Home Resources The Privacy Commissioner is ready. Are you? Why now is the time for marketers to prioritise privacy Compliance The Privacy Commissioner is ready. Are you? Why now is the time for marketers to prioritise privacy The OAIC has drawn a line in the sand. Legislative reform may be delayed, but expectations are rising. Here, Andrea Martens, CEO of the Association for Data-Driven Marketing and Advertising (ADMA), shares what every marketer needs to know - and do - before the regulator comes knocking. Australian Privacy Commissioner Carly Kind’s latest statements are a clear warning to Australian businesses: the time to prepare for regulatory change is not after Tranche 2 lands - it’s now. Kind recently signalled that while the timeline for changes in legislation is still uncertain, her office will move ahead with proactive enforcement using the powers already granted under Tranche 1 of the Privacy and Other Legislation Amendment Act 2022. What’s emerging is a clear intention to use these powers to correct non-compliance and potentially seek judicial interpretations that clarify long-standing ambiguities in the Privacy Act. The implications for marketers are significant and timely. The message is clear: the Privacy Commissioner has stated her office now has everything they need to begin issuing penalties. Australian businesses should be treating privacy as a strategic, board-level concern. Marketers can no longer assume de-identified data, clean rooms or assumptions around pixel tracking offer blanket protection. As Kind highlighted, de-identification must be robust and if individuals are still ‘reasonably identifiable’, privacy laws may still apply. These practices are now in sharper regulatory focus. From “wait and see” to “act now” Many businesses may have been tempted to interpret the recent delay of Tranche 2 as a reprieve from the pressures to optimise for privacy, leading to a softening of internal momentum and resourcing around privacy initiatives. But the slowing of legislative movement shouldn't be mistaken for a reason to pause. The foundations for stronger enforcement are already in place, and now is a good time to start building internal momentum. We now know that The Office of the Australian Information Commissioner (OAIC) does not need new legislation to take action - Tranche 1 has given the OAIC the ability to test and enforce the law as it currently stands. In doing so, the OAIC may use enforcement cases to bring about judicial interpretations of terms like “personal information” and “consent”, which are sometimes hard to interpret across industry. This is a strategic move that could shift the privacy compliance landscape substantially and swiftly. For marketers and customer-focused teams, this is something to take keen note of. Those businesses which have adopted a “watch and wait” approach should begin to shift gears and begin proactively implementing privacy-safe measures. It will not necessarily be enough to say, “we’re not collecting personal information” or “the data is de-identified”. As Kind herself pointed out, “It is a lot harder to de-identify data to the point where the privacy laws no longer apply.” Tracking pixels and shared accountability Among the first areas flagged for active enforcement are website tracking technologies - specifically, the use of tracking pixels. These tools, which underpin vast portions of the digital marketing ecosystem, are coming under scrutiny for how they collect, transmit and share data - particularly where health, financial or other sensitive information may be involved. Importantly, the OAIC is focused not on the tech platforms supplying these tracking tools but on the organisations implementing them. In other words, if you own the website, you are responsible for how data is collected and disclosed. This includes cases where that data may be shared - intentionally or not - with platforms like Meta or Google via embedded code. For marketers, this raises pertinent questions. How many third-party tags are running on your website? Who installed them? What information are they collecting and where is it being sent? If your teams or agencies can’t answer these questions, you may already be exposed to compliance risk. Ending ambiguity: the role of education and governance It’s important to recognise that the OAIC’s enforcement strategy is not intending to “catch out” businesses, but rather to promote greater compliance and remove the grey areas that have allowed questionable practices to persist. The goal is a more transparent, consistent data governance environment - one where privacy is integrated from the start and embedded in every marketing and data decision. This means marketers must collaborate more closely with legal, compliance and data governance teams. They must understand the full lifecycle of the data they use - from collection and consent to