Good afternoon
It’s lovely to join you today and provide you with a brief overview of some of the matters we are focusing on that will be of interest to the financial industry.
As always, it’s a busy time at the OAIC, with several matters on hand, further legislation in prospect, and a community with a heightened awareness of their privacy rights. And it’s also busy for you all, navigating economic headwinds, changing compliance responsibilities, and dealing with the daily business realities of your organisations.
I was interested to see recent remarks by the chairwoman of the Productivity Commission, Danielle Woods, lamenting what she called ‘performative regulation’. She saw this a reflex action when governments are unable or unwilling to solve a problem.
I take her views on board. While the OAIC does advocate for legislative change, we are also mindful of the need to bring the regulated community along with us, and a major part of that is ensuring compliance is not overly burdensome. Education and providing the right guidance are core functions for us – we seek to work with our stakeholders to create the right environment.
And law does not need to be complex. That’s embodied by our support for the Privacy Act to contain a fair and reasonable test for processing personal information.
A fair and reasonable test in the Privacy Act would require the collection, use or disclosure of personal information to be fair and reasonable in the circumstances, even if an individual consents to the processing of their personal information.
It would address the current power imbalance inherent in the existing framework by shifting the responsibility to organisations to proactively consider the impact that their data handling practices may have on individuals. It would also prevent consent from being used to legitimise handling of personal information in a manner that is, objectively, unfair or unreasonable.
This would be a very important step. But it is also about getting the right foundations in place, so that businesses have clarity and can go forward and innovate.
In the past two years the OAIC has become a more enforcement-focused regulator. We pursue enforcement action where we can change market practices, where our intervention is going to reshape products, reshape services, reshape platforms.
If there is non-compliance, we’ll be prepared to take enforcement action.
Last week we published a determination involving American Express and interference with a complainant’s privacy. The week before it was Optus and a long-running matter involving the publication of personal information in the White Pages. [This week we are publishing an investigation into the use of third-party tracking pixels].
A couple of months ago, we published a determination on the rent-tech sector. The issue of excessive collection of personal information by unfair means was very visible in this situation.
We are also in the final stages of our investigation into the personal information handling practices of Latitude Financial, which was commenced in 2023.
When you look at the matters I have mentioned you can see that they closely align with the regulatory priorities we announced last year, particularly in regard to the priority of rebalancing power and information asymmetries.
Sectors included within that priority are rent tech, the credit reporting and data brokerage sectors and ad tech. There is a strong focus on artificial intelligence and the excessive collection and retention of personal information.
When we choose the subject of an investigation, or make a determination, we give much thought to how the findings can advance the application of the Privacy Act, by assisting organisations to have a clearer understanding of their privacy obligations. And I recommend that you take some time to observe these decisions to help you build up your understanding of what good compliance looks like.
ACAPS
I’d like to highlight some of the findings in our recently released Australian Community Attitudes to Privacy Survey 2026 that are relevant to the AFIA.
- Only 10% of people think that organisations handle their data fairly, and 9 in 10 told us that they didn't want their data collected for one thing to be used for another without their consent, like targeting ads, training AI models, or being sold onto third parties.
- Australians remain cautious about the use of artificial intelligence (AI) in decision-making that may affect them, with nearly all (96%) saying some conditions should be in place before it is used.
- The finance sector is in the top group when it comes to expectations of responsible AI use, sitting on 68%, behind government agencies and health services.
- Australians don't feel that they have genuine choice and control when it comes to their personal information. 67% of people told us that they didn't feel that handing over personal data was a genuine choice and more than half of people said that they agreed to hand over their personal information, because if they didn't, they'd miss out on essential services.
- 91% of Australians say that the organisation that collected their personal information is responsible for it. To build trust with the Australian community, industry and government should focus on limiting collection of personal information to what's necessary and proportionate, giving people real choices when it comes to their personal data and providing easy pathways for accessing and contesting uses of personal information.
- Australians show strong support for the right to data deletion and erasure. More than 9 in 10 (93%) support or strongly support a legal right for individuals to request that organisations delete their personal information, including almost three-quarters (73%) who strongly support this provision.
If you look at these survey results it also further refines the scope of our regulatory posture, and where the community perceive harms as significant.
They are also relevant to some of our recent initiatives.
AML CTF
First, the reforms under the Anti-Money Laundering and Counter-Terrorism Financing Act.
We provided updated guidance on these provisions earlier this year following a round of stakeholder consultation.
The guidance provided clear direction to businesses about what personal information they may collect, how they must protect it, and when it must be deleted, supporting stronger integrity and transparency across the AML/CTF regulatory framework.
The updated guidance is designed to support an expanded range of businesses that will soon fall under the Privacy Actas part of the AML/CTF reforms.
From 1 July 2026, an expanded range of businesses will fall under the act. These include real estate professionals, dealers in precious metals and stones, and professional service providers such as lawyers, conveyancers, accountants, and trust and company service providers.
Changes for current reporting entities took effect at the end of the March, clarifying that reporting entities must only collect personal information that is reasonably necessary to comply with AML/CTF obligations and perform their broader organisational functions. For example, businesses should not retain copies of full ID documents for AML/CTF record-keeping purposes.
This echoes the finding in ACAPS that many Australians want their information deleted if no longer required, and our priority addressing excessive collection and retention of personal information.
One of the most significant risks to Australians’ privacy is the unnecessary retention of ID documents, which are some of the most important pieces of personal information Australians possess. Entities can collect, use and disclose the personal information required to meet their obligations, but they don’t have a blank cheque to collect any personal information without considering what is reasonably necessary.
For those entities who will now come under the Privacy Act, we have published a privacy collection notice that entities can use, and we have also made it clear that we will always be proportional in how we use our regulatory powers and not seek to target smaller operators.
ADM
Australians’ wariness about the undisclosed use of AI or automated decision making – as shown in our ACAPS survey – supports the logic of including the ADM transparency obligation in the Privacy Act.
The obligation comes into effect on 10 December, and I know is subject to much discussion among your member organisations. Privacy policies will need to contain information about substantially automated decisions which significantly affect individuals’ rights or interests, including the kinds of decisions and kinds of personal information used.
Providing individuals with greater transparency allows them to understand how an entity handles their information and for what purposes and allows them take further action if there has been a breach of their personal privacy.
The OAIC is seeking information and views to inform the development of the Guidance for the ADM Transparency Obligation and recently released an issues paper for consultation. We will be releasing our guidance in September.
Attitudes about the use of AI and ADM among the public are very context dependent. Where the stakes are higher for individuals – eligibility for benefits, financial credit situations – their concerns increase, particularly if they cannot have the decision reviewed.
ADM and AI can increase the efficiency, accuracy, and consistency of decisions across the public and private sectors. However, the productive opportunities can only be fully realised if the ethical and legal issues associated with it are properly mitigated and trust is built with the Australian community.
Conclusion
As I have outlined, the OAIC is active on my fronts across privacy regulation. We are making sure that our actions are focused on significant harms, are proportional, and deliver for the Australian community.
We are also committed to working with the regulated community to strengthen frameworks that work for all.
For you as AFIA members, adopt a future-ready attitude, take a privacy by design approach, and you will be in a good place.