Does the Privacy Act apply to your AI project?
The Privacy Act 1988 applies to most Australian Government agencies and to many private organisations, including those with annual turnover above AU$3 million and some smaller ones, such as health service providers. Its thirteen Australian Privacy Principles (APPs) cover the life cycle of personal information. This is general information and not legal advice, so confirm how the Act applies to your organisation with qualified counsel.
Personal information is information or an opinion about an identifiable individual. In AI projects it appears in more places than people expect: customer emails fed to an assistant, call recordings, documents with names and addresses, prompts typed by staff, and logs.
Which APPs matter most for AI?
| Principle | What it asks | What it means for an AI project |
|---|---|---|
| APP 1 | Open and transparent management of personal information | Keep a current privacy policy that describes AI uses |
| APP 3 and 5 | Collect only what is reasonably necessary, and notify individuals | Limit data fed to the system and update collection notices |
| APP 6 | Use and disclose for the purpose collected, or a related purpose people would expect | Check that the AI use falls within the original purpose |
| APP 8 | Cross-border disclosure of personal information | Know who receives data overseas, including model providers |
| APP 10 and 13 | Quality of information, and correction | Test accuracy and provide a way to correct outputs and sources |
| APP 11 | Security, destruction and de-identification | Access control, retention limits and deletion of prompts and logs |
The Office of the Australian Information Commissioner (OAIC) has published guidance on privacy and the use of commercially available AI products and on developing and training generative AI models. Read it with your counsel.
What is changing with automated decisions?
Privacy reforms passed in December 2024 added new obligations. One requires entities that use automated decision-making to say so in their privacy policies where decisions significantly affect individuals' rights or interests. That obligation is scheduled to start in December 2026, so it is close. The reforms also created a statutory tort for serious invasions of privacy. Confirm details and dates with counsel.
The practical response is simple: inventory the automated decisions your systems make or support, document the data they use, and keep a route for human review.
Can personal information go to a team or provider overseas?
APP 8 says that before disclosing personal information to an overseas recipient, an organisation must take reasonable steps to ensure the recipient does not breach the APPs, and in many cases the organisation remains accountable for the recipient's acts. For AI work the overseas recipient might be a development partner, a cloud service or a model provider. Common controls follow.
- Keep production data in an Australian cloud region, in your own account.
- Use masked or synthetic data for development and testing.
- Limit and log access by offshore engineers, and revoke it when the work ends.
- Put binding contract terms in place, including breach notification and deletion.
- Check each model provider's retention and training terms, and choose options that do not use your data to train their models.
How do you handle data residency?
AWS, Azure and Google Cloud all operate regions in Sydney and Melbourne. Residency is often a procurement requirement for government, health and financial services, whether or not the Act demands it. It has limits to check early: not every model or feature is hosted in every Australian region, and some services process requests elsewhere. Confirm in writing where prompts, outputs and logs are processed and stored.
Regulated financial entities should also consider APRA standards on information security (CPS 234) and operational risk, including service providers (CPS 230). Government suppliers are often asked about IRAP-assessed cloud services.
What counts as sensitive information, and why does it matter?
Sensitive information is a subset of personal information. It includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation and biometric data, among other categories. The APPs generally require consent to collect it, and expectations for its security are higher.
In AI projects it often arrives by accident: a support assistant that receives a medical detail in a free-text message, or a document pipeline that reads a licence containing a photo. Design for it. Detect and redact where you can, restrict who may view transcripts, and decide in advance what the assistant does when someone volunteers sensitive details.
What evidence will procurement and risk teams ask for?
- A data inventory and flow diagram naming every system, region and provider that touches personal information.
- Test results on realistic samples, with the types of error found and how each is handled.
- An access register for engineers and vendors, with the dates access was granted and removed.
- A description of human oversight, and of how individuals can ask for correction.
- A change log showing what altered between releases, including model and prompt changes.
Preparing these as you build is far easier than assembling them under a deadline.
A practical checklist before you build
- Write the purpose and check it against the purposes for which the personal information was collected.
- Inventory the data entering prompts, retrieval, logs and training sets.
- Run a privacy impact assessment with your privacy officer. The OAIC encourages one for projects with high privacy risk.
- Decide where data lives and who can reach it, including offshore engineers and model providers.
- Test for accuracy on realistic samples and plan how errors are corrected.
- Update notices and policies to describe the AI use and any automated decisions.
- Keep a human route for decisions that significantly affect people, with a record of who decided.
Where to start
Choose one narrow use case and pilot it on masked data in an Australian region. Our page on AI development for Australian businesses explains the working rhythm across the time difference, our document AI and automation service covers paperwork-heavy workflows, and you can try the live document AI demo or contact us.