AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
State and Territory Reporting Obligations There are also schemes at the state/territory level. For example, both NSW and Queensland had introduced mandatory notification of data breach schemes via, respectively, the Privacy and Personal Information Protection Amendment Act 2022 (NSW) (entered into force 28 November 2023) and Information Privacy and Other Legislation Amendment Act 2023 (Qld) (com - mencement date to be set by proclamation). These largely mirror the federal scheme. Other Reporting Obligations There is other relevant legislation for data protec - tion and reporting obligations, including in relation to certain health records (see 6.3 Cybersecurity in the Healthcare Sector ), the financial sector ( 3. Opera- tional Resilience in the Financial Sector ) and critical infrastructure assets ( 2. Critical Infrastructure Cyber- security Regulation ). 6.2 Cybersecurity and AI At the time of writing, there is no AI-specific regulation on AI; however, there is a patchwork of laws regulating critical infrastructure, privacy, consumer protection, data security, and more that all touch on aspects of AI development and use. Further, Australia has voluntary instruments, including the following. • Ethical frameworks, including the Australia’s AI Ethics Principles, which was supplemented on 15 June 2023 by NAIC’s Implementing Australia’s AI Ethics principles: A selection of responsible AI practices and resources. • A voluntary AI Safety Standard was released on 5 September 2024, comprising practical guidance in the form of ten “AI guardrails”. • A “Guidance for AI Adoption” was published on 21 October 2025 by the Australian Department of Industry, Science and Resource, outlining six essential practices for safe and responsible AI gov - ernance. In line with the report, Australia’s AI Ethics Principles was updated on 2 December 2025 to reflect the recommendations. Similarly, regulators such as ASD, in conjunction with foreign authorities such as the U.S. National Security
Agency’s Artificial Intelligence Security Centre, has published guidance on deploying, engaging with, and developing AI systems. On 24 January 2024, the ASD alongside international partners published a report titled “Engaging with artificial intelligence”, which rec - ognises privacy issues such as when organisations provide customer data to generative AI systems. Further, the ASD has endorsed the Cybersecurity Per - formance Goals (CPGs) developed by the Cybersecu - rity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST). 6.3 Cybersecurity in the Healthcare Sector In Australia, healthcare provider organisations must generally notify the Australian Digital Health Agency (ADHA) of potential risk or actual data breaches relat - ing to the My Health Record system. The ADHA has provided a guide on how to notify the agency if there is a risk or if an actual data breach has occurred. The four steps are: Contain, Assess, Man - age Notifications, and Continue Investigation. Reporting Obligations Certain data breaches relating to My Health Record information or the system itself are to be reported under Section 75 of the My Health Records Act (rather than through the NDB scheme under the Privacy Act). Section 75 of the My Health Records Act requires a report where there has (actually or potentially) been unauthorised collection, use, or disclosure of health information included in a healthcare recipient’s My Health Record or the (actual or potential) compromise of the security or integrity of the My Health Record. This report must be made to the relevant system operator and/or the OAIC. Subsequently, all “affect - ed healthcare recipients” must also be notified of the compromise or unauthorised disclosure. Other than those data breaches to which the My Health Records Act applies, medical data would generally be personal information and covered by the federal NDB scheme (see 6.1 Cybersecurity and Data Protection ).
24 CHAMBERS.COM
Powered by FlippingBook