Skip to Content

IAPP ANZ Summit 2026

Privacy | AI governance | Cybersecurity law

Sydney

1-4 December

Conference

3-4 Dec.

Training

1-2 Dec.

Back to conference agenda

You Cannot Disclose What You Cannot See: Data and the New ADM Disclosure Rules

Thursday, 3 Dec.

13:30 - 14:30 AEDT

Advanced level

BREAKOUT SESSIONPRIVACYAI AND MACHINE LEARNINGCOMPLIANCE TECHLAW AND REGULATIONPRIVACY ENGINEERINGREGULATORY GUIDANCESTRATEGY AND GOVERNANCERISK MANAGEMENTTECHNOLOGY

From 10 December, companies and institutions covered by the Privacy Act must describe in their privacy policies the kinds of personal information and decisions involved when automated systems make or substantially assist significant decisions. The OAIC has signaled a broad reading, and human sign-off may not take a system out of scope. The harder problem is visibility: most enterprises cannot say which systems are in scope or what personal information they can reach. This session gives privacy teams a practical method to inventory systems, map the decisions they feed, test the human's role, and classify and minimize the data behind them, so every disclosure is backed by evidence.

Sponsored by RecordPoint

Featured in this session

generic profile silhouette

Kirolos Ayad

Senior Product Manager

RecordPoint