This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If you have already decided to use AI tools in your hiring process, the next question is whether you are meeting your legal obligations under the Privacy Act 1988. For most Australian SMBs, hiring is the most common situation where automated decision-making rules actually apply to them, and the obligations are more specific than a general privacy policy update.
This article covers which AI hiring tools trigger disclosure requirements, what the Privacy Act and Fair Work Act 2009 require of you, and what candidates are entitled to ask for. This is general information, not legal advice. For your specific situation, consult a qualified employment lawyer and privacy professional.
In short: Using AI to screen resumes, score candidates, or produce a shortlist is an automated decision that significantly affects a person's employment prospects. Under the Privacy Act 1988 and APP 1.7, the law requires this to be disclosed in your privacy policy. Privacy Act obligations also include notifying candidates upfront that AI is part of your process. APP 1.7 is a transparency obligation only: it does not create a legal right for candidates to demand human review of an AI-influenced decision, unlike the EU's GDPR. See the OAIC's guidance at oaic.gov.au.
Which AI hiring tools trigger Privacy Act obligations?
The Privacy Act threshold is whether AI is used to make a decision that significantly affects a person. In a hiring context, that line sits between tools that filter or rank candidates and tools that perform minor formatting or grammar assistance.
These tool types do trigger disclosure obligations: resume screening tools that filter out applications before a human sees them, video interview analysis platforms that score candidates on facial expressions, tone, or language, skills assessment platforms with AI-generated scores that influence shortlisting, and AI tools that produce a ranked candidate list or written shortlist recommendation.
These tool types generally do not trigger the same obligations: AI grammar checkers used on job ads or offer letters, AI tools that summarise or reformat a candidate's resume for human review without scoring or ranking, and scheduling tools that automate interview calendar management.
The practical test is this: if the AI output changes which candidates a human sees or seriously influences who advances, it significantly affects employment. If the AI only changes how information is presented to a human who still makes the call independently, it likely does not.
Take the HR manager at a 60-person logistics firm running her first AI-assisted hiring round. Her team used to spend two full days manually reading through 200 resumes for a warehouse coordinator role. Now the AI screening tool sorts them into a ranked shortlist in under an hour, that's more than a day back for her team. But because that ranking changes who she sees and interviews, it counts as an automated decision under the Privacy Act 1988. Before she can use the shortlist, her privacy policy needs to say AI is doing the screening, and candidates need to be told before they apply, not after.
What Privacy Act guidance says to disclose about AI in your hiring process
Four Australian Privacy Principles create specific obligations when AI is used in hiring. Understanding each one helps you build a compliant process rather than patching problems after the fact.
APP 1.7 (automated decision-making disclosure) requires that if your business uses personal information to make or significantly contribute to decisions by automated means that affect individuals, this must be stated in your privacy policy. For hiring, this means your policy must name that AI tools are used in candidate screening or shortlisting, and explain in plain terms what that means for applicants.
APP 5 (collection notification) requires that candidates be told at the point of application that their data is being processed by AI tools. Burying this in a general privacy policy link is not sufficient. A clear statement in the application form or job posting is the safer approach.
APP 3 (sensitive information) requires explicit consent before collecting and using sensitive categories of information. This is particularly relevant if your AI tools process video interviews, voice recordings, or any health, disability, or union-membership information. Consent for general application data does not cover sensitive categories automatically.
APP 11 (data security) requires that candidate data is stored and handled securely. If you are sending applications to a third-party AI screening service, you are responsible for understanding where that data goes, who can access it, and whether it is used to train the vendor's models. Check your vendor's data processing terms before using any tool with candidate information.
Fair Work and anti-discrimination considerations
Privacy Act obligations sit alongside separate requirements under the Fair Work Act 2009 and federal and state anti-discrimination legislation. These are distinct obligations, not the same rule, and breaching one does not automatically mean you have breached the other.
Under the Fair Work Act 2009, employers cannot take adverse action against a person based on a protected attribute, which includes race, sex, age, disability, pregnancy, and union membership, among others. Using an AI tool that screens out candidates based on patterns that correlate with a protected attribute, even if the attribute is not explicitly named in the data, can constitute adverse action.
This is the disparate impact problem: an AI trained on historical hiring data can learn to replicate past patterns of bias without anyone intending it. If your AI screening tool disproportionately filters out candidates of a particular age group, gender, or ethnic background, you may face liability under the Fair Work Act 2009, the Sex Discrimination Act 1984, the Racial Discrimination Act 1975, and relevant state legislation, regardless of whether the AI was the cause the vendor intended.
The practical implication is that you cannot outsource legal responsibility to the tool. Checking your vendor's bias testing documentation and auditing outcomes periodically is part of responsible use, not optional extra diligence.
