OAIC — Australia’s privacy, FOI and Consumer Data Right regulator
The OAIC is Australia’s national privacy regulator and a steady publisher of guidance that UK practitioners can borrow from — breach triage, facial-recognition risk assessment, AI product due diligence and privacy impact assessments among them.
- Published by
- Office of the Australian Information Commissioner — an independent statutory agency in the Attorney-General’s portfolio, headed by the Australian Information Commissioner.
- Type
- Statutory regulator; guidance publisher.
- Versions and language
- English; the site also offers community-language summaries.
- Jurisdiction
- Australia (Commonwealth). The Privacy Act applies to Australian Government agencies and to organisations with annual turnover above AUD 3 million, plus specified others.
- Primary audience
- Privacy officers; DPOs of groups with Australian entities; processors.
- Topic tags
- Australian Privacy Principles · notifiable data breaches · PIAs · facial recognition · AI · Consumer Data Right · FOI
- Availability
- Free.
Why it matters
The OAIC’s functions cover three regimes — the Privacy Act 1988, the Freedom of Information Act 1982 and government information policy under the AIC Act — and, in addition, the Consumer Data Right and Digital ID. On privacy it handles complaints, runs Commissioner-initiated investigations and privacy assessments, registers enforceable codes, can direct an agency to produce a privacy impact assessment, and recognises external dispute-resolution schemes.
Its guidance for organisations is where the value sits for a UK reader: the notifiable data breaches scheme guidance and a 2026 quick-reference breach guide, built around a “reasonable person” serious-harm test that reads well against Article 33; a facial recognition privacy-risk guide; a matched pair of guides on commercially available AI products and on developing generative AI models; and a privacy-foundations self-assessment tool.
The UK position. Australia has no UK adequacy decision; transfers from the UK need an Article 46 tool, and Australian Privacy Principle 8 governs the other direction. The Australian regime is principles-based with a turnover threshold, so the guides are best read for method — checklists, triage and proportionality reasoning — rather than as statements of UK obligations. The OAIC’s regulator profile sits in Regulators & Authorities.
