Good morning
I would like to begin by acknowledging the Traditional Owners of the land on which we meet today, the Wurundjeri people of the Kulin Nation, and pay my respects to Elders past and present.
As Australia’s Information Commissioner, the subject of information governance is, not surprisingly, of great importance to me. I truly value the opportunity to engage with you today and view you as valuable allies in upholding the values of information governance, and with it, supporting fundamental values of democracy and justice.
As a government agency, we play a different role to many of you present and have different functions, but there is a clear overlap in interests due to our need to preserve information integrity and best practice record-keeping.
Information is a strategic asset ready to be harnessed. But there is always work to do to ensure its value is realised, and that it’s realised in a way that makes a positive contribution to both our society and the economy.
Information is being generated at an unprecedented rate, which has resulted in the management of information becoming a critical challenge in itself for both the private and public sectors. Because that information has to be accurate and reliable.
The volume and variety of information, and the speed at which it is created, has often overwhelmed traditional approaches to information governance.
Information management obligations don’t cease as organisations and industries embrace new technology. Rather, advances in technology have made it essential that openness, transparency, accountability and integrity are maintained.
For my organisation, the Office of the Australian Information Commissioner – an integrity agency – information governance touches upon all facets of our operations.
We have regulatory responsibility for 3 primary statutes and 37 other statutes. The human rights we promote, and preserve, are privacy and freedom of information (FOI).
As Information Commissioner, I also have the additional responsibility for systems, policies and procedures in relation to data governance in the Australian Public Service (APS).
It is one of our strategic goals to promote information integrity across the organisations we regulate – with a particular focus on the government sector.
Within that, we seek to ensure that:
- Regulated entities are transparent and open about how they adopt and use AI and automated decision-making
- The community experiences fairness, efficiency and accessibility when exercising their privacy complaints and FOI rights, and
- Regulated entities embed governance to ensure information integrity, privacy and FOI rights.
That demonstrates the scope of what we seek to do, encompassing the delivery of democratic ideals of justice and fairness while adapting to an environment of great technological change, and responding to the potential benefits, and potential pitfalls, of those technologies.
We are committed to ensuring that these rights of information access and privacy are preserved in emerging technologies, such as artificial intelligence.
For us, transparency and access are essential to promoting information integrity.
I know that for the work you do, where the need for accuracy is critical, the impact of AI is of vital interest. You no doubt are aware of court filings in Australia and elsewhere that have included false citations generated by AI, prompting warnings by the Federal Court. According to a French researcher who monitors such matters, there have been 97 cases in Australia where generative AI produced hallucinated content – typically as fake citations.
The Federal Court now requires greater transparency and the use of safeguards where generative AI has been used, which resembles our approach to the issue of AI and automated decision-making.
Later in my address, I will speak more about the work we do and how our mission is informed by information integrity as I believe it resonates with much of the work you do, whether it is through promoting access to information, record-keeping, or reducing risk.
Robust governance
So, what does robust information governance look like?
In many ways, our experience is not too dissimilar to your work in the courts, firms and academia. We need, and have, robust information governance guidelines in place, and many of these are applicable to your situation.
As a government agency that is entrusted with the personal information of many Australians, that deals with community complaints about FOI and privacy, that is a repository for government FOI statistics, that runs numerous investigations dealing with sensitive information, that has caseloads in the thousands – we have to walk the talk.
As a regulator of privacy and FOI, the OAIC is committed to modelling best practice in transparency, access to information and accountability through compliance with the Privacy Act 1988 (Privacy Act) and Freedom of Information Act 1982 (FOI Act).
We manage personal information in accordance with the Privacy Act and the Australian Privacy Principles (APPs). The policy addresses the types of personal information the OAIC collects, its use and disclosure, collection of sensitive personal information, how you can access and correct personal information, and how privacy complaints can be made.
In summary, we seek to:
- manage our information and data assets – both corporate and operational – strategically with appropriate governance and reporting to meet current and future needs of government and community
- implement fit-for-purpose information and data management processes, practices and systems that meet our identified needs for information and data asset creation, use and re-use
- reduce areas of information and data management inefficiency and risk to ensure public resources are managed effectively.
While the stakeholders will be different, this would not be dissimilar to the responsibilities you face.
We strive to be:
Consistent
Building strong information management foundations reduces divergent practices and non-compliance. We have consistent governance processes, in accordance with our plans and policies, while recognising the diverse practices of all teams and business functions across the OAIC.
Proactive
Technology facilitates the creation and management of information and data assets however information and data often have a lifespan longer than the technology cycle. Data and information will be considered as a separate entity to technology and governed in accordance with its value and risk. We continue to engage with new technologies to improve and empower information management practices.