storage, sharing and deletion. Just as importantly, they must ensure their teams are educated on privacy risks and equipped to apply privacy-by-design principles in campaign planning and execution. The road ahead As the Commissioner made clear, brands can’t count on a grace period and there is no more time to wait. The risk of non-compliance is rising - not just in terms of potential financial penalties but in reputational risk and customer trust. Marketers must take the lead in reviewing current practices, auditing data flows, tightening consent processes and questioning assumptions - including around de-identified data, data sharing, and AI training practices. This isn’t just about staying on the right side of the law. It’s about demonstrating to customers, boards and regulators that your business takes privacy seriously and is prepared to act. When the OAIC does come knocking, those who’ve taken this approach will have nothing to fear and everything to gain. Need to sharpen your privacy and compliance skills? Check out our regulatory course offering with a range of options to suit your needs. From our online short courses to our more comprehensive Privacy and Compliance for Marketers course, ADMA has your regulatory upskilling needs sorted. FIND OUT FIRST, STAY CONNECTED Sign up to receive ADMA newsletters, updates, trends, special offers, events, critical issues and more Job role*Agency Account Manager/ExecutiveAgency Account/Strategy DirectorCDOCEO / Managing DirectorClient Service / Sales ManagerClient Service/Sales DirectorCMO / CCO / Marketing DirectorCreative Director / HeadData Analyst / Scientist / EngineerDesigner/Copywriter/Creative ManagerEarly Career Data Analyst / Scientist / EngineerHead of Analytics / Analytics LeaderHead of Category/Customer Experience/InsightsHead of Marketing/BrandHead of ProductHR/Learning and Development ManagersIT Director/ManagerLegal/RegulatoryMarketing ConsultantMarketing Executive / CoordinatorMarketing Freelancer / ContractorProduct / Brand / Digital / Communication ManagerSenior Data Analyst / Scientist / EngineerSenior Marketing/Brand ManagerOther You may unsubscribe at any time using the link provided in the communication. View our Privacy Policy. Filter Resources Filter Courses Capability Capability Campaign Integration Compliance Customer Experience Marketing Technology Insights Learnings Brand Development Content Format Content Format Information sheet Member-only Press-release Article Blog Case Study Data Event Infographic Media Coverage Research Tool-kit Video Webinar Whitepaper Topics Topics CMO Crib Sheet CMO Spotlight Global Forum Global Forum 2023 Privacy series Resource Compliance Resources CEO Blog Compliance Regulatory Content Copywriting Creative Data Data-driven Marketing Digital Campaigns Leadership Social Media Thought Leadership 09th Jun 2022 13 mins Avoiding Deceptive Conduct: Charities, Social Media Influencers and Businesses Can All Get Caught It can be easy to get carried away with sales promises, headlines and great customer offers but Australian laws and regulators come down hard on misleading and deceptive conduct and claims. It's best to steer clear of deceptive and misleading conduct, read on how you can. 09th Jun 2022 17 mins Regulations for Competitions: Trade Promotion Rules Competitions and promotions are great to grab attention, generate conversation and gather data but there are plenty of rules to be considered before they are brought to life. 09th Jun 2022 17 mins Do Not Spam: Spam Regulations Spam is unsolicited electronic messages which usually arrive through email or SMS. Unwanted marketing messages is one thing, but these days spam can also be synonymous with scams, phishing and outright fraud where dangerous links and viruses can lead to theft and privacy breaches. Click to read more about Australia's Spam regulations.
09th Jun 2022 13 mins Avoiding Deceptive Conduct: Charities, Social Media Influencers and Businesses Can All Get Caught It can be easy to get carried away with sales promises, headlines and great customer offers but Australian laws and regulators come down hard on misleading and deceptive conduct and claims. It's best to steer clear of deceptive and misleading conduct, read on how you can.
09th Jun 2022 17 mins Regulations for Competitions: Trade Promotion Rules Competitions and promotions are great to grab attention, generate conversation and gather data but there are plenty of rules to be considered before they are brought to life.
09th Jun 2022 17 mins Do Not Spam: Spam Regulations Spam is unsolicited electronic messages which usually arrive through email or SMS. Unwanted marketing messages is one thing, but these days spam can also be synonymous with scams, phishing and outright fraud where dangerous links and viruses can lead to theft and privacy breaches. Click to read more about Australia's Spam regulations.