9 July 2026

AI memory features can result in the reuse of client, customer, or patient information collected for one purpose in work done for another. That can put you on the wrong side of IPP10, and IPP11 and IPP8 issues might arise as well.

29 June 2026

A privacy impact assessment captures a moment in time. Microsoft 365 Copilot’s provision of access to Anthropic’s new models (export bans aside…) shows why agencies need to keep their AI PIAs current.

27 May 2026

The Privacy Commissioner’s MMH inquiry phase 1 report sets out what “reasonable security safeguards” actually means under Rule 5. It is essential reading for all agencies handling sensitive personal information.

There seems to be some confusion among some health practitioners as to the scope of the new rule 3A of the Health Information Privacy Code. This post endeavours to clear things up.

23 May 2026

An AI scribe’s FAQ says patient data isn’t used for training. Sounds good, but its privacy policy tells a more involved story. A reminder to read the fine print.

22 May 2026

On 1 May 2026, the new information privacy principle 3A took effect. If your organisation uses AI tools to process personal information, this change could affect you. And it could do so in two quite different scenarios.

30 May 2025

The Privacy Commissioner has issued its most prescriptive compliance notice yet. Public and private sector agencies handling large volumes of personal information may want to take note.

27 August 2024

Information sharing MOU templates in circulation that would or could allow secondary use and disclosure if permitted by law, may now need to be reconsidered in the light of AI.

19 August 2024

The rights of claimants to access their personal information under the Privacy Acts are not limited by certain specific provisions in welfare legislation and court rules.