Featured image for Privacy Reform Hits HR showing a December 2026 calendar with 10 December highlighted alongside privacy, security and compliance symbols.

Privacy Reform Hits HR: The Statutory Tort, the Employee Records Exemption, and the December 2026 Deadline for Automated Decisions

Two things have changed in Australian privacy law that most HR functions have not yet absorbed. 

The first is already in force: since 10 June 2025, individuals can sue for a serious invasion of privacy — and the employee records exemption does not apply to that action. The second lands on 10 December 2026, when employers using software to make or materially assist decisions about people must disclose it in their privacy policy. 

Between them, they reach the things HR does every day: surveillance, investigations, disciplinary processes, information sharing, recruitment screening and performance analytics. 

What’s the real issue? 

The real issue is that most employers have organised their privacy thinking around a single reassuring proposition: “employee records are exempt.” 

That exemption is real, but it is far narrower than the confidence placed in it. It does not cover prospective employees who are not subsequently employed. It does not cover contractors. It does not cover customers or clients. It does not displace confidentiality, contractual or security obligations. And it does not apply to the new statutory tort at all. 

At the same time, HR has quietly become one of the most automated functions in the business — applicant tracking systems that rank candidates, rostering algorithms, engagement and attrition analytics, productivity monitoring, and increasingly AI features embedded in platforms nobody procured as “AI”. From December 2026, that automation carries a disclosure obligation. 

What this looks like in practice 

An anonymised composite, not a real organisation. 

A mid-sized Queensland employer ran a workplace investigation into a complaint about a manager. In the course of it: 

  • The investigator collected material from the manager’s work email and calendar, including personal correspondence, without any documented basis or notification. 
  • Findings were circulated by email to a leadership group of eleven people, most of whom had no need to know. 
  • The recruitment platform used to hire her replacement automatically scored and ranked applicants. Nobody in HR could explain what the scoring was based on, and the organisation’s privacy policy said nothing about it. 
  • The organisation’s privacy policy had not been reviewed in four years. 

Each of these was defensible-looking in isolation. Together they created exposure on three fronts: a potential serious invasion of privacy claim not answered by the employee records exemption, a discrimination risk in the automated ranking, and a disclosure gap that would breach the Privacy Act from December 2026. 

What does the law say — and how must it be applied? 

  1. The statutory tort for serious invasions of privacy

Introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth), the tort applies to conduct occurring on or after 10 June 2025. Its elements are: 

  • an invasion of privacy — either intrusion upon seclusion or misuse of information relating to the person; 
  • the person had a reasonable expectation of privacy in the circumstances; 
  • the invasion was intentional or reckless; 
  • the invasion was serious; and 
  • the public interest in privacy was not outweighed by any countervailing public interest. 

Individuals can seek damages, injunctions and other orders. Defences include that the invasion was required or authorised by or under an Australian law or a court or tribunal order, consent, and a reasonable belief that the invasion was necessary to prevent or lessen a serious threat to a person’s life, health or safety. 

Critically, the employee records exemption does not apply to the tort. An employer cannot answer a serious invasion of privacy claim by pointing to the exemption. For HR this bears directly on surveillance and monitoring, evidence gathering during investigations, disciplinary processes, and how widely findings and personal information are shared internally. 

  1. The employee records exemption — narrower than assumed

Private sector employers currently remain exempt from the Act in relation to their handling of employee records, where the act or practice relates directly to a current or former employment relationship. The exemption also affects notifiable data breach obligations for that material. 

It does not apply to: 

  • information collected about prospective employees who are not subsequently employed; 
  • contractors; or 
  • the statutory tort. 

Nor does it displace confidentiality, contractual, security or work health and safety obligations. 

Reform is proposed. The direction of the proposals is to extend stronger protections to employees — greater transparency about how their personal information is used, while preserving employers’ ability to collect, use and disclose information where necessary; protection of employee information from misuse, loss and unwanted access, with destruction when no longer needed; and notification to employees and the Information Commissioner of data breaches involving employee information likely to result in serious harm. Related proposals would require entities to keep records of the purposes for collecting, using and disclosing personal information, and to collect, use and disclose data only where fair and reasonable. 

This matters because several high-profile Australian data breaches have involved employee records as well as customer records — and the exemption has never protected the organisation from the operational and reputational consequences of losing them. 

  1. The small business exemption

The exemption for businesses with annual turnover under $3 million remains in place, subject to existing carve-outs such as health service providers. Removing it has been proposed, but only after an impact analysis, consultation with small business to develop appropriate support, determining how to make obligations proportionate to risk, and ensuring small businesses are able to comply. Employers close to the threshold — or growing toward it — should plan on the basis that the exemption is temporary. 

