Michael Rivette appeared in and initiated the cases that defined Australian privacy law, and wrote its leading texts. Solicitors brief him for the matters where privacy, data, and technology carry real risk.
In appropriate matters, corporations and individuals engage him directly. Where a solicitor is needed, he will say so at the outset.
Leading Lawyer, Privacy and Data Protection
Best Lawyers
2019-2026 (continuous)
Leading Barrister, Technology, Media & Telecommunications
Doyles Guide
2019
Leading Barrister, Intellectual Property
Doyles Guide
2018
Senior Fellow, Privacy Law, Master of Laws
Melbourne Law School
Current
Co-author, The Law of Privacy and the Media
Oxford University Press
Leading international text
Privacy Class Actions (2020) 94 ALJ 791
Australian Law Journal
Seminal article
Co-author, Remedies for Breach of Privacy
Hart Publishing
Leading international text
Editorial Board, Privacy Law Bulletin
LexisNexis
Current
These are the cases that established privacy litigation in Australia. Michael initiated, structured, or appeared as counsel in each of them.
Australia's first privacy class action to obtain compensation for class members, the template for all subsequent mass privacy breach litigation.
One of Australia's most significant data breach class actions, arising from the breach affecting approximately 9.7 million customers.
The foundational Victorian Court of Appeal decision that gave breach of confidence the capacity to protect individual privacy in Australia.
Significant Full Federal Court decision on the scope of personal information under the Privacy Act, with broad application across Australian industry.
Commercial disputes in the digital economy turn on data, IP, and regulation as much as on contract. Michael has practised across all of them at the Bar, after 35 years as an owner, director, and board member in media and technology businesses.
Most matters come to Michael on a brief from an instructing solicitor. The professional rules also allow direct engagement where the matter suits it.
Michael Rivette continues to appear in courts and tribunals across all Australian jurisdictions in privacy, technology, and intellectual property matters.
Michael Rivette is one of Australia's most recognised barristers in privacy and data protection. Over more than 25 years at the Victorian Bar, he has appeared in and helped initiate the cases that defined Australian privacy law, alongside a broad technology, intellectual property, and commercial practice.
He regularly advises corporations, government agencies, and regulators on privacy compliance, cybersecurity risk, and data breach response and litigation. He also represents a wide range of individuals, including international public figures and celebrities, in complex and sensitive matters.
He appeared as counsel in Giller v Procopets (2008) 24 VR 1, the foundational Victorian Court of Appeal decision that gave breach of confidence the capacity to protect individual privacy. He led Evans v Health Administration Corp [2019] NSWSC 1781 as lead counsel, Australia's first privacy class action to obtain compensation for class members. He has appeared in McClure v Medibank Limited and in Privacy Commissioner v Telstra (2017) 249 FCR 24.
He is the Australian co-author of two leading international texts, The Law of Privacy and the Media (Tugendhat and Christie, Oxford University Press) and Remedies for Breach of Privacy (Hart Publishing). His article Privacy Class Actions (2020) 94 ALJ 791 is regarded as a significant contribution to the development of class action jurisprudence in privacy law, and he has published widely in journals including the Australian Law Journal, the Privacy Law Bulletin, the Media and Arts Law Review, and the Intellectual Property Forum.
Michael is a Senior Fellow at Melbourne Law School, where he teaches Privacy Law in the Master of Laws program and contributes to teaching in media, IP, and commercial law. He is regularly invited to speak at conferences and legal seminars throughout Australia, and serves on the Advisory Board of the Centre for Media and Communications Law and the Editorial Board of the Privacy Law Bulletin (LexisNexis).
Michael Rivette is briefed by solicitors, and in appropriate matters engaged directly, across privacy law, data protection, technology law, intellectual property, commercial law, and advocacy. The following sets out the principal areas of practice.
Michael has been at the centre of Australian privacy law's development since arguing the foundational issues in Giller v Procopets (2008). He has led Australia's first privacy class action and appeared in Privacy Commissioner v Telstra, one of the most significant Federal Court decisions on personal information under the Privacy Act.
Understanding the regulatory landscape before a breach occurs determines how well it is managed when one happens.
Michael Rivette led Evans v Health Administration Corp [2019] NSWSC 1781 as lead counsel, Australia's first privacy class action to obtain compensation for class members, and has appeared in McClure v Medibank Limited.
Michael Rivette initiated Australia's first successful privacy class action. He also wrote the text that defines how they work. That combination is without parallel in Australian practice.
Michael advises across technology law, from the contracts that build technology businesses to the regulation that now surrounds them. When those matters turn into litigation, he appears in them. And he has founded and directed technology companies himself, so founders and boards get advice from counsel who has sat on their side of the table.
His 2019 article in the Privacy Law Bulletin on blockchain and the Australian Privacy Principles remains the leading analysis of that incompatibility.
