Agent skill

Australia Privacy Act

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments.

Apache-2.0Auto-check passedLegal & Compliance

Install Australia Privacy Act

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill australia-privacy-act -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills australia-privacy-act --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/australia-privacy-act .claude/skills/australia-privacy-act && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
australia-privacy-act
GitHub stars
301
Token cost
~2.8k tokens
SKILL.md length
1,286 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments.

  • Works in 3 steps: Take reasonable steps to ensure the… → The organisation remains accountable for… → Exceptions: individual consent after…
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Australian Privacy Principles…, 2024 Reform Amendments and Cross-Border Disclosure (APP 8), plus 3 more sections
  • Runs Python scripts from its folder

What it does

Australia Privacy Act is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments. Covers automated decision-making transparency, children's privacy code, individual rights expansion, enforcement strengthening, and the Australian Privacy Principles (APPs). Keywords: Australia Privacy Act, APPs, OAIC, automated decisions, children privacy code, privacy reform.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the australia-privacy-act skill to guide compliance with Australia's Privacy Act 1988 including the 2024 reform amendments”
  • “/australia-privacy-act”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Take reasonable steps to ensure the overseas recipient does not breach the APPs (APP 8.1)
  2. The organisation remains accountable for the overseas recipient's handling of the information
  3. Exceptions: individual consent after being informed the APPs may not apply; required by Australian law; enforcement of criminal law…

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Australia Privacy Act loads about 2.8k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 1,286 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,286 words, ~2,762 tokens.

Download SKILL.mdSave it as .claude/skills/australia-privacy-act/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
australia-privacy-act
description
Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments. Covers automated decision-making transparency, children's privacy code, individual rights expansion, enforcement strengthening, and the Australian Privacy Principles (APPs). Keywords: Australia Privacy Act, APPs, OAIC, automated decisions, children privacy code, privacy reform.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
global-privacy-regulations
metadata.tags
australia-privacy-act, oaic, automated-decisions, children-privacy, apps

Australia Privacy Act Compliance (2024 Amendments)

Overview

Australia's Privacy Act 1988 (Cth) is the primary federal data protection legislation, administered and enforced by the Office of the Australian Information Commissioner (OAIC). The Privacy Act applies to Australian Government agencies, private sector organisations with an annual turnover of more than AUD 3 million, and certain other organisations regardless of turnover (health service providers, organisations trading in personal information, credit reporting bodies).

The Australian Government's 2024 Privacy Act Reform Amendments (building on the Attorney-General's Department Privacy Act Review Report of February 2023) introduced significant reforms including a statutory tort for serious invasions of privacy, enhanced individual rights, automated decision-making transparency obligations, a children's privacy code, and strengthened enforcement powers.

Australian Privacy Principles (APPs)

The 13 APPs
APPSubjectKey Requirement
APP 1Open and transparent managementMaintain a clear privacy policy; take reasonable steps to implement practices that ensure compliance
APP 2Anonymity and pseudonymityGive individuals the option of dealing anonymously or under a pseudonym where practicable
APP 3Collection of solicited personal informationCollect only information reasonably necessary for functions/activities; collect sensitive information only with consent
APP 4Dealing with unsolicited personal informationIf unsolicited information could not have been collected under APP 3, destroy or de-identify it
APP 5Notification of collectionNotify individuals of: identity, purpose, third-party disclosures, overseas disclosures, access/correction rights, complaint mechanism
APP 6Use or disclosureUse or disclose only for the purpose of collection or a directly related secondary purpose within reasonable expectations
APP 7Direct marketingMay use for direct marketing if individual would reasonably expect it and opt-out is provided; sensitive information requires consent
APP 8Cross-border disclosureBefore disclosing overseas, take reasonable steps to ensure the overseas recipient complies with the APPs
APP 9Adoption, use, or disclosure of government identifiersMust not adopt a government identifier as own identifier; limited use and disclosure
APP 10Quality of personal informationTake reasonable steps to ensure information is accurate, up-to-date, complete, and relevant
APP 11Security of personal informationTake reasonable steps to protect from misuse, interference, loss, and unauthorised access; destroy or de-identify when no longer needed
APP 12Access to personal informationOn request, give individuals access to their personal information
APP 13Correction of personal informationTake reasonable steps to correct if inaccurate, out-of-date, incomplete, irrelevant, or misleading

2024 Reform Amendments

Automated Decision-Making Transparency
ElementDetail
ScopeOrganisations using personal information in substantially automated decisions that significantly affect individual rights or interests
Transparency obligationMust provide meaningful information about the automated decision-making process including: the fact that an automated decision has been made, the types of personal information used, and how the decision was reached
Right to human reviewIndividuals may request human review of automated decisions that significantly affect them
Impact assessmentOrganisations must assess the impact of automated decision-making systems on privacy before deployment
Record-keepingMaintain records of automated decision-making systems, including the logic involved and data inputs
Children's Privacy Code
ElementDetail
ScopeSocial media services, online platforms, and other services likely to be accessed by children
Definition of childUnder 18 years (aligned with the definition in the Online Safety Act 2021)
Best interests principleThe best interests of the child must be a primary consideration in all actions concerning children's personal information
Age assuranceOrganisations must implement appropriate age assurance mechanisms
RestrictionsProhibition on using children's personal information for targeted advertising; restrictions on profiling; data minimisation requirements specific to children
Code developmentOAIC to develop and register the code; industry consultation required
Enhanced Individual Rights
Right2024 StatusDetail
Right of accessEnhanced (APP 12)Clarified scope; reduced grounds for refusal
Right to correctionEnhanced (APP 13)Strengthened obligation to correct upon request
Right to erasureNewRight to request deletion of personal information where it is no longer necessary for the purpose of collection, consent is withdrawn, or information was unlawfully collected
Right to de-identificationNewAlternative to erasure where deletion is impracticable
Right to object to direct marketingStrengthenedClearer opt-out obligations; unsubscribe must be actioned within 5 business days
Right to request explanationNewRight to request explanation of how personal information was used in an automated decision
Statutory Tort for Serious Privacy Invasions
ElementDetail
Cause of actionIndividual may bring proceedings for a serious invasion of privacy
ThresholdInvasion must be serious; court considers the nature of the privacy and the means of invasion
RemediesDamages (including for emotional distress), injunctions, account of profits, apology orders
Limitation period1 year from when the individual became aware (or ought to have become aware) of the invasion
DefenceThe invasion was in the public interest
Show full SKILL.md (512 more words)Show less
Strengthened Enforcement
EnhancementDetail
Civil penalty increaseMaximum civil penalty increased to the greater of: AUD 50 million, three times the value of the benefit obtained, or 30% of adjusted turnover in the relevant period
Infringement noticesOAIC may issue infringement notices for specified contraventions
Enforceable undertakingsStrengthened regime for enforceable undertakings
Public interest determinationsEnhanced OAIC power to make public interest determinations

