Data privacy-compliant AI builds public trust

Data Privacy-Compliant AI

The Office of the Australian Information Commissioner (OAIC) issued a clarification regarding the application of Australia’s Privacy Act to artificial intelligence. This announcement responds to the interim enquiry by the Productivity Commission into “Harnessing data and digital technology,” which the commission released on August 5, 2025, in Canberra.

These guidelines apply to the creators of generative AI models and organisations that implement commercially available AI solutions. Privacy Commissioner Carly Kind emphasised that these guides “should remove any doubt about how Australia’s existing privacy law applies to AI make compliance easier and help businesses follow privacy best practice.”

Government agencies must ensure that AI initiatives align with community expectations and legal requirements. The OAIC takes decisive action to ensure AI enhances productivity by fostering trusted data governance and safeguarding privacy standards.

OAIC strengthens AI privacy

OAIC released two new guidance documents that provide clear instructions on applying existing privacy law to artificial intelligence throughout the lifecycle of AI projects. The initial guide outlines how to integrate generative artificial intelligence with Privacy Act requirements and incorporates a principle of privacy by design. 

This requires conducting privacy impact assessments, managing personal and sensitive data meticulously, and ensuring robust data governance from the start. The approach emphasises the importance of training, data provenance, and deidentification as essential safeguards. It highlights significant privacy risks associated with the extensive use of personal data in artificial intelligence. The second guide addresses how organisations implement commercially available AI products. 

It compels them to examine the data they input into and output from these tools in light of their privacy responsibilities. It requires careful attention to product design, incorporates human oversight, ensures transparency in privacy notices, recognises AI-generated personal information as distinct personal data, and limits the use of sensitive or personal information without explicit justification.

OAIC directs AI governance

Public sector leaders must regard the Privacy Act as relevant to artificial intelligence systems that manage personal information during both design development and deployment phases. The directive stresses the need to integrate privacy considerations into AI initiatives and conduct privacy impact assessments from the initial phases of generative model development. Agencies must manage training data meticulously and implement strict provenance checks and de-identification whenever feasible. Any inferred or generated personal or sensitive data should be regarded as governed by the Australian Privacy Principles. 

Public sector organisations using commercially available AI tools must conduct thorough due diligence. This includes assessing privacy and security risks, identifying who has access to personal data, and ensuring that privacy notices and policies are updated to accurately reflect the use of AI. OAIC expects agencies to adopt a cautious, risk-oriented strategy for data collection and sharing that emphasises transparency and human oversight. This approach preserves public trust and enhances productivity through artificial intelligence while advancing digital government initiatives.

Check Out: “NTC steers AI to responsible governance”

Australians demand AI privacy

Australians are cautious about how organisations manage personal information. Only 32 percent of Australians feel in control of their data privacy. An overwhelming 84 percent want greater control and choice over the collection and use of their information. Data breaches pose significant concerns, with 74 percent of individuals recognising them as a leading threat to privacy. Selecting digital services requires considering privacy as a key factor right after quality and price. 

About 83 percent of Australians believe companies should obtain consent before using personal data to train AI models. People expect artificial intelligence initiatives to follow established standards for consent, transparency, and accountability. Public sector agencies must acknowledge that incorporating privacy from the outset and ensuring transparent communication serve as vital components of building trust and are key to the effective implementation of AI-driven digital government.

AI transforms government operations

The government’s integration of artificial intelligence compels public sector agencies to revamp their data infrastructure and governance frameworks. More than fifty APS agencies participated in a six-month trial of Copilot for Microsoft 365, involving over 7,400 public servants to explore secure use cases and assess data collaboration across internal systems. The trial highlighted the importance of accountability, transparency, and privacy when using AI tools in cloud storage systems and silos. 

Public sector entities must reveal instances where automated decision-making impacts individuals and revise privacy policies by December 2026 to align with AI systems governed by the Australian Privacy Principles. The interim enquiry by the Productivity Commission into data and digital technology reveals that AI can contribute as much as A$116 billion to the economy over the next ten years. The text suggests a transition in privacy regulations from strict checklists to a more outcome-focused approach.

Enforce AI compliance

  1. Audit AI projects for compliance with the Australian Privacy Principles and conduct Privacy Impact Assessments before model training: This enables agencies to identify risks quickly. This includes the unintentional addition of sensitive personal data, and it is important to adjust workflows before deployment to avoid costly remediation or damaging the organization’s reputation.
  2. Require vendors to document data provenance and deletion processes: Understanding the precise origins of training data and its disposal methods helps agencies minimise the risk of violating privacy regulations and enhances their safeguards against data misuse or unauthorised retention.
  3. Embed human review for high-risk automated decisions and update privacy notices: In areas like benefits eligibility or licencing, human oversight plays a crucial role in identifying AI errors that could impact individuals negatively. Revised privacy notices keep the public informed and mitigate feelings of mistrust.

 

Australia shows that privacy and productivity can thrive together in AI governance. This achieves robust privacy governance that fosters trust and facilitates innovation. The OAIC emphasises that incorporating privacy by design into AI initiatives helps public sector agencies enhance community trust and improve the efficiency of government services. Trust is delicate. Agencies must uphold transparent data management to ensure artificial intelligence provides advantages while maintaining public confidence. Future privacy legislation will evolve into a regulatory framework that emphasises outcomes and strikes a balance between the benefits of sharing data and safeguarding personal information.

Content Producer at  |  + posts

Justin Lavadia is a content producer and editor at Public Spectrum with a diverse writing background spanning various niches and formats. With a wealth of experience, he brings clarity and concise communication to digital content. His expertise lies in crafting engaging content and delivering impactful narratives that resonate with readers.

Leave a Reply

Your email address will not be published. Required fields are marked *