What's actually changing on 10 December
In 2024, Parliament passed the Privacy and Other Legislation Amendment Act 2024, which added new subclauses to Australian Privacy Principle 1:APP 1.7, 1.8 and 1.9. They commence on 10 December 2026. This is not a proposal or a discussion paper; it's already law, waiting for its start date.
The rule, in plain English: if a business is bound by the Privacy Act (an "APP entity"), and it arranges for a computer program to use someone's personal information to make (or substantially help make),a decision that could reasonably be expected to significantly affect that person's rights or interests, the business must explain this in its privacy policy. Specifically, it has to describe the kinds of personal information the program uses and the kinds of decisions it makes. The OAIC (Australia's privacy regulator) has confirmed the obligation applies "regardless of whether the decision is beneficial or adverse to the individual", so it's not only about knock-backs.
The OAIC's own guidance gives three examples of the kind of decision this is aimed at: granting or refusing a benefit or entitlement (like eligibility for something), a decision affecting someone's rights under a contract or agreement (such as an insurance policy), and a decision affecting access to a significant service, like healthcare.
Does this actually apply to a small business?
Probably not, for most small businesses. But it's worth fifteen minutes to check honestly rather than assume, because two separate things both have to be true before it applies to you.
First hurdle: is your business bound by the Privacy Act at all? Businesses with annual turnover under $3 million are generally exempt from the Privacy Act under the existing small-business exemption. A second wave of privacy reform has floated removing that exemption, but as of now it remains only a government commitment.No bill has passed and no date is set. Don't let anyone tell you the exemption is already gone; it isn't. (There are some carve-outs to the exemption already in place (for example, businesses that trade in personal information, or that provide health services) worth checking with a professional if you're unsure which category you're in.)
Second hurdle: do you actually use a computer program to make, or substantially help make, that kind of decision? This is the part worth being concrete about. A basic contact form that emails an enquiry to a staff member for a human to review isn't caught. A person is making the decision. What the rule is aimed at is closer to: an online quoting or application tool that automatically approves, declines or adjusts a price or an offer based on what a customer enters; a booking or intake system that automatically triages who gets priority or access to a service; a CRM automation that doesn't just sort leads for a human to look at, but effectively decides who gets contacted and who's filtered out.
This is exactly the kind of case-by-case judgement worth putting to a professional rather than deciding alone, particularly the closer your situation sits to the line. The point of this guide is to help you ask the right question of whoever built or runs your systems: not to hand down a ruling on your specific setup.
Why it's worth doing now, not in late November
Two things make this timely rather than something to file away. The date itself (about thirteen weeks out at time of writing) is close enough that "we'll get to it" quietly becomes "we didn't get to it." And this new rule doesn't exist in isolation: it's part of the same 2024 legislative package that already gave the OAIC a stronger toolkit for privacy-policy enforcement generally. The regulator used that toolkit for the first time with a compliance sweep that began in January 2026, reviewing around 60 businesses' privacy policies, with non-compliant entities facing infringement notices and penalties of up to $66,000. That sweep was about the existing baseline requirements for what a privacy policy must contain (APP 1.4) (not the new automated-decision rule specifically) but it shows the same regulator, under the same reform package, is actively enforcing in this exact area. A business getting ready for the ADM disclosure requirement is a business that's also due for a general privacy-policy check-up.
Three things worth doing this week
Ask the honest question about your own systems
If you run any online quoting, application, booking-triage or lead-scoring tool, ask whoever built or manages it directly: "does this use customer data to automatically make, or substantially help make, a decision that could materially affect someone?" If the honest answer is no (a person always makes the actual call) you're likely not caught, and no action is needed beyond noting the answer in case the system changes.
If the answer is yes, or you're genuinely not sure, plan the disclosure now
You have until 10 December to add a plain-English section to your privacy policy describing the kinds of information used and the kinds of decisions made. The OAIC ran its own consultation on this (an Issues Paper, submissions closed 15 June 2026) and published its guidance on 30 September 2026: an updated Chapter 1 of the APP Guidelines (version 2.0), plus an APP 1.7–1.9 fact sheet with worked examples for recruitment software, a housing platform, bank fraud tools and a government agency. Two points in it are worth knowing before you decide you are out of scope: a decision can be caught even where the program’s output is only advisory, or is reviewed by a person, and a contract with your software vendor does not move the obligation off you. It stays with the business using the personal information to make the decision. Worth a professional’s eye on the exact wording, given this is a compliance document.
Check the basics regardless
Whether or not the ADM rule applies to you, confirm your privacy policy actually covers what the Australian Privacy Principles already require today: what you collect, whether it's disclosed to third parties or overseas, how it's stored, how someone makes a complaint, and a visible last-updated date. That's the exact ground the OAIC's current compliance sweep is checking, and the most common gap is a missing or template policy, not a missing ADM clause.
What a scan can and can't see
Being precise about the boundary, because this is a topic where it would be easy to imply more than we do.
What AegorIQ checks, on every tier including the free Scorecard: whether you have a privacy policy at all, and whether it covers the core elements the Australian Privacy Principles expect: what you collect, whether it's disclosed to third parties or overseas, how it's stored, how someone complains, and whether it carries a last-updated date. We name the specific elements that are missing rather than giving a pass/fail.
What we don't check. We can't determine from outside whether the Privacy Act applies to your specific business, and we can't tell whether any system on your site uses automated decision-making in the way APP 1.7 describes, only you know what your quoting tool, CRM or booking system actually does behind the login. Where something is a legal judgement, like whether your business or your systems are caught by this rule, we say so and point you to a professional. We don't rule on it. The full itemised list of what we do and don't check is published here.
Sources
- OAIC, Chapter 1: APP 1, "New obligations about automated decisions from December 2026" (APP 1.7, 1.8, 1.9 commence 10 December 2026, with worked examples of qualifying decisions)
- Privacy and Other Legislation Amendment Act 2024 (Cth), Part 15, Automated decisions and privacy policies
- OAIC, Privacy compliance sweep to put privacy policies under the spotlight (9 December 2025; sweep began January 2026; penalties up to $66,000 for non-compliant privacy policies under APP 1.4)
- MinterEllison, OAIC ramps up privacy enforcement: are you ready?
- OAIC, Consultation on Guidance for Transparency in Automated Decision Making (Issues Paper published 18 May 2026, submissions closed 15 June 2026)
- OAIC, New resources on transparency for use of AI and automated decision-making (30 September 2026; updated APP 1 Guidelines v2.0, fact sheet and flowchart)
- OAIC, APP 1.7–1.9 Transparency Obligation Fact Sheet (September 2026)
- Gilbert + Tobin, Automated decision-making transparency under the Privacy Act: are you prepared for 10 December 2026? (OAIC guidance expected September 2026)