Recognised by Doyles Guide as a Leading Barrister in Intellectual Property (2018), Michael has appeared in reported IP cases and practised across the full range of intellectual property rights throughout his career at the Bar.
His practice in IP has run alongside his technology and privacy work for more than 25 years, reflecting the reality that in the digital age, intellectual property and technology law are increasingly inseparable.
Michael Rivette's commercial practice covers complex commercial disputes, contract construction, corporations law, and the commercial dimensions of technology, media, and intellectual property.
He acts where a company's proprietary and confidential information has been compromised, by a departing employee, a contractor, or a competitor. These matters are won or lost in the first days, and Michael is experienced in obtaining urgent injunctions and search orders to stop the misuse and preserve the evidence.
In the digital economy, significant commercial disputes turn on data, intellectual property, and regulatory obligations as much as on contract and corporations law. Michael's commercial work is integrated with his specialist practice across all three.
He also brings over 35 years as an owner, director, and board member in media, communications, and technology businesses, so his advice is commercially grounded as well as legally sound.
Commercial disputes at the intersection of technology, IP, and data require counsel who is expert across all three. That integration, between the law and the business reality, has been a feature of my practice throughout my career at the Bar.
Michael Rivette appears in courts and tribunals across all Australian jurisdictions. He has appeared as lead counsel in many of Australia's most significant privacy matters and continues to be briefed for complex litigation, hard cases, and matters requiring senior advocacy experience.
Commercial advocacy remains a substantial part of the practice. Michael appears in commercial trials and appeals, contract and corporations disputes, and urgent interlocutory applications, the hearings where a matter is won or held in the first days. His appearances in Giller v Procopets in the Court of Appeal and Privacy Commissioner v Telstra in the Full Federal Court sit alongside a career of commercial trial work.
Some matters are genuinely hard. They involve novel questions, high stakes, experienced opponents, and outcomes that will matter beyond the individual case. Michael Rivette has spent his career preparing for exactly these matters.
Privacy is not only a commercial issue. It is a human one, and the law is finally beginning to reflect that. Australia's new Serious Invasion of Privacy tort creates a direct cause of action for individuals whose privacy has been seriously invaded.
Michael Rivette was present at the formation of this area of law, arguing the privacy and breach of confidence issues in Giller v Procopets (2008), and writing articles that anticipated the new tort. He is uniquely positioned to advise individuals on privacy matters and the new cause of action, and to appear in proceedings under it.
In appropriate circumstances individuals may engage Michael directly, without a solicitor. For Individuals sets out how that works under the professional rules.
Michael Rivette has authored and co-authored significant texts and articles in Australian and international privacy law, writing as the practitioner who has appeared in the cases the texts describe.
Michael Rivette, (2020) 94 ALJ 791, Australian Law Journal
The definitive text on privacy class actions in Australia. Maps the causes of action, the class action framework, and the significance of Evans v Health Administration Corp as the template for mass privacy breach litigation. Written by the barrister who led the first successful privacy class action in Australia.
Australian co-author. The leading international text on privacy and media law.
Co-author, Chapter 7: "Invasion of Privacy and Recovery for Distress" (with Richardson and Neave).
Blockchain and the Australian Privacy Principles: Never the Twain Shall Meet
(2019) Privacy Law Bulletin 165, with Adam Lodders
Privacy as a Human Right
(2017) 14(2) Privacy Law Bulletin 22
The Ultimate Balancing Test: Privacy v Freedom of Expression
(2015) Privacy Law Bulletin 170
Litigating Privacy Cases in the Wake of Giller v Procopets
(2010) 15 Media and Arts Law Review 283
Brief Michael in a privacy, confidential information, or technology matter, and your client gets counsel who has appeared in Australia's most significant cases in these fields, from the foundational breach of confidence decisions to the landmark data breach class actions, and who wrote the texts privacy law relies on. Your firm gets a barrister who works closely with instructing solicitors and responds within one business day.
The commercial practice carries the same weight. Michael appears in commercial trials and appeals, contract and corporations disputes, and urgent applications, including injunctions and search orders where a client's confidential information has been taken. For a commercial dispute with a technology, data, or IP dimension, one counsel covers the whole matter.
From urgent strategic advice to appearances in any Australian court or tribunal, one counsel carries the matter from first call to final orders.
Over 35 years as an owner, director, and board member in media and technology businesses. Advice that is grounded in how these businesses actually run.
Written advice on complex privacy, technology, IP, and commercial questions, from the author of the leading Australian texts in the field.
Presentations to your firm's solicitors on developments in privacy, technology, and IP law, delivered by the barrister who has appeared in the cases under discussion.
Privacy is personal. Australia's new Serious Invasion of Privacy tort gives individuals a direct cause of action for the first time, and Michael acts for people whose privacy has been invaded, whose information has been exposed in a data breach, or who face media intrusion.
