Work with us
AI regulation in Australia / Privacy Act 1988 / Australian Privacy Principles

Privacy Act 1988 / Australian Privacy Principles

Personal information handled by or through an AI tool falls under the same collection, use, disclosure and security rules as any other personal information. The law most Australian businesses using AI are actually bound by.

Status
In force · Australia (Commonwealth) · OAIC
Applies to
APP entities: businesses with annual turnover over $3 million, and some smaller businesses regardless of size (health service providers, businesses that trade in personal information, Commonwealth contractors, others)
Primary source
Official document →
Last reviewed
28 September 2026

What it is

The Privacy Act 1988 and its thirteen Australian Privacy Principles are the law that governs how organisations collect, hold, use and disclose personal information. It says nothing about AI by name and does not need to: when personal information goes into an AI tool, or comes out of one, the Act applies exactly as it would to a spreadsheet or an email. The regulator, the OAIC, has said so directly in its guidance on using commercially available AI products. For most Australian businesses using AI today, this is the binding law, not any AI-specific rule.

What it requires

The principles that do the work with AI are these. Collection (APP 3 and 5): if you collect personal information through an AI system, for example a customer-facing chatbot, the usual rules on necessity, notice and consent apply, and the OAIC treats information an AI generates or infers about a person as a collection too. Use and disclosure (APP 6): putting personal information into an AI tool is a use if the information stays under your control and a disclosure if it does not. Entering it into a public chatbot is a disclosure to the chatbot’s owner, and the OAIC’s stated best practice is that organisations “do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools”. Accuracy (APP 10): you must take reasonable steps to keep the information you use accurate and complete, which matters when a model summarises or infers. Security (APP 11): you must protect the information from misuse and unauthorised access, and destroy it when no longer needed. Transparency (APP 1): your privacy policy must describe what you do, and from 10 December 2026 must also explain automated decisions that significantly affect people (that reform has its own entry on the map). Serious or repeated breaches carry civil penalties of up to the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover, and eligible data breaches must be notified.

Does this reach your business?

If your annual turnover is over $3 million, yes. If it is $3 million or less, yes if you are a health service provider, trade in personal information, hold a Commonwealth contract, are a credit reporting body, operate a residential tenancy database, are a reporting entity under anti-money-laundering law, are accredited under the Consumer Data Right, are related to a covered business, or have opted in. Otherwise the small business exemption still applies as at September 2026; the government has agreed in principle to remove it and has not yet legislated to do so. Whichever side of the line you are on, your larger customers are covered, and their contracts will pass the obligations to you.

What we recommend

Our advice is to treat one rule as non-negotiable and build the rest around it: personal information does not go into public AI tools. Then, for every AI system your team uses, write down what personal information it can see, whether that information leaves your control (a disclosure) or not (a use), and whether the purpose is one the person would reasonably expect. If any system collects, generates or infers information about people, or makes decisions about them, run a privacy impact assessment before it goes live; the OAIC will ask whether you did. Update your privacy policy to say what AI you use with personal information, and put the 10 December 2026 automated decision-making change in your calendar now. The record this produces, system by system, is the same record Certrak keeps, and it is what the OAIC’s first privacy policy sweep in January 2026 went looking for.

Questions people ask

Yes, whenever personal information goes in or comes out. The Act is technology neutral, and the OAIC has published guidance applying it to commercially available AI products.

It is a disclosure of that information to the chatbot's owner, which must be permitted under APP 6. The OAIC's best-practice position is not to enter personal information into public generative AI tools at all.

Only if your turnover exceeds $3 million or you fall into a covered category such as health service provider, trader in personal information or Commonwealth contractor. The exemption for other small businesses remains in force as at September 2026, although the government has agreed in principle to remove it.

For a serious or repeated interference with privacy, up to the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover, since December 2022.

The OAIC recommends one whenever an AI use could affect people's privacy, as part of a privacy-by-design approach. It is the fastest way to answer the questions the regulator will ask.