Skip to Content
OPINION

Notes from the Asia-Pacific region: OAIC actions signal growing focus on accountability, governance

Recent actions from Australia's privacy regulator highlight rising expectations for proactive governance, transparent decision-making and resilience in managing privacy risk.

Published
Subscribe to IAPP newsletters

Contributors:

Adam Ford

Managing Director, Australia, New Zealand

IAPP

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

As we move into the second half of 2026, it's reasonable to say this year has already been a busy one for Australia's regulated community — and the pace of change, enforcement and reform is only increasing. Taken together, recent announcements from the Office of the Australian Information Commissioner demonstrate not only the breadth of issues currently attracting regulatory attention, but also the growing expectation that organizations take a proactive and accountable approach to managing privacy risk across their operations.

One of the more notable developments was the OAIC's publication of updated guidance on the use of facial recognition technology in retail environments. The revised guidance incorporates key findings from the Administrative Review Tribunal's consideration of the Bunnings Group's use of facial recognition technology and reinforces what many privacy professionals have long suspected: the threshold for deploying the technology in Australia remains exceptionally high.  

The guidance makes clear that organizations contemplating the use of biometric technologies in publicly accessible spaces must undertake careful contextual assessments and be prepared to justify their approach against both the requirements of the Privacy Act and broader community expectations. Importantly, the OAIC highlighted a significant increase in public concern regarding facial recognition technologies, suggesting that organizations must consider not only legal compliance but also social license when evaluating these tools.

At the same time, the OAIC released the outcome of its preliminary inquiries into the well-publicized Qantas data breach incident that affected approximately 5 million Australians. While the regulator found no evidence suggesting a likely breach of privacy law and therefore determined further regulatory action was not warranted, the findings are nevertheless instructive. 

The report recognized the preventative measures Qantas had implemented, including oversight of third-party providers, security controls and privacy management processes. Perhaps the most important lesson is that data breaches can occur despite significant investment in cybersecurity and privacy controls. The case reinforces the importance of resilience, preparedness and continual improvement, rather than assuming risk can be entirely eliminated.

What I find particularly interesting across these developments is the consistent theme of accountability and governance. Whether considering facial recognition technologies, managing third-party supplier relationships or responding to a significant cyber incident, regulators are increasingly focused on the quality of governance, decision-making and risk management practices that sit behind organizational actions. Privacy is no longer assessed solely by outcomes. Increasingly, organizations are being evaluated on the strength of the processes they establish before issues arise.

There is also an emerging recognition that trust and transparency have become business imperatives alongside legal compliance. Organizations are expected to be able to demonstrate not only that they have appropriate safeguards in place, but that they can provide evidence of thoughtful decision-making when deploying new technologies or managing complex data ecosystems. This is particularly relevant as businesses continue to explore advanced analytics, AI-enabled capabilities and increasingly sophisticated customer engagement tools.

For privacy and digital responsibility professionals, this presents both a challenge and an opportunity. Strong governance frameworks, effective privacy impact assessments, diligent vendor oversight and transparent engagement with stakeholders are becoming core organizational capabilities. As regulatory expectations continue to mature, the organizations best positioned for success will be those that view privacy not simply as a compliance obligation, but as a foundation for trust, resilience and long-term value creation.

This article originally appeared in the Asia-Pacific Dashboard Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here.

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Adam Ford

Managing Director, Australia, New Zealand

IAPP

Tags:

EnforcementPrivacy

Related Stories