Skip to main content
Published:  

Good morning.

We have regulatory responsibility for 3 primary statutes and 39 other statutes. The human rights we promote, and preserve are privacy and freedom of information (FOI) – and they intertwine in many fascinating ways.

As Information Commissioner, I also have the additional responsibility for systems, policies and procedures in relation to data governance in the Australian Public Service (APS).

Strong data protection and privacy rights are both necessary to uphold our human right to dignity in the digital age. And managing information well is a foundation for protecting human rights.

The evidence shows that people want more transparency from government and are deeply concerned about their privacy rights. At the same time, rapid changes in technology and data systems are changing how public information is created and how personal information is used.

Today, I will talk to you about the range of varied work we do and also talk about the strategic plan we have just completed, and give you an insight into what lies ahead.

How are regulators responding

Faced with this challenging world, how are regulators responding? One way is by regulation and enforcement.

As observed by the OECD the digital age poses complex challenges for governance and regulation. Our traditional regulatory approach will not serve us well in an increasingly dynamic digital environment. We need to deploy a greater focus on ex ante regulation.

In an AI environment we need to focus on emerging and latent harms. We are increasingly dependent upon co-regulation and the sharing of information between regulators. We need to adopt an anticipatory regulatory posture; one which recognises the value of incentivising compliance and that equips the regulator with the tools required to monitor practices in real time, and the powers to intervene to inquire and require substantiation. Regulatory effort in this way better reflects an approach that prevents harm and assures compliance.

Another way we respond to our environment is by gathering data through comprehensive surveys about privacy and information access. This informs our regulatory approach as well as widens awareness among our stakeholders.

The Australian Community Attitudes to Privacy Survey 2026 found that only 10% of people thought organisations handle their data fairly, and 9 out of 10 told us they didn't want their data collected for one thing to be used for another without their consent, like targeting ads, training AI models, or being sold onto third parties

Promisingly – and here is an incentive for you all – itfound that two-thirds of respondents said they would be more likely to use digital services requiring personal information if they believed their data was handled fairly and responsibly.

And there is strong community interest in access to information. The cross-jurisdictional 2025 Information Access Survey showed 96% of Australians (up 5% from 2023), agreed their right to access government information is important.

This desire – for stronger privacy protections and greater information access – are reflected in our caseload statistics.

The community’s focus on these fundamental rights has directed our case management strategies to major increases in productivity and timeliness.

Our case management report details the Australian community’s engagement with the OAIC from July 2025 to March 2026. We saw a significant increase in incoming matters across case types from 1 July 2025 to 31 March 2026, with 18,164 incoming matters, compared to 14,125 in the 2024-25 financial year. We resolved 6,856 matters compared to 5,326 in the year before. Such demand raises challenges for us as an organisation and requires us to be strategic, flexible and agile in our approach.

While consistent progress continues to be made to improve case finalisation rates, the number of Information Commissioner reviews, FOI extension of time applications and individual privacy complaints received continues to increase consistently and at rates exceeding previous years. The data indicates internal measures, while effective to date, need to be accompanied by the action of entities external to the OAIC to deliver systemic shifts in practice and performance.

Transparency as a right under the FOI Act

We conducted a desktop review of 23 government agencies’ websites who are authorised to use ADM. The final report looked into whether agencies authorised to use ADM are being transparent about their use through the public reporting requirements contained in the FOI Act – and what regulatory guidance we can provide in response. We found that information published about ADM use was limited, with only 17% disclosing its use.

Information about decision-making and the exercise of agencies’ functions is important for the Australian community. It improves integrity, accountability and trust.

The benefits of utilising ADM technology in government will only be realised if risks are appropriately mitigated and trust is built with the Australian community. A key enabler of trust is transparency, and by leading the way in transparency, the government can build public trust in the technology and ensure its benefits are shared widely across society.

Wherever we turn in this arena, we see a demand for transparency and reinforcement of the need for human-centred decision making.

Transparency as a right under the Privacy Act

The fundamental human rights of information access and privacy are not, as generally thought, divergent. Their common pathway is information governance to create, preserve and access information and to secure the right to transparency by entities responsible for these functions.

ACAPS found that Australians remain cautious about the use of AI in decision-making that may affect them, with nearly all saying some conditions should be in place before it is used. Australians expect organisations to be open about how AI is used and how decisions are made, with particular concern about decisions that may impact eligibility for financial support.

This helps explain the need for the Automated Decision-Making (ADM) transparency obligation in the Privacy Act 1988, which come into effect on 10 December. Privacy policies will need to contain information about substantially automated decisions, which significantly affect individuals’ rights or interests, including the kinds of decisions and kinds of personal information used.

