Twenty-five years shaping
Australian privacy law.

Michael Rivette appeared in and initiated the cases that defined Australian privacy law, and wrote its leading texts. Solicitors brief him for the matters where privacy, data, and technology carry real risk.

In appropriate matters, corporations and individuals engage him directly. Where a solicitor is needed, he will say so at the outset.

★ Lawyer of the Year
Privacy and Data Protection
Best Lawyers
2026-2027
★ Best Lawyers®
★ Lawyer of the Year
Privacy and Data Protection
Best Lawyers
2020
★ Best Lawyers®
Michael Rivette, Barrister
Recognition and awards

Leading Lawyer, Privacy and Data Protection

Best Lawyers

2019-2026 (continuous)

Leading Barrister, Technology, Media & Telecommunications

Doyles Guide

2019

Leading Barrister, Intellectual Property

Doyles Guide

2018

Senior Fellow, Privacy Law, Master of Laws

Melbourne Law School

Current

Co-author, The Law of Privacy and the Media

Oxford University Press

Leading international text

Privacy Class Actions (2020) 94 ALJ 791

Australian Law Journal

Seminal article

Co-author, Remedies for Breach of Privacy

Hart Publishing

Leading international text

Editorial Board, Privacy Law Bulletin

LexisNexis

Current

Privacy class actions

He appears in Australia's most significant
privacy litigation.

These are the cases that established privacy litigation in Australia. Michael initiated, structured, or appeared as counsel in each of them.

Lead counsel for lead plaintiff

Evans v Health Administration Corp [2019] NSWSC 1781

Australia's first privacy class action to obtain compensation for class members, the template for all subsequent mass privacy breach litigation.

Counsel

McClure v Medibank Limited

One of Australia's most significant data breach class actions, arising from the breach affecting approximately 9.7 million customers.

Counsel, Court of Appeal

Giller v Procopets (2008) 24 VR 1

The foundational Victorian Court of Appeal decision that gave breach of confidence the capacity to protect individual privacy in Australia.

Counsel

Privacy Commissioner v Telstra (2017) 249 FCR 24

Significant Full Federal Court decision on the scope of personal information under the Privacy Act, with broad application across Australian industry.

Commercial law

Over 35 years of
hands-on commercial experience.

Commercial disputes in the digital economy turn on data, IP, and regulation as much as on contract. Michael has practised across all of them at the Bar, after 35 years as an owner, director, and board member in media and technology businesses.

Engagement

Three ways
to engage Michael.

Most matters come to Michael on a brief from an instructing solicitor. The professional rules also allow direct engagement where the matter suits it.

01
Law Firms
Specialist counsel for your client's privacy, technology, IP, or commercial matter, from written opinion to trial. Brief through Young's List or direct to chambers.
02
Corporations and Institutions
Major organisations facing privacy, data, and technology law matters may engage Michael directly for appropriate advisory work, whether through in-house counsel or on a direct access basis, with referral to external solicitors where the matter requires it.
03
Individuals
Individuals in privacy matters, including under the new Serious Invasion of Privacy tort, may be able to engage Michael directly in certain circumstances. See For Individuals for how direct engagement works.
About Michael Rivette
Michael Rivette, Barrister
Currently appearing

Michael Rivette continues to appear in courts and tribunals across all Australian jurisdictions in privacy, technology, and intellectual property matters.

One of Australia's
foremost privacy barristers.

Michael Rivette is one of Australia's most recognised barristers in privacy and data protection. Over more than 25 years at the Victorian Bar, he has appeared in and helped initiate the cases that defined Australian privacy law, alongside a broad technology, intellectual property, and commercial practice.

He regularly advises corporations, government agencies, and regulators on privacy compliance, cybersecurity risk, and data breach response and litigation. He also represents a wide range of individuals, including international public figures and celebrities, in complex and sensitive matters.

He appeared as counsel in Giller v Procopets (2008) 24 VR 1, the foundational Victorian Court of Appeal decision that gave breach of confidence the capacity to protect individual privacy. He led Evans v Health Administration Corp [2019] NSWSC 1781 as lead counsel, Australia's first privacy class action to obtain compensation for class members. He has appeared in McClure v Medibank Limited and in Privacy Commissioner v Telstra (2017) 249 FCR 24.

He is the Australian co-author of two leading international texts, The Law of Privacy and the Media (Tugendhat and Christie, Oxford University Press) and Remedies for Breach of Privacy (Hart Publishing). His article Privacy Class Actions (2020) 94 ALJ 791 is regarded as a significant contribution to the development of class action jurisprudence in privacy law, and he has published widely in journals including the Australian Law Journal, the Privacy Law Bulletin, the Media and Arts Law Review, and the Intellectual Property Forum.

Michael is a Senior Fellow at Melbourne Law School, where he teaches Privacy Law in the Master of Laws program and contributes to teaching in media, IP, and commercial law. He is regularly invited to speak at conferences and legal seminars throughout Australia, and serves on the Advisory Board of the Centre for Media and Communications Law and the Editorial Board of the Privacy Law Bulletin (LexisNexis).

2026-27Best Lawyers: Lawyer of the Year, Privacy and Data Protection
2020Best Lawyers: Lawyer of the Year, Privacy and Data Protection
2019-26Best Lawyers: Leading Lawyer, Privacy and Data Protection (continuous)
2019Doyles: Leading Barrister, Technology, Media & Telecommunications
2018Doyles: Leading Barrister, Intellectual Property
OUPCo-author: The Law of Privacy and the Media (Oxford University Press)
HartCo-author: Remedies for Breach of Privacy (Hart Publishing)
MLSSenior Fellow, Melbourne Law School, LLM Privacy Law
BoardAdvisory Board, Centre for Media and Communications Law
BoardEditorial Board, Privacy Law Bulletin (LexisNexis)
Practice Areas

Where the risk lives.

