Privacy Act reform and AI: preparing for automated decision transparency
What tightening Australian privacy expectations around automated decision-making mean for organisations already running AI in customer-facing processes.
The direction of travel
Australian privacy reform has moved steadily toward greater transparency about how personal information is used in automated decisions, alongside stronger expectations on fairness, retention and security.
For organisations running AI in customer or employee processes, the practical consequence is documentation. You need to be able to say which decisions involve automation, what information feeds them, and what a person can do about the outcome.
Start with the decisions, not the models
Work backwards from decisions that affect people: eligibility, pricing, prioritisation, screening, escalation, service refusal. For each one, establish whether an automated system contributes to the outcome and how heavily.
Many organisations discover automation in places they never classified as AI — scoring rules inside a CRM, a triage model inside a vendor platform, a ranking feature switched on by default.
Notice that actually informs
A privacy notice that mentions automation in a clause nobody reads will not satisfy a regulator or a complainant. Say plainly which kinds of decisions involve automated processing and what information is used.
Keep the notice consistent with the inventory. Divergence between what your policy claims and what your systems do is the failure mode that turns a complaint into a finding.
Make human oversight defensible
Human oversight only counts when the reviewer has the information, the authority and the time to reach a different conclusion. A queue of two hundred approvals per hour is not oversight.
Record what the reviewer saw, what they decided and how often they diverged from the automated recommendation. A divergence rate of zero over months is itself a finding.
Want this assessed against your environment?
Send us the specifics and a senior advisor will respond within one business day.
Data minimisation and retention
AI programmes tend to accumulate data because more data feels safer. Privacy obligations push the other way. Define what the system genuinely needs, exclude the rest, and set retention for prompts, outputs and logs the way you would for any other record.
Prompt and output logs frequently contain personal information nobody planned for. Classify and retain them accordingly.
What to do in the next quarter
Identify automated decisions affecting people, confirm the notice matches reality, evidence human oversight for the highest-impact ones, set retention on AI logs, and record vendor data-use and residency positions.
General information only — not legal advice. Confirm your specific obligations with your legal adviser and current OAIC guidance.
Sources and further reading
- OAIC guidance on privacy and the Privacy Act
- Australia's AI Ethics Principles
- ISO/IEC 42001 AI management systems
This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.
Related reading
Securing enterprise AI adoption: a practical AI security control set
The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.
Read articleAI risk assessment: how to assess an AI system before it ships
A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.
Read articleISO 42001 vs ISO 27001: how the two management systems interlock
What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.
Read article