Good afternoon. Thank you for opportunity to speak today. Before I start I’d like to acknowledge and pay respects to the people of the Yugambeh language region of the Gold Coast and all their descendants both past and present. I also acknowledge the many Aboriginal people from other regions as well as Torres Strait and South Sea Islander people who now live in the local area and have made an important contribution to the community.
I have a question to start with. Is anyone on the call wearing smart glasses? If so, please take them off.
I did intend that as a bit of a joke to start, given the topicality of smart glasses in the community and in privacy circles. But it is an interesting prompt. What will be the longer-term response to a technology such as this – will some areas become ‘no smart glass’ zones; will the technology adapt in ways we do not yet imagine? How will the visible community concern interact with attempts to regulate effectively?
Such are the challenges of dealing with emerging technologies. It is an issue of I will come back to.
It’s a pleasure to join with the Australian Insurance Law Association and I understand that you interact with the insurance industry and with the law in a range of ways. I’d like to start with an appropriate analogy.
Good privacy practice and building privacy by design into your approach is insurance for your business and good for the insurance industry. It is essential to your risk mitigation. And – particularly in regard to cyber threats and data breaches – being talked about in the country’s boardrooms.
A coordinated cyber-attack may share some similarities to what are termed “acts of God” in the insurance industry. It can have a seismic effect on an organisation – financially and reputationally – and of course on members of the community who have their most sensitive information placed in the hands of bad actors.
But privacy law itself, and the steps you can take to embed good practice, exist in a much calmer environment. I say this despite the fact we expect the Federal Government to announce Tranche 2 of privacy reform in the near future, coming on top of the reforms passed by Parliament at the end of 2024. While these reforms are likely to be significant, and they are ones I eagerly await, I confidently believe you have enough information to navigate a way forward.
Over the past 2 years, through dozens of decisions and regulatory actions, the OAIC has been working to define in concrete terms what good privacy practice looks like.
Where does the insurance industry sit
Earlier this year we released Australian Community Attitudes to Privacy Survey (ACAPS) 2026, a comprehensive survey we carry out every 3 years.
Overall, it found that only 10% of people think organisations handle their data fairly, and 9 out of 10 told us they didn't want their data collected for one thing to be used for another without their consent, like targeting ads, training AI models, or being sold onto third parties.
Community trust in the insurance industry to use their personal information has fallen, from 40% in our previous survey, to 28%. The industry sits significantly below health service providers and government agencies, but well above social media companies and AI companies, which are close to flatlining.
As is the case with similar regulators in Canada, Britain and Ireland, we are seeing a rapid increase in the number of privacy complaints we receive.
We received a total of 3,948 complaints in 2025-26. That’s an increase of 73%.
In terms of sectors, insurance is in the top 10, sitting in 9th place with just over 3% of complaints, but growth in insurance complaints is outpacing the overall trend. Is this a reflection of falling trust? Either way, it is something to be alert to.
Most complaints centre on APP6, disclosure about the use of an individual’s personal information, and APP12, individuals being able to access their personal information.
The broader issues of rising privacy complaints are troubling. Our community privacy survey showed a great deal of frustration from individuals in trying to get their concerns addressed.
Privacy complaints are not just a workload challenge for my office. They are a signal: when entities fail to act on privacy compliance, individuals who have nowhere else to turn come to us. The complaint queue is a measure of systemic non-compliance, and of the failure of first-instance dispute resolution.
This year has also seen an important development in the insurance industry’s use of sensitive personal information with the passing of legislation banning life insurers from using adverse genetic testing results to deny or limit life insurance cover.
Health or genetic information is sensitive information under the Privacy Act. A rationale for the change is that is Australians could be discouraged from undertaking genetic testing out of fear it may have an impact on their ability to get insurance or drive-up premiums. Ultimately, as a result of the ban, genetic information about an individual cannot be solicited or use to accept or deny life insurance cover.
In many ways this is an example of the purposes of a new technology – genetic testing – can change or have impacts that we did not initially expect. We can see a relationship 2 of the OAIC’s regulatory priorities:
- rebalancing power and information asymmetries, and
- rights preservation in new and emerging technologies.
