In the know: A recap of the 2026 Australian Community Attitudes to Privacy (ACAPs) survey
Privacy 11.06.26
The Office of the Australian Information Commissioner (OAIC) has just published its 2026 Australian Community Attitudes to Privacy (ACAPs) survey which paints a clear picture of how Australians feel about their personal data and the organisations that hold it. ACAPs may also provide a clue to where regulatory priorities will shift in FY2027.
If you collect, store, or process customer information, these findings are directly relevant to you.
The economics of trust
Across an economy, trust is not just a brand metric – it is a driver of consumer spending, market competition, and economic participation. When trust erodes at scale, so does the confidence that underpins normal economic activity.
Across our nation, weak privacy practices are actively suppressing trust, and this means an impact not only on your brand but on the broader landscape – and it presents an opportunity to those who do better to win market share.
The ACAPs survey tells us that trust has declined across insurance, technology, telecommunications, retail, and real estate since 2023. Trust in AI companies and data brokers sits at just 4%, which means when you bring those entities as vendors into your environment and let them touch your customer data, your brand or initiative may be tainted.
Brands that differentiate themselves on trusted data practices will win consumer sentiment. 68% of Australians say they would be more likely to use digital services that require personal information if they believed their data was handled fairly and responsibly.
Regulation is tightening and transparency requirements clearer
So called ‘Tranche 1’ of Privacy Act reforms was enacted in December 2024, bringing with it new enforcement and investigation powers for the Privacy Commissioner and a statutory tort for serious invasions of privacy. New transparency laws under Tranche 1 come into force later in December 2026, requiring regulated entities to disclose the use of AI and automated decision-making (ADM) in their privacy policies.
If your business uses AI-assisted tools – even in areas like fraud detection, HR screening, or customer service triage, you need to review your privacy documentation now.
Even if you’re not implementing automated decision making, the OAIC has actively stated that its current priorities include correcting information imbalances between organisations and individuals and protecting individual rights as new technologies emerge. They’re looking more closely at how organisations use data, particularly where customers don’t fully understand or control what’s happening. ACAPs provides support for this: Only 23% of Australians say they read privacy policies carefully before agreeing to them.
The OAIC has signalled that must do better. Consent buried in long privacy policies or pre-ticked boxes will receive much less deference than it once did. The OAIC wants genuine, informed consent – specific, meaningful, and easy to withdraw.
Businesses would be well advised to keep an eye out for the OAIC’s findings in its first ever Privacy Compliance Sweep, which took place in late 2025, examining the adequacy of selected businesses’ privacy policies. Entities found to have non-compliant privacy policies may face compliance and infringement notices and penalties of up to $66,000 under Tranche 1 reforms.
The OAIC informs us that they intend to release a public report detailing the outcome of the sweep, including compliance trends across entities and lessons to help entities achieve compliance early in the new financial year.
It’s not the breach necessarily, it’s how you manage it that counts
Data breaches are part and parcel of life in a data driven environment. That means that it is not only the prevention of breaches that needs investment, but response capability for when things go wrong. ACAPs found that 77% of Australians whose data was involved in a breach experienced at least one form of harm.
Organisations that focus on good process and remediating human impacts will fare better than those who view incident response as purely an IT problem with an obligation to notify. If you haven’t tested your breach response process recently, now is a good time to do so.
AI is ok, but conditions apply
Australians aren’t categorically opposed to AI, but they want to know when AI is being used in decisions that affect them, they want to be able to seek human review, and they don’t want their data fed into AI systems without explicit consent.
The majority are uncomfortable with AI being used to make significant decisions impacting credit, employment, or health without human oversight. A large proportion say they would stop using a service if they discovered it was training AI on their personal data without their knowledge.
If you’re deploying AI tools, including third-party SaaS products that may use customer data for model training by default, you need to check the terms of service carefully. What your vendor does with your customers’ data is ultimately your problem, not theirs.
Do better with complaints
The theme of Privacy Awareness Week this year was “Trust is built here. In every complaint. In every resolution.” The message here was that privacy complaints need to be properly addressed. Just like incidents, they require a good process and proper consideration of the human impacts behind them.
64% of Australians had a privacy concern in the past year. Of those, 52% didn’t raise it – with the most common reasons being that they didn’t think it would make a difference (56%), it seemed too hard, or they didn’t know how (40%). Among the people who did complain, only 9% said their issue was resolved to their satisfaction.
Now is a good time to look at your complaints process and data from the last year. If you’re not analysing trends (root cause, remediation metrics), you’re missing a trick, as these show you where your fault lines lie. You may find that the next complaint that is escalated to the OAIC results not only in intervention in that matter, but a broader examination of how your obligations under APP 1 (privacy program and controls – which includes complaint management) are being met.
Regulatory convergence
The ACAPS 2026 findings are relevant to every regulator with an interest in how organisations treat individuals and compete in the market. The ACCC, ASIC, APRA, state and territory privacy regulators, and the CDR regime will all be watching the trends around AI transparency, secondary data use, consumer harm from breaches, and deceptive consent practices.
A single compliance failure can now trigger simultaneous scrutiny from multiple regulators at once. Consider the example of an AI vendor whose product defaults to training on customer data. This creates a potential OAIC issue (secondary use without consent), an ACCC issue (misleading conduct about how data is used), and possibly an ASIC issue if the service touches financial decisions.
What to do next
The six risk areas that ACAPs highlights – regulatory compliance, customer trust, breach response, AI governance, consent design, and complaint pathways – are all areas where ctrl:cyber can help.
If you’d like to understand where your organisation stands right now and how you can implement better practices, contact us ↗