What changes on 10 December 2026
The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024. One part was given 24 months so businesses could prepare: a new transparency rule inside Australian Privacy Principle 1, the principle that governs your privacy policy.
From 10 December 2026, if the Privacy Act covers your business, your privacy policy must include two extra things where they apply:
- the kinds of personal information your computer programs use when making, or substantially helping to make, decisions about people, and
- the kinds of decisions those programs make, split into decisions the program makes alone and decisions where it does something substantially and directly related to the decision and a person signs off.
The test has three parts, and all three have to be true: you have arranged for a computer program to make a decision, or do something substantially and directly related to making it; the decision could reasonably be expected to significantly affect a person’s rights or interests; and personal information about that person is used in running the program.
Three things the OAIC’s issues paper makes clear. “Computer program” includes rule-based systems, spreadsheets with scoring formulas, and AI, so “we do not use AI” is not the answer. “Decision” includes refusing or failing to make one. And “significantly affect” cuts both ways: a decision in the person’s favour counts as much as one against them.
It applies to decisions made from 10 December onward, whatever the age of the system. There is no grace period.
Who it applies to
The rule applies to APP entities: government agencies, and every business or not-for-profit with annual turnover over $3 million. If that is you, you are in.
Under $3 million, the small business exemption usually applies and this rule does not reach you. But the exemption has exceptions, and two matter a great deal in this part of the country:
- Health service providers of any size. If you provide a health service and hold health information, you are covered whatever your turnover. That takes in aged care providers, allied health practices, NDIS providers and clinics.
- Businesses that trade in personal information. If you buy, sell or swap personal information for a benefit, you are covered.
The OAIC also lists Commonwealth contractors, credit reporting bodies, tenancy database operators, companies related to a larger covered company, and anti-money laundering reporting entities. That last one is new: since 1 July 2026, lawyers, conveyancers, accountants, real estate agents and precious metals dealers are AML reporting entities, and for their AML-related handling of personal information the exemption no longer protects them.
Enacted versus proposed. The 10 December rule is law. Removing the small business exemption is not. The government agreed in principle to remove it, but the exposure draft of the tranche 2 bill released for consultation in September 2026 does not touch the $3 million threshold. Until a bill passes, a business under $3 million with none of the exceptions above is outside this rule. Near the line? Act as if you are covered.
One more change ignores turnover. Since 10 June 2025, an individual can sue any person or business, small business included, under the statutory tort for serious invasions of privacy: intruding on their seclusion or misusing information about them where they had a reasonable expectation of privacy. A court action, not an OAIC complaint, so the exemption does not apply.
What counts as an automated decision in a small business
The OAIC’s examples are big-end-of-town: benefits, insurance, healthcare access, differential pricing. The same test in an owner-led SEQ business:
Aged care and allied health. Rostering software that allocates shifts by rules or a score is deciding about your staff. An incident system that triages reports and decides which ones a clinical lead sees today is deciding about your residents or clients. Intake forms that score a referral and route or decline it are in scope. Most providers here are covered whatever their turnover, so there is the least room to wait.
Agri and regional multi-site operators. A grading line that sorts produce is not about a person. A grower portal that scores a sole-trader grower’s history and sets their price band or payment terms is. So is automated pre-screening of seasonal workers.
Distribution and wholesale. Credit holds applied from a scoring rule. Order holds triggered by a sole-trader customer’s payment history. Automated quote approvals that set a customer’s price.
Any office team. An applicant tracking system that filters CVs before a human reads them. A chatbot that decides whether a customer gets a refund, a callback, or nothing. Leave or expense tools that auto-approve or auto-decline.
The pattern: if a person could reasonably say “the system decided that about me” and the outcome matters to them, write it down.
The 30-minute inventory you can do this month
You cannot disclose what you have not listed. One page, no consultant needed.
- List every system that touches people’s information. Rostering, HR, CRM, quoting, accounts, intake forms, chatbots, the spreadsheet everyone pretends is not a system.
- For each one, ask: does it decide anything about a person, or do most of the work behind a decision? Yes, no, or not sure. “Not sure” stays on the list.
- For each yes, write three things. The kinds of personal information it uses. The decision it makes. Whether the program decides alone or a person signs off.