Barristers usually act on the instructions of a solicitor. The professional rules also allow a barrister to be engaged directly by a client, without a solicitor, in appropriate matters. Whether yours is one of them depends on what the matter needs, and Michael will tell you at the outset.
The rules define a barrister's work. Appearing as an advocate, giving legal advice, negotiating with the other side, representing you in a mediation, and preparing or advising on documents for your matter. Legal Profession Uniform Conduct (Barristers) Rules 2015, r 11.
A barrister cannot do the work of a solicitor's office. Commencing and serving court proceedings, conducting general correspondence, and holding or handling money for a client are outside a barrister's work under r 13. Where a matter requires them, a solicitor is needed.
The rules require that you be fully informed first. Michael must explain in writing what he can and cannot do, and that circumstances may require you to retain a solicitor, possibly at short notice, and you sign an acknowledgement before the engagement begins. Rule 22.
Some matters need a solicitor from the start, and others come to need one as they develop. If yours does, Michael will say so plainly and can continue as counsel working alongside your solicitor.
To find out where your matter stands, describe it through the enquiry form. Michael will advise whether he can act directly or whether a solicitor should be appointed.
When a matter involves serious privacy or data issues, the response must cover the immediate obligations, the regulatory landscape, and the litigation risk that follows. Michael is briefed across data breach response, regulatory proceedings, and the litigation that comes after.
From the first hour, Michael provides the legal direction a breach response needs, establishing privilege over the investigation, advising on notification obligations, and ensuring every step taken in the critical early period is defensible if the matter reaches a court or regulator.
Working with instructing solicitors, Michael can assist in coordinating specialist cybersecurity and data incident response teams, ensuring the technical investigation is conducted under legal direction from the outset. Privilege is preserved, and technical findings are framed for regulatory and litigation purposes from the first moment.
Michael advises and appears in OAIC investigations and regulatory proceedings, with 25 years of insight into how privacy regulators investigate and determine matters.
Following a data breach, class action risk must be assessed early. Michael assesses that exposure at the earliest stage, as counsel who has acted in Australia's first successful privacy class action and in McClure v Medibank Limited.
A data breach managed correctly in the first 72 hours is a recoverable event. Managed incorrectly, it becomes a class action, a regulatory determination, and a reputational crisis. The difference is having the right barrister briefed at the first moment.
Michael Rivette writes on the privacy and technology law developments that matter, with the perspective of a practitioner who has been present at the law's formation, and continues to appear in its most significant cases.
The prompt is a disclosure. AI, privacy, and other people's secrets
What you type into an AI tool does not stay with you, and the sharpest risks arise when the information is about someone else. Where the information actually goes, the obligations it triggers, and how to build the closed system that answers them.
Thousands of small businesses have just been brought into the Privacy Act, and many do not know it
The Tranche 2 AML/CTF reforms have brought real estate agents, conveyancers, accountants, lawyers, and barristers within the Privacy Act for the first time, regardless of turnover. What is caught, what is regulated, and the two traps to avoid.
For the first time, Australians can sue for invasion of privacy
The new statutory tort hands individuals a power they have never had, against any person or entity, small businesses included. What it delivers, where it fails, and the door it leaves open for the common law.
Privacy is a human right. Everything else follows from that
Australia helped write the right into international law, with an Australian presiding over the adoption of the Universal Declaration. What the human rights foundation means for compliance, breach, and the development of the law.
Privacy class actions changed the economics of data risk, and health information is the sharpest edge
Every business holding personal, confidential, or sensitive information now faces litigation risk as well as regulatory risk. The practices that create the exposure, and the two assumptions that will not hold.
Blockchain and the Privacy Act: the incompatibility has not gone away
An immutable, distributed ledger cannot correct, destroy, or contain personal information the way the APPs require. The issues for companies using blockchain, what to do with an access and correction application, and the uses most exposed.
The Privacy Act reforms are not finished, and the small business exemption is living on borrowed time
The government has agreed in principle to abolish the small business exemption and to introduce the controller and processor architecture the GDPR is built on. What is coming, and why preparing now is best practice in any event.
Ask a suburban real estate agent, a two-partner accounting practice, a jeweller, a small law firm, or a barrister in chambers whether the Privacy Act applies to their business, and until this year the answer was usually no. The small-business exemption, for businesses with an annual turnover of $3 million or less, has kept most Australian small businesses, and most of the legal profession's smaller practices with them, outside the Privacy Act 1988 (Cth) since its commencement.
Since 1 July 2026, that answer has changed for a large class of them, and by an unexpected route. The second tranche of the anti-money laundering and counter-terrorism financing reforms extends the AML/CTF regime to real estate professionals, conveyancers, lawyers, accountants, trust and company service providers, and dealers in precious metals and stones. A business that provides a "designated service" under that regime becomes a "reporting entity". Section 6E(1A) of the Privacy Act then deems it an "organisation", regulated by the Australian Privacy Principles in relation to its AML/CTF activities, and turnover is irrelevant. Privacy compliance arrives not as a considered choice but as the by-product of an entirely different regulatory regime.