This transparency is important because it helps stop bias and discrimination, enables contestability,  and consumers deserve to know when ADM is used instead of a human decision-maker.

We are on the verge of releasing our guidance for the ADM transparency obligation, having carried out consultation earlier this year.

Our actions on proactive disclosure and transparency of ADM and AI complement the Administrative Review Council’s core functions to monitor and improve the Commonwealth administrative law system. I am an ex officio member of the ARC. This role offers a significant opportunity to contribute to the administrative decision-making system operating in the Commonwealth jurisdiction.

The Administrative Review Council recently published a Statement of Position to guide Australian Government agencies as to how they should respond to administrative review decisions made by courts and tribunals. That statement recognises the rapid development and deployment of AI and ADM by government agencies and the inherent risk of bias or incorrect decisions. The remediation required in the context of automated systems can be challenging and therefore delayed with resultant adverse impacts on the community.

The Council’s position is that, as a matter of law, agencies must comply with decisions of courts and tribunals. If an agency disagrees with a decision about the interpretation of the law, it cannot ignore it.

In the current environment, the sound application of fundamental administrative law principles combined with integrity oversight is more important than ever.

Understanding through education

With principles secured we can then turn to the application of technology in our contemporary environment. We also use materials such as blogs and case studies to build that understanding by both the community and by respondents. Our vision is to empower respondent entities and the community through guidance to prevent harms occurring and to stem the escalation in disputation in this dynamic regulatory environment.

Subjects we have addressed include the opportunities and challenges of generative AI tools in the workplace, and the merits of good administration in the FOI system.

We have published 2 reports about preliminary inquiries – which did not result in official investigations – because we believed there was great value in doing so.

One of these was into i-MED Radiology, in relation to the alleged disclosure of medical scans to a third party for the purposes of training an AI model. The other was into the data breach at Qantas last year, which involved a social engineering attack.

Both provide insight into the OAIC’s decision-making process, explore complex matters, and demonstrate our proportional approach.

One matter with high community relevance was our investigation into the RentTech sectors with a company called InspectRealEstate or IRE for short.

The decision is under review. However, our decision as published found that the 2Apply rental platform interfered with the privacy of individuals by collecting excessive personal information from rental applicants beyond what was ‘reasonably necessary’ for one or more of its functions or activities and using unfair collection practices. Among our findings, we found there was a significant power imbalance between renters and real estate agents, property managers and landlords.

In a first for the OAIC, the decision considered the design, structure and way information is conveyed in the 2Apply form and utilised the concept of online choice architecture, which describes how the presentation and structure of choices presented to individuals can shape how they make decisions.

Children's online privacy code

December the 10th will be an important day, because as well as the ADM transparency obligation coming into effect, the new Children’s Online Privacy Code (the Code) must be finalised and registered.

The Code, developed by the OAIC, specifies how online services, like apps, games and websites, likely to be accessed by children or primarily concerned with the activities of children, must comply with the Australian Privacy Principles (APPs). The Code also sets out additional requirements in relation to the handling of children’s personal information.

While the primary objective of the Code is to improve privacy protections for children, it will also play an important role in uplifting privacy practises across entities more broadly. This is the type of anticipatory regulation required to prevent harm. The aim of the Code is not to prevent children from engaging online, but to ensure their personal information is protected within the digital ecosystem.

Consultation has been at the heart of this project – including widespread consultation with those who will be affected most – children and their carers.

The Code is not being developed in isolation. The Children’s Online Privacy Code, the Social Media Minimum Age scheme (SMMA) and eSafety’s Age-Restricted Material Codes are complementary in delivering stronger protections for children online, but they do different things.

Our strategic plan 2026-29

Within the OAIC we have considered the colossal changes impacting our regulated environment and we have responded with a future focused strategic plan. We have strengthened our organisational culture, regulatory approach and enterprise practices in the last 2 years, building our profile as a proactive and proportionate regulator.

We have identified 3 core strategic impacts:

1. Address power and information asymmetries – We will even the playing field to promote compliance and ensure people can actively exercise their rights to privacy and access to information.

  • Regulated entities will need to embed a positive information rights culture that delivers open access to information and privacy by design in all products and services.
  • Government policy will be informed by the OAIC’s expertise and insights on information integrity and privacy issues, including in new technologies.​
  • The rights of people experiencing vulnerability are prioritised and protected​ because this is where harm can be most acute

2. Promote information integrity – We will promote integrity in information systems, and governance​.

  • Regulated entities will need to be transparent and open about how they adopt and use AI and ADM.
  • We want the community to experience fairness, efficiency and accessibility when exercising their privacy complaints and FOI rights​.
  • Regulated entities should embed good governance to ensure information integrity, privacy and FOI rights​.

