A plain-English guide to the Australian automated decision-making transparency obligation that commences on 10 December 2026. From that date, APP entities that use a computer program, including AI, to make decisions that could reasonably be expected to significantly affect an individual's rights or interests must disclose in their privacy policy the kinds of personal information used and the kinds of decisions made. Corrects a widespread claim that the Privacy Act small business exemption is removed on the same date: it is not. The exemption remains in place, its removal was left out of the Privacy and Other Legislation Amendment Act 2024 and deferred to a second tranche of reforms that has not been introduced and has no commencement date. Covers who is actually caught, including the exceptions that cover businesses under the $3 million turnover threshold such as health service providers, businesses that buy or sell personal information, and Commonwealth contractors. General information, not legal advice.

    Compliance Guide
    Commences 10 December 2026

    Automated decisions and your privacy policy: what actually changes on 10 December 2026

    If your business uses a computer program, and that includes AI, to make decisions that could seriously affect someone, your privacy policy will have to say so. It is narrower than a lot of what you have read, and it does not land on every business in Australia.

    StartCloud16 September 20267 min read
    The short version

    The short version

    A new transparency rule starts on 10 December 2026. Privacy policies have to disclose automated decisions that significantly affect people, including decisions made by AI.

    It only applies if the Privacy Act already covers you. Most businesses under $3 million turnover are still outside the Act, though the exceptions catch more of them than owners expect.

    The small business exemption is not removed on that date. A lot of articles say it is. They are wrong, and we set out the source below.

    Clearing something up

    The thing you have probably read, and why it is wrong

    Over the past few months a wave of articles has appeared telling Australian small businesses that the Privacy Act small business exemption disappears on 10 December 2026, and that 2.5 million businesses are about to be pulled into the Act.

    That is not right.

    The small business exemption, the one that keeps most businesses under $3 million turnover outside most of the Privacy Act, is still there. Removing it was proposed during the Privacy Act review, and the government has said it is working on a second tranche of reforms that would do it. But that legislation has not been introduced, and there is no commencement date.

    You do not have to take our word for it. The Parliamentary Library's own Bills Digest for the Privacy and Other Legislation Amendment Bill 2024 records industry groups being disappointed that the Bill did not remove the small business exemption. It was left out and deferred.

    What genuinely commences on 10 December 2026 is the automated decision-making transparency obligation, added to Australian Privacy Principle 1 by that same Act. Two different things, one date, and a lot of articles have welded them together.

    We are not saying this to score points. We are saying it because a Perth business owner who believes the wrong version spends money and worry on the wrong problem, and quite possibly ignores the obligation that does apply to them.

    Scope

    Does this actually apply to you?

    The new rule applies to APP entities. If the Privacy Act already covers you, it covers this too.

    Most businesses turning over under $3 million a year are not APP entities, so as things stand today this does not apply to them. That is the exemption doing its work.

    Except the exemption has holes in it, and they catch more small businesses than people expect. You are covered regardless of turnover if you are a health service provider and hold health records, which includes a surprising number of allied health and wellbeing businesses. You are covered if you buy or sell personal information. You are covered if you are a contractor providing services under a Commonwealth contract, which sweeps in businesses doing government work. Credit reporting and tax file number handling bring their own obligations too.

    If you are a WA business bidding for government work, read that list again. Plenty of businesses that assume they are exempt are not.

    And if you are over $3 million, this is simply yours to deal with.

    The test

    What counts as an automated decision

    The test is not whether you use AI. The test is whether a computer program uses personal information to make a decision that could reasonably be expected to significantly affect someone's rights or interests.

    Two halves matter there.

    The decision has to be made, or substantially made, by the program rather than by a person using a tool. A human who reads a report and decides is not automated decision-making. A system that scores an application and returns an answer probably is.

    And the effect has to be significant. Credit decisions. Hiring and shortlisting. Insurance pricing. Access to a service someone needs. Tenancy. Those affect people's lives in a way that a recommendation engine picking which product photo to show does not.

    Here is where it gets uncomfortably close to home for a lot of businesses. If you have wired an AI tool into your hiring process to rank applicants, or you use automated scoring to decide who gets credit terms, you are likely in scope. Most businesses that did this did not think of it as automated decision-making. They thought of it as saving time.

    If you are not sure what your team has connected to what, that is worth finding out for more reasons than this one. Our AI usage analysis exists because most businesses genuinely do not know.

    The obligation

    What your privacy policy has to say

    The obligation is a disclosure one. You are not being told you cannot make automated decisions. You are being told you have to be open about it.

