The HR Tool You Approved Is Now a Compliance Problem You Don’t Know You Have
Most CEOs and CHROs who signed off on AI-assisted hiring platforms, performance monitoring tools, or workforce analytics software in the last three years did not treat those decisions as data governance decisions. They treated them as procurement decisions. That distinction is now catching up with them.
Victorian Labor’s proposal to restrict workplace AI and biometric surveillance — covered by iTnews — is not an isolated state-level experiment. It reflects a regulatory direction that is moving federally, and organisations that deployed these tools quietly, without privacy impact assessments, without legal counsel, and without board visibility, are sitting on undisclosed compliance exposure. Most of them have no idea.
What HR Actually Bought
The platforms are not mysterious. They include tools that score candidates using behavioural or linguistic analysis, systems that infer employee sentiment from email and calendar patterns, productivity monitoring software that tracks keystrokes and application usage, and scheduling tools that use historical performance data to make workforce decisions. Many are bundled inside larger HR platforms — Workday, SAP SuccessFactors, Microsoft Viva — which makes them easier to approve and harder to scrutinise.
The procurement story tends to run the same way. HR identifies a capability, a vendor demo impresses, IT confirms the integration works. Legal is not in the room and neither is privacy counsel. The privacy impact assessment either never happens or gets written afterwards to close a gap someone noticed. What reaches the board is a line item on an operational budget rather than a data governance decision with legal exposure attached.
The technology is not the problem. The process that classified it as something other than what it is — that is the problem.
What These Tools Do With Employee Data
These platforms collect and infer considerably more than most organisations realise at signature. Sentiment inferred from communication metadata. Productivity scores that quietly become a de facto performance record. Candidate assessments capable of embedding demographic bias at scale. Biometric collection — facial recognition for attendance, voice analysis in call centres — carrying specific legal obligations that very few HR buyers have read.
Under the Privacy Act 1988, employee records have historically enjoyed an exemption from the Australian Privacy Principles. That exemption is narrower than most organisations assume, and it does not cover data collected before employment begins — meaning AI-assisted candidate screening sits in a different legal position than internal performance monitoring. The exemption is also under active reconsideration as part of the ongoing Privacy Act reform process, which the Attorney-General’s Department has been progressing since the 2022 review.
Organisations that assumed the employee records exemption gave them broad licence to deploy whatever HR analytics they chose made a legal assumption without legal advice. Some of them made it years ago and have not revisited it.
Why Victoria Matters Beyond Victoria
State-level workplace surveillance legislation does not stay at the state level. Victoria introducing restrictions creates pressure on the federal government to harmonise, particularly given the Privacy Act reform already in motion and Labor’s stated commitments to strengthening worker protections. It also creates immediate exposure for Victorian employers — which includes every national organisation with Victorian employees.
More importantly, it signals what regulators and legislators now believe is reasonable. When a regulator eventually investigates an AI-assisted HR decision — a hiring outcome that appears discriminatory, a dismissal that relied on algorithmic performance data, a redundancy process informed by productivity monitoring — the existence of this regulatory conversation will form part of the context. “We didn’t know this was regulated” becomes a harder argument when the legislative debate was public.
The OAIC has also been explicit, in its guidance on privacy and AI, that automated decision-making involving personal information requires transparency and accountability. Organisations using AI tools to inform hiring or performance decisions that affect individuals are already operating in a space where regulatory expectations exist — even before new state legislation passes.
The Board Visibility Problem
Most boards cannot say what employee data their HR platforms collect, infer, or pass to third parties. That is the governance failure, and it is easy to test.
Put it to the CHRO or the CIO at the next meeting: describe what these platforms collect about employees and candidates, what is inferred from it, who receives it, and what the legal basis is. A confident and complete answer puts you ahead of most organisations. A vague one, or a deferral, or a request to clarify what you mean, is the finding — and it is the kind of exposure that tends to surface during due diligence, a regulatory investigation or an unfair dismissal claim, when the cost of not having done the work is priced for you.
What Needs to Happen Now
None of this belongs with IT. It sits with the CEO, the CHRO and legal counsel.
Start with an inventory of what is actually running, which is not the same as what procurement approved. Plenty of organisations have HR tooling in daily use that was never separately assessed because it arrived bundled inside a platform that was. Microsoft Viva, LinkedIn Talent products and any third-party integration hanging off the ATS or HRIS all count.
Then commission a legal review of what those tools collect and infer, measured against current Privacy Act obligations and the direction reform is heading. It needs to deal specifically with the employee records exemption, with candidate data, and with any biometric collection.
The last step is the one that gets skipped. Brief the board on the exposure rather than the technology: what employee data the organisation holds, what it is used for, and whether the current practice would survive scrutiny. A board that cannot answer those questions is not in a position to govern the risk, whatever the risk register says.
The Victorian bill is not the threat here. The threat is a series of quiet procurement decisions that built legal exposure into the organisation without anyone who could manage it being present. That is a fixable situation, and it stays unfixable exactly as long as it stays invisible.