Michael Rivette is briefed by solicitors, and in appropriate matters engaged directly, across privacy law, data protection, technology law, intellectual property, commercial law, and advocacy. The following sets out the principal areas of practice.

Privacy and Data Protection

Michael has been at the centre of Australian privacy law's development since arguing the foundational issues in Giller v Procopets (2008). He has led Australia's first privacy class action and appeared in Privacy Commissioner v Telstra, one of the most significant Federal Court decisions on personal information under the Privacy Act.

Understanding the regulatory landscape before a breach occurs determines how well it is managed when one happens.

★ Best Lawyers®: Lawyer of the Year, Privacy and Data Protection  ·  2026-2027 and 2020

Advice and appearances include

  • Privacy compliance, advisory opinions
  • OAIC investigations and regulatory proceedings
  • Data breach response, legal strategy and litigation risk
  • Privacy Act reform, regulatory readiness advice
  • Class action strategy and representation
  • Notifiable Data Breach scheme

Privacy Class Actions

Michael Rivette led Evans v Health Administration Corp [2019] NSWSC 1781 as lead counsel, Australia's first privacy class action to obtain compensation for class members, and has appeared in McClure v Medibank Limited.

Michael Rivette initiated Australia's first successful privacy class action. He also wrote the text that defines how they work. That combination is without parallel in Australian practice.

Advice and appearances include

  • Class action risk assessment
  • Defence strategy, data breach class action risk
  • Plaintiff representation in privacy class actions
  • Settlement strategy and court approval
  • Regulatory class action proceedings

Technology Law

Michael advises across technology law, from the contracts that build technology businesses to the regulation that now surrounds them. When those matters turn into litigation, he appears in them. And he has founded and directed technology companies himself, so founders and boards get advice from counsel who has sat on their side of the table.

His 2019 article in the Privacy Law Bulletin on blockchain and the Australian Privacy Principles remains the leading analysis of that incompatibility.

Doyles Guide: Leading Barrister, Technology, Media & Telecommunications  ·  2019

Advice and appearances include

  • Advice to technology companies, founders, and boards
  • Technology contracts, and disputes over failed IT projects
  • Software licensing, SaaS, and cloud agreements
  • AI governance, automated decision-making, and regulatory risk
  • Cybersecurity and critical infrastructure obligations
  • Data licensing, sharing, and API arrangements
  • Digital platforms and marketplaces, regulation and liability
  • Online safety and content regulation
  • Blockchain, digital assets, and smart contracts
  • Digital identity and biometrics
  • Media and communications law

Intellectual Property

Recognised by Doyles Guide as a Leading Barrister in Intellectual Property (2018), Michael has appeared in reported IP cases and practised across the full range of intellectual property rights throughout his career at the Bar.

His practice in IP has run alongside his technology and privacy work for more than 25 years, reflecting the reality that in the digital age, intellectual property and technology law are increasingly inseparable.

Doyles Guide: Leading Barrister, Intellectual Property  ·  2018

Advice and appearances include

  • Copyright, infringement, ownership, licensing
  • Breach of confidence and trade secrets
  • Trade marks, registration, enforcement, disputes
  • IP in technology transactions
  • Passing off and unfair competition
  • Creative works, music, film, digital content, software
  • IP litigation across all Australian jurisdictions

Commercial Law

Michael Rivette's commercial practice covers complex commercial disputes, contract construction, corporations law, and the commercial dimensions of technology, media, and intellectual property.

He acts where a company's proprietary and confidential information has been compromised, by a departing employee, a contractor, or a competitor. These matters are won or lost in the first days, and Michael is experienced in obtaining urgent injunctions and search orders to stop the misuse and preserve the evidence.

In the digital economy, significant commercial disputes turn on data, intellectual property, and regulatory obligations as much as on contract and corporations law. Michael's commercial work is integrated with his specialist practice across all three.

He also brings over 35 years as an owner, director, and board member in media, communications, and technology businesses, so his advice is commercially grounded as well as legally sound.

Commercial disputes at the intersection of technology, IP, and data require counsel who is expert across all three. That integration, between the law and the business reality, has been a feature of my practice throughout my career at the Bar.

Advice and appearances include

  • Complex commercial disputes, contract construction and enforcement
  • Misuse of company confidential information by employees, contractors, or competitors
  • Urgent injunctions, and search orders (Anton Piller orders) to preserve evidence
  • Corporations law, directors duties, shareholder disputes, oppression
  • Equity, breach of fiduciary duty, constructive trusts
  • Misleading and deceptive conduct under the Australian Consumer Law
  • Technology and IP transactions, and the disputes that follow them
  • Commercial litigation, Federal Court and Supreme Courts

Advocacy

Michael Rivette appears in courts and tribunals across all Australian jurisdictions. He has appeared as lead counsel in many of Australia's most significant privacy matters and continues to be briefed for complex litigation, hard cases, and matters requiring senior advocacy experience.

Commercial advocacy remains a substantial part of the practice. Michael appears in commercial trials and appeals, contract and corporations disputes, and urgent interlocutory applications, the hearings where a matter is won or held in the first days. His appearances in Giller v Procopets in the Court of Appeal and Privacy Commissioner v Telstra in the Full Federal Court sit alongside a career of commercial trial work.

Some matters are genuinely hard. They involve novel questions, high stakes, experienced opponents, and outcomes that will matter beyond the individual case. Michael Rivette has spent his career preparing for exactly these matters.

Appearing in

  • Privacy class actions, Federal Court and Supreme Courts
  • Commercial trials and appeals, contract and corporations disputes
  • Urgent interlocutory applications, injunctions and search orders
  • OAIC and regulatory proceedings
  • Technology and IP disputes
  • Breach of confidence matters
  • Media and communications law
  • Serious Invasion of Privacy proceedings
  • All Australian courts and tribunals

Individuals

Privacy is not only a commercial issue. It is a human one, and the law is finally beginning to reflect that. Australia's new Serious Invasion of Privacy tort creates a direct cause of action for individuals whose privacy has been seriously invaded.