What candidates are entitled to know and request
Candidates are not passive subjects of your AI tools. The Privacy Act gives them rights over how their personal information is used, and the automated decision-making obligations add a layer specific to AI-influenced processes.
Candidates are entitled to know that AI is being used in your process. This must be disclosed before or at the point of application, not only if they ask. They are also entitled to access the personal information you hold about them, including any AI-generated scores or assessments, if they make a formal access request under APP 12.
APP 1.7 is a transparency requirement, not a right to contest a decision. It does not create a legal right for candidates to demand human review of an AI-influenced decision: unlike the EU's GDPR, the current Privacy Act framework stops at disclosure. Some businesses choose to offer a human review option anyway, as good practice or to reduce complaint risk, but doing so is a business decision, not a legal obligation under APP 1.7.
If a candidate asks why they were not shortlisted, and the reason is substantially an AI score they were never told about, that is both a practical risk and a potential breach of your notification obligations under APP 5.
Practical checklist for compliant AI hiring
The following steps apply regardless of the specific tools you use. Treat this as a baseline, not a ceiling, and revisit it each time you adopt a new hiring tool or change your process.
- Update your privacy policy. Add a clear statement that AI tools are used in your candidate screening process, what types of tools they are (screening, scoring, shortlisting), and what candidates can do if they want more information. This addresses the disclosure requirements outlined in APP 1.7. Confirm how the rule applies to your specific circumstances with a qualified advisor.
- Tell candidates upfront. Add a disclosure to your job advertisements and application forms stating that AI tools are part of your process. Do not assume a buried policy link is sufficient for APP 5.
- Get explicit consent for sensitive information. If any tool processes video, voice, health, or disability-related information, obtain separate explicit consent before that processing occurs. General application consent does not cover it.
- Consider a human review option. APP 1.7 does not legally require a human review pathway, but offering one for AI-influenced decisions can reduce complaint risk and build candidate trust. If you choose to offer it, document who handles requests and what the timeframe is.
- Check your vendor's data terms. Before using any AI hiring tool, confirm: where candidate data is stored, whether it is used for model training, what the data retention policy is, and whether the vendor is an APP entity or subject to equivalent obligations.
- Document what you use and why. Keep a record of which AI tools are used in your hiring process and what decisions they influence. If a complaint or audit arises, this documentation is your first line of response.
- Review for disparate impact. Periodically check whether your AI screening is producing skewed outcomes by gender, age, or other protected attribute. Ask your vendor whether the tool has been bias-tested and for what populations.
Last verified: June 2026 | Next review: September 2026
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: our can staff upload customer data to AI tools, our AI and the Privacy Act guide, and our HR AI compliance in Australia.
Related reading: our Claude AI review for Australian business.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Related reading: our AI governance by region.
Does using an AI resume screening tool mean I need to update my privacy policy?
Yes. If the AI tool filters, scores, or ranks candidates in a way that influences who advances in your process, that is an automated decision that significantly affects individuals under the Privacy Act 1988. APP 1.7 requires this to be disclosed in your privacy policy. A general data collection notice is not sufficient on its own.
Can a job candidate ask to see their AI screening score?
Yes. Under APP 12, candidates can request access to personal information your business holds about them, which includes any AI-generated scores or assessment outputs if those are retained. The OAIC's guidance on APP 12 indicates that businesses should respond to access requests within 30 days. See the full APP 12 guidance at oaic.gov.au. If you do not retain the scores, document why and be prepared to confirm that to the candidate if asked.
Is it enough to mention AI screening in our terms and conditions or privacy policy link?
Generally no. APP 5 requires that candidates be notified at or before the point of collection, in a way that is reasonably likely to bring it to their attention. A link to a long privacy policy document buried at the bottom of an application form is unlikely to satisfy this in practice. A short explicit statement in the application form or job advertisement is the safer approach.
What happens if the AI tool we use was built and trained overseas?
If candidate data is disclosed to an overseas entity, APP 8 requires you to take reasonable steps to ensure that entity handles the data consistently with the Australian Privacy Principles. In practice this means reviewing the vendor's data processing agreement and privacy terms before use. You remain accountable under Australian law for how the overseas vendor handles the data you send them.
Do these obligations apply to a business with fewer than 15 employees?
Small businesses with an annual turnover under $3 million are generally exempt from the Privacy Act 1988. However, some small businesses are still covered, including health service providers and some contractors to government. Anti-discrimination obligations under the Fair Work Act 2009 and state legislation apply regardless of business size. If you are uncertain whether your business is covered, the OAIC website has a small business exemption checker, or seek specific legal advice.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
The Privacy Act's automated decision-making rules go beyond hiring. Read our full guide to how the new APP 1.7 obligations apply across your business, including what counts as a significant decision and what your privacy policy must say.
Read the Full ADM Compliance Guide