← All Writing

4 Apr 2026·8 min read·Greg Turner

AI and Data Privacy: What Australian Businesses Need to Know

Australia’s privacy landscape is shifting. With the December 2026 automated decision-making deadline approaching, learn what AI privacy obligations mean for your business.

What This Article Covers

  1. Understanding Australia's current privacy framework and how it applies to AI.
  2. Key changes introduced by the 2024 Privacy Act reforms, including the December 2026 automated decision-making deadline.
  3. Common areas where AI systems create privacy risk for organisations.
  4. The role of the Voluntary AI Safety Standard and AI6 guidance in responsible AI governance.
  5. Practical steps to audit, govern, and future-proof your organisation's AI privacy practices.
  6. Common mistakes businesses make when deploying AI without adequate privacy consideration.
  7. How privacy-compliant AI builds trust and creates competitive advantage.

Who This Article Is For

  1. Business leaders responsible for AI strategy and digital transformation.
  2. Privacy officers and compliance managers assessing AI-related obligations.
  3. Technology leaders evaluating or deploying AI systems that handle personal information.
  4. Organisations preparing for the December 2026 automated decision-making transparency requirements.
  5. Teams seeking practical guidance on balancing AI innovation with privacy compliance.

Introduction

Artificial intelligence is transforming how Australian businesses operate, from automating customer service to analysing data at scale. But with that transformation comes a responsibility that many organisations are not yet prepared for: managing the privacy implications of AI.

Australia's privacy landscape is shifting significantly. The Privacy Act reforms passed in 2024 are introducing new obligations around automated decision-making, transparency, and accountability that will directly affect how businesses use AI. The deadline for key compliance requirements is December 2026, and organisations that wait until the last minute will find themselves scrambling.

This article explains what Australian businesses need to understand about AI and data privacy right now, what is changing, and what practical steps you can take to stay ahead.

The Current Privacy Landscape in Australia

The Privacy Act 1988 remains the primary law governing how personal information is handled in Australia. It applies to Australian Government agencies, private sector organisations with annual turnover exceeding $3 million, and certain smaller organisations in sectors like health and finance.

The Australian Privacy Principles (APPs) set out the rules for collecting, using, disclosing, and securing personal information. These principles are technology-neutral, which means they already apply to AI systems, even though they were written long before generative AI existed.

The Office of the Australian Information Commissioner (OAIC) has made this position clear: if your AI system collects, uses, or discloses personal information, the Privacy Act applies. There is no AI exemption.

What Is Changing: The 2024 Privacy Reforms

In November 2024, the Privacy and Other Legislation Amendment Act introduced the first tranche of significant reforms to the Privacy Act. These changes are rolling out progressively through 2025 and 2026, and several have direct implications for businesses using AI.

Automated Decision-Making Transparency

From 10 December 2026, organisations that use automated or semi-automated decision-making must disclose this in their privacy policies. Specifically, if your organisation uses a computer program to make decisions, or to substantially assist in making decisions, that could reasonably be expected to significantly affect an individual's rights or interests, you must describe the types of personal information used and the nature of the decisions being made.

This captures a broad range of AI applications, including AI-powered credit scoring, automated recruitment screening, algorithmic pricing, fraud detection systems, and customer service chatbots that make decisions about access to services or support.

Statutory Tort for Serious Privacy Invasions

Since June 2025, individuals have had the right to sue for serious invasions of privacy. This creates a direct litigation pathway that did not exist before. Organisations using AI to process personal information now face legal exposure not just from the regulator but from individuals whose privacy is breached.

Stronger Enforcement Powers

The OAIC now has expanded civil penalty powers, infringement notice capabilities, and stronger compliance tools. Penalties for serious or repeated breaches can reach up to the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover. The OAIC's first ever privacy compliance sweep, launched in January 2026, signals that enforcement is an active priority.

Where AI and Privacy Intersect

Understanding where AI creates privacy risk is the first step toward managing it. There are several common areas where AI systems interact with personal information in ways that require careful governance.

Data Collection and Consent

AI systems often require large volumes of data to function effectively. The question of whether that data was collected with appropriate consent, and whether individuals were informed about how their data would be used in AI processing, is fundamental. If you collected data for one purpose and are now feeding it into an AI system for a different purpose, you may be in breach of the APPs.

Automated Decisions Affecting Individuals

Any AI system that makes or influences decisions about individuals, from loan approvals to insurance pricing to job screening, falls squarely within the new transparency requirements. The question is not just whether the decision is fair, but whether individuals know it is being made by or with the assistance of a machine.

Data Quality and Accuracy

AI systems are only as good as the data they are trained on. If your training data contains errors, biases, or outdated information, the decisions your AI makes will reflect those problems. Under the Privacy Act, organisations have an obligation to take reasonable steps to ensure personal information is accurate, up-to-date, and complete.

