Privacy Act 2026 AI Compliance Guide
The detailed companion to this checklist explains the law in plain language, how to identify covered automated decisions and what an APP privacy policy needs to address.
Interactive Privacy Act resource
Record what is in place across AI inventory, automated decision disclosure, privacy and data handling, staff training, governance and records. Your answers stay in this browser so you can return to them with the team.
Interactive checklist
Work area
Expand an area and tick only what you can support with a policy, system setting, register entry or other record.
Start with a record of the tools, data and accounts already in use. The list will change as staff adopt new products.
Overseas disclosure can engage APP 8 and must also be addressed in an APP privacy policy where the relevant conditions apply.
This includes ChatGPT, Gemini, Claude and similar services used outside approved business accounts.
From 10 December 2026, new APP privacy policy requirements apply when the statutory conditions for automated decisions are met.
The additional APP 1 requirements apply where the decision could reasonably be expected to significantly affect a person’s rights or interests.
This requirement commences on 10 December 2026 for APP entities where the statutory conditions are met.
Use the template as a drafting aid, then check it against the way the system works. Open the ADM disclosure template
Compare the public policy with the systems people use now. A policy that describes last year’s process will not do the job.
The OAIC received 532 data breach notifications from January to June 2025. Human error accounted for 37 per cent of them.
OAIC can use compliance action and infringement notices for certain foundational privacy policy breaches.
Written rules are useful only when staff know what they mean for the work they do each day.
Put a name against decisions and record what was checked before a tool reaches live work.
Most substantive privacy and responsible information sharing provisions commenced on 1 July 2026. Serious breach reporting commences on 1 January 2027.
Keep the record current when tools, settings, vendors or business processes change.
Response summary
Use the unticked items as a discussion list. They are not findings and they do not establish whether the organisation complies with the law.
This checklist is general information, not legal advice. Your obligations depend on your circumstances. Obtain advice from a qualified legal or privacy professional where needed.
Current legal position
APP 1.7 to 1.9 commence on 10 December 2026. They require an APP privacy policy to contain additional information where an entity has arranged for a computer program to use personal information to make a decision, or do something substantially and directly related to making it, and the decision could reasonably be expected to significantly affect a person’s rights or interests. In WA, most substantive PRIS Act provisions commenced on 1 July 2026. Serious breach reporting under that Act commences on 1 January 2027.
Companion resources
The detailed companion to this checklist explains the law in plain language, how to identify covered automated decisions and what an APP privacy policy needs to address.
An adaptable starting point for an APP privacy policy disclosure. Check the wording against the way your systems and decisions work.
FAQ
From 10 December 2026, APP entities must add information to their APP privacy policy if they arrange for a computer program to make a decision, or do something substantially and directly related to making it, where personal information is used and the decision could reasonably be expected to significantly affect a person’s rights or interests. APP 1.8 sets out the kinds of information the policy must include.
Turn the gaps into work