Michael Rivette was present at the formation of this area of law, arguing the privacy and breach of confidence issues in Giller v Procopets (2008), and writing articles that anticipated the new tort. He is uniquely positioned to advise individuals on privacy matters and the new cause of action, and to appear in proceedings under it.

In appropriate circumstances individuals may engage Michael directly, without a solicitor. For Individuals sets out how that works under the professional rules.

Advice and appearances include

  • Serious Invasion of Privacy, new statutory tort
  • Breach of confidence, privacy context
  • Unauthorised disclosure of personal information
  • Non-consensual intimate imagery
  • Media privacy intrusions
  • OAIC complaints, representation
  • Data breach, personal impact
Publications

Writing at the forefront
of Australian privacy law.

Michael Rivette has authored and co-authored significant texts and articles in Australian and international privacy law, writing as the practitioner who has appeared in the cases the texts describe.

Books

Oxford University Press, Tugendhat and Christie

The Law of Privacy and the Media

Australian co-author. The leading international text on privacy and media law.

Hart Publishing, Varuhas and Moreham (eds)

Remedies for Breach of Privacy

Co-author, Chapter 7: "Invasion of Privacy and Recovery for Distress" (with Richardson and Neave).

Journal articles and essays

Privacy Law Bulletin, 2019

Blockchain and the Australian Privacy Principles: Never the Twain Shall Meet

(2019) Privacy Law Bulletin 165, with Adam Lodders

Privacy Law Bulletin, 2017

Privacy as a Human Right

(2017) 14(2) Privacy Law Bulletin 22

Privacy Law Bulletin, 2015

The Ultimate Balancing Test: Privacy v Freedom of Expression

(2015) Privacy Law Bulletin 170

Media and Arts Law Review, 2010

Litigating Privacy Cases in the Wake of Giller v Procopets

(2010) 15 Media and Arts Law Review 283

For Law Firms

Michael Rivette is available to be briefed in privacy, technology, intellectual property, and commercial law.

Brief Michael in a privacy, confidential information, or technology matter, and your client gets counsel who has appeared in Australia's most significant cases in these fields, from the foundational breach of confidence decisions to the landmark data breach class actions, and who wrote the texts privacy law relies on. Your firm gets a barrister who works closely with instructing solicitors and responds within one business day.

The commercial practice carries the same weight. Michael appears in commercial trials and appeals, contract and corporations disputes, and urgent applications, including injunctions and search orders where a client's confidential information has been taken. For a commercial dispute with a technology, data, or IP dimension, one counsel covers the whole matter.

Advice and advocacy

From urgent strategic advice to appearances in any Australian court or tribunal, one counsel carries the matter from first call to final orders.

A commercial perspective

Over 35 years as an owner, director, and board member in media and technology businesses. Advice that is grounded in how these businesses actually run.

Specialist opinions

Written advice on complex privacy, technology, IP, and commercial questions, from the author of the leading Australian texts in the field.

CLE and training

Presentations to your firm's solicitors on developments in privacy, technology, and IP law, delivered by the barrister who has appeared in the cases under discussion.

For Individuals

Engaging Michael
directly.

Privacy is personal. Australia's new Serious Invasion of Privacy tort gives individuals a direct cause of action for the first time, and Michael acts for people whose privacy has been invaded, whose information has been exposed in a data breach, or who face media intrusion.

Barristers usually act on the instructions of a solicitor. The professional rules also allow a barrister to be engaged directly by a client, without a solicitor, in appropriate matters. Whether yours is one of them depends on what the matter needs, and Michael will tell you at the outset.

What Michael can do on a direct brief

The rules define a barrister's work. Appearing as an advocate, giving legal advice, negotiating with the other side, representing you in a mediation, and preparing or advising on documents for your matter. Legal Profession Uniform Conduct (Barristers) Rules 2015, r 11.

What a barrister cannot do

A barrister cannot do the work of a solicitor's office. Commencing and serving court proceedings, conducting general correspondence, and holding or handling money for a client are outside a barrister's work under r 13. Where a matter requires them, a solicitor is needed.

Before a direct brief is accepted

The rules require that you be fully informed first. Michael must explain in writing what he can and cannot do, and that circumstances may require you to retain a solicitor, possibly at short notice, and you sign an acknowledgement before the engagement begins. Rule 22.

If a solicitor is needed

Some matters need a solicitor from the start, and others come to need one as they develop. If yours does, Michael will say so plainly and can continue as counsel working alongside your solicitor.

To find out where your matter stands, describe it through the enquiry form. Michael will advise whether he can act directly or whether a solicitor should be appointed.

Data breach response

When the breach happens,
the first hours decide the rest.

When a matter involves serious privacy or data issues, the response must cover the immediate obligations, the regulatory landscape, and the litigation risk that follows. Michael is briefed across data breach response, regulatory proceedings, and the litigation that comes after.

Data Breach Response: Legal Direction

From the first hour, Michael provides the legal direction a breach response needs, establishing privilege over the investigation, advising on notification obligations, and ensuring every step taken in the critical early period is defensible if the matter reaches a court or regulator.

Cybersecurity and Incident Response

Working with instructing solicitors, Michael can assist in coordinating specialist cybersecurity and data incident response teams, ensuring the technical investigation is conducted under legal direction from the outset. Privilege is preserved, and technical findings are framed for regulatory and litigation purposes from the first moment.

Regulatory Proceedings and OAIC Strategy

Michael advises and appears in OAIC investigations and regulatory proceedings, with 25 years of insight into how privacy regulators investigate and determine matters.

Class Action Exposure Assessment

Following a data breach, class action risk must be assessed early. Michael assesses that exposure at the earliest stage, as counsel who has acted in Australia's first successful privacy class action and in McClure v Medibank Limited.