Cross-Border Disclosure (APP 8)

Requirements

Before disclosing personal information to an overseas recipient, the organisation must:

  1. Take reasonable steps to ensure the overseas recipient does not breach the APPs (APP 8.1)
  2. The organisation remains accountable for the overseas recipient's handling of the information
  3. Exceptions: individual consent after being informed the APPs may not apply; required by Australian law; enforcement of criminal law; necessary to lessen a serious threat
2024 Enhancement

The reforms strengthen APP 8 by:

  • Requiring organisations to maintain records of overseas disclosures
  • Introducing a prescribed list of countries with substantially similar privacy protections (to be developed by the Attorney-General)
  • Allowing transfer to prescribed countries without the APP 8.1 reasonable steps requirement
Zenith Global Enterprises Cross-Border Register
Transfer FlowDestinationAPP 8 ComplianceMechanism
Customer data → EU HQGermanyReasonable steps (contractual safeguards)Data processing agreement with APP-equivalent obligations
Employee data → Regional HRSingaporeReasonable steps (contractual safeguards)Intra-group data sharing agreement
Logistics data → APACJapanReasonable steps (contractual safeguards)Service agreement with privacy schedule

Notifiable Data Breaches (Part IIIC)

Eligible Data Breach Criteria

A breach is eligible (notifiable) if:

  1. Unauthorised access to, disclosure of, or loss of personal information
  2. A reasonable person would conclude the breach is likely to result in serious harm to any individual
Notification Requirements
ElementRequirement
OAIC notificationAs soon as practicable (not later than 30 days after the entity becomes aware)
Individual notificationAs soon as practicable after preparing the statement
Statement contentDescription of breach, information involved, recommended steps for individuals
Assessment period30 days from reasonable grounds to suspect a breach

Enforcement Actions

OAIC v. Australian Information Commissioner v. Clearview AI (2021)
  • Determined that Clearview AI breached APPs 2, 3, 5, and 10 by scraping Australians' biometric data from the internet
  • Ordered to cease collection and destroy existing data
  • Significance: Established OAIC jurisdiction over overseas entities processing Australian personal information
Australian Information Commissioner v. Facebook (Meta) (2022-ongoing)
  • Civil penalty proceeding regarding Cambridge Analytica data sharing affecting Australian users
  • Federal Court proceedings for breaches of APP 6 and APP 11
  • Significance: Testing the enhanced civil penalty regime

Compliance Programme

ComponentDetail
Privacy Officer (Australia)Sarah Mitchell, Privacy and Compliance Lead — Sydney office
APP 1 privacy policyPublished at zenithglobal.com.au/privacy
APP 3 collectionMinimal collection; consent for sensitive information
APP 7 direct marketingOpt-out mechanism; 5 business day unsubscribe processing
APP 8 cross-borderContractual safeguards with all overseas recipients
APP 11 securityISO 27001 certification; annual penetration testing
APP 12-13 access/correctionPrivacy portal with 30-day response target
Part IIIC breach notification30-day assessment + notification workflow
Automated decision-makingImpact assessment conducted for credit scoring; human review available
Children's code readinessMonitoring OAIC code development; no direct child services

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/australia-privacy-act of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Australia Privacy Act next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Australia Privacy Act compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Australia Privacy Act this skillmukul975/Privacy-Data-Protection-Skills301—~2.8kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Australia Privacy Act

What does Australia Privacy Act do?

Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments. Australia Privacy Act is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments.

When should I use Australia Privacy Act?

Australia Privacy Act fits situations like: tasks that involve Privacy and GDPR.

How do I install Australia Privacy Act in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill australia-privacy-act -a claude-code`. Or copy the skill folder (skills/privacy/australia-privacy-act in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/australia-privacy-act in your project. Claude Code loads it when a task matches its description.

How do I install Australia Privacy Act in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill australia-privacy-act -a codex`. Or copy the skill folder (skills/privacy/australia-privacy-act in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/australia-privacy-act in your project. Codex loads it when a task matches its description.

Can I use Australia Privacy Act in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill australia-privacy-act -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/australia-privacy-act, .gemini/skills/australia-privacy-act, .github/skills/australia-privacy-act and .opencode/skills/australia-privacy-act in your project.

What does Australia Privacy Act need to run?

Going by SKILL.md and its folder, Australia Privacy Act needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Australia Privacy Act access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Australia Privacy Act safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Australia Privacy Act use?

Australia Privacy Act is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Australia Privacy Act use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.

What are the alternatives to Australia Privacy Act?

Skills that share tags, products or a category with Australia Privacy Act: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Australia Privacy Act?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.