The gateway is the designated service. The agent selling a house provides one. So does the conveyancer on an ordinary settlement, the accountant structuring a family trust or company, the service provider supplying a registered office or nominee director, the dealer in a large precious metals transaction, and the solicitor acting on a property or business sale. Advice that does not advance a transaction, and representation in a court or tribunal, generally are not designated services.
There is no de minimis exemption. A single designated service, one settlement, one trust establishment, one conveyance, is enough to make the business a reporting entity. For the legal profession the line runs through the middle of ordinary practice. A solicitor's firm that does any conveyancing cannot quarantine its trust account from the regime. A barrister briefed by a solicitor provides no designated service, and the obligations sit with the instructing firm. The direct brief is where care is needed. A brief confined to advocacy and advice, conferences, opinions, pleadings and appearances, stays outside the regime. A brief that turns to transactional work, advancing a sale, a financing, or a corporate or trust structure, may not, and the barrister who crosses that line becomes an APP entity for the records the brief generates.
For a business under the $3 million threshold, only the personal information handled for or in connection with the AML/CTF Act is regulated. That is the material customer due diligence generates. Identity documents and verification records, beneficial ownership of corporate and trust clients, and screening records, which may include sensitive information where checks for politically exposed persons touch political associations. The business's wider files remain outside the Act, but the regulated core is exactly the information a criminal most wants and a client most fears losing.
The obligations are concrete. A clearly expressed privacy policy confined to what it actually covers. Collection notices at or before collection, most simply built into the engagement or agency agreement. Collection limited to what is reasonably necessary. Security over what is kept, and destruction when the seven-year AML/CTF retention rules no longer require it. Access and correction procedures. And a plan for the Notifiable Data Breaches scheme, under which a suspected eligible breach must be assessed within 30 days.
The reformed tipping-off offence reaches every reporting entity, not just lawyers. Records bearing on a suspicious matter report must be kept out of ordinary files, and no response to a client, including a privacy access request, may reveal that a report exists.
The second trap is overreach. A small business that publishes a general privacy policy, without confining it to the information the Act actually regulates, may be held to the wider promises it has made, under the Australian Consumer Law or in contract. Represent only what the policy covers, and no more.
A business that stays outside the AML/CTF net takes no shelter from the statutory tort of serious invasion of privacy, in force since 10 June 2025 and not subject to the small-business exemption. For any business holding identity documents and financial details, poor data handling is now a litigation risk as well as a regulatory one. And professionals who have always kept client confidences are not, for that reason, privacy compliant. Confidentiality is about non-disclosure. The Privacy Act governs the whole life of the information, from collection to destruction.
The obligations commenced on 1 July 2026. A business that has not yet acted should treat the work as overdue rather than pending.
A fuller version of this article, with references, will be published in the Privacy Law Bulletin.
Michael accepts briefs to advise on the implications of the new regime for legal firms, businesses, and individuals, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.
For most of the Privacy Act's life, a business that mishandled personal information faced an aggrieved individual with no economic path to a courtroom. Most privacy breaches cause distress, embarrassment, and humiliation rather than quantifiable financial loss, and a claim of that size could never carry the cost of litigation. The complaint went to a regulator, or nowhere.
The class action changed that arithmetic. By collecting thousands of individually small claims into a single proceeding, it created a vehicle that can support the cost of litigation, and modern data breaches suit it, because a breach harms thousands of people in essentially identical ways. In Evans v Health Administration Corp [2019] NSWSC 1781, Australia's first privacy class action to obtain compensation for class members, the information was contained in workers compensation files, including staff medical records, sold by a contractor. Michael Rivette appeared as lead counsel.
Health information sits at the top of the private information hierarchy. The courts regard information about a person's health as among the categories most easily identifiable as private, and since Giller v Procopets (2008) 24 VR 1 compensation has been available for the distress, embarrassment, and humiliation a disclosure causes, without proof of psychiatric injury or economic loss. In the reported cases, compensation for distress alone has reached the tens of thousands of dollars per person. That is the multiplier. In a breach of health, financial, or genuinely confidential information, nearly every affected individual has a compensable claim, and the total is the per-person figure multiplied by everyone the breach touched.
Certain practices are no longer acceptable in a holder of personal, sensitive, or confidential information, and each of them converts directly into pleadable allegations when a breach occurs.
Access beyond need. Personal, confidential, and sensitive information should be available only to the people who need it to do their jobs. Giving staff or contractors access to records they do not require, health, financial, or otherwise, is not just poor security. It is arguably itself a use or disclosure of the information, in breach of confidence, contract, and the reasonable expectations the Privacy Act protects.
Blindness to exfiltration. A holder that cannot tell whether information has left its systems has a security posture that will not withstand scrutiny, because the adequacy of security is judged against the nature and sensitivity of the information held.