A data breach managed correctly in the first 72 hours is a recoverable event. Managed incorrectly, it becomes a class action, a regulatory determination, and a reputational crisis. The difference is having the right barrister briefed at the first moment.

Insights

Commentary from inside
the law's development.

Michael Rivette writes on the privacy and technology law developments that matter, with the perspective of a practitioner who has been present at the law's formation, and continues to appear in its most significant cases.

AI, privacy and confidentiality  ·  August 2026  ·  Read the article

The prompt is a disclosure. AI, privacy, and other people's secrets

What you type into an AI tool does not stay with you, and the sharpest risks arise when the information is about someone else. Where the information actually goes, the obligations it triggers, and how to build the closed system that answers them.

AML/CTF and privacy  ·  August 2026  ·  Read the article

Thousands of small businesses have just been brought into the Privacy Act, and many do not know it

The Tranche 2 AML/CTF reforms have brought real estate agents, conveyancers, accountants, lawyers, and barristers within the Privacy Act for the first time, regardless of turnover. What is caught, what is regulated, and the two traps to avoid.

The Serious Invasion of Privacy tort  ·  Individuals' new rights  ·  August 2026  ·  Read the article

For the first time, Australians can sue for invasion of privacy

The new statutory tort hands individuals a power they have never had, against any person or entity, small businesses included. What it delivers, where it fails, and the door it leaves open for the common law.

Privacy as a human right  ·  August 2026  ·  Read the article

Privacy is a human right. Everything else follows from that

Australia helped write the right into international law, with an Australian presiding over the adoption of the Universal Declaration. What the human rights foundation means for compliance, breach, and the development of the law.

Privacy class actions, data risk  ·  August 2026  ·  Read the article

Privacy class actions changed the economics of data risk, and health information is the sharpest edge

Every business holding personal, confidential, or sensitive information now faces litigation risk as well as regulatory risk. The practices that create the exposure, and the two assumptions that will not hold.

Blockchain and privacy  ·  August 2026  ·  Read the article

Blockchain and the Privacy Act: the incompatibility has not gone away

An immutable, distributed ledger cannot correct, destroy, or contain personal information the way the APPs require. The issues for companies using blockchain, what to do with an access and correction application, and the uses most exposed.

Privacy Act reform  ·  August 2026  ·  Read the article

The Privacy Act reforms are not finished, and the small business exemption is living on borrowed time

The government has agreed in principle to abolish the small business exemption and to introduce the controller and processor architecture the GDPR is built on. What is coming, and why preparing now is best practice in any event.

← All insights Insights  ·  AML/CTF and privacy  ·  August 2026

Thousands of small businesses have just been brought into the Privacy Act, and many do not know it.

Ask a suburban real estate agent, a two-partner accounting practice, a jeweller, a small law firm, or a barrister in chambers whether the Privacy Act applies to their business, and until this year the answer was usually no. The small-business exemption, for businesses with an annual turnover of $3 million or less, has kept most Australian small businesses, and most of the legal profession's smaller practices with them, outside the Privacy Act 1988 (Cth) since its commencement.

Since 1 July 2026, that answer has changed for a large class of them, and by an unexpected route. The second tranche of the anti-money laundering and counter-terrorism financing reforms extends the AML/CTF regime to real estate professionals, conveyancers, lawyers, accountants, trust and company service providers, and dealers in precious metals and stones. A business that provides a "designated service" under that regime becomes a "reporting entity". Section 6E(1A) of the Privacy Act then deems it an "organisation", regulated by the Australian Privacy Principles in relation to its AML/CTF activities, and turnover is irrelevant. Privacy compliance arrives not as a considered choice but as the by-product of an entirely different regulatory regime.

Who is caught

The gateway is the designated service. The agent selling a house provides one. So does the conveyancer on an ordinary settlement, the accountant structuring a family trust or company, the service provider supplying a registered office or nominee director, the dealer in a large precious metals transaction, and the solicitor acting on a property or business sale. Advice that does not advance a transaction, and representation in a court or tribunal, generally are not designated services.

There is no de minimis exemption. A single designated service, one settlement, one trust establishment, one conveyance, is enough to make the business a reporting entity. For the legal profession the line runs through the middle of ordinary practice. A solicitor's firm that does any conveyancing cannot quarantine its trust account from the regime. A barrister briefed by a solicitor provides no designated service, and the obligations sit with the instructing firm. The direct brief is where care is needed. A brief confined to advocacy and advice, conferences, opinions, pleadings and appearances, stays outside the regime. A brief that turns to transactional work, advancing a sale, a financing, or a corporate or trust structure, may not, and the barrister who crosses that line becomes an APP entity for the records the brief generates.

What is actually regulated

For a business under the $3 million threshold, only the personal information handled for or in connection with the AML/CTF Act is regulated. That is the material customer due diligence generates. Identity documents and verification records, beneficial ownership of corporate and trust clients, and screening records, which may include sensitive information where checks for politically exposed persons touch political associations. The business's wider files remain outside the Act, but the regulated core is exactly the information a criminal most wants and a client most fears losing.

The obligations are concrete. A clearly expressed privacy policy confined to what it actually covers. Collection notices at or before collection, most simply built into the engagement or agency agreement. Collection limited to what is reasonably necessary. Security over what is kept, and destruction when the seven-year AML/CTF retention rules no longer require it. Access and correction procedures. And a plan for the Notifiable Data Breaches scheme, under which a suspected eligible breach must be assessed within 30 days.

Two traps

The reformed tipping-off offence reaches every reporting entity, not just lawyers. Records bearing on a suspicious matter report must be kept out of ordinary files, and no response to a client, including a privacy access request, may reveal that a report exists.

The second trap is overreach. A small business that publishes a general privacy policy, without confining it to the information the Act actually regulates, may be held to the wider promises it has made, under the Australian Consumer Law or in contract. Represent only what the policy covers, and no more.

