Privacy Act 1988 — Automated Decision-Making Reforms
Obligations Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| Privacy and Other Legislation Amendment Act 2024 assented | Dec 10, 2024 | Schedule 1 Part 15 inserts APP 1.7-1.9 |
| ADM privacy-policy provisions commence | Dec 10, 2026 | Schedule 1 Part 15 commences after the 24-month period specified in section 2 |
Related Regulations and Standards
Related instruments are selected from shared compliance obligations and jurisdiction coverage.
Automated Decision-Making Transparency (APP 1.7/1.8)
From 10 December 2026, APP 1.7 requires an APP entity's privacy policy to contain the APP 1.8 information only when the entity has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision; the decision could reasonably be expected to significantly affect an individual's rights or interests; and personal information about that individual is used in the program for that decision or related thing. This is an APP-entity duty with statutory conditions, not a rule for every AI provider or every use of personal information.
Requirements
| Requirement | Details |
|---|---|
| Actor and arrangement | The actor is an APP entity that has arranged for a computer program to make a decision or do a thing substantially and directly related to making it |
| Significant-effect condition | The decision must be one that could reasonably be expected to significantly affect an individual's rights or interests, adversely or beneficially |
| Personal-information condition | Personal information about that individual must be used in the program to make the decision or do the substantially and directly related thing |
| Kinds of personal information | The privacy policy must state the kinds of personal information used in such programs |
| Solely automated decisions | The privacy policy must state the kinds of covered decisions made solely by such programs |
| Computer-assisted decisions | The privacy policy must state the kinds of covered decisions for which such programs do a thing substantially and directly related to making the decision |
| Application after commencement | The amendment applies to decisions made after 10 December 2026 even if the arrangement, data use, or acquisition or creation of the personal information occurred earlier |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | A breach of an APP can constitute an interference with privacy; remedies and penalties depend on the applicable Privacy Act enforcement provisions and facts |
Data Minimisation for AI Systems
APP 3 regulates an APP entity's collection of solicited personal information, and APP 6 restricts an APP entity's use or disclosure of personal information for a secondary purpose unless an exception applies. OAIC guidance applies those existing rules to covered AI collection, generation, inference, inputs, uses, and disclosures. It describes proportionality and data minimisation under APP 3 and recommends minimising personal information used or disclosed for an APP 6 secondary purpose. These are not duties on every AI system or new APP clauses commencing in December 2026.
Requirements
| Requirement | Details |
|---|---|
| APP 3 collection boundary | For non-sensitive personal information, an agency's collection must be reasonably necessary for, or directly related to, its functions or activities; an organisation's collection must be reasonably necessary for its functions or activities |
| Sensitive information and collection method | APP 3 adds consent or exception requirements for sensitive information and generally requires lawful and fair collection directly from the individual unless an exception applies |
| Proportionality and minimisation guidance | OAIC's APP 3 Guidelines say proportionality is implicit in reasonable necessity and that entities should limit collection to the minimum amount necessary in the circumstances |
| APP 6 purpose limitation | An APP entity must not use or disclose personal information for a secondary purpose unless consent or another APP 6 exception applies; reasonable-expectations exceptions require a related purpose, or a directly related purpose for sensitive information |
| AI-specific OAIC guidance | For AI uses, OAIC guidance tells organisations to identify whether an AI input is a use or disclosure, assess the primary purpose and any exception, and minimise the personal information used or disclosed for a secondary purpose |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | A breach of an APP can constitute an interference with privacy; remedies and penalties depend on the applicable Privacy Act enforcement provisions and facts |
Privacy Impact Assessments for AI
Review of APP 1.2 in the current Privacy Act compilation, the OAIC PIA Guide, and the OAIC commercial-AI guidance did not establish a generic private-sector PIA mandate for AI use. OAIC guidance says a PIA can assist an APP entity to identify practices, procedures, and systems that may be reasonable under APP 1.2, strongly encourages PIAs for projects involving personal information, and recommends a PIA when an organisation considers commercially available AI. The OAIC also states that not every project needs a PIA and that its power to direct agencies does not apply to private-sector organisations. A separate APP Code requires Australian Government agencies to conduct PIAs for high privacy risk projects; that Code mandate is not reclassified here as a Privacy Act AI obligation.
Requirements
| Requirement | Details |
|---|---|
| APP 1.2 relationship | OAIC says a PIA may assist an entity to demonstrate privacy compliance and identify practices, procedures, or systems that may be reasonable for new projects under APP 1.2 |
| Private-sector guidance | OAIC strongly encourages PIAs for projects involving personal information and says organisations considering AI products should take a privacy-by-design approach that includes a PIA; this guidance does not create a generic statutory PIA mandate |
| Project-specific threshold | OAIC says not every project needs a PIA and recommends a threshold assessment based on the project's handling of personal information and privacy risk |
| Separate agency mandate | The Privacy (Australian Government Agencies - Governance) APP Code 2017 separately requires covered Australian Government agencies to conduct a PIA for high privacy risk projects |
Penalties
| Violation | Fine |
|---|---|
| Private-sector PIA guidance | OAIC states that its power to direct agencies to undertake a PIA does not apply to private-sector organisations |
Cite this regulation
Permalink: https://everyailaw.com/regulation/au-privacy-act-adm/
JSON: https://everyailaw.com/api/v1/regulations.json
Attribution: EveryAILaw, PAICE.work PBC. “Privacy Act 1988 — Automated Decision-Making Reforms”, EveryAILaw.com, Jun 30, 2026. https://everyailaw.com/regulation/au-privacy-act-adm/
Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.