Unguarded credentials. Compromised staff credentials are a standard route into a network. Multi-factor authentication, threat awareness training, and monitoring for compromised credentials are now baseline expectations, not sophistication.
Data kept past its purpose. Information about former customers that should have been destroyed or de-identified is pure liability. It cannot earn anything, and in a breach it swells the affected class.
Promises the systems cannot keep. Every assurance in a privacy policy or public report about security practices, staff training, or data handling is potential contractual and Australian Consumer Law material, judged at the time it was made. A business should promise what its systems actually do.
Slow notification. Delay in telling affected individuals compounds the harm and the claim. The Notifiable Data Breaches scheme sets the clock, and the common law duties do not wait for it.
The first is that the criminal breaks the chain. A business should not assume that the intervention of a hacker answers the claim. Australian courts have allowed negligence claims arising from the criminal acts of third parties, and where a business has promised to keep information secure, the argument that its own failings caused the loss is squarely available. The second is that a clean history is protection. A business that has had earlier incidents is on notice, and prior breaches inform foreseeability in everything that follows.
The information a business holds should be priced as a liability as well as an asset. Collect less. Confine access to need. Secure what is kept, against insiders as well as intruders. Destroy what is no longer required. Notify promptly. And make sure the privacy policy describes the systems that exist, not the systems the business wishes it had. Michael argued in Privacy Class Actions (2020) 94 ALJ 791 that it may be only through class actions that businesses put a proper price on the protection of the personal, private or confidential information they hold. That argument is now the operating environment. The businesses that fare best will be the ones that acted before anyone tested it.
Michael Rivette appeared as lead counsel in Australia's first successful privacy class action and is the author of Privacy Class Actions (2020) 94 ALJ 791. He accepts briefs to advise businesses on data risk, breach response, and class action exposure, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.
Blockchain solves the problem of trust in a trustless environment by making its record permanent, verified, and copied to every participant. The Privacy Act assumes the opposite. A record keeper who controls the information it holds, can correct it, can destroy it, and answers for where it goes. As Michael Rivette and Adam Lodders argued in Blockchain and the Australian Privacy Principles: Never the Twain Shall Meet (2019) Privacy Law Bulletin 165, the two designs are in conflict at the level of architecture, and that conflict has not been resolved.
Immutability against correction and destruction. The APPs give individuals the right to have their personal information corrected, and require destruction or de-identification once the information is no longer needed. A blockchain's record cannot be rewritten without consensus across the network, and deletion runs against the structure itself.
Distribution against control. Every node holds the whole record, and a node can sit anywhere with an internet connection. On a public chain, each new participant receives a copy of everything, which may itself be a disclosure to an unknown third party, and the cross-border rules in APP 8 are engaged with no practical way of honouring them.
Loss of control against the breach regime. Each movement of data outside the record keeper's control has the capacity to become a notifiable data breach, and the record keeper cannot control the other nodes.
The reasonableness trap. The APPs qualify these duties by what is reasonable in the circumstances. A company that chose an architecture incapable of correction or destruction should expect the choice itself to be scrutinised, against the alternatives it passed over. The point is unsettled, which is not comfort.
The application cannot be ignored and cannot be charged for. The entity must respond within a reasonable period and take reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading. Where the chain cannot be rewritten, correct the off-chain systems that feed it and record the correction there. If correction is refused, APP 13 requires written notice of the reasons and the complaint mechanisms, and the individual may require a statement to be associated with the information, made apparent to anyone who uses it. On request, other entities to whom the information was disclosed must be told of the correction. The only reliable answer is architectural. Keep personal information off the chain, store references to it rather than the information itself, and keep the substance in systems that can be corrected and destroyed.
The 2024 privacy amendments left the correction, destruction, and cross-border principles untouched, and the proposed second tranche of reform contemplates a right to erasure, which an immutable ledger can honour even less than the current destruction duty. The digital assets legislation now before Parliament licenses platforms and custody. It says nothing about privacy, and licensing a platform does not make its records correctable.
Writing personal information to a public chain is the highest exposure, and the risk rises with the sensitivity of the information. Identity and credential systems, customer records, and anything touching health information sit at the top. Permissioned networks with known participants reduce the exposure but do not remove it, because the copies still distribute and the correction problem remains.
Michael Rivette is the co-author of Blockchain and the Australian Privacy Principles: Never the Twain Shall Meet (2019) Privacy Law Bulletin 165, the leading analysis of the incompatibility. He accepts briefs to advise on blockchain, data, and privacy compliance, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.
On 10 June 2025, something Australian law had refused individuals for more than a century arrived. A cause of action for serious invasion of privacy, in Schedule 2 of the Privacy Act, that a person can take to court in their own name. No complaint to a regulator. No waiting for a commissioner to investigate. A writ, a courtroom, and a judgment.