No false comfort outside the regime

A business that stays outside the AML/CTF net takes no shelter from the statutory tort of serious invasion of privacy, in force since 10 June 2025 and not subject to the small-business exemption. For any business holding identity documents and financial details, poor data handling is now a litigation risk as well as a regulatory one. And professionals who have always kept client confidences are not, for that reason, privacy compliant. Confidentiality is about non-disclosure. The Privacy Act governs the whole life of the information, from collection to destruction.

The obligations commenced on 1 July 2026. A business that has not yet acted should treat the work as overdue rather than pending.

A fuller version of this article, with references, will be published in the Privacy Law Bulletin.

Michael accepts briefs to advise on the implications of the new regime for legal firms, businesses, and individuals, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.

← All insights Insights  ·  Privacy class actions, data risk  ·  August 2026

Privacy class actions changed the economics of data risk, and health information is the sharpest edge.

For most of the Privacy Act's life, a business that mishandled personal information faced an aggrieved individual with no economic path to a courtroom. Most privacy breaches cause distress, embarrassment, and humiliation rather than quantifiable financial loss, and a claim of that size could never carry the cost of litigation. The complaint went to a regulator, or nowhere.

The class action changed that arithmetic. By collecting thousands of individually small claims into a single proceeding, it created a vehicle that can support the cost of litigation, and modern data breaches suit it, because a breach harms thousands of people in essentially identical ways. In Evans v Health Administration Corp [2019] NSWSC 1781, Australia's first privacy class action to obtain compensation for class members, the information was contained in workers compensation files, including staff medical records, sold by a contractor. Michael Rivette appeared as lead counsel.

Why health information multiplies the risk

Health information sits at the top of the private information hierarchy. The courts regard information about a person's health as among the categories most easily identifiable as private, and since Giller v Procopets (2008) 24 VR 1 compensation has been available for the distress, embarrassment, and humiliation a disclosure causes, without proof of psychiatric injury or economic loss. In the reported cases, compensation for distress alone has reached the tens of thousands of dollars per person. That is the multiplier. In a breach of health, financial, or genuinely confidential information, nearly every affected individual has a compensable claim, and the total is the per-person figure multiplied by everyone the breach touched.

The practices that create the exposure

Certain practices are no longer acceptable in a holder of personal, sensitive, or confidential information, and each of them converts directly into pleadable allegations when a breach occurs.

Access beyond need. Personal, confidential, and sensitive information should be available only to the people who need it to do their jobs. Giving staff or contractors access to records they do not require, health, financial, or otherwise, is not just poor security. It is arguably itself a use or disclosure of the information, in breach of confidence, contract, and the reasonable expectations the Privacy Act protects.

Blindness to exfiltration. A holder that cannot tell whether information has left its systems has a security posture that will not withstand scrutiny, because the adequacy of security is judged against the nature and sensitivity of the information held.

Unguarded credentials. Compromised staff credentials are a standard route into a network. Multi-factor authentication, threat awareness training, and monitoring for compromised credentials are now baseline expectations, not sophistication.

Data kept past its purpose. Information about former customers that should have been destroyed or de-identified is pure liability. It cannot earn anything, and in a breach it swells the affected class.

Promises the systems cannot keep. Every assurance in a privacy policy or public report about security practices, staff training, or data handling is potential contractual and Australian Consumer Law material, judged at the time it was made. A business should promise what its systems actually do.

Slow notification. Delay in telling affected individuals compounds the harm and the claim. The Notifiable Data Breaches scheme sets the clock, and the common law duties do not wait for it.

Two assumptions that will not hold

The first is that the criminal breaks the chain. A business should not assume that the intervention of a hacker answers the claim. Australian courts have allowed negligence claims arising from the criminal acts of third parties, and where a business has promised to keep information secure, the argument that its own failings caused the loss is squarely available. The second is that a clean history is protection. A business that has had earlier incidents is on notice, and prior breaches inform foreseeability in everything that follows.

What follows for boards and management

The information a business holds should be priced as a liability as well as an asset. Collect less. Confine access to need. Secure what is kept, against insiders as well as intruders. Destroy what is no longer required. Notify promptly. And make sure the privacy policy describes the systems that exist, not the systems the business wishes it had. Michael argued in Privacy Class Actions (2020) 94 ALJ 791 that it may be only through class actions that businesses put a proper price on the protection of the personal, private or confidential information they hold. That argument is now the operating environment. The businesses that fare best will be the ones that acted before anyone tested it.

Michael Rivette appeared as lead counsel in Australia's first successful privacy class action and is the author of Privacy Class Actions (2020) 94 ALJ 791. He accepts briefs to advise businesses on data risk, breach response, and class action exposure, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.

← All insights Insights  ·  Blockchain and privacy  ·  August 2026

Blockchain and the Privacy Act: the incompatibility has not gone away.

Blockchain solves the problem of trust in a trustless environment by making its record permanent, verified, and copied to every participant. The Privacy Act assumes the opposite. A record keeper who controls the information it holds, can correct it, can destroy it, and answers for where it goes. As Michael Rivette and Adam Lodders argued in Blockchain and the Australian Privacy Principles: Never the Twain Shall Meet (2019) Privacy Law Bulletin 165, the two designs are in conflict at the level of architecture, and that conflict has not been resolved.

The issues for any company using blockchain

Immutability against correction and destruction. The APPs give individuals the right to have their personal information corrected, and require destruction or de-identification once the information is no longer needed. A blockchain's record cannot be rewritten without consensus across the network, and deletion runs against the structure itself.

Distribution against control. Every node holds the whole record, and a node can sit anywhere with an internet connection. On a public chain, each new participant receives a copy of everything, which may itself be a disclosure to an unknown third party, and the cross-border rules in APP 8 are engaged with no practical way of honouring them.

Loss of control against the breach regime. Each movement of data outside the record keeper's control has the capacity to become a notifiable data breach, and the record keeper cannot control the other nodes.

