AI Framework

Data Privacy Regulations in Australia: The Full Picture

Australia's data privacy regulations aren't one law - they're the Commonwealth Privacy Act 1988 plus separate state laws that only cover state government, not private business. A new automated decision-making disclosure requirement lands 10 December 2026. Which of these actually apply depends on your business's industry, size and state.

Searching "data privacy regulations" in Australia usually means one thing: trying to find the one law that applies to your business. There isn't one - there's a national framework, several state ones with much narrower scope, and a live pattern of confusion about which is which.

AI Framework's legislative register maps the Commonwealth and state instruments that apply to a business's actual profile, because "which regulations apply to me" only has a useful answer once it's specific to your business, not general to the country.

Australia's data privacy regulations at a glance

What data privacy regulation actually looks like in Australia

The core framework is the Commonwealth Privacy Act 1988, built around 13 Australian Privacy Principles (APPs), applying to most private businesses over $3 million annual turnover. The full breakdown of all 13 principles - and which ones change once AI is involved - is the natural next stop if you're starting from scratch. Roughly 94-95% of Australian businesses are commonly estimated to sit under that threshold and be exempt, though a handful of exceptions (health information, trading in personal information, and a few others) pull smaller businesses in regardless of size.

State and territory governments run their own, separate privacy laws - but they cover state government, not private business, with narrow exceptions covered below.

The date every AI-using business should have on the calendar

From 10 December 2026, APP 1.7 introduces a disclosure requirement in privacy policies when a computer program makes, or substantially supports, a decision that could significantly affect someone's rights or interests. The legislation covers decisions a computer program "substantially supports," not just ones it makes outright - so human review alone doesn't take a decision outside its scope. The full explainer covers the exact three-part test.

The data privacy regulations covered across this site range from the Commonwealth Privacy Act to state public-sector laws - see which ones actually apply to your specific business, rather than working through all of them to find out.

Victoria: government-only, with a real vendor angle

Victoria's Privacy and Data Protection Act 2014 covers Victorian government agencies, not private business - with one real exception worth knowing if you supply services to Victorian government. Contracted service providers can be bound to the same Information Privacy Principles the government follows, where a state contract includes a provision requiring it under section 17(2) of the Act.

Queensland: recently and substantially reformed

Queensland's Information Privacy Act 2009 is also public-sector-only - and it was significantly reformed on 1 July 2025, replacing a two-tier principle structure (Information Privacy Principles and National Privacy Principles) with a single unified set of Queensland Privacy Principles, based on and generally consistent with the Commonwealth APPs. Most content on this Act hasn't caught up with that change yet.

New South Wales: two pieces, one picture

NSW runs the PPIP Act for its public sector and a separate law for private health providers - and for a private NSW business generally, the Commonwealth Privacy Act is almost always the one that actually applies, not any NSW state law. NSW also has its own AI-specific angle worth knowing: the Work Health and Safety Amendment (Digital Work Systems) Act 2026 explicitly covers AI used to allocate or monitor staff work - WHS law, not privacy law, but close enough to it that it's easy to miss.

The obligation that isn't privacy law at all

Privacy and confidentiality are legally different things - one is statutory, the other is contractual or an equitable duty - and pasting information into a public AI tool can breach either one independently of the other. Worth knowing before assuming privacy compliance is the whole picture.

FAQ

What are the main data privacy regulations in Australia? The Commonwealth Privacy Act 1988 and its 13 privacy principles - Australia's core data privacy regulations for private business - plus separate state laws (Victoria, Queensland, NSW and others) that cover state government only, not private business.

Does the Privacy Act apply to small businesses? Generally not, if turnover is under $3 million - though some categories (health service providers, businesses trading in personal information, and a few others) are covered regardless of size.

What's changing in Australian privacy law? From 10 December 2026, a new disclosure requirement applies where automated systems are used in decisions that significantly affect people. Separate reform proposals are under consultation, though the small business exemption has not been removed as of this writing.

Do state privacy laws apply to my business? Almost certainly not directly - Victoria's, Queensland's and NSW's privacy Acts all cover state government agencies, not private business, with narrow exceptions for government contractors and, in some states, private health providers.

How is Australian privacy law enforced? The Office of the Australian Information Commissioner (OAIC) enforces the Commonwealth Privacy Act. Each state has its own regulator - OVIC in Victoria, OIC in Queensland, IPC in NSW - for their own public-sector laws.

If your business handles personal information and uses AI, an AI governance framework built for your specific profile is the place to start. Address it today with AI Framework.

This post is general information, not legal advice.

Current as at September 2026.

← Back to Insights