The tort reaches the two ways privacy is actually invaded. Intrusion upon seclusion, which covers physically entering private space and watching, listening to, or recording private activities. And misuse of information relating to a person, where the truth of the information is no defence. The plaintiff must show a reasonable expectation of privacy, an invasion that was intentional or reckless and serious, and that their privacy outweighed any countervailing public interest. Damage need not be proved. The invasion itself is the wrong.
The remedies have teeth. Injunctions to stop a threatened or continuing invasion. Damages, including for emotional distress, with exemplary damages in exceptional cases. And a set of orders the regulatory regime never offered an individual, an account of profits, an apology, a correction, and the destruction or delivery up of the offending material.
Two features deserve emphasis. First, anyone can be sued. The tort is not confined to government agencies or large companies. A small business, an employer, a neighbour, a former partner, all are within reach, because the Privacy Act's $3 million small-business exemption does not apply to it. Second, the tort sits in the Privacy Act but operates outside its constraints. It does not require the defendant to be an APP entity, it is not confined to "personal information" as the Act defines it, and it protects against conduct, the watching and the recording, not merely the mishandling of data. Parliament placed a tort inside a regulatory statute and cut it free of the regulation.
The exemptions are categorical, and that is the design flaw. The journalist exemption is arguably the worst of them. Journalists, their employers, and their assistants are exempt for journalistic material, and the exemption holds even where the journalist has breached their own professional code. The class of defendant most likely to invade privacy is the class the tort cannot touch, and no balancing of interests ever occurs, because an exemption is not a defence, it is a locked door. Law enforcement bodies, intelligence agencies, and public authorities acting in good faith are also carved out, and no action lies against a defendant under 18.
The limits go further. Only intentional or reckless invasions are caught, so the merely negligent invasion of privacy, however damaging, falls outside the tort. The invasion must be serious. The limitation period is severe, in general one year from awareness or three years from the act, against six years for most torts. Damages are capped at the defamation cap. And the defamation defences of absolute privilege, public documents, and fair report are imported wholesale, giving defendants a second run at a public interest argument the tort's own elements already weigh.
Schedule 2 says expressly that it does not exclude the concurrent operation of other law, and the High Court in Lenah Game Meats and again in Smethurst has left open the recognition of a privacy tort at common law. Some trial courts have already gone further. In Grosse v Purvis in the District Court of Queensland, and in Doe v Australian Broadcasting Corporation and Lynn v Romy in the County Court of Victoria, damages were awarded for invasion of privacy at common law, although these are decisions of lower courts and no superior court has yet recognised the tort. A common law tort would carry none of the statutory exemptions. No journalist carve-out, no immunity for the under-18 defendant, no imported defamation defences, just the balancing of privacy against the public interest on the facts of each case, which is how the United Kingdom and New Zealand already do it.
The statute began the work. It has handed individuals a real power, and its failures map the ground the common law should now claim. What remains is the right case, properly argued.
Michael Rivette argued the privacy issues in Giller v Procopets (2008) 24 VR 1, the foundation of Australian privacy litigation, and has appeared in and written on this field for more than twenty-five years. He acts for individuals in serious invasion of privacy matters, on brief from solicitors and, in appropriate cases, on direct engagement. To find out where you stand, make an enquiry through the contact page.
The 2024 amendments to the Privacy Act delivered the statutory tort, new penalty tiers, automated decision-making transparency, and a criminal doxxing offence. They were the first tranche, and the easier one. The structural reforms recommended by the Privacy Act Review remain on the government's table, agreed in principle but not yet legislated, and two of them will redraw who Australian privacy law applies to.
The small business exemption has kept businesses with an annual turnover of $3 million or less outside the Privacy Act since the Act was extended to the private sector. The Privacy Act Review recommended its abolition, and the government has agreed in principle, subject to an impact analysis and consultation on how obligations should be tailored and supported for small business. The principle behind the recommendation is hard to argue with. A person's information deserves the same protection whether it is held by a company with a $3 million turnover or a $300 million one, and the GDPR, the reference point for data protection worldwide, contains no equivalent carve-out. Australia's exemption is an outlier, and outliers in privacy law do not last.
The Review also recommended introducing the concepts of controllers and processors, and the government has again agreed in principle. The distinction is the organising structure of the GDPR. The controller decides why and how personal information is handled, and carries the primary obligations. The processor handles information on the controller's instructions, and carries obligations scaled to that role. The current Act draws no such line, treating every APP entity alike regardless of its actual role, which fits poorly with a world of outsourcing, cloud services, and data handled by chains of providers. Australian businesses dealing with international counterparties already sign controller and processor clauses in their contracts. The Act has simply not caught up with the way information is actually handled.
