Skip to main content

    Compliance

    Assess the information practice, not the AI label.

    A privacy review should examine how personal information enters, moves through and leaves the actual workflow. The product name does not establish whether the arrangement is appropriate. This operational guide helps prepare the facts for assessment under the Privacy Act and Australian Privacy Principles where they apply.

    Start with applicability and purpose

    Confirm the entity's coverage, the activity and the kinds of information involved. Identify the intended purpose and how it relates to the organisation's existing information practices.

    Do not assume an existing database can automatically be used for any new AI task. Equally, do not reduce the analysis to a blanket rule that every use requires consent.

    Follow information through the system

    Document inputs, retrieval sources, prompts, generated outputs, storage, integrations and logs. Identify vendors and relevant processing arrangements.

    Who can access the information? What is retained? Can it be used for another purpose? Which locations and recipients matter?

    Unknown vendor settings are questions to resolve, not reassurance.

    Examine quality and effects on people

    AI can produce inaccurate information about an individual or derive new inferences from existing records. Establish how quality is assessed for the purpose and how errors will be identified and addressed.

    Consider the practical effect of the output, including whether it enters a significant decision. A low-cost tool can still create consequential information practices.

    Review safeguards and operation

    Access, confidentiality, security, deletion and retention need to reflect the information and use. Appropriate arrangements may include limiting inputs, restricting permissions, training users and evaluating outputs.

    A staff policy is one control, not evidence that all uses conform to it.

    Treat automated-decision disclosure separately

    The new APP 1 provisions add privacy-policy information requirements for arrangements that meet their conditions. They do not replace the rest of the privacy assessment or apply to every AI activity.

    Read the APP 1.7 scope and disclosure guide.

    Prepare a decision record

    Record the facts, assessment, specialist advice, allowed boundary, controls, owner and reassessment triggers. Where a material fact remains unknown, state what must be resolved before proceeding.

    This page is general guidance, not legal advice or a complete compliance determination.

    The 10 December 2026 deadline does not move. Request a Rapid Review to map automated decisions and the disclosure work still required.

    Request a Rapid Review

    Related Topics

    Explore This Pillar

    Go deeper with the matching master pillar and the most relevant supporting topics for this page.