From 10 December, your privacy policy needs an ingredients list for the decisions software helps you make
By Brett Gavaghan, Founder of Adaptd ·
New Australian Privacy Principles start on 10 December 2026. If a computer program, including AI, helps make significant decisions about people, your privacy policy has to say so.
The short version
- From 10 December 2026, privacy policies must explain when computer programs use personal information to help make significant decisions about people.
- It applies to businesses covered by the Privacy Act, which generally excludes those with annual turnover of $3 million or less.
- List where software or AI informs decisions about customers or staff, then update your privacy policy before 10 December.
Plenty of businesses now let software take a first pass at things that matter to people, like who gets approved, shortlisted or flagged. From 10 December, Australian privacy law says you have to tell them.
What is the new automated decision rule?
The new rule, in Australian Privacy Principles 1.7 to 1.9, requires a privacy policy to explain when a computer program uses personal information to make, or help make, a decision that could significantly affect someone's rights or interests.
The OAIC's fact sheet, published in September 2026, reads 'computer program' broadly. It covers rule-based software, AI and machine learning, off-the-shelf software you've configured, and generative AI such as chatbots. A decision can still count when a person reviews the output, so 'but a manager signs off' isn't a get-out clause.
Who does it apply to, and when?
The rule applies from 10 December 2026 to every organisation covered by the Privacy Act, known as APP entities.
That generally means businesses with annual turnover over $3 million. Smaller businesses are mostly exempt, but the OAIC lists exceptions, such as health service providers, so check its small business page if you're unsure. The policy has to describe the kinds of personal information and the kinds of decisions involved, not every piece of software you own.
What should your business do about it?
Businesses covered by the Privacy Act should list every place software or AI helps decide something significant about a customer, applicant or employee, then update the privacy policy before 10 December.
Allens suggests starting with an audit of the tools involved in decisions, including ones run by outside providers. My advice: look first at recruitment screening, credit or payment checks and anything that rejects or flags an application. The rule is about transparency and doesn't ban anything, so the work is mostly honest paperwork. Think of it as an ingredients list. Nobody minds the sugar. They mind finding out about it later.
Sources
Wondering what this means for your business?
That's exactly what the discovery call is for.