which, ironically, may now be part of the problem).

It’s time to start asking:

  • Do we need to collect this data?
  • Do people know we’re collecting it?
  • What would happen if this info leaked, financially and reputationally?

Your CCTV Is Watching You Too

The new privacy tort isn’t designed to terrify businesses, but it is meant to make them stop and think. The fact is, data is everywhere and the more casually it’s handled, the greater the risk.

This is about being intentional and building trust, not about becoming a cautionary tale.

So next time you hit “send,” install a camera, or ask someone to hand over their details, pause. Because in 2025, privacy is personal. And now, it’s also legally enforceable.

Jake McKinley notes that this article is written for the purpose of providing generalised information and not to provide specialised legal advice. If you require qualified legal advice on anything mentioned in this article, our experienced team of solicitors at Jake McKinley are here to help. Please get in touch with us on 02 9232 8033 today to make an enquiry. 

Related Articles

- End", entire site, priority AFTER 8417. * * What it does: * 1. On load, reads gclid + utm_* from the URL and stores them in a * first-party cookie for 90 days (only overwrites gclid when a new one * is present, so a later organic visit does not wipe the paid click). * 2. Appends those params to every calendly.com link and to any inline * Calendly embed, so a completed booking carries them into Calendly and * onward to the RedRain integration. */ (function () { 'use strict'; var COOKIE = 'jm_attr'; var MAXAGE = 60 * 60 * 24 * 90; // 90 days var UTM_KEYS = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_content', 'utm_term']; function readCookie(name) { var m = document.cookie.match('(?:^|; )' + name + '=([^;]*)'); return m ? decodeURIComponent(m[1]) : ''; } function writeCookie(name, val) { document.cookie = name + '=' + encodeURIComponent(val) + '; path=/; max-age=' + MAXAGE + '; SameSite=Lax; Secure'; } // ---- 1. capture from URL, merge with stored ---- function capture() { var url = new URLSearchParams(window.location.search); var stored = {}; try { stored = JSON.parse(readCookie(COOKIE) || '{}'); } catch (e) { stored = {}; } var incomingGclid = url.get('gclid'); if (incomingGclid) { stored.gclid = incomingGclid; } // only overwrite on a fresh click UTM_KEYS.forEach(function (k) { var v = url.get(k); if (v) { stored[k] = v; } }); // if a gclid arrived but no utm_source, tag the source so RedRain is not blank if (incomingGclid && !stored.utm_source) { stored.utm_source = 'google'; stored.utm_medium = 'cpc'; } if (Object.keys(stored).length) { writeCookie(COOKIE, JSON.stringify(stored)); } return stored; } var attr = capture(); if (!attr || (!attr.gclid && !attr.utm_source)) { return; } // nothing to forward // ---- 2. build a query string for Calendly ---- function calendlyParams() { var p = new URLSearchParams(); UTM_KEYS.forEach(function (k) { if (attr[k]) { p.set(k, attr[k]); } }); // carry the raw gclid too. utm_content is the safe carrier RedRain can map // if its Calendly field mapping does not expose a native gclid slot. if (attr.gclid) { p.set('gclid', attr.gclid); if (!p.get('utm_content')) { p.set('utm_content', 'gclid:' + attr.gclid); } } return p.toString(); } function withParams(href) { if (!href || href.indexOf('calendly.com') === -1) { return href; } var qs = calendlyParams(); if (!qs) { return href; } // don't double-append if (href.indexOf('utm_source=') !== -1 || href.indexOf('gclid=') !== -1) { return href; } return href + (href.indexOf('?') === -1 ? '?' : '&') + qs; } // ---- 3a. rewrite anchor links (covers the popup/booking click path) ---- function rewriteLinks() { var links = document.querySelectorAll('a[href*="calendly.com"]'); for (var i = 0; i < links.length; i++) { var a = links[i]; if (a.getAttribute('data-jm-attr') === '1') { continue; } a.setAttribute('href', withParams(a.getAttribute('href'))); a.setAttribute('data-jm-attr', '1'); } } // ---- 3b. rewrite inline embeds. Must run before Calendly widget.js reads // data-url; if the widget already initialised, re-point and let it // re-read on next interaction. Most bookings go via the link path. ---- function rewriteEmbeds() { var w = document.querySelectorAll('.calendly-inline-widget[data-url]'); for (var i = 0; i < w.length; i++) { var el = w[i]; if (el.getAttribute('data-jm-attr') === '1') { continue; } el.setAttribute('data-url', withParams(el.getAttribute('data-url'))); el.setAttribute('data-jm-attr', '1'); } } function run() { rewriteLinks(); rewriteEmbeds(); } if (document.readyState === 'loading') { document.addEventListener('DOMContentLoaded', run); } else { run(); } // catch links injected later (Elementor popups, lazy content) if (window.MutationObserver) { var mo = new MutationObserver(function () { rewriteLinks(); }); mo.observe(document.documentElement, { childList: true, subtree: true }); } })();