Privacy and Other Legislation Amendment Act 2024 (Australia)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Automated Decisions
Per AUPA 2024: automated decision-making transparency. Requirements include (a) implement transparency requirements for automated decision-making including disclosure in privacy policy + (b) provide meaningful information about logic + significance + envisaged consequences + (c) implement human review where significant impact + (d) maintain documentation of automated decision systems + (e) align with broader AI governance + EU AI Act readiness.
- AUPA 2024 evidence for AUPA24-D
- new statutory tort + children's code preparation partial
Children's Online Privacy
Per AUPA 2024: Children's Online Privacy Code. Requirements include (a) prepare for Children's Online Privacy Code applicable to services likely to be accessed by children + (b) implement age verification + age-appropriate design + (c) maintain documented children's data handling + safeguards + (d) align with international best practice (UK AADC + similar) + (e) integrate with broader child safety + privacy + (f) maintain change management for Code development.
- AUPA 2024 evidence for AUPA24-C
- new statutory tort + children's code preparation partial
Doxxing Protection
Per AUPA 2024: doxxing offence. Requirements include (a) understand new doxxing criminal offence under Criminal Code Amendment + (b) implement controls preventing organisational involvement in publishing personal identifying information + (c) implement removal mechanisms for affected individuals + (d) cooperate with law enforcement + (e) maintain training + awareness.
- AUPA 2024 evidence for AUPA24-E
- new statutory tort + children's code preparation partial
Enhanced Enforcement
Per AUPA 2024: enhanced Privacy Act enforcement. Requirements include (a) understand new mid-tier + low-tier civil penalty provisions + (b) understand expanded OAIC powers including infringement notices + (c) implement enhanced compliance programme + (d) cooperate with OAIC including information sharing with foreign regulators + (e) maintain training + awareness on new penalty regime + (f) integrate with broader compliance.
- AUPA 2024 evidence for AUPA24-B
- new statutory tort + children's code preparation partial
Lifecycle and Operations
Per AUPA 2024 lifecycle reforms: marketing + training + complaints + sharing. Requirements include (a) implement Direct Marketing Opt Out Mechanisms enhanced + (b) deliver Privacy Training and Awareness on AUPA 2024 changes + (c) operate Privacy Complaints Handling + (d) maintain Documentation per OAIC guidance + (e) implement Information Sharing with Foreign Regulators procedures + (f) integrate with broader governance.
- AUPA 2024 evidence for AUPA24-H
- new statutory tort + children's code preparation partial
PIA and Inventory
Per AUPA 2024 + supporting reforms: PIA thresholds + inventory. Requirements include (a) implement PIA Threshold Triggers - PIA required for high privacy impact activities + (b) maintain Personal Information Inventory including data flows + classification + purposes + retention + cross-border + (c) integrate with broader privacy programme + (d) maintain documentation supporting OAIC inquiries + (e) maintain change management for thresholds evolution.
- AUPA 2024 evidence for AUPA24-F
- new statutory tort + children's code preparation partial
Security Enhanced
Per AUPA 2024 enhancing APP 11: technical and organisational measures. Requirements include (a) implement enhanced Technical and Organisational Security Measures clarifying reasonable steps + (b) implement encryption + access control + activity logging + (c) conduct regular security testing aligned to Essential Eight + ISM + (d) maintain documented security baseline + (e) align with NDB Scheme breach handling + (f) integrate with broader InfoSec.
- AUPA 2024 evidence for AUPA24-G
- new statutory tort + children's code preparation partial
Statutory Tort and Civil Remedy
Per Australian Privacy and Other Legislation Amendment Act 2024 Schedule 2: statutory tort for serious invasions of privacy. Requirements include (a) understand new statutory tort enabling civil action for serious invasion of privacy by intrusion upon seclusion or misuse of personal information + (b) implement controls to prevent intrusion + misuse + (c) maintain documentation supporting defence including reasonable safeguards + (d) integrate with broader privacy + media + tort risk + (e) maintain change management for evolving case law.
- AUPA 2024 evidence for AUPA24-A
- new statutory tort + children's code preparation partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.