TechGurus
Strategy Automation Intelligence
Client login ↗Book a Strategy Call
Resources / Guide

What Australian privacy law asks of you

Whether the Privacy Act applies to your business, the four principles an AI project actually touches, and the disclosure rule for automated decisions arriving in December 2026.

7 minute readWritten for owners and operations managers

Most owners we talk to know the Privacy Act exists and are not sure whether it applies to them. That uncertainty turns into one of two mistakes: assuming none of it is their problem, or assuming all of it is and stalling a project that was never at risk.

What follows is a plain-language tour of what the law asks and where AI work touches it. It is general information rather than legal advice, and the Office of the Australian Information Commissioner publishes the detail for free if you want to go further.

Does it apply to you?

The Privacy Act 1988 and its thirteen Australian Privacy Principles apply to Australian businesses with an annual turnover above $3 million. Below that, most businesses are exempt. Not all of them, though, and the exceptions catch more organisations than people expect.

Regardless of turnover, the Act applies to health service providers, which takes in allied health, care and disability providers and anyone else holding health information. It also applies to businesses that trade in personal information, to credit reporting bodies, and to contractors delivering services under a Commonwealth contract.

The small business exemption has also been under review for years, and removing it has been recommended. If you are under the threshold today and specifying a system meant to last five years, it is not something to build on.

And even where the Act does not reach you, the obligations often arrive by contract instead. Supplier agreements, insurer requirements and government or NDIS arrangements routinely ask for the same handling standards the Act describes.

The principles an AI project actually touches

Thirteen principles is a lot to hold in your head, and most of them are about collection practices that will not change because you added an automation. Four of them do change.

What it asksWhat that means for an AI project
APP 1: opennessKeep a current privacy policy describing how you handle personal informationIf a new tool now processes client records, the policy has to say so. This is the step most commonly skipped
APP 6: use and disclosureUse information for the purpose you collected it forPutting client records through a third-party tool is usually a disclosure. Check it sits inside the purpose you told people about
APP 8: sending it overseasYou remain accountable for information disclosed to an overseas recipientKnow which country your vendor processes in and what the agreement commits them to. Responsibility does not transfer with the data
APP 11: security and disposalProtect it, and destroy or de-identify it when it is no longer neededIncludes the chat histories, uploaded files and logs that accumulate quietly inside a tool nobody is watching

Almost every privacy problem we are called into starts the same way: the business did not know where its data had already been sent.

If something goes wrong

The Notifiable Data Breaches scheme sets out what happens next. If you have grounds to suspect a breach, you are expected to assess it promptly, and the Act allows thirty days to complete that assessment. If it is an eligible data breach, meaning one likely to result in serious harm, you notify the affected individuals and the Commissioner as soon as practicable.

Most breaches are undramatic: a spreadsheet sent to the wrong address, a shared login nobody retired. The useful preparation is not a thick document. It is deciding now who makes the assessment, and making sure they will hear about it.

The change worth knowing about

The 2024 amendments to the Act added a requirement that privacy policies disclose where automated systems are used to make, or substantially influence, decisions that significantly affect a person's rights or interests. It commences in December 2026, so it is worth confirming the current position rather than taking this page as the last word.

If you have already decided where your systems may act alone and where a person stays in the loop, the practical effect is small: you are writing down something you know. If you cannot say which decisions your systems make without a human, having to publish it forces the question, which is arguably the point of the requirement.

What to do this quarter

Four things, none of which need a lawyer to begin. Know what personal information you hold and where it lives. Know which third parties it reaches, AI vendors included. Read your own privacy policy and check it still describes the business you are running. And decide, before you need to, who assesses a suspected breach.

The short version

If your turnover is above three million, or you hold health information, the Act applies and the four principles above are the ones an AI project touches. If it does not apply to you yet, your clients' contracts probably ask for much the same, and the exemption may not last. Either way the work is identical: know what you hold, know where it goes, and make sure what you have written down matches what actually happens.

Not sure where your data has already been sent?

The Shadow AI Audit shows you which tools your team is using and what they are being given, which is where most of these answers start.

Start the audit →
Keep reading