Cross-Border Data Flows

Many AI tools, particularly cloud-based platforms and large language models, process data in overseas jurisdictions. Under the Privacy Act, organisations that disclose personal information overseas must take reasonable steps to ensure the overseas recipient handles the information in accordance with the APPs. This is not always straightforward when dealing with global AI providers.

Retention and Deletion

AI systems can make it difficult to delete personal information, particularly when that information has been used to train models. Organisations need to think carefully about data retention policies and whether their AI systems can support individuals' rights to have their information corrected or deleted.

The Voluntary AI Safety Standard and AI6

While the Privacy Act provides the legal framework, the Australian Government has also released voluntary guidance to help organisations govern AI responsibly.

The Voluntary AI Safety Standard (VAISS), released in September 2024, introduced 10 guardrails covering accountability, risk management, data governance, testing, human oversight, transparency, contestability, and record-keeping.

In October 2025, the National AI Centre updated this guidance with the Guidance for AI Adoption, which condenses the 10 guardrails into six essential practices known as AI6. This is now the primary source of voluntary governance guidance for Australian organisations.

The December 2025 National AI Plan confirmed that Australia will rely on existing laws and sector regulators rather than introducing standalone AI legislation for now, supported by a new AI Safety Institute rolling out from early 2026. However, the alignment between the voluntary guardrails and the proposed mandatory guardrails signals clearly where regulation is heading. Organisations that adopt AI6 now will be better positioned if and when mandatory requirements arrive.

Practical Steps for Australian Businesses

Audit Your AI Systems

Start by identifying every AI system your organisation uses or plans to use that involves personal information. This includes third-party tools, not just systems you have built. For each system, document what personal information it processes, how that information was collected, what decisions it makes or influences, and where the data is stored and processed.

Update Your Privacy Policy

The December 2026 deadline for automated decision-making transparency is approaching. Review your privacy policy now. If any of your AI systems make or substantially assist in making decisions that could significantly affect individuals, your privacy policy needs to describe this clearly. Do not wait until November 2026 to start this work.

Review Consent and Collection Practices

Check whether the personal information you are feeding into AI systems was collected with appropriate consent for that use. If you collected data for one purpose and are now repurposing it for AI analysis or decision-making, you may need to obtain fresh consent or assess whether a permitted use exception applies.

Implement Data Governance

Establish clear data governance practices for AI, including data quality checks before information enters AI systems, processes for identifying and correcting biased or inaccurate data, retention policies that account for AI training data, and procedures for handling deletion requests when data has been used in AI models.

Ensure Human Oversight

For AI systems that make decisions affecting individuals, build in meaningful human oversight. This does not mean a human rubber-stamps every AI decision. It means there are processes for humans to review, intervene in, and override AI decisions, particularly where those decisions have significant consequences.

Assess Third-Party AI Providers

If you use third-party AI platforms, assess how they handle personal information. Where is the data processed? What security measures are in place? Can the provider support your obligations under the Privacy Act, including responding to access and correction requests? Document these assessments and include appropriate contractual protections.

Train Your Team

Privacy is not just a legal or IT issue. Everyone in your organisation who works with AI or personal information needs to understand the basics of privacy compliance. This includes understanding when and how to escalate privacy concerns, and knowing what the organisation's obligations are under the Privacy Act.

Common Mistakes to Avoid

Assuming AI Tools Are Automatically Compliant

Many businesses adopt AI tools from reputable providers and assume the provider has handled privacy compliance. This is not how the Privacy Act works. The obligation sits with your organisation, not the tool provider. You are responsible for how personal information is used within your operations, regardless of the technology platform.

Treating Privacy as an Afterthought

Bolting privacy controls onto an AI system after it has been deployed is far more expensive and disruptive than building them in from the start. Privacy impact assessments should be part of the planning process for any AI initiative, not something that gets added at the end.

Ignoring the December 2026 Deadline

The automated decision-making transparency obligations take effect on 10 December 2026. This applies to any decision made on or after that date, regardless of when the underlying AI system was deployed. If your systems are already in use, you need to be compliant by that date.

Conclusion: Privacy Is a Competitive Advantage

Organisations that get AI privacy right will not just avoid penalties and litigation. They will build the kind of trust with customers, employees, and partners that creates lasting competitive advantage. In an environment where data breaches regularly make headlines, demonstrating that your organisation handles personal information responsibly, particularly in the context of AI, is a genuine differentiator.

The regulatory direction is clear. The OAIC is actively enforcing privacy obligations. The December 2026 deadline is approaching. And further reforms are expected. The organisations that act now will be the ones best positioned to use AI confidently and responsibly.

At Humanising Technologies, we help organisations design and implement AI systems that are practical, effective, and privacy-compliant from the ground up. We understand both the technology and the regulatory landscape, and we focus on building solutions that work within Australian legal requirements.

Ready to make sure your AI systems are privacy-ready? Contact us to discuss your situation.

Related reading:

Working through something like this?

A short description of the problem is enough to start.

Contact Us
Next Article The Hidden Costs of Getting AI Wrong