Compliance
From 10 December, Your Privacy Policy Has to Say What Your Automations Decide
The four-question test, who it covers, and a register you can start this week
It is a transparency rule, not a ban. The work is knowing what your systems already decide.
From 10 December 2026, an Australian business covered by the Privacy Act that lets a computer program make significant decisions about people has to say so in its privacy policy. It must describe the kinds of personal information the program uses and the kinds of decisions it makes. The rule was added to Australian Privacy Principle 1 by the Privacy and Other Legislation Amendment Act 2024, and it applies to every decision made from that date, including by systems you switched on years ago.
It is not a ban and it does not need anyone's consent. It is a disclosure rule. The hard part is not the wording. It is knowing what your systems are actually deciding.
Which decisions does it cover?
The rule bites when four things are all true. Work through them in order: a "no" at any step means this rule does not require a disclosure for that system.
APP 1 · The four-question test, from 10 December 2026
Is your business covered by the Privacy Act at all? Generally that means annual turnover above A$3 million. Some smaller businesses are covered regardless, including health service providers and businesses that trade in personal information.
Does a program make the decision, or do something substantially and directly related to making it? A program that scores, ranks, approves or declines counts. A program that only files an email does not.
Could the decision reasonably be expected to significantly affect someone's rights or interests? Whether they get a service, a price, a payment plan, a job interview, or a call back.
Does the program use personal information about that person? Almost any decision about a named person will.
Watch for this one: a person glancing at the result does not take a decision outside the rule. It covers decisions made "substantially and directly" by a program, and the regulator's issues paper asks whether a human genuinely can and does override the output.
Is the small business exemption ending too?
No, and it is worth saying clearly because several articles online claim it is. The second round of Privacy Act reforms was released as an exposure draft on 31 August 2026. It does not remove the small business exemption, and the A$3 million threshold stays. The government agreed in principle in 2023 that the exemption should go eventually, but there is no bill and no date for that.
There is one exception worth knowing if you run an accounting, legal, real estate or conveyancing practice. A small business that is a reporting entity under the anti-money-laundering laws is treated as covered by the Privacy Act for those activities, and the new AML/CTF obligations for these professions started on 1 July 2026. If your client-onboarding checks are automated, ask your adviser whether they fall inside this rule.
What might this look like in a small business?
The regulator, the Office of the Australian Information Commissioner (OAIC), said it would publish detailed guidance by September. As at 26 September 2026 we had not found it published, so treat the examples below as questions to take to your adviser, not answers.
| System | What it does | Worth listing? |
|---|---|---|
| Enquiry auto-reply | Acknowledges a form and says who will call | Probably not: it decides nothing about the person |
| Lead scoring | Decides which enquiries get a call back first | Ask: it can affect whether someone gets a service |
| Client risk rating | Flags or declines a new client at onboarding | Likely: a significant effect, made from personal information |
| Payment-plan eligibility | Approves or refuses instalments automatically | Likely |
| Rostering or job allocation | Assigns shifts or work to staff | Ask: and note the separate NSW workplace rules |
What should you do before 10 December?
Law firms advising on this rule have said the same thing: do not wait for the guidance, because the gap between the guidance and the deadline is short.
- List every automation that touches people. Forms, CRMs, scoring, onboarding checks, anything a supplier runs for you. Systems run by third parties on your behalf still count.
- For each one, write two lines: what it decides, and what personal information it reads.
- Mark the ones that pass all four questions. Those are your disclosures.
- Draft the policy wording from the list, in categories, not algorithm detail. The explanatory material says the policy is not expected to include commercial-in-confidence detail about how a system works.
- Re-check when the OAIC guidance lands, then publish before 10 December.
The list from step 2 is useful well beyond this rule. It is the same register every sensible AI policy starts from, and it is what a buyer, an insurer or an auditor will ask you for next.
This article is general information, not legal advice. Sources: OAIC consultation on ADM transparency, Gilbert + Tobin, White & Case on the tranche 2 draft.
Key takeaways
- Four questions decide itCovered business, a program making or substantially making the decision, a significant effect on a person, and their personal information used. All four, and it goes in the policy.
- Existing systems countThe rule applies to decisions made from 10 December, however long ago the system was switched on.
- The register is the real workWrite down each automation, what it decides and what it reads. The wording for the policy follows from that list.
Frequently asked
Does this apply to my small business?
Only if you are covered by the Privacy Act. Most businesses with annual turnover of A$3 million or less are exempt, but some are covered regardless of size, such as health service providers and businesses that trade in personal information. An accounting practice that is an AML/CTF reporting entity is covered for its AML/CTF activities. Check your position with an adviser.
Is the small business exemption ending on 10 December?
No. Several online articles say so, and they are mixing up two things. The 10 December date belongs to this automated-decision rule. The second round of Privacy Act reform, released as an exposure draft on 31 August 2026, leaves the small business exemption in place.
Do I need people's consent for automated decisions?
Not under this rule. It is a transparency requirement: your privacy policy must describe the kinds of personal information used and the kinds of decisions made. It does not add a consent step and it does not ban anything.
Does a human checking the output take it outside the rule?
Not automatically. The rule covers decisions made substantially and directly by a program, not only fully automatic ones. The OAIC's issues paper points to how much weight the output carries and whether a person genuinely can and does override it. A rubber-stamp review is unlikely to be enough.
Has the OAIC published its guidance yet?
It said it would by September 2026. As at 26 September we had not found final guidance published. Check the OAIC's APP 1 guidelines page before you finalise any wording.