Collaborative
Working together across branches and teams is critical to the work of the OAIC. To support this, the OAIC will seek out tools to support staff to communicate and collaborate, promote information sharing, and break down silos.
Accessible
Information and data assets will be governed to promote:
- usability as a valuable organisational asset
- accessibility through appropriate formats and metadata.
Our approach to information governance is not carried out in isolation. We work according to larger framework of government requirements such as the Building Trust in the Public Record Policy, developed by the National Archives of Australia.
That policy document states:
Government information is a public asset, and one that can have profound and enduring significance for communities. Managing it effectively is fundamental to sustaining public trust, and in this era of rapid data generation and increasing mis- and dis-information, this responsibility is more critical than ever.
There are 8 requirements that align with the principles for management of information assets. I have adapted them slightly for this talk.
Information assets should be:
- Governed systematically
- Created accurately and completely
- Described so they can be found and understood
- Stored securely and preserved so they remain usable
- Kept for as long as needed
- Accountably destroyed when no longer needed
- Kept in fit-for-purpose systems and managed according to value and use
- Available for reliable use and re-use.
That is a solid checklist, no matter the industry in which you work.
As a government agency, we are also encouraged to adopt cloud solutions, so we understand the challenges that face many of you.
There is a Whole-of-government cloud computing policy that provides a unified and practical framework for cloud adoption across the APS. It helps agencies move from ageing ICT environments to platforms that offer stronger resilience, scalability and security for government services. And we are encouraged to harness artificial intelligence to empower innovation and drive efficiencies.
It recognises that agencies today rarely create and organise their information assets centrally. Instead, they create and keep them in a variety of locations, onsite and cloud-based, using many formats, applications and systems.
This policy is designed to help agencies design for interoperability and portability and provide access to computing power to support new technologies and provide.
But this brings its own challenges. It is not a set and forget approach.
Formats and systems can become outdated and need active intervention to preserve the accessibility, authenticity and stability of content.
There is a risk that information can be siloed in different systems and may not be able to be retrieved or exchanged.
It requires effective governance, if you want to preserve a single source of truth in record-keeping.
Interoperability and portability are paramount.
It means that governance must assess risk, considering ways in which technological solutions can be future-proofed so that they will continue to meet stakeholder needs.
The flipside of future proofing is dealing with legacy technology, setting up a decommissioning roadmap, with milestones and timelines.
Your staff need to live and breathe information governance and understand the need for best practice at all times, and the need to keep information secure.
The issue of staff training is one that we regularly encounter through our oversight of the Notifiable Data Breaches Scheme, where organisations covered by the Privacy Act must notify affected individuals and the OAIC when a data breach is likely to result in serious harm to an individual whose personal information is involved.
Many times, we encounter situations where staff were not adequately trained, where processes have broken down, where the obligations of third parties were not considered adequately. Training needs to be refreshed on a regular basis and new risks assessed.
The work of the OAIC
As I previously mentioned, we have regulatory responsibility for 3 primary statutes and 37 other statutes. This means there are many exciting ways in which information governance interacts with our responsibilities.
As the independent national regulator for privacy and freedom of information, we promote and uphold your rights to access government-held information and have your personal information protected.
I’ll talk about freedom of information first.
The objects of the Freedom of Information Act 1982 (FOI Act) are explicit in the intention to promote Australia’s representative democracy. The FOI Act recognises that government information is a national resource and access to this information supports transparency, accountability and public participation in government decision-making.
Proactive disclosure of government information provides an important bulwark against misinformation and disinformation in an increasingly complex information environment. In an information landscape where government resources struggle to meet increasing demand and community expectations, it is critical we turn to initiatives that anticipate public need and have the dual impact of improving service delivery and increasing transparency.
Each year, we hold a day celebrating International Access to Information Day, celebrating the ways in which freedom of information can strengthen our society. This year’s international theme is Upholding Information Integrity in the Digital Age, which is a fortuitous coincidence with the subject of my address today.
The day has been a potent reminder of how important access to information is in many countries, particularly ones where democracy is under threat, and how access is a fundamental human right.
FOI is not an abstract ideal. It underpins public participation, scrutiny and confidence that decisions are being made for the public good. When it functions correctly, FOI promotes trust in the public service.
And there is strong community interest in access to information. The cross-jurisdictional 2025 Information Access Study showed 96% of Australians (up 5% from 2023), agree that their right to access government information is important.
Tens of thousands of Australians seek access to government-held information every year. The financial year just finished – 2025-26 – had applications at record levels. About three-quarters of applications are from individuals seeking personal information.
