The definition that does the AI work
Privacy tranche two is one of the government’s five AI safety priorities, and
we noted on 4 October that it now
has draft legislation. Having read the draft and its 42-page consultation paper in full,
the answer to what it does about AI is narrower and more useful than a new AI law. The
Attorney-General’s Department says on the consultation page that the reforms will
help tackle emerging risks from new technologies, including artificial intelligence and
wearable devices such as smart glasses
. The bill does that almost entirely through
definitions.
The key one is new section 6AAA. An entity collects personal information only if
the entity collects the personal information for inclusion in a record or generally
available publication (regardless of the source from which or means by which the
information is collected)
. The note under it gives the examples that matter for AI:
means of collection include generating the information itself using its own processes,
systems, observations or measurements, or deriving it from other information
.
The consultation paper spells out the intent twice. On page 7 it says personal
information may be generated or derived through means such as data analysis, artificial
intelligence or other technological processes
. On page 41, under emerging
technologies, it says: This reform will ensure that inferences drawn by AI-enabled
technology about an individual would be considered collection of information for the
purpose of the Act.
The paper calls this clarifying the definition, and it rests on a
second change: personal information becomes information that relates to
an
identified or reasonably identifiable person, with a note listing characteristics,
behaviours, traits, preferences or patterns of activity
as information that can make
someone identifiable. A profile is squarely in that list.
What being a “collection” would trigger
Calling an inference a collection matters because of what the draft attaches to collection.
| If the inference is | The draft requires | Where |
|---|---|---|
| Any personal information | The collection must be fair and reasonable in the circumstancesand lawful. Factors include whether a reasonable person would expect it, whether the purpose could be met with less information, whether the person has genuine choice, whether any risk of harm is proportionate, and, for a child, the child’s best interests as a primary consideration | New APP 3.1 and 3.2 |
| Sensitive information (racial or ethnic origin, political opinions, religious beliefs, sexual orientation, health, criminal record and others) | An APP entity must not collect sensitive information that relates to an individual unless the individual has consented to the collection of the information, subject to exceptions | New APP 4.1, 4.3 |
| Sensitive, and for direct marketing | The strictly necessaryexception can never apply: such a collection is never strictly necessary | New APP 4.5 |
The draft is careful about when a sensitive inference is collected. Holding ordinary
data from which something sensitive could be worked out is not enough: An entity is not
taken to collect sensitive information only because the entity collects personal
information from which the sensitive information can be derived.
The sensitive
information is collected when the entity derives it for a record, uses or discloses it, or
at the start if that was the purpose all along. The paper’s example is a halal meal
order: not sensitive information when it is used to deliver a meal, but a collection of
religious belief once the entity uses it to send marketing about a religious festival.
The exceptions an AI builder would look at first
The consent rule for sensitive information does not apply when the information is
collected from a publicly available document
. The paper says that definition is
intended to be broad
and that a publicly available document may also include
other publicly accessible material, such as social media posts
. The fair and
reasonable test still applies in that case: its own exceptions, in APP 3.3, cover only
collections required or authorised by law and the permitted general and health
situations.
The draft also gives a right to erasure, a new APP 14, but only against a
large digital platform: a provider of a social media service, relevant
electronic service or designated internet service under the Online Safety Act whose
business group had gross revenue of at least $500 million in the previous financial year,
or whose service averaged at least 2.5 million monthly end users in Australia, or which is
prescribed by regulation. eSafety’s 2024 industry standard defines a high impact
generative AI service as a designated internet service
that uses machine
learning models to enable an end-user to produce material
, and we have explained
why generative AI services generally fall in that
class. On our reading, a large enough chatbot provider would be inside the erasure
right. The platform would have to destroy the information on request unless an exception
applies, one of which is that, despite reasonable steps, destruction is unreasonable or
impracticable due to technical impossibility or infeasibility
.
Neither document says how any of this applies to information inside a trained model. The words model, training and trained do not appear in the exposure draft or the consultation paper.
