Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
AUDEEP coverage1 enforcement action

Australia — Privacy Act 1988 AI Obligations + Reform Watch (2024 Amendments): AI Compliance Requirements

Australia has no standalone mandatory AI law as of July 2026 (web-verified 2026-07-01), but two frameworks govern AI use of personal data. (1) Privacy Act 1988 (Cth) — enforced by the Office of the Australian Information Commissioner (OAIC) — requires transparency about automated decision-making, data minimisation, and individual access rights for any organisation with annual turnover over AUD $3 million. The OAIC's 2023 guidance on privacy and AI is the clearest compliance roadmap available. (2) The Australian Government's National AI Strategy and voluntary "Responsible AI for Government" principles set expectations for organisations operating in regulated industries (finance, healthcare, government). The Privacy and Other Legislation Amendment Act 2024 added an automated-decision-making transparency obligation that COMMENCES 10 December 2026: APP entities must update their privacy policy to disclose the kinds of decisions made wholly or substantially by automated systems that could significantly affect individuals (e.g. credit, insurance, employment, tenancy, services). Monitor OAIC and the Attorney-General's Department for further reform. (web-verified 2026-07-01)

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

December 21, 1988

Maximum Penalty

AUD $50 million, 30% of adjusted turnover, or 3× benefit obtained — for serious or repeated privacy interference (Privacy and Other Legislation Amendment Act 2024)

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Privacy Act Compliance for AI Systems (APP 1, 3, 11, 12, 13)

High Priority

The Privacy Act 1988 applies to any AI system processing personal information of Australian residents. Key obligations: (1) Disclose in your Privacy Policy that AI/automated processing is used and for what purpose (Australian Privacy Principle 1). (2) Collect only personal data that is reasonably necessary for your stated AI function (APP 3). (3) Allow individuals to access data used in automated decisions about them (APP 12). (4) Correct inaccurate data that feeds AI decisions (APP 13). Document your AI data flows for OAIC compliance readiness.

Deadline: December 21, 1988

Privacy Act 1988 (Cth), Australian Privacy Principles 1, 3, 11, 12, 13

Notifiable Data Breaches (NDB) — AI Incident Reporting

High Priority

Under the Notifiable Data Breaches scheme (Privacy Act Part IIIC), organisations must notify the OAIC and affected individuals when a data breach involving personal data is "likely to result in serious harm." AI system compromises — including unauthorised access to training data, model inversion attacks, or AI-generated output disclosing personal information — trigger NDB obligations. Notification must be made "as soon as practicable" (OAIC guidance: within 30 days of becoming aware). Failure to notify is now subject to the AUD $50 million penalty threshold under the 2024 amendments.

Privacy Act 1988 (Cth) Part IIIC

Automated-Decision-Making Transparency Obligation — Commences 10 December 2026

High Priority

The Privacy and Other Legislation Amendment Act 2024 added an automated-decision-making transparency obligation that COMMENCES 10 December 2026: APP entities must update their privacy policy to disclose the kinds of decisions made wholly or substantially by automated systems that could significantly affect individuals (e.g. credit, insurance, employment, tenancy, services). Separately, the government's Privacy Act Review report recommended a further explicit right to explanation for automated decisions, not yet enacted as of this cycle. Monitor oaic.gov.au and attorney-general.gov.au for: mandatory AI register requirements, right-to-explanation legislation, and sector-specific AI rules from ASIC (financial AI) and APRA (prudential AI).

Deadline: December 10, 2026

Privacy and Other Legislation Amendment Act 2024, amending Privacy Act 1988 (Cth) APP 1 (privacy-policy disclosure of automated decision-making)

Privacy Impact Assessment for AI Systems (OAIC 2023 Guidance)

Medium Priority

The OAIC's "Privacy and AI" guidance (2023) outlines expected practices: conduct Privacy Impact Assessments (PIAs) before deploying AI systems that process personal data at scale; implement human oversight for AI decisions with significant consequences; provide meaningful transparency notices (not buried in fine print); and establish a process for individuals to query or appeal AI-driven decisions. While currently voluntary for the private sector, a PIA is MANDATORY for Australian Government agencies (and their contractors) undertaking high-privacy-risk projects under the Australian Government Agencies Privacy Code cl. 12 — the AFP's 2023 Clearview AI trial was found to breach exactly this duty (see enforcementActions).

Australian Government Agencies Privacy Code cl. 12 (mandatory PIA for high-privacy-risk agency projects); OAIC "Privacy and AI" guidance (2023, voluntary for private sector)

Who Does This Apply To?

