Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

Australia · Privacy Act 1988

Notifiable Data Breaches & APPs.

Applies to: APP entities handling Australian personal information. Built · NDB since 22 Feb 2018 · APP 1.7 automated decisions from 10 Dec 2026

What the signed record shows

Eligible-breach assessment records, governance signals, and breach detail for OAIC notification.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: Privacy Act 1988 Part IIIC s.26WH/26WK/26WL; APP 1/11; APP 1.7 (from 10 Dec 2026)

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Privacy Act 1988 (Cth). Provisions addressed:

Part IIIC
Notifiable Data Breaches (NDB) scheme:
s. 26WE
meaning of "eligible data breach".
s. 26WH
assessment of a suspected eligible data breach.
s. 26WK
statement about an eligible data breach (content for the OAIC).
s. 26WL
entity must notify the OAIC (Commissioner) and affected individuals.
Schedule 1
Australian Privacy Principles:
APP 1
open and transparent management of personal information.
APP 11
security of personal information. The NDB scheme came into force 22 February 2018 (Part IIIC), amended by the Privacy and Other Legislation Amendment Act 2024.
APP 1.7
Automated decision-making transparency, commencing 10 December 2026. Inserted into Schedule 1 by the Privacy and Other Legislation Amendment Act 2024. Where an APP entity uses a computer program to make, or to substantially assist in making, a decision that could reasonably be expected to significantly affect the rights or interests of an individual, and personal information is used in that program, the entity’s privacy policy must set out specified information about that use. The obligation reaches AI-assisted decisions, not only fully automated ones.

Taken from the Regulayer entry for this instrument, which is built against the primary text.