What enforcement has looked like since it began
Since active enforcement started, the Information Regulator's activity has moved from largely reactive, complaint-driven assessments toward more proactive investigation and clearer procedural expectations - most visibly through the April 2025 amendments tightening breach reporting and Information Officer obligations.[1]
What the pattern signals about priorities
| Signal | What it suggests |
|---|---|
| Mandatory eServices portal reporting | Breach response process is now a checkable compliance item, not just good practice |
| Expanded IO obligations | Regulator expects an actively engaged, not just nominally appointed, Information Officer |
| Instalment payment options for fines | Fines are expected to be used more routinely, not held in reserve for extreme cases |
What to check on your website now
- Confirm your Information Officer is registered and named in your privacy policy.
- Confirm someone in the organisation has eServices portal access and knows the reporting process.
- Re-check consent mechanisms against the "prior, opt-in" standard, not "continuing to browse."
- Confirm operator agreements exist for every third party processing data on your behalf.