  1. Automated decision-making transparency: the 10 December 2026 deadline

New Australian Privacy Principles 1.7, 1.8 and 1.9 commence on 10 December 2026. 

APP 1.7 requires an entity’s privacy policy to contain the information set out in APP 1.8 where: 

  • the entity has arranged for a computer program to make, or to do a thing that is substantially and directly related to making, a decision; 
  • the decision could reasonably be expected to significantly affect the rights or interests of an individual; and 
  • personal information about the individual is used in the operation of that program. 

APP 1.8 requires disclosure of the kinds of personal information used; the kinds of decisions made solely by the operation of such programs; and the kinds of decisions for which something substantially and directly related to making the decision is done by such programs. 

APP 1.9 clarifies that making a decision includes refusing or failing to make one, doing a thing includes refusing or failing to do it, and a decision may affect an individual’s rights or interests whether the effect is adverse or beneficial. 

The OAIC released an issues paper on 18 May 2026 with submissions closing 15 June 2026, and has indicated final guidance around September 2026. That leaves a short runway to commencement — and organisations waiting for finished guidance before starting their inventory may have only weeks. 

The OAIC’s own worked example is instructive for HR: an engineering firm advertises graduate roles through a platform whose algorithm prioritises promoting the advertisement to male graduates, so a female graduate never sees it. Is that a “decision”? The question is live — and the bias and discrimination risk sits alongside it regardless of how the privacy question resolves. 

Failure to make adequate disclosure from 10 December 2026 is a breach of privacy law. The OAIC’s powers to issue compliance and infringement notices apply, alongside civil penalties. The OAIC has separately been conducting a compliance sweep of privacy policies, so this is an active enforcement area, not a dormant one. 

  1. AI and personal information generally

Privacy obligations apply to any personal information entered into an AI system, and to the output it generates. Personal information can only be used for permitted purposes; expanded data storage increases data breach exposure; and privacy policies and collection notices need to be transparent about AI use. The OAIC recommends that organisations do not enter personal information into publicly available generative AI tools — a point that connects directly to shadow AI, which we have addressed separately. 

What are the risks and pain points for employers? 

  • False comfort in the employee records exemption. It does not cover contractors, unsuccessful applicants, or the statutory tort — and reform would narrow it further. 
  • Investigations as a privacy risk. Over-collection of personal material, over-circulation of findings, and covert monitoring are the classic fact patterns for a serious invasion of privacy claim. 
  • Automation you did not know you had. ADM obligations attach to third-party and vendor-embedded functionality, not just to systems you consciously built. Legacy tools whose functionality has crept over time are a particular blind spot. 
  • A compressed timeline. Final OAIC guidance expected around September against a 10 December commencement. 
  • Discrimination riding alongside privacy. An automated tool that filters, ranks or scores people can produce indirect discrimination exposure irrespective of what your privacy policy says. 
  • Surveillance obligations layered on top. Any monitoring must also comply with surveillance devices legislation and any applicable industrial instruments, and be transparent to staff. 
  • Over-disclosure. Hedging by loading a privacy policy with dense detail undermines the transparency objective and helps nobody. 

Our top five tips: what every employer should do 

  1. Build an inventory of every system that touches a decision about a person — starting now. List your applicant tracking, screening and video-interview tools; rostering and scheduling systems; performance, engagement and attrition analytics; productivity and monitoring software; and any AI features embedded in your HRIS or payroll platform. For each, record what personal information it uses, what it decides or materially assists in deciding, and whether a human genuinely reviews the output. You cannot draft the disclosure until you have this list, and building it takes longer than everyone expects. 
  2. Interrogate your vendors in writing. Much of the automation in HR arrives inside someone else’s product. Ask suppliers directly: does your product make or materially assist decisions about individuals; what personal information does it use; what is the logic; can a human override the output; and how has it been tested for bias? Put these questions into procurement and renewal processes, and build the answers into your contracts. 
  3. Re-scope how investigations collect and share personal information. Decide before an investigation begins what material will be collected and on what basis, notify where you can, and keep collection proportionate to the allegations. Then control distribution rigorously — findings and personal information go to those with a genuine need to know and no further. Over-disclosure during an investigation is now a litigation risk in its own right, not merely poor practice. 
  4. Update the privacy policy and the collection notices together — and keep them readable. Your privacy policy needs the APP 1.8 disclosures by 10 December 2026, but the more useful work is upstream: employee and candidate collection notices that plainly say what is collected, why, who it is shared with, and where automation is used. Aim for a policy someone would actually understand, not a defensive document that discloses everything and communicates nothing. 
  5. Keep meaningful human control — and be able to prove it. Assign clear accountability for AI and automated decision-making to a person with the competence, authority and resources to exercise it. Ensure a human can review and override an output, maintain an alternative pathway if a system malfunctions, establish a channel for people to raise concerns, and decommission tools when they are no longer appropriate. For decisions with real consequences for a person — hiring, promotion, discipline, termination — the automated output should inform a reasoned human decision, never be it. 