The Privacy Act 1988 applies to organisations with annual turnover exceeding AUD $3 million and to all federal government agencies (regardless of size). No turnover threshold for health service providers. Extraterritorial reach: applies to overseas organisations that collect or hold personal information of Australian residents and carry on a business in Australia. AI-specific: no AI Act exists yet — AI obligations flow from the Australian Privacy Principles (APPs). APP 1 (transparency), APP 3 (collection), APP 11 (security), APP 12 (access), and APP 13 (correction) are the primary AI compliance provisions. The Privacy and Other Legislation Amendment Act 2024 (passed November 2024) increased penalty limits to AUD $50 million and added an automated-decision-making transparency obligation that commences 10 December 2026 (privacy-policy disclosure of automated decisions that significantly affect individuals); further AI-specific provisions are expected in a subsequent reform bill. ASIC (financial AI), APRA (prudential AI), and TGA (medical AI) add sector-specific requirements on top of the Privacy Act.

Recent Enforcement Actions

2021-10-14Source verified· as of 2026-08-22

Against:

Source

Recent Regulatory Guidance

guidance2024-06

OAIC Privacy and AI Guidance (2023, updated 2024)

The Office of the Australian Information Commissioner's guidance on privacy and AI sets out how existing Australian Privacy Principles apply to AI systems. Key expectations: (1) Privacy Impact Assessments before deploying AI on personal data at scale; (2) Transparency notices must specifically name AI processing; (3) Human oversight for decisions with significant consequences; (4) Data minimisation — don't collect more data than needed for the AI function; (5) Individual query/appeal mechanisms for AI-driven decisions. Updated in 2024 to address generative AI: AI tools used by staff that could expose customer data require privacy risk assessment and staff training.

guidance2025-07

APRA — AI/GenAI under existing prudential standards (CPS 234 / CPG 234, CPS 230)

APRA has not issued a dedicated AI prudential standard or guide. AI/ML systems used by APRA-regulated entities (banks, insurers, superannuation funds) are governed by the EXISTING framework: CPS 234 Information Security (with its guide CPG 234 Information Security, June 2019) treats AI systems as information assets to be secured, and CPS 230 Operational Risk Management (effective 1 July 2025) brings AI-driven processes and material service providers within operational-risk and business-continuity controls. APRA has publicly identified AI/GenAI as a supervision focus, but firms should map AI governance to these existing standards rather than to any AI-specific APRA rule, which does not yet exist.

Key Case Law & Precedent

Australian Information Commissioner v Meta Platforms (Cambridge Analytica)

Federal Court of Australia · 2024

Outcome: Settled Dec 2024 via enforceable undertaking: AUD $50 million payment program for affected Australian users (no court liability finding; proceedings withdrawn).

Case reference

Australian Information Commissioner v Medibank Private Limited (2024)

Federal Court of Australia · 2024

Outcome: Civil penalty proceedings on foot (commenced 5 June 2024); up to AUD $2.22M per contravention of s 13G. No judgment yet as of mid-2026.

Case reference

Quarterly Enforcement Digest

CYCLE 4 UPDATE (2026-08-22): removed a reference to "the ASIC v. Mercer case" establishing AI-financial-advice disclosure standards — this pointed to the fabricated "ASIC v. Mercer Financial Advice — AI Recommendation Engine (2025)" entry, now removed from enforcementActions (verified this cycle: Mercer's two real recent penalties, AUD $11.3M for greenwashing in 2024 and AUD $10.3M for reportable-situations reporting failures in 2026, involve neither AI nor a recommendation engine). Australia is in active transition toward mandatory AI obligations regardless: the 2024 Privacy Act amendments raised the penalty ceiling to AUD $50 million. The OAIC's Clearview AI (2023-11-28) and AFP PIA-failure (2023-03-16) determinations confirmed biometric facial recognition requires explicit consent and a PIA before high-privacy-risk AI deployment. Most significant near-term item: the automated-decision-making transparency obligation (privacy-policy disclosure duty) COMMENCES 10 December 2026 under the 2024 amendments — organizations should have disclosure text ready well before that date. For SaaS companies with Australian clients: ensure your Privacy Policy names AI processing, your AI governance framework includes a PIA process, and your NDB procedures include AI incident scenarios.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering Australia — Privacy Act 1988 AI Obligations + Reform Watch (2024 Amendments)

These industry playbooks include jurisdiction-specific checklist items and guidance for Australia — Privacy Act 1988 AI Obligations + Reform Watch (2024 Amendments).

Frequently Asked Questions

Does Australia — Privacy Act 1988 AI Obligations + Reform Watch (2024 Amendments) apply to my business?

Australia has no standalone mandatory AI law as of July 2026 (web-verified 2026-07-01), but two frameworks govern AI use of personal data. (1) Privacy Act 1988 (Cth) — enforced by the Office of the Australian Information Commissioner (OAIC) —… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Australia — Privacy Act 1988 AI Obligations + Reform Watch (2024 Amendments) is: AUD $50 million, 30% of adjusted turnover, or 3× benefit obtained — for serious or repeated privacy interference (Privacy and Other Legislation Amendment Act 2024). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Australia — Privacy Act 1988 AI Obligations + Reform Watch (2024 Amendments)?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.oaic.gov.au/privacy/guidance-and-advice/privacy-and-ai

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan