What is the Office of the Australian Information Commissioner?
The OAIC describes itself as an independent agency within the Attorney-General's portfolio, with a mandate spanning privacy, freedom of information and government information policy. Its work includes conducting investigations, reviewing decisions, handling complaints, and providing guidance and advice.
The office is established by the Australian Information Commissioner Act 2010, Act No. 52 of 2010. Section 5 of that Act establishes the Office, which consists of three information officers, the Information Commissioner, the Freedom of Information Commissioner and the Privacy Commissioner, plus staff. The Information Commissioner is the head of the Office for the purposes of the Public Service Act 1999. The functions belong to the Office rather than one to each officer: all three information officers may perform the freedom of information functions and the privacy functions, and only the Information Commissioner can perform the information commissioner functions, which the Act describes as strategic functions concerning information management by the Commonwealth Government. Part 4 of the Act also provides for an Information Advisory Committee.
On the privacy side the OAIC administers the Privacy Act 1988 and publishes the guidelines to the Australian Privacy Principles that regulated entities are expected to work from. Part IV of the Privacy Act sets out the functions of the Information Commissioner, and Part VIB deals with compliance and enforcement.
Who does the OAIC regulate?
Its privacy jurisdiction follows the Privacy Act's coverage: most Australian Government agencies and private sector organisations with an annual turnover of more than $3 million, plus the smaller operators the Act catches by exception, such as private sector health service providers, credit reporting bodies, and businesses that buy or sell personal information.
Beyond the Australian Privacy Principles the office oversees the privacy component of consumer credit reporting, tax file number handling, and specified schemes including My Health Record and healthcare identifiers. It also has responsibilities under Consumer Data Right privacy arrangements and freedom of information review functions in relation to Australian Government agencies.
The notifiable data breaches scheme is the most visible touchpoint for most organisations. Where a data breach involving personal information is likely to result in serious harm, the entity must notify affected individuals and the OAIC. The office's role in that scheme includes receiving notifications, encouraging compliance including by handling complaints, conducting investigations and taking other regulatory action, and providing information to the community about how the scheme operates.
One boundary is worth naming. The statutory tort for serious invasions of privacy commenced on 10 June 2025 under Schedule 2 of the Privacy Act, but the OAIC states plainly that it does not have a direct role in administering the tort. That is a court-based remedy, not a regulator-led one.
Where does AI fit in the OAIC's work?
The OAIC has become the primary Australian source of practical privacy guidance on AI. It has published guidance on privacy and the use of commercially available AI products and separate guidance on privacy and developing and training generative AI models.
The central position in that guidance is that the Privacy Act applies to all uses of AI involving personal information, and that obligations attach to any personal information input into an AI system as well as to output data generated by AI where it contains personal information. The office expects organisations to take a cautious approach proportionate to the risk, notes that use of personal information in AI systems is a source of significant community concern, and states that AI products should not be used simply because they are available.
Specific expectations follow. Organisations should conduct due diligence before adopting a product, including whether it has been tested for the intended use, how human oversight can be embedded, and who will have access to input and output data. Due diligence should not be a set and forget exercise. Privacy policies and notifications should carry clear and transparent information about AI use, and public-facing tools such as chatbots should be clearly identified as AI. As best practice, the OAIC recommends organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools.
The OAIC is also building the guidance for the automated decision making transparency obligation that commences on 10 December 2026, running a consultation with submissions closing 15 June 2026.
What should practitioners do with the OAIC's guidance?
Treat the OAIC's published guidance as the working standard rather than a background reading list. It is the material a regulator will measure conduct against, and it is specific enough to convert directly into controls.
Three moves are worth making now. Build the AI inventory that the December 2026 privacy policy obligation will require, so the disclosure describes what the organisation actually does rather than what it intends. Confirm the data breach response plan names who notifies the OAIC and on what trigger, because the serious harm threshold requires a judgement someone has to own. Then close the highest-frequency gap, which for most organisations is staff pasting personal information into public generative AI tools.
Related material sits under the privacy topic hub and across the GRC section.
Bottom line
The OAIC is Australia's independent regulator for privacy, freedom of information and government information policy, and on the privacy side it administers the Privacy Act, publishes the Australian Privacy Principles guidelines and receives notifiable data breach notifications. It has also become the primary Australian source of practical guidance on privacy and AI, holding that the Act applies to all uses of AI involving personal information, covering what an organisation puts into a system as well as what the system generates. Practitioners should treat that published guidance as the working standard rather than a background reading list, because it is the material a regulator will measure conduct against and it converts directly into controls. The moves worth making now are building the AI inventory the privacy policy obligation will require, confirming who notifies the OAIC of a breach and on what trigger, and closing the highest-frequency gap of staff pasting personal information into public generative AI tools.
TheAICommand. Intelligence, At Your Command.*
TheAICommand. Intelligence, At Your Command.
