AI vendors based in Australia
AI vendors based in Australia. Subject to the Privacy Act 1988 and a proposed reform regime, with Five Eyes alignment and emerging sector-specific AI guidance.
Australia-based AI vendors operate under the Privacy Act 1988, regulated by the Office of the Australian Information Commissioner (OAIC). A significant Privacy Act reform package is in progress; the proposed Privacy and Other Legislation Amendment Bill 2024 introduces a statutory tort for serious invasions of privacy and a children's privacy code. Australia is a Five Eyes member, which is a benefit for U.S./UK/CA/NZ buyers and a consideration for buyers concerned about intelligence sharing arrangements.
Buyer considerations
- Australia does not currently have an EU adequacy decision; EU-to-Australia transfers require SCCs or other mechanisms.
- Privacy Act reform is incremental; multiple tranches over 2024-2026.
- Australian Cyber Security Centre (ACSC) Essential Eight framework is the local equivalent of NIST baseline.
- Federal Government Hosting Certification Framework restricts non-Australian-hosted services for certain workloads.