Skip to content

Interactive Privacy Act resource

Privacy Act AI compliance checklist for 2026

Record what is in place across AI inventory, automated decision disclosure, privacy and data handling, staff training, governance and records. Your answers stay in this browser so you can return to them with the team.

This is general information, not legal advice. Reviewed 1 September 2026.

Interactive checklist

A tick records your answer. It does not test the control or confirm legal compliance.

Record the current state while the evidence is in front of you

Expand one area at a time. Tick an item only when you can point to a policy, setting, register entry or other record that supports the answer.

Work area

Record what is in place

Expand an area and tick only what you can support with a policy, system setting, register entry or other record.

Know your AI use0 of 5 recorded

Start with a record of the tools, data and accounts already in use. The list will change as staff adopt new products.

  • Recommended control
  • Recommended control
  • Depends on scope

    Overseas disclosure can engage APP 8 and must also be addressed in an APP privacy policy where the relevant conditions apply.

  • Recommended control

    This includes ChatGPT, Gemini, Claude and similar services used outside approved business accounts.

  • Recommended control

Automated decision making disclosure0 of 5 recorded

From 10 December 2026, new APP privacy policy requirements apply when the statutory conditions for automated decisions are met.

  • Depends on scope

    The additional APP 1 requirements apply where the decision could reasonably be expected to significantly affect a person’s rights or interests.

  • Legal requirement

    This requirement commences on 10 December 2026 for APP entities where the statutory conditions are met.

  • Recommended control

    Use the template as a drafting aid, then check it against the way the system works. Open the ADM disclosure template

  • Depends on scope
  • Recommended control

Privacy policy and data handling0 of 6 recorded

Compare the public policy with the systems people use now. A policy that describes last year’s process will not do the job.

  • Legal requirement
  • Depends on scope
  • Recommended control
  • Recommended control
  • Recommended control

    The OAIC received 532 data breach notifications from January to June 2025. Human error accounted for 37 per cent of them.

  • Legal requirement

    OAIC can use compliance action and infringement notices for certain foundational privacy policy breaches.

Staff and training0 of 5 recorded

Written rules are useful only when staff know what they mean for the work they do each day.

  • Recommended control
  • Recommended control
  • Recommended control
  • Recommended control
  • Recommended control

Governance and ownership0 of 5 recorded

Put a name against decisions and record what was checked before a tool reaches live work.

  • Recommended control
  • Recommended control
  • Recommended control
  • Recommended control
  • Depends on scope

    Most substantive privacy and responsible information sharing provisions commenced on 1 July 2026. Serious breach reporting commences on 1 January 2027.

Records and review0 of 5 recorded

Keep the record current when tools, settings, vendors or business processes change.

  • Recommended control
  • Recommended control
  • Recommended control
  • Recommended control

Response summary

No responses are recorded yet

Use the unticked items as a discussion list. They are not findings and they do not establish whether the organisation complies with the law.

This checklist is general information, not legal advice. Your obligations depend on your circumstances. Obtain advice from a qualified legal or privacy professional where needed.

Current legal position

The commencement dates are fixed. The scope depends on the entity and the system

APP 1.7 to 1.9 commence on 10 December 2026. They require an APP privacy policy to contain additional information where an entity has arranged for a computer program to use personal information to make a decision, or do something substantially and directly related to making it, and the decision could reasonably be expected to significantly affect a person’s rights or interests. In WA, most substantive PRIS Act provisions commenced on 1 July 2026. Serious breach reporting under that Act commences on 1 January 2027.

Companion resources

Use the guide and template where the checklist needs more detail

The guide explains the preparation work. The template gives you a disclosure draft to adapt to the system and decision.
Compliance guide

Privacy Act 2026 AI Compliance Guide

The detailed companion to this checklist explains the law in plain language, how to identify covered automated decisions and what an APP privacy policy needs to address.

Read about Privacy Act 2026 AI Compliance Guide
Template

ADM Disclosure Template

An adaptable starting point for an APP privacy policy disclosure. Check the wording against the way your systems and decisions work.

Read about ADM Disclosure Template

FAQ

Frequently asked questions

From 10 December 2026, APP entities must add information to their APP privacy policy if they arrange for a computer program to make a decision, or do something substantially and directly related to making it, where personal information is used and the decision could reasonably be expected to significantly affect a person’s rights or interests. APP 1.8 sets out the kinds of information the policy must include.

Turn the gaps into work

The checklist records the answers and a review checks the work behind them

Bring the unticked items and the records behind the answers. We will help separate implementation work from questions that need legal advice.
This is general information, not legal advice.