New privacy laws change the rules on workplace surveillance
Technology makes it easy to watch everything. Depending on your business, you might have access to emails, GPS tracking, screen monitoring, CCTV and message logs.
Most small and medium businesses have these tools to increase productivity, safety or security. There usually introduced with good intentions, but sometimes without much thought.
In June 2025, a new statutory tort for serious invasions of privacy came into effect. Individuals can now take court action if their privacy is seriously invaded.
That changes the risk calculation for employers.
How have Australia’s privacy laws changed?
Under amendments to the Privacy Act 1988, a person can sue if:
- their privacy was seriously invaded
- they had a reasonable expectation of privacy
- the conduct was intentional or reckless
- the invasion was serious
They don’t need to prove financial loss. Harm to dignity or emotional distress, may be enough.
This reform targets conduct that crosses the line. Workplace monitoring is where that line can be blurry.
Monitoring is now a bigger risk for small business
Large organisations usually have legal teams reviewing surveillance policies. SMEs often don’t.
Monitoring tools are affordable, accessible and increasingly built into everyday systems. It’s easy to implement them without fully assessing if they are necessary or proportionate.
Examples that may increase risk if not clearly justified or supported by policy include:
- Opening an employee’s private social media accounts on a work device out of suspicion or curiosity, rather than as part of a documented investigation.
- Installing GPS tracking on company vehicles for safety, then using the information to question why someone stopped for coffee, even though breaks are permitted.
- Checking CCTV footage to see who arrived late, when the cameras were introduced for security purposes.
- Using remote log-in data to monitor if someone was online late at night or on weekends, without a genuine operational reason.
- Accessing a former employee’s email account out of curiosity rather than for a clear business need, such as protecting client relationships or investigating misconduct.
On their own, these decisions might feel like a part of normal management. But if they’re deliberate, disproportionate, or drift beyond their original purpose, they can put you at risk.
If a staff member has a reasonable expectation of privacy and the intrusion is serious, your business could face litigation.

Monitoring needs to serve a business purpose
Just because you can monitor staff, should you?
Before introducing or continuing monitoring, employers should ask:
- What problem are we trying to solve?
- Is monitoring genuinely required?
- Is there a less intrusive way to manage the risk?
- Have employees been clearly informed?
- Is this consistent with our policies?
- Would we be comfortable explaining this decision in court?
If monitoring serves a legitimate business purpose, is clearly communicated and is limited to what’s reasonably required, the risk is lower.
Privacy reform changes how employers manage staff data
The new tort reflects a broader cultural shift. Privacy is increasingly recognised as a right individuals can actively enforce.
For SMEs, that means privacy decisions need to be deliberate, documented and defensible.
Now is the time to review your workplace surveillance practices, revisit your policies and brief your managers. Ensure access to personal information is limited, controlled and clearly justified.
If monitoring is genuinely necessary for safety, compliance or a legitimate business reasons, these reforms shouldn’t worry you.
Technology will continue to evolve. But if monitoring is introduced simply because the capability exists, it’s worth considering where you stand.
Seek advice early
If you’re unsure whether your current workplace surveillance practices go too far, contact us to discuss in detail. A practical review now can help reduce risk and give you confidence on where you stand.
Read more about the statutory tort for serious invasions of privacy: Office of the Australian Information Commissioner website