As regulators, we seek to make the system work as efficiently as possible, with timeliness of response a core goal. We monitor agency performance and where there are systemic issues of under-performance we seek to work collaboratively with agencies to find improvements.
Australians expect accountability and transparency – particularly where technology such as AI is being used to support automated decisions.
AI is a technology that will change the way we live and work. It is exciting and will have applications in freedom of information and can drive efficiency and make the overall system work better. There is the possibility of AI conducting records searches, applying redactions uniformly and identifying efficiencies in systems, the kind of potential productivity gains that you encounter.
But its use should not cause the sacrifice of fundamental tenets such as transparency, accountability and a human-centred approach.
Issues of transparency and record-keeping remain constant.
The OAIC earlier this year released a report, “Automated decision-making and public reporting under the Freedom of Information Act”.
Our report looked at whether agencies authorised to use ADM are being transparent about their use through the public reporting requirements contained in the FOI Act – and what regulatory guidance we can provide in response.
Information about decision-making and the exercise of agencies functions is important information for the Australian community. It improves integrity, accountability and trust.
In our report we did a desktop review of the websites of 23 government agencies authorised to use ADM. The review assessed how agencies disclose their use of ADM as ‘operational information’ required to be published under the FOI Act.
The Report highlights good practice but also opportunities for improvement for agencies to meet their obligations under the FOI Act to proactively publish information through the Information Publication Scheme. Only 4 of the surveyed agencies (or 17%) disclosed the use of ADM in their IPS.
The benefits of utilising ADM technology in government will only be realised if risks are appropriately mitigated and trust is built with the Australian community. A key enabler of trust is transparency and by leading the way in transparency ‘the government can build public trust in the technology and ensure its benefits are shared widely across society’.
Wherever we turn in this arena, we see a demand for transparency and reinforcement of the need for human-centred decision making.
Accurate record-keeping is also a key element in good administration of FOI, so that information can be retained and accessed to aid future decision-makers. Records can range from official policy documents to post-it notes. And we need to be on alert for ways in which technology can influence this process.
For example, the OAIC produced an influential report on the use of Messaging Apps like WhatsApp by Government departments to gauge whether they had appropriate policies to meet their record-keeping, FOI and privacy obligations. Were appropriate records being kept, or lost?
In the report we made on messaging apps by government agencies, we made 4 recommendations to ensure staff that are using these apps are able to meet FOI, privacy and record-keeping requirements:
- Agencies should review existing policies or develop a policy to clearly set out whether or not they permit the use of messaging apps for work purposes
- Agencies that permit the use of the apps should have policies and procedures that adequately address information management, FOI and privacy considerations
- They should examine the features of messaging apps needed to support official work, and do appropriate due diligence
- And they should also conduct due diligence to ensure the apps collect and handle personal information appropriately. This may be achieved through a privacy threshold assessment.
That focus on transparency in use of ADM also applies to privacy.
Starting on 10 December this year, entities covered by the Privacy Act that use ADM will need to disclose the following 3 items in their privacy policy:
- the kind of personal information used by an ADM program
- the kind of decisions made solely by ADM
- the kind of decisions for which a thing, that is substantially and directly related to making a decision, is done by ADM.
This transparency is important because:
- Transparency helps stop bias and discrimination
- Transparency enables contestability
- Black-box decision-making erodes trust
- Consumers deserve to know when ADM is used instead of a human decision-maker.
Our 2026 Australian Community Attitudes to Privacy Survey (ACAPS) 2026 found that expectations are clear for new and emerging technologies.
AI is a widely recognised privacy risk (69%), trust in AI companies is low (4%), and acceptance of AI uses involving personal information appears contingent on protections that make high impact uses transparent and contestable.
So again, there is this high awareness and sensitivity to the use of AI without the capability of human review.
And the public often do not trust that organisations will handle their personal information in the right way. They often do not trust organisations:
- to store their information securely
- to use and share their information only for the purposes stated
- to collect only the information needed
- to delete their information when no longer needed.
Unfortunately, data breaches are still prevalent and continue to make headlines.
The 2026 ACAPS identified data breaches as the top perceived privacy risk for Australians, with 82% of Australians concerned about the issue, up from 74% in 2023.
Conclusion
The issue of information governance is broad issues and there are many other areas I could address, such as the use of data sets and deidentification.
I am grateful that you have recognised that integrity is central to our end goal.
The OAIC is an integrity agency. We support rights that are pro-integrity.
The Australian Government has published a Commonwealth Integrity Strategy that has metrics that directly focus on agency performance of both privacy and FOI functions.
I trust I have made it clear the impact that sound information governance practices can have on our society. They go beyond your daily work – there is a bigger picture that involves fundamental human rights and the support of democracy.
Thank you for the important work you do.