The reasonableness trap. The APPs qualify these duties by what is reasonable in the circumstances. A company that chose an architecture incapable of correction or destruction should expect the choice itself to be scrutinised, against the alternatives it passed over. The point is unsettled, which is not comfort.

If an access and correction application arrives

The application cannot be ignored and cannot be charged for. The entity must respond within a reasonable period and take reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading. Where the chain cannot be rewritten, correct the off-chain systems that feed it and record the correction there. If correction is refused, APP 13 requires written notice of the reasons and the complaint mechanisms, and the individual may require a statement to be associated with the information, made apparent to anyone who uses it. On request, other entities to whom the information was disclosed must be told of the correction. The only reliable answer is architectural. Keep personal information off the chain, store references to it rather than the information itself, and keep the substance in systems that can be corrected and destroyed.

Reform has not softened the problem

The 2024 privacy amendments left the correction, destruction, and cross-border principles untouched, and the proposed second tranche of reform contemplates a right to erasure, which an immutable ledger can honour even less than the current destruction duty. The digital assets legislation now before Parliament licenses platforms and custody. It says nothing about privacy, and licensing a platform does not make its records correctable.

The uses most susceptible

Writing personal information to a public chain is the highest exposure, and the risk rises with the sensitivity of the information. Identity and credential systems, customer records, and anything touching health information sit at the top. Permissioned networks with known participants reduce the exposure but do not remove it, because the copies still distribute and the correction problem remains.

Michael Rivette is the co-author of Blockchain and the Australian Privacy Principles: Never the Twain Shall Meet (2019) Privacy Law Bulletin 165, the leading analysis of the incompatibility. He accepts briefs to advise on blockchain, data, and privacy compliance, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.

← All insights Insights  ·  The Serious Invasion of Privacy tort  ·  Individuals' new rights  ·  August 2026

For the first time, Australians can sue for invasion of privacy. Here is what the new tort delivers, and where it fails.

On 10 June 2025, something Australian law had refused individuals for more than a century arrived. A cause of action for serious invasion of privacy, in Schedule 2 of the Privacy Act, that a person can take to court in their own name. No complaint to a regulator. No waiting for a commissioner to investigate. A writ, a courtroom, and a judgment.

The new power

The tort reaches the two ways privacy is actually invaded. Intrusion upon seclusion, which covers physically entering private space and watching, listening to, or recording private activities. And misuse of information relating to a person, where the truth of the information is no defence. The plaintiff must show a reasonable expectation of privacy, an invasion that was intentional or reckless and serious, and that their privacy outweighed any countervailing public interest. Damage need not be proved. The invasion itself is the wrong.

The remedies have teeth. Injunctions to stop a threatened or continuing invasion. Damages, including for emotional distress, with exemplary damages in exceptional cases. And a set of orders the regulatory regime never offered an individual, an account of profits, an apology, a correction, and the destruction or delivery up of the offending material.

Two features deserve emphasis. First, anyone can be sued. The tort is not confined to government agencies or large companies. A small business, an employer, a neighbour, a former partner, all are within reach, because the Privacy Act's $3 million small-business exemption does not apply to it. Second, the tort sits in the Privacy Act but operates outside its constraints. It does not require the defendant to be an APP entity, it is not confined to "personal information" as the Act defines it, and it protects against conduct, the watching and the recording, not merely the mishandling of data. Parliament placed a tort inside a regulatory statute and cut it free of the regulation.

Where it fails

The exemptions are categorical, and that is the design flaw. The journalist exemption is arguably the worst of them. Journalists, their employers, and their assistants are exempt for journalistic material, and the exemption holds even where the journalist has breached their own professional code. The class of defendant most likely to invade privacy is the class the tort cannot touch, and no balancing of interests ever occurs, because an exemption is not a defence, it is a locked door. Law enforcement bodies, intelligence agencies, and public authorities acting in good faith are also carved out, and no action lies against a defendant under 18.

The limits go further. Only intentional or reckless invasions are caught, so the merely negligent invasion of privacy, however damaging, falls outside the tort. The invasion must be serious. The limitation period is severe, in general one year from awareness or three years from the act, against six years for most torts. Damages are capped at the defamation cap. And the defamation defences of absolute privilege, public documents, and fair report are imported wholesale, giving defendants a second run at a public interest argument the tort's own elements already weigh.

The door the statute leaves open

Schedule 2 says expressly that it does not exclude the concurrent operation of other law, and the High Court in Lenah Game Meats and again in Smethurst has left open the recognition of a privacy tort at common law. Some trial courts have already gone further. In Grosse v Purvis in the District Court of Queensland, and in Doe v Australian Broadcasting Corporation and Lynn v Romy in the County Court of Victoria, damages were awarded for invasion of privacy at common law, although these are decisions of lower courts and no superior court has yet recognised the tort. A common law tort would carry none of the statutory exemptions. No journalist carve-out, no immunity for the under-18 defendant, no imported defamation defences, just the balancing of privacy against the public interest on the facts of each case, which is how the United Kingdom and New Zealand already do it.

The statute began the work. It has handed individuals a real power, and its failures map the ground the common law should now claim. What remains is the right case, properly argued.

Michael Rivette argued the privacy issues in Giller v Procopets (2008) 24 VR 1, the foundation of Australian privacy litigation, and has appeared in and written on this field for more than twenty-five years. He acts for individuals in serious invasion of privacy matters, on brief from solicitors and, in appropriate cases, on direct engagement. To find out where you stand, make an enquiry through the contact page.

← All insights Insights  ·  Privacy Act reform  ·  August 2026

The Privacy Act reforms are not finished, and the small business exemption is living on borrowed time.

The 2024 amendments to the Privacy Act delivered the statutory tort, new penalty tiers, automated decision-making transparency, and a criminal doxxing offence. They were the first tranche, and the easier one. The structural reforms recommended by the Privacy Act Review remain on the government's table, agreed in principle but not yet legislated, and two of them will redraw who Australian privacy law applies to.

