Privacy Act 1988, plain-English definition from TheAICommand
← Glossary
Definition

What is the Privacy Act 1988?

The Privacy Act 1988 (Cth) is the Commonwealth statute governing how personal information is handled in Australia. It carries the 13 Australian Privacy Principles, the notifiable data breaches scheme, credit reporting and tax file number rules, and since 10 June 2025 a statutory tort for serious invasions of privacy.

Quick answer

The Privacy Act 1988 (Cth) regulates how Australian Government agencies and organisations with annual turnover above $3 million handle personal information. It contains the 13 Australian Privacy Principles, the notifiable data breaches scheme, credit reporting and tax file number rules, and since 10 June 2025 a statutory tort for serious invasions of privacy.

What does the Privacy Act 1988 actually regulate?

The Privacy Act 1988 (Cth), Act No. 119 of 1988, is the Commonwealth statute governing how personal information is handled in Australia. The OAIC describes the Act as introduced to promote and protect the privacy of individuals and to regulate how Australian Government agencies and certain organisations handle personal information.

Section 6(1) defines personal information as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true and whether or not it is recorded in a material form. That definition is deliberately wide. It captures opinions and inferences, not only verified records, and it is technologically neutral.

The Act runs well beyond the privacy principles. The current compilation carries separate parts for information privacy, credit reporting, privacy codes, notification of eligible data breaches, the functions of the Information Commissioner, investigations, and compliance and enforcement. Schedule 1 contains the 13 Australian Privacy Principles. Schedule 2 contains the statutory tort for serious invasions of privacy, which commenced on 10 June 2025.

Under the notifiable data breaches scheme, where a data breach involving personal information is likely to result in serious harm, a covered entity must notify the affected individuals and the OAIC, including recommendations about the steps individuals should take. The Act also regulates the privacy component of the consumer credit reporting system, tax file numbers, and health and medical research.

Who does the Privacy Act 1988 apply to?

Coverage turns on entity type and size. Most Australian Government agencies are covered, as are organisations with an annual turnover of more than $3 million. Together these are called APP entities.

Smaller operators are not automatically outside the Act. The OAIC lists small business operators that are covered anyway, including private sector health service providers, businesses that sell or purchase personal information, credit reporting bodies, contracted service providers for an Australian Government contract, accredited participants in the Consumer Data Right, and businesses that have opted in.

The exclusions matter just as much. State and territory government agencies are generally outside the Act, as are individuals acting in their own capacity, public schools, universities other than private universities and the Australian National University, registered political parties, and media organisations acting in the course of journalism where the organisation is publicly committed to observing published privacy standards. In some situations the Act also does not cover an organisation's handling of employee records in relation to current and former employment relationships.

Where does AI fit under the Privacy Act 1988?

The OAIC's position is direct: the Privacy Act applies to all uses of AI involving personal information. Privacy obligations attach to any personal information put into an AI system as well as to output data generated by AI where that output contains personal information.

Three consequences follow. First, if an AI system generates or infers personal information, including images, that is a collection and must comply with APP 3, and inferred, incorrect or artificially generated information about an identifiable individual, including hallucinations and deepfakes, is personal information. Second, where personal information is put into an AI system, APP 6 limits use and disclosure to the primary purpose of collection unless consent applies or the secondary use would be reasonably expected and is related to that purpose. Third, as a matter of best practice the OAIC recommends organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools.

A dated obligation is now approaching. From 10 December 2026, where an APP entity uses personal information in a computer program to make a decision that could reasonably be expected to significantly affect the rights or interests of an individual, its privacy policy must disclose the kinds of personal information used and the kinds of decisions made that way. The OAIC ran a consultation on the supporting guidance with submissions closing 15 June 2026.

What should practitioners do about the Privacy Act 1988?

Start with an inventory. Identify every AI system that touches personal information, including staff use of public chatbots, then confirm which of those systems feed a decision that could significantly affect an individual. Those are the systems that carry the December 2026 privacy policy obligation and the sharpest APP 3 and APP 6 exposure.

Update the privacy policy and collection notices before the deadline rather than at it, and make sure any public-facing AI tool such as a chatbot is clearly identified as AI. Treat vendor due diligence as ongoing rather than a one-off, covering how human oversight is embedded, who can access input and output data, and whether the product has been tested for the intended use. Run a privacy impact assessment where the risk warrants it.

Finally, do not assume the employee records exemption clears workforce analytics. It is narrow, it applies only in some situations, and it does not displace the separate obligations that sit under the Fair Work Act 2009 or work health and safety law. Related material sits under the privacy topic hub and across the GRC section.

Bottom line

The Privacy Act is the Commonwealth statute governing how personal information is handled in Australia, and its definition of personal information is deliberately wide, reaching opinions and inferences about a reasonably identifiable person whether or not they are true. That width is why the OAIC can say the Act applies to all uses of AI involving personal information, covering both what an organisation puts into a system and what the system generates, including material a model infers or hallucinates. For practitioners the work starts with an inventory of every AI system that touches personal information, staff use of public chatbots included, then narrows to the systems feeding a decision that could significantly affect an individual, because those carry the approaching privacy policy disclosure duty and the sharpest exposure. Do not assume the employee records exemption clears workforce analytics, since it is narrow, it applies only in some situations, and it displaces nothing under workplace relations or work health and safety law.

TheAICommand. Intelligence, At Your Command.*

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

Who does the Privacy Act 1988 apply to?
It applies to most Australian Government agencies and to private sector organisations with an annual turnover of more than $3 million, together called APP entities. Some smaller operators are also covered, including private health service providers, credit reporting bodies, businesses that buy or sell personal information, and Commonwealth contracted service providers.
Does the Privacy Act 1988 cover AI tools?
Yes. The OAIC states the Privacy Act applies to all uses of AI involving personal information, covering both what an organisation puts into an AI system and what the system generates. Inferred or hallucinated information about an identifiable person is still personal information and must be handled under the Australian Privacy Principles.
What Privacy Act change starts on 10 December 2026?
From 10 December 2026, APP entities that use personal information in a computer program to make a decision that could reasonably be expected to significantly affect an individual's rights or interests must set out in their privacy policies the kinds of personal information used and the kinds of decisions made that way. The OAIC consulted on guidance during 2026.
What is the statutory tort for serious invasions of privacy?
Introduced by Schedule 2 of the Privacy Act and commenced on 10 June 2025, it lets an individual sue for intrusion upon seclusion or misuse of information where they had a reasonable expectation of privacy. Courts may award damages, an injunction or an order requiring an apology. The OAIC does not administer it.
Does the Privacy Act 1988 cover employee records?
In some situations the Act does not cover an organisation's handling of employee records connected to a current or former employment relationship. The exemption is narrow and does not remove other obligations, so employers running AI over workforce data need to confirm whether the exemption applies before relying on it.

Primary sources

← Back to the glossary

General information and education only. Not legal, compliance, financial, or professional advice. Always confirm obligations against the primary source and current regulator guidance.