Data privacy in Australia is not what it was two years ago. The regulatory environment has shifted, and if your business has not reviewed its privacy governance recently, the gap between where you are and where the law expects you to be has quietly grown wider than most leaders realise.
Here is a plain-language breakdown of what has changed, what is still coming, and what your business needs to govern before the regulator comes looking.
What Has Already Changed
The Australia Privacy Act reforms have been moving through Parliament in stages. The most significant recent step was the passage of the Privacy and Other Legislation Amendment Act 2024 in November 2024.
Legislative changes to the Privacy Act passed by Parliament in 2024 expanded the possible regulatory consequences for infringements of certain foundational requirements of the Act, including the failure to have a privacy policy containing certain information. Entities found to have non-compliant privacy policies may face compliance and infringement notices and penalties of up to $66,000.
That is not a hypothetical. The OAIC has already started acting on it. Australia’s privacy regulator launched its first-ever compliance sweep in January 2026, conducting a targeted review of selected businesses’ privacy policies, scrutinising businesses that collect information in person, such as real estate agents and car rental agencies.
If your privacy policy has not been reviewed since before 2024, it may not meet the current standard, and the regulator is now actively checking.
The AI Governance Obligation Is Already Here
This is the part most Australian businesses have not fully processed.
In 2024–25, the OAIC’s major areas of regulatory focus included ensuring emerging technologies, including artificial intelligence, align with community expectations and regulatory requirements, targeting current and emerging harms effectively while continuing to proactively guide compliance.
The existing Australian Privacy Principles already apply to AI systems that collect, use, or disclose personal information. If your business uses AI tools for hiring, customer communications, data analysis, or operational decisions, those tools are already within the regulatory frame.
The OAIC published guidance in October 2024 specifically aimed at assisting businesses to comply with their privacy obligations when using commercially available AI products and providing information to developers using personal information to train generative AI models.
The guidance is published. The expectation is set. AI risk management in Australia is not a future consideration, it is a current one.
What the Data Breach Numbers Are Telling You
Data breach notifications to the OAIC were up 25% year on year across the 2024 calendar year, with the period of 1 July to 31 December 2024 alone seeing 595 notifications, a 15% increase on the previous six months.
Rising breach numbers mean rising regulatory scrutiny. The OAIC has made its approach clear, education first, enforcement second. If education has not moved a business to comply, enforcement follows. You can review the latest Notifiable Data Breaches statistics here.
Three Governance Gaps Most Businesses Are Carrying
An outdated privacy policy. Given the OAIC has already conducted a compliance sweep targeting this, an outdated policy is not a minor oversight, it is an active compliance exposure. Use the OAIC’s Privacy Foundations self-assessment tool to check where you stand.
No documented AI governance process. If your business uses AI tools and has not formally assessed how they collect, use, or share personal information, you are missing a governance obligation the regulator has explicitly flagged.
No data breach response plan. Every business covered by the Privacy Act needs a documented, tested response plan, not a general IT security policy, but a specific plan that triggers the right steps within the right timeframe when a breach occurs.
What Is Still Coming
The Attorney-General has committed to continuing to advance Privacy Act reform proposals, with the government working to develop draft provisions and engaging on the detail of further changes in the coming months.
The OAIC is also developing the Children’s Online Privacy Code, which will enhance protections for children under 18 when registered in late 2026. For businesses operating online platforms accessed by younger Australians, this is a material upcoming obligation that needs governance attention now.
What Prepared Looks Like in Practice
For most businesses the foundations are already there, they just need to be formally reviewed and connected into a coherent governance structure.
A prepared organisation has a privacy policy that meets current legislative requirements, a documented process for assessing how AI tools handle personal information, a tested data breach response plan, and clear leadership accountability for privacy governance, not just an IT team managing security.
If any of those are missing, the gap is worth closing before a sweep, a complaint, or a breach opens the conversation for you.
At Anitech, we help Australian businesses build practical privacy governance frameworks that meet current legislative requirements and position organisations for the reforms still to come. If your business has not reviewed its privacy governance since the 2024 amendments, that is exactly where the conversation starts




Recent Comments