APP 11 and AI Processing
APP 11 requires reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. When AI processes personal data, APP 11 applies to that processing. No exceptions.
Here's where most organisations get caught: consumer AI subscriptions don't meet enterprise security requirements. If your marketing team is pasting customer data into ChatGPT on a personal account, or your HR team is screening CVs through an AI tool without enterprise data agreements, that's likely an APP 11 breach.
The AI tool's terms of service don't replace your obligations under the Privacy Act. Your organisation is the data controller. The AI provider is a processor. You're responsible for ensuring adequate protection regardless of which tool your team chooses to use.
Practical steps:
- Audit which AI tools across your organisation process personal information
- Verify enterprise-grade security controls and data processing agreements for each
- Confirm data sovereignty (personal information processed offshore creates additional obligations)
- Establish policies that prohibit consumer AI accounts for processing business or customer data
- Document data flows between your systems and AI providers
The ADM Transparency Requirement
The Privacy and Other Legislation Amendment Act 2024 added a mandatory transparency requirement for automated decision-making. By 10 December 2026, organisations must update their privacy policies to disclose:
- Which automated decision-making systems they use
- How those systems affect individuals' rights or interests
- What information feeds into those decisions
The scope covers any automated system that "significantly affects rights or interests." That includes credit scoring, insurance premium calculations, fraud detection, HR screening, automated claims processing, and customer service routing. If the system makes a decision about a person without human review, it's almost certainly in scope.
This isn't a best-practice recommendation. It's law. Non-compliance after 10 December 2026 is a legislative breach subject to OAIC enforcement.
The OAIC Privacy Sweep
OAIC launched an active Privacy Sweep in January 2026, targeting 60 entities across property, retail, car rental, venues, chemists, and pawnbrokers. The focus: in-person data collection practices and privacy policy compliance.
Penalties reach $66,000 per non-compliant privacy policy. That's the current enforcement environment, before the ADM deadline even hits.
The sweep signals where OAIC's attention is directed. Organisations with outdated privacy policies, missing disclosure statements, or no mention of automated processing are getting enforcement notices, not warnings. This trend will intensify as the December deadline approaches.
Data Sovereignty Considerations
When AI processes personal information on overseas servers, additional Privacy Act obligations apply. Australian data processed by US-based AI providers sits under a different legal jurisdiction. Your organisation remains liable for that data regardless of where it's processed.
28% of enterprises downloaded OpenAI's Atlas browser within one week of launch. No IT approval required. Whatever employees are signed into, the browser has access to. If that includes customer data, client records, or employee information, you've created a data sovereignty exposure that the Privacy Act holds you accountable for.
The question isn't whether your employees use AI. They do. The question is whether they're using it in ways that comply with your Privacy Act obligations. Most organisations can't answer that because they don't have an AI tool inventory.
Related Questions
Frequently asked questions
The ADM transparency deadline is 10 December 2026. Start your compliance sprint now while advisory capacity is still available. Waiting until September costs more for the same outcome.
Related Topics
Explore This Pillar
Go deeper with the matching master pillar and the most relevant supporting topics for this page.