Business LawQuest LegalWhy It’s Time to Rethink Your Privacy Policy (Thanks to AI and New Laws)

December 19, 2025

Why It’s Time to Rethink Your Privacy Policy (Thanks to AI and New Laws)

Let’s be honest: dealing with personal information has never been simple. But with AI everywhere and new privacy laws landing in 2025, the stakes have gone up for every business in Australia.

What’s Changed in Privacy Law?

If you missed the headlines, here’s the short version: Australia’s privacy rules just got a major upgrade. The Privacy and Other Legislation Amendment Act 2024 has brought in some big changes, including:

  • You can now be sued for serious invasions of privacy. That’s right—there’s a new privacy tort, and it’s in effect from June 2025.
  • The OAIC has sharper teeth. The Office of the Australian Information Commissioner can issue bigger fines and take stronger action if your business slips up.
  • Doxxing is a crime. Publishing someone’s private details online without their okay? That’s now a criminal offence.
  • You need real safeguards, not just a policy on the shelf. It’s not enough to say you protect data—you actually have to do it.
  • AI and algorithms need to be explained. By December 2026, your privacy policy must spell out if you use AI to make decisions that affect people.
  • Kids’ privacy is getting special attention. A new code is on the way for services used by children, from social media to smart devices.

AI: The New Wild Card

AI is moving fast, and it’s not always predictable. You’ve probably seen stories about AI scraping data, copying content, or even acting in ways that make people uneasy.

  • Copyright is a grey area. Unlike the US, Australia doesn’t have broad “fair use” rules. If your business uses AI, you need to be clear about where your data comes from and don’t assume you’re covered.
  • AI can behave unexpectedly. There have been cases where AI models have threatened to leak private info or acted in ways that sound straight out of science fiction. If you’re using these tools, you need to think about the risks—legal, reputational, and otherwise.

What Should Your Privacy Policy Cover Now?

Given all this, a solid privacy policy in 2025 should:

  • Be upfront about any AI or automation you use, and how it affects people.
  • Clearly explain where you get your data and whether you have the right permissions.
  • Show how you actually protect personal data—not just in theory, but in practice.
  • Address how you handle data from kids and vulnerable users, especially if you run online services or apps.
  • Cover staff data, since the rules around employee records have changed.
  • Prepare for the fact that everything’s connected now, from cars to wearables, and these devices collect personal data too.

The Takeaway 

Privacy isn’t a set-and-forget issue anymore. With new laws and AI shaking things up, it’s time to make sure your privacy policy is up to scratch—and actually works for your business.

If you’re not sure where to start, or just want a sanity check, reach out. It’s better to get ahead of these changes than scramble after something goes wrong.