The timing of the second tranche is uncertain. The direction is not. The government has committed itself in principle to both reforms, and when they arrive, organisations, sole practitioners, and individuals in business who have never been within the Privacy Act will be regulated by it. Many small businesses have already had a first taste, because the AML/CTF reforms brought reporting entities partly within the Act from 1 July 2026, and the statutory tort of serious invasion of privacy already applies to everyone, regardless of turnover.
Preparation is cheaper now than under a compliance deadline, and the steps are best practice in any event. Collect only what is needed. Secure what is kept, and destroy what is not. Know what information the business holds and where it sits. Publish a privacy policy that describes the systems that exist. Have a breach plan. A business that does these things now will meet the reforms as a formality. A business that waits will meet them as a project, with a regulator watching.
Michael Rivette advises organisations, small businesses, and practitioners on privacy compliance and on preparing for the coming reforms, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.
In 1890, Warren and Brandeis identified privacy as a right of the individual, the right of a person who has remained private to keep their life their own unless some overriding public interest requires otherwise. Within sixty years that idea had become international law, and Australia did not merely sign up to it. Australia helped write it.
Australia was one of only eight nations involved in drafting the Universal Declaration of Human Rights, and the man at the centre of that work was an Australian. Dr H V Evatt had been a Justice of the High Court of Australia and was the Commonwealth's Attorney-General and Minister for External Affairs when he led Australia's delegation to the United Nations. He became the third President of the General Assembly, and it was under his presidency, in December 1948, that the Universal Declaration was adopted. Article 12 declares that no one shall be subjected to arbitrary interference with their privacy, family, home, or correspondence. Australia then became a founding signatory to the International Covenant on Civil and Political Rights, whose Article 17 carries the same guarantee into binding treaty law. On privacy, Australia was not a follower. It stood at the front of the room when the right was created.
What the right protects is not information for its own sake. It is human autonomy and dignity, the ability of a person to control what is known of their private life and to hold the esteem and respect of others, as the House of Lords put it in Campbell v MGN Ltd. A data breach, a surreptitious recording, an intrusive publication, each is at its core the same wrong, an invasion of the person, not merely a mishandling of records.
This is not abstract philosophy. It is built into Australian law. The Privacy Act's preamble invokes the Covenant, and its stated objects include implementing Australia's international obligations on privacy. The Victorian Charter of Human Rights embodies Article 17 directly. And since Mabo, the High Court has treated international human rights law as a legitimate and important influence on the development of the common law.
The practical consequences are real, and businesses overlook them at their cost. Privacy legislation is remedial, enacted to confer a benefit on individuals, and the courts construe such legislation to give the fullest relief its language allows, with exceptions read narrowly. A business that runs its privacy compliance from its own convenience has the analysis backwards. The measure is the individual whose information is held, which is why privacy by design, building protection in at the start rather than bolting it on, is both the principled approach and the one most likely to limit liability when something goes wrong.
For decades the human rights framing was treated as rhetoric while calls for real remedies went unanswered. No longer. The United Kingdom built a tort of misuse of private information on exactly this foundation, concerned with intrusion and not merely secrets, and surviving even publication to the world. And in 2025 Australia's statutory tort of serious invasion of privacy arrived, with an objects clause that expressly implements the Covenant. The commitments Australia helped write in 1948 are finally acquiring teeth in our own courts. The statutory tort carries major shortcomings, however, and does not cover the field. Its exemptions and limits, and the ground they leave open for the common law, are examined in a separate insight on this page. The direction of travel, though, is no longer in doubt.
So start every privacy question, whether compliance, breach, or litigation, where the law itself starts. Privacy is a human right, grounded in the autonomy and dignity of the person. Seen that way, the obligations fall into place, the exceptions stay narrow, and the cost of protection is understood for what it is, the price of respecting the people whose lives the information describes.
This commentary is based on Michael Rivette's article Privacy as a Human Right (2017) 14(2) Privacy Law Bulletin 22, updated for the law as it now stands. Michael advises and appears in privacy matters across this field, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.
Every day, people paste things into AI tools. A client list, a medical report, a complaint about a named colleague, a set of accounts, a draft agreement. The tool answers in seconds and the moment passes. The law sees that moment differently. The prompt may be a disclosure, and what was disclosed may not have been yours to disclose.
On most commercial AI tools, a query passes through the provider's systems. Providers commonly retain logs of prompts and outputs for a period, often around 30 days, to monitor misuse, and provider staff can review flagged queries. Behind the provider sits a chain of other companies, cloud hosts, identity services, monitoring services, each of which may handle the data. Documents uploaded for the tool to search are stored again in the tool's own database, a second copy with its own retention and deletion behaviour. And a provider subject to foreign law can be compelled by foreign legal process to produce what it holds, wherever the data is stored. Keeping data in Australia does not, by itself, answer that. None of this means AI cannot be used safely. It means the assumption that what you type stays with you is wrong, and the legal analysis starts there.
