Privacy Act 1988 — Automated Decision-Making Reforms

Jurisdiction:
Australia
enacted
Effective:
Dec 10, 2026
Authority:
Office of the Australian Information Commissioner
Official text

Obligations Covered

Transparency & Disclosure Data Governance

Timeline

MilestoneDateNotes
Privacy and Other Legislation Amendment Act 2024 assentedDec 10, 2024Schedule 1 Part 15 inserts APP 1.7-1.9
ADM privacy-policy provisions commenceDec 10, 2026Schedule 1 Part 15 commences after the 24-month period specified in section 2

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Automated Decision-Making Transparency (APP 1.7/1.8)

Copy link to this provision

Obligation:
Transparency
enacted
Effective:
Dec 10, 2026
Risk tier:
all
Scope:
APP entities meeting every condition in APP 1.7(a)-(c)
sleepercross-domainupcoming
From 10 December 2026, APP 1.7 requires an APP entity's privacy policy to contain the APP 1.8 information only when the entity has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision; the decision could reasonably be expected to significantly affect an individual's rights or interests; and personal information about that individual is used in the program for that decision or related thing. This is an APP-entity duty with statutory conditions, not a rule for every AI provider or every use of personal information.

Requirements

RequirementDetails
Actor and arrangementThe actor is an APP entity that has arranged for a computer program to make a decision or do a thing substantially and directly related to making it
Significant-effect conditionThe decision must be one that could reasonably be expected to significantly affect an individual's rights or interests, adversely or beneficially
Personal-information conditionPersonal information about that individual must be used in the program to make the decision or do the substantially and directly related thing
Kinds of personal informationThe privacy policy must state the kinds of personal information used in such programs
Solely automated decisionsThe privacy policy must state the kinds of covered decisions made solely by such programs
Computer-assisted decisionsThe privacy policy must state the kinds of covered decisions for which such programs do a thing substantially and directly related to making the decision
Application after commencementThe amendment applies to decisions made after 10 December 2026 even if the arrangement, data use, or acquisition or creation of the personal information occurred earlier

Penalties

ViolationFine
Non-complianceA breach of an APP can constitute an interference with privacy; remedies and penalties depend on the applicable Privacy Act enforcement provisions and facts

Data Minimisation for AI Systems

Copy link to this provision

Obligation:
Data Governance
enforcing
Effective:
Mar 12, 2014
Risk tier:
all
Scope:
APP entities when collecting, holding, using, or disclosing personal information in an AI context, subject to the Act's entity coverage and applicable exceptions
sleepercross-domain
APP 3 regulates an APP entity's collection of solicited personal information, and APP 6 restricts an APP entity's use or disclosure of personal information for a secondary purpose unless an exception applies. OAIC guidance applies those existing rules to covered AI collection, generation, inference, inputs, uses, and disclosures. It describes proportionality and data minimisation under APP 3 and recommends minimising personal information used or disclosed for an APP 6 secondary purpose. These are not duties on every AI system or new APP clauses commencing in December 2026.

Requirements

RequirementDetails
APP 3 collection boundaryFor non-sensitive personal information, an agency's collection must be reasonably necessary for, or directly related to, its functions or activities; an organisation's collection must be reasonably necessary for its functions or activities
Sensitive information and collection methodAPP 3 adds consent or exception requirements for sensitive information and generally requires lawful and fair collection directly from the individual unless an exception applies
Proportionality and minimisation guidanceOAIC's APP 3 Guidelines say proportionality is implicit in reasonable necessity and that entities should limit collection to the minimum amount necessary in the circumstances
APP 6 purpose limitationAn APP entity must not use or disclose personal information for a secondary purpose unless consent or another APP 6 exception applies; reasonable-expectations exceptions require a related purpose, or a directly related purpose for sensitive information
AI-specific OAIC guidanceFor AI uses, OAIC guidance tells organisations to identify whether an AI input is a use or disclosure, assess the primary purpose and any exception, and minimise the personal information used or disclosed for a secondary purpose

Penalties

ViolationFine
Non-complianceA breach of an APP can constitute an interference with privacy; remedies and penalties depend on the applicable Privacy Act enforcement provisions and facts

Privacy Impact Assessments for AI

Copy link to this provision

voluntary
Scope:
APP entities receive OAIC guidance and encouragement; Australian Government agencies have a separate high-privacy-risk-project mandate under the Privacy (Australian Government Agencies - Governance) APP Code 2017
sleeper
Review of APP 1.2 in the current Privacy Act compilation, the OAIC PIA Guide, and the OAIC commercial-AI guidance did not establish a generic private-sector PIA mandate for AI use. OAIC guidance says a PIA can assist an APP entity to identify practices, procedures, and systems that may be reasonable under APP 1.2, strongly encourages PIAs for projects involving personal information, and recommends a PIA when an organisation considers commercially available AI. The OAIC also states that not every project needs a PIA and that its power to direct agencies does not apply to private-sector organisations. A separate APP Code requires Australian Government agencies to conduct PIAs for high privacy risk projects; that Code mandate is not reclassified here as a Privacy Act AI obligation.

Requirements

RequirementDetails
APP 1.2 relationshipOAIC says a PIA may assist an entity to demonstrate privacy compliance and identify practices, procedures, or systems that may be reasonable for new projects under APP 1.2
Private-sector guidanceOAIC strongly encourages PIAs for projects involving personal information and says organisations considering AI products should take a privacy-by-design approach that includes a PIA; this guidance does not create a generic statutory PIA mandate
Project-specific thresholdOAIC says not every project needs a PIA and recommends a threshold assessment based on the project's handling of personal information and privacy risk
Separate agency mandateThe Privacy (Australian Government Agencies - Governance) APP Code 2017 separately requires covered Australian Government agencies to conduct a PIA for high privacy risk projects

Penalties

ViolationFine
Private-sector PIA guidanceOAIC states that its power to direct agencies to undertake a PIA does not apply to private-sector organisations
Cite this regulation

Permalink: https://everyailaw.com/regulation/au-privacy-act-adm/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Privacy Act 1988 — Automated Decision-Making Reforms”, EveryAILaw.com, Jun 30, 2026. https://everyailaw.com/regulation/au-privacy-act-adm/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.