6 Apr 2026·6 min read·Greg Turner
AI and the Privacy Act 2024 Amendments: What Australian Businesses Must Know
Australia's 2024 Privacy Act amendments introduce significant new obligations for businesses using AI. Here's what you need to know before the key deadlines.

What This Article Covers
Who This Article Is For
Introduction
Australia's privacy law is changing, and artificial intelligence is at the centre of those changes. The Privacy and Other Legislation Amendment Act 2024, passed in late 2024, introduces the most significant reforms to the Privacy Act 1988 in over a decade. For Australian businesses using AI — whether to make lending decisions, screen job applicants, personalise content, or automate customer service — the implications are substantial. This is not a distant compliance deadline. The provisions around automated decision-making, transparency notices, and children's privacy come into effect progressively through 2025 and 2026. Businesses that treat this as an IT problem or a legal formality are taking a significant risk. The organisations that get ahead now will have a structural advantage in how they build, deploy, and govern AI systems. This article breaks down what changed, what it means for AI specifically, and what your organisation should be doing right now.What Changed in the 2024 Privacy Act Amendments
The 2024 amendments address several areas directly relevant to AI deployment. The most significant are the new transparency requirements, the introduction of a right to explanation for automated decisions, and strengthened consent obligations around sensitive information. The transparency requirements mean that organisations must now clearly communicate when and how automated systems make decisions that significantly affect individuals. If your AI is determining credit eligibility, filtering job applications, setting insurance premiums, or personalising health-related recommendations, you will need to tell people that, explain the logic in plain language, and provide a pathway to human review. This is a meaningful shift. Previously, many businesses buried AI decision-making in lengthy privacy policies that few people read. The amended Act requires active disclosure — not just disclosure available somewhere.The Automated Decision-Making Provisions
The automated decision-making provisions are the area of greatest practical impact for AI teams. They establish that individuals have a right to know when a decision about them has been made using automated means, to understand the basis of that decision, and in some circumstances to request human review. The obligations apply where automated decisions have a "significant effect" on an individual. The Act defines this broadly enough to capture most commercially significant AI use cases: financial decisions, employment screening, healthcare recommendations, access to services, and pricing. Businesses need to map their AI systems now. Which ones are making or significantly influencing decisions about individuals? What data are they using? Can those decisions be explained in plain language? Is there a human review pathway? These questions need answers before the provisions take effect.Consent, Sensitive Information, and AI Training Data
The amended Act also tightens consent requirements around sensitive information, which includes health data, biometric data, racial or ethnic origin, political opinions, and sexual orientation. This matters for AI in two ways. First, if your AI system processes sensitive information to make decisions, consent requirements are now more stringent. Bundled consent buried in terms and conditions is increasingly difficult to defend. Consent must be informed, specific, and freely given. Second, if you are training AI models using data that includes sensitive information — even aggregate or anonymised data — you need to examine whether your original collection consents covered that use. Many organisations are sitting on datasets collected for one purpose and now being used to train models for another. That gap is a compliance risk.The Children's Privacy Provisions
The 2024 amendments introduce stronger protections for children's data, requiring organisations to take reasonable steps to verify age where services are likely to be accessed by under-18s, and to apply the highest available privacy protections to children's data by default. For AI systems that interact with consumers — recommendation engines, chatbots, content personalisation, behavioural analytics — this means verifying whether minors are likely users and adjusting data handling accordingly. It is not enough to say "our terms prohibit under-18s" if your product is actually used by them.What the Australian Privacy Principles Mean for AI Governance
The existing Australian Privacy Principles (APPs) have always applied to AI, but the 2024 amendments clarify and strengthen their application. APP 1 (open and transparent management of personal information) now has more teeth: your privacy policy must accurately describe AI decision-making, and the Office of the Australian Information Commissioner (OAIC) has indicated it will be scrutinising this more closely. APP 3 (collection of solicited personal information) requires that you only collect information reasonably necessary for your functions. If you are collecting granular behavioural data to feed AI systems, you need to be able to justify each data point against a specific business need. The "collect everything and figure it out later" approach is no longer defensible. APP 11 (security of personal information) extends to AI systems. If a model trained on personal data is breached, stolen, or used in ways that expose the training data, that is an APP 11 issue. Model security is privacy security.Practical Steps to Take Now
The businesses that will navigate the 2024 amendments well are those that treat compliance as a design challenge rather than a documentation exercise. There are five practical areas to address. The first is AI inventory and impact assessment. Map every AI system that touches personal information. Document what data it uses, what decisions it influences, and whether those decisions have significant effects on individuals. This inventory is the foundation of everything else. The second is privacy notices and transparency. Review every customer-facing privacy notice against the new transparency requirements. If an AI is making or influencing decisions about your customers, your notice needs to say so clearly, explain the logic, and describe the review pathway. The third is consent architecture. Audit existing consents, particularly for sensitive information and AI training data. Where consents do not clearly cover current AI uses, you will need to either re-consent or stop using that data. The fourth is human review processes. For any AI making significant decisions about individuals, establish a documented human review pathway. This does not need to be a complex system, but it does need to be real, accessible, and staffed. The fifth is governance documentation. The OAIC is moving toward requiring organisations to demonstrate privacy-by-design in AI development. Document your AI governance processes, risk assessments, and the steps you took to embed privacy into system design.The Competitive Upside of Getting This Right
There is a tendency to frame privacy compliance as a cost. The 2024 amendments are an opportunity for businesses that think differently. Customers increasingly understand that their data is being used by AI systems, and they are making choices based on which organisations they trust with that data. Organisations that can demonstrate transparent, responsible AI — that can show customers how decisions are made and give them meaningful control — will differentiate in markets where trust is scarce. The compliance floor is rising. Building above it is a strategic choice.Related reading:
- AI and data privacy in Australia
- managing risk in AI systems
- explainable AI for compliance
- AI procurement in Queensland
Conclusion
The 2024 Privacy Act amendments represent a genuine shift in the obligations Australian businesses face when deploying AI. The automated decision-making provisions, strengthened consent requirements, children's privacy protections, and transparency obligations collectively raise the bar significantly. The organisations that will handle this well are those that start now — mapping their AI systems, reviewing their privacy architecture, and building governance processes that can demonstrate compliance rather than simply assert it. If you are not sure where your organisation stands, a good starting point is understanding your current AI readiness across governance, data, and risk. Contact us to talk through your specific situation.Working through something like this?
A short description of the problem is enough to start.