2025 – A Litigation Risk Primer

Last year brought in a significant number of regulatory, governance and geo-political changes. As we start the new year, it is an opportune time to reflect on some of these changes and whether you have in place adequate systems and procedures to mitigate your risk.
February 11 2025

By Monique Carroll, Partner, Emma Berkeley, Lawyer and Jazmine Rosart

In the article below we consider the changes to privacy legislation and the new statutory tort of serious breach of privacy, climate change reporting, the failure to prevent foreign bribery offence and managing geo-political risk.

The spotlight on privacy

In November 2024, the Commonwealth Parliament passed the Privacy and Other Legislation Amendment Bill 2024 (Cth) (the Bill), now referred to as the Privacy and Other Legislation Amendment Act 2024 (Cth) (the Amendment Act).

The Amendment Act amends the Privacy Act 1988 (Cth) (the Act) (amongst others) and introduces a:

  • new civil penalty provision (with a maximum penalty of 2,000 penalty units (currently $660,000)) for doing an act or engaging in a practice that is an interference with the privacy of an individual. Previously the Act only contained a civil penalty provision for repeated or serious interferences with privacy.  An interference with privacy under the Act is a failure of an APP entity (an entity subject to the Australian Privacy Principles (APPs)) to comply with the APPs contained in Schedule 1 of the Act; and
  • statutory tort for serious invasions of privacy from:
    • intruding upon a plaintiff’s seclusion (including by physically intruding on their private space or watching, listening to or recording a person’s private activities); and/or
    • misusing information that relates to a person.

The statutory tort – more detail

The statutory tort for serious invasion of privacy (applicable from 10 June 2025) does not require proof of damage to be actionable but does require the plaintiff to establish that:

  1. they had an expectation of privacy in all the circumstances;
  2. the invasion of privacy was serious, and, intentional or reckless; and
  3. the public interest in the plaintiff’s privacy outweighed any countervailing public interest.

The Explanatory Memorandum to the Bill provides that ‘intentional’ has its ordinary meaning.  The defendant’s intent may be subjective or imputed, and the intention must be to invade a person’s privacy by intrusion on or misuse of information.  In other intentional torts, the proof of intention of a corporation is assessed by determining the intention of the directing mind and will of the corporation, being directors or individuals charged with a relevantly high degree of responsibility.  The Explanatory Memorandum to the Bill also provides that ‘reckless’ is defined as having the same meaning as in the Criminal Code Act 1995 (Cth).  In respect of an individual, recklessness will be established if the person is aware of a substantial risk and having regard to the circumstances known to him or her is unjustified in taking that risk.  In respect of a corporation, recklessness will be established where it is shown that the corporation expressly, tacitly or impliedly authorised or permitted the act, here being the invasion of privacy.

In the United Kingdom, the tort of misuse of private information was a part of Meghan Markle’s successful litigation against the publisher Associated Newspapers, where it was found that the publisher misused her private information in publishing a personal letter she wrote to her father.[1]  The law was also at play in the case settled between Prince Harry and Murdoch owned News Group Newspapers (NGN), where NGN acknowledged and apologised for phone hacking, surveillance and misuse of the Prince’s private information by journalists and private investigators.[2]

In Victoria, Judge Tran of the County Court awarded $30,000 in damages for common law invasion of privacy in June 2024, before the Bill went into effect, to a woman whose privacy was invaded when her father published her private information which he gathered from joint counselling sessions regarding the mother’s attempted murder of the father.[3]  Judge Tran recognised a common law action for invasion of privacy as part of the available actions in respect of the tort of breach of confidence.  It was held that such tort not only protects confidential trade information but also provides redress to natural persons to ‘protect human dignity in privacy’.

What you need to do

First, we recommend undertaking an assessment of the extent to which you or your organisation currently monitors individuals or their activities or collects their data, and whether this has been consented to.

Secondly, it will be necessary to review your privacy policies and procedures to ensure that they cover the new risks and include an adequate regime for identifying and reporting breaches or potential breaches.

Lastly, we recommend undertaking training for your employees and representatives with a high degree of responsibility.  Any failure to comply with the APPs, even when adequate policies and procedures are in place, can give rise to liability under the new civil penalty provision.

Climate change risk and reporting

On 1 January 2025, the Treasury Laws Amendment (Financial Market Infrastructure and Other Measures) Act 2024 (Cth) (the FMI Act) became effective thereby amending the Australian Securities and Investments Commission Act 2001 (Cth) (ASIC Act) and the Corporations Act 2001 (Cth) (Corporations Act).  Entities which are required to file financial reports, or entities registered under the National Greenhouse and Energy Reporting Act 2007 (Cth), and which meet certain threshold ‘size’ requirements are required to file an annual sustainability report for the proceeding financial years.  There is a phased introduction for smaller entities up until 1 July 2027.