3. Embed fairness, accountability and transparency in new technology – We will ensure new technologies do not undermine people’s information rights.

  • Regulated entities should use new technologies in ways that support effective, safe and fair management of personal information, and promotes accessibility of government information​.
  • Expectations and standards relating to compliance with privacy and FOI obligations in the context of new technologies will be clear.​
  • Our compliance and enforcement action will be robust and proportionate, serving community interests​.

These strategic impacts are central to our goal of increasing public trust in Australia’s privacy and FOI systems. And they are all connected by information – managing its flow, protecting it where required, and using it wisely. And they are all reinforced by integrity.

Tranche 2 privacy reforms

And there are further changes ahead.

Just over a fortnight ago the Attorney-General announced a planned revamp of Australia’s privacy laws – the so-called Tranche 2 initiatives.

At the moment, these reforms are in the form of a consultation paper and draft legislation, so there is a way to go. The consultation process runs until 18 September, and all interested parties are encouraged to have their say – so you have just 3 days left.

While the final legislation and its path through Parliament is not finalised, our view is that the proposed measures are a welcome step in modernising the Privacy Act for the digital era. The Attorney-General’s Department is aiming to strike the right balance between protecting individuals’ personal information and allowing it to be used and shared in ways that support better services, innovation and economic growth.

The headline initiatives from the Attorney-General’s announcement are:

  • a fair and reasonable test for data collection and use
  • a right to erasure from large digital platforms
  • stronger, more meaningful consent standards
  • measures to stop the trading of personal information without clear permission.

The proposal that’s most exciting is for the fair and reasonable test. This is one we have supported consistently and is a landmark advancement in establishing a general requirement for data practices to protect individuals instead of just relying on consent and notice. This will require collection, use and disclosure to be fair and reasonable in the circumstances, regardless of individual consent.

It addresses the current power imbalance inherent in the existing framework by shifting the responsibility to entities to proactively consider the impact on individuals.

This reform will be experienced through its operationalisation – that means testing the policy intent in practice – in the context of its regulation. To regulate harms arising in this digital environment we must be equipped to act rapidly – we are engaging the values of the Australian community in the face of global tech giants.

To secure these rights we will require the best regulatory tools. Looking at the regulatory toolkit deployed to facilitate swift action we see the value in substantiation notices – as an immediate and cost-effective way of evaluating a respondent entities’ assertion that the practice was fair and reasonable in the most.

Another useful power would be administrative warnings – putting entities on notice that if they proceed to introduce products to market without strengthening privacy protections, this could be considered aggravating circumstances in any subsequent proceedings for an interference with an individual’s privacy.

We also consider that anticipatory regulation could be supported by a widening of our regulatory powers to investigate proactively rather than in response to a complaint. Building on the concept underpinning the data notification scheme a central notification system of adverse harm would also facilitate swift regulatory action.

International Access to Information Day

Finally, I want to highlight another information issue that is of increasing concern and may not be on your agenda – that of misinformation. As an integrity agency, information integrity is of critical interest to our organisation, and to the wider community.

The responsiveness of governments globally, to the threat to information integrity may be a litmus test of democracy itself.

The UNESCO theme for the 2026 International Access to Information Day 2026, which will occur in the coming weeksis poignant: "Upholding Information Integrity in the Digital Age: The role of access to Information in addressing Information Disorder".

Information disorder is a current challenge. In the digital environment it has a heightened potential for harm through the use of ‘fakes’; mis and disinformation and the algorithms that curate and feed our content.

Information integrity is the antidote to information disorder. Information integrity is secured through the construction of conditions for creation, preservation and access to information that are contemporary and enduring. Government has a role to play in both dissemination of information and in developing and applying safeguards.

One of the best treatments for the harms associated from information disorder is transparency. People cannot challenge that which they cannot see.

In line with our regulatory priorities of ensuring rights preservation in emerging technologies, and strengthening the information governance of the Australian Public Service, the OAIC is finalising a Statement of Principles for the APS to assist in achieving the productive and beneficial goals of AI whilst ensuring the preservation of the fundamental human rights of information access and privacy. These principles will recognise the significant trust placed by the Australian people on the APS for its responsible stewardship and governance of AI to act in the interests of the public.

This guidance may also impact the design, development and deployment of AI more broadly through the Australian governments purchasing power and provide the community with greater confidence that their rights are preserved.