Does Privacy Act 1988 — Automated Decision-Making Reforms require Data Governance?

Australia • enacted

Yes — 1 provision

Requirements at a glance

This regulation imposes 5 specific requirements for Data Governance across 1 provision:

Data Minimisation for AI Systems

Copy link to this provision

Obligation:
Data Governance
enforcing
Effective:
Mar 12, 2014
Risk tier:
all
Scope:
APP entities when collecting, holding, using, or disclosing personal information in an AI context, subject to the Act's entity coverage and applicable exceptions
sleepercross-domain
APP 3 regulates an APP entity's collection of solicited personal information, and APP 6 restricts an APP entity's use or disclosure of personal information for a secondary purpose unless an exception applies. OAIC guidance applies those existing rules to covered AI collection, generation, inference, inputs, uses, and disclosures. It describes proportionality and data minimisation under APP 3 and recommends minimising personal information used or disclosed for an APP 6 secondary purpose. These are not duties on every AI system or new APP clauses commencing in December 2026.

Requirements

RequirementDetails
APP 3 collection boundaryFor non-sensitive personal information, an agency's collection must be reasonably necessary for, or directly related to, its functions or activities; an organisation's collection must be reasonably necessary for its functions or activities
Sensitive information and collection methodAPP 3 adds consent or exception requirements for sensitive information and generally requires lawful and fair collection directly from the individual unless an exception applies
Proportionality and minimisation guidanceOAIC's APP 3 Guidelines say proportionality is implicit in reasonable necessity and that entities should limit collection to the minimum amount necessary in the circumstances
APP 6 purpose limitationAn APP entity must not use or disclose personal information for a secondary purpose unless consent or another APP 6 exception applies; reasonable-expectations exceptions require a related purpose, or a directly related purpose for sensitive information
AI-specific OAIC guidanceFor AI uses, OAIC guidance tells organisations to identify whether an AI input is a use or disclosure, assess the primary purpose and any exception, and minimise the personal information used or disclosed for a secondary purpose

Penalties

ViolationFine
Non-complianceA breach of an APP can constitute an interference with privacy; remedies and penalties depend on the applicable Privacy Act enforcement provisions and facts
View full regulation View obligation Obligation matrix