The rise of new tech
Which brings me to smart glasses. Dubbed as “pervert glasses” by many, this is a technology that in its visibility and potential privacy harms, is now subject to intense debate.
The public conversation has quickly turned to the implications for personal privacy of a new spate of wearables that permit a wearer to record images, video and sound in any environment, from a public bathroom to the local pub. The content gathered could range from harmless activities to harassment and surveillance. And the question of consent is inescapable.
The Attorney-General has asked my office to give smart glasses priority consideration and to identify any new privacy risks and mitigation measures.
Such a technology asks questions of our society as to what we can tolerate. It also calls into question whether we need laws, as the Privacy Act only applies to businesses and government agencies, not to individuals, and it only applies when those entities collect personal information.
As I recently wrote, in circumstances where a tech company is receiving and storing personal information collected by surveillance wearables, they’ll have to make sure they’re complying with privacy law. And there are real questions as to whether they will be able to do so – how will they notify individuals that their images or voice has been recorded? If they’re making facial recognition features available, how will they ensure that they have the consent of the people whose faces the tech is analysing?
We are giving serious consideration to the issues raised by surveillance wearables and monitoring their market presence in order to understand if scrutiny and intervention is required or warranted.
Compliance with existing privacy law is likely to be only one part of the puzzle that companies developing and deploying these tools will need to consider
The Australian government is currently in the process of developing the Tranche 2 reforms to the Privacy Act, which are likely to include expanding the scope of application of privacy law in ways that create additional hurdles for the developers of surveillance wearables. Under the proposed reforms, for example, entities will need to be able to demonstrate that their collection and use of personal information, including to train AI models, is both fair and reasonable.
Higher standards around consent, more protections on geolocation data and an expanded definition of personal information are also likely to strengthen my hand as Australia’s privacy regulator in scrutinising these tools.
The privacy reform odessey
As I say, the details of further privacy reform are not far away. It has been a long journey for those who champion reform. Thankfully that journey is far shorter than Odysseus’s wanderings in Homer’s epic, which is now gracing our movie screens.
As we head into the final stages of the process, I trust we can avoid siren calls, gift horses and stormy seas, to make it safely home.
One of the key changes we have been supporting is for the Privacy Act to contain a fair and reasonable test for processing personal information.
A fair and reasonable test in the Privacy Act would require the collection, use or disclosure of personal information to be fair and reasonable in the circumstances, even if an individual consents to the processing of their personal information.
It would address the current power imbalance inherent in the existing framework by shifting the responsibility to organisations to proactively consider the impact that their data handling practices may have on individuals. It would also prevent consent from being used to legitimise handling of personal information in a manner that is, objectively, unfair or unreasonable.
It would be an important step. It also brings into play a conceptual framework of thinking that sits comfortably within privacy by design. If we take the view that technology should be deployed in the pursuit of societal objectives, a view that I accept not all agree with, then we have the power to shape our technological environment.
Privacy considerations should be at the forefront of the entire design life cycle. Is what you are doing – at each step – fair and reasonable?
Organisations can get in front of this now by thinking about how new products and offerings can embody fairness and reasonableness from the start. One mechanism for facilitating this process is to get into the habit of undertaking a privacy impact assessment at the commencement of any new technological deployment or novel use of personal data. This can help organisations identify and mitigate risks and think through the ‘should’ as well as the ‘could’.
And good privacy practices make good business sense. As our survey found: around two-thirds of respondents say they would be more likely to use digital services requiring personal information if they believed their data was handled fairly and responsibly,
Our regulatory approach and focus
From a privacy standpoint, we have been active in the 2 regulatory priorities I mentioned in earlier.
In terms of rebalancing power and information asymmetries we have published important determinations involving rental technology and third-party pixel tracking in the health sector, with accompanying guidance.
In terms of rights preservation in new and emerging technologies, we have updated our facial recognition technology guidance and commenced an investigation into connected car technology.
That regulatory priority also addresses the preservation of privacy and information access rights in government use of AI and automated decision making, which is a focus that engages the whole of our office and involves action across both our privacy and information access functions. We have also published important guidance in these areas as well.
