Amendments to the Australian Privacy Act 1988 (APA) expanded its extraterritorial provisions with effect from 13 December 2022, thereby requiring foreign organisations carrying on business in Australia to comply with the APA.

Insights

Amendments to Australian Privacy Act Expands Extraterritoriality

Date
December 19, 2022
Author
OrionW

On 13 December 2022, amendments to the Australian Privacy Act 1988 (APA),including the enhancement of its extraterritorial provisions, were passed and took effect.  Consequently, foreign organisations (including sole traders) carrying on business in Australia must comply with the APA and the Australian Privacy Principles (APPs) although they do not collect or hold personal information in Australia.

APA’s Extraterritorial Application – What Changed and Why It Matters

Before the amendment, the APA already had extraterritorial effect – that is, it applied to foreign organisations which have an ‘Australian link’.  A foreign organisation would be deemed to have an ‘Australian link’ if it met both of the following conditions:

  • it carries on business in Australia; and
  • it collected or held personal information in Australia, either before or at the time information was handled.

The APA amendment removed the second condition in considering whether an ‘Australian link’ exists.  The change extensively broadened the application of the APA to cover foreign organisations that carry on business in Australia but do not collect or hold personal information in Australia.  That said, if an act done by a foreign organisation outside Australia is required by an applicable foreign law, that act will not be considered a breach of the APA or the APPs.

The Office of the Australian Information Commissioner (OAIC), the Australian government agency that administers the APA, reasoned that the change was necessary to address the risks arising from foreign organisations handling or trading in Australians’ personal information which is not directly collected in Australia (e.g., collection is done by a related entity in Australia or an overseas digital platform).

When a Foreign Organisation Carries on Businessin Australia

The APA does not define the phrase ‘carries on business in Australia’.  However, the OAIC has noted that the following factors will be among the points considered in determining whether an organisation is doing business in Australia:

  • having an agent in Australia who acts on the organisation’s behalf;
  • offering goods or services to Australia through the organisation’s website;
  • including Australia in the drop-downlist of countries of the organisation’s website; and
  • having registered trademarks in Australia.

In addition, an Australian Federal Court case also noted that an organisation may prima facie be regarded as carrying on a business in Australia by installing cookies on devices of Australian users and allowing Australian developers to use its application programming interface to provide services in Australia.

Accordingly, even an entity without a physical presence in Australia could be considered as having an ‘Australian link’.  However, an organisation will not generally be considered as carrying on business in Australia solely because it has a website which is accessible from Australia.

Impact of the APA Amendment

The impact of the expanded extraterritoriality clause is substantial given the equally broad construction of ‘carrying on business in Australia’(and therefore, an ‘Australian link’), as discussed above.  In other words, a foreign organisation without a physical office in Australia may not be aware that it would need to comply with the APA and the APPs when it collects personal information from an individual physically located in Australia (including a foreign citizen)through its website hosted overseas.  This could be a major issue given the hefty penalty for non-compliance with the APA and the APPs under the amended APA – up to AUD50 million for body corporates.

Key Takeaway

Given the expanded extraterritorial application of, and the hefty penalty attached to a breach of, the APA and the APPs, foreign organisations who carryon business in Australia but do not collect or store personal data in Australia should take extra measures to determine whether they would need to comply with the APA and the APPs in respect of their data processing activities outside Australia.

For More Information

OrionW regularly advises clients on cross-border data protection matters.  For more information about data protection issues, or if you have questions about this article, please contact us at info@orionw.com.

Disclaimer: This article is for general information only and does not constitute legal advice.

Newsletter

Subscribe to
our newsletters

To subscribe, select the newsletter options that interest you (TMT, FinTech or DPC - Data Protection and Cybersecurity) and provide your details.

  • TMT - Technology, Media and Telecommunications
  • FinTech
  • DPC - Data Protection & Cybersecurity
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.