Support
Contact
Book a Free ReviewCall 1300 053 948
Privacy

From December 2026, if software makes decisions about people, your privacy policy must say so

New Privacy Act rules from 10 December 2026 make businesses disclose automated decision-making. Who's caught, what to write, and how to get ready in time.

From 10 December 2026, Australian privacy law requires businesses to disclose when computer programs make significant decisions about people. If software scores, filters, approves or prices anything involving humans in your business, this applies to you.

Buried in Australia's 2024 privacy reforms is an obligation with a long fuse: from 10 December 2026, privacy policies must explain the automated decision-making a business uses. It sounds bureaucratic. It is actually one of the first legal obligations in Australia that forces businesses to take stock of what their software — increasingly, their AI — decides on its own.

What exactly has to be disclosed?

From 10 December 2026, if a business uses computer programs to make decisions (or do things substantially connected to making decisions) that could reasonably be expected to significantly affect a person's rights or interests, its privacy policy must set out: the kinds of personal information used in those decisions, and the types of decisions made or substantially assisted by automation. The obligation sits within the Privacy Act's transparency rules, so it applies to businesses already covered by the Act — generally those with over $3 million turnover, plus smaller businesses in certain categories like health services.

What counts as an automated decision in a normal business?

More than most owners assume. Likely candidates hiding in everyday tools:

Finance and lending

credit scoring, loan pre-approvals, automated risk pricing.

Recruitment

software that screens, ranks or filters candidates before a human looks.

Real estate

automated tenant screening and application scoring.

Insurance and advice

algorithmic pricing and eligibility checks.

Anything with an AI layer

if an AI tool recommends who gets a callback, a discount or a decline, and a human rubber-stamps it, that is "substantially assisted" territory.

How do you get ready without overengineering it?

Getting ready is a stocktake, a policy update, and a judgement call on human review:

1

Inventory the decisions.

List where software scores, ranks, filters, prices or approves anything involving a person — including AI tools adopted informally by staff. (This inventory is the same one good AI governance needs anyway; do it once, use it twice.)

2

Classify significance.

A spam filter is not a significant decision about a person's rights; declining a rental application is. When in doubt, list it.

3

Update the privacy policy.

Plain-English descriptions of the information used and decision types — not vendor names or algorithm details.

4

Add a human path.

The reform's direction of travel is people being able to question automated outcomes. Building a review path now is cheap; retrofitting one under complaint is not.

FAQ

Frequently asked questions

We're under $3 million turnover — can we ignore this?

Mostly, unless you are in an always-covered category (health services being the big one) or trade in personal information. But if larger clients rely on your processing, expect their contracts to push the obligation down to you regardless.

Does using ChatGPT or Copilot trigger this?

Not by itself. The trigger is software making or substantially assisting decisions that significantly affect people's rights or interests — drafting an email does not; auto-ranking job applicants does.

What happens if we just don't update the policy?

Transparency breaches sit inside the Privacy Act's beefed-up penalty framework, and the regulator has been signalling a more active enforcement posture across 2026. The fix costs an afternoon; being an example costs considerably more.

Who should own this internally?

Whoever owns privacy generally — but they need IT's help for the inventory, because the decisions live inside systems. We produce exactly this software-and-AI inventory as part of our governance work.

Start with the stocktake

December feels far away until it isn't. We help clients inventory their automated and AI-assisted decisions as part of Using AI safely & securely — the same exercise that keeps AI adoption sane also gets your privacy policy ready.

Book your free IT & Cyber Security Review

See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.