The exemption's days are numbered

The small business exemption has kept businesses with an annual turnover of $3 million or less outside the Privacy Act since the Act was extended to the private sector. The Privacy Act Review recommended its abolition, and the government has agreed in principle, subject to an impact analysis and consultation on how obligations should be tailored and supported for small business. The principle behind the recommendation is hard to argue with. A person's information deserves the same protection whether it is held by a company with a $3 million turnover or a $300 million one, and the GDPR, the reference point for data protection worldwide, contains no equivalent carve-out. Australia's exemption is an outlier, and outliers in privacy law do not last.

Controllers and processors, the architecture that is coming

The Review also recommended introducing the concepts of controllers and processors, and the government has again agreed in principle. The distinction is the organising structure of the GDPR. The controller decides why and how personal information is handled, and carries the primary obligations. The processor handles information on the controller's instructions, and carries obligations scaled to that role. The current Act draws no such line, treating every APP entity alike regardless of its actual role, which fits poorly with a world of outsourcing, cloud services, and data handled by chains of providers. Australian businesses dealing with international counterparties already sign controller and processor clauses in their contracts. The Act has simply not caught up with the way information is actually handled.

Prepare now, because the direction is set

The timing of the second tranche is uncertain. The direction is not. The government has committed itself in principle to both reforms, and when they arrive, organisations, sole practitioners, and individuals in business who have never been within the Privacy Act will be regulated by it. Many small businesses have already had a first taste, because the AML/CTF reforms brought reporting entities partly within the Act from 1 July 2026, and the statutory tort of serious invasion of privacy already applies to everyone, regardless of turnover.

Preparation is cheaper now than under a compliance deadline, and the steps are best practice in any event. Collect only what is needed. Secure what is kept, and destroy what is not. Know what information the business holds and where it sits. Publish a privacy policy that describes the systems that exist. Have a breach plan. A business that does these things now will meet the reforms as a formality. A business that waits will meet them as a project, with a regulator watching.

Michael Rivette advises organisations, small businesses, and practitioners on privacy compliance and on preparing for the coming reforms, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.

← All insights Insights  ·  Privacy as a human right  ·  August 2026

Privacy is a human right. Everything else follows from that.

In 1890, Warren and Brandeis identified privacy as a right of the individual, the right of a person who has remained private to keep their life their own unless some overriding public interest requires otherwise. Within sixty years that idea had become international law, and Australia did not merely sign up to it. Australia helped write it.

Australia was one of only eight nations involved in drafting the Universal Declaration of Human Rights, and the man at the centre of that work was an Australian. Dr H V Evatt had been a Justice of the High Court of Australia and was the Commonwealth's Attorney-General and Minister for External Affairs when he led Australia's delegation to the United Nations. He became the third President of the General Assembly, and it was under his presidency, in December 1948, that the Universal Declaration was adopted. Article 12 declares that no one shall be subjected to arbitrary interference with their privacy, family, home, or correspondence. Australia then became a founding signatory to the International Covenant on Civil and Political Rights, whose Article 17 carries the same guarantee into binding treaty law. On privacy, Australia was not a follower. It stood at the front of the room when the right was created.

What the right protects is not information for its own sake. It is human autonomy and dignity, the ability of a person to control what is known of their private life and to hold the esteem and respect of others, as the House of Lords put it in Campbell v MGN Ltd. A data breach, a surreptitious recording, an intrusive publication, each is at its core the same wrong, an invasion of the person, not merely a mishandling of records.

This is not abstract philosophy. It is built into Australian law. The Privacy Act's preamble invokes the Covenant, and its stated objects include implementing Australia's international obligations on privacy. The Victorian Charter of Human Rights embodies Article 17 directly. And since Mabo, the High Court has treated international human rights law as a legitimate and important influence on the development of the common law.

The practical consequences are real, and businesses overlook them at their cost. Privacy legislation is remedial, enacted to confer a benefit on individuals, and the courts construe such legislation to give the fullest relief its language allows, with exceptions read narrowly. A business that runs its privacy compliance from its own convenience has the analysis backwards. The measure is the individual whose information is held, which is why privacy by design, building protection in at the start rather than bolting it on, is both the principled approach and the one most likely to limit liability when something goes wrong.

For decades the human rights framing was treated as rhetoric while calls for real remedies went unanswered. No longer. The United Kingdom built a tort of misuse of private information on exactly this foundation, concerned with intrusion and not merely secrets, and surviving even publication to the world. And in 2025 Australia's statutory tort of serious invasion of privacy arrived, with an objects clause that expressly implements the Covenant. The commitments Australia helped write in 1948 are finally acquiring teeth in our own courts. The statutory tort carries major shortcomings, however, and does not cover the field. Its exemptions and limits, and the ground they leave open for the common law, are examined in a separate insight on this page. The direction of travel, though, is no longer in doubt.

So start every privacy question, whether compliance, breach, or litigation, where the law itself starts. Privacy is a human right, grounded in the autonomy and dignity of the person. Seen that way, the obligations fall into place, the exceptions stay narrow, and the cost of protection is understood for what it is, the price of respecting the people whose lives the information describes.

This commentary is based on Michael Rivette's article Privacy as a Human Right (2017) 14(2) Privacy Law Bulletin 22, updated for the law as it now stands. Michael advises and appears in privacy matters across this field, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.

← All insights Insights  ·  AI, privacy and confidentiality  ·  August 2026

The prompt is a disclosure. AI, privacy, and other people's secrets.

Every day, people paste things into AI tools. A client list, a medical report, a complaint about a named colleague, a set of accounts, a draft agreement. The tool answers in seconds and the moment passes. The law sees that moment differently. The prompt may be a disclosure, and what was disclosed may not have been yours to disclose.

