Does Privacy Act 1988 — Automated Decision-Making Reforms require Risk Assessment?
Australia • enacted
Yes — 1 provision
Requirements at a glance
This regulation imposes 3 specific requirements for Risk Assessment across 1 provision:
- Privacy Impact Assessment — Must conduct PIA before deploying AI systems handling personal information
- Proactive disclosure — Must proactively disclose AI use at the point of data collection
- Third-party assessment — Remain responsible for data shared with external AI platforms
Privacy Impact Assessments for AI #
Requirements
| Requirement | Details |
|---|---|
| Privacy Impact Assessment | Must conduct PIA before deploying AI systems handling personal information |
| Proactive disclosure | Must proactively disclose AI use at the point of data collection |
| Third-party assessment | Remain responsible for data shared with external AI platforms |
Penalties
| Violation | Fine |
|---|---|
| Serious breach | Significant civil penalties per Privacy Act enforcement provisions |