- Mark the ones that matter to the person. Employment, pay, care, credit, price, access to a service. Those are the entries your policy needs.
- Check the third-party systems. If a SaaS tool decides on your behalf, it is still your arrangement and your disclosure. Ask the vendor how the feature works and keep the answer.
- Date the page and diarise a re-check. The OAIC’s final guidance was not published when this page was last checked. Read the list against it when it lands.
That list does triple duty: your December disclosure, the honest starting point for any automation worth paying for, and the security check for tools your team has already built with AI.
What to put in the privacy policy
A shape, not legal advice. Read it against your own list first.
Automated decisions. We use computer programs, including [rule-based software / scoring tools / AI tools], to make or help make some decisions about the people we deal with. These programs use [kinds of personal information: for example contact details, availability, payment history, intake health information]. Decisions the program makes without a person reviewing them include [for example: allocating shifts, applying an account hold when an invoice is overdue]. Decisions where the program does substantial work and a person makes the final call include [for example: ranking incident reports for clinical review, shortlisting job applications, recommending a quote price]. If you have a question about a decision that affects you, contact [name and email] and a person will review it.
Keep it at the level of “kinds”. The obligation is about categories of information and decisions, not system names or commercial-in-confidence detail.
What not to automate
If you cannot write down what a system decides about a person and why, that is a decision you should not have fully automated. That is P2A’s whole position. Automate the boring bits. Keep the work human.
In practice that is a governed loop: the program reads, recommends and logs; a person approves wherever judgement or risk is involved; then the program acts. Decisions about someone’s job, care, credit or access stay on the human side of that line. Built that way, the disclosure almost writes itself. The safety loop on the Why automate page shows how that looks in a real workflow.
If you are forwarding this to a client
Accountants, bookkeepers and IT providers get asked about this by clients unsure whether it means them. The short version to send with the link:
- Starts 10 December 2026, already law. A privacy policy disclosure, not a ban on automation.
- Over $3 million turnover: covered. Health service providers: covered at any size. AML reporting entities: covered for AML-related handling. Everyone else under $3 million: not covered yet; removal of the exemption is proposed, not enacted.
- The work is a one-page inventory and a paragraph in the policy, about an hour. No lawyer needed unless the list turns up something uncomfortable.
- No transition period for existing systems.
You are welcome to use this page or the inventory steps in your own client communications, with a link back. If you want a co-hosted session for your clients on the inventory, ask.
Questions owners ask
Does this apply to businesses under $3 million turnover?
Not unless an exception applies: health service providers, businesses that trade in personal information, Commonwealth contractors and AML reporting entities are covered regardless of turnover. Removing the exemption is proposed, not legislated.
Does it only apply to AI?
No. Any computer program that makes or substantially helps make a decision counts, including rule-based software and spreadsheet formulas.
What if a person always reviews the decision?
You may still need to disclose it. The rule separately covers decisions where the program does something substantially and directly related to the decision and a person makes the final call.
Is there a penalty for getting it wrong?
The same 2024 Act gave the OAIC a lower tier of civil penalties and infringement notices for administrative breaches such as privacy policy failings. The practical risk for a small business is a complaint or a regulator request you cannot answer.
Where is the OAIC's guidance?
The OAIC consulted on an issues paper from 18 May to 15 June 2026 and intended to publish guidance before commencement. It had not been published when this page was last checked. This page will be updated when it is.
Where to from here
If the inventory turns up decisions you did not know were automated, or systems nobody can explain, that is worth a conversation before December, and it is what the free discovery call is for. Bring the list. I will tell you what I would fix first, what to leave alone, and whether you need a lawyer or just a paragraph. Need someone accountable for technology decisions beyond this one? See the fractional CIO seat.
Sources
- Privacy and Other Legislation Amendment Act 2024 (Cth), No. 128, 2024
- OAIC, APP Guidelines Chapter 1: new obligations about automated decisions from December 2026
- OAIC, Consultation on guidance for transparency in automated decision making
- OAIC, Automated decision making issues paper (PDF)
- OAIC, Small business
- OAIC, Statutory tort for serious invasions of privacy
- OAIC, Guidance on privacy and the use of commercially available AI products
- Attorney-General's Department, exposure draft Privacy Amendment (Personal Data Protection) Bill 2026