    Your privacy policy needs to cover the kinds of personal information the systems use, and the kinds of decisions those systems make.

    Kinds, not a line-by-line inventory. You are describing the shape of what happens, clearly enough that someone reading it understands their information goes into an automated process and what sort of call comes out the other end.

    The OAIC has been consulting on more detailed guidance and has signalled it will publish before the commencement date. When that lands, it is worth reading properly rather than guessing, because the difference between adequate and inadequate disclosure is exactly the kind of thing guidance is for.

    Practical steps

    What to do now

    None of this requires a compliance department. Four moves cover most of the ground for a typical WA business.

    Check if you are covered

    Turnover first, then the exceptions. Ten minutes with your accountant settles it, and if the answer is no, you have just saved yourself a project.

    List where software decides

    Not where you use software, where software decides. Hiring, credit, pricing, eligibility, access. Include anything you plugged an AI tool into over the past two years.

    Ask who is really deciding

    If a person reviews the output and can genuinely overrule it, that is different to a system that just returns an answer. Be honest here rather than optimistic.

    Update the policy

    If anything is in scope, your privacy policy needs to describe it before 10 December 2026. Start the review now, not in November.

    And if you turn out to be exempt, do the security basics anyway. Most privacy trouble does not start with a compliance failure, it starts with a breach. The exemption will not help you explain to a client why their data is on a leak site, which is why the Essential Eight basics are worth more to most businesses than any policy wording.

    Verdict

    The takeaway

    The rule that commences on 10 December 2026 is real, it is narrower than the headlines suggest, and it lands on businesses the Privacy Act already covers.

    The exemption removal is coming at some point. It is not here, and it is not dated. Anyone telling you otherwise has read a blog post rather than the legislation.

    If you are not sure which side of the line you sit on, that is a short conversation rather than a project. We would rather tell you that you are fine than sell you something you do not need.

    Sources

    Where this comes from

    This article takes a position that contradicts a lot of what is currently published, so here is where every claim comes from. All of it is Australian Government material, and none of it is behind a paywall.

    Privacy and Other Legislation Amendment Bill 2024, Bills Digest

    Parliament of Australia

    Records that the Bill did not remove the small business exemption, which was left to a later tranche of reforms.

    Consultation on guidance for transparency in automated decision-making

    Office of the Australian Information Commissioner

    The OAIC's work on what the APP 1 automated decision-making disclosure will require in practice.

    APP 1: Open and transparent management of personal information

    Office of the Australian Information Commissioner

    The Australian Privacy Principle the new automated decision-making obligation is being added to.

    Privacy obligations for small business

    Office of the Australian Information Commissioner

    The current small business exemption, including the exceptions that catch businesses under the turnover threshold.

    FAQ

    Common questions

    Is the small business exemption removed on 10 December 2026?

    No. The exemption is still in place. What commences on that date is the automated decision-making transparency obligation under Australian Privacy Principle 1. Removing the exemption was proposed as part of a second tranche of privacy reforms, but that legislation has not been introduced and has no commencement date. A lot of articles have run the two together.

    We use AI to help shortlist job applicants. Are we caught?

    Possibly, if the Privacy Act covers you. Hiring decisions affect people's rights and interests, so if a program is making or substantially making the shortlisting call using personal information, that is the kind of thing the rule is aimed at. If a person reviews every application properly and the tool only sorts them, you are on safer ground. Write down how it actually works, not how it was meant to work.

    We turn over under $3 million. Can we ignore this?

    Probably, but check the exceptions first. Health service providers, businesses that buy or sell personal information, and contractors working under a Commonwealth contract are covered regardless of turnover. WA businesses doing government work catch people out here more than anything else.

    What happens if we do nothing and we are covered?

    This is a transparency obligation under APP 1, so failing to meet it is a privacy breach like any other and the OAIC can investigate. The more likely practical consequence is simpler. A client, an insurer, or a tender process asks how you handle automated decisions, and you have no answer.

    Do we need a lawyer for this?

    For most businesses, no. Working out whether you are covered and describing your automated decisions honestly is something you can do in an afternoon. If you hold health records or you are deep in government contracts, get advice.

    This article is general information, not legal advice, and privacy law is changing quickly. For how these obligations apply to your specific business, particularly around health records or government contracts, check the current guidance at oaic.gov.au or speak to a qualified adviser.

    StartCloud Assistant

    Online

    G'day! 👋 I'm the StartCloud Assistant. How can I help you today?