Frequently asked questions 

Are employee records still exempt from the Privacy Act? 

For private sector employers, yes — for handling that relates directly to a current or former employment relationship. But the exemption does not cover contractors, prospective employees who are not subsequently employed, or the new statutory tort, and it does not displace confidentiality, contractual or security obligations. Reform to narrow it has been proposed. 

What is the statutory tort for serious invasions of privacy? 

A cause of action, available for conduct on or after 10 June 2025, where there has been an intentional or reckless invasion of privacy — by intrusion upon seclusion or misuse of information — in circumstances where the person had a reasonable expectation of privacy, the invasion was serious, and the public interest in privacy was not outweighed. Damages and injunctions are available. 

Could an employer be sued under the tort? 

Yes. The most likely fact patterns are covert or disproportionate surveillance, over-collection of personal material during an investigation, and disclosing an employee’s personal information more widely than necessary. The employee records exemption is not an answer. 

What exactly must we disclose about automated decision-making, and by when? 

By 10 December 2026, where you have arranged for a computer program to make — or do something substantially and directly related to making — a decision that could reasonably be expected to significantly affect an individual’s rights or interests using their personal information, your privacy policy must set out the kinds of personal information used and the kinds of decisions involved. 

Does the obligation only apply to fully automated decisions? 

No. It also reaches decisions where a computer program does something substantially and directly related to making the decision — so a system that screens, scores or ranks people for a human decision-maker can be caught. It also covers refusals and failures to decide, and beneficial as well as adverse effects. 

Does it apply to third-party tools we did not build? 

Yes, where you have arranged for the program to be used in that way. This makes vendor due diligence and contract terms essential, and makes legacy systems whose functionality has expanded over time a particular risk. 

Are we required to stop using AI in recruitment? 

No. The obligation commencing in December 2026 is a transparency obligation. But separate legal risks apply — discrimination and bias, procedural fairness, and your own responsibility for the accuracy of the outcome — so real human oversight remains essential regardless. 

Can we put employee information into ChatGPT or a similar public tool? 

The OAIC recommends against entering personal information into publicly available generative AI tools. Beyond privacy, doing so can engage confidentiality, contractual, security and record-keeping obligations. Use approved tools with appropriate terms, and set clear rules about what may never be entered. 

We’re a small business under $3 million turnover — does any of this apply? 

The small business exemption remains in place, subject to existing carve-outs, though its removal has been proposed. Importantly, the exemption does not extend to the statutory tort, and contractual and confidentiality obligations apply regardless of turnover. 

Where do we start if we have nothing in place? 

Assign accountability, build the inventory of systems that touch decisions about people, interrogate your vendors, then update your privacy policy and collection notices before 10 December 2026. A workable framework can be stood up quickly and refined once the OAIC’s final guidance is released. 

How Harrisons can help 

Get privacy wrong in an HR context and the consequences are no longer theoretical: a serious invasion of privacy claim the employee records exemption does not answer, a discrimination complaint arising from an automated screening tool, and a privacy policy that breaches the Act from 10 December 2026. 

We help Australian employers — SME business owners, Queensland local government councils, and community and not-for-profit organisations — get ahead of it: 

  • Map your automated decision-making across recruitment, rostering, performance and monitoring, including vendor-embedded tools. 
  • Draft compliant privacy policies and collection notices that meet the new APP 1 obligations and remain readable. 
  • Review investigation and surveillance practice against the statutory tort, surveillance legislation and your industrial instruments. 
  • Build human oversight and accountability into decisions that materially affect your people. 

The runway to 10 December 2026 is shorter than it looks. Get in touch with our team today and start with a privacy and automated decision-making readiness review.  

This article provides general information for Australian employers and is not legal advice. Privacy law in Australia is under active reform and regulator guidance is still being developed. For advice tailored to your organisation, contact Harrisons.

Facebook
Twitter
LinkedIn
TAKE THE GREAT WORKPLACE TEST

Discover your workplace score and increase your ability to attract and retain superstars

Human Resources Brisbane | Best Workplace Assessment
FEATURED PRODUCTS

THE CEO SECRET GUIDE

TO MANAGING + MOTIVATING EMPLOYEES

Scroll to Top