When, and what it is not
This is an exposure draft, not law and not yet a bill. The department’s page
says The Bill remains subject to further consideration by government
. The
consultation opened on 31 August and closed on 18 September. The draft’s
commencement table has no entries, and its transitional item says the new definition of
collects would apply in relation to collections made on or after the commencement of
this item
, so an inference made before then would not be caught by the new collection
rules. A ParlInfo title search for the bill on 7 October returned no results.
It is also separate from the automated decision-making rule that starts on 10 December. That obligation, to say in a privacy policy when a computer program makes decisions that significantly affect people, is already law from the 2024 amendments; we covered what counts as an automated decision under it. The 10 December rule is about decisions. This draft is about the information, and the inference is where it starts.
Our view
Handling AI through the definition of collection is the right design. The paper says
the Privacy Act is intentionally technology neutral and principles based
, and a
rule that turns on whether you generated information about a person will not date the way
a list of AI techniques would. It also closes the most obvious gap in practice: a business
that never asked for your health status but has a system that works it out would, under
this draft, have collected it, and would need your consent unless an exception applied.
Two things weaken it. The publicly available document exception is broad by design,
and the draft does not say whether a sensitive inference drawn from public posts is
collected from a publicly available document
or derived by the entity, which is the
whole question for anyone building on scraped data. And the erasure right, the one place a
person could make an AI company delete what it holds, says nothing about models. If
government means inferences and models to be covered, the introduced bill or its
explanatory memorandum should say so in those words.
Sources
- Exposure Draft, Privacy Amendment (Personal Data Protection) Bill 2026, Attorney-General’s Department, 58 pages (PDF downloaded and read in full 7 October 2026): the blank commencement table (p 2); section 6AAA and its note (pp 4-5); section 6FD and note 1, section 6FE, and Schedule 1 transitional item 13 (pp 6-8); APP 3.1 to 3.4 (pp 12-13); APP 4.1 to 4.5 (pp 14-15); section 6EB and its end-user method statement (pp 43-45); APP 14.1 to 14.3 (p 46). Absence of the AI terms checked against the DOCX version from the same page.
- Privacy Reform, Consultation Paper, Attorney-General’s Department, 42 pages (PDF downloaded and read 7 October 2026): roughly 40 proposals (p 1); the definition of collects and the halal meal example (p 7); the publicly available document exception (pp 16-17); large digital platforms and the right to erasure (pp 33-35); addressing emerging technologies (pp 41-42).
- Privacy Reform, Consultation on Exposure Draft legislation, Attorney-General’s Department, Citizen Space (read 7 October 2026): opened 31 August 2026, closed 18 September 2026; the AI and smart glasses framing; the Bill remains subject to further consideration by government.
- ParlInfo bills search, title “Personal Data Protection”, Parliament of Australia (run 7 October 2026): no results found.
- Online Safety (Designated Internet Services, Class 1A and Class 1B Material) Industry Standard 2024, eSafety Commissioner (PDF, read in full 4 August 2026; definition re-read 7 October 2026): the definition of a high impact generative AI DIS, section 6, printed page 8.
How we checked this. Both documents were downloaded from the department’s consultation page and read in full; every quotation is verbatim. The absence of the words artificial intelligence from the draft, and of model, training and trained from both documents, comes from a full-text search of the PDF and DOCX text on 7 October; the draft’s only use of “automated” is in the sensitive information definition, about biometric verification. Whether a generative AI service is a large digital platform is our reading of section 6EB with the eSafety definition, not a statement by the department. We have not compared the new definition of collects with how the courts or the regulator read the current one. The ParlInfo absence is about that search on 7 October; a bill introduced since may not yet be indexed. We have not asked the department about the points in “Our view”, which is opinion based on the documents cited.
Made a submission on the draft, or read section 6AAA differently? Tell us and we will check it against the document and log the outcome here.