The annual sustainability report must disclose a number of matters including:

  1. material climate related financial risks and opportunities for the entity;
  2. governance structures in place to monitor and manage those risks and opportunities; and
  3. metrics concerning scope 1, 2 and 3 greenhouse gas emissions, which are defined by the Australian Sustainability Reporting Standards set by the Australian Accounting Standards Board (AASB).

The Corporations Act now contains a number of specific provisions providing for the content of a sustainability report and how it is to be prepared and audited, including that:

  • Entities must keep sustainability records which correctly explain and record the preparation of the substantive provisions of the sustainability report and be retained for 7 years (section 286A).
  • Annual sustainability reports are to include:
    • climate statements for the year and any notes to those statements; and
    • a directors’ declaration declaring that in the directors’ opinion the substantive portions of the sustainability report are in compliance with the Corporations Act (section 296A).
  • If ASIC considers that a statement made by an entity in a sustainability report is incorrect, incomplete or misleading, it can direct the entity to provide further explanation or provide ASIC with information that could substantiate or support the statement (section 296E).
  • A reporting entity must have their sustainability report for the financial year audited in accordance auditing standards (section 301A).
  • An auditor of a sustainability report must form an opinion about whether:
    • the report complies with the Corporations Act (section 307AA); and
    • they have been given sufficient information to conduct the audit, and whether the entity that prepared the report has kept sufficient records for the report to be prepared and audited.
  • The AASB may by legislative instrument, make sustainability standards for the purposes of the Corporations Act or the ASIC Act (section 336A).

What you need to do

In addition to understanding whether and when your entity is required to file an annual sustainability report, it is important that your entity understands the increased transparency applicable to all entities in respect of sustainability records and reporting, as this reporting requirement will impact a vast majority of the supply chain.

The reporting requirement will result in a high degree of disclosure regarding climate change impacts and much greater discourse around which entities are managing climate change risk and sustainability and which are not.  Even if you are not an entity to which the sustainability reporting requirements apply, it can be expected that many of your customers will be and will exert pressure for your entity to meet their sustainability standards.

The increased disclosure will also bring increased litigation risk.  In particular, statements made regarding sustainability and greenhouse gas emissions to your customers (or the public generally) must be accurate and supported by objective evidence.  If they are not, parties who have relied upon them may have a claim against you.  ASIC may also take enforcement action.

Immunity

Section 1707D of the Corporations Act provides a limited immunity from legal action in relation to certain ‘protected’ statements.

A statement is a ‘protected statement’ if it relates to future matters and is:

  • made in a sustainability report, for a financial year commencing during the 3 years starting on the start date, as that term is defined, for the purpose of complying with a sustainability standard; or
  • made in an auditor’s report of an audit or review of a sustainability report mentioned directly above for the purpose of complying with the Corporations Act or the auditing standards, and
  • concerns any of the following:
    • scope 3 greenhouse gas emissions (including financed emissions);
    • climate-related scenario analysis (as, outlined in the AASB Sustainability Standards as effectively being a mechanism to assess an entity’s climate resilience); or
    • a climate-related transition plan (as defined in the AASB Sustainability Standards as ‘[a]n aspect of an entity’s overall strategy that lays out the entity’s targets, actions or resources for its transition towards a lower-carbon economy, including actions such as reducing its greenhouse gas emissions’, or
  • made in a sustainability report, for a financial year commencing during the 12 months starting on the start date, as that term is defined, for the purpose of complying with a sustainability standard; or
  • made in an auditor’s report of an audit or review of a sustainability report mentioned directly above for the purpose of complying with the Corporations Act or the auditing standards, and
    • relates to climate; and
    • at the time it is made, is about the future.

The immunity at section 1707D(1) of the Corporations Act does not apply to an action, suit or proceeding if it is criminal in nature or brought by ASIC.  For example, section 286A of the Corporations Act, being the obligation to keep and retain written sustainability records, holds a penalty of 2 years imprisonment for the fault based offence, or a penalty of 60 penalty units (currently $19,800) for the strict liability offence.  And, non-compliance with ASIC directions required by section 296E of the Corporations Act, is a strict liability offence with a penalty of 60 penalty units (currently $19,800).

Sustainability reports for all financial years will also be subject to the liability framework which existed prior to the FMI Act. This includes provisions under the Corporations Act and ASIC Act in respect of director’s duties, misleading and deceptive conduct and general disclosure obligations including the obligation to keep accurate financial records.

ASIC has indicated that:

  • its early enforcement efforts will be focused on serious misconduct such as misconduct that would cause harm to investors or the primary users of the information;
  • its first annual climate-related disclosures surveillance program will begin in 2026 after the first reports are made under the regime and will generally reflect the surveillance program currently in place with respect to annual financial reporting;
  • it will make a public report on its findings with a goal of continued improvement in reporting standards; and
  • it will use its information-gathering and new direction powers to require an entity to provide further explanation or documentation if it considers that the statement may be incorrect or incomplete.

