Privacy Act 2026 AI Compliance Guide
The step by step companion to this checklist. Covers the law in plain language, how to identify ADM uses, and how to structure your privacy policy disclosures.
Interactive resource · Privacy Act readiness
Work through six areas covering AI inventory, automated decision-making disclosure, privacy and data handling, staff training, governance ownership and records. Your progress stays in this browser so you can return to it with the team.
Interactive checklist
Current progress
Area 01
You cannot govern what you have not mapped. These items build the inventory.
Area 02
From 10 December 2026, organisations must disclose in their privacy policy where AI makes or substantially assists decisions that significantly affect individuals.
Area 03
The Privacy Act reform tightened disclosure obligations and introduced enforcement teeth. The policy must reflect current AI use.
Area 04
Human error drove 37% of notifiable data breaches in H1 2025. Training reduces the risk before it becomes a breach.
Area 05
For Commonwealth agencies, naming accountability officials is already mandatory under the DTA policy. For private organisations, it is simply good practice.
Area 06
Governance is not a one-off exercise. These items keep the posture current as AI use evolves.
VibeZero works with Australian businesses on the practical side of Privacy Act compliance, AI governance, and data loss prevention. General information only, not legal advice.
This checklist is general information only, not legal advice. Your obligations depend on your specific circumstances. Consult a qualified legal or privacy professional for advice about your situation.
What this covers
01 · Inventory
Approved tools, shadow AI, data flows, offshore processing. You cannot disclose what you have not mapped.
02 · ADM disclosure
Identifying which AI uses are ADM under the Privacy Act and updating your privacy policy before 10 December 2026.
03 · Privacy policy
Policy currency, overseas disclosures, data minimisation, vendor retention terms, and breach surface awareness.
04 · People
Written policy distribution, rules on personal accounts, sensitive data categories, and incident reporting paths.
05 · Governance
Named accountability, new tool review process, vendor due diligence, and the AI register.
06 · Records
Annual review scheduling, mid cycle tool additions, policy review dates, and incident logging below threshold.
Legal basis
The legal basis for the key items is straightforward. The Privacy and Other Legislation Amendment Act 2024 (Cth) received Royal Assent on 10 December 2024. Automated decision-making transparency requirements commence 10 December 2026. The OAIC recorded 532 notifiable data breaches in H1 2025, with 37% attributed to human error. Infringement notices of up to $66,000 per contravention are available to the regulator under the reform. This checklist is general information only. See our AI governance field note for cited source material.
Companion resources
The step by step companion to this checklist. Covers the law in plain language, how to identify ADM uses, and how to structure your privacy policy disclosures.
An adaptable disclosure statement for your privacy policy. Covers the language the Privacy Act reform requires for automated decision-making disclosures.
Related services
FAQ
Turn the gaps into work