AI Framework

APP 10 Privacy: Keeping AI Data Accurate

APP 10 of the Privacy Act 1988 requires reasonable steps to keep personal information accurate, up-to-date and complete when it's collected, and additionally relevant when it's used or disclosed. AI complicates this: the OAIC's own guidance warns that generative AI can produce confidently wrong output, and that human oversight alone may not be enough for consequential decisions.

Australian Privacy Principle 10 sits within the 13 Australian Privacy Principles as the one covering data quality - not security, not access, but whether the personal information itself is actually right.

AI Framework's legislative register includes APP 10 as one of the 13 Australian Privacy Principles mapped against a business's actual profile, alongside other Commonwealth and state instruments - because "keep your data accurate" reads simple until an AI system is the one generating it.

Two obligations, not one

APP 10 splits into two distinct requirements, and the difference matters: at collection (APP 10.1), the standard is accurate, up-to-date and complete; at use or disclosure (APP 10.2), the standard adds a relevance requirement tied to that specific purpose. Something collected accurately can still fail APP 10 later if it's no longer relevant to what it's being used for. Most explanations of this principle treat it as one generic "keep your data accurate" rule - it's actually two separate checkpoints.

APP 10 - two obligations, not one

The four quality terms, as OAIC defines them

How the OAIC assesses reasonable steps

There's no fixed checklist. The OAIC weighs it against the sensitivity of the information, the size and resources of the business, the risk to the individual if quality fails, and whether a step is actually practicable - inconvenience alone doesn't excuse it. A business collecting information directly from the person it's about can often rely on that as inherently reliable. A business relying on a third party's data, or generating new information itself, carries more responsibility to check it.

Reasonable steps the OAIC itself points to: auditing data quality periodically, keeping consistent records that show when information was collected, updating records promptly when something changes, giving people a way to correct their own details, and checking a third party's data practices before relying on what they provide.

Where AI changes the calculation

The OAIC's own AI guidance treats this directly, in two separate documents - one for businesses building AI models, one for businesses just using commercial AI tools like ChatGPT or Copilot. For developers, the guidance is blunt: generative models are trained on data "highly likely to include inaccuracies and be impacted by unfounded biases," so training-data accuracy has to be understood and documented, not assumed.

For the much larger group - SMEs using AI tools someone else built - the more relevant warning is about output, not training data. The OAIC's own language: generative AI has a tendency to "confidently produce outputs which appear credible, regardless of their accuracy." That's the actual mechanism that makes this obligation harder than ordinary data entry - a typo is usually obviously wrong; a hallucinated fact delivered in a confident, well-formatted sentence often isn't.

The line that changes what "human oversight" actually means here

The OAIC's commercially available AI guidance warns directly that human review and staff training to verify AI output may not always be enough. Its exact words: "it is possible that these measures may not always be sufficient to constitute 'reasonable steps' for the purposes of APP 10." This is worth sitting with: the default answer most businesses reach for - "we have a person check it" - is explicitly flagged by the regulator as not automatically enough once the decision matters. What counts as sufficient scales with what's at stake, the same way "reasonable steps" always has - it's just that AI-generated content makes the checking itself harder, precisely because it's built to sound right.

An AI-generated inference about someone - a summary, a risk flag, a hallucinated detail - falls within the same obligation. Machine-generated content carries no exemption from APP 10.

Working out whether your AI use meets this bar is easier against your specific setup - see how the other 12 Australian Privacy Principles apply to your business, not just this one.

The two related principles worth knowing

Data quality connects directly to two other APPs already covered here: if someone asks to see what a business holds about them, that's APP 12; if what's held turns out to be wrong, correcting it sits under APP 13, and the disclosure obligation landing 10 December 2026 is a related but separate requirement about telling people an automated system was involved at all, not about the accuracy of what it produced.

FAQ

What's the difference between APP 10 and APP 11? APP 10 is about the quality of personal information - is it accurate, complete, relevant. APP 11 is about security - is it protected from misuse or loss. Different obligations entirely.

Does APP 10 apply to opinions, or only facts? Both. An opinion can be "accurate" under APP 10 if it's honestly held, clearly presented as an opinion, and a genuine assessment - someone disagreeing with it doesn't make it inaccurate.

What counts as "reasonable steps" for a small business versus a large one? There's no fixed checklist - it scales with the sensitivity of the information, the business's size and resources, and the risk to the person if the information is wrong.

Do we have to proactively check our records, or only when someone complains? The obligation applies at collection and again at use or disclosure - it's not purely reactive, though the level of active checking expected depends on the reasonable-steps factors above.

Does APP 10 apply to what an AI tool outputs, not just what we put into it? Yes. AI-generated content about an identifiable person - including hallucinated or inferred information - is personal information subject to the same accuracy obligation as anything collected directly.

For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.

This page covers one obligation. Most businesses using AI have several more that apply depending on industry, state and how the AI is actually used - get your free preview covers the first two AI6 practices at no cost.

This post is general information, not legal advice.

Current as at September 2026.

← Back to Insights