Home / Rules / Privacy Act 1988 (Cth)
Privacy Act 1988 (Cth): the rules AI agent steps rest on
- Edition
- Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026
- Checked current
- 2026-10-06
- Official source
- https://www.legislation.gov.au/C2004A03712/latest/text
| Rule | Our statement | Steps that cite it |
|---|---|---|
| Privacy Act s 26WE(2) | An eligible data breach is unauthorised access to or disclosure of personal information, or its loss where unauthorised access or disclosure is likely, that a reasonable person would conclude would be likely to result in serious harm to any of the individuals it relates to. | KC-02 S2 What happened to the information?; KC-02 S3 Is it an eligible data breach?; KC-05 S4 Privacy Act: is it an eligible data breach? |
| Privacy Act s 26WG | In judging whether serious harm is likely, have regard to the kinds and sensitivity of the information (health information is sensitive information), any security protection and the chance it is overcome, who has obtained or could obtain it, and the nature of the harm. | KC-02 S3 Is it an eligible data breach? |
| Privacy Act s 26WK | As soon as practicable after becoming aware that there are reasonable grounds to believe there has been an eligible data breach, the entity prepares a statement setting out its identity and contact details, a description of the breach, the kinds of information concerned, and recommendations about the steps individuals should take, and gives a copy to the Commissioner. | KC-02 S4 What must be notified, and when?; KC-02 S6 Who acts on the drafts?; KC-05 S4 Privacy Act: is it an eligible data breach? |
| Privacy Act s 26WL | As soon as practicable after preparing the statement, the entity takes reasonable steps to notify its contents to each individual to whom the information relates, or to each individual at risk; if neither is practicable, it publishes the statement on its website and takes reasonable steps to publicise it. It may notify an individual by the method it normally uses to communicate with that individual. | KC-02 S4 What must be notified, and when?; KC-02 S5 Who is notified, how many, and how?; KC-05 S4 Privacy Act: is it an eligible data breach? |
| Privacy Act s 26WM | Where the same breach is an eligible data breach of more than one entity, a statement prepared and notified by one of them satisfies the duty for the others. | KC-05 S4 Privacy Act: is it an eligible data breach? |
| Privacy Act s 6D(4)(b) | An entity is not a small business operator if it provides a health service to another individual and holds any health information except in an employee record. Such an entity is an organisation bound by the Australian Privacy Principles whatever its turnover. | KC-02 S1 Does the Privacy Act bind the entity? |