Risk Of Non-Compliance
The risk of non-compliance is the exposure an organisation carries when it fails to meet an obligation that applies to it. In Australia that exposure is financial, criminal and reputational, and its scale has shifted. Penalties once treated as a cost of doing business now reach into the millions, and in some cases into prison sentences.
The privacy regime shows how far it has moved. In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties over a data breach affecting more than 223,000 people. These were the first civil penalties ever ordered under the Privacy Act 1988. Most of it, $4.2 million, was for failing to take reasonable steps to protect the information the company held. Two further penalties of $800,000 each followed from not assessing the breach promptly and not notifying the Commissioner as soon as practicable.
One detail in that judgment deserves more attention than the headline figure. The Court reduced the penalty in part because the company had started a programme of work to lift its cyber security capability, which the judge accepted showed meaningful steps towards a satisfactory culture of compliance. What an organisation can demonstrate it did, and when it did it, changes the outcome.
The exposure reaches well beyond privacy. Since 1 January 2025, intentionally underpaying employees has been a criminal offence under the Fair Work Act, with a maximum of 10 years imprisonment for individuals. Serious interferences with privacy now carry maximum civil penalties of the greater of $50 million, three times any benefit obtained, or 30% of adjusted turnover.
In everyday practice, the risk usually surfaces through:
- Privacy and how personal information is collected, stored and disposed of
- Internet and social media use that exposes confidential or personal information
- Workplace policies people have genuinely read and accepted, not just been sent
- Records management that evidences who did what, and when, if you are ever asked
Obligations differ across states and territories and change over time, so treat this as general information rather than legal advice and take proper advice on anything contentious. Browse Sentrient’s workplace compliance training courses to see how these areas are covered.
The 7 Steps Good Businesses Take To Mitigate The Risk Of Non-Compliance
Quick Answer: To mitigate the risk of non-compliance, work through seven steps: recognise where your real exposure sits, accept that the law applies regardless of your size or location, build training and policies as your reasonable steps defence, apply the ‘your honour’ test to decisions, make sure people can identify, report and resolve incidents, hold […]
Employee Privacy Breach | Employer Fined $60,000 | What Can We Learn?
Case Study: A Thursday Morning Nobody Planned For Picture this: it is Thursday morning. The compliance manager at a mid-size Australian organisation arrives at the office, coffee in hand, ready for an ordinary day. By 10 am, three employees are sitting in front of them, visibly upset. What followed was a serious employee privacy breach: […]
Understanding Workplace Online Privacy of Employees | FAQs
When it comes to creating an ideal workplace, workplace online privacy is an aspect that can’t be ignored. The online privacy of employees is a responsibility that falls on the shoulders of leaders. 2019 saw one of the biggest data leaks in history. Over 540 million records about Facebook users were publicly exposed. 146 gigabytes […]
Step #7 Send A Clear Message From Top Down
Let’s not even get into corporate jargon around leadership, culture and engagement. Instead, let’s reflect on some old-school wisdom. A wise person once said that the best thing a father can do for their children is to love their mother. Why is this so important in the make-up of a family unit? Yes, it is […]