This is where the risk sharpens. Handing another person's personal, sensitive, or health information to an AI provider may itself be a use or disclosure that the privacy laws regulate. Confidential information received for a purpose is bound to that purpose, and equity's rule is that using it for something else can be a breach of confidence even if it never becomes public. The tool's output carries its own consequences. When an AI draws a conclusion about an identified person, a likely diagnosis, a credibility assessment, a pattern of conduct, that conclusion is new personal information about that person, created by you and held by you, with the obligations that follow. If the conclusion is adverse, untested, and shared, defamation enters the frame. The person it concerns usually knows nothing about any of it.
An AI tool connected to an organisation's documents can surface material to a staff member who would never have found it by ordinary means, straight through the access controls and information barriers the organisation thought it had. And a model trained or fine-tuned on an organisation's own material can, in some circumstances, be induced to give that material back. Access controls outside the tool must be mirrored inside it, and the decision to train a model on your own files deserves far more caution than it usually gets.
The usual answer to these risks is a "secure, closed system". Treat that phrase with care, because no commercial AI tool is a closed system off the shelf. A closed system is an outcome you construct, partly in the contract and partly in how the tool is set up. On the contract side, the minimums are a prohibition on the provider training any model on your data, log retention measured in days with review confined to defined safety triggers, a named list of every company behind the provider with notice and a right to object before it changes, data, including the system's operational records, kept in Australia, an obligation to resist foreign legal process so far as the law allows and to give notice of it, deletion of stored material when the work ends, and audit rights.
On the configuration side, the tool must mirror the organisation's own walls. Each matter or project separated from every other, access confined to the people working on it, no cross-project operation unless deliberately enabled, and outputs about identified people treated as records the organisation now holds. For the most sensitive information there is a stronger answer again, running the model on infrastructure you control, which removes the provider-side exposures, the logs, the supply chain, the foreign process, at their source. And where de-identified data is used, test it the way an intruder would, because removing names is not de-identification, and an AI tool with access to public information is itself a re-identification engine.
Professionals carry all of this plus their own duties. For lawyers, the duty of confidentiality under r 9 of the Legal Profession Uniform Law Australian Solicitors' Conduct Rules 2015 and r 114 of the Legal Profession Uniform Conduct (Barristers) Rules 2015 attaches to what goes into the tool, and the duties of competence and candour reach the output. The courts have added a layer of their own. Practice Note SC Gen 25 of the Supreme Court of Victoria, which commenced on 14 May 2026, requires content produced using AI in court documents to be verified with meaningful human control, and empowers the Court to require a party to identify the portions of a document produced using AI and to explain how the output was verified. Australian practitioners have already faced costs orders and disciplinary consequences over unverified AI output. Advisers in other fields should assume their own professional obligations reach their AI use in the same way.
Know which tool you are using, and on what terms, because consumer products and properly configured enterprise arrangements are different worlds. Do not put another person's information into a tool unless you are entitled to use it for that purpose. Send the minimum the task needs. If the tool matters to your business, get the contract right, no training on your data, tight retention, a known list of the companies behind the provider, and honesty about what foreign process can reach. Treat AI conclusions about people as records you now hold. And verify output before you rely on it. The technology is worth using. It is simply not a private conversation, and the law will not treat it as one.
Michael Rivette advises organisations, agencies, and practitioners on the privacy, confidentiality, and data risks of AI adoption, from instructing solicitors and, in appropriate matters, on direct engagement. To discuss your position, make an enquiry through the contact page.
Michael Rivette is available to be briefed by instructing solicitors for advisory, regulatory, and advocacy matters across all areas of practice.
In certain matters he may be engaged directly, under the Direct Access provisions of the Legal Profession Uniform Conduct (Barristers) Rules 2015.
Individuals with privacy matters are welcome to enquire using this form. Michael will advise whether he can act directly or whether a solicitor should be appointed.
Chancery Chambers, Melbourne
+61 3 8600 1717
0418 375 566
+61 3 8600 1725
All Australian courts and tribunals
All enquiries responded to within one business day. Urgent matters as priority.
Michael Rivette is a member of Young's List. Solicitors wishing to brief Michael may contact his clerk directly.
Tammy Young, Young's List
Suite 8B, Level 2, 221 Queen Street, Melbourne Victoria 3000
GPO Box 4770, Melbourne Victoria 3001
+61 3 9225 6777
Tammy Young +61 414 523 515
Tara O'Connor +61 466 638 081
Oscar Morrison +61 403 603 463
Privacy collection notice. Personal information submitted through this form is collected by Michael Rivette to respond to your enquiry and to assess whether he can act. It is treated in confidence, is used for no other purpose, and is handled in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Submissions are processed and stored by Formspree on Michael's behalf. Sending an enquiry does not create a barrister and client relationship. Please describe your matter briefly and do not include confidential detail beyond what is needed to explain it.
Thank you for your enquiry.
Michael Rivette will respond personally within one business day.