The Australian government has agreed to amend the Privacy Act to make automated decision-making more transparent. The changes include defining “types of personal information that will be used in substantially automated decisions” affecting individuals’ rights and enshrining “a right to request meaningful information about how automated decisions are made.” The government aims to ensure that information provided to individuals is comprehensible and does not reveal commercially sensitive data. These changes could impact decisions in various sectors, including financial services, housing, insurance, education, criminal justice, employment, and healthcare.
Additionally, the government plans to introduce criminal penalties for “malicious re-identification” of information, where there is intent to harm or obtain an illegitimate benefit. The details of how de-identification and re-identification will be defined will be subject to consultation.
Furthermore, the government acknowledges that the Privacy Act needs to include technical and organizational measures to protect user data effectively. It agrees that the Office of the Australian Information Commissioner should provide additional guidance on reasonable steps organizations should take to secure and destroy or de-identify personal information. However, the government has only agreed in-principle to require entities to comply with a set of baseline privacy outcomes aligned with the Australian Cyber Security Strategy.


