Parliament is overhauling privacy law in Australia, and the changes are due to take effect on 10 December 2026. The main change is about transparency in automated decision-making. In this article, we go over what is changing, who it applies to, and how to get your small business privacy policy ready.
What changes on 10 December 2026?
The Privacy and Other Legislation Amendment Act 2024 inserted new requirements into Australian Privacy Principle 1 in the Privacy Act 1988 (the APP that governs privacy policies). From 10 December 2026, you’ll have an obligation to disclose additional information in your privacy policy about your automated decision-making if:
- Your business uses a computer program to make a decision, or uses a computer program for something that is substantially and directly related to making that decision; and
- A reasonable person would expect that decision to significantly affect the rights or interests of an individual (such as your customers, employees, competition, etc.); and
- That individual’s personal information is used in the process of using the computer program to make the decision or do a thing (such as feeding that personal information into an AI model).
If your business is an ‘APP (Australian Privacy Principle) entity’, and these criteria apply to you, then your privacy policy will have to include:
- The sorts of personal information being used in automated decision-making;
- What sorts of decisions are being made by the computer program; and
- What things the computer program is doing that are substantially and directly relevant to making decisions.
Doesn’t this only apply to big tech?
No. We mentioned that these requirements apply to ‘APP entities’ before, and APP entities aren’t limited to massive companies.
There is currently a small business exception for businesses with an annual turnover of $3 million or less, however depending on the information you deal with or how you deal with it, this exemption may not apply. Further, there have been discussions about removing the exemption entirely.
As such, it’s a good idea to start amending your privacy policy now, regardless of your turnover. It’ll be cheaper than scrambling later, and your customers increasingly expect it anyway.
What else is already in force?
There are two other things that have already changed in the Privacy Act.
First, individuals can already sue directly for serious privacy invasions, and that applies regardless of business size.
Second, penalties were increased significantly in 2022, and the enforcement regime was restructured again in 2024.The top penalty now applies to a serious interference with privacy, and for a company it is the greater of $50 million, three times any benefit obtained, or 30% of adjusted turnover. Those numbers are aimed at large-scale breaches.
What matters more for most small and medium businesses is the lower tier the 2024 changes introduced, which lets the Information Commissioner issue compliance and infringement notices, including where a privacy policy does not contain what the law requires. The Commissioner began reviewing businesses’ privacy policies directly in January 2026.
What should you update before December?
- Audit your tools: List every system that makes or shapes decisions about people. This includes approval workflows, screening tools, AI assistants, and scoring systems.
- Update your privacy policy: Add the required automated decision-making disclosures, and check that the policy still reflects reality. Consider what you collect, why, where it goes, and how people can complain. A policy that does not match practice is worse than no policy, because it is evidence of a misrepresentation.
- Check your collection notices: The policy is not the only document; the notices you give when collecting information should line up with it.
- Look at your website terms alongside it: Privacy policies and website terms work as a pair, and we covered the terms side in our website terms guide. Both documents are included in our online shop and app packages.
- If you use AI tools on customer data, get advice: AI complicates how your privacy policy works with the new disclosure rules, the ACL and confidentiality. This is a core area of our IT, SaaS and software practice.
What next?
December’s deadline is really an audit deadline in disguise. Start your audit and update your privacy policy now to avoid the rush in December. If you would like us to review or rewrite your privacy policy at a fixed fee, book a free consultation.