Where the information actually goes

On most commercial AI tools, a query passes through the provider's systems. Providers commonly retain logs of prompts and outputs for a period, often around 30 days, to monitor misuse, and provider staff can review flagged queries. Behind the provider sits a chain of other companies, cloud hosts, identity services, monitoring services, each of which may handle the data. Documents uploaded for the tool to search are stored again in the tool's own database, a second copy with its own retention and deletion behaviour. And a provider subject to foreign law can be compelled by foreign legal process to produce what it holds, wherever the data is stored. Keeping data in Australia does not, by itself, answer that. None of this means AI cannot be used safely. It means the assumption that what you type stays with you is wrong, and the legal analysis starts there.

When the information is about someone else

This is where the risk sharpens. Handing another person's personal, sensitive, or health information to an AI provider may itself be a use or disclosure that the privacy laws regulate. Confidential information received for a purpose is bound to that purpose, and equity's rule is that using it for something else can be a breach of confidence even if it never becomes public. The tool's output carries its own consequences. When an AI draws a conclusion about an identified person, a likely diagnosis, a credibility assessment, a pattern of conduct, that conclusion is new personal information about that person, created by you and held by you, with the obligations that follow. If the conclusion is adverse, untested, and shared, defamation enters the frame. The person it concerns usually knows nothing about any of it.

The quiet risk inside the organisation

An AI tool connected to an organisation's documents can surface material to a staff member who would never have found it by ordinary means, straight through the access controls and information barriers the organisation thought it had. And a model trained or fine-tuned on an organisation's own material can, in some circumstances, be induced to give that material back. Access controls outside the tool must be mirrored inside it, and the decision to train a model on your own files deserves far more caution than it usually gets.

A closed system is built, not bought

The usual answer to these risks is a "secure, closed system". Treat that phrase with care, because no commercial AI tool is a closed system off the shelf. A closed system is an outcome you construct, partly in the contract and partly in how the tool is set up. On the contract side, the minimums are a prohibition on the provider training any model on your data, log retention measured in days with review confined to defined safety triggers, a named list of every company behind the provider with notice and a right to object before it changes, data, including the system's operational records, kept in Australia, an obligation to resist foreign legal process so far as the law allows and to give notice of it, deletion of stored material when the work ends, and audit rights.

On the configuration side, the tool must mirror the organisation's own walls. Each matter or project separated from every other, access confined to the people working on it, no cross-project operation unless deliberately enabled, and outputs about identified people treated as records the organisation now holds. For the most sensitive information there is a stronger answer again, running the model on infrastructure you control, which removes the provider-side exposures, the logs, the supply chain, the foreign process, at their source. And where de-identified data is used, test it the way an intruder would, because removing names is not de-identification, and an AI tool with access to public information is itself a re-identification engine.

The professional overlay

Professionals carry all of this plus their own duties. For lawyers, the duty of confidentiality under r 9 of the Legal Profession Uniform Law Australian Solicitors' Conduct Rules 2015 and r 114 of the Legal Profession Uniform Conduct (Barristers) Rules 2015 attaches to what goes into the tool, and the duties of competence and candour reach the output. The courts have added a layer of their own. Practice Note SC Gen 25 of the Supreme Court of Victoria, which commenced on 14 May 2026, requires content produced using AI in court documents to be verified with meaningful human control, and empowers the Court to require a party to identify the portions of a document produced using AI and to explain how the output was verified. Australian practitioners have already faced costs orders and disciplinary consequences over unverified AI output. Advisers in other fields should assume their own professional obligations reach their AI use in the same way.

What to do before you paste

Know which tool you are using, and on what terms, because consumer products and properly configured enterprise arrangements are different worlds. Do not put another person's information into a tool unless you are entitled to use it for that purpose. Send the minimum the task needs. If the tool matters to your business, get the contract right, no training on your data, tight retention, a known list of the companies behind the provider, and honesty about what foreign process can reach. Treat AI conclusions about people as records you now hold. And verify output before you rely on it. The technology is worth using. It is simply not a private conversation, and the law will not treat it as one.

Michael Rivette advises organisations, agencies, and practitioners on the privacy, confidentiality, and data risks of AI adoption, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.

Contact

Contact.
Chancery Chambers, Melbourne.

Michael Rivette is available to be briefed by instructing solicitors for advisory, regulatory, and advocacy matters across all areas of practice.

In certain matters he may be engaged directly, under the Direct Access provisions of the Legal Profession Uniform Conduct (Barristers) Rules 2015.

Individuals with privacy matters are welcome to enquire using this form. Michael will advise whether he can act directly or whether a solicitor should be appointed.

Location

Chancery Chambers, Melbourne

Phone

+61 3 8600 1717

Mobile

0418 375 566

Fax

+61 3 8600 1725

Jurisdictions

All Australian courts and tribunals

Response

All enquiries responded to within one business day. Urgent matters as priority.

Clerk, Young's List

Michael Rivette is a member of Young's List. Solicitors wishing to brief Michael may contact his clerk directly.

Clerk

Tammy Young, Young's List

Location

Suite 8B, Level 2, 221 Queen Street, Melbourne Victoria 3000

Postal

GPO Box 4770, Melbourne Victoria 3001

Telephone

+61 3 9225 6777

After hours

Tammy Young +61 414 523 515
Tara O'Connor +61 466 638 081
Oscar Morrison +61 403 603 463

Michael Rivette is a barrister practising at the Victorian Bar. He does not act as a solicitor, and will advise when a solicitor is required. Most litigation and court appearances require an instructing solicitor.

Privacy collection notice. Personal information submitted through this form is collected by Michael Rivette to respond to your enquiry and to assess whether he can act. It is treated in confidence, is used for no other purpose, and is handled in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Submissions are processed and stored by Formspree on Michael's behalf. Sending an enquiry does not create a barrister and client relationship. Please describe your matter briefly and do not include confidential detail beyond what is needed to explain it.

Thank you for your enquiry.

Michael Rivette will respond personally within one business day.