Research · Source register
The evidence behind I’m Fine, Thanks, kept separate from the proposed legislative reform. Company terms show what is disclosed; regulator guidance explains existing protections. Neither establishes that a particular customer suffered unlawful processing.
- Wesfarmers: OneData, OnePass and OneReachCompany disclosure
Supports the reported shared-data asset and its stated purposes. A company statement is not an independent audit of individual records.
- OnePass privacy policyCompany disclosure; version dated 13 August 2026
Supports disclosed matching, historical information, inferred characteristics and controls. Permissions are not proof of every processing event. My earlier summary used an older policy date.
- Bunnings Buddy terms and conditionsCompany disclosure
Supports collection, identification, retention and stated LLM-training limits. Does not establish a connection between Buddy and OneData.
- OAIC: APP 2, anonymity and pseudonymityRegulator guidance
Existing anonymity protections have exceptions. The proposed quiet-transaction right must be tested against these, rather than presented as filling a completely empty legal space.
- OAIC: APP 3, collection of solicited personal informationRegulator guidance
Explains collection requirements and the treatment of sensitive information. Broad collection is not automatically lawful merely because a business describes a purpose.
- OAIC: APP 7, direct marketingRegulator guidance
Relevant to marketing and opt-out rights. A marketing opt-out should not be described as a universal deletion or profiling stop.
- OAIC: APP 11, security of personal informationRegulator guidance
Relevant to security, retention, destruction and de-identification duties, with applicable exceptions.
- OAIC: APP 12, access to personal informationRegulator guidance
Access can concern information and opinions about an identifiable person, not just raw transaction records. The reform seeks a consolidated explanation; it does not assume all inferences are outside existing access rights.
- OAIC: automated decision-making transparency consultationRegulator material
Describes obligations commencing 10 December 2026 and questions of scope. Does not support a blanket assertion that all retail AI is exempt.
Claim register
Supported: a company-reported shared customer asset; disclosed information matching; historical information and inferred characteristics; published controls; tool-specific retention and training statements.
Interpretation: the practical distinction between trusting a shop and choosing a data architecture. This is the campaign’s analysis, not a finding by a regulator.
Proposed: a single refusal control, consolidated profile disclosure and stronger transactional purpose limits. These are not existing statutory entitlements in the proposed form.
Not established: a particular customer’s complete profile; all shoppers being included; Buddy accessing OneData; personalised pricing; government access; or any breach of law.
Corrections log
My earlier guide and research summary informed the article. They are campaign research material, not additional independent primary sources. The draft provisions are set out on the separate proposed reform page.
The public account does not repeat an unsupported claim that APP 12 only covers raw data, that all retail AI sits outside privacy law, or that a 12-million-record threshold is a sensible legal definition. Those matters need precise legal drafting and evidence.