The record of decision-making and jurisprudence
We are targeted in our approach and targeted with our enforcement. We are not afraid of taking action. Last year, the Federal Court handed down the first ever civil penalties under the Privacy Act against Australian Clinical Laboratories – an amount of $5.8 million – in relation to a data breach by its Medlab Pathology business.
The findings are specific: the failure was not a failure of policy, it was a failure of investment. Inadequate testing. Insufficient training. Underpowered tools. The message from the Court is unambiguous: reasonable steps to secure personal information under APP11 require actual resourcing, not aspirational statements.
The take home from these matters that I mentioned is that our determination and actions are contributing to a great understanding of the powers of the Privacy Act. This is not about waiting for reform, we are actively using the powers we already have to shape the environment, to educate, to uplift the privacy culture.
Qantas – what this says about our approach
A great example of our willingness to educate, and to adopt a flexible and proportionate approach with our regulatory toolkit, was our decision to publish the report of the OAIC’s preliminary inquiries into the Qantas data breach in 2025. This may seem counter-intuitive – the matter did not proceed to investigation – so why bother?
I decided to publish because my powers allow me to do so in matters of high public interest, and because I saw the educative value of disseminating both the findings and information about the OAIC’s decision-making process.
A caveat to what I am about to say. The OAIC has not conducted a Commissioner-initiated investigation (CII) and did not make concluded findings on the matters involved. It is still open to me to commence an investigation of Qantas with respect to the breach or other practices.
The data breach experienced by Qantas Airways affected approximately 5.12 million Australians and came about as a result of a social engineering attack on an overseas third-party provider contracted by Qantas. Social engineering refers to situations where a malicious actor impersonates another individual to gain access to an account, system, network or physical location, bypassing technical security measures in the process.
The breach left many Australians concerned for their privacy, and frustrated that their personal information had been subjected to unauthorised access by hackers. As is standard procedure in major data breaches, the OAIC made preliminary inquiries to ascertain the causes of the data breach and identify any acts or practices on the part of Qantas that could warrant investigation.
What we found did not indicate a likelihood that Qantas had failed to take reasonable steps to protect the personal information it held at the time of the incident. Nor did it indicate a likelihood that Qantas failed to take reasonable steps to ensure its overseas third-party provider complied with the Australian Privacy Principles.
Qantas had reduced the impact of the breach by timely implementation of its incident management and reporting framework which sought to contain and remediate the data breach. Furthermore, Qantas’ post-incident remediation steps, which included engaging specialist teams to assist in forensic analysis of the incident and the provision of additional training, are examples of additional risk reduction measures. While they may not prevent all future intrusions, they are indicative of Qantas taking steps to reduce these risks.
I did not consider the evidence supported the likelihood of a breach and did not consider it an appropriate use of resources to commence an investigation.
If you haven’t, I urge you to read this report. It highlights the importance of keeping abreast of the changing nature of cyberthreats and constantly refreshing procedures to mitigate risk and to protect the security of personal information being held. I think it also makes a compelling argument against the approach that some adopt, of inadequate disclosure and non-cooperation with the regulator, in the hope that the problem will just go away.
Unfortunately, despite the prominent data breaches of recent years and the focus on prevention that has brought, the issue is not receding.
Our most recent published statistics revealed that 2025 saw the highest number of data breach notification reported to the OAIC since the mandatory data breach reporting scheme commenced in 2018. The OAIC received 1,205 data breach notifications in the 2025 calendar year, representing an 8% increase over 2024.
Cyber hacking remains the primary cause of data breaches reported to the OAIC. Of the 1,205 data breaches notified in 2025, the majority were attributable to malicious or criminal activity.
We have recognised the constant challenges for entities reporting under the scheme. That’s why we have published a quick reference guide for entities with obligations under the Notifiable Data Breaches scheme.
It’s a practical guide outlining the scheme’s requirements, helping to determine whether an assessment is required, whether to notify the OAIC and affected individuals, and how to do so. It provides quick access to essential information when an organisation might be grappling with a data breach and when they may be under significant pressure.
Facial recognition update
One other matter I will touch on is the Administrative Review Tribunal’s decision in the Bunnings facial recognition matter, which concerned the retailer’s use of the technology in 62 of its stores. The Tribunal found that Bunnings was permitted to use FRT.
