Skip to content

Interactive resource · Privacy Act readiness

Privacy Act 2026 AI compliance checklist

Work through six areas covering AI inventory, automated decision-making disclosure, privacy and data handling, staff training, governance ownership and records. Your progress stays in this browser so you can return to it with the team.

Self assessment only · general information, not legal advice
self-assessment items
31observed
governance areas
Sixobserved
ADM requirements commence
10 Dec 2026context

Interactive checklist

Self assessment only · general information, not legal advice

Work through the current state with your team

Tick each item as you verify it. Progress is stored in this browser so you can return to the same device later.

Current progress

0 of 31 items complete

0%

Loading saved progress from this browser…

Area 01

Know your AI use

0/5

You cannot govern what you have not mapped. These items build the inventory.

Area 02

Automated decision-making disclosure

0/5

From 10 December 2026, organisations must disclose in their privacy policy where AI makes or substantially assists decisions that significantly affect individuals.

Area 03

Privacy policy and data handling

0/6

The Privacy Act reform tightened disclosure obligations and introduced enforcement teeth. The policy must reflect current AI use.

Area 04

Staff and training

0/5

Human error drove 37% of notifiable data breaches in H1 2025. Training reduces the risk before it becomes a breach.

Area 05

Governance and ownership

0/5

For Commonwealth agencies, naming accountability officials is already mandatory under the DTA policy. For private organisations, it is simply good practice.

Area 06

Records and review

0/5

Governance is not a one-off exercise. These items keep the posture current as AI use evolves.

Want help closing the gaps?

VibeZero works with Australian businesses on the practical side of Privacy Act compliance, AI governance, and data loss prevention. General information only, not legal advice.

This checklist is general information only, not legal advice. Your obligations depend on your specific circumstances. Consult a qualified legal or privacy professional for advice about your situation.

What this covers

Six areas, 31 items

The sequence moves from finding the tools through to maintaining the records.
  1. 01 · Inventory

    Know your AI use

    Approved tools, shadow AI, data flows, offshore processing. You cannot disclose what you have not mapped.

  2. 02 · ADM disclosure

    Automated decision-making

    Identifying which AI uses are ADM under the Privacy Act and updating your privacy policy before 10 December 2026.

  3. 03 · Privacy policy

    Data handling

    Policy currency, overseas disclosures, data minimisation, vendor retention terms, and breach surface awareness.

  4. 04 · People

    Staff and training

    Written policy distribution, rules on personal accounts, sensitive data categories, and incident reporting paths.

  5. 05 · Governance

    Ownership

    Named accountability, new tool review process, vendor due diligence, and the AI register.

  6. 06 · Records

    Review cadence

    Annual review scheduling, mid cycle tool additions, policy review dates, and incident logging below threshold.

Legal basis

The dates are fixed. The application depends on your circumstances

The legal basis for the key items is straightforward. The Privacy and Other Legislation Amendment Act 2024 (Cth) received Royal Assent on 10 December 2024. Automated decision-making transparency requirements commence 10 December 2026. The OAIC recorded 532 notifiable data breaches in H1 2025, with 37% attributed to human error. Infringement notices of up to $66,000 per contravention are available to the regulator under the reform. This checklist is general information only. See our AI governance field note for cited source material.

Companion resources

Go deeper with the guides

Use the detailed walkthrough and disclosure template alongside the self assessment. None of these resources are legal advice.
Compliance guide

Privacy Act 2026 AI Compliance Guide

The step by step companion to this checklist. Covers the law in plain language, how to identify ADM uses, and how to structure your privacy policy disclosures.

Read more
Template

ADM Disclosure Template

An adaptable disclosure statement for your privacy policy. Covers the language the Privacy Act reform requires for automated decision-making disclosures.

Read more

Related services

Bring in help where the checklist exposes a gap

VibeZero works with Australian businesses on the practical side of Privacy Act compliance, AI governance, and data loss prevention. General information only, not legal advice.

FAQ

Frequently asked questions

Turn the gaps into work

The checklist shows the baseline. A limited review turns it into a plan

Bring the incomplete items and we will help you separate the urgent privacy work from the useful governance improvements.
General information only · not legal advice