The failure to prevent bribery offence

Overview

In 2024 the Criminal Code Act 1995 (Cth) was amended by the Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024 (Cth) so as to include provisions making corporations liable for the offence of failing to prevent foreign bribery.

The Crimes Legislation Amendment (Combatting Foreign Bribery) Bill 2023 (Bill 2023), which was used to introduce the new offence, sought to address previous challenges with investigating and prosecuting cases of foreign bribery related to Australia.  In particular, the Explanatory Memorandum to the Bill provides that the new offence is ‘designed to overcome challenges in establishing criminal liability of businesses that engage in wilful blindness with respect to misconduct by their employees and other associates and is intended to incentivise businesses to implement and maintain adequate procedures to prevent foreign bribery from occurring’.

The amendment brings Australia’s legislation in line with that of the United Kingdom such that a corporate intention need not be established.  Rather, an offence can be committed if an ‘associate’ of the corporation committed the bribery and the corporation failed to implement ‘adequate procedures’ aimed at preventing foreign bribery from occurring.

An ‘associate’ of a corporation include its:

  • officers, agents, employees, contractors or anyone who performs services for or on its behalf;
  • subsidiaries within the meaning of the Corporations Act; and
  • controlled entities within the meaning of the Corporations Act (the definition of which includes entities over which the corporation has the capacity to determine decisions regarding financial and operating policies).

The maximum penalty for the failure to prevent bribery offence is the greatest of either:

  • 100,000 penalty units (currently $33 million);
  • the value of the benefit obtained or sought to be obtained by the associate; or
  • if the above cannot be determined, 10% of the annual turnover of the corporation in the 12 months prior to the offence taking place.

If a corporation can establish that it had in place adequate procedures to prevent the commission of foreign bribery, this will act as a defence.  In this way, the new offence is intended to act as a positive incentive for corporations to implement and maintain best practice procedures.  A similar provision was introduced in the United Kingdom in 2011.  The provision has been used to successfully prosecute several companies and has had the desired effect of increased adoption of effective corporate compliance programs to prevent bribery.[4]

What you need to do

Corporations need to conduct a risk assessment which takes into account the role and operations of each of its associates or categories of associates and then implement policies and procedures aimed at mitigating the risk of foreign bribery by the associates.

The Attorney-General’s guidance on adequate procedures can be viewed here: https://www.ag.gov.au/crime/publications/guidance-adequate-procedures-prevent-commission-foreign-bribery.  We can also advise you on whether particular policies and procedures are adequately tailored to the risk faced by your organisation.

Geo-political risk

Overview

2024 saw a continuation of disruption, changing geopolitical dynamics and broadening of commercial risk, including from an increasing number of companies entering insolvency or administration.  In this environment, which looks set to continue into 2025, it is integral to ensure that your contracts are enforceable from a legal and practical perspective.  This is especially so, if the counterparty resides outside of Australia or has no or little assets in Australia.

What you need to do

Ideally questions concerning the legal and practical enforcement of contracts should be considered at the earliest stages of contract drafting and negotiation.  Whilst it is often imperative to ensure that the applicable forum of dispute resolution is capable of producing a legally enforceable arbitral award, the considerations often go beyond this to include the capitalisation of the contracting party and the formalities required in the relevant jurisdiction for that party to enter into a binding contract.  These are matters which may require due diligence and consideration at the beginning of negotiations.

If you are investing overseas, you may also wish to consider and take advantage of any protections available for your investment under international law.

If you have already taken these steps, the start of the year is a good opportunity to consider whether your organisation’s business operations have since changed and if so, the consequent changes to the risk assessment and systems and procedures in place.

Conclusion

With ever increasing regulatory requirements and geo-political uncertainty, risk can be mitigated by regular and robust reviews as to how you are conducting business.

Please don’t hesitate to contact us for assistance in conducting these reviews.

[1] Jill Lawless, ‘UK judge says newspaper invaded Meghan’s privacy with letter’, The Associated Press (Web Page, 12 February 2021) <https://apnews.com/article/meghan-markle-privacy-lawsuit-fa0f447e403e0df077ea60af7ba0f071>.

[2] Brian Melley and Jill Lawless, ‘Prince Harry gets apology, big settlement from Murdoch’s UK tabloids over intrusion’, The Associated Press (Web Page, 22 January 2025) <https://globalnews.ca/news/10971730/prince-harry-settlement-apology-rupert-murdoch-uk-tabloids-intrusion-princess-diana/>.

[3] Waller (A Pseudonym) v Barrett (A Pseudonym) [2024] VCC 962, see [297]-[320], in particular [315]-[319].

[4] Commonwealth, Second Reading Speech, House of Representatives, 22 June 2023, 5016 (Mark Dreyfus, Attorney-General and Cabinet Secretary).