However, it established something important about APP5 and the notification of collection. General signage about video surveillance was not sufficient. The novelty of facial recognition technology required more specific disclosure.
We have updated our guidance for entities that are considering using facial recognition technology in high volume and publicly accessible physical spaces such as retail shopfronts.
There is a high bar for using facial recognition technology in Australia. Retailers will continue to need to make contextual assessments of the legality of using FRT. A precautionary approach to the deployment of FRT is required under Australian law.
These clarifications provided by the Tribunal are welcome and add to our ability to apply the law. And while this application may not be applicable to your areas of work, it’s a further example of how we are shaping the privacy environment.
Artificial intelligence
Our ACAPS survey found very little trust in AI companies and that 93% of respondents said that it is not fair and reasonable for organisations to use personal information for training AI models and products such as chatbots.
Our focus has been primarily on interrogating certain instances of AI training to ascertain their compliance with the Act. We’ve been particularly interested in the privacy practices of AI companies, as well as of entities which hold existing stores of personal information that they repurpose to use to train AI models, and we have also been tracking closely the mainstream roll out of AI scribe technology.
We have always maintained that it is prudent to take a precautionary approach to embracing artificial intelligence so that we can maximise the benefits from that technology. Recent headlines have only emphasised the wisdom of that course.
The Economist Magazine alluded to the “wild west” nature of AI just last week, and took the analogy a step further.
As recent “loss-of-control” episodes by the most advanced models of Anthropic and OpenAI attest, agents, which are supposed to work on people’s behalf in “alignment” with their values, lie, cheat and steal if necessary. They break free from captivity and form harmful posses to do harm to people. They’d drink whisky and brawl if they could.
Interestingly, the magazine highlighted the growing market in AI-infrastructure firms who provide protection against AI agents that go rogue.
As lawyers, you are probably seeing the challenge firsthand. You no doubt are aware of court filings in Australia and elsewhere that have included false citations generated by AI, prompting warnings by the federal court. According to a French researcher who monitors such matters, as of last week there were 97 cases in Australia where generative AI produced hallucinated content – typically as fake citations.
The Federal Court now requires greater transparency and the use of safeguards where generative AI has been used.
This need for transparency is mirrored in community attitudes, and it’s something the OAIC has been pushing for. That’s why I am very pleased to be join a new body with a remit to shape AI deployment in the public sector at the point in the adoption lifecycle before the harms and risks crystalise. I've been appointed in my capacity as Privacy Commissioner to the new AI Review Committee, which will provide advice on high-risk, sensitive, complex or novel uses of AI in the public service.
Often, as a regulator, you're in the position of having to bring accountability or transparency to problematic acts and practices only after the damage to the community (and to reputations) has already been done.
Adjacent to this is the already legislated requirement for entities to be transparent about the use of Automated Decision Making, which comes into effect on December 10.
We will be shortly releasing our guidance for the ADM transparency obligation, having carried out consultation earlier in the year. Privacy policies will need to contain information about substantially automated decisions which significantly affect individuals’ rights or interests, including the kinds of decisions and kinds of personal information used.
Providing individuals with greater transparency allows them to understand how an entity handles their information and for what purposes, and allows them take further action if there has been a breach of their personal privacy.
Again, this is an issue of great concern to the public.
Conclusion
And when it comes to the public, industry should focus on limiting collection of personal information to what's necessary and proportionate, giving people real choices when it comes to their personal data and providing easy pathways for accessing and contesting uses of personal information.
The underlying principles of good privacy governance have not changed. Organisations should only collect only what is necessary, keep it safe, and if it is no longer needed, delete. Regularly carry out information audits to ensure the best possible outcomes.
Look widely to assess potential privacy risks, be frank in your assessment, and take action – before the damage is done. Keep surprises to a minimum.
We remain ready to use all elements in our regulatory toolkit to take action that can minimise harms and send a message. We remain vitally interested in issues of data minimisation, genuine consent and transparency. But I trust I have also conveyed that our actions are always proportional, and I also want you to have as much regulatory certainty as possible. The work we have been doing in